Service offer set publishing to device agent with on-device service selection.
Abstract
Disclosed in the present invention is various embodiments for editing a set of service offerings for a device agent on an end-user device and for selecting a service on the device. In some embodiments, a network system publishes a set of service offerings to the end-user device through a wireless access network, receives a user selection from the set of offers from the end-user device, and provides a or more network functions depending on the selection of the set of offers by the user.

Term
5 yearsleft in the term
Expires 21 September 2031.
- Priority
- Filed
- Granted
- Today
- Expires
13 claims: 1 independent, 12 dependent
- 1269 269 INSTITUTO MEXICANO DE LA PROPIEDAD MEXICAN INSTITUTE OF PROPERTY INDUSTRIAL INDUSTRIAL CLAIMS ............................ REIVINDICACIONES ............................ 1. An end user device comprising:a modem for accessing a network data service through a mobile access network;a user interface;and, a service processor configured to: 1. Un dispositivo de usuario final que comprende: un módem para acceder a un servicio de datos de red a través de una red de acceso móvil;una interfaz de usuario;y, un procesador de servicios configurado para: requerir, a través de una interfaz de programación de la aplicación segura (API) de un elemento de red accesado via la red de acceso móvil, un conjunto de ofertas de servicios;require, through a secure application programming interface (API) of a network element accessed via the mobile access network, a set of service offerings;obtain, in response to the request, a corresponding set of service offers comprising information describing the service plan offer and actionable user selection options;obtener, en respuesta al requerimiento, un conjunto de ofertas de servicios correspondiente que comprende información descriptica de la oferta del plan de servicios y opciones de selección del usuario accionables;extract information from the set of service offerings;extraer información desde el conjunto de ofertas de servicios;presentar un mensaje de notificación que contiene la información desde el conjunto de ofertas de servicios a través de la interfaz del usuario;presenting a notification message containing the information from the set of service offerings through the user interface;obtaining, through the user interface, a response from the user to the notification message;obtener, a través de la interfaz de usuario, una respuesta del usuario al mensaje de notificación;generar un mensaje de respuesta que comprende información que especifica una elección del usuario de entre las opciones de selección del usuario accionables en un formato esperado por un conjunto de selecciones del receptor de selección de ofertas por el usuario ;y, generating a response message comprising information specifying a user's choice from actionable user selection options in a format expected by a set of user offer selection receiver selectio ns;Y, 270 270 I !NS ds la fr.·.· o [f UV enviar el mensaje de respuesta a la interfaz de programación de la aplicación segura. I! NS in fr. ·. · O [f UV send the reply message to the programming interface of the secure application.
1,259 paragraphs in 102 sections, as filed
Institute
Mexican Property
Industrial
<img file="MX336960B_D0001.tif" />
PATENT TITLE NO. 336960 _SE_
SECMTAIElA W «WOMÍA
<img file="MX336960B_D0002.tif" />
Owner (s): HEADWATER PARTNERS I LLC
Address: 350 Marine Parkway, Suite 300, Redwood City, California, 94065, USA
Name: SERVICE SET OF ADVERTISING OFFER TO A DEVICE AGENT WITH SELECTION OF SERVICE IN DEVICE. lnt.CI.8: H04M15 / 00
5REGC
<img file="MX336960B_D0003.tif" />
lien)>: 21
Validity: Twenty-one Date of the Vi .a patent reference granted by ct
<img file="MX336960B_D0004.tif" />
i conformity with the ari ntada from the right faith.
<img file="MX336960B_D0005.tif" />
CITUD
Presentation date September i, 2011
PRIORITY
Date:
<img file="MX336960B_D0006.tif" />
September 1 December December 2010 September 2011 September 2011
<img file="MX336960B_D0007.tif" />
the Property and Law of the P ontation of the application
61/385.020
61M18.S09
61/422,674
13/229,680
13 / 237,827 twenty years imf ía fee to maintain industrial.
pr Togi lables, lenses the
of the 705/1999,
01/26/2004, 06/16/2005, 01/25/2006, 05/06/2009, 06/01/2010, 06/18/2010, 06/28/2010, 01/27/2012 and 09/09 04/2012); Articles 1, 3 'section V subsection a), 4' and 12 'sections I and III of the Regulations of the Mexican Institute of Industrial Property (DOF 12/14/1999, amended on 07/01/2002, 07/15/19 2004, 07/28/2004 and 09/07/2007); Articles 1, 3, 4, 5 fraction V subsection a), 16 sections I and III and 30 of the Organic Statute of the Mexican Institute of Industrial Property (DOF 12/27/1999, amended on 10/10/2002, 07/29/2004, 08/04/2004 and 09/13/2007); 1 '3 ° and 5' subsection a) of the Agreement that delegates powers to the Deputy General Directors, Coordinator, Divisional Directors, Heads of Regional Offices, Divisional Deputy Directors, Departmental Coordinators and other subordinates of the Mexican Institute of Industrial Property. (DOF 12/15/1999, amended on 02/04/2000, 07/29/2004, 08/04/2004 and 09/13/2007).
<img file="MX336960B_D0008.tif" />
Arena No. 550. Floor 1 «
Col. Pueblo Sania Marta Tepepan, Xochtmüco Delegation,
CP 16020. Mexico City
Te¡ (55) 53 34 07 00 www.impi.aob wx
Issue Date: February 8, 2016
TO DIVISIONAL DIRECTOR OF PATENTS
<img file="MX336960B_D0009.tif" />
NAHANNY CANAL REYES
<img file="MX336960B_D0010.tif" />
MX / 2016/10974 3/3! 38
PÜBLICII OFFERING SERVICE SET
DEVICE WITH SERVICE SELECTION
Background of the invention
With the emergence of communications
<img file="MX336960B_D0011.tif" />
<img file="MX336960B_D0012.tif" />
content distribution in a mass market, numerous access networks such as wireless networks, wired networks and DSL (Digital Subscriber Line) networks, are operationally pressured with respect to the ability of users for, for example, wireless networks EVDO (Evolution Optimized Data), HSPA (High Speed Packet Access), LTE (Long Term Evolution), WiMax (Worldwide Interoperability for Microwave Access) and WiFi (Wireless Fidelity) that make user capacity increasingly restricted. Although the capacity of wireless networks will increase with new, higher capacity wireless radio access technologies such as MIMO (Multiple Input, Multiple Output) and with more frequency spectra to be developed in the future, these gains of capacities are likely to be less than needed to meet the increasing demand for digital network management.
Similarly, although wired access networks, such as cable and DSL, may have higher average capacity per user, the service consumption habits of wired line users tend toward
LF H ~ <sup>v</sup>'· V \' or <sup>1</sup> > PRCFiíO, · ,!}.
very high-bandwidth applications, which can & éñ '^ - col deupKTKíCq $ \ quickly, available capacity and * "~" 7ieg9? a<sub>(</sub>dAX »^<sub>and</sub>~ ^ global network service experience. As some components of service provider costs increase with increased bandwidth, this trend will negatively impact service provider profits.
Brief description of the drawings
Various embodiments are disclosed in the following detailed description and accompanying drawings.
Figure 1 illustrates a wireless network architecture to provide a device-assisted CDR record creation, aggregation, mediation and billing function in accordance with some embodiments.
Figure 2 illustrates another wireless network architecture for providing a device-assisted CDR record creation, aggregation, mediation and billing function, in accordance with some embodiments.
Figure 3 illustrates another wireless network architecture for providing a device-assisted CDR record creation, aggregation, mediation and billing function according to some embodiments.
Figure 4 illustrates the provision of a wireless network
Mexican Institute of Industrial Property
<img file="MX336960B_D0013.tif" />
to provide a device-assisted CDR record creation, aggregation, mediation and billing function according to some embodiments.
Figure 5 illustrates a network architecture for providing device-assisted record CDRs according to some embodiments.
Figure 6 illustrates another network architecture for providing device-assisted record CDRs according to some embodiments.
Figure 7 illustrates another network architecture for providing device-assisted record CDRs according to some embodiments.
Figure 8 illustrates another network architecture for providing device-assisted record CDRs according to some embodiments.
Figure 9 is a functional diagram illustrating a device-based service processor and a service controller according to some embodiments.
Figure 10 illustrates a table summarizing various service processor functional elements according to some embodiments.
Figure 11 illustrates a table summarizing various service controller functional elements according to some embodiments.
Figure 12 illustrates a stack of devices that
<img file="MX336960B_D0014.tif" />
<img file="MX336960B_D0015.tif" />
-k
INSTITUTO MTS 'CANO provides various measurements of P utilization<sup>£</sup>^ £ V§ / givarios points in the network management stack for a service monitoring agent, a billing agent, and an access control integrity agent to assist in verifying service utilization metrics and reporting billing according to some embodiments.
Figure 13 illustrates an embodiment similar to Figure 12 where part of the service processor is implemented in the modem and part of the service processor is implemented in the device application processor according to some embodiments.
Figures 14 (A), 14 (B), 14 (C), 14 (D) and 14 (E) illustrate various embodiments of intermediate network management devices that include a service processor for the purpose of measuring verifiable service utilization, reporting and billing reports according to some embodiments.
Figure 15 illustrates a wireless network architecture to provide a device-assisted CDR record creation, aggregation, mediation and billing function, including a proxy server according to some embodiments.
Figure 16 is a functional diagram illustrating the service processor service control device link and the controller service control device link in some embodiments.
<img file="MX336960B_D0016.tif" />
Figure 17 is a functional diagram illustrating the framing structure of a service processor communication frame and a service controller communication frame, in accordance with some embodiments.
Figures 18A through 18E provide tables summarizing various parameters and functions of the service processor live network verification signals, in accordance with some embodiments.
Figures 19A through 19G provide tables summarizing various device-based service policy implementation verification techniques in accordance with some embodiments.
Figures 20A through 20C inclusive provide tables that summarize various techniques for protecting device-based service policy against operationally compromised situations, in accordance with some embodiments.
Figure 21 illustrates an exemplary embodiment of a process for initiating or interrupting a data session with notification from the SGSN node.
Figure 22 illustrates an embodiment, by way of ίί .μ τ
Λ
<img file="MX336960B_D0017.tif" />
example of a process to start or stop a data ^ e with notification from the GGSN node.
Figure 23 illustrates an exemplary embodiment with network system elements that can be included in a service controller system to facilitate a device-assisted service (DAS) implementation and the flow of information between those elements. .
Figure 24 illustrates an exemplary embodiment of a service controller reconciliation processing procedure that can be used to detect potential fraud using information from the end user device and information from a second source. .
Figure 25 illustrates an exemplary embodiment that may be operationally advantageous in cases where it is desirable to identify service utilization classifications, on the network, for the purpose of providing a user of the device, or a sponsor of the service, the opportunity to pay for the use of the access network service that is classified by application or website.
Detailed description
The invention can be carried out in numerous ways, including as a process; an apparatus; a system; an operational composition in this regard; a program product
Bí M PROWEDAD V
<img file="MX336960B_D0018.tif" />
of computer science materialized in a computer-readable medium and / or a processor7 ~ ^ ~ TuT mwin nn, a processor configured to execute memorized instructions and / or provided by a memory coupled to the processor. In this specification, these implementations, or any other form that the invention may take, may be referred to as technical. In general, the order of the steps of the disclosed processes can be modified within the scope of protection of the invention. Unless otherwise indicated, a component such as a processor or memory that is described as being configured to perform a task may be implemented as a general component that is temporarily configured to perform the task at a certain time. or a specific component that is manufactured to perform the task. As used herein, the term 'processor' refers to one or more devices, circuits, and / or processing cores configured to process data, such as computer program instructions.
A detailed description of one or more embodiments of the invention is disclosed below with reference to the accompanying figures illustrating the principles of the inventive idea. The invention is described in relation to such embodiments, but the invention is not limited to any one embodiment. The reaching
INSTITUTE ΜΓ- · ΙΓ,> κη OíWPRÓÚIoaS
INDUSTRIAL
<img file="MX336960B_D0019.tif" />
Protection of the invention is limited only by the claims and the invention encompasses numerous alternatives, modifications and equivalents. Numerous concrete details are set forth in the following description in order to provide a thorough understanding of the invention. These details are provided for the purpose of serving as an example and the invention may be practiced according to the claims without some or all of these particular details. For the sake of clarity, technical material that is known in the technical fields related to the invention has not been described in detail in order not to unnecessarily hinder the description of the invention.
There are numerous new types of digital devices where it is desirable, by way of example, to connect these devices to wireless networks including wireless wide area networks (WWAN, such as 3G and 4G) and / or wireless local area networks (WLAN). . These devices include, by way of example, consumer electronics devices, business user devices, and machine-to-machine devices that benefit from flexible wide area data connections and Internet services. Devices, by way of example, include so-called netbooks, notebooks, mobile Internet devices, personal navigation devices (eg, enabled by
<img file="MX336960B_D0020.tif" />
<img file="MX336960B_D0021.tif" />
INSTITUTO MEXICANO Si LA INDUSTRIAL PROPERTY
GPS), music and multimedia players, electronic readers eReaders, industrial telemetry, automotive emergency response and diagnostics, two-way industrial and household energy measurement and control devices, vending machines, parking meters and numerous other devices. By way of example, it is highly desirable to offer service utilization and service billing plans for such devices that are most optimal for each type of device and each type of desired user experience. To do this, more sophisticated service utilization billing and service utilization metering systems are needed compared to currently existing conventional network-based techniques. By providing more flexibility in the metering and billing of services, more advantageous and profitable service plans can be created, for example, the new WWAN networked devices, mentioned above, for the three markets (eg, consumer, commercial and machine-to-machine) that still maintain the profit margins necessary for WWAN network operators that are satisfactory for these various service business activities.
Accordingly, various embodiments are disclosed in the present description to provide a new and flexible extension or replacement system for measuring sprviHn-HP utilization of existing operator networks, accounting for service utilization and systems and billing techniques for the use of the service.
μεχκανο institute for industrial property
<img file="MX336960B_D0022.tif" />
A billing data record (CDR) is a term that, as used herein, defines a formatted measure of device service utilization information, typically generated by one or more network functions that monitor, regulate, and / or they control network access for the device. CDRs records often form the basis for recording network service usage and often form the basis for billing for such usage. Various embodiments are provided in this description for a device-assisted CDR record creation, mediation and billing function. There are numerous limitations to the capabilities of registration, aggregation and / or billing of the use of the service when CDRs are generated exclusively by equipment or network-based functions. Consequently, by augmenting network-based service utilization metrics with device-based service utilization metrics or substituting network-based service utilization metrics with device-based service utilization metrics, it is possible to create a generation solution. , aggregation, mediation and / or billing of CDR that has
IMPI
M-X'CANO INSTITUTE OF INDUSTRIAL FÍtOHEDAD
<img file="MX336960B_D0023.tif" />
superior or more desirable capabilities / characteristics.
Although from a theoretical point of view, much of the service utilization measures, which can be evaluated on a device, can also be evaluated on the network data paths using various network equipment technologies including, without limitation, the so-called Deep Packet Inspection (DPI), there are numerous examples where the use of the measurement service, in the device, is more desirable or more practical or, in some cases, it is the only way to obtain the desired measurement. Such examples include, without limitation, the following:
<td>- Measurements</td><td>of</td><td>utilization</td><td>of</td><td>service</td><td>cape</td><td>of</td>
<td>application (p</td><td>.and. ,</td><td>utilization</td><td>of</td><td colspan="2">classified traffic</td><td>for</td>
<td>application or</td><td>for</td><td>combinations</td><td>of</td><td>app,</td><td>destination</td><td>me</td>
type of content);
-Measures of utilization that do not involve user traffic but instead involve general network traffic (eg, basic connection maintenance traffic, signaling traffic, network registration / AAA / authentication / supervision traffic, service software update);
- The use that is associated with services that are billed to another entity other than the end user (eg, network connection service offer traffic, traffic associated with providing access to the network or downloading
ΜΡΙ
<img file="MX336960B_D0024.tif" />
MEXICAN INSTITUTE. . ,, .... , - _. OF ΙΑ PROPERTY information marketing service ^ TiuAtr associated with services sponsored by. a . ¿¡AuflciatiUr ·. traffic associated with services sponsored by a content provider, 911 service traffic);
-Measures of use that involve encrypted traffic (eg, traffic that is carried out through encrypted network management protocols or between secure endpoints);
- Implementation of the collection of measures for the use of services and / or billing for the use of services through multiple networks that may have different, and in some cases incompatible, inaccessible (to the CDR registration system) or incomplete measurement capabilities of the use of services;
- Service utilization measurement capabilities and / or service utilization billing that are not supported by current network gateways, routers, MWC / HLRs, AAA, CDR aggregation, CDR mediation, billing systems and / or provisioning;
-New service utilization measures and / or new service utilization billing capabilities that are desirable for implementation in a way that does not require major changes or modernizations in existing network gateways, routers, MWC / HLRs, AAA, CDR aggregation, CDR mediation, billing and / or provisioning systems;
IMP
<img file="MX336960B_D0025.tif" />
INSTITUTE .MEXICANO <sub>and</sub>Dtí THE PROPERTY
-New service utilization measures<sup>Du</sup>^ e utilization billing capabilities - de »-e« eswiaicis-u3Uja <are desirable for implementation, in a way that allows rapid definition and implementation of new service measures and / or billing plans ;
-New service utilization measures and / or new service utilization billing capabilities that are desirable for implementation, in a way that can be applied in a way that allows multiple device group definitions, where each group of devices devices obtain a personalized programmable definition for data collection, accounting and / or billing of the use of the service;
-Multi-device billing;
-Multi-user billing;
- Billing of intermediate devices with single and multi-user users with and without multi-device;
-Downloads of content from a specific source to a specific application with the content being of a specific type or even identified to a particular content ID and / or
- Various other unique operational event transactions that are used for billing purposes.
For these and other reasons, it is desirable to provide a system / process that uses measures of use of β-
<img file="MX336960B_D0026.tif" />
<sup>INDIR</sup>Mexican guro service assisted by a device that propagated the improvement of the capacities and techniques of the system. of existing network-based service utilization CDR and / or a replacement of network-based CDR system capabilities and techniques.
In other embodiments, techniques, such as a system and / or process, employing device-assisted service utilization measures include one or more of the following: (1) the receipt of a service utilization measurement from a device in communication with a wireless network, (2) the verification or protection of the validity of the service utilization measurement, (3) the generation of a CDR on the measurement basis of service utilization (eg, device-assisted CDR), (4) aggregation of CDRs and (5) mediation of CDR with network CDRs. In some embodiments, the techniques further include providing network equipment / device provisioning and design to recognize CDR records. In some embodiments, the techniques further include the provision of means to recognize that the device belongs to a group of Device Assisted Services (DAS) devices and that the corresponding CDRs records must be accepted and mediated. In some embodiments, device-assisted CDRs are further generated using formats,
IM F"
MEXICAN JNÍTITUTO
<img file="MX336960B_D0027.tif" />
network communication protocols, network device and / or provisioning to allow device-assisted CDRs in the network CDR system, encryption and / or signatures that are required by the network (e.g., to meet CDR requirements generated by the network or based on any other network requirements and / or service provider and / or standards).
In other embodiments, the mediation rules include multi-device, multi-user, single-user devices, and / or intermediate network management devices that can be single-user or multi-user, as described herein.
In some embodiments, a device-assisted CDR generator collects device-based service utilization metrics that are used as the basis for, or as an enhancement (eg, as a supplement or addition) to, one or more CDRs records (eg, network generated) that provide one or more network management functions with appropriately formatted service usage reports that the network functions accept as being transmitted from an authorized source, Read and used to help determine service utilization for a device or group of devices. In some embodiments, the network functions that the device-assisted CDR generator shares CDRs with the inclusion, in
IMPI normal conditions, one or more of lS<sup>0UST</sup>Slgu?
MEXICAN INSTITUTE
LEAVE THE PROPERTY
<img file="MX336960B_D0028.tif" />
CDR / service utilization mediation and / or aggregation servers, gateways, routers, communication nodes, Mobile Wireless Centers (MWCs, including HLRs registries), databases, AAA systems, billing interfaces and billing systems. As an example, the CDR creation process in the CDR generator typically includes the use of one or more device-based service utilization measures or one or more device-based service utilization measures in combination with a or more network-based measures of service utilization, possibly with the processing of one or more of such service utilization measurements in accordance with a set of CDR creation rules, CDR aggregation and / or CDR mediation to arrive at a measure of end device utilization which is, by way of example, then formatted with the appropriate syntax, framed, possibly encrypted and / or signed with signatures and encapsulated in a packet or communication protocol suitable for sharing network functions. In some embodiments, the CDR generator resides in the device. In some embodiments, the CDR generator resides in a network server function that receives device-assisted service utilization metrics, along with possibly utilization metrics.
<img file="MX336960B_D0029.tif" />
I SAW THE NETWORK-BASED MOREDaD and then, I created a CDR record (EP. ^ Ew service controller 122). ............
In other embodiments, the device-assisted CDR generator may reside in the service processor (eg, service processor 115), for example in the billing server functions or service usage history log. . In some embodiments, the device-assisted CDR generator resides in the device itself, for example within the functions of the service processor, such as the billing agent or the service supervisor agent.
There are several factors that are considered in the various embodiments in order to create a useful, reliable, and secure device-assisted CDR system including, by way of example, without limitation, to:
- Identification of each service utilization measure, based on device, with one or more utilization transaction codes;
-Verification of device-based utilization measures;
- Secure communication of device-based utilization measures to the network;
-Efficient communication (eg, low bandwidth) of the device-based service utilization measurement;
INSTITUTE MEX<sub>IC</sub>YEAR θΕ Μ. PROPERTY
INDUSTRIAL
<img file="MX336960B_D0030.tif" />
- Coordination / comparison / aggregation of device-based service utilization metric with network-based service utilization metrics;
-Forming the device-based service utilization measure in a CDR record that can be adequately communicated to network functions and / or equipment that process service utilization information;
- Making the functions and / or network-based equipment used for data collection, aggregation, mediation and / or billing of CDRs records, perform the functions of recognizing, authorizing and accepting communications and CDR records from the CDR generator. device-assisted, with proper reading and implementation of the correct network session context for the CDR record, so that the CDR is properly associated with the correct device / user / session;
- Implementing CDR aggregation rules that determine how to collect and aggregate device-assisted CDRs, as they are reported through the network's CDR system hierarchy;
- Putting into practice the mediation rules that determine how the service use transaction code measures, based on various devices, are combined and mediated with the other service use transaction code measures, based on
ΡΙ 'W «£ S
INBUjtiuaL
<img file="MX336960B_D0031.tif" />
in device, to give rise to infnrmapiÁB ^ dfl .._ ntj, 1.ization of the coherent service for each of the categories of transaction codes maintained in the network;
- Putting into practice the mediation rules that determine how the CDRs, assisted by device, are combined and mediated with the network-based CDRs to give rise to a coherent service utilization information for each of the categories of transaction codes maintained on the network;
- Implementing mediation rules to reconcile variances between network-based CDR utilization measures and device-assisted CDR utilization measures;
-Classification of one or more groups of devices, with each group having the ability to define, in a unique way, the rules for collecting data on the use of the service, accounting and / or billing;
- Carrying out the collection of CDRs records generated in networks other than the home network, so that the use of the service can be measured, accounted for and / or billed through multiple networks;
-Multi-device billing;
- Multi-user billing and / or
- Billing of intermediate devices with single and multi-user users with and without multi-device.
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0032.tif" />
In other embodiments, verification of the relative accuracy of the device-assisted service utilization measure is disclosed. Given that, by way of example, the service utilization measure is usually generated on an end-user device or a device that is easily physically accessed by the general public or other personnel that are not secure from the point of view of network management, in some embodiments, device agents, used in one or more of the service processor agents 115, are protected against so-called hacking intrusion, spoofing and / or other misuse. Various techniques will be disclosed here to protect the integrity of the agents used to generate the device-assisted service utilization measures.
In some embodiments, the service utilization measures are verified by network-based, cross-checking using various techniques. By way of example, network-based, cross-checks can provide valuable verification techniques since, by way of example, it is usually not possible, or at least very difficult, to operationally reject well-designed network-based cross-checks using various techniques, such as those described here even though, by way of example, the measures used to protect agents
<img file="MX336960B_D0033.tif" />
against operational attacks or if no device protection measures are employed. In some embodiments, network-based cross-checks, used to verify device-assisted service utilization measures, include comparison of network-based service utilization measures (eg, CDRs records generated by a meter). of service utilization in the network equipment, such as BTS / BSCs 125, network gateways RAN 410, transport gateways 420, Mobile Wireless Center / HLR 132, AAA 121, Historical Record of Service Utilization / Aggregation, Mediation and Billing of CDR 118 or other network equipment), the sending of sequences of secure response / consultation orders to the agents of the service processor 115 involved in the measurement of service utilization of CDR, device-assisted, or CDR creation, Sending operational event sequences of use of the test service to the device and verifying that the device is adequately informed of the use of the service and the use of various other techniques, such as those described herein with respect to various embodiments.
In other embodiments, one or more of the following actions is taken if the device-based service utilization measure is found to be in error or inaccurate:
bill the user
<img file="MX336960B_D0034.tif" />
over-service or out-of-policy device, suspend device, operational quarantine device, SPAN (span) device, and / or inform device regarding a network management person or role.
In some embodiments, the CDR record syntax, used to format device-assisted service usage information, in a CDR and / or network communication protocols for transmitting CDRs, are determined by industry standards ( eg, various versions of the 3GPP TS 32.215 and 3GPP2 TSG-X X.S0011 format or TIA-835 format). In some embodiments, for a given network implementation, network designers will specify modifications to the standard syntax, formats, and / or network transmission / communication protocols. In some embodiments, for a given network implementation, network designers will specify network transmission / communication syntax, formats, and / or protocols, which are completely different from standard types.
In other embodiments, within the syntax and operation of formatting CDR, device-assisted service utilization is typically classified by a transaction code. As an example, the iMSTirisro mfjgca '/ o transaction code may be similar or identical to those by the network equipment used for gpnnwM; —rnps p habí Ha note that the device is capable of generating a much broader set of measurements service usage, the transaction codes can be a super-set of the codes used by the network equipment used to generate CDRs (eg, examples of usage activity that can be tagged as transaction codes that are more easily supported by device-assisted CDR systems compared to simply network-based CDR systems disclosed in this description).
In other embodiments, the device sends an identifier for a usage activity tag, a proxy determines how to aggregate into CDR transaction codes and which CDR transaction code to use in this regard.
In some embodiments, the device service processor 115 establishes pre-assigned device activity transaction code usage compartments (eg, these can subtransactions within the main account, transactions within a given transaction of the type billing by account, or sub-transactions within an invoice transaction per account). The device implements the
<img file="MX336960B_D0035.tif" />
rf ··:
billing rules per account for
Λ ΡI
WS + tTUTO MSKiCAJtO BEtÁPRr: tiT.'D ínbustrlú.
<img file="MX336960B_D0036.tif" />
submit different usage reports for each billing function per account. In some embodiments, the service controller 122 programs the device to provide instructions on how to set up billing-by-account service utilization activity compartments so that they can be mapped to code correspondence. transaction.
In other embodiments, the device communicates the service utilization information, less compartmentalized, and the service controller 122 performs mapping of the service utilization activities to the CDR transaction codes, including, in in some cases, billing codes per account.
In some embodiments, the CDR sent to 118 or other network equipment, by way of example, may include various types of transaction codes including, without limitation, a no-treatment device usage CDR, a billing type CDR account (eg, a subactivity transaction code), a billing offset CDR, and / or a billing credit CDR. As an example, the decision logic (also referred to as business rules or CDR records aggregation and mediation rules) that determines how
Β / τ Ό τ
,. ,. Did I see rif faith, ^ K.Í'SKS ',<sub>w</sub> ......? AO ü'.kíüSTfc'AL
<img file="MX336960B_D0037.tif" />
These various types of CDR transaction codes have to be aggregated and mediated by the base network and the<sup></sup>Billing system may be located in the network equipment (eg, a network element, such as service utilization 118), in the service controller 122 and / or in the billing system 123.
In other embodiments, the device-assisted CDR generator uses device-assisted service utilization metrics to generate a CDR record that includes service utilization information, service utilization transaction codes, and in some ways implementation, network information context. In other embodiments, the service usage information, the transaction code, and / or the network information context are provided in the communication fabric, syntax, encryption / signature, security, and / or management protocol format. networks that are compatible with the formatting operation used by conventional network management equipment to generate CDR records. By way of example, this allows the network management equipment used for the CDR collection, registration, aggregation, mediation and / or conversion to the billing record to perform an appropriate acceptance, reading and interpretation of the CDR records that are generated with the based service utilization metering assistance
<img file="MX336960B_D0038.tif" />
ip j
i. · on device. In some forms of realization. device-assisted service utilization metrics if provided to an intermediate network server referred to as a service controller (eg, service controller 122). In other embodiments, the service controller uses a CDR billing aggregation system for a wireless network to collect device-generated utilization information for one or more devices on the wireless network and provides the device-generated utilization information at a syntax (eg, billing data record (CDR)) and a communication protocol (eg, 3GPP or 3GPP2 or other communication protocols) that can be used, over the wireless network, to augment or replace the utilization information generated by the network for the one or more devices on the wireless network.
In other embodiments, the mediation rules include multi-device, multi-user, single-user device, intermediate network management device that can be a single user or multi-user. By way of example, device-assisted CDR records can be formatted by the device-assisted CDR generator to include a transaction code for a single user account, even though the CDRs originate from multiple devices that they all belong
<img file="MX336960B_D0039.tif" />
INSTITUTE V '- * -
L-- J llh W ww i ¿IJZ J.
them to the same user. This is, by way of example, for a multi-user device assisted CDR billing solution. As another example, for a multi-user device-assisted CDR billing solution, device-assisted CDR records from multiple devices and multiple users can all be billed for the same account (eg, a family plan or a corporate account), but CDR transaction records of the type billing by account can be maintained through the billing system, so that visibility of subaccounts is provided, In order that the person or entity responsible, for the main account, can obtain visibility on which users and / or devices are creating most of the billing for the use of the service. By way of example, this type of multi-user, multi-device, device-assisted CDR billing solution can also be used to track service utilization rates and / or billing for service utilization classes that are impossible or at the same time. less very difficult to account and / or bill with simply web-based CDR systems. In some embodiments, CDR account billing type transaction records can be used to provide sponsored transaction services, account for private social network, provide '\ / Γ or
iNífrruTf? ia LA PLt
INDUSTRIAL cako 'Ολο
<img file="MX336960B_D0040.tif" />
• 'Services selection interfaces and services for' multi-user or multi-device service plans.
In addition to conventional single-user devices (eg, mobile phones, smartphones, netbooks / notebooks, mobile Internet devices, personal navigation devices, music players, eReaders, and other single-user devices), measurement service utilization, assisted by device, and CDRs records are also useful for other types of network capable devices and / or network management devices, such as intermediate network management devices (eg, 3G / 4G WWAN to WLAN bridges / routers / gateways, Femto cells, DOCSIS modems, DSL modems, remote access / backup routers, and other intermediate network devices). By way of example, in such devices, particularly with regard to a secure way to verify that device-assisted service utilization measurements are relatively accurate and / or device service processor software 115 is not compromised or compromised. Subject to operational intrusions, many new service provider billing and service delivery models can be supported and implemented using the techniques described here. As an example, in an operational router or bridge device
ι.Γ 7λ /) 7'Τι ΊΓ ζ-β »κ.
Inst; tuto macano feSSÍc:
OF THE PRüFIEOAO ν ^ Ί-? ** Industrial W from Wi-Fi to WWAN, multiple user devices can be supported with the same management device Do you networks ”intermediate in a way that is consistent and compatible with CDR's aggregation and / or billing system, central provider, sending records CDRs, assisted by device, as described herein and that have a billing and / or service usage code that is the object of reference for the end user and / or the particular intermediate device.
In other embodiments, the device-assisted CDRs, generated for the intermediate network management device, are associated with a particular end user, where there may be several or many end users using the intermediate network management device to access to network management and, in other embodiments, with each end user being required to enter a unique login to the intermediate network management device. By way of example, in this way, all devices that connect using Wi-Fi to the intermediate network management device to gain access to WWAN generate CDRs that can be obtained billed for a particular end user, who is responsible for the master account for that device or CDRs records can be billed in a secure manner, with a verified relative utilization metric accuracy for multiple users
2Μ.ΡΙ iNíTrn;? ..:.
UAL
<img file="MX336960B_D0041.tif" />
same intermediate network management device. As another example, an end user may have a single account that allows access to multiple intermediate network management devices and each intermediate network management device can generate CDRs, assisted by device, consistent with the transaction codes for that. end user, regardless of the intermediate network management device that the end user enters in the initial registration.
In other embodiments, some of the services provided by the intermediate network management device are billed for a specific end-user, device-assisted CDR transaction code, while the other billing-by-account type services are billed. for other transaction code accounts, such as sponsored partner transaction service accounts, private social network accounts, sponsored advertiser accounts and / or service subscription accounts. By way of example, thus, various embodiments are disclosed where intermediate network management devices (eg, a WWAN to Wi-Fi router / bridge) can be sold to a single user, but can serve and used to bill other users (eg, and this operation can be covered in the terms of service of the '·> λ'Αλ \' Ο
<img file="MX336960B_D0042.tif" />
THE;·;
first acquiring user perhaps in exchange<sup>TO THE</sup> po discount) or such devices from '* gestfiW ^ ~ dtt surrounds ..'. Intermediates can be located where access is desired regardless of whether the device is subject to operational intrusion, so that services can be purchased without charge.
In some embodiments, various types of service usage transactions are billed on the intermediate network management device, for any one or more users, where the information required to bill said services is not available to the central provider or MVNO network equipment, as is the case with, for example, conventional single-user devices. Considering the various embodiments and techniques described herein, those skilled in the art will appreciate that similar service models are equally applicable not only to intermediate network management devices from WWAN to Wi-Fi, but also to the cell called Femto, remote access router, DOCSIS, DSL and other intermediate network management devices from WWAN to Wi-Fi.
Figure 1 illustrates a wireless network architecture to provide a CDR record creation, aggregation, mediation and billing function, in accordance with some embodiments. As illustrated, Figure 1
<img file="MX336960B_D0043.tif" />
ÍMPí cu i Á'i, '-<sup>!AC</sup>DO NOT <sup>CE LA</sup>, w,<sup>t</sup>,?<sup>p, ED</sup>'' or industrial includes a 4G / 3G / 2G wireless network used by, for example, a central provider. As illustrated7 “^ Tc wireless devices 100 are in communication with base stations 125 for wireless network communication with the wireless network and other devices 100 are in communication with Mesh Wi-Fi access points (APs) 702 for communication Wireless to Wi-Fi access CPE 704 in communication with a central provider access network 109. In some embodiments, each of the wireless devices 100 includes a service processor 115 (as illustrated) and each service processor connects via a secure control plane link to a service controller 122. In some In embodiments, the network-based service utilization information (eg, CDRs), is obtained from one or more network elements. As illustrated, an MVNO base network 210 further includes a CDR storage, aggregation, mediation, billing device 118, an MVNO billing interface 122, and an MVNO 123 billing system (and other network elements according to indicated in Figure 1).
As illustrated in Figure 1, a CDR storage, aggregation, mediation, billing function 118 (eg, service utilization 118, which includes a billing aggregation data storage and rule engine) is a functional descriptor «« is"
<img file="MX336960B_D0044.tif" />
embodiments, a function of collecting eyaciwh? mediation and reporting of service utilization data at the device / network level and a reporting function located in one or more of the components of network management equipment incorporated in one or more of the subnets illustrated in Figure 1 (eg, central provider access network 109 and / or central provider home network 110), which is in communication with the service controller 122 and a central billing interface 127. As illustrated in Figure 1, service utilization 118 is shown as a function in communication with the central provider's home network 110. In some embodiments, the CDR storage, aggregation, mediation, and billing function 118 is located anywhere in the network or partially located anywhere or integrated with a part of other network elements. In other embodiments, CDR record storage, aggregation, mediation, billing functionality 118 is located or partially located in AAA server 121 and / or mobile wireless center / home location registration (HLR) 132 (as illustrated , in communication with a DNS / DHCP server 126). In some embodiments, service utilization functionality 118 is located, or partially located, at the base station, base station controller, and / or aggregator system.
<img file="MX336960B_D0045.tif" />
INOUi'TíJÁi.
base station, collectively referred to as base station
125 in Figure 1. In other embodiments, the CDR record storage, aggregation, mediation and billing functionality 118 is located, or partially located in a network management component in the central provider access network 109, a component management network in the home network 110, the central billing system 123, the central billing interface 127 and / or in another network function or component. This discussion on the possible locations for the service utilization information collection, aggregation, mediation and communication function (eg, CDR 118 record storage, aggregation, mediation and billing function) can easily be generalized as described here and as illustrated in the other Figures herein described by a person skilled in the art. In addition, as illustrated in Figure 1, the service controller 122 is in communication with the central billing interface 123 (also sometimes referred to as the external billing management interface or billing communication interface) 127, which is in communication with the central billing system 123. As illustrated, an order management 180 and a subscriber management 182 are also in communication with the central provider's home network 110 to facilitate order management and service subscribers for devices 100 ϊ Μ> ΐί 35 in accordance with some embodiments ......
ΠΧ5ΤυΊ; τ <ξί'Γ.:; '~ Λ5! Ο Í Ν Λ / ¿A. L
<img file="MX336960B_D0046.tif" />
In some embodiments, the CDR 118 record storage, aggregation, mediation and billing function (and / or other network elements or combinations of network elements) provides a function of collecting, aggregating, mediating and communicating information from utilization of the service at the device / network level. In some embodiments, the CDR 118 record storage, aggregation, mediation, and billing function (and / or other network elements or combinations of network elements) collects device-generated utilization information for one or more devices on the network. wireless (eg, devices 100) and provides the device-generated utilization information in a communication syntax and protocol that can be used by the wireless network to augment or replace the network-generated utilization information for the one or more devices on the wireless network . In some embodiments,! the syntax is a billing data record (CDR) and the communication protocol is selected from one or more of the following: 3GPP, 3GPP2, or other communication protocols. In some embodiments, the record storage, aggregation, mediation, and billing function CDR 118 (and / or other network elements or combinations of network elements) includes a rule engine and data storage of
<img file="MX336960B_D0047.tif" />
service utilization (eg, a billing aggregator) to aggregate collected device-generated utilization information. In other embodiments, the syntax is a billing data record (CDR) and the network device is a CDR billing aggregator and the CDR record storage, aggregation, mediation and billing function 118 (and / or other network elements or combinations of network elements) further adds CDRs records for the one or more devices in the wireless network; applies a set of rules to the aggregated CDR records using a rules engine (eg, billing by account, transactional billing and / or any other billing rules or other rules for the information gathering, aggregation, mediation and utilization communication function service) and communicates a new set of CDR records to the one or more devices on the wireless network for a billing interface or a billing system (eg, provide a CDR record with a billing offset per account / service). In some embodiments, the CDR record storage, aggregation, mediation, and billing function 118 (and / or other network elements or combinations of network elements) communicates a new set of CDRs for the one or more devices, in the wireless network, to a billing interface or a billing system. In some forms of
Instituto msxicano D £ LA PROPERTY INDUSTRIAL
<img file="MX336960B_D0048.tif" />
realization, the CDR 118 record store, aggregation, mediation and billing function (and / or other network elements or combinations of network elements) communicates with a service controller to collect device-generated utilization information for the one or more devices on the wireless network. In some embodiments, the CDR 118 record store, aggregation, mediation, and billing function (and / or other network elements or combinations of network elements) communicates with a service controller, where the service controller is in communication with a billing interface or a billing system. In other embodiments, the CDR 118 record storage, aggregation, mediation and billing function (and / or other network elements or combinations of network elements) communicates the usage information generated per device to a billing interface or a billing system. In some embodiments, the record store, aggregation, mediation, and billing function CDR 118 (and / or other network elements or combinations of network elements) communicates with a transport gateway and / or a network gateway of radio access (RAN) to collect network-generated utilization information for the one or more devices on the wireless network. In some embodiments, the service controller
<img file="MX336960B_D0049.tif" />
122 communicates the utility information generated by device, to the warehouse function ^ · ^ - aggregation, mediation and billing of CDR 118 record (and / or other network elements or combinations of network elements).
In other embodiments, the record storage, aggregation, mediation and billing function CDR 118 (and / or other network elements or combinations of network elements) realizes rules to perform an aggregation and mediation function of the type of billing by bill.
In other embodiments, the service controller 122 in communication with the CDR record store, aggregation, mediation, and billing function 118 (and / or other network elements or combinations of network elements) performs a rules engine to develop the aggregation and mediation functions of the usage information generated by device. In other embodiments, a rules engine device, in communication with the record store, aggregation, mediation, and billing function CDR 118 (and / or other network elements or combinations of network elements), realizes a record engine. rules for the aggregation and mediation functions of the utilization information generated by device.
In other embodiments, the rules engine is included in (eg, integrated with / part of) the storage, aggregation, mediation, and billing function of
<img file="MX336960B_D0050.tif" />
iMPÍ faith
INSTiTUTE A'L-T'JCAUO
FROM ¿A ¡Τ.ΟγΜΟΛΟ
INDUSTRIAL CDR register 118. In other embodiments, the rule engine and associated functions, as described herein, is a separate function / device. In some embodiments, the service controller 122 performs some or all of these rules engine-based functions, as described herein, and communicates with the central billing interface 127. In some embodiments, service controller 122 performs some or all of these rule engine-based functions, as described herein, and communicates with central billing system 123.
In some embodiments, duplicate CDR records are sent from the network equipment to the billing system 123 which is used to generate billing for services. In other embodiments, the duplicate CDRs are filtered to send only the CDRs / records for devices controlled by the service controller and / or service processor (eg, the managed devices). By way of example, this method may provide the same communication level, lower communication level, and / or higher communication level compared to the communication reports required by the central billing system 123.
In other embodiments, a bill-type billing offset per account is disclosed. TO
<img file="MX336960B_D0051.tif" />
By way of example, billing type billing offset information by account may be reported to central billing system 123 by providing a CDR aggregator feed aggregating device-based service usage data that was provided, to supply a new set of CDRs for the managed devices to the central billing interface 127 and / or the central billing system 123. In other embodiments, transaction billing using similar techniques is disclosed. By way of example, the transaction billing record information may be provided to the central billing interface 127 and / or the central billing system.
123.
In other embodiments, the rules engine (eg, performed by using service 118 or other network element, as described herein) provides billing type billing offset per account. By way of example, the device-generated usage information (eg, billing data records (CDRs)) includes a transaction type field (eg, indicating a service type for the associated service usage information). The rule engine can apply a rule, or a set of rules, based on the identified service associated with the utilization information
<img file="MX336960B_D0052.tif" />
generated per device, to determine an invoice type billing offset per account (eg, a new CDR record may be generated to provide the billing type billing offset per account). By way of examples, billing compensation of the type invoice by determined account can be provided as a credit to the user's service usage account (eg, a new CDR can be generated with a negative compensation to the user's service usage account). user, such as for use of private social network service or use of transactional service or for any other purposes based on one or more rules made by the rules engine).
By way of another example, for a transactional service, a first new CDR can be generated with a negative offset to the user's service utilization account for that transactional service-related utilization and a second new CDR can be generated with a value of positive service usage to bill that same service usage to the transactional service provider (eg, Amazon, eBay or other transactional service provider). In other embodiments, the service controller 122 generates these two new CDRs records and the service utilization function 118 stores, aggregates, and communicates these two new CDRs records to
<img file="MX336960B_D0053.tif" />
the central billing interface 127. In some embodiments, the service controller 122 generates these two new CDRs records and the service utilization function 118 stores, aggregates, and communicates these two new CDRs records to the central billing interface 127, wherein the central billing interface 127 applies rules (eg, performs the rules engine to determine the billing offset of the bill type per account).
In other embodiments, the service controller 122 sends the device-generated CDRs records to the rule engine (eg, service utilization 118) and the rule engine applies one or more rules, such as those described herein and / or any other rules related to the billing / use of the service, as would be evident to an expert in this matter. In other embodiments, the service controller 122 generates CDRs similar to other network elements, and the rules (eg, bill-by-account type) are performed at the central billing interface 127. By way of example, for service controller 122 to generate CDR records similar to other network elements, in some embodiments, service controller 122 is provisioned on the wireless network and behaves substantially similar to others. CDR record generators on the web as would be apparent to an expert in this
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0054.tif" />
technique.
In some embodiments, the service controller 122 is provided with a new type of network management function, which is recognized as a valid and secure source for CDR records by the other necessary elements in the network (eg, the server of aggregation and mediation of CDRs records / historical record of service use 118). In some embodiments, where the network appliance usually only recognizes CDRs records from some types of network management equipment (eg, RAN 410 network gateway or 420 transport gateway (as illustrated in Figure 3) ), then the service controller 122 may provide authentication credentials to the other network management equipment indicating whether it is one of the approved types of equipment (eg, for purposes of generating / providing CDRs records). In other embodiments, the link between the service controller 122 and the necessary CDR aggregation and mediation equipment is secured, authenticated, encrypted, and / or provided with signatures.
In other embodiments, the CDR record store, aggregate, mediate, and bill function 118 discards the network-based service utilization information (eg, network-based records CDRs) received from one or more network elements. In these forms of
<img file="MX336960B_D0055.tif" />
INSTITUTO MÍXICX.NO ΒΪ LA ['KO7IEDAD INBUSTfclAl.
<img file="MX336960B_D0056.tif" />
In embodiment, the service controller 122 may provide the usage information to the device-based service (eg, device-based records CDRs) to the CDR record storage, aggregation, mediation and billing function 118 (eg, the storage function, registration aggregation, mediation and billing CDR 118 can only provide storage, aggregation and communication functions) and the service utilization information, Device-based, it is provided to the central billing interface 127 or the central billing system 123.
In other embodiments, device-based records CDRs and / or new CDR records generated, based on the execution of a rule engine, as described herein, are disclosed only for devices that are managed and / or based on a device group, service plan or any other criteria, categorization and / or grouping.
Figure 2 illustrates another wireless network architecture for providing device-assisted CDR record creation, aggregation, mediation, and billing functionality in accordance with some embodiments of the invention. As illustrated in Figure 2, some devices 100 are in communication with the DOCSIS headend 125 and some devices 100 are in communication.
<img file="MX336960B_D0057.tif" />
MEXICAN INSTITUTE
D $ THE PROPERTY __ communication with DSLAM 125, which are in communication, in turn, with the access network to the central provider-iO ^; - "
Figure 3 illustrates another wireless network architecture for providing device-assisted CDR record creation, aggregation, mediation, and billing function according to some embodiments. Referring now to the 4G / 3G / 2G access network, as illustrated in Figure 3, the 4G / 3G and 3G / 2G base stations / nodes 125 are in communication with a radio access network gateway ( RAM) of the 4G / 3G / 2G type 410 through a radio access network 405, which is in communication with a 4G / 3G / 2G transport gateway 420 through an access transport network 415. Central provider home network 110 is in network communication with access transport network 415 (eg, via a leased / leased line and as illustrated, via a so-called 'firewall' 124). Internet network 120 is available via 'firewall' 124 and transport gateways 420, as illustrated. In addition, as illustrated, a network appliance provisioning system 160, order management 180, and subscriber management 182 are in communication with the central provider's home network 110. As illustrated, an AAA server 121, a mobile wireless center / home position record (HLR) 132, a DNS / DHCP 126 and a CDR record store, aggregation, mediation and billing function 118 are
<img file="MX336960B_D0058.tif" />
also in communication with the access transport network 415. The central billing system 123 and the central billing interface 127 are illustrated in communication with the central provider's home network 110.
As illustrated, Figure 3 includes a 4G / 3G / 2G wireless network used by, by way of example, a central provider. In some embodiments, each of the wireless devices 100 includes a service processor 115 (as illustrated) and each service processor connects via a secure control plane link to a service controller 122. In other embodiments, the network-based service utilization information (eg, CDRs records generated by the network) is obtained from radio access network (RAN) gateways 410 and / or transport gateways 420. In other embodiments, device-based service utilization information (eg, device-assisted CDR records) is generated by service processor 115 and / or service controller 122 for some or all of the wireless devices 100 using techniques. similar to those described herein and in other embodiments, said device-based service utilization information (eg, records CDRs assisted by device) is sent to the storage, aggregation, mediation and billing function of CDR record 118 (eg, the function of i
<img file="MX336960B_D0059.tif" />
'IM JC 1
INSTITUTO MEXICANO V * D £ LA PROPERTY industrial storage, aggregation, mediation- v registration billing CDR 118 can only provide storage, aggregation and communication functions) and / or the central billing interface 127 or the central billing system 5 123 according to was similarly described herein with respect to various embodiments.
Figure 4 illustrates the provision of a wireless network to provide the device-assisted CDR record creation, aggregation, mediation and billing function according to some embodiments of the invention. As illustrated in Figure 4, the provision of various network equipment, as illustrated, is disclosed to recognize each other as an authoritative source of CDR records (eg, this operation can be performed manually or in an automated manner). By way of example, order management 180, subscriber management, billing interface 127, billing system 123, network provisioning system 160, service controller 122, access network AAA server 121 , a mobile wireless center 132 and the CDR record store, aggregation, mediation and billing function 118 communicate with each other for such provision, which can be implemented using various techniques. In some embodiments, the various network elements are provided to recognize the device-assisted CDR records,
IMPIOUS
INSTITUTO MEXICANO that are generated by the service controller<sup>AND</sup>For example, billing 127 and / or billing system 123 may be provided. In other embodiments, the CDRs generated by the network are provided by access / RAN gateway 410, aggregation / transport gateway 425 and / or the base station controller 125. In some embodiments, other network elements generate / receive / store device-assisted CDR records.
In other embodiments, provisioning of various network equipment is disclosed to recognize a datum device as belonging to a group of devices, which supports a service utilization and / or billing function that is based on and / or utilizes records Device-assisted CDRs.
In some embodiments, CDR formats, transaction codes, and CDR record transmission destinations are programmed for each device that generates CDRs, including the service controller 122 (eg, in some embodiments, the CDR controller). services 122 is the broker for CDRs records) and / or service processor 115 (eg, in some embodiments, The device sends CDRs records to the CDR record aggregation or billing interface of the network 127 / billing system 123, without any function of
<img file="MX336960B_D0060.tif" />
I To PI
MEXICAN INSTITUTE. -. . ',. M THE FROFY MEETING SERVER). industrial
Figure 5 illustrates a network architecture for providing device-assisted registration CDRs in accordance with some embodiments. As illustrated, the CDR records generated by the network are sent from various network elements to the CDR record storage, aggregation, mediation, and billing function 118 and the service controller 122, as illustrated in dashed lines with arrows at Figure 5. In some embodiments, the network-generated CDRs are used for verification of device-assisted service (DAS) usage and / or billing information. In some embodiments, the network generated CDRs are provided to the service controller 122 and the service controller 122 performs the aggregation and / or mediation rules to examine and, in some cases, aggregate and / or perform the mediation. of network based / generated CDRs records with device based / assisted CDRs records.
In other embodiments, device-assisted CDR records are sent from service controller 122 to CDR record store, aggregate, mediate, and billing function 118 and are communicated to billing system 123, as indicated by solid lines. with arrows in Figure 5. In some forms of
<img file="MX336960B_D0061.tif" />
<img file="MX336960B_D0062.tif" />
<img file="MX336960B_D0063.tif" />
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL realization, storage, aggregation, mediation and billing function of CDR 118 record uses CDR records of use of DAS service to increase CDR records based / generated by the network with transaction codes of the type of billing by account (eg, as similarly described in this description). In other embodiments, the CDR record store, aggregation, mediation, and billing function 118 implements the aggregation and / or mediation rules to account for the amount of DAS CDR utilization in a new transaction code of the bill type per account and removes the same amount of service utilization from the high volume device account transaction code. In other embodiments, a first DAS CDR record is submitted for rebilling by the account transaction code and a second DAS CDR record is submitted to be used as a correction (credit) for the account usage account transaction code. main device and CDR record storage, aggregation, mediation and billing function 118 implements the rules to perform this mediation. In other embodiments, a first DAS CDR record is used for an invoice-per-account-type transaction code and a second DAS CDR record is used as the primary device account transaction code, where the Mexican iíí,<sup>0P, tDA</sup>E>
. . . 'NDUSTRIAl _ —w.
service controller 122 (or device) has already implemented the mediation rules, so that the CDR 118 record store, aggregation, mediation, and billing function simply transmits those DAS records
CDRs to billing after aggregation.
Figure 6 illustrates another network architecture for providing device-assisted record CDRs in accordance with some embodiments of the invention. Figure 6 further illustrates the communication of device-assisted records CDRs and network-generated CDR records using solid and dotted lines with arrows, respectively. As noted, in some embodiments, the record store, aggregation, mediation, and billing function CDR 118 sends records
Network-based CDRs to the service controller 122 for various purposes, such as those described herein above.
In some embodiments, the service controller 122 sends DAS CDRs to billing records for various uses by the billing system 123. In some embodiments, the billing system 123 uses the DAS service usage records CDRs to increase the Web-based CDR records with invoice-by-account transaction codes. In other embodiments, the billing system 123 implements aggregation and / or mediation rules to account for the
<img file="MX336960B_D0064.tif" />
MEXICAN INSTITUTE OF PROPERTY. ,,. ,. . ,,. INDUSTRIAL DAS CDR records usage amount in one invoice type transaction code per account and removes the same amount of service usage from the high volume device account transaction code. In other embodiments, a first DAS CDR record is submitted for re-billing using the account transaction code and a second DAS CDR record is submitted to be used as a correction (credit) for the usage accounts transaction code. host device and billing system 123 implements the rules to perform this mediation. In other embodiments, a first DAS CDR record is used for a given invoice-type transaction code and a second is used as the primary device account transaction code, where the service controller 122 (or device ) has already implemented the mediation rules, so that the billing system 123 simply transmits said DAS CDR record after its aggregation.
Figure 7 illustrates another network architecture for providing device-assisted record CDRs in accordance with some embodiments of the invention. Figure 7 further represents the communication of device-assisted CDRs records and network-generated CDRs records using solid and dotted lines with arrows,
<img file="MX336960B_D0065.tif" />
<img file="MX336960B_D0066.tif" />
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY respectively. Figure 7 is similar to Figure 6, with the exception illustrated in Figure 7, the service usage information is transmitted through the billing interface 127 instead of the billing CDR record aggregation interface. As an example, information such as invoice per detailed account of service usage and compensation (credit) information can be formatted as a CDR record or can be formatted in a higher level syntax as required. by the billing interface 127.
Figure 8 illustrates another network architecture for providing device-assisted record CDRs in accordance with some embodiments of the invention. Figure 8 further illustrates the communication of device-assisted records CDRs and network-generated CDR records using solid and dotted lines with arrows, respectively. In other embodiments, as illustrated in Figure 8, the central provider does not need to modify the existing CDR 118 record storage, aggregation, mediation and billing function, so the additional aggregation and mediation rules, previously described, with respect to Figure 5, they are implemented as a new rule layer in a new network function, illustrated as a 118A secondary DAS CDR record aggregation mediation, which is situated between the billing system and the CDR 118 record storage, aggregation, mediation and billing function. By way of example, this new network function (eg, secondary DAS CDR record aggregation mediation 118A) may reside in the network (as illustrated) or at the service processor 115, at the service controller 122, or anywhere else on the network or at the device.
Figure 9 is a functional diagram illustrating a device-based service processor 115 and a service controller 122 in accordance with some embodiments. By way of example, this discloses the relatively feature-rich device-based service processor implementation and the service controller implementation. As illustrated, this corresponds to a network management configuration where the service controller 122 is connected to the Internet network 120 and not directly to the access network 1610. As indicated, a data plane communication path (eg, service traffic plane) is represented in solid line connections and control plane communication paths (eg, service control plane) is illustrated in dashed line connections. As will be apparent, the division in functionality between one device agent and another is based on, by way of example, design choices, network management environments, devices and / or
MEXICAN INSTITUTE
<img file="MX336960B_D0067.tif" />
services / applications and various different combinations? They can be used in various implementations * -saidL.- As an example, the functional lines can be redrawn in whatever way the designers of 5 products deem appropriate. As illustrated, this includes some functional splits and breaks for device agents as an illustrative implementation, although other, potentially more complex, embodiments may include different functional splits and breaks for device agent functionality specifications. , as an example, to be able to manage the specification of the development and the complexity of tests and workflows. Furthermore, the placement of the agents that operate, interact with, or monitor the data path can be shifted or reordered in various embodiments.
By way of example, the functional elements depicted in Figure 9 are described below with reference to Figures 10 and 11.
As illustrated in Figure 9, the service processor 115 includes a service control device link 1691. By way of example, as device-based service control techniques become more sophisticated, involving the monitoring through a network, it becomes increasingly important to have an efficient and flexible control plane communication link,
<img file="MX336960B_D0068.tif" />
INSTITUTO MEXICANO DI LA PROPERTY,. . INDUSTRIAL between device agents and network elements communicate with, control, monitor or verify STT— service policy. In other embodiments, the service control device link 1691 provides the device side of a system for transmission and reception of service agent to / from network element functions. In some embodiments, the traffic efficiency of this link is improved by buffering and framing multiple agent messages in transmissions. In other embodiments, traffic efficiency is further improved by controlling the transmission frequency or by linking the transmission frequency with the service utilization or traffic utilization rate. In other embodiments, one or more levels of security or encryption are used to make the link resilient for discovery, eavesdroppping (eavesdropping), or compromise. In other embodiments, the service control device link 1691 further provides the communication link and active network verification signal timing for the agent's active network verification function. As described below, various embodiments disclosed herein for the 1691 service control device link provide an efficient and secure solution for transmitting and receiving.
INSTITUTO MEXICANO,, DELA PROPERTY <Λ · uiiaJíLiffi<sup>4</sup> policy implementation information<sup>, N</sup>of<sup>R1A</sup>ser ^ '55 arCf7 control, supervision and verification with. others- -eLemen.tos, -da.
net.
As illustrated in Figure 9, the service controller 122 includes a service control server link 1638. In other embodiments, device-based service control techniques that involve monitoring across a network (eg, at the control plane) are more sophisticated and therefore it is increasingly important to have a communication link. efficient and flexible control plane between device agents (eg, service processor 115) and network elements (eg, service controller 122) that communicate, control, monitor or verify service policy. By way of example, the communication link between the service control server link 1638 of the service controller 122 and the service control device link 1691 of the service processor 115 may provide a control plane communication link, efficient and flexible, a 1653 service control link as illustrated in Figure 9 and, in some embodiments, This control plane communication link provides a secure (eg, encrypted) communication link to provide secure two-way communications between the service processor 115
<img file="MX336960B_D0069.tif" />
INSTITUTO MEXICANO DE LA EROPICDAD and the controller of services 122. In some ^^ b:
<img file="MX336960B_D0070.tif" />
In one embodiment, the SglVlUldS coatevol server link 1638 provides the network side of a system for transmitting and receiving service agent functions to / from network elements. In some embodiments, the traffic efficiency of this link is improved by buffering and framing multiple agent messages in transmissions (eg, thereby reducing the value of the private social network). In some embodiments, traffic efficiency is further improved by controlling the transmission frequency and / or linking the transmission frequency with the service utilization rate or traffic utilization. In some embodiments, one or more levels of security and / or encryption are used to secure the link against possible discovery actions, eavesdropping (eavesdropping), or compromise of communications on the link. In other embodiments, the service control server link 1638 further provides the communication link and active network verification signal timing for the agent's active network verification function.
In other embodiments, the link of the service control server 1638 provides the functions of security, signatures, encryption and / or otherwise, protection of communications ant & ÉAKj
<img file="MX336960B_D0071.tif" />
such communications via the service control link 1653. By way of example, the service control server link 1638 may send to the transport layer or directly to the link layer for transmission. By way of another example, the service control server link 1638 further secures communications with transport layer encryption, such as TCP TLS SSH version 1 or 2 or another secure transport layer protocol. By way of another example, the service control server link 1638 may encrypt, at the link layer, such as using IPSEC, various possible VPN services, other forms of IP layer encryption, and / or another encryption technique. link layer.
As illustrated in Figure 9, the service controller 122 includes an access control integrity server 1654. In some embodiments, the access control integrity server 1654 collects information from the device about service policy, usage of the service, agent configuration and / or agent behavior. By way of example, the access control integrity server 1654 may cross-check this information to identify integrity breaches in the implementation of the control system and service policy. By way of another
<img file="MX336960B_D0072.tif" />
I example, the server integrity control<sub>s</sub>-4etEMa <^ g ^ s <sup>Dt</sup> Industrial '•' '' can initiate action when a violation of service policy or a breach of system integrity is suspected.
In some embodiments, the access control integrity server 1654 (and / or some other service controller agent 122) acts on the access control integrity agent 1654 on error reports and conditions. Numerous checks of the 1654 Access Control Integrity Agent can be performed by the server. As an example, the access control integrity agent 1654 checks one or more of the following: service utilization measure against a policy-consistent utilization margin (eg, utilization measure from the network and / or from the device); agent configuration; agent operation and / or dynamic agent download.
In other embodiments, access control integrity server 1654 (and / or some other service controller agent 122) verifies service policy implementations by comparing various service utilization measures (eg, based on information monitored by the network, such as using IPDRs or CDRs and / or monitoring information of the use of the local service) against the behavior in the
<img file="MX336960B_D0073.tif" />
í
INSTITUTO MEXICANO DE LA r «OH INDUSTRIAL AGE use of the service provided, taking into account the policies that are expected to be established. As an example, device service policy implementations may include measurement of total data transmitted, data transmitted over a period of time, IP addresses, data by IP address, and / or other measurements, such as location. , downloads, access by email, URLs and comparison of said measures provided for in the behavior of the use of the service, taking into account the policies that are planned to be established.
In some embodiments, the access control integrity server 1654 (and / or some other service controller agent 122) checks the device's service policy and conditions for verification errors that may indicate a mismatch in the service measure and service policy that include one or more of the following: unauthorized network access (eg, access beyond the limits of the environmental service policy); unauthorized network speed (eg, average speed higher than the service policy limit); amount of data on the network that does not match the policy limit (eg, device does not stop at the limit without revision / re-establishment of the service policy); unauthorized network address; unauthorized use of the service (eg, VOIP, email
<img file="MX336960B_D0074.tif" />
<img file="MX336960B_D0075.tif" />
(NítlTUTO MEXICANO BE LA PROPERTY electronic and / or web browsing); unauthorized application use (eg, electronic mail, VU'iP, ”email and / or web); service utilization rate too high for plan and policy controller not controlling / loosening it and / or any other mismatch in service policy and service measures. Accordingly, in some embodiments, access control integrity server 1654 (and / or some other service controller agent 122) continuously provides a service / policy control integrity service (eg, periodically and / or based on operational initiation events) verify that device service control has not been compromised and / or is not behaving outside of policy.
As indicated in Figure 9, the service controller 122 includes a service log server 1650. In some embodiments, the service log server 1650 collects and records service usage or service activity reports. from access network AAA server 1621 and service supervisor agent 1696. By way of example, although the historical record of service use, obtained from the network elements, may, in some embodiments, be less detailed than the historical record of services from the device, the historical record of
Á M r 1 Qgp
MEXICAN INSTITUTE
OF THE PROPERTY
INDUSTRIAL services from the network can provide a valuable source for verification of the implementation of the device services policy because, for example, it is very difficult for a device error or compromise operational event on the device to compromise the devices. functions of computer programs and network-based equipment. By way of example, the service history log reports, from the device, may include various service tracking information, as similarly described above. In some embodiments, service log server 1650 provides on-demand service log for other servers and / or one or more agents. In some embodiments, the service history log server 1650 provides the service usage history for the device service history record 1618. In some embodiments, for the purpose of facilitating the functions of the activity tracking service (described below), the service history log server 1650 maintains a history record of which networks the device has connected to. By way of example, this summary of network activities may include a summary of the networks to be accessed, relationships of activity with time per connection and / or traffic with time for connection. By way of another example, this activity summary may be further analyzed or reported to estimate the type of service plan associated with the traffic activity for the purpose of bill sharing reconciliation.
As illustrated in Figure 9, the service controller 122 includes a policy management server.
1652. In other embodiments, the policy management server 1652 transmits policies to the service processor 115 through the service control link.
1653. In some embodiments, the policy management server 1652 manages the policy settings on the device (eg, multiple policy settings as described herein with respect to various embodiments) in accordance with a device service profile. In some embodiments, the policy management server 1652 sets snapshot policies on policy enforcement agents (eg, policy enforcement agent 1690). By way of example, the policy management server 1652 can issue policy settings, monitor service utilization, and, if necessary, modify policy settings. As an example, in the case of a user who prefers that the network manage their costs of using the service or in the case of any need
<img file="MX336960B_D0076.tif" />
σιτυτο ηε INDUSTRIAL PROPERTY
<img file="MX336960B_D0077.tif" />
For adaptive policy management, the policy management server 1652 can maintain a relatively high frequency of communication with the device for collecting traffic and / or service measurements and for issuing new policy sets. By way of example, service metrics monitored by device and any change in user service policy preference is reported, periodically and / or based on various operational initiations / events / demands, to the policy management server 1652. As an example, user privacy settings often require secure communication with the network (eg, a 1653 secure service control link), such as with the 1652 policy management server, to ensure that various aspects of privacy are adequately maintained during such configuration / policy setting demands transmitted over the network. As an example, the information can be distributed in compartments for the management of the service policy and not communicated to other databases used for CRM in order to maintain the privacy of the user.
In other embodiments, the policy management server 1652 provides adaptive policy management on the device. As an example, the server
<img file="MX336960B_D0078.tif" />
Policy management 1652 may issue policy and goal setting and rely on device-based policy management (eg, service processor 115) for part or all of the policy adaptation. This method may require fewer interactions with the device, reducing the level of conversation between social network users on the 1653 service control link for device policy management purposes (eg, the level of conversation is reduced network in relation to various server / network-based policy management methods described above). This method may further provide user privacy embodiments by allowing the user to configure the device policy for user privacy preferences / settings so that, by way of example, no sensitive information is communicated (geolocation data, history website) to the network without the consent of the user. In some embodiments, the policy management server 1652 adjusts the service policy depending on the time of day. In other embodiments, the policy management server 1652 receives, requests, or otherwise obtains a measure of network availability and adjusts the traffic modeling policy and / or other policy settings based on the available network capacity.
<img file="MX336960B_D0079.tif" />
ΙΝ3Ί ITIJTO MEXICANO t'if LA PKCíiBJAD
INDUSTRIAL
<img file="MX336960B_D0080.tif" />
As indicated in Figure 9, the service controller 122 includes a network traffic analysis server 1656. In other embodiments, the network traffic analysis server 1656 collects / receives a historical record of usage of the device. service for devices and / or groups of devices and analyzes the use of the service. In other embodiments, network traffic analysis server 1656 displays service utilization statistics in various formats to identify improvements in network quality of service and / or cost effectiveness of the network.
<td>service. In</td><td>other forms</td><td>of</td><td>realization,</td><td>the</td><td>server</td><td>of</td>
<td>analysis of</td><td>traffic of the</td><td>net</td><td>1656 estimated</td><td>the</td><td>quality</td><td>of</td>
<td>service and / or</td><td>the utilization</td><td colspan="3">of the service for</td><td colspan="2">the net under</td>
<td colspan="2">variable establishments</td><td colspan="3">about the possible</td><td>politics</td><td>of</td>
<td>services. In</td><td>other forms</td><td>of</td><td>realization,</td><td>the</td><td>server</td><td>of</td>
<td>analysis of</td><td>traffic of</td><td>the</td><td>network 1656</td><td colspan="2">identifies</td><td>the</td>
actual or potential service behaviors by one or more devices that are causing problems for the overall network quality of service or cost of service.
As illustrated in Figure 9, the service controller 122 includes a beta test server 1658. In some embodiments, the beta test server 1658 publishes service plan policy establishments for one or more devices. In some embodiments, the beta 1658 test server provides
<img file="MX336960B_D0081.tif" />
INSTITUTO DELA summary reports of use of the service information on rebilling of nanart n — jww—. more candidate service plan policy establishments. In some embodiments, beta test server 1658 provides a mechanism for comparing beta test results for different candidate service plan policy establishments or select optimal candidates for optimization of additional policy establishments.
As depicted in Figure 9, the service controller 122 includes a service download control server 1660. In some embodiments, the service download control server 1660 provides a download function to install and / or update. elements of services software (eg, service processor 115 and / or service processor 115 agents / components) on the device, as described herein.
As illustrated in Figure 9, the service controller 122 includes a billing operational event server 1662. In some embodiments, the billing operational event server 1662 collects billing events, provides service plan information to the service processor 115, provides service utilization updates to service processor 115, serves as the interface between the device and the
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0082.tif" />
central billing server 1619 and / or provides a proven third-party function for some e-commerce billing operations.
As illustrated in Figure 9, the access network AAA server 1621 is in network communication with the access network 1610. In some embodiments, the access network AAA server 1621 provides the access network AAA services. necessary access (eg, authorization and access control functions for the device access layer) to allow devices, at the central provider, to access the network and the service provider's network. In some embodiments, another access control layer is required for the device in order to gain access to other networks, such as the Internet, a corporate network, and / or a machine-to-machine network. This additional access control layer can be implemented, for example, by the service processor 115 in the device. In some embodiments, the access network AAA server 1621 further provides the ability to suspend service for a device and resume service for a device based on communications received from the service controller 122. In other forms In implementation, the access network AAA server 1621 further provides the ability to direct routing for device traffic to a network.
Mexican INSTITUTE <sup>OF</sup> INDUSTRIAL PROPERTY
<img file="MX336960B_D0083.tif" />
quarantined or to restrict or limit network access when a device quarantine condition is requested. In some embodiments, access network AAA server 1621 further records and reports device network service utilization (eg, device network service utilization may be reported to the service history log of device 1618).
As illustrated in Figure 9, the service history record of device 1618 is in network communication with the access network 1610. In some embodiments, the device service history record 1618 provides a data record of device usage. service used for various purposes in various embodiments. In some embodiments, the service history record of device 1618 is used to assist in verifying the implementation of the service policy. In other embodiments, the device service history record 1618 is used to verify service monitoring. In other embodiments, the service history record of device 1618 is used to verify billing records and / or implementation of billing policies. In some embodiments, device service history record 1618 is used to synchronize _
<img file="MX336960B_D0084.tif" />
local service utilization controller, ...........- ........
As illustrated in Figure 9, central provider billing server 1619 is in network communication with access network 1610. In some embodiments, central provider billing server 1619 provides a mediation function for central provider billing events. By way of example, the central provider billing server 1619 may accept changes to service plans. In some embodiments, central provider billing server 1619 provides updates on device service utilization, service plan limits, and / or service policies. In other embodiments, central provider billing server 1619 collects billing operational events, formulates bills, bills service users, provides some billing event data and service plan information to service controller 122, and / or or to device 100.
As illustrated in Figure 9, in some embodiments, the control and selection of the 1811 modem selects the access network connection and is in communication with the so-called 'firewall' of the 1655 modem and the 1831, 1815 modem drivers, 1814, 1813, 1812 turn traffic
<img file="MX336960B_D0085.tif" />
PI
INSTITUTO MEXICANO CELA INDUSTRIAL PROPERTY data on modem bus traffic for one or more modems and they are in communication with the control and selection of Modems— 1811. In some embodiments, different profiles are selected depending on the network connection selected (eg, different policies / service profiles for WWAN, WLAN, WPAN, Ethernet and / or DSL network connections) are also referred to, in this case, as multimode profile establishment. As an example, service profile establishments may be based on the actual access network (eg, home DSL / work network or cable) behind the WiFi and not the fact that it is WiFi (or any other network , such as DSL / cable, satellite or Tl), which is considered different from accessing a Wi-Fi network in a shopping mall. As an example, in an instantaneous Wi-Fi situation where there is a significant number of users on a DSL or a Tl backhaul network, the service controller can be located in a service provider computing cloud or in a cloud by MVNO, the service controls being able to be provided by a VSP capability offered by the service provider or service controller that may be owned by the wireless access point service provider, called a hotspot used by the service controller, itself , without any association with an access network service provider. As an example, service processors can be
<img file="MX336960B_D0086.tif" />
<img file="MX336960B_D0087.tif" />
INSTITUTO MEXICANO Oí LA PROPERTY INDUSTRIAL control by the service controller to divide the bandwidth available in the hotspot based on the quality of service QoS or rules of shared use of users (eg, with some users having higher differential priority (potentially for higher service payments) than other users). As another example, environmental services (as similarly described here) can be provided for the hotspot for verified service processors.
In other embodiments, the service processor 115 and the service controller 122 are capable of assigning multiple service profiles associated with multiple service plans that the user chooses individually or in combination as a package. As an example, a device 100 starts with environmental services that include free transaction services where the user pays for the transactions or operational events instead of the basic service (eg, a news service, eReader, PND services, Internet session of the type called pay as you go) where each service is supported by an account capacity billing to correctly account for any subsidized partner billing to provide the transaction services (eg, Barnes and Noble can pay for the eReader service and offer a revenue share for the provider institutomex: cano
OF INDUSTRIAL PROPERTY>. 'Tar ^ jy of services for any transaction of books or magazines that are acquired from device 100). In some embodiments, the account billing service may additionally perform transaction log tracking and, in some embodiments, advertisements for the purpose of revenue sharing, all using the monitoring capabilities of the account. service disclosed here. After starting the services with the aforementioned free environmental service, the user can later choose a monthly post-paid Internet, email and SMS service. In this case, the service controller 122 would get from the billing system 123, in the case of network-based billing (or in some embodiments, the billing event server 1622 from the service controller 122 in the case of device-based billing), the billing plan code for the new Internet, email and SMS service. In some embodiments, this code is cross-referenced in a database (eg, Policy Management Server 1652) to find the appropriate service profile for the new service in combination with the initial environmental service. The new super-ensemble service profile is then applied so that the user maintains free access to the environmental services and partners of
MEXICAN INSTITUTE OF PROPERTY. z. z<sub>η</sub> . j -i. , INDUSTRIAL billing continue to subsidize such services.
<img file="MX336960B_D0088.tif" />
that the user also obtains access to the yeiViCflOS'-TRr Internet and can choose the service control profile (eg, from one of the embodiments disclosed here). The superset profile is the profile that provides the combined capabilities of two or more service profiles when the profiles are applied to the same device service processor 100. In some embodiments, device 100 (service processor 115) may determine the profile of the super-set instead of service controller 122 when more than one service (stackable) is selected by the user or otherwise applied to device. The flexibility of the service processor 115 and the embodiment of the service controller 122, described herein, allow a wide variety of service profiles to be defined and applied individually, or as a super-set, to achieve the service characteristics of the device. desired 100.
As illustrated in Figure 9, an agent communication bus 1630 represents a functional description for providing communication for the various agents of the service processor 115 and their functions. In some embodiments, as represented in the functional diagram illustrated in Figure 9, the bus architecture
<img file="MX336960B_D0089.tif" />
Mexican INSTITUTE CE THE PROPERTY is usually multipoint to multipoint type, so that ^^ 'ffcttí'qu agent can communicate with any o'OT<sup>1</sup> fast?
services controller or, in some cases, other device components, such as 1697 user interface and / or modem components. As described above, the architecture can also be of the point-to-point type for some agents or communication transactions or of the point-to-multipoint type within the agent's framework, so that all agent communications can be concentrated or secured or control or restrict as well as record or report. In other embodiments, the agent communication bus is secured, signed, encrypted, hidden, partitioned, and / or otherwise protected against unauthorized use or monitoring. In other embodiments, an application interface agent (not illustrated) is used to literally tag or virtually tag application layer traffic so that the 1690 policy enforcement agents have the necessary information to implement selected traffic modeling solutions. In some embodiments, an application interface agent (not illustrated) is in communication with various applications, including a TCP application 1604, an IP application 1605, and a voice application 1602.
"Tables
In other embodiments, service techniques?
Device Assisted (DAS) to provide a ^ map'nSe'— activity to classify or categorize service usage activities to associate various monitored activities (eg, by URL, by network domain, by website, by site web, by type of network traffic, by application or type of application and / or any other categorization / classification of service use activity) with associated IP addresses that are provided in this regard. In some embodiments, a policy control agent (not illustrated), a service supervisor agent 1696, or another agent or function (or some combination thereof) of service processor 115 provides a DAS activity map. In some embodiments, a policy control agent, service monitoring agent, or other service processor agent or function (or some combination thereof) provides an activity map to classify or categorize the use activities of the service processor. service to associate various monitored activities (e.g., by a uniform resource locator (URL), by network domain, by website, by type of network traffic, by application or type of application and / or any other classification / categorization of service use activity) with associated IP addresses. In some embodiments, an agent
IMPIMM
MEXICAN INSTITUTE -ir
OF THE PROPERTY £ · «-— * - ',. . INDUETKUL .VSq ~ 7¿t- ^ x policy control, a supervisory service agent, or other agent or function (or some combination of / from the "" "service processor determines the associated IP addresses for supervised service utilization activities using various techniques for unauthorized access to DNS demands (eg, performing such snooping techniques (unauthorized access) on device 100, being able to determine the associated IP addresses without the need for a network demand for reverse DNS lookup). In some embodiments, a policy control agent, service monitoring agent, or other agent or function (or some combination thereof) from the service processor records, records and reports IP addresses or includes a lookup function. DNS to communicate IP addresses or associated IP addresses and URLs for monitored service usage activity. By way of example, a policy enforcement agent, service monitoring agent, or other service processor agent or function (or some combination thereof) may determine associated IP addresses for monitored service utilization activities using various perform features. a DNS lookup function (eg, using a local DNS cache on monitored device 100). In some embodiments, one or more of these techniques is maintained, in a · way ™ *<sup>1</sup>
<img file="MX336960B_D0090.tif" />
establishes, the ~ «xuu ^ S Trend, to IP addresses, applications to content to IP addresses and / or used to build and map of DAS activity which, for example, from URLs to IP addresses, types of any other distribution in categories / classification for IP addresses where applicable. In some embodiments, the DAS activity map is used for various DAS traffic control and / or restriction techniques, as described herein with respect to various embodiments. In some embodiments, the DAS activity map is used to provide the user with various information and notification techniques related to Ul as well as related to the use of the service as described herein with respect to various embodiments. In some embodiments, the DAS activity map is used to provide service utilization monitoring, prediction / estimation functions with respect to future service utilization, service utilization billing (eg, bill by account and / or any other classification technique in categories of billing / service use), DAS techniques for monitoring the use of environmental services, DAS techniques to generate micro-CDRs (eg, Also referred to as a service use partition, service use record partition, billing basket of
<img file="MX336960B_D0091.tif" />
INSTITUTO MEXICANO DS LA PROPERTY services, records CDRs generated by disposiTW ^ tStSS as in the case that the device and not — a tuiiiyüi'itífUje 'fler the network is generating the records of use, records of environmental use specialized service utilization logs or other terms to indicate a service utilization data record generated to provide a more refined detailed breakdown of service utilization for the device) and / or any of the various other DAS-related techniques, as per It is described here with respect to various embodiments.
In other embodiments, all or part of the functions of the service processor 115 disclosed herein are implemented in computer programs. In some embodiments, all or part of the functions of the service processor 115 are implemented in hardware. In other embodiments, all or nearly all of the functionality of the service processor 115, as described herein, is implemented and stored in computer programs that can be performed on (eg, run by) various components on the device. 100. In some embodiments, it is desirable to memorize or implement some or all of the service processor 115 in a protected or secure memory, so that other unwanted programs (and / or unauthorized users) have
IMPI institute ι · 'μ' '·:<sup>λ</sup>: 'ο UE LA i'f'O.-U ·
<img file="MX336960B_D0092.tif" />
INDUSTRIAL «a» Pz »difficulties in accessing the functions or computer programs in the service processor 115. In other embodiments, the service processor 115, at least in part, is implemented in, and / or memorized in, secure non-volatile memory (eg, non-volatile memory can be secure non-volatile memory) that is not accessible without passwords and / or other security mechanisms. In some embodiments, the ability to load at least a portion of the service processor 115 computer programs into a protected non-volatile memory also requires a secure key and / or signature and / or requires that the components of the service processor's computer programs service processor 115, that are being loaded into non-volatile memory are also encrypted for security and with appropriate signatures by * a verified authority or a secure software download function, such as a 1663 service downloader as illustrated in Figure
16. In some embodiments, a secure software download also uses secure non-volatile memory. Those skilled in the art will also appreciate that all memory can be on-board, off-board, on-board, and / or off-board.
Figure 10 provides a table summarizing various functional elements of the service processor 115 in accordance with some embodiments of the
<img file="MX336960B_D0093.tif" />
. ,, INSTITUTO MEXICANO, \ Χ ~ “invention. Most of these agents form similar to what was done previously and the table illustrated in Figure 10 is not intended to be an exhaustive summary of these agents, nor an exhaustive description of all the functions that the agents perform or are described herein, rather, Figure 10 is provided as an aid to the summary in the knowledge of the basic functions of each agent according to some embodiments and how the agents interact with each other, with service controller server elements and / or with other network functions, in some embodiments, to form a reliable device-based service delivery platform and / or solution.
Figure 11 provides a table summarizing various functional elements of the service controller 122 in accordance with some embodiments. Much of these agents / elements were described previously in a similar way and the table illustrated in Figure 11 is not intended to be an exhaustive summary of these server elements, nor is it an exhaustive description of all the functions that the elements perform or here are described, but Figure 11 provides, rather, as an aid to the summary in the knowledge of the basic functions of each element in accordance with some embodiments of the invention and how the
- i lM.Pi
ÍN'STlTfjT.
From the r<sub>(</sub> -. <sub>?</sub> .J elements to each other, some network elements and / or the '<sup>1</sup> agen! of the service processor, in some embodiments, to form a reliable device-based service delivery platform and / or solution.
Figure 12 illustrates a device stack that provides various service utilization metrics from various points in the network management stack for a service supervisor agent, billing agent, and access control integrity agent to assist in verification of service utilization measurements and billing reports in accordance with some embodiments of the invention. As illustrated in Figure 12, multiple service agents take part in data path operations to achieve various data path enhancements and, as an example, various other service agents can manage the policy settings for the data path. data path service, implement billing for data path service, manage one or more establishments and selection of modem to access the network connection, interface with the user and / or provide verification of the implementation of the service policy. Additionally, in some embodiments, multiple agents perform functions to assist in verifying that the
<img file="MX336960B_D0094.tif" />
INSTITUTO MEXICANO DS LA PROPERTY policies for supervision or control of services <sup>N</sup>^ Wis to establish, that they are adequately rcZJpÜLdllaa luu service control or supervision policies, that the service processor or one or more service agents are functioning properly, to prevent unforeseen errors in the implementation of the policies or control and / or to prevent the improper use of the service or control policies. As noted, the service measurement points, labeled I through VI inclusive, represent various measurement points for the service supervisor agent 1696 and / or other agents to perform various service supervision activities. Each of these measurement points can serve a useful purpose for the various embodiments described herein. As an example, each of the traffic measurement points, which is used in a given design, can be used by a supervisory agent to track application layer traffic through the communication stack to provide assistance. to policy enforcement functions, such as the 1690 policy enforcement agent or in some embodiments, the 1655 modem 'firewall' agent or the application interface agent, in making a determination regarding traffic parameters or type once the traffic is beyond the communication stack, where it is sometimes difficult or impossible
<img file="MX336960B_D0095.tif" />
complete determination of parameters
<img file="MX336960B_D0096.tif" />
Particular location for the measurement points, provided in these Figures, is provided by way of instructive example and other measurement points may be used for different embodiments, as will be apparent to a person skilled in the art considering the embodiments described herein. . In general, in some embodiments, one or more measurement points may be used, within the device, to assist in verifying service control and / or locating device or service anomalies.
In some embodiments, the service supervisor agent and / or other agents implement virtual traffic tagging by tracking packet flows through the various stages of formatting, processing, and encrypting the communication stack and providing the virtual tagging information to the various agents that monitor, control, model, restrict or otherwise observe, manipulate or modify the traffic. This method of tagging is referred to here as virtual tagging, since there is no literal data stream, traffic stream, or packet tag that is incorporated into the streams or packets and the accounting record keeping for tagging
<img file="MX336960B_D0097.tif" />
INSTITUTE .ΜΓ.Χ! · -Α; ιο
DE LA Pr.O?, 'SDAD the package is made by tracking the fl'ttg®<sup>11</sup>'© pack through the stack, instead. Enalg ^ ffiee — íacuás. In implementation, the application interface and / or other agents identify a traffic flow, associate it with a service utilization activity and cause a literal tag to be incorporated into the traffic or packets associated with the activity. This method of tagging is referred to here as literal tagging. There are several advantages to the virtual tagging and literal tagging methods. By way of example, it may be preferable, in some embodiments, to reduce the interagency communication required to track a packet through stack processing by assigning a literal tag so that each stream or packet has its own association of 15 activities incorporated into the data. By way of another example, it may be preferable, in some embodiments, to reuse parts of the components or computer programs from the standard communication stack, enhancing the verifiable traffic control or service control capabilities of the standard stack by inserting additional processing steps associated with the various service agents and monitoring points other than full stack rewriting to correctly process the literal tagging information and In such cases, a virtual labeling system may be desirable. Like another Mexican institute. , „. π -,. . ,,, 6f U PROPERTY example, some standard communication stacks p3? © jp © # c
<img file="MX336960B_D0098.tif" />
unused, unspecified bit fields 'or' otherwise available in a packet stream or frame and these unused, unspecified or otherwise available bit fields can be used for literal labeling traffic without the need to rewrite all the software in the standard communication stack, with only the parts of the stack being added to extend the verifiable traffic control or service control capabilities of the standard stack that you need to decode and use the literal labeling information encapsulated in the available bit fields. In the case of literal tagging, in some embodiments, the tags are removed prior to passing the packets or streams to the network or to applications using the stack. In some embodiments, the manner in which literal or virtual tagging is implemented can be developed into a standard communication specification, so that multiple device or service product developers can independently develop the communication stack and / or hardware and / or software of the service processor in a manner that is compatible with the specifications of the service controller and the products of other device or service product developers.
<img file="MX336960B_D0099.tif" />
It will be appreciated that although the implementation / use of any or all of the CW puift illustrated in Figure 12 is not required to have effective implementation, as was similarly shown with respect to various embodiments described herein, various embodiments can benefit from these and / or similar measurement points. Likewise, it will be appreciated that the exact measurement points can be moved to different places in the traffic processing stack, just as the various embodiments described herein may have the agents that affect the implementation of the policy moved to. different points in the traffic processing stack, while still maintaining effective operation. In some embodiments, one or more measurement points are provided deeper in the modem stack where, by way of example, it is more difficult to bypass and may be more difficult to access for tampering purposes, if the modem is designed with adequate software and / or hardware security to protect the integrity of the modem stack and measurement points.
Referring to Figure 12, describing the device communication stack from the bottom to the top of the stack, as shown, the device communication stack provides a communication layer for each of the device's modems in i Ivíi P} (s-ssíte.,.
the bottom of the device communication stack YES<sup>L</sup>Useful The VI measuring point, as an example emp 1 o. da.níu..u — or immediately above the modem driver layer. By way of example, the modem controller performs modem bus communications, data protocol conversions, modem control, and configuration for interface of network management stack traffic to the modem. As illustrated, measurement point VI is common to all modem controllers and to the modems themselves and it is desirable, for some embodiments, to differentiate traffic or service activity that occurs through a modem from that of one or more of the other modems. In some embodiments, the VI measurement point, or other measurement point, is located above, within, or below one or more of the individual modem controllers. The respective modem buses, for each modem, reside between measurement points V and VI, by way of example. In the next higher layer, a modem selection and control layer for multimode device-based communication is provided in this regard. In some embodiments, this layer is controlled by a network decision policy that selects the most suitable network modem for part or all of the data traffic and when the most desirable network is not available, the policy reverts to the next most desirable network until
<img file="MX336960B_D0100.tif" />
available. In some embodiments.). some network hacking, such as check, control, redundant, or secure traffic, is routed to one of the networks even when some or all of the data traffic is routed to another network.
This dual routing capability provides a diversity of enhanced security, enhanced reliability, or correspondingly enhanced manageability devices, services, or applications. At the next higher layer, a so-called modem 'firewall' is provided. As an example, the modem 'firewall' provides traditional 'firewall' functions, but unlike traditional verifiable 'firewall' 'firewalls' to control such control
<td>with</td><td>the end of</td>
<td>of</td><td>utilization</td>
<td>of</td><td>access and</td>
relying on the security protection service regarding applications or unwanted network management traffic, the various techniques and service verification agents, described here, are added to the 'firewall' function to verify compliance with the security policy. services and prevent misuse of service controls. In other embodiments, the modem 'firewall' is implemented further up the stack, possibly in combination with other layers as indicated in other Figures. In other embodiments, a layer or function of
IMPIOS Mexican institute dedicated 'firewall' that is independent of the processing layers, such as the frog, .. de. new in practice of the policy, the packet forwarding layer and / or the application layer. In some embodiments, the modem 'firewall' is implemented further down the stack, such as within modem drivers, below modem drivers, or on the modem itself. Measurement point VI, for example, resides between the modem 'firewall' and an IP routing and queuing layer. As illustrated, an IP routing and queuing layer is separate from the policy implementation layer, where the policy implementation agent performs a portion of the usage control policy. service and / or traffic control. As described here, in some embodiments, these functions are separated so that a standard network stack function can be used for IP routing and queuing, and the modifications necessary to implement the IP functions. Policy implementation agent can be provided in a new layer inserted into the standard stack. In some embodiments, the IP routing and queuing layer is combined with the traffic or service utilization control layer. A • · ·> & α. · Α.
Κ, 4'Γ
V
MEXICAN INSTITUTE of Property,,. , r- J,. . χ, INBUStRlAI.
By way of example, one embodiment of the policy and routing implementation layer 'cl can also be used with the other embodiments, as illustrated in Figure 12. Measurement point III resides between the implementation layer queuing and IP routing and a policy enforcement agent layer. Measurement point II resides between the policy enforcement agent layer and the transport layer, including TCP, UDP, and other IP as illustrated. The session layer resides above the transport layer, which is shown as a socket mapping and session management (eg, basic TCP establishment, TLS / SSL). The network services API (eg, HTTP, HTTPS, FTP (File Transfer Protocol), SMTP (Simple Mail Transfer Protocol), POP3, DNS) resides above the session layer. Measurement point I resides between the network services API layer and an application layer, which is represented as an application service interface agent in the communication stack of the device of Figure 12.
As illustrated in Figure 12, the application service interface layer is on top of the standard network management stack API, and in some embodiments, its role is to monitor and in some cases intercept and process traffic between applications and
<img file="MX336960B_D0101.tif" />
ΐΝέτιτυτοMszvaiÍS t> EM. PRCrífp /. '? V'i-lF'jS'j'®}
Standard networking stack API. In al ^ CffifSS ^ foüfiSi ^^ realization, the interface layer of c rrv ί<sup>7</sup>^ **** ^ ui rl i oa identifies application traffic that flows before application traffic flows that are more difficult or virtually impossible to further identify downstream on the stack. In some embodiments, the application service interface layer thus assists in the tagging of the application layer in the cases of virtual and literal tagging. For upstream traffic, application layer tagging is straightforward, since the traffic originates from the application layer. In some downstream embodiments, where the classification of traffic or service activity is based on attributes of the traffic that are easily obtainable such as source address or URL, application connector address, IP destination address, time of day or any other easily obtainable parameter, the type of traffic can be identified and tagged for processing by the 'firewall' agent or another agent when it initially arrives. In other embodiments, as described herein, in the case of downstream flow, the solution is usually more sophisticated when a traffic parameter that is needed to classify how the flow of traffic is to be controlled, or restricted, not easily
<img file="MX336960B_D0102.tif" />
available at the lower levels of the stack, such as association with an application aspect, content type, something contained within TLS line rates, IPSEC or other secure format, or other information associated with traffic. Consequently, in some embodiments, the networking stack identifies the flow of traffic before it is fully characterized, categorized, or associated with a service activity, and then passes the traffic through the interface layer. application, where the final classification is concluded. In such embodiments, the application interface layer then communicates the traffic flow identifier ID with the appropriate classification, so that after an initial short burst of traffic or a specified period of time, the commissioning agents policy practice can adequately control traffic. In some embodiments, there is also a policy to tag and set the control policy for services for traffic, which cannot be completely identified with all tagging sources, including application layer tagging.
As illustrated in Figure 12, a service supervisor agent, who is also in communication with agent communication bus 1630, communicates with various layers of the device communication stack. As an example,
<img file="MX336960B_D0103.tif" />
INSTITUTO MEXICANO D £ LA PS ') HEL / .¡)
INDüSrRJAL the service supervising agent performs supervision at each of the measurement points and I to VI inclusive, receiving information that includes application information, service use and other information related to the service and assignment information. An access control integrity agent is in communication with the service supervisor agent via agent communication bus 1630, as also noted.
Figure 13 illustrates an embodiment similar to Figure 12 where part of the service processor is implemented in the modem and part of the service processor is implemented in the device application processor in accordance with some forms of realization. In other embodiments, a part of the service processor is implemented in the modem (eg, in the modem ICs or modem module hardware) and a part of the service processor is implemented in the modem. device application processor subsystem. It will be apparent to one skilled in this art that variations can be made to the embodiment illustrated in Figure 13, where more or less of the functionality of the service processor is shifted to the modem subsystem or the application processor subsystem of devices. By way of example, said embodiments, similar to those
<img file="MX336960B_D0104.tif" />
illustrated in Figure 13, may be motivated by the advantages of including some or all of the processing of the network communication stack of the service processor and / or part or all of the other functions of the service agent in the subsystem of the modem (eg, and said method being applicable to one or more modems). By way of example, the service processor may be distributed as a standard feature set contained in a modem IC hardware of the software package or of the modem module software or hardware package and such configuration may be provided for ease of use. adoption or development of OEM equipment for devices, a higher level of differentiation for the integrated circuitry or modem module manufacturer, highest levels of performance or implementation of control of the use of the service in its integrity or security, specification or interoperability in a standardized way and / or other advantages.
Referring to Figure 13, which depicts the device communication stack, from the bottom to the top of the stack, as illustrated, the device communication stack provides a communication layer for the MAC / PHY layer of the device. modem at the bottom of the device communication stack. Measurement point IV resides above the MAC / PHY layer of the
V?
.Ι-L JS '<sup>l</sup>·. ·. A v
<img file="MX336960B_D0105.tif" />
tHOTITTEE
CE LA ': ···) of the modem resides among the next highest layer, implementation of the modem. The 'firewall' layer measurement points IV and III. In the policy agent is provided, where the policy enforcement agent is performed on the modem (eg, on the modem hardware). Measurement point II resides between the policy enforcement agent and the modem driver layer, illustrated below under a modem bus layer. The next highest layer is represented as the IP routing and queuing layer, followed by the transport layer, including TCP, UDP, and other IP as illustrated. The session layer resides above the transport layer, which is shown as a session management and socket allocation layer (eg, basic TCP establishment, TLS / SSL). The network services API (eg, HTTP, HTTPS, FTP (File Transfer Protocol), SMTP (Simple Mail Transfer Protocol), POP3, DNS) resides above the transmission layer. Measurement point I resides between the network services API layer and an application layer, illustrated as an application service interface agent in the device communication stack depicted in Figure 13.
Figure 14 illustrates various embodiments of intermediate networking devices that include a
<img file="MX336960B_D0106.tif" />
INSTÍTUT '?) 3 service processor for the purpose <sup>D</sup>verifiable service use, report generation and billing reports in accordance with some embodiments of the invention. By way of example, Figures 14 (A) to 14 (E) inclusive illustrate various extended modem alternatives for access network connection through an intermediate modem or combination of networking devices that have one connection (eg , LAN network connection) to one or more 100 devices.
In some embodiments, device 100 includes a 3G and / or 4G network access connection in combination with the Wi-Fi LAN connection to device 100. By way of example, the intermediate device or combination of connection devices The network can be a device that simply converts the Wi-Fi data to the WWAN access network without implementing any part of the service processor 115 as illustrated in Figure 14 (A). In other embodiments, an intermediate device or networking device combination includes a more sophisticated implementation comprising a networking stack and some processor embodiments, as is the case, by way of For example, if the intermediate networking device or combination of networking devices includes a router function, in which case the service processor 115 is
IMPI
<img file="MX336960B_D0107.tif" />
INSTITUTO MEXICANO can implement, in part or in its intermediate modem or in the combination of ña-network connection devices. The combination of networking devices or intermediate modem can also be a multi-user device where more than one user gains access to the 3G or 4G access network through the Wi-Fi LAN connection. In the case of such a multi-user network, the access network connection may include several managed services links using multiple operational instances of the service processor 115, each operational instance having, by way of example, its implementation in all or partly on the device 100 with the combination of networking devices or intermediate modem providing only the conversion services from the Wi-Fi LAN to the WWAN access network.
Referring now to Figures 14 (B) - (D), in some embodiments, the service processors 115 are implemented in part or in whole in the combination of intermediate modem or networking devices. In the case where the service processor 115 is implemented in part or all of the combination of networking devices or intermediate modem, the service processor 115 can be implemented for each device or each user in network so that there are multiple managed provider accounts
100
<img file="MX336960B_D0108.tif" />
of services that all get access through the same combination of networking devices or intermediate modem. In some embodiments, the functions of the service processor 115 are implemented in an aggregated account that includes the WWAN access network traffic for all users or devices connected to the Wi-Fi LAN served by the combination of networking devices or mezzanine modem. In some embodiment, the central provider may also supply an aggregated account service plan, such as a family plan, a corporate user group plan, and / or a wireless network access point plan, so-called hotspots, instantaneous. In the event that there is a single account for the mix of networking devices or intermediate modem, the combination of networking devices or intermediate modem can implement a local division of services for one or more devices 100 o users where the services are controlled or managed by the combination of networking devices or the intermediate modem or device 100, but the management is not subject to the control of the service provider and is auxiliary to the implementation of the service policy or service management carried out by the service processors 115. In some forms of
101
PT
Instituto m .-; - tcai; o Di LA ΡΛΟΓΙΕΒ / .ϋ
INDUSTRIAL
<img file="MX336960B_D0109.tif" />
In realization, another service model may also be supported in which there is an aggregated service provider plan, associated with a combination of intermediate modem or networking devices or a group of modem or networking device combinations. intermediate, but where each user or device still maintains its own service plan which is a sub-plan under the aggregate plan, so that each user or device has an independent service policy implementation with a single operational incorporation of the service processor 115 instead of the aggregated service policy implementation across multiple users in the group with a unique operational embodiment of the service processor 115.
As illustrated in Figure 14 (B), in some embodiments, device 100 includes a Wi-Fi modem, a Wi-Fi modem combined with a WWAN, 3G and / or 4G modem, in a Intermediate Modem or Networking Device Combination 1510 and Intermediate Modem or Networking Device Combination forwards WWAN access network traffic to and from device 100 over the Wi-Fi link. By way of example, the service processor 115 can be implemented, in its entirety, on the device 100 and the service provider account can be exclusively associated with a
IMPÍO institute ma / Ta:: o V<sup>:</sup>>
Ü2 THE PF, TILTY V
INDUSTRY »· & 'device. Similarly, as depicted in the
102
<img file="MX336960B_D0110.tif" />
Figure 14 (C), such implementation can be provided using a different access modem and access network, such as a DSL, 2G and / or 3GPP WWAN wired line, DOCSIS cable wired line or a wired line configuration of fibers instead of the 3G and / or 4G access network connection to the combination of networking devices or intermediate modem 1510. In addition, various other embodiments similarly utilize DSL as illustrated in Figure 14 (D), USB, Ethernet, Bluetooth, or other LAN or a point-to-point connection from device 100 to the combination of networking or networking devices. 1510 mezzanine modem or a Femto cell modem and DSL / cable / TL / other combination as illustrated in Figure 14 (E).
Figure 15 illustrates a wireless network architecture to provide device-assisted CDR record creation, aggregation, mediation, and billing functions, including proxy servers 270 according to some embodiments. As illustrated, Figure 2 includes a proxy server 270 in communication with a 4G / 3G / 2G wireless network used by, by way of example, a central provider. By way of example, proxy servers 270 can be used to implement and / or assist in providing various techniques described herein, such as service utilization management and / or other techniques herein.
IMPIAS
Λ
103 iNsn also described.
industrial
In some embodiments, you can<sup>i</sup>* HÓ it will be possible to exactly identify each attempt to access network services or use of the service (eg, or access to traffic) as belonging to a given service use partition (eg, a given environmental service use, a use of a basic private social network, a use of the user's service plan, use of the emergency service and / or another type of use of the service). As used herein, the terms of service use partition, service use record partition, service billing basket, and micro-CDRs are used interchangeably. Accordingly, it is desirable to provide a so-called service billing basket for the traffic, which is allowed and not definitively identified as belonging to a known service billing basket. This allows techniques such as a so-called allow but verify method to be employed for traffic that is likely to be legitimately associated with an environmental service or a user service or a network service that is intended to be permitted, but is not definitely identified as being associated with a permitted service.
As an example, there may be a website access associated with an environmental service that does not have a
104
IMPI YY5
Bís-nvirro ι /. 'ΤΊτ.'. '.' Η
LL LA JAJ / · / .. I,;,
INiUSTíJAL ^ 47. ^<sup>1</sup>..
reference identifier or other traffic parameter, allowing the service processor to associate it with the correct environmental service. In this case, a set of rules can be applied to determine if it is probable that access to the website is legitimate access, taking into account the access control policies that are established and if the access can be allowed and the use of the traffic registered in the billing basket of the environmental service, which is suspected to be associated with, or the use of the traffic can be billed to a basket of use of the service of a private social network or the use of the traffic can be billed to the basket of use of the service of the user or the use of the traffic can be registered in a basket of billing of the service classified but allowed. In some embodiments, where such traffic is billed to the unclassified but allowed service usage billing basket, additional verification measures are used to ensure that the amount of traffic that is not classified but allowed is not make it too big or become a so-called 'back door' for service utilization errors. As an example, the rules of the access control policy, to allow unclassified traffic, may be relatively lax as long as the amount of billing charges of the institute tra<sub>t</sub> -,,, '¿fif utilization of the service, which accumulate erf ^' l'auPóesfesí ^^ unclassified billing, remain within do ρί / »· <·? Ρ105 limits and / or the rate of use of the service billed in the The unclassified basket remains within certain limits, but if the unclassified traffic becomes large or the growth rate of the unclassified traffic becomes large, then the rules governing when to allow the unclassified traffic can be tightened.
By way of another example, a browser application can access a website that is known to be an environmental service website and that the website could again serve a number of traffic flows, some of which are associated with the environmental service website via URL identifiers, that are known as being part of the website and other traffic may be associated with the environmental service website by virtue of a referring website header or tag and some traffic may be returned to the same application in close proximity, to the other traffic than environmental. In this form, for example, as the basket of non-preset traffic faster
<td colspan="4">in time, relatively</td>
<td>I know</td><td>identifies</td><td>What</td><td>traffic</td>
<td>of</td><td>realization</td><td>, to</td><td>mode of</td>
<td>of</td><td>billing</td><td>of</td><td>service</td>
classified does not exceed a policy limit on its magnitude and / or does not develop with a given pre-established policy rate
106
IMOpAA instí 's'. ·.'
Ós HA t'í.Or? l · · '\ ¿p ·
IHDUiiklAÍ. -Ο-Χί— and / or received within a certain preset policy time period different from the time other environmental service billing basket traffic is received, then the unclassified traffic is still allowed. However, if the magnitude of the unclassified traffic or the growth rate exceeds the pre-established policy limits or if the period of time between when it is verified that an environmental service traffic is received and that the unclassified traffic that is received exceeds the policy limits, in which case the unclassified traffic may be blocked or another action can be taken to analyze the unclassified traffic as well.
In other embodiments, it is important to disclose a hierarchy of service utilization billing rules for the various service utilization partitions on a device. By way of example, for a given service plan, there may be two environmental service billing baskets, one private social network service billing basket (eg, or general network load) and a billing basket of services from the user's service plan and it is convenient to make sure that no environmental services or general network load services or unclassified services are charged in the billing for the service plan of the user and it is also advisable to make sure that the totality of the traffic of
107
IMPK
<img file="MX336960B_D0111.tif" />
iNSTnvfO κκΐΤΛϊα BE U PíA ':: £' Pí known environmental service is billed to ± appropriate environmental service partner and it is desirable that no general network load service or any unclassified service is billed to environmental service partners. In such situations, a service billing basket hierarchy can be provided as follows: determine if a traffic flow (eg, or network connector) is associated with the overall network load and if so, allow it and bill that basket of services and then, 10 determine if a traffic flow (or network connector ) is associated with environmental service number 1 and if so, allow it and bill the basket of services, then determining if a traffic flow (or network connector) is associated with environmental service n<sup>to</sup> 2 and if so, 15 allow it and bill that basket of services, then determining if a traffic flow (or network connector) is associated with unclassified traffic and if so, allow it and bill that basket of services , and then if the traffic is not associated with any of the above service billing baskets, allow it and bill it to the billing basket of the user's service plan. By way of another example, if the user has not yet decided to pay for a user's service plan then the same hierarchical access control and service billing policy can be used with the exception that step
108
<img file="MX336960B_D0112.tif" />
<img file="MX336960B_D0113.tif" />
INSTITUTO MEXICANO DE LA PROí'íEUAD INDUSTRIAL final would be: if the traffic is not associated with any of the above service billing baskets, block the traffic. Identifying the hierarchical service billing basket, as illustrated in these examples, can be a crucial aspect of a robust access control policy and / or a proper service billing policy system. Numerous other access control policy hierarchies and service billing basket policy hierarchies will now be apparent to one of ordinary skill in this art.
In other embodiments, unclassified traffic is billed based on billing rules for the service that are based on the billing basket of the service likely to be the most candidate for the traffic. By way of another example, if the unclassified traffic is being provided to the same application as other known environmental service traffic and the time difference between the provision of the known environmental service traffic and the unclassified traffic is small, then , unclassified traffic can be billed for environmental service in accordance with a pre-established billing policy rule that specifies these conditions. Other embodiments that will now be apparent to one of ordinary skill in this art, by way of example another billing rule for unclassified traffic
109
IMPIí
INSTITUTE ΜΜ1 ~ Λ ·, '·? Θ
OE ΙΑFRONLu '/ tD, ... _ could be done with apportionment assignment <sup>, r</sup>Q £ l<sup>WAI</sup>traffic not classified to the totality of the other threeTaS '”” ^! service billing with the pro rata assignment being based on the percentage of the total traffic used by the device for each service billing basket. As another example, unclassified traffic may be billed to a subset of the service billing baskets for the device (eg, all environmental services plus general network load service) in accordance with the quota, on a pro-rata basis. for each service included in the pro rata division.
In other embodiments, the user's service plan agreement is structured so that the user confirms that the environmental services where the connection to access the service is sponsored, paid for and / or partially subsidized by an entity, other than the user. , are a benefit for the user and / or the user confirms that there is no inherent right to free environmental services and that the accounting system for the use of the service may not always adequately characterize the use for a sponsored or subsidized environmental service (eg , or some other specialized service) in the billing basket of services with correct accounting and therefore, the user's service plan account can be charged and / or
110 τΜ, ΡΪ 0S3
INSTITUTE;··..: ; γό '. -J bill with part of this traffic. At tenéTMjéMu.frsaa ^ ioknowledge of an agreement of ηΐ-ΐ i ί d ^ i ^. · ΡΓϊ. <? · Ίη this way, then, some environmental traffic can be billed to the account of the user's service plan including, as For example, the allowed but not classified traffic, the use of the environmental service surpluses beyond pre-established policy limits, use of the environmental service during periods of busy network or in congested network resources and / or other criteria / measures. In some embodiments, the user could be notified that service activities are being billed that are sometimes subsidized or free to the user. As described above, it is important to ensure that an unclassified service billing basket does not become the operationally called 'back door' for service billing errors or hacking intrusion. It will now be apparent to one of ordinary skill in this art that unclassified service usage billing loads can be verified in a variety of ways including, by way of example, observing the magnitude of the unclassified service billing basket in comparison to other device service utilization billing loads (e.g., total device service utilization, service utilization
111
<img file="MX336960B_D0114.tif" />
iNS-iTUTóy: xy-.j7 environmental, use of the service 'fteirMoes user billing and / or rri records rpj-jn.g / mgñ-ídag.)., gnn establish an upper limit for the unclassified billing basket and / or for the growth rate of the unclassified basket.
In some embodiments, it is important to verify not only that the total device service utilization amount is correct, but that the service utilization is being reported in the appropriate service billing baskets. As an example, if the service processor software may be subject to operational intrusion, so that it correctly reports the total service utilization, but reports the user's service plan traffic under one or more service billing baskets then simply verifying that the total magnitude of service utilization is correct, it will not be sufficient to prevent the device from obtaining a free user service that can be billed to environmental service partners. There is a variety of direct and indirect ways of carrying out this verification of the divisions of the service billing basket. By way of example, in direct verification embodiments, one or more alternate service utilization measures are used to cross-check the accuracy of splits.
112
MWCANO INSTITUTE <sub>(</sub> ) service billing baskets. In indirect forms, one of two verification classes are used: the .... The magnitude and the credit rate for the service billing baskets is analyzed and compared with a pre-established group of policies to detect and / or modify the growth of the service billing basket that is outside the policy and / or the proper operation of the elements of the service processor involved in the realization of the partition of the service billing basket.
Various embodiments that involve direct verification of the utilization of the service billing basket and / or its accounting includes the use of network-based service utilization measures, such as CDRs, IPDRs, flow data records (eg, FDRs-detailed reports of service utilization for each service flow, such as the so-called network connector, open and used to transmit data to or from the device), accounting records, interim accounting records, or other similar usage records to verify device is within service policy and / or device-based service utilization reports are accurate. The use of said records of use of the service generated by the network to directly verify
113
IMPW
Mexican Institute 'r adherence to the use policy <sup>D £</sup>Proper service and / or billing of the service are described in the present invention. When the destination network address and / or source information is available in these records, as described herein, this operational circumstance can be used in some embodiments to verify the accounting of the billing basket of the service provided by the device's service processor. In some embodiments, some types of service usage logs include real-time data, but not necessarily all of the useful information needed to aid in the verification of the billing basket accounting for the service, whereas other types of service usage logs provide more detail (eg, IP address for destination and source) but do not always arrive in real time. By way of example, in some embodiments, FDRs are created each time a new service flow (eg, network connector) is opened and then closed. At the moment the service flow is closed, a data usage record (eg possibly with timestamps) indicating the source address, the destination address, and the amount of data transmitted, is created and sent to a function of billing aggregation in the network. The billing aggregation function can then forward
114 service controller for
<img file="MX336960B_D0115.tif" />
direct posting of the service billing basket. By comparing the FDR addresses with the known environmental service traffic address associations, the operation of partitioning the utility billing baskets between one or more environmental services and other services such as a plan service billing basket can be verified. user services. However, in some cases, a long period of time can be generated for an FDR report when a device service flow (eg, the network connector) remains open for a long period of time, as is the case, by way of For example, a long file download, a peer connection with a network connector that remains active, or a proxy server service with a connector that remains active. In such cases, it can be inconvenient to have large amounts of data to be transferred without an FDR to confirm the reports based on the device's service processor and in some cases, this can provide an opportunity for intrusions into the service reports of the device. service processor. This situation can be remedied in a variety of ways by using other service utilization information reported by the network to augment the network information.
<img file="MX336960B_D0116.tif" />
115
FDR. By way of example, they can, at times, be obtained jecjísancos. accounting of the type 'start and stop.M ^^, some embodiments, from a network element, such as a service gateway or AAA servers (eg, or other elements of network equipment depending on the architecture of the network). Although the records of the type 'start and stop' do not have the detail of the information of the use of the service that have the reports FDRs, CDRs, IPDRs, interim accounting reports or other records of use of the service, they inform the controller of services of that a device is connected to the network or has dropped its connection. If a device is connected to the network and is not transmitting service utilization reports or active network verification signals, then the services controller is warned that an operational intrusion, hacking, or error condition is likely. As another example of how two or more types of service utilization information communicated by the network can be used to create a better real-time or near-real-time check on device service utilization, if both FDRs and logs 'start / stop' type accounting are available, the service controller can send a service command of type 'interrupt then resume' for the device (eg, or, alternatively, send íM.PIí3¡ »
116
INSTITUTE νίζ <sup>ϋε</sup> ^ '' iNDIJÍtP<sup>0</sup> a service command of the type 'interrupt and then terminate an item of network equipment), which will cause ^ T ^ ctTSPOCit i vo to terminate all open service flows before restarting them and once the service flows are interrupted, then the FDR flow records will be completed and transmitted for any service flows that were in progress, but not reported when the service interruption order was issued. This will cause any long-term open network connector file transfers to be reported in the FDR flow logs, thus establishing a potential for a so-called 'back door' hole in the posting verification method. of the use of the service.
By way of another example, it is illustrated how multiple types of network generated service usage accounting records can be used to complement each other and strengthen verification of service billing basket accounting partitions, interim data records that can be used with FDRs. Interim data records are available in accordance with some embodiments of the invention, where interim data records are generated, on a periodically scheduled basis, by a network element (eg, gateway, base station, HLR, AAA me
117 . MEXICAN VSTITUTp<sub>F</sub>r, DELAfilOPltOAl) <sub>v</sub> , Other function / network element). Registries<sup>11</sup>'’<sup>1</sup>· Provisional deM ^ & atos are usually near-real-time logs - '- real - reporting aggregate traffic utilization for the device at a point in time, but do not typically include traffic direction information or other traffic details. . In some embodiments, where interim posting records and FDRs are available, when interim posting records are indicating service usage that is not being reported in the FDR record flow, this is evidence that a device has one or more long-term network connectors and are not in the process of being terminated. In this case, the service controller can verify that the device-based utilization reports are properly accounting for the total amount of service utilization reported by the interim accounting records and / or the service controller can force an FDR report to open network connectors by issuing an 'interrupt then resume' service command in the manner described above.
As described herein, other embodiments may be disclosed that involve direct verification of the accounting of service billing baskets. An exemplary embodiment consists of routing the environmental service traffic to a
118
ΪΜΡΙ. · ^ 'ΠΤΟΤΟ MEXICAN ¡·!' Ι Α NUtlJTRIAL PXOflITy
<img file="MX336960B_D0117.tif" />
proxy server or router programmed to — qnnnrtart only allowed network access for environmental service and to account for environmental service utilization. Additional routers or proxy servers can be similarly programmed for each environmental service that is part of the device service plan, and in some embodiments, another router or proxy server is programmed to support traffic control and account for access to the service of the device. user service plan. By comparing the accounting of service usage for each of these routers or proxy servers, the accounting of service billing baskets, generated by device, can be verified directly. In other embodiments, the usage accounting, provided by the routers or proxies, is used directly for service usage accounting.
In some embodiments, the environmental service partner rebilling is used to verify the accounting of the service billing basket. By way of example, web servers used by environmental service partners to provide such environmental services may identify a user device based on information from
IMPI
119
Mexican Institute of Industrial Property
<img file="MX336960B_D0118.tif" />
header embedded in HTML traffic—. then, to count the service used by the device during the sessions of environmental services or to count the number of transactions that the user completes. If service utilization is logged, then it can be communicated to the service controller and used directly to verify the environmental services billing basket posting. If the transactions are all recorded, then this operational circumstance can be reported to the utility controller and the magnitude of the environmental service used by the device can be compared with the number of transactions performed to determine whether the environmental service utilization is reasonable or it must be restricted or blocked. It will now be apparent to a person skilled in this art that other embodiments may be disclosed that use more than one type of network-generated service utilization records to verify service utilization accounting and / or verify the accounting of the service billing basket.
Other embodiments, which involve indirect methods to verify or control the accounting of the billing basket of the service, include monitoring the magnitude and / or growth rate of the use of the service.
120
<img file="MX336960B_D0119.tif" />
«Λ. .¿Κ
Mexican INSTITUTE OF ΙΑ INDUSTRIAL PROPERTY
<img file="MX336960B_D0120.tif" />
environmental service. In some embodiments, the access control policy rules demanded to restrict an access to the given environmental service, when the amount of charges for the use of the service, which accumulate in the billing basket of the environmental service, exceeds a pre-established policy limit and / or when the service utilization rate, for the environmental service, exceeds a pre-established policy limit. By way of example, once these limits are reached, the environmental service can be restricted again for a period of time, blocked for a period of time, or charged to the billing basket of the user's service plan. In some embodiments, before these actions are taken, the user's Ul can be used to notify the user of the action of the function of its service policy. In other embodiments, indirect verification of the service billing basket accounting includes the various techniques described herein to verify proper operation of the service processor agent software and / or protection of the service processor agent software. service processor against errors, manipulation or operational intrusion.
In other embodiments, the device's service processor directs destined traffic, to
121
- «· η
INSTITUTE ΜΓΚΙΓΜΙΟ ϊ> ^ «. HERE
D £ LA ΓΗΙΗ'ιΕίΙ Λυ \ -, teeS INDUST ITlAL a given environmental service, to a router or proxy server programmed to support that environmental service and any traffic control policies and / or access control policies, for the environmental service , are implemented in the router or proxy server. By way of example, in such embodiments, the router or proxy server can be programmed to only allow access to one or more environmental services that are authorized by the device's service plan, with the router or proxy server controlling access. to the device so that other destinations on the network cannot be reached. Continuing with this embodiment, by way of example, the router or proxy server may account for the environmental service usage in an environmental service billing basket as described elsewhere. In such embodiments of environmental service control with the router or proxy server, the same traffic association techniques, described elsewhere, that allow inbound traffic to be associated with an environmental service website or other service to be identified , allowed or blocked, potentially restricted and posted to a service billing basket, they can be implemented in router or proxy server programming. Said embodiments with the router or the
122
<img file="MX336960B_D0121.tif" />
IVIPI ¡TITUTO Mf.J (ΟλΝΟ
OS THE PkOAWAD iNÜL'STiUAL proxy server can implement, in addition, the service billing baskets of the user's service plan, the traffic controls of the user's service plan and the access control of the user's service plan according to described here. In some embodiments, the router or proxy server parses the HTML traffic content of the traffic streams, as described herein, to perform such associations, traffic control, and / or service usage accounting. Similarly, in some embodiments, a router or proxy server may provide the so-called surf-out capabilities described here by performing the same surf-out traffic associations (eg, HTML derivation reference associations and / or other lead associations) described here. It will now be apparent to one of ordinary skill in this art that most of the adaptive environmental service control and service utilization billing functions described herein for a service processor can be easily implemented with a router or proxy server. that it is properly programmed.
In other embodiments, the routing of the device traffic for one or more environmental services and / or services of the user's service plan, for a router or proxy server, is performed by
123 <sup>r</sup> ίϊ, ___________ <sup>, NST</sup>™ TO MECANO,. · <- —- or the device service processor uses the device service traffic control embodiments described here. In other embodiments, the routing of the device traffic for one or more environmental services and / or services of the user's service plan, for a router or proxy server, is carried out by dedicated network equipment such as gateways (eg , SGSN, GGSN, PDSN or PDN), internal agents, HLRs or base stations, with the network equipment being provided by a service controller (eg, or other interchangeable network element with similar functions for this purpose) to direct device traffic to the router or proxy server. In some embodiments, the environmental service traffic or the user service plan traffic is controlled by the proxy server in accordance with an established service plan policy that is supplied by the service controller (eg, or a function equivalent network for this purpose). The traffic control service policy, thus implemented by the proxy server, can control traffic based on one or more of the following: time period, network address, type of service, content type, type application, QoS class of service, time of day, network occupancy status, bandwidth and data utilization.
s * i «5t7aeeKrxissBrr..T
124
<img file="MX336960B_D0122.tif" />
INSTITUTE ?
FROM ΙΛ I-
<img file="MX336960B_D0123.tif" />
In other embodiments, • a erííSáftíiuiaddaP ^ Mí<sup>5 </sup>proxy server is used to verify -ia · r; enfrafeá-li □ aion of a given service, for example an environmental service. In other embodiments, this operation is performed by the device's service processor directing the desired service flows to a router or proxy server programmed to manage the desired service flows, with the router or proxy server being programmed to only allow access to valid network destinations allowed by the access control policies for the desired service and also the router or proxy server being programmed to account for the use of the traffic for the desired services. In some embodiments, the proxy service utilization accounting may be used to verify the device-based service utilization accounting that is communicated by the service processor. In other embodiments, the accounting thus reported by the router or proxy server can be used directly to account for service utilization, such as environmental service utilization or service utilization from the user's service plan.
In other embodiments, where a proxy server is used for accounting for the usage of the
125
ΎΓ Τ \ Γ? · 7 ”\>: ί t ι t:
ΟΙ
<img file="MX336960B_D0124.tif" />
device service, the proxy server maintains a link to the device service notification UI via a secure communication link, such as the active network verification signal device link, described herein. As an example, the router or proxy server may keep a record of the device's service utilization against the upper limits / utilization limits of the service plan and notify the user's device UI via the communication link. device (eg, link of active network verification signals) between the services controller and the device. In some embodiments, the router / proxy server communicates with a device UI in a variety of ways, such as the following:
UI connection via device link (eg active network verification signal link), via device link connected to a service controller (eg, or other network element with similar function for this purpose ), presenting a proxy web page to the device, providing a scrollable page to the device and / or installing a special mini-portal browser on the device that communicates with the router / proxy server. In some embodiments, the UI connection to the router / proxy server is used as a notification channel for the user to communicate
126 utilization notification information, service plan choices, or any of the multiple service UI embodiments described herein.
In other embodiments for router / proxy server techniques to implement access / traffic controls of the service and / or accounting of the service billing basket, it is desirable to have the same information as for the service processor on the device including, by way of example, an application associated with traffic, network occupancy status, level of quality of service QoS or other information about the activity of the service that is available on the device. By way of example, such information can be used to help determine traffic control rules and / or the special service credit owed (eg, environmental services credit). In some embodiments, the information available about the device can be communicated to the router / proxy server and associated with traffic flows or service utilization activities in a variety of ways. By way of example, secondary information can be transmitted to the router / proxy server that associates a traffic flow or service activity flow with the information available about the device, but not readily available in the traffic flow or service activity flow.
127
<img file="MX336960B_D0125.tif" />
service itself. In some embodiments, such secondary information may be communicated over a dedicated control channel (eg, the device control link or active network verification signal link) or over a standard network connection which, in some embodiments, it can be secure (eg, TLS / SSL or a secure tunnel). In some embodiments, the secondary information available on the device can be communicated to the router / proxy server through information embedded in the data (eg, special padding and / or header fields in communications packets). In some embodiments, the secondary information available on the device can be communicated to the router / proxy server by associating a given secure link or tunnel with said information. In some embodiments, secondary information is collected from a device agent or device API agent that monitors traffic flows, collects secondary information for said traffic flow, and transmits the information associated with a given flow to a router / proxy server. It will now be apparent to one of ordinary skill in this art that other techniques can be used to communicate available secondary information about the device to a router / proxy server.
As an example, only the hierarchy of billing rules may be important for commissioning.
128 • y'r
INSTITUTE ΗΓ · 'of the: α · ε.
Ii ^ vgj i i'c.iL practice in which the service processor is creating the billing basket accounting for the service, which may also be important in the implementation that uses a router or proxy server for the basket accounting billing service. Accordingly, various embodiments described herein for creating a hierarchy of service utilization billing rules can be applied to proxy server or proxy router embodiments. It will be apparent to one skilled in the art that the service billing basket embodiments and the access control and traffic control embodiments described herein for permitted but unclassified billing baskets apply equally to the router / proxy server embodiments. By way of example, predefined service policy rules can be programmed into the router / proxy server to control traffic flows and / or set usage limits or access limits on an environmental service or a service plan service of the Username. It will now be apparent to one of ordinary skill in this art that the embodiments described herein, which disclose an initial permitted service access list, which temporarily allow additional service activities until it is determined that they are permitted or not
129
ΜΡϊΓ -¾
¡. INSTITUTE V
DELA íao? L ;; r. „£ 5 t,; . 1NÜÜ> TR-.L __ allowed, the expansion of the list * of permitted service activities, the maintenance 'of a ΓίβΈεΓ of non-permitted service activities and the expansion of the list of non-permitted service activities also apply equally to the router / proxy server embodiments. Similarly, it will now be apparent to one of ordinary skill in this art that the router / proxy server embodiments can be used to directly generate the service billing basket utilization reports (or micro-CDRs) used to provide more details and / or billing capabilities for the use of the service. In some embodiments, where the device's service processor directs traffic to a router / proxy server, there are embodiments with advantageous design features available, which can reduce the need for provision of a network to detect and force specialized device service traffic to the appropriate router / proxy server. By way of example, this operation can be performed by creating a usage credit system for the services supported by the router / proxy server. Total service utilization is accounted for, on the one hand, by the device's service processor or by other network equipment or by both at the same time. Credit, on the other hand, for the use of
[MPI r Ρ:
130
<img file="MX336960B_D0126.tif" />
INSTITUTE Í. ': V--<sup>J</sup>
OF THE rivú'VF ;.
ΙΝίιΙτ, ϊλϋΧ environmental service or other use of the specialized access service, which is not billed to the user, is then provided for services that the device directs through the destinations of the router / proxy server (eg, URL or route jump) that it supports the particular environmental service or other specialized access service. If the device correctly directs traffic to the router / proxy server, then the accounting and / or access rules are correctly enforced by the router / proxy server. In this way, the service can be controlled and / or accounted for. When the service is posted, the router / proxy server reports the posting of the service billing basket back to the service controller (eg, or other network team responsible for the service billing basket / micro-CDR mediation ) and the account of the billing basket of the service of the service plan of the user can be object of credit for the services. The traffic reaching the router / proxy server is controlled by the access rules and / or traffic control rules and / or QoS control rules of the router / proxy server scheduling, so that there is no no question regarding the type of service that is supported with the service billing baskets, which are reported for mediation functions (eg, mediation functions can
131
<img file="MX336960B_D0127.tif" />
If / ÓUE'J'iííAj.
be done by one or more of the controller services, mediation of use, billing7 ™ servi'aSS<sup>r</sup>*<sup>TO</sup>~ ^ * AAA and / or internal agent / HLR). When the router / proxy server is on the network and can be physically secured and protected against operational intrusion, there is high confidence that the service control and / or billing rules envisaged for environmental services or some other specialized service are properly implemented and that the router / proxy server connection is being used for the envisaged service and not some another service subject to unforeseen operational intrusion. If the device is in any way subject to operational intrusion or otherwise in error, so that traffic is not directed through the proper walker / proxy server, then the router / proxy server does not record the traffic in microCDRs / billing baskets and no specialized service utilization credits are sent to the mediation functions so there is no utilization credit deducted 20 from the service utilization totals of the device user service plan. In this way, the user pays for the services when the device is subject to operational intrusion to bypass the router / proxy server. The user account service agreement may specify that if the user performs a manipulation
-¾ - .i / »·» · »
<img file="MX336960B_D0128.tif" />
132
<img file="MX336960B_D0129.tif" />
with the software and traffic is not routed to the servers, then no credit will be provided and the user's plan will be billed.
In other router / proxy server embodiments, the usage credit is sometimes logged by the router / proxy server detecting which device is accessing. Device identification can be done in a variety of ways, including a header / tag inserted into the traffic by the device, a route on the network, specified for this device, a secure link (eg, TSL / SSL, IP Sec or other secure tunnel), a unique device IP address or other credential (eg, where the router / proxy server has access to an active IP address lookup feature), a router / proxy server address and / or network connector for the device.
In some embodiments, coordinating the device's service controller traffic control elements with a router / proxy server can make it easier to locate, install, provision, and use proxy servers. The routers / proxies do not need to be located in line with the access network, because it is the responsibility of the device to make sure that the traffic is routed to the servers / routers or elsewhere without any credit and loaded into the network.
133
<img file="MX336960B_D0130.tif" />
billing of the user's account. In some embodiments, this makes it unnecessary or reduces the need to route device traffic on the carrier's network. In some embodiments, the routers / proxy servers may be located on the operator's network or on the Internet. If the routers / proxies are on the Internet, then the traffic can be authenticated against a so-called 'firewall' before being passed to the routers / servers to improve security against a malicious attack.
In other embodiments, the service billing basket registration software on the router / proxy server can be programmed directly into an EOS partner network computer, eliminating the need for appliances. specials. The environmental service partner team (eg, a web server, load balancer or router) can recognize the device using one of the techniques described above, aggregate the billing basket accounting for the device service, and periodically send the utilization accounting to the service controller or other network service utilization mediation function.
The programming and / or provision of the types of environmental services, services of the user's service plan
134
<img file="MX336960B_D0131.tif" />
and / or specialized services, disclosed in various embodiments described herein, can be a complex process. In some embodiments, a simplified user programming interface, also referred to herein as a service design interface, is used to program the necessary policy settings for those services, which is operationally desirable. By way of example, a service design interface is disclosed that organizes and / or categorizes the various policy establishments that are required to establish an environmental service (eg, or other service) including one or more of the following : a list of policies of service activities that are allowed under the environmental service (eg, or other service), access control policies, rules to implement and / or adapt an allowed list of network destinations, rules to implement in practice and / or adapt a blocked list of network destinations, service billing basket policies, user notification policies, service control and / or verification policies for service billing baskets as well as the actions to be taken to verify errors. In some embodiments, the information required for one or more of these established policies is formatted in an Ul that organizes and simplifies the programming of the policies. In other forms of
135
<img file="MX336960B_D0132.tif" />
In realization, the Ul is partially graphical to help the user understand the information and what policy settings need to be defined in order to define the service. In other embodiments, the UI is created with an XML interface. In some embodiments, the UI is offered over a secure web connection. In some embodiments, a basic service policy is created for an environmental service (eg, or other service) that includes one or more of the above service policy establishments, and then this established service policy is converted to a list or an object that can be replicated and used in multiple multiple service plan policy setting definitions (eg, the so-called drag and drop operation in a graphical UI interface). In some embodiments, the resulting set of policies created, in this service design interface, are then distributed to the necessary policy control elements, in the network and / or in the device, which act in coordination to put into practice the service policy set for a given device group. As an example, if a service processor is used in conjunction with a service controller, then the service design interface can load the service policy setting subsets they need
136
* .'- Η Κ- * '. «Jl J¡l ..a.
INSTITUTE ί. · -.:;- ·.<sub>?</sub>.; ο V> -ü-rc = 3> <H
I'ü L. \ <
to go;.
be programmed into the service controller and the device service processor into the service controller and the service controller loads the policy setting subset of the service controller into the service controller components that control policies and loads the subset of setting device policies on devices that belong to that device group. In some embodiments where a proxy server / router is used to help control and account for services, the service design interface loads the service policy setting subsets that need to be programmed into the proxy server / router. In other embodiments where other network equipment (eg, gateways, base stations, registration / aggregation / billing of the equipment use of the service, AAA servers, internal agent / HLR, mediation system and / or billing system ) need to be provisioned or scheduled, the service design interface also loads the appropriate device group policy subsets for each piece of equipment. Consequently, several techniques, as described here, can be used to greatly simplify the complex task of converting a service policy set, or service plan, into the
137
<img file="MX336960B_D0133.tif" />
all of the multiple establishments of devices and / or equipment, programming and / or provisioning orders that are required to correctly implement the service. It will now be apparent to one of ordinary skill in this art that several of these techniques can be similarly used for the VSP service design interface.
Those skilled in the art will appreciate that various other rules can be provided for the rule engine as described herein. Also, such experts will appreciate that the functions described herein can be implemented using various other network architectures and network implementations (eg, using various other network management protocols and corresponding network equipment and techniques).
In device-assisted services (DAS) systems, end-user device agents can assist the network in implementing or enforcing related policies. As an example, device agents can assist the network, in maintaining records, in allocating costs when end-user devices access data services over an access network, in enforcing policies. access control or service limits for the device, the enforcement of usage limits or assistance in notification policies for information
138 í to xvji .y,, n. he
ÍItéT! TU7C · μ ·) ί? ' yes
DE LA FROI'ÍE:. · - i industrial '· —i ~<sup>!</sup> '' regarding the network access services, which are in communication with the end user of the device. If a device is configured with a device agent configured to assist the network in enforcing or enforcing policies, there may be a device part of a network policy running on the device and a network part of an access network services policy, which is enforced by network elements in the network. In some access networks, network-based systems are used to implement the network portion of the access network services policy, such as, by way of example, to manage the authentication process of allowing a device in a network or to determine one or more network policies that must be enforced by network elements such as access control policy, service use limits, billing policy or accounting for the use of the service or notification policy for the use of the service.
To achieve an overall network service policy, the network part of the access network service policy can be configured to work in conjunction with the device-based part of the access network service policy to achieve a global combined network services policy. If the device agents, required to implement the device part of the
the network services policy
139
<img file="MX336960B_D0134.tif" />
present on the device or are not properly configured, in which case the overall combined network services policy may be in error or may not be achievable, potentially as a consequence of an implementation of the network services policy not desired. In such cases, it is desirable that a network system be used to detect this condition and modify the network part of an access network services policy, executed by the network-based elements, so that a execution of the desired network services policy.
In some embodiments, a device agent that can assist the network in executing or enforcing the policy may be referred to as a device policy enforcement agent which, in some embodiments, may be part of the service processor.
Exemplary embodiments of when it may be desirable to adapt the network portion of an access network services policy in order to take into account an absence or presence of an improperly configured service processor includes, but is not limited to limitation: (i) a device credential has been moved to a device that does not have a service processor, (ii) a
140
<img file="MX336960B_D0135.tif" />
device credential has been moved to a device with a service processor with a different configuration than the service processor originally associated with the device credential, (iii) a device service processor has been misused or exhibits a improper configuration.
In other embodiments, the service processor is used to assist in classifying service usage into subcategories for the purpose of executing the usage accounting policy, executing the access control policy, limits. of use of the service or execution of the notification policy that differs according to the category. In some embodiments, the rating can be for one or more applications of the device. In other embodiments, the classification may be for one or more destinations on the network. In other embodiments, the classification can be for one or more network types. In some embodiments, a service utilization classification (referred to herein as a sponsored service or an environmental service) may be performed to facilitate the allocation of access network costs, in whole or in part, associated with the environmental service or sponsored to a service sponsor, the service sponsor being an entity other than the
141
<img file="MX336960B_D0136.tif" />
device user.
y tít ........—— nm i -
What is needed is a networking system that detects the presence and proper configuration of a service processor, or its absence, in the end-user device, where the service processor, if present, runs a part of the device. of an access network services policy on a device configured with a device credential and, if the service processor is present and properly configured, that causes a first network part of an access network services policy to be executed on the network, the first network part of an access network services policy being configured to provide a counterparty policy execution to a device part of an access network services policy to achieve a first access network services policy global desired and if the service processor is not present or properly configured, cause a second network part of an access network service policy to be executed on the network that is configured to operate without a device counterparty policy to achieve a desired second global access network service policy.
In other embodiments, a network system is used to detect when unscrupulous users try
142
<img file="MX336960B_D0137.tif" />
INSTITUTO MEXICANO DÉ LA PROPERTY INDUSTPJAL acquire free data services with. . the improper use of a service processor to be able to use a single service and have the service utilization accounting assigned to a second device sponsored. As an example, if a device sends reports of its data usage to the network, a user could attempt to hack into the device, so that its reports contain information that is more favorable to the user than it should be, by way of example, communicating less use of data than actually used by the device. By way of another example, a device may contain a sponsored SIM card or other credential that enables the device to use a fixed amount of data, possibly associated with a particular service, at reduced or no burden to the user. Unscrupulous users may try to find ways to increase their amount of free or subsidized data usage with | sponsored SIM cards.
Bandwidth limitations on wireless access networks are making unlimited data plans less attractive to service providers. At the same time, end-user device users want more control over their device data usage to control their costs. The ability to
143
<img file="MX336960B_D0138.tif" />
Tracking a device's data utilization with high precision, on a more granular level than simply measuring data utilization with aggregation, is an important enabler for new service offerings that meet these needs. By way of example, accurate tracking of a device's data usage, on a service-by-service or application-by-application basis, or at even more precise levels, will allow service providers to offer a service plan to ' the letter 'which allows users to choose custom application or service specific data plans.
Therefore, there is a need for security measures to prevent policy errors caused by changes in device credentials, improper configuration of a service processor, or fraud in DAS service systems. In particular, there is a need for tools that allow the network to detect fraudulent end-user device activity.
In this description, various embodiments are disclosed to prevent, detect, or take actions in response to moving a device credential from one device to another, improper configuration of a service processor, absence of a service processor, or misuse of a processor
144 j fUí Ό TY i YJ-h \:
INST '.- í !. , V t \ -: i /, ·. . · · - V
<img file="MX336960B_D0139.tif" />
services in device-assisted service systems (DAS).
In some embodiments, the service controller, on the network, authenticates the service processor and checks that it is communicating the use of the end-user device in the intended manner, eg, in the anticipated times, including the anticipated information. , with anticipated indications of authenticity, etc.
In other embodiments, when the end user device reports usage, the service controller checks whether the reports sent by the service processor are with reports from a verified source, such as a network element.
In some embodiments, when the service controller detects fraudulent or potentially fraudulent activity, the service controller notifies a network or network resource administrator, who can then further assess the situation and decide how to respond. In other embodiments, the subscriber's billing rate is increased.
In other embodiments, a device client configured to implement a device portion of a network access service policy (eg, an access control policy or a traffic control policy, a security policy of the environment
145
OWV INSTITUTE OF THE ÍRCrt-DAD
INDUSTRIAL
<img file="MX336960B_D0140.tif" />
operating or software di gpn «i ti —nn ao. service utilization ', a service billing or accounting policy, a service notification policy, or other policy) may be referred to as a device policy implementation customer, which, in some embodiments, may be part of the service processor. Also without loss of generality, the term service controller can be used to refer to a service processor management and authentication system. Both the service processor and the service controller may have functions in addition to those described here.
In other embodiments, a device is configured with a suitably configured service processor responsible for implementing or executing a portion of a device's first access network service policy. In some embodiments, the device is configured without a properly configured service processor. In other embodiments, a service controller can be configured to determine if the service processor is present on the device and, if so, if it is properly configured.
In some embodiments, if the service controller determines that the device is configured with an appropriately configured service processor, the
146
<img file="MX336960B_D0141.tif" />
service controller causes a network-based access network service policy enforcement system to implement or execute a first network-based part of the first access network service policy. In this case, since the service controller has verified that a properly configured service processor is present in the device, the service controller system operates on the premise that the device is properly implementing or executing. , the part of the device's first access network services policy. If, however, the service controller determines that a properly configured device service processor is not present on the device, the service controller causes the network-based access network service policy enforcement system implement or enforce a second, network-based part of the first access network services policy. In this case, the service controller system operates on the premise that the device is not properly implementing or enforcing a device portion of an access network service policy.
In other embodiments, an end-user device is configured with: (1) a wireless modem for connection to a wireless access network (or another modem of • - and
147
ÍIV ^ L-ú i 1 access to the network for connection to another type of network, <sup>..</sup>.......................
access); (2) one or more device credential sources (eg, a SIM card, a programmable SIM module, a universal SIM module, an IMSI source, a wireless modem, a phone number source, an IMEI source, a MEID source , a user gateway or PIN number, a source of MAC addresses, a source of IP addresses, a source of secure device identifiers, a source of device secure communication encryption keys, etc.) that memorize a device credential and provide the device credential to one or more executing elements of the network services policy (eg, AAA, HLR, PCRF, access network authentication system, admission system or check-in system) for the purpose of seeking or obtaining admission to the wireless access network (or other access network) and (3) a service processor (eg, a device client) configured to implement or execute a device-based part of a wireless access network service policy and to communicate with a network-based service controller in order to provide processor authentication information configured to allow verification that the service processor is present and properly configured on the device.
148
<img file="MX336960B_D0142.tif" />
In other embodiments, a network-based system is configured with: (1) one or more network-based device admission or authentication elements (eg, AAA, HLR, PCRF, access network authentication system, admission system, check-in system, etc.) configured to receive a device credential, from an end-user device, that is attempting to receive or is receiving access network services; (2) one or more service policy execution elements (eg, a network gateway, a router, a GGSN node, an SGSN node, a proxy device, a billing element, a notification operational initiation element, etc. .) configured to implement an access network services policy that is associated with the device credential; (3) a service processor authentication and management system (eg, a service controller) configured to receive authentication information from the service processor and use the information to verify that the service processor is present and properly configured on the device . In other embodiments, the service processor's management and authentication system is further configured to: (a) assuming the service processor is present and properly configured on the device, cause the policy to be executed access network services, which is associated with the device credential, such as a
149 first part of a service network
<img file="MX336960B_D0143.tif" />
<img file="MX336960B_D0144.tif" />
(b) in the event that the service processor is not present in the device or properly configured, have the access network service policy, which is associated with the device credential, executed as a second part of the network of an access network service.
Without loss of generality, in the following related embodiments, the terms SIM card and SIM are used to represent a source of device credentials. As would be appreciated by one skilled in the art, other sources of device credentials (eg, a programmable SIM module, a universal SIM module, an IMSI source, a wireless modem, a telephone number source, an IMEI source, a source of MEID, a source of MAC addresses, a source of IP addresses, a source of secure device identifiers, a source of encryption keys for secure communication of the device, etc.) can be interchanged with the SIM card in most of the embodiments. By way of example, in embodiments where a SIM card moves from one device to another, another type of device credential could move in its place (eg, programmable SIM module, universal SIM module,
150
<img file="MX336960B_D0145.tif" />
MEXICAN INSTITUTE OF TA PROPERTY
INDUSTRIAL
<img file="MX336960B_D0146.tif" />
an IMSI source, a wireless modem phone number, an IMEI source, a MEID source, a MAC address source, an IP address source, a secure device identifier source, a secure communication encryption key source device, etc.). By way of another example, when a user misuses a service processor associated with a SIM module, the user could misuse a service processor associated with another type of device credential (eg, programmable SIM module, SIM module universal, an IMSI source, a wireless modem, a phone number source, an IMEI source, a MEID source, a MAC address source, an IP address source, a source of secure device identifiers, a source of secure device communication encryption keys, etc.). There are numerous other exemplary embodiments where the term SIM may be exchanged for another source of device credentials with the embodiments being too numerous to list and still apparent to one skilled in the art in the context of the teachings provided here.
In some embodiments, the one or more device credential sources include a SIM card. In other embodiments, the service controller
151
<img file="MX336960B_D0147.tif" />
can be configured to recognize with gmá. ~ .di .qpnsi tlvo or service processor is associated with the SIM module, to use the association of the SIM module and the device to find a part of the device designed for a policy of wireless access networks services and to communicate the policy to the appropriate device service processor. In other embodiments, the two different device parts of a wireless access network policy are determined in accordance with a device group or user group service policy definition, which includes one or more module credentials. SIM and / or one or more service processor credentials and these policy definitions are entered into a virtual service provider workstation, that manages the policies of the device's service controller and / or service processor.
In some embodiments, the service controller is configured to recognize when the SIM card has moved from a first device with a first service processor to a second device with a second service processor. In other such embodiments, the service controller may be configured to recognize which device or service processor the SIM module is associated with, to use the SIM module and device association to find a
152 / ϊ Ή; * !?
FROM LA .'A '.f · ΑΟΛΰ 11 «DU Τ ΚΙ AL
<img file="MX336960B_D0148.tif" />
INSTIT desired network part of a wireless access network services policy and have the network part of a wireless access network services policy implemented or executed in one or more implementing elements of the wireless access network policy. network services. In other embodiments, the two different network parts of a wireless access network policy are determined based on a device group or user group service policy definition, which includes one or more module credentials. SIM and / or one or more service processor credentials and these policy definitions are entered into a virtual service provider workstation, that manages the policies of the execution elements of the network services policy and / or the services controller.
In other embodiments, the one or more device credential sources include a SIM card. In some embodiments, the service controller is configured to detect when a user of the device has moved the SIM card from a first device, configured with an appropriately configured service processor, to a second device that is not configured with a service processor. properly configured services. In some embodiments, the service controller can be configured to determine that the first
153
<img file="MX336960B_D0149.tif" />
device is configured with a. appropriately configured service processor and to communicate a device portion of a wireless access network service policy to the appropriate device service processor. In other embodiments, the device portion of a wireless access network policy is determined based on a device group or user group service policy definition, which includes a SIM module credential and / or a service processor credential, and these policy definitions are entered into a virtual service provider workstation, that manages the policies of the device service processor and / or service controller. In other embodiments, the service controller is configured to determine that the first device is configured with a suitably configured service processor and cause a first network portion of an access network service policy to be implemented or enforced. wireless in one or more elements of execution of the network services policy. In some embodiments, the service controller is configured to determine that the second device is not configured with a properly configured service processor and cause a second network part of an access network service policy
154
<img file="MX336960B_D0150.tif" />
wireless is implemented or enforced in one or more elements of the network services policy. In other embodiments, the device part of a wireless access network policy is determined based on the definition of the device group or user group service policy, which includes a SIM module credential and these definitions. policies are entered into a virtual service provider workstation, that manages the policies of the network service policy execution elements and / or service controller.
In some of these embodiments, differences between the first network part of a wireless access network services policy and the second network part of a wireless access network services policy may include a difference in the privileges of the wireless access network. network access, a difference in eligible network destinations, a difference in accounting or billing of service usage for global access, a difference in the accounting or billing of the use of the service for an access classification, a difference in the accounting or billing rates of the use of the service for global access, a difference in the accounting or billing rates of the use of the service for a
155
MP t NST ΙΤ · ITO f. · ·· X! CAN O Du LA ΗΚ ·? · Μ. · Λ0 INLUSTMAL
<img file="MX336960B_D0151.tif" />
access classification, a difference in the accounting or billing of sponsored services (environmental), a difference in the speed or quality of the service, a difference in the networks to which the device or user has access, a difference in the notification of use of the service that is provided to the end user, a difference in roaming policies or notification that is provided to the end user, a difference -in roaming service policies or permissions or accounting / billing rates, a quarantine of user or device access capabilities, differences between (eg, inhibition or otherwise modification) of one or more features device operation or device suspension from network access.
In some embodiments, a SIM module and a service processor are associated with a service utilization classification and a corresponding device part of the access network service policy enforcement. The service controller is then responsible for proper authentication of the proper configuration of the service processor in association with the SIM module, in order to determine the appropriate network part of the network access service policy to be run.
156
<img file="MX336960B_D0152.tif" />
In other embodiments, a SIM module and a service processor are associated with one or more "application-specific services, wherein the device's network access service has policy elements that are specific to a firmware application. or device software. A specific firmware or software application service may include, without limitation, a service with specific policy elements associated with a user application program; an operating systems program, with the corresponding library or function; a background application service such as an application update, content store, software update, or other background application service.
In other embodiments, a SIM module and a service processor are associated with one or more services specific to the destination of the network, wherein the device's network access service has policy elements that are specific to a resource or network destination. A network destination or resource can include, without limitation, a server, gateway, destination address, domain, website, or URL locator.
In other embodiments, a SIM module and a service processor are associated with any combination of a device application, network target
157
<img file="MX336960B_D0153.tif" />
fr & mvro MEXICAN OF THE PROPERTY or resource; a type of network; a condition of F ^ StSnei (eg, a home or roaming network); ungpaas<sup>1</sup> ele · ti amper?
a level of network congestion; a network quality of service (QoS) level and background or foreground communication.
In some embodiments, a SIM module and a service processor are associated with one or more sponsored services (also referred to herein as environmental services), where part or all of the service usage accounting, for one or more plus service utilization ratings are posted, charged or billed to a service sponsor and not to the device user or party paying the user service plan. The portion of the service that is sponsored may be the entire access to the device or a portion or classification of the access to the device. In other embodiments, the classification of the sponsored portion of the service (eg, the identification of the portion of the access network device usage, which should be assigned to the service sponsor) is performed on the device with a data processor. services. In other embodiments, the classification of the sponsored portion of the service is done over the network using DPI elements, gateway elements, server elements, mandatory elements, website elements, or service elements.
158
<img file="MX336960B_D0154.tif" />
Web. In some embodiments, the classification of the sponsored portion of the service is performed with a classification policy implemented by a combination of a service processor in the device (eg, directing a classification of service to a network element given to through a redirection, rerouting or tunnel [eg, secure SSL, VPN, APN or other tunneling protocol]) and one or more network elements (eg, DPI elements, gateway elements, server elements, proxy elements, website elements or web service elements). In other embodiments, the portion of service that is sponsored includes service for a device application or a group of device applications. In other embodiments, the portion of service being sponsored includes service for a network or resource destination, a server or website, or a group of network destinations, servers or websites. In some embodiments, the portion of the service that is sponsored includes the service on a specific type of network. In other embodiments, the sponsored service portion includes service in a home network or in a roaming network. In other embodiments, the portion of service that is sponsored includes service for a period of time. In other embodiments, the portion of the service that is sponsored includes service for a certain range of congestion in the
159
I Μ ρ ϊ
V ..!. (/. K 1 .. X institute Murceo
<img file="MX336960B_D0155.tif" />
DEI.A ÍKGí '; Úi<sub>TO</sub>r. I;
net. In some embodiments, the part<sup>!</sup>The sponsoring system may include a certain range of network quality of service QoS. In some embodiments, the portion of the service being sponsored includes the service for a foreground or background data communication of the network. In other embodiments, the sponsored service portion includes any combination of device application, network destination or resource, a network type, a roaming condition (eg, home or roaming network), a period of time, a network congestion level, a network QoS level of service, and a foreground background communication.
In some embodiments, a SIM module (or other user credential or device credential source, as described above) is installed in, or present in association with, a device configured with a device service processor configuration. which provides the execution of the network access policy. In such embodiments, one or more network elements can implement or execute a part based on the access network policy enforcement network and the device service processor can be configured to implement or execute a part, device-based policy enforcement
160
<img file="MX336960B_D0156.tif" />
<img file="MX336960B_D0157.tif" />
INSTITUTO MEXICANO DE IA PROPERTY access networks. In other embodiments,<sup>D</sup>uses<sup>L </sup>SIM module credentials can be useful i zar 7% Τ<sup>Ί</sup>'metras in ·· part, to identify the network-based part of the access network policy. In some embodiments, one or more credentials of the SIM module may be used, at least in part, to identify the device-based part of the access network policy.
In other embodiments that include a SIM module policy association, executing the policy includes one or more of executing the access control policy, service usage limits, executing the access accounting policy. and execution of the user notification policy of the access service. In other embodiments, the execution of the access control policy includes one or more of the functions of allowing, limiting, blocking, deferring, delaying or shaping device network access traffic for global access (eg, unclassified access) or one or more specific classifications of access network service activities. In other embodiments, the execution of the access accounting policy includes one or more of the functions of counting an amount of use of the global network access service (eg, unclassified) or counting an amount of use of the access network service for one or more specific classifications of service activities
161 .instituto j «; ucá?; o industrial '^ sr<sup>5</sup>®^’·»·'<sup>3</sup>'from the access network. In other embodiments, the execution of the access service notification policy includes one or more of the notification functions of an end user when a predefined service use condition occurs for the use of the global access network service ( eg, unclassified) or notification to an end user of when a predefined service use condition occurs for one or more specific classifications of access network service activities. By way of example of specific classifications of access network service activities include access via an OS application or function, access to one or more network destinations or network resources (such as website, domain, address IP or other address identifier, URL locator, connector type, network server, network path or APN, network gateway or proxy, network or subnet content source). Additionally, by way of example, specific classifications of access network service activities include device access to network services with different QoS service levels. In other embodiments, a part of the policies associated with specific classifications of the access network service are implemented or executed with a processor of
162
<img file="MX336960B_D0158.tif" />
<img file="MX336960B_D0159.tif" />
• \
INSTITUTE // Λ '- · i ca: ·: o DE LA tí-, O
INL U 4 Y rJ AL device-based services and other parts of the access network service policy run on one or more network-based elements.
In other embodiments, in which one or more network elements implement or execute a network-based portion of the access network policy enforcement and a device service processor is configured to implement or run a device-based part of the access network policy enforcement, one or more credentials of the device's SIM module are identified and used, at least in part, to determine the policies enforced by the network. In such embodiments, the device's service processor may be in charge of implementing or executing some operational aspects of the access network services policy that are not implemented or executed in the network.
In other embodiments, a first part of the access network services policy is determined, at least in part, by one or more credentials of the SIM module and is implemented by one or more network elements and a second part of the access network services policy is intended to be implemented by a device-based service processor, but the SIM module is installed in a device that is not configured with a
163
<img file="MX336960B_D0160.tif" />
INSTITUTE ΜλΧ: Γ · 1ΝΟ DE LA p; <C?; C.CA »
INDUSTFJAL
<img file="MX336960B_D0161.tif" />
service processor capable of implementing the second part of the access network services policy. In some of said embodiments, a network element identifies whether the SIM module is installed in a device that is configured with a service processor capable of implementing the second part of the access network services policy intended to be implemented. in practice on the device. In other embodiments, the identification is performed by a network system that implements one or more of the following network policy selection and device configuration detection functions: (1) identify when a SIM module whose credentials are used, at least in part, to identify a network-based part of an access network policy is installed in a device configured to include a service processor capable of implementing o implement a device-based portion of an access network service policy and provide a network-based service policy, in one or more network-based policy enforcement elements, which implement or enforce the access network services policy; (2) identify when a SIM module whose credentials are used, at least in part, to identify the network-based part of the access network policy that is installed in a device that is not configured
IMPI;
services able to put in device-based, 3e
164
INSTITUTO MEXICANO DE LA PROi'lf gao INDUSTRIAL
<img file="MX336960B_D0162.tif" />
access networks v noner en to include a practice processor or execute a part, the practice service policy a second, network-based service policy, in one or more network-based policy execution elements, which put in practice or execute the access network services policy.
In other embodiments, when it is determined that a SIM module whose credentials are used, at least in part, to identify the network-based part of the access network policy, is installed in a device configured to include a service processor capable of implementing or executing a device-based part of access network service policy, A network-based service policy provision system provides a network-based service policy on one or more network elements (e.g., schedules or sends the policy to one or more network elements) and also provides a network-based service policy. services, based on the device, in a service processor of the device. In other embodiments, when it is determined that a SIM module whose credentials are used, at least in part, to identify the network-based part of an access network policy, is installed in a device that is not configured to include a service processor capable of
165
<img file="MX336960B_D0163.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0164.tif" />
implement or execute a device-based part of the access network service policy, a network-based service policy provision system, provides a second, network-based service policy on one or more network elements and there is no policy provision for a device-based service processor.
Such embodiments are desirable, by way of example, when a device-based service processor is capable of implementing or executing a network access service policy that has fine-granularity classification aspects that, otherwise, they are not implemented or run on the network. By way of example, in some embodiments, a SIM module is installed in a first device configuration that includes a device-based service processor capable of classifying access network service utilization associated with one or more device software applications and to enforce a policy for access control, service limit, access accounting, or access service notification for that application. In this case, a first set of network-based access network service policies may be provided in the network elements that implement or execute an access network service policy. If the same module
166
<img file="MX336960B_D0165.tif" />
SIM is installed in a second device configuration, which does not include the described service processor capability, a second set of network-based access network service policies can be provided in the network elements that implement or execute the access network services policy. In such embodiments, the first device configuration may include a proven access control or service limit policies in the service processor, which determine network access assignments for one or more applications and the first service policies of the device. The network is configured to facilitate this service limitation or application access control, based on the device. In contrast, the second device configuration, which does not have any service processor, has no proven access control or service limitation policies, and therefore the second network service policies can be configured in a way that allows access only if the service plan or service account in association with the SIM module (or second device or user of the SIM module) includes permissions for global access, unclassified access or access that is classified by the network and not by the device.
In other embodiments, the second
167
<img file="MX336960B_D0166.tif" />
IMPI
INSTITUTO MEXICANO DE LA PROPIEDAD network services are configured for modff! F? L<sup>R</sup>How to classify network access services- “en” -funt'ió'JT of the capabilities that exist only in the network without the assistance of a device-assisted classification component.
In other embodiments, the second network service policies include an access service accounting or billing rate that is different from the access service accounting or billing rate of the first network service policies. By way of example, the method of accounting for the service or billing for the service to the end user in the case where the SIM module is installed in a device configuration that includes a service processor capability (eg, the device is capable of to perform functions of classification of the service, accounting, control or notification) may be different than the method of accounting for the service or billing for the service to the end user in the case where the SIM module is installed in a device configuration that includes the capacity of the service processor. As an example, if the SIM module is installed in a device configuration that includes a service processor capability, a given application (eg, social media application, email application, email application,
168
<img file="MX336960B_D0167.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0168.tif" />
search, voice app, app) could have a first service accounting or service billing policy that defines a first billing measure (eg, time-based usage for an app, website, content type, class QoS of the type of, service or eg, usage based on megabytes for an application, website, content type, QoS class of type of service, etc.) and / or a first billing rate (eg, $ X per minute or eg, $ Y per megabyte, etc.) when the device configuration includes a service processor capacity, whereas when the SIM module is not installed in a device configuration that includes a service processor capacity, all traffic can be charged at the same way (eg, time-based or megabyte-based), potentially with a higher price. In other embodiments, when the SIM module is not installed in a device configuration that includes a Service Processor Capability, the device's network access permissions are changed or device communications may be quarantined or blocked.
In other embodiments, when a SIM module is installed in a device with a first device configuration, the service processor is configured to differentially handle one or more classifications of
<img file="MX336960B_D0169.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0170.tif" />
service activities of the access networks depending on the level of network congestion, time of day, QoS level or background / foreground access (eg, memorization of background content or background loading of user analytics / device, OS updates or background software, background application / server communications, etc.) but the same SIM module can alternatively be installed, on a device without such service processor capabilities (eg, a device with a second device configuration). In such an embodiment, one or more of the network-based parts of the service limitation or access control policy, the network-based part of the accounting or billing policy, or the part The network-based, user notification policy can be varied depending on whether the SIM module is installed in a device with the first device configuration or with the second device configuration. As an example, if the SIM module is recognized by the network in association with the first configuration of the device, a lower accounting rate or service usage price may be applied to traffic that (i) is assigned to the operational state of background, (ii) is controlled based on the level of network congestion, (iii) is controlled in
170
<img file="MX336960B_D0171.tif" />
IΜ Ρ11 institutomexícano
OF THE PROPERTY
INDUSTRIAL _ based on the time of day, (iv) is controlled based on a lower QoS rating assignment, etc., whereas if the SIM module is recognized by the network in association with the second device configuration, it is you may apply a potentially higher accounting rate or service usage price. In other embodiments, if the SIM module is recognized by the network in association with the second device configuration, the device's network access permissions can be modified or device communications can be quarantined or blocked.
In some embodiments, when the SIM module is determined by a network element to be installed in a device configuration that includes the service use billing capability of the service processor, one or more network elements are configured for a zero rate of access to the device (that is, the one or more network elements will not apply the accounting of the use of the service registered by one or more network elements for the user's bill) and the accounting or billing of the user's service is directed to a service controller that receives the information of accounting or billing of the use of the service from the service processor.
In other embodiments, when a SIM module is
171
<img file="MX336960B_D0172.tif" />
<img file="MX336960B_D0173.tif" />
a
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL determines by a network element to be installed in device configuration that includes a capacity of the service processor to route, redirect or in any other way, control the traffic for one or more classifications of service activities to a or more proxy gateways / servers, one or more network elements are configured for zero rate of device access (i.e. the one or more network elements will not apply the accounting of use of the service registered by one or more network elements for the user's bill) and the accounting or billing of the user's service is directed to one or more proxy gateways / servers that are configured to account for or bill the use of the device service.
In other embodiments, when a SIM module is determined by a network element to be installed in a device configuration that includes a service processor ability to route, redirect, or otherwise regulate traffic for one or more classifications of service activities to one or more proxy gateways / servers, the one or more proxy gateways / servers perform access control to additional traffic or the implementation or execution of a service limitation policy for the one or more service usage classifications.
IMPI
172
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0174.tif" />
In some embodiments, when a SIM module is determined by a network element to be installed in a device configuration that includes a service processor capability to route, redirect, or otherwise regulate traffic for one or more classifications of service activities to one or more proxy gateways / servers, the one or more proxy gateways / servers perform an additional service use classification for the purpose of accounting for service use, access control, service limitation or user notification.
In other embodiments, when a SIM module is determined by a network element to be installed in a device configuration that does not include a service processor capability to route, redirect, or otherwise regulate traffic for one or more service activity classifications for one or more proxy gateways / servers, network elements other than proxy gateways / servers account for service utilization potentially at a different rate than when a SIM module is determined by a network element to be installed in a device configuration that includes a service processor capability to route , redirect or in any other way, regulate traffic for one or more classifications of service activities.
INSTITUTE: á
OF THE tn
INE realization, in which the
In other forms of
173
<img file="MX336960B_D0175.tif" />
INSTÍTUTO MEXICANO V '—- DE LA INOPd'DAD L INDUSTRIAL device configuration includes a service processor capability to route, redirect or in any other way, regulate traffic for one or more classifications of service activities to one or more gateways proxy / servers, the routing, redirection or regulation of the device is done by routing, redirecting or regulating device traffic to one or more service utilization classifications for a specific network destination or resource associated with the proxy / server gateway. In other embodiments, the routing, redirection, or regulation functions are performed using a secure tunnel through the network. In other embodiments, the routing, redirection, or regulation functions are performed with a tunnel of
VPN or APN.
In some embodiments, a network-based service billing policy system is used in conjunction with a user service contractual agreement confirmation system, wherein the confirmation system of the user's contractual agreement provides confirmation that the user has agreed to conditions of use of the access service that stipulate a first accounting or billing rate for the use of the access service when a SIM module is detected in association with a configuration of the
174
V Ή / τ pl ν ¡ti «V« Fi “- t 11 λ. »Δ, JA. Hee
INSTITUTO MEXICANO DB LA INDUSTRIAL PROPERTY
<img file="MX336960B_D0176.tif" />
device that includes a service processor capability and a second access service utilization accounting or billing rate when a SIM module is detected in association with a device configuration that does not include a service processor capability. In other embodiments, if a user removes or misuses a device configuration that includes a service processor capability or if a user installs a SIM module in a device that is not configured with a service processor capability, they are changed. the billing conditions for the use of the service. In other embodiments, depending on device configuration (eg, with or without a service processor capacity), the user is billed at a different rate for overall service utilization or is billed at a different rate for one or more more utilization classifications. from service.
In other embodiments, a web-based service billing policy system is used in conjunction with a user service contractual agreement confirmation system, wherein the user's contractual agreement confirmation system provides confirmation. that the user has agreed to the
175
<img file="MX336960B_D0177.tif" />
MEXICAN INSTITUTE V,
DE LA I'ROPií OAa \ conditions of use of the service <sup>J</sup> access stipulating a first set of privileges — CCS service access when a SIM module is discovered in association with a device configuration that includes a transmitter capability and a second set of access service privileges when a SIM module is discovered in association with a device configuration that does not include a service processor capability. In other embodiments, if a user deletes or misuses a device configuration that includes a service processor capability or if a user installs a SIM module in a device that is not configured with a service processor capability, they are modified. the user's service use permissions. In other embodiments, this modification may include altering allowed network destinations, altering allowed network services, altering allowed network resources, quarantining access, or blocking access.
In some embodiments, the presence of a device service processor in combination with a SIM module results in the service controller providing convenient network access services for the user. By way of example, they include, without limitation, the sponsored services described herein, services based
176
<img file="MX336960B_D0178.tif" />
W LXiCANO PROPERTY INSTITUTE
INDUSTRIAL
<img file="MX336960B_D0179.tif" />
in applications paid by the user (eg, services paid by the user where access to one or more applications of the device is included in an allocation of services with potentially lower cost than global Internet access), destination services paid by the user (eg, user-paid services where access to one or more network destinations or resources is included in an allocation of services with a potentially lower cost than global Internet access), roaming services (eg, services that assist the user when the device is connected to a roaming network, such as informing the user that they are roaming and asking if they want to continue or block the use of the roaming service, update roaming service usage indication or cost indication, roaming service fee indications, allowing a user to decide which device service usage classifications they want to allow while roaming, etc.) or roaming services notification of use of the service (eg, providing the user with an update of the magnitude of the use of the service or the cost that has been incurred, informing the user of what service plans are available, informing the user of when the subscription to a service plan may be convenient for the user in
177
IMPI
<img file="MX336960B_D0180.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL ~ function of an activity or group of activities that the user is attempting or providing the user with a set of service plan subscription options that can be selected and purchased from a device user interface (Ul), etc.). In some embodiments, these user services are made possible by the capabilities of the service processor in the device in conjunction with a specific configuration of a service controller or other network elements in an access service provider network.
In other embodiments, if the SIM module, for a first network service provider, is removed from the device and another SIM module, for a second network or service provider, is installed, the user may not have access to the same services. In other embodiments, the service processor in the device detects that the SIM module has been changed and informs the user through a device user interface (Ul) notification that the user changes the SIMS module or provider networks. services, the user will lose some services. In other embodiments, the services to be lost are indicated in a notification on the Ul interface. In other embodiments, the Ul interface notification states that if the user wants to regain access to some services, the user can reinstall the SIM module.
178
<img file="MX336960B_D0181.tif" />
<img file="MX336960B_D0182.tif" />
INSTITUTO MEXICANO DE LA PROPERTY INDUSTRIAL original.
In other embodiments, one or more network elements determine whether an end user device has an active service processor. In some embodiments, a service controller, on the network, performs service processor authentication.
In other embodiments, the service controller authenticates the service processor to ensure that it is present and properly configured to implement a device portion of the access network service policy. Figures 16 and 17 depict a system diagram for a service processor of the service controller communication link device that can assist in secure communication and authentication and verification functions of the service processor.
FIG. 16 is a functional diagram illustrating the link of the service control device 1691 of the service processor 115 and the link of the service control service 1638 of the service controller 122 in accordance with some embodiments. In particular, the service control device link 1691 of the service processor 115 and the service control service link 1638 of the service controller 122, as illustrated in Figure 16, provide a
179
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0183.tif" />
secure control plane communication via a service control link 1653 between the service processor 115 and the service controller 122 in accordance with some embodiments. Various embodiments include two or three layers of encryption in the service control link, with one embodiment or layer that implements the encryption functions (2408, 2428) and decoding functions (2412, 2422). and another embodiment or layer implemented in the transport service stack (2410, 2420). An optional third embodiment or encryption layer is implemented below the transport service stack, for example with IPSEC or other IP layer encryption, VPN or tunneling system. By way of example, various known security encryption techniques can be implemented in the encryption functions (2408, 2428), with public / private or completely private keys and / or signatures, so that very high levels can be achieved. security for service processor control plane traffic even when basic transport services (2410, 2420) implemented with standard secure or open Internet networking protocols, such as TLS or TCP. By way of example, communications from the service processor agent, locally, to the device, can be made to and from the devices.
180
<img file="MX336960B_D0184.tif" />
INSTITUTO MEXICANO DE LA PROPERTY INDUSTÍUAL through the link
1691 in your connection
1630. Combining elements of the service controller of the service control device with the link agent communication bus of the service control device 1691 and the agent communication bus 1630, which, in some embodiments, is also encrypted or secure signatures, provides a very secure, asynchronous control plane connection, between the server elements of the service controller and the service processor and the agents of the service processor and the service processor itself, which is carried out over a wide range of access networks, such as any access network you have the ability to connect IP or TCP traffic to another TCP or IP endpoint on the access network, another private network, or over the Internet. As described herein, in some embodiments, the agent communication bus 1630 also provides a fourth level of encrypted, or signed, communication to form a secure, on-device closed system for agent-to-agent communication. by way of example, making it very difficult or practically impossible, for applications or software, to access one or more of the service processor agents, on the device, in any form other than the 1691 service control device link. Thus, in some embodiments, the
181
I MEXICAN INSTITUTE <
From THE PROPERTY rk ..
. ι. · INDUSTRIAL agent communications 1630 and agents of the processing] of services can only be accessed by when necessary or permitted by the communications policies of the agents or by the service controller or other authorized network function, with credentials appropriate security devices, in communication through a link of the service control device 1691. Furthermore, in some embodiments, communications between a subset of two or more agents or between one or more agents and one or more elements of the service controller server are encrypted with unique keys or signatures, such that a fourth level of security for point-to-point, point-to-multipoint or multipoint-to-multipoint private secure communication lines.
In other embodiments, all 1691 service control device link communications are transformed into a continuous control plane connection, with a frequency based on the service utilization rate, a minimum set period between connections, and / or other methods to establish the frequency of communication. In other embodiments, this active network verification function, called a heartbeat, provides a continuous verification link whereby the service controller verifies that the service processor and / or device is working properly.
<img file="MX336960B_D0185.tif" />
with the implementation of service policies
182
<img file="MX336960B_D0186.tif" />
correct. Considering the following embodiments of active network verification functions described herein, it will be apparent to one skilled in the art that different methods are possible for implementing the various embodiments of active network verification and it will be apparent that there are numerous ways to achieve the essential characteristics that allow a reliable, sometimes continuous, control link, and the verification function for the purpose of assisting the use of the control service in a verifiable way. As indicated, within the service processor 115, the service control device link 1691 includes an active network verification signal sending counter 2402 in communication with the agent communication bus 1630. As an example, the active network verification signal sending counter 2402 may provide a count for operational initiation.
<td>processor</td><td>of</td><td>services</td><td> 115</td>
<td>based on</td><td>a</td><td>mechanism</td><td>of</td>
<td>controller</td><td>of</td><td>services</td><td> 122</td>
<td>heartbeat</td><td> 2404</td><td>, as well</td><td>in</td>
of when a communication from the (eg, periodic heartbeat communication) must be sent to and from the communication buffer with the communication bus of the agent 1630, it performs the intermediate storage of any of said information for the next communication of the service processor 115, in conformity with various heartbeat technical shapes, according to here
Intermediate memorization
183
<img file="MX336960B_D0187.tif" />
was similarly described.
heartbeat 2404 is in communication with framing element 2406 and encryption element 2408 for framing and encryption of any communications from service processor 115 transmitted to service controller 122 via the transport service stack 2410 via a 1653 service control link. Similarly, as illustrated within the service controller 122, the service control server link 1638 includes an active network verification signal send counter 2434 in communication with the service controller network 2440 and the 2432 heartbeat buffer, also in communication with the 2440 service controller network, which performs buffering of any of said information for the next service controller 122 communication, in accordance with various embodiments based on active network verification signals, as similarly described herein. The heartbeat buffer 2432 is in communication with the framing element 2430 and the encryption element 2428 for framing and encryption of any such communications from the service controller 122 transmitted to the processor. <sup>INST</sup>ds7? ÍS<sup>c</sup>'<sup>spout</sup>
OF THE industrial PROPERTY
184 ίr t
<img file="MX336960B_D0188.tif" />
services 115 via transport service stack 2420 via service control link 1653.
As also illustrated within the service processor 115 of Figure 16, the link of the decoding control device 1691 service
2412 to include decoding element of any received service controller 122 communications (eg, decrypting the encrypted communications), unpacking item 2414 to unpack the received communications from service controller 122 (eg, assembling the packed communications) and the agent path 2416 to route the communications received from the service controller 122 (eg, orders, instructions, information related to the heartbeat technique or operational status reports, information related to policies or operational adjustments and / or configuration updates, trouble / response inquiries, operational regenerations of the agent and / or new software for your installation) for the appropriate agent service processor 115. Similarly, as illustrated within the service controller 122, the service control server link 1638 also includes a decoding element 2422 to decode any communications received from the service processor 115 (eg, decrypting the encrypted communications). , a
185
<img file="MX336960B_D0189.tif" />
unpack 2424 to unpack
<img file="MX336960B_D0190.tif" />
received from service processor 115 (eg, assembling packaged communications) and route from agent 2426 to route communications received from service processor 115 (eg, response to instructions and / or commands, information related to network verification signals active, called heartbeat, or reports of operational states, information related to policies or operational adjustments of configurations and / or updates, consulted for difficulties / responses, agent status information, cost / network service utilization information and / or any other communication-related information) to the appropriate agent of the service controller 122. Accordingly, as described herein with respect to various embodiments, The various secure communications between the service controller 122 and the service processor 115 can be accomplished using the embodiment illustrated in Figure 16 and those skilled in the art will appreciate that a variety of other embodiments can be used to similarly provide the various secure communications in service controller 122 and service processor 115 (eg, using different software and / or hardware architectures to provide secure communications, such as using
186
<img file="MX336960B_D0191.tif" />
additional elements / functions and / or some of them or other design options to provide such secure communications).
In some embodiments, a communication framing structure between the service processor and service controller is disclosed and the following embodiments (eg, as illustrated and described with respect to Figure 17) teach such a structure that packages the various service processor agent control plane communications and the various service controller element control plane connections in a non-consuming format. too much bandwidth to allow a continuous control plane connection between the device and the services controller. In other embodiments, an efficient and effective communication framing structure between the service processor and the service controller is disclosed for buffering said communication messages for some period of time prior to formation. of frames and transmission, such as on an active network check signal frequency, which is based on the service utilization rate. In other embodiments, an efficient and effective communication framing structure between the service processor and the controller is disclosed.
187
<img file="MX336960B_D0192.tif" />
services to allow the frame to be easily packed, encrypted, decoded, unpacked and the messages distributed. Considering the various embodiments described here, it will be apparent to a person skilled in the art that numerous frame formation structures will serve the intended purpose of organizing or forming frames between agent communications and the uniqueness and importance of combining said element of the system with device service controller functions, service processor functions, the verification functions of the control of the service and / or the other objectives.
Figure 17 is a functional diagram illustrating a framing structure of the communication frame of the service processor 2502 and the communication frame of the service controller 2522 in accordance with some embodiments. In particular, the link of the service control device 1691 of the service processor 115 and the link of the service control service 1638 of the service controller 122 (eg, as illustrated in Figure 16) provide secure control plane communication over the control link 1653 between the service processor 115 and the service controller 122 using communication frames in the format of the communication processor communication frame. services 2502
188
<img file="MX336960B_D0193.tif" />
iNsrmr ._.....
DELÁi-.Mr'rb /. 'Y and of the communication frame of the services controller · 2522, as illustrated in Figure 17, according to some embodiments. As illustrated, the communication frame of the service processor 2502 includes a number of framing sequences of the service processor 2504, timestamp 2506, ID identifier of the first function of the agent 2508, message length of the first function of agent 2510, message of the first function of agent 2512 and, assuming that more than one message is transmitted in this frame, the identifier ID of the nth function of agent 2514, the length of the message of the nth function of agent 2516 and the message of the nth function of agent 2518. Consequently, the communication frame of the service processor 2502 may include one or more messages as illustrated in Figure 17, which may depend on the network connection's frame length requirements and / or other design options. Similarly, as shown, the communication frame of the service controller 2522 includes the number of framing sequences of the service controller 2524, a timestamp 2526, the identifier ID of the first function of the agent 2528, the message length of the first agent role 2530, the message of the first people role 2532 and, assuming more than one message is transmitted in this frame, the identifier ID of the nth
189
<img file="MX336960B_D0194.tif" />
Agent function 2534, the length of the message of the nth Agent role 2536, and the message of the nth Agent role 2538. Accordingly, the communication frame of the service controller 2522 may include one or more messages as represented in Figure 17, which may depend on networking frame length requirements and / or other design options.
Figures 18A to 18E inclusive, Figures 19A to 19G inclusive, and Figures 20A to 20C inclusive, present numerous embodiments that can be used in isolation or in combination, by a service controller, in service processor authentication. to ensure that it is present and properly configured to implement a device part of an access network services policy. Figures 18A through 18E inclusive provide tables that summarize various parameters and functions of service processor active network verification signals (eg, implemented by various agents, components, and / or functions performed in software and / or hardware) accordingly. with some embodiments. Much of these active network verification signal parameters and functions were previously described in a similar way and the tables depicted in Figures 18A-E are not intended to be an exhaustive summary of these network signal parameters and functions.
190
<img file="MX336960B_D0195.tif" />
active network verification, but rather are provided as an aid in better understanding these functions and parameters in accordance with some embodiments, based on the heartbeat technique, described herein.
Figures 19A through 19G, inclusive, provide tables that summarize various device-based service policy implementation verification techniques in accordance with some embodiments. Much of these device-based service policy implementation verification techniques were similarly described above and the tables depicted in Figures 19A-G are not intended to be an exhaustive summary of these implementation verification techniques. in practice of device-based service policies, rather, they are provided as an aid to better understanding of these techniques in accordance with some of the device-based service policy embodiments described here.
Figures 20A through 20C inclusive provide tables that summarize various techniques for protecting device-based service policy against a compromised situation in accordance with some embodiments. Much of these techniques for protecting device-based service policy against compromised situations were previously described in
191
<img file="MX336960B_D0196.tif" />
Similarly, the tables depicted in Figures 20A-C are not intended to be an exhaustive summary of these techniques to protect device-based service policy from a compromised situation, but rather are provided as an aid to better understanding. these techniques in accordance with some of the device-based service policy implementations described here.
Figure 21 illustrates an exemplary embodiment of a process for initiating or interrupting a data session with notification from the SGSN node. End user device 100 attempts to initiate a data session by sending a GPRS join message to SGSN node 2230. SGSN node 2230 notifies service controller 122 that end user device 100 has initiated a data session. Service controller 122 waits for a predetermined time, for example 1 minute, to receive an authentication or login request from service processor 115. In other embodiments, service controller 122 sets a timer check-in. If the service controller 122 receives the authentication or check-in request before the timer runs out, it attempts to authenticate the service processor 115.
192
<img file="MX336960B_D0197.tif" />
One or more authentication errors can occur when service controller 122 attempts to authenticate service processor 115. By way of example, service processor 115 may have invalid credentials. By way of another example, the service processor 115 may send invalid kernel signatures or applications. By way of another example, the service processor 115 may report root detection errors from the end user device. By way of another example, service processor 115 may contact service controller 122 using an identifier that is already in use by a different end user device.
If the service controller 122 does not receive the request from the service processor 115 within the predetermined time period or if the service controller 122 is unable to authenticate the service processor 115 for some reason, the service controller 122 assumes that (1) the end user device 100 does not contain a service processor and therefore, is unable to participate in device-assisted services or (2) even though end-user device 100 has a service processor, service processor 115 has been inhibited. Service controller 122 sends a notification (No SP active message ) to the
I
193
<img file="MX336960B_D0198.tif" />
INST11 u í u MEX'CAW'T OF PROPERTY
INDUSTRY!
data charging element 2220 to indicate that end user device 100 does not have the ability to provide the necessary information to data mediating element 2210 to generate detailed data usage reports, eg, micro-CDRs. In other embodiments, the service controller 122 sends an operational initiation to the network to indicate that the end-user device 100 should be billed for usage at standard lump-sum rates. In other embodiments, service controller 122 specifies a standard flat rate billing code on CDRs by sending it to data mediation element 2210. In other embodiments, data charging element 2220 determines usage. of data by the end user device 100 based on the records based on the communications operator.
If the service controller 122 receives the authentication or check-in request from the service processor 115, within the predetermined time period, and performs a successful authentication of the service processor 115, service controller 122 sends a notification (Device OK message) to data rating element 2220 to indicate that end user device 100 has a service processor and is capable of supporting device-assisted services. In others
194
IMPI
MEXICANO owned by INDUSTRIAR embodiments, data charging element 2220 expects to receive micro-CDR reports from data mediation element 2210 when services controller 122 has determined that end-user device 100 has a data processor. active services. In other embodiments, data rating element 2220 determines utilization based on micro-CDRs, which contain more granular information than ordinary CDRs. As an example, although an ordinary CDR could simply report that an end-user device used 100 megabytes (MB) of data, a set of micro-CDRs could report that the end-user device used 15 MB of email, 35 MB social media management and 50MB streaming video signals.
In some embodiments, the element of
<img file="MX336960B_D0199.tif" />
data mediation 2210 sends communications operator-based utilization reports (eg, CDRs) to service controller 122. Service controller 122 queries utilization database 22 00 for device-based utilization reports (eg, micro-CDRs) for end-user device 100. The service controller 122 determines the data utilization of the end user device 100 from the utilization reports based on the communications operator. The service controller 122 determines the usage of
I
MEXICAN INSTITUTE
OF THE PROPERTY
INDUSTRIAL
195
<img file="MX336960B_D0200.tif" />
from the device. The utilization data from the end user device 100 utilization reports based on the service controller 122 compares determined from the utilization reports, based on the communications operator with the utilization determined from the utilization reports based on the device. If the service controller 122 determines that the two utilization measures do not match (eg, they are not identical or are not within the threshold of each other), the service controller 122 sends a notification (eg, a fraud alert) to the data charging element 2220 to indicate that the end user device is in a fraud state and the data charging element 222 0 should bill the usage to the end user device 100 based on the utilization reports based on the communications operator. The service controller 122 sends the utilization reports, based on the communications operator, and the utilization reports based on the device to the data mediation element 2210.
When the GPRS detach message is received by the SGSN node 223 0, the SGSN node 2230 sends a notification to the service controller 122 that the data session for the end user device 100 is closed.
Figure 22 illustrates an exemplary embodiment of a process for initiating or interrupting an IVI data session with notification of the GGSN. The process is similar to
196
INSTITUTO MEXICANO DK LA INDUSTRIAL PROPERTY
<img file="MX336960B_D0201.tif" />
described with reference to Figure 21, with the exception of the way the data session starts and ends. The end user device 100 initiates a data session by sending the data traffic to the GGSN node 2240. The GGSN node 2240 recognizes the start of a new data session and notifies the service controller 122 that the end user device 100 has started. a data session. When the GGSN node 2240 determines that the data session has been closed, it sends a notification to the service controller 122 that the data session is closed for the end user device 100.
As described above, in some embodiments, a device service processor can provide information to aid in the classification of service utilization for any combination of device application, network destination or resource, a network type , roaming condition (eg, home network or roaming network), a period of time, a level of network congestion, a network QoS level of quality of service and background or foreground communication. In other embodiments, when a service processor provides service utilization for a service utilization classification that involves one or more of the device application, network destination, or
ÍMÍPIíy; MEXICAN INSTITUTE
OF/. PROPERTY V «
INDUSTRIAL '' fes resource, a network type, roaming condition (eg, network
197 base or roaming network), a time period, a network congestion level, a network QoS level of service QoS, and a foreground background communication, the service processor 115 generates a service, called a micro-CDR, which is then communicated to a network element (eg, a service controller). The micro-CDR provides a breakdown of the service utilization accounting in more accurate detail (eg, including information about a device application, a network or resource destination, a network type, a roaming condition (eg, home network or roaming, a period of time, a level of network congestion, a network QoS level of service and foreground or background communication) than a global CDR that does not provide such a usage accounting breakdown.
In other embodiments, a device is configured to receive access network services and is further configured to include a service processor capability to take into account one or more classifications of service activities and send the corresponding accounting to a service controller. In some embodiments, the service controller is configured to communicate at least a portion of the
198
<img file="MX336960B_D0202.tif" />
INSTITUTO MEXICANO CE LA? RO? ¡5üAQ
INDUSTRIAL
<img file="MX336960B_D0203.tif" />
accounting for the service processor's service as a service utilization credit to a service utilization reconciliation system. It should be noted that a service utilization reconciliation system also refers, in this description, to various other embodiments as a service utilization mediation system or a similar term involving mediation. In other embodiments, the service usage reconciliation system is configured to withdraw a credit from a user service posting or usage invoice. In some embodiments, the service usage credit that is removed from a user service posting or usage bill is assigned to the sponsored services bill or posting.
In some embodiments, it is desirable to reconcile micro-CDR service usage accounting reports received from a service processor against a verified source. In other embodiments, this is done by a system that provides usage credits for one or more micro-CDR usage reports that are reconciled to, or validated by, a proven source. In other embodiments, if such credit is provided, the corresponding utilization is removed from utilization
199
<img file="MX336960B_D0204.tif" />
tNS'fl MEXICAN PROPERTY TUTE
INDUSTRIAL
<img file="MX336960B_D0205.tif" />
user global and reassigned to the user in accordance with the service usage accounting rules associated with the micro-CDR classification. In other embodiments, the micro-CDR accounting rules may be designated for accounting for micro-CDR service utilization reports for a user service classification under payment (eg, a device application based on accounting service, a network destination or resource based on the service count, a roaming service usage count, etc.). In other embodiments, the micro-CDR accounting rules can be designed for accounting of micro-CDR service utilization reports for a sponsored service classification (eg, a sponsored device application based on service accounting , a sponsored network resource or destination-based service count, a sponsored background ranking of service utilization, a personalized content source classification of service use, a sponsored marketing service, etc.).
In some embodiments, the verified source used to validate the micro-CDR service utilization classification reports is a source of FDR cr
200
i.
! í, Ü
Ι; · \ z. '. I .T..1PI
ΕΝίΤΠ ·; ιτο MEXICAN WíZ INDUSTRIAL PROPERTY
<img file="MX336960B_D0206.tif" />
(flow data record) reporting a Triv ^ - = defeaiLg4 £ L „..,. Classification that indicates the destination or source of the network (eg, domain, URL, IP address, etc.) and possibly one or more ports and protocols. In other embodiments, the source of the FDR is a network element. In other embodiments, the source of the FDR record is a device agent. In some embodiments, the agent that generates the FDR report is located in a secure execution environment on the device. In other embodiments, the agent that generates the FDR report is located in a secure hardware environment on the device.
In some embodiments, the agent generating the FDR report uses a secure transmission protocol with the service controller that is subject to sequencing and signatures and / or encryption in a manner where if the FDR reporting sequence or the FDR reporting content is misused, in which case an FDR integrity violation may be detected by the services controller. In other embodiments, a communication from the services controller to the agent that generates FDR reports is subject to sequencing and signatures and / or encryption in a manner where whether the sequence of FDR reports or the content of the FDR reports is used improperly, in which case an FDR integrity violation may be detected by the agent
t.
generates the FDR reports. In some form
201
<img file="MX336960B_D0207.tif" />
r
<img file="MX336960B_D0208.tif" />
When the FDR reporting agent detects a FDR integrity violation, the FDR reporting agent causes the device to be quarantined or blocked for one or more access networks. In other embodiments, other device communication links other than the access network links can also be quarantined or blocked by including one or more of the wired device access ports (eg, Ethernet, USB, firewire, etc. .), Bluetooth, WiFi and nearby field communications.
In some embodiments, the verified source, used to validate the micro-CDR service utilization classification reports, is a network-based element such as a server, gateway, proxy element or router that processes the classification of the service associated with the micro-CDR. In some embodiments, the network-based element classifies the service utilization associated with the micro-CDR, measures the service utilization, and provides a service utilization classification report back to a service controller, so that can be reconciled with respect to micro-CDR reports.
In other embodiments, a device is configured to receive access network services and is
202 i 1WIC /
Í ÍMSTITUTO MisXrCA'-íO \ J0O0 ~ rre · <D £ LA Γ * Ιθ; - 'ϊΞίλ · \ η V <-' <sup>;</sup>
r. · INDUSTRIAL configured, in addition, to include a service processor capacity to route, redirect or in any other way, regulate traffic from one or more classifications of service activity to one or more proxy gateways / servers. In some such embodiments, a service utilization reconciliation system is configured to receive device service utilization information (eg, a credit amount) from the one or more proxy gateways / servers and the information from use of the service is used when eliminating a quantity (eg, a credit amount) from the use of the service assigned or charged to a user invoice by the reconciliation system of the use of the service. In some embodiments, device routing is accomplished by device routing, redirection, or policing to one or more service utilization classifications for a specific network resource or destination associated with the proxy / server gateway. In other embodiments, routing, redirection, or regulation is done using a secure tunnel through the network. In some embodiments, the routing, redirection, or throttling functions are performed using an SSL, VPN, or APN tunnel.
In some embodiments, a processor
203
MEXICAN (, '
OF THE PROPERTY V v,
INDUSTRIAL device services classifies the - use of the device
.....<sup>. 1</sup> ·! <· «-Jwsesss service in accordance with a service classification policy and routes, redirects or regulates the traffic associated with the classification policy for a network element (eg, a server, gateway, proxy element or router that processes the service classification associated with the micro-CDR) generated by the micro-CDR for that accounting of service use. In this way, the device can associate the use of the service for device applications or functions of OS operating systems with a specific network destination that, in turn, processes the traffic and generates the appropriate micro-CDRs, which are sent to the controller. services for your reconciliation (eg, mediation) as described above. The service processor can regulate classified traffic in accordance with the classification policy by redirecting traffic to the network destination associated with the appropriate network element, routing the traffic to the network destination associated with the appropriate network element, or routing traffic to the network destination associated with the appropriate network element. tunneling or secure tunneling (eg, SSL, VPN, APN) of traffic to the network destination associated with the appropriate network element.
In other embodiments, the verified source, used to validate the micro-CDR service utilization ranking reports, is a server or website that provides the service and validation is provided in the form of informative feedback from
204
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0209.tif" />
Reputable customer associated with a user credential, service processor credential, or device credential, which can be used to determine to which device or user to provide the credit. As an example, if a website is associated with the service utilization classification defined for a micro-CDR and the website is visited by a device with a given device credential or a user credential and the website's servers they track the number of visits, numbers of transactions, amount of commercial activity generated, amount of data communicated or other measure of the interaction of the device with the website, in such a case, a summary of this interaction of the device with the website can be communicated to the services controller and the services controller can provide credit for the micro-CDR.
In other embodiments, other means of limiting the possibility of accounting for improper service utilization due to improper configuration of a service processor or misuse with the service processor may be accomplished by upper limit of quantity of service for a given period of time that is allowed for a micro-CDR service utilization classification category (eg,
<img file="MX336960B_D0210.tif" />
205 limiting the amount of service utilization in a given time period for one or more classifications of service utilization, including a device application, network destination or resource, a network type, a roaming condition (e.g., home network or roaming), a period of time, a level of network congestion, a level of network QoS, or a background or foreground communication). In other embodiments, the upper limit of service quantities over a given period of time that is allowed for a given micro-CDR service utilization classification category is desirable as a mode of limitation of utilization costs. of the service for a service paid for by the user, which is based on a specific classification of use of the service. In other embodiments, the misuse of the service utilization report for one or more micro-CDR service utilization classification categories is limited by combining service utilization reconciliation with the use of one or more of the functions of counting start / stop, CDR informational feedback, FDR informational feedback, etc., and establishing a limit on the usage that is allowed for one or more of the micro-CDR service usage classification categories.
ftwftrAT.'nsií '
206 «* - \, '·: ··.»' '·' INSTITUTO MEXICANO \ - - '—---' 4 ''
DEIAPÍOPIEDAD V.. - -. INDUSTRIAL
In some embodiments, misuse of service utilization reports, for one or more micro-CDR service utilization classification categories is limited by comparing total service utilization for all micro-CDR service utilization classifications. pooled micro-CDRs against the total amount of service used in global CDR reports received from a proven source.
In some embodiments, using associative classification (also referred to as adaptive environmental service utilization classification), part of service utilization, which cannot be directly identified as belonging to a micro-CDR service utilization classification given, it is assigned to the micro-CDR service utilization classification based on one or more of: (i) proximity in time to one or more known service utilization streams identified as belonging to the micro-CDR classification, (ii) a maximum amount of service utilization (eg, byte count) that has occurred since one or more known service utilization streams belonging to the micro-CDR classification were identified or (iii) the fact that the unidentified service utilization is associated with the same application as one or more known service usage streams that belong to the classification of
207
<img file="MX336960B_D0211.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0212.tif" />
my ero-CDR. _______
In some such associative classification embodiments (adaptive environmental service classification), exposure to service utilization fraud can be limited by setting a limit on the amount of service utilization that may not be counted, so that if the Most utilization can be classified as belonging to a micro-CDR service utilization classification category, unaccounted service usage is allowed to be counted in the same micro-CDR posting. In this way, if the fraudulent service utilization activity results in a large percentage of service utilization that is not known to be classified as belonging to the micro-CDR utilization classification category, an integrity violation can be declared. micro-CDR accounting. Service usage above limits that cannot be reconciled (accounted for) can alternatively be accounted for (eg, billed to the user) at an agreed contract rate. In other embodiments, the agreed rate is as high or higher than the rate for global services paid for by the user (eg, higher than the rate at which services based on the website or application of type sponsored and specialized).
208 x '¥' .a. Jtr ¿L
INSTmno rtóxxx.V '-; · DE 1AFROK iZM INDUStt & nt
In other embodiments, the user is notified by the service controller that the user is being billed at a higher rate. In some embodiments, the user enters into a service contract where the user agrees to be billed at a higher rate, assuming the micro-CDR accounting is compromised or is compromised by the service processor.
In other embodiments, the micro-CDR reports include the amount of service utilization that was identified by the service processor as known as belonging to the micro-CDR service utilization category. In some embodiments, a flow identifier (eg, domain, URL locator, IP address, port, or device application associated with the flow [source or termination]) may be provided in the micro-CDR reports for service utilization. known as belonging to the micro-CDR classification. In some embodiments, the utility controller samples or scans these known good micro-CDR stream identifiers to ensure that the streams do indeed belong to the micro-CDR service utilization classification and if not, a micro-CDR accounting integrity violation can be declared. In other embodiments, a
209
<img file="MX336960B_D0213.tif" />
flow identifier (eg, domain, URL locator, IP address, port or device application associated with [source or termination] the flow) can be provided in micro-CDR reports for service utilization that cannot be classified as belonging to the micro-CDR classification. In other embodiments, the service controller samples or performs scanning of these unknown micro-CDR stream identifiers to determine if the service destination models indicate fraudulent service utilization that is incompatible with micro-classification policies. -CDR and if so, a violation of the integrity of the micro-CDR accounting can be declared.
In some embodiments, a SIM module that is expected to be installed in a device configured with a suitably configured service processor is assigned a relatively small upper service utilization limit, in a network portion of a service utilization policy. network access so that the device can connect to the network and to allow the service processor to authenticate with the service controller. By limiting the initial amount of service utilization allowed before the service processor authenticates with the service controller, it is not possible to get a larger amount of service before
210
MY PI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0214.tif" />
Make sure that a configured service processor is present on the device. In some embodiments, once the device's service processor is authenticated, an increase to the utilization limit can be added to the network portion of the access network service policy. In other embodiments, additional utilization limit increments may be added to the network portion of the access network services policy when CDRs, FDRs, or micro-CDRs generated by the processor are received by the service controller. device services. In other embodiments if, at any time, the flow of CDRs, FDRs, or micro-CDRs from the device is misused or interrupted when the service controller interrupts increasing the utilization limit on the network portion of the access network policies and access to the device is denied. Alternatively, in some embodiments, other than service interruption when a service processor is removed or misused, the network portion of the access network service policy requests the application of a higher billing rate. high compared to one or more micro-CDR billing rates for micro-CDR credits provided by the service controller (e.g., user-paid application-based services,
211 <Ρ ϊ
MEXICAN INSTITUTE \ '
OF THE PROPERTY V.
INDUSTRIAL '' «, website-based services paid by the user, content services paid by the user, services based on sponsored applications, services based on sponsored websites or services based on sponsored content). In other embodiments, if the service processor ceases to send micro-CDRs to the service controller, the user ceases to be paid for the use of the micro-CDR service and all use is billed at a global rate that can be higher than micro-CDR service rates.
In another embodiment, a SIM module is provided or sold to a user where the SIM module is associated with sponsored services, which are based on network access service policies configured in the network policy enforcement elements. and a service controller. In such embodiments, the problem arises that the SIM module may be installed in a device that does not have a properly configured service processor, giving rise to the possibility that a user could receive unanticipated free services with the sponsored SIM module. . The above-described embodiments can be used to limit the amount of access the SIM module is allowed to receive prior to authentication of the service processor with the service controller by limiting the amount of
212
<img file="MX336960B_D0215.tif" />
utilization of the initial service that is nprtLt-a on the initial network part of the access network services policy. However, if multiple sponsored SIM modules are readily available and low cost or free, a user could potentially swap multiple SIM modules in the device and remove each SIM module when the service controller stops performing service processor authentication. In other embodiments, the service controller recognizes the SIM module and a second device credential (eg, an IMEI, modem credential, or device credential) the first time the sponsored SIM module acquires use of the service and stop performing service processor authentication for that device. After the service processor stops authenticating with the service controller, the service controller re-establishes the network portion of the access network service policy to deny service the next time a SIM module try to authenticate with the device credential associated with the original SIM module.
In other embodiments, a reputable customer feedback can be used as a micro-CDR credit source directly without a service processor in the device. As an example,
213
<img file="MX336960B_D0216.tif" />
OF THE Γ-ROriSD / O INDUSTRIAL
<img file="MX336960B_D0217.tif" />
In some embodiments, a website 'is X' used with the service utilization classification defined for a micro-CDR and the website or server that is visited by a device with a given device credential or user credential performs a tracking of one or more of the various visits, number of transactions, amount of commercial activity generated, amount of data communicated or other measure of the interaction of the device with the website or server, creates a summary report of this device interaction with the website or server and then communicates the summary report to a service controller. The service controller can then reconcile the reputable customer informational feedback summary report of the device's interaction with the website or server by applying a user service utilization credit rating rule to deduct a global portion of use of the service from the user's account and add a classification of use of the service to the user's account that is charged, for billing purposes, applying a charging rule for the given micro-CDR classification. Alternatively, the service controller can deduct a portion of the 'accounting or billing for the use of the micro-CDR service from the reputable customer and add it to an account of the entity.
214
<img file="MX336960B_D0218.tif" />
sponsor, such as the entity that provides the website or server service. Thus, a micro-CDR service usage billing system can be implemented in a network for rating service usage with specialized service usage rating rating, for user paid rating and sponsored ratings, without the need for a service processor in the device.
Figure 23 illustrates an exemplary embodiment with network system elements that can be included in a service controller system to facilitate a device-assisted service (DAS) implementation and information flow between those items. Figure 23 represents the flow of information to facilitate the reconciliation of data usage records generated by the device with data usage records generated by the network (eg, generated by the wireless network operator) associated with an end user device. . Furthermore, Figure 23 depicts the flow of information from a communications operator to an end user device for the purpose of publishing a set of offers. A user of the end-user device can then select or act on the set of offerings.
The billing data records generated by the
215
<img file="MX336960B_D0219.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0220.tif" />
operator communications (CDRs) or real-time reporting logs (RTRs) (or other formats of real-time, or near-real-time utilization logs, such as, e.g., FDRs, batch-processed utilization logs, event feeds continuous utilization logging or utilization log messages in SMS format), flow from the 2650 communications operator (which may be, for example, a real-time reporting system, a network gateway, a network utilization billing system element, an AAA, an HLR record, a billing element, etc.) to the 2652 load balancer for the filtering element of
RTR 2654.
In some embodiments, the load balancer 2652 selects one of numerous CDR / RTR processing initiations that are available in the service controller information processing system. In other embodiments, the initiation of processing is an asynchronous firmware or software program that runs on a server CPU unit or gateway. In some embodiments, the processing thread is the initiation of virtual machine processing, which exists in a resource pool of server CPUs or gateways or virtual machines, which may include redundant or redundant resource pools.
216
<img file="MX336960B_D0221.tif" />
v ·, geographically separated. As illustrated in Figure 23, each processing initiation includes the functional steps of CDR / RTR 2654 filtering, JMS 2656 queuing, CDR / RTR processor 2658, and the interface to the CDR / RTR database. RTR 2660. In other embodiments, the processing initiations are asynchronous in that they start when the 2652 load balancer directs one or more CDR / RTR data transfers to a so-called thread of execution and ends when the CDR information has been processed. / RTR processed and deposited in the CDR / RTR database 2660. It should be noted that Figure 23 represents only one of potentially numerous available CDR / RTR processing initiations.
CDR / RTR 2654 filter element selects records that are associated with devices that include a device client that communicates with the service controller (eg, the device client can be a service processor configured to provide notification updates use of the service, acquisition of the service plan on the device or activation with the visual presentation of Ul options and user selection actions, execution of device-assisted access control policy, execution of device-assisted service usage billing policy, service notification messages
217 .VA AA
INSTITUTO MEXICANO DE LA F ROFÍF.DAD
INDUSTRIAL
<img file="MX336960B_D0222.tif" />
device-assisted, etc.). In Other Terms <=> embodiment, devices that support DAS are identified by device credentials or user credentials that are communicated to the service controller as described herein, where the device credential or user credential are members of a group of devices or a group of users, which is managed by the service controller.
In some embodiments, the CDR / RTR filter element 2654 can be advantageously used to quickly receive and confirm a CDR / RTR record to provide asynchronous functionality due to real-time processing requirements, requirements of scalability and maintainability of server processing initiations or geographic redundancy requirements of server processing initiation. In some embodiments, the filter operation removes unnecessary load on the JMS 2656 queue and / or the CDR / RTR 2660 database. The CDR / RTR 2654 filter element places logs from known end-user devices to configure with a device client (e.g., a service processor configured to provide service utilization notification updates, service plan acquisition on the device or activation with
218 _ Μ Ρ1Ρ Ρ \
INSTITUTO MEXICANO \ χ ~ 'Μι DS LA PROPERTY CV.- „, 4 .jr'í
INDUSTRIAL visual presentation of Ul options and user selection actions, device-assisted access control policy execution, device-assisted service usage billing policy execution, device-assisted service notification messages) that is communicated with the service controller through the 2656 Java Messaging Service (JMS) queue. In other embodiments, the CDR / RTR filter element 2654 filters device records for devices that may adopt a service processor form, but the service processor did not have proper authentication with the service controller. In other embodiments, device clients that are known to be configured with a device client communicating with the service controller are determined by looking up a device credential or user credential associated with CDRs or RTRs in a database. management of user groups or groups of devices (eg, in database SDC 2692 or subscriber management system 182 (represented, by way of example, in Figures 1 to 3)).
The JMS 2656 queue buffers the remaining CDR / RTR information after the 2654 CDR / RTR filtering and allocates one or more CDR / RTR records to a service utilization processing initiation
219
<img file="MX336960B_D0223.tif" />
on the CDR / RTR processor 2658. In some embodiments, the JMS 2656 queue is a persistent queue. In other embodiments ^ the JMS 2656 queue is a primary messaging system between applications.
The CDR / RTR processor 2658 retrieves the records from the JMS 2656 queue, transforms the records, and stores them in the CDR / RTR database 2660. In some embodiments, the CDR / RTR processor 2658 is an application or a processing initiation. In other embodiments, the CDR / RTR processor 2658 extracts a CDR / RTR record from the JMS 2 656 queue, transforms the record, and stores the transformed record in the CDR / RTR database 2660 into a single transaction to provide fault tolerance in the event of a system operational failure. In other embodiments, the CDR / RTR processor 2658 formats the CDR / RTR information to provide a common service utilization information format to facilitate one or more of the service utilization processing operations, generation of reporting, analysis, comparison, mediation, and reconciliation performed within the service controller system. In some embodiments, the CDR / RTR processor 2658 observes the CDR / RTR timestamps and synchronizes the time, aligns the time, or adds, in
220
Ό MEXICAN Κ- *
A PROPERTY V- jb ÍNswyrL
GIVE OWNERSHIP u - jb. ,,. i INDUSTRIAL over time, multiple reports ae CDR / RTR, so that a measure & S can be achieved<sup>T</sup> More consistent utilization with a common time reference within the service controller system for one or more operational purposes of service utilization processing, reporting, analysis, comparison, mediation, and reconciliation.
In some embodiments, end-user devices capable of generating DAS reports (eg, devices configured with a client of the device that communicates with the service controller, such as a service processor described herein) are periodically connected, or occasionally to usage reporting gateway 2672 to report your data usage. In some embodiments, the DAS service communication information includes, without limitation, one or more of the user's service plan purchase or activation selection choices, user service policy configuration preference selections, device (eg, user-generated service policy assignments for apps, websites, network types, or roaming / base policies), DAS service utilization reports, DAS services device policy status reports, DAS software environment integrity reports, and more
221 <sup>?</sup><í AI
INSTITUTO MEXICANO DE LA FT.OP'SüAD INDtJ STrj / d,
<img file="MX336960B_D0224.tif" />
reports indicated in the tables represented in Figures 18 to 20 inclusive.
In some embodiments, DAS services device utilization reports and analytical reports flow from the 2668 communications carrier device network (eg, devices configured with service processors that are in communication with the service controller) to the 2670 Load Balancer to Utilization Reporting Gateway 2672. In other embodiments, the load balancer 2670 selects one of numerous utilization report processing initiations, which are available from the service controller information processing system. In other embodiments, the utilization report processing initiation is an asynchronous firmware or software program running on a server CPU unit or gateway. In other embodiments, the utilization report processing initiation is a virtual machine processing initiation, which exists in a resource pool of server or gateway CPUs or virtual machines, which may include redundant resource pools or geographically separated. As illustrated in Figure 23, each usage report processing initiation consists of the reporting gateway functions steps.
222
<img file="MX336960B_D0225.tif" />
2672 utilization, 2674 JMS queue, 2676 reporting pyocASAdn -r, and the interface to the 2678 utilization reporting database. In other embodiments, utilization report processing initiations are asynchronous in that they start when the load balancer 2 670 directs one or more transfers of utilization report data to a so-called initial thread of execution and terminate when the Processed utilization reporting information has been processed and deposited in utilization reporting database 2678. It should be noted that Figure 23 represents only one of potentially many available utilization report processing initiations.
The utilization reporting gateway 2672 accepts reports from devices configured with a device client (eg, a service processor configured to provide service utilization notification updates, on-device service plan acquisition, or activation with display of options UI and user selection actions, device-assisted access control policy execution, device-assisted service utilization billing policy execution, device-assisted service notification messages) communicating with the service controller and queuing the reports
223
<img file="MX336960B_D0226.tif" />
JMS standby 2674. In other embodiments, usage reporting gateway 2672 only accepts device reports from device service processors that have been authenticated with the service controller system. In other embodiments, the utilization reporting gateway 2672 only accepts device reports from device service processors configured with device credentials or user credentials that are members of a device group or user group, which is managed by the services controller. In other embodiments, the usage reporting gateway 2672 rejects reports from the end-user device without authenticating service processors. In other embodiments, usage reporting gateway 2 672 is an application or processing initiation. In some embodiments, usage reporting gateway 2672 quickly receives and acknowledges reports from end user devices. In other embodiments, usage reporting gateway 2672 provides asynchronous functionality that is advantageous to support real-time processing requirements.
In some embodiments, the end user device is authenticated before reports are put into the JMS 2674 queue. In others
224
<img file="MX336960B_D0227.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0228.tif" />
embodiments, the JMS 2674 queue is a persistent queue. In other embodiments, the JMS 2674 queue is a primary messaging system between applications.
The report processor 2676 retrieves reports from the JMS queue 2674, transforms the reports, and stores the transformed reports in the utilization report database 2678. In some embodiments, the report processor 2676 is an initiation of EAI company integration. In other embodiments, the report processor 2676 retrieves reports from the JMS queue 2 674, transforms the reports, and stores the transformed reports in the utilization report database 2678 in a single transaction in order to provide fault tolerance in case of operational system failure. In some embodiments, the 2676 report processor formats the device utilization report information to provide a common service utilization information format to facilitate one or more of the purposes of service utilization processing, generation of data. reporting, analysis, comparison, mediation and reconciliation in internal processing and its comparison within the service controller system. In other embodiments, the report processor 2676 observes the
225
ΙΜΡΙΓΓ timestamps of the device utilÜ ^^ g ^ i reports and synchronizes the time, aligns, with, time or adds, over time, the multiple device utilization reports, so that a most consistent measure of utilization with a common time reference within the service controller system for one or more of the purposes of service utilization processing, reporting, analysis, comparison, mediation and reconciliation.
In some embodiments, CDR / RTR filtering 2654, CDR / RTR processor 2658, report processor 2676, and utilization report gateway 2672 share a host hub.
In some embodiments, microCDR generator 2680 retrieves records from CDR / RTR database 2660 and retrieves reports from utilization report database 2678. In other embodiments, the micro-CDR generator 2680 determines a service utilization amount for a utilization accounting identifier service utilization classification for the micro-CDR report that identifies utilization as being counted for a user of the device for the device associated with a device credential or user credential and reports this amount of from a micro-CDR, assigns
226
<img file="MX336960B_D0229.tif" />
utilization of communications operator network service 2666 (in the exemplary embodiment of Figure 23, via JMS queue 2662 and FTP or editor 2664). In some embodiments, the micro-CDR generator 2680 determines a service utilization amount for a micro-CDR service utilization classification, assigns a utilization accounting identifier to the micro-CDR report, which identifies the utilization as being accounted for by a service sponsor and reports this amount of service utilization to the 2666 communications operator's network. In other embodiments, the micro-CDR for the sponsored services usage report further comprises an identifier for a device credential or a user credential. In some embodiments, the amount of service utilization accounted for in the micro-CDR is mediated or reconciled by an overall service utilization accounting of the user or device. In other embodiments, micro-CDR generator 2680 sends micro-CDRs to JMS 2662 queue. In other embodiments, FTP or 2664 editor retrieves micro-CDRs from JMS 2662 queue and takes the micro-CDRs to communications operator 2666.
In some embodiments, the 2682 fraud analyzer retrieves records from the base
227
<img file="MX336960B_D0230.tif" />
OF EA I'ROpifda; )
CDR / RTR data INDUSTRIAL 2660. In other embodiments, fraud analyzer device 2682 retrieves reports from utilization report database 2678. In other embodiments, fraud analyzer 2682 retrieves micro-CDRs from the 2680 microCDR generator. In some embodiments, the fraud analyzer 2682 performs a fraud analysis using one or more of the log and report information sources consisting of the CDR / RTR database 2660, utilization 2678 and micro-CDR generator 2680. In other embodiments, the fraud analyzer device 2682 compares the usage records associated with a specific device or user credential from one or more of the CDR / RTR database 2660, the CDR / RTR database 2660. utilization 2678 and micro-CDR generator 2680 to determine whether service utilization is outside the predefined service utilization policy behavior limits. In other embodiments, the fraud analyzer device 2682 compares the service utilization information associated with a specific device or user credential from one or more of the CDR / RTR database 2660, reporting database 2 678 and the 2680 micro-CDR generator to determine if s <
exceeded a limit of use of s
228
<img file="MX336960B_D0231.tif" />
<img file="MX336960B_D0232.tif" />
In other embodiments, the fraud analyzer device 2682 compares the service utilization information associated with a specific device or user credential from one or more of the CDR / RTR database 2660, utilization report database 2678 and micro-CDR generator 2680 to determine if the specific user or device is exhibiting service utilization behavior that is outside of predefined statistical limits compared to utilization behavior of the service of a population of devices or users. In other embodiments, fraud analysis device 2682 stores the results of its fraud analysis in data memory 2694. In other embodiments, fraud analysis device 2682 sends fraud alert to the communications operator's network 2666.
In some embodiments, a service design center is used to create service offerings (eg, service plan offerings to purchase or activate a global service plan, an application-specific service plan, a service plan specific to the application pool, a website service plan, a website group service plan, etc.). In other forms of
229
INSTITUTO MEXICANO Dt LA PROPERTY
INDUSTRIAL
<img file="MX336960B_D0233.tif" />
realization, service offerings are edited for devices enabled by DAS services. To edit an offer for one or more devices on the 2668 communications operator's device network, the 2696 communications operator enters information into the 2690 Service Design Center. The 2690 Service Design Center (SDC) memorizes the set of offers in the SDC 2692 database. The set of offers then flows to the 2688 device message queue. In other embodiments, the 2688 device message queue is a database-backed persistent queue. In some embodiments, when an end user device, with an authenticated service processor, connects to offer set gateway 2686, offer set gateway 2686 carries the offer set to the end user device. In other embodiments, the offer set gateway brings the offer set to the end user device in the next usage report. In other embodiments, the new offer is an offer to purchase or activate a service plan and the offer notification is configured with offer acceptance features that allow the device user to select an option to purchase or activate the offer of services on the Ul interface of the
230
<img file="MX336960B_D0234.tif" />
device.
In some embodiments, a list of service offerings that is available to a group of devices or a group of users, where the list of service offers is created in a user interface of the service design center, is memorized in the SDC 2692 database and is edited for the devices that belong to the device group or user group.
In other embodiments, a set of offers is defined in Service Design Center (SDC) 2690. In some embodiments, this set of offers includes multiple service plans that can be communicated to the device's service processor for its visual presentation to the end user of the device for the selection of the service plan, acquisition or activation through the Ul interface of the device. In other embodiments, the display of the offer set UI is configured to allow the user to purchase or activate a service plan within the offer set in real time or near real time. In other embodiments, the offer set information is received from the service controller and the offer set information is processed for display of the UI interface by a service processor of the device. In other embodiments, the
231
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0235.tif" />
The processing of the service processor offer set information and the UI display is configured to allow the user to purchase or activate a service plan within the offer set in real time or near real time. In other embodiments, the user selection of a service plan for acquisition or activation is communicated to the user through a visual display of the offer set UI interface, which is configured by a service processor, and the service processor communicates with a service controller through a communications interface to the set of offers and notifications gateway 2686 to acquire or activate service plan 1 in real time or near real time. In other embodiments, the set of offers and notifications gateway 2686 communicates the user's selection of the service plan to the user's offer selection receiver 2710, which then makes the operational adjustments of executing the policy of the user. service plan, corresponding to the user's service plan selection, are implemented by communicating the user's service plan selection to the network provision system 160 (or subscriber management 182, order management 180, mobile wireless center 132, billing 123, etc.) which, in turn, communicates with the communications operator's network
232
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0236.tif" />
2712 to make the operational settings of the execution of the ... adequate service reproduction policy is programmed in the various network elements responsible for executing the service plan policy. Thus, in some embodiments, the network service policy enforcement that is required to implement the new service plan for the device can be provided on the various network elements responsible for implementing the policy based on on the network (eg, 420 aggregation / transport gateways [eg, PDN or
GGSN] mobile wireless hub 132 [eg, HLR], AAA server 121, access gateway / RAN 410 [eg, SGSN, PDSN], hub
BSC 125). In other embodiments, network service policy enforcement implementing the new service plan for the device may be provided on the various service processor device agents responsible for executing the policy based on the net. In other embodiments, when the provision of the service plan policy is terminated, the service controller communicates with the device service processor to indicate that the new service plan has been purchased or activated. In other embodiments, the service processor communicates a message from the service controller to the device UI indicating that the new service plan has been
INSTITUTO MEXICANO r DELA LIVING PROPERTY
INDUSTRIAL
233
<img file="MX336960B_D0237.tif" />
<td colspan="2">prosecution</td><td>of</td><td>the</td>
<td>of</td><td colspan="2">processor</td><td>of</td>
<td>the</td><td>Interface</td><td>UI</td><td>I know</td>
purchased or activated.
In some embodiments, the service offer set information and the display is configured to allow the user to purchase or activate a service plan within the offer set in real time or near real time. In other embodiments, User selection of a service plan for acquisition or activation is accepted by a display of the offer set UI interface that is configured by a service processor and the service processor communicates with a service controller to allow the user to acquire or activate the service plan in real time or near real time and the operational adjustments of the service plan policy is communicated by the service controller to the service processor, so that service processor policy enforcement agents, who implement the new service plan for the device, can be provisioned.
In some embodiments, provisioning the various network elements responsible for executing the network-based policy (so that the device can receive the appropriate policies and service plan assignments) can take considerable time, For example, minutes or even longer and this circumstance
234
<img file="MX336960B_D0238.tif" />
Operational INDUSTRIAL can create a poor -ΐτ ^ -Ηρ experience that is neither in real time nor near real time. In such cases, the service controller may create a temporary service lease by providing a subset of the various network elements responsible for executing the network-based policy to allow a temporary service plan to be established before it is completed. can provide all required network elements, responsible for network-based policy enforcement, and possibly, the accounting or billing of the use of the service. By way of example, the temporary lease may provide some or all of the data path or traffic path processing elements required to enable device service utilization classifications that correspond to service utilization classifications admissible in the service plan that the user has selected, but they do not account for the utilization for the correct setup of the accounting or billing system of the service utilization until the provision of the accounting or billing items is completed. By way of another example, during the lease period of the temporary service before the provision of the accounting or billing items is completed, the service controller may perform a
235
OJpI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0239.tif" />
tracking service usage that is incurred during the temporary service lease period and, after completing the provision of the accounting or billing items, transfer the service usage that is incurred during the temporary service lease period to the appropriate service usage log database, so that the use incurred during the lease period of the temporary service is properly accounted for or invoiced. In another embodiment, by way of example, during the temporary service lease, the service controller causes a temporary service provision to take effect on the various sensitive network elements for network access control, where the provision of the temporary service provides all, or a subset, of the provision of data path necessary to allow the assignments of the service plan that correspond to the access control policies for the service plan that the user has selected and the use of the service incurred, during the temporary lease period, it is taken into account for a temporary posting so that it is not the final posting that will be in effect once the provision of the new service plan selected by the user is in full effect. In other embodiments, the posting
236
MPI
INSTITUTE
DELA PiWmD INDUSTRIAL temporary is an account called a 'catchment basket' that is set up to track device usage during the temporary lease period. In other embodiments, the temporary posting has a service utilization rate that is different from the service utilization rate that will be in effect after the new service plan selected by the user is fully provisioned (eg, a posting zero rate). In other embodiments, the use of the service during the temporary lease period is tracked and then transferred to the appropriate service account after the new service plan selected by the user is fully delivered.
In some embodiments, part of the delay in activating a new service plan, directly in a device UI, may be related to performing a credit check or service check of the user, of good business reputation, to the user's credit credentials or service account credentials. In such cases, embodiments similar to those disclosed above can be used to provide a temporary service lease, possibly with a temporary service accounting eventually being transferred to the accounting for
<img file="MX336960B_D0240.tif" />
237 iV L <p - 'lt; / iw! DO NOT
I
INS1 end use. If, during the lease period of the temporary service, an indication is returned to the service controller indicating that the user's credit or the good operational reputation of the user's service is insufficient to provide the service plan that the user has selected, then the user can be notified of this troublesome situation, possibly with instructions on how to resolve it and the temporary service lease can be canceled, thereby inhibiting network access permissions that would have been provided to the device if the credit check had been approved and provision had taken place of the final service plan. In such embodiments, utilization may be tracked during the temporary lease period before canceling the temporary lease and this service utilization may be posted to an account used for the purposes of tracking utilization lost due to failure of credit checks or checks of the good reputation of the user's service. In other embodiments, the usage incurred during a temporary lease, which is eventually canceled due to a failure in the credit check or in the verification of the good reputation of the user's service, can be re-posted for another user with respect to to its
OF THE<sup>1</sup> ·· - ', industrial
<img file="MX336960B_D0241.tif" />
238
OF THE PROPERTY vK »*<sup>Λ</sup>· - ··? 7 ^ 1νΝΐ INDUSTRIAL accounting or billing and in some embodiments, this operational provision is in accordance with a user service contract.
As one skilled in the art will now recognize, prior to the time that the network can fully provide a new service plan selected by a device user on a device UI interface, there are numerous additional related embodiments, too numerous to cite in this description, to facilitate the rapid obtaining of access permissions to the device network, that are identical or similar to the network access permissions that would be allowed for the device after the new service plan, selected by the user, is fully provided, so that the user of the device can enjoy a relatively short delay from the moment the user selects a service plan for acquisition or activation on a device and the moment the network has a full provision to implement the new service plan.
In other embodiments, the service processor is configured to display one or more service plan offers to the end user of the device and the timing of this display is determined based on what the user is performing with.
239
<img file="MX336960B_D0242.tif" />
<img file="MX336960B_D0243.tif" />
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL the device or where the device is located the end-user device tries to access the network, an application on the device tries to access the network, a given application or a set of applications is used or is trying to use, the device enters a roaming operating state, etc.). In other embodiments, the service processor determines when said service offerings are to be displayed for the user of the device by detecting what the user is doing with the device or a device condition caused by the user (eg, device is roaming, etc.).
In some embodiments, a service design center is used to create device user notification messages (eg, a service offer message, a service utilization notification message, a message indicating a quantity of service global used, a claim indicating a quantity of a micro-CDR service classification used, a claim indicating that a global usage limit has been reached, a notification indicating that a micro-CDR utilization classification utilization limit has been reached, etc.). In some embodiments, the notification messages are edited for a device service processor (or group of
240
ΜΡΪΓ
INSTITUTE «SECANO.
GIVE THE PROPHEOAD »LJ ·
ÍNDL'STRLíiL device service processors belonging to a device group or a group of users) and the service processor determines when there is an operational initiation condition to display a specific notification message. In other embodiments, a service utilization notification operational initiation condition (eg, a device utilization state such as a global service utilization state or attempted utilization, utilization or attempted utilization of applications, utilization or utilization attempted website, use or attempted use of roaming / base, use or attempted use of mobile telephony / WiFi, etc.) is associated with each message. In other embodiments, the service processor, in a device, determines when the operational initiation condition has been met and displays a pre-stored notification message associated with the operational initiation condition. In some embodiments, a network element determines when the operational initiation condition has been met and uses the notification and offer set gateway 2686 through the device's message queue 2688 to transmit the notification message to the device for display by the device's service processor. In other embodiments, a service notification message from the
241 i: AFK ASA ~!
ΙΝ3Τ1Ϊ '- J <sup>U2L</sup>'FFF:; F?
device includes a utilization update '—- of i, j service from the CDR / RTR database “76W; —which was sent-—, through the gateway of the set of offers and notification 2686 by means of a waiting queue of 2688 device messages. In other embodiments, a device service notification message includes a service utilization update from micro-CDR generator 2680, which is sent through the offer and notification set gateway 2686 via a 2688 device message queue. In other embodiments, service utilization updates from one or more of the 2660 CDR / RTR database or 2680 micro-CDR generator are sent through the 2686 offer and notification set gateway. by queuing 2688 device messages on a recurring basis. In some embodiments, the recurring base is dependent on a predetermined amount of utilization being reached (for example, a predetermined bit count, a predetermined time count, or a predetermined percentage of a predetermined limit, etc.). In some embodiments, the recurring basis is a function of a usage notification update frequency or time interval.
Figure 24 illustrates an embodiment, by way of «Ni ΪΙΓΛΙ'β
<img file="MX336960B_D0244.tif" />
Example of a service controller reconciliation processing procedure that can be used to detect potential fraud using information from the end user device and information from a second source (as described below). Service processor 115 (not illustrated) or an application on end user device 100 (not illustrated) generates usage metrics 2300. Based on the utilization metrics 2300, the end user device 100 sends first utilization records to the service controller 122 or the service controller 122 requests the first utilization records from the end user device 100. The service controller 122 processes the first usage records in the 2310 usage record preprocessing. In other embodiments, the 2310 device usage record preprocessing modifies the format of the first usage records to facilitate one or more of the service usage processing, reporting, analysis, comparison, mediation, and reconciliation performed within the service controller system. In other embodiments, the 2310 usage record preprocessing looks at the first usage records and the usage records.
243
<img file="MX336960B_D0245.tif" />
timestamps and syncs time, <sup>a1-;</sup>Tün ol o aggregates, over time, the multiple CDR / RTR reports multiple first utilization records, so that a more consistent measure of utilization can be achieved with a common time reference within the service controller system for one or more purposes of processing, reporting, analysis, comparison, mediation and reconciliation of the use of the service. The service controller 122 stores the first usage records in device usage records 2320.
A second source (not illustrated) generates or provides second service utilization measures 2370. In some embodiments, the second source is a network element, such as a mediation element, a gateway, a reporting element in real time, a load item, a billing item or the like. In other embodiments, the second source is a database. In some embodiments, the second source is a roaming partner network element. In other embodiments, the second source is an item on the end-user device 100 that generates secure device data records. In other embodiments, the second source is a partner network destination that provides information about the client's usage of
244 or
ii.
Κκκληο INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0246.tif" />
that destination or transactions with that destination. In other embodiments, the second source is an application on end user device 100.
Based on the second service utilization measurements, the second source sends second utilization records (described below) to the service controller 122 or the service controller 122 obtains the second utilization records from the second source. The service controller 122 processes the second usage records in record normalization, time reconciliation, and preprocessing 2360. In other embodiments, log normalization, time reconciliation, and 2360 preprocessing modify the format of the second usage logs to facilitate one or more of the service utilization processing, reporting, analysis, etc. operations. comparison, mediation and reconciliation performed within the service controller system. In other embodiments, record normalization, time reconciliation, and 2360 preprocessing look at second utilization records and timestamps and synchronize time, time align, or time aggregate multiple second utilization records, from so that a more consistent measure of utilization can be achieved with a common time reference within the
245
INSTITUTE I.
OF THE t
INDUSTRIAL> me / ic / jpo Vii PROPERTY V wí - o;. ·
INDUSTRIAL service controller system for one or more purposes of service utilization processing, reporting, analysis, comparison, mediation, and reconciliation. The services controller 122 stores the second usage records in the second source usage records 2350.
The service controller 122 applies reconciliation and verification processing algorithms 2340 to reconcile records in device usage records 2320 with records in second source usage records 2350 and to validate records in device usage records 2320. The services controller 122 stores the information based on the results of the reconciliation and verification processing algorithms 2340 in the data memory 2330.
In some embodiments, the reconciliation and verification processing algorithms 2340 reconcile the detailed service utilization classifications (eg, micro-CDRs) from a global service utilization accounting and into an accounting micro-CDR classification. of the use of the service. In other embodiments, the verification and reconciliation processing algorithms 2340 perform billing for a detailed classification of
246
Λ ΡI (Ο
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL the use of the service by providing · ..... i.1 of the micro-CDR billing code detailed in the micro-CDR use record, communicated to the mediation or billing system of the communications operator.
realization, reconciliation and billing algorithms for those of a
In other forms, verification processing 2340 performs the detailed classification of service use with the mediation (or subtraction) of the amount of service use reported in the micro-CDR from the amount of service use accounted for global service use . In other embodiments ,. the reconciliation and verification processing algorithms 2340 send billing data records (eg, CDRs, micro-CDRs, etc.) for carrier data mediation 2380.
In some embodiments, the reconciliation and verification processing algorithms 2340 perform fraud analysis using information from one or both of the second source usage records 2350 and device usage records 2320. In other forms of In realization, the 2340 verification and reconciliation processing algorithms compare the usage logs associated with a device credential or
247
INSTITUTO MÍXÍCANO de LA ΡΓλ 'Γ-'ΕΟΑ.Ο industrial
<img file="MX336960B_D0247.tif" />
from one or both of the second source utilization records 2350 and device utilization records 2320 to determine whether the service utilization is outside the predefined service utilization policy behavior limits. In some embodiments, the verification and reconciliation processing algorithms 2340 compare the service usage information associated with a specific user or device credential from one or both of the second source usage records 2350 and data records. 2320 device utilization to determine if a predefined service utilization limit has been reached or exceeded. In other embodiments, the reconciliation and verification processing algorithms 2340 compare the service utilization information associated with a specific device or user credential from one or both of the second source utilization records 2350 and the device utilization records 2320 to determine if the specific device or user is exhibiting behavior in the use of the service that is outside the predefined statistical limits in comparison with the behavior in the use of the service of a population of users or devices. In other forms of
248
Jr 1
INSTITUTO MEXICANO B5 INDUSTRIAL PROPERTY
<img file="MX336960B_D0248.tif" />
In one embodiment, the reconciliation and verification processing algorithms 2340 memorize the results of their fraud analysis in data memory 2330. In other embodiments, the reconciliation and verification processing algorithms 2340 send fraud alerts to the CRM system. operator 2390 (eg, an operator fraud processing system, operator personnel, a device user, a system administrator, etc.).
In other embodiments, the second usage records comprise information from multiple other measurements or reports. In other embodiments, the second usage records are based on information, measurements, or reports from end user device 100. In other embodiments, the second usage records are based on information, measurements, or reports from other devices. end user. In other embodiments, the second utilization records are determined based on information, measurements, or reports from one or more network elements (eg, base station, RAN network, base core, or device-assisted media utilization. , etc.).
In some embodiments, second utilization records comprise a measure of global data utilization (eg, aggregated or unclassified) using the
249
<img file="MX336960B_D0249.tif" />
<img file="MX336960B_D0250.tif" />
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL end user device 100. By way of example, in some embodiments, the second usage records comprise a global usage report, specific for the end user device 100, generated by the network, through an application service provider or through a server. In other embodiments, the second usage records are based on the information in one or more previous reports sent by the end user device 100.
In some embodiments, the second usage records comprise the information associated with the operational status of the access networks. In other embodiments, the second usage records are determined from the tagged information of the operational status of the network. In some embodiments, the second usage records comprise information from a device data record (DDR), which can indicate the network occupancy status and the type of network. In other embodiments, the second usage records are determined from the labeled operational status information of the DDR network.
In some embodiments, the second usage records comprise information from the stream data record. In other embodiments, the flow data record (FDR) reports a detailed level of usage classification.
250
Α · Λ / ¡π <sub>Γ</sub> Jr institute ct l ·. ' of
<img file="MX336960B_D0251.tif" />
Yiokqná indicates the use of the service desoí nsifflB k »ajk, .Qriqei ^ or destination of the network (eg, domain, URL, IP address, etc.) and possibly one or more ports and protocols. In other embodiments, the FDR record reports a detailed level of service utilization classification indicating utilization broken down by user application of the device or OS application. In other embodiments, the FDR reports a detailed service utilization classification level, which indicates service utilization broken down by time of day, network congestion status, or service QoS quality level. In some embodiments, the FDR reports a detailed level of service utilization broken down by network type (eg, 2G, 3G, 4G, WiFi, etc.). In some embodiments, the FDR record reports a detailed level of service utilization broken down by roaming or home network.
In some embodiments, the FDR records originate from a network element capable of classifying the traffic (eg, a deep packet inspection [DPI] gateway, a proxy server, a gateway, or a server dedicated to classifying the service. given, a reputable customer feedback source described elsewhere here, etc.). In other embodiments, the
251
WICKED
MEXICAN INSTITUTE OF PROPERTY
IN DUSTR1AL = i-seconds usage records are derived from a device service monitor. In some embodiments, the second usage records are derived from a service monitor of the contrasted device. In other embodiments, the service monitor of the tested device is located in a secure execution environment, on the device, which cannot be accessed by a user or user-installed application software.
In some embodiments, the second usage records allow the service controller 122 to determine whether the access behavior of the end user device 100, given the state of the network, indicates that the end user device 100 is implementing the right policy controls. In other embodiments, service controller 122 confirms that service processor 115 is reporting correct network status in its data usage reports. In other embodiments, a network element determines the correct network state based on a group of devices.
The information is communicated to the service controller 122 or other suitable network function. The service controller 122 (or other suitable network function) characterizes parts of the subnet (eg, base stations, base station sectors, geographic zones, radio access network (RAN), etc.) in
252
INSTjtí
OF\
<img file="MX336960B_D0252.tif" />
depending on the population of do -end devices connected to that part of the subnet. The network element may also group network occupancy state measurements from network equipment, such as from base stations or by sampling the network RAN, to determine the second measurement.
In some embodiments, the second utilization records provide information on an upper bound on the aggregate amount of data utilization by the end user device 100. The service controller 122 verifies that the total data utilization by the user device final 100, as reported in the first utilization logs, do not exceed the upper limit. If the first usage records provide the data usage amounts for individual services used by the end user device 100, the service controller 122 verifies that the sum of the usage amounts, for the individual services, does not exceed the upper limit. .
In other embodiments, the network classifies the FDRs for known service components, determines the classified utilization credits for each service component, ensures that the utilization of the service components does not exceed specified limits (or matches the reports of the end-user device with those of components) and checks if the sum of the
253
INSTITUTE McT'T / NO Dt la pi? O i '.' ·· :, '? / O
INDIVIDUAL
<img file="MX336960B_D0253.tif" />
components matches the overall measure.
There are several potentially fraudulent circumstances that can be detected by the service controller 122 using one or more of the embodiments disclosed herein, such as the exemplary embodiment illustrated in Figure 24. In other embodiments, the service controller 122 generates a fraud alert if it receives usage reports, based on the communications operator, from a network element and UDRs registers from the service processor 115, but the usage counts contained in the reports do not agree within a specified tolerance. In order to generate a fraud alert under these circumstances, in some embodiments, the service controller 122 posts the unsent usage reports that may still be on the end user device 100.
Figure 25 illustrates an exemplary embodiment that may be desirable in cases where it is desirable to identify classifications of service utilization on the network in order to provide a device user or service sponsor with the opportunity to pay for the use of the access network »service that is classified by application or website. Figure 25 further illustrates, by way of example, elements that provide, in some embodiments, the generation of micro-CDRs in
254
IMPI
INSTITUTE ίΓ '-' ι'ι-τ,
U2 LA j NZJSTkiA !.
<img file="MX336960B_D0254.tif" />
based on a network classification of micro-CDR service utilization categories. Also, Figure 25 further illustrates, by way of example, a means of transmitting the micro-CDRs generated by the network to the communications operator network 2666 for billing purposes. In other embodiments, the network-generated micro-CDRs are used to implement user-paid application plans, website plans, or content type plans. In other embodiments, the network-generated micro-CDRs are used to implement sponsored application plans, website plans, or content type plans.
The exemplary system illustrated in Figure 25 operates on the same principles as the exemplary system illustrated in Figure 23. Detailed usage reports, for the generation of micro-CDRs, are obtained at from an FDR source in the 2698 communications operator network (eg, the source can be a DPI gateway, proxy server, dedicated service server, reputable customer feedback, etc.). The FDRs records from the FDR source are transmitted by the load balancer 2700 to the detailed utilization reporting gateway 2702. In other embodiments, the utilization reporting gateway
255 institi r
INSTiTlJ 'OF 1
<img file="MX336960B_D0255.tif" />
Detailed 2702 views FDR timestamps and synchronizes time, time aligns, or aggregates multiple FDR reports over time, so that a more consistent measure of utilization can be achieved with a common time reference, within the system of the service controller for one or more of the purposes of service utilization processing, reporting, analysis, comparison, mediation, and reconciliation. The processed FDRs records are transmitted by the detailed usage report gateway 2702 to the JMS queue 2704 which, in turn, transmits them to the detailed report processor 2706. The other functions, in Figure 25, are similar to those described in the context of Figure 23. As would be appreciated by one skilled in the art, the exemplary embodiment of Figure 25 provides the benefits of accounting for the use of the micro-CDR service for website services and user-paid applications. or sponsored website or application services.
In some embodiments, the FDR (flow data record) reports a detailed level of service utilization classification that indicates service utilization broken down by network source or destination (eg, domain, URL, IP address , etc.) and possibly one or more ports and protocols. In other ways
256
ΙΜ
<img file="MX336960B_D0256.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL _ of implementation, the FDR reports a detailed level of service utilization classification ^ which indicates utilization broken down by device user application or OS operating system application. In other embodiments, the FDR reports a detailed service utilization classification level, which indicates service utilization broken down by time of day, network congestion status, or QoS level of quality of service. In some embodiments, the FDR reports a detailed level of service utilization broken down by network type (eg, 2G, 3G, 4G, WiFi, etc.). In other embodiments, the FDR reports a detailed level of service utilization broken down by roaming or home network.
In some embodiments, the FDRs originate from a network element capable of classifying the traffic (eg, the source is a Deep Packet Inspection [DPI] gateway, a proxy server, a gateway, or a dedicated classification server. of the service given, etc.). In other embodiments, the FDRs are derived from a device service monitor. In some embodiments, the FDRs are derived from a service monitor of the contrasted device. In some embodiments, the service monitor of the tested device is located in an environment of
257
<img file="MX336960B_D0257.tif" />
safe execution, on the device, which cannot be accessed by the user or application software installed by the user.
In some embodiments, the FDRs report not only the use of the service that is attempted and allowed by a device, but also the use of the service that is attempted and not allowed by a device. In other embodiments, an FDR record reporting service utilization, which is attempted but not allowed, may include the various classification capabilities described herein. In this way, an FDR record can not only detect global service utilization or classified service utilization for an application, website, network type, etc., but it can also detect when a user is trying to access services. for global services or classified services for an application, website, network type, etc.
In some embodiments, the micro-CDR utilization accounting, derived from the network utilization monitoring sources, is fed back to a user service utilization notification function in a device service processor in order to to provide a disaggregated service utilization classification for website services and
258
ΙΊΑ Μ -¡τ
BÍFi
MEXICAN INSTITUTE OF IA PROPERTY
INDUSTRIAL
<img file="MX336960B_D0258.tif" />
user-paid applications or sponsored website or application services. This path is indicated in Figure 25 by the connection, in dashed lines, from the 2680 micro-CDR generator to the 2688 device's message queue and the subsequent processing and transmission of a service utilization classification update. micro-CDR to the device service processor through the 2686 notification and offer set gateway.
In some embodiments, the service processor is configured to display one or more service plan offers to the end user of the device and the timing of this display is determined by what the user is doing with the device. (eg, the user tries to access the network, an application on the device tries to access the network, a given application or a set of applications is used or attempted to be used, the device enters a roaming state, etc.). In other embodiments, the service controller determines when said service offers are to be displayed to the user of the device by detecting what the user is doing with the device. In other embodiments, the service controller detects what the user is doing with the device by looking at the access models or access models.
259
<img file="MX336960B_D0259.tif" />
Ha JLviL JL hee. MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX336960B_D0260.tif" />
access attempted in the FDRs or micro-CDRs registers In some embodiments, the service controller observes the FDRs registers that report an access service attempt from the device that was denied and this circumstance triggers the service processor to initiate a message notification of the device providing a service offer and the service offer notification is transmitted through the offer and notification set gateway 2686. In some embodiments, the service controller looks at the FDRS records that report an access service attempt from the device for a service utilization classification, such as an application or website that was denied and this circumstance triggers the service processor to initiate a notification message from the device that provides a service offering for an application service or a website service and transmits the notification of the offer of services through the gateway of offers and notification sets 2686.
In some embodiments, the interface protocols for the 2686 notification and offer set gateway may be exposed to application developers or device OEMs in the form of an API. In other embodiments, the API for the
260
<img file="MX336960B_D0261.tif" />
offerings and nofei'Éioaoion gateway — 3-686 provides a uniform means for developers of OS operating system software or device application software to perform writing of various application software that can use a uniform interface to demand , from a service controller, a list of the service offerings that are available for a device and display the list to the user interface of the device. In other embodiments, a list of service offerings that have been made available to a group of devices or a group of users is created using a service design center user interface, stored in a SDC database. and edited for the 2686 notification and offer set gateway API. In other embodiments, the service plan execution policies for one or more of the network access permissions or traffic control, limitations on the use of the service, accounting or billing for the use of the service or notification of the use of the service. they can also be configured in the 2690 service design center. In other embodiments, the API for the 2686 notification and offer set gateway provides a uniform means for developers of OS operating system software or device application software to perform the application.
Τ M 'writing of various programs
261
<img file="MX336960B_D0262.tif" />
• M.
MEXICAN INSTITUTE
OF THE PROPERTY 1% industrial. Indications that can use a uniform interface to provide the options of the user's service plan for the acquisition or activation of the service in a UI interface of the device, collect the user's option and transmit the user's option to a service controller which then activates the new service for the device. In other embodiments, the available service plan listing or service plan purchase or activation of the API user selection components for the offer and notification set gateway 2 686 is created with an XML interface . In other embodiments, the listing of the available service plan or the purchase of the service plan or activation of the user selection components of the 2686 notification and offer set gateway API is offered over a secure connection from the Web.
In some embodiments, the interface protocols for the offer and notification set gateway 2686 may be exposed to sponsored device providers or sponsored application providers in the form of an API. In other embodiments, the API for the notification and offer set gateway 2686 provides a uniform means for sponsored service providers to develop a
262
<img file="MX336960B_D0263.tif" />
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX336960B_D0264.tif" />
device application software or OS operating system software that can use a uniform interface to demand, from a service controller, the activation of a sponsored service plan for the device from a service controller. In other embodiments, the sponsored service plan offered and activated through the API is to sponsor all access to the device. In some embodiments, the sponsored service plan offered and activated through the API is for sponsoring an application or a group of applications. In other embodiments, the service plan sponsored, offered, and activated through the API is for sponsoring a website or group of websites. In some embodiments, the API for the 2686 notification and offer set gateway provides a uniform means for developers of sponsored device application software or OS operating system software to write various application software that can use a uniform interface to activate a sponsored service plan for your device, app, or website.
In some embodiments, the interface protocols for the offer and notification set gateway 2686 may be exposed to developers of
263
<img file="MX336960B_D0265.tif" />
OEMs or applications of the device in the form of an API that provides a uniform interface to device application software or OS operating system software to request updates to service utilization information from a service controller. In other embodiments, service utilization information updates are provided by the service controller in the global service utilization form. In other embodiments, the service utilization information updates are provided by the service controller in the form of service utilization classification or micro-CDR service utilization updates. In some embodiments, a user software application of the OS device or function is configured to use a uniform interface to obtain service utilization updates from a service controller and to display utilization updates. of the service for a device user interface. In some embodiments, the service utilization update displayed for the device UI is in the form of a gauge, meter, bar, amount used, amount remaining, percentage used, or percentage remaining. In other forms of
264
<img file="MX336960B_D0266.tif" />
In realization, a device user software application or function of the OS operating system is configured to use a uniform interface in order to obtain service utilization updates for a service utilization classification (eg, an application rating or website rating or other rating) from a service controller and to display service utilization updates for a device user interface. In some embodiments, a group of one or more service usage notifications, to be provided by the API for the notification and offer set gateway 2686 to devices that belong to a device group, or to a user group , are created using a service design center user interface, memorized in the SDC 2692 database and edited for the 2686 notification and offer set gateway API. In other embodiments, the service plan notification policies (eg, the conditions that operatively initiate a given service utilization notification and the content of the notification information) may also be configured in the 2692 service design center. In some embodiments, the API service utilization notification interface component for the offer set gateway and
265
<img file="MX336960B_D0267.tif" />
to. JlWa
MEXICAN INSTITUTE
OF THE PROPERTY _ an interface In other components of ”* · iñtéFFcL? <sup>1</sup> Do you 'service nara API for notification 2686 is created with realizations, notification of use of the gateway of the set of offers and notification 2686 is offered through a secure connection of the web.
In other embodiments, the API for the offer and notification set gateway 2686 comprises a secure interface that can only be accessed by providing a device credential corresponding to a known device or user account on the network (eg, a credential of SIM card, an IMSI, a phone number, an MDID, an API communication with signature, an encrypted API communication or other form of secure device agent communication with the API). In other embodiments, the API for the offer and notification set gateway 2686 comprises a secure interface that can only be accessed by providing a user credential corresponding to a known device or user account on the network (eg, a PIN number of the username, password, answer to a secure question, biometric credential or other secure user credential available, in general, only for a device user or an entity verified by the device user). In other embodiments, the 2686 notification and offer set gateway API
266
Μ
ΙΙΊ, ι ΙΤυ. O MEXICANO r Do oA í'ROPitPAD INDUSTRIAL
<img file="MX336960B_D0268.tif" />
intrusion, encrypted, device or comprises a secure interface that -ri ^ -pi-A ° q can access by providing an application credential (eg, application certificate, signature, communication information with signature, encrypted message communication or other credential application that identifies, in a secure way, an application or function of the operating system OS) corresponding to a known application that is allowed access to the API for the 2686 notification and offer set gateway. In other embodiments, a software application operating system function OS must provide a secure device credential, secure application credential, or secure user credential in accordance with a predefined API format 15 suitable for obtaining information from service utilization notification from API for 2686 notification and offer set gateway. In other embodiments, a device software application or function of the OS operating system must provide a secure device credential, secure application credential, or secure user credential, in accordance with a suitable predefined API format to obtain service offer set information from the API for the offer set gateway and 2686 notification. In some embodiments, a • ¡ί -. 'Λ »·
267
<img file="MX336960B_D0269.tif" />
Device software application or an OS operating system function must provide a secure device credential, secure application credential, or secure user credential, in accordance with a predefined API format suitable for communicating plan selection information. user services to the 2686 notification and offer set gateway API. In some embodiments, a device software application or OS operating system function must provide a secure device credential, secure application credential, or secure user credential to the API for the notification and offer set gateway. 2686 for the purpose of receiving sponsored service. In other embodiments, the API for the offer and notification set gateway 2686 comprises a secured XML interface. In other embodiments, the API for the offer and notification set gateway 2686 comprises a secure web connection.
Although the above embodiments have been described, in some detail, for the purposes of clarity of understanding, the invention is not limited to the details provided. There are numerous alternative ways of practicing the invention. The disclosed embodiments are illustrative and not restrictive.
It is stated that in relation to this date, the best
268
<img file="MX336960B_D0270.tif" />
The method known to the applicant to carry out said invention is the one that is clear from the present description of the invention.
Contents102
327 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73 Sheet 74 Sheet 75 Sheet 76 Sheet 77 Sheet 78 Sheet 79 Sheet 80 Sheet 81 Sheet 82 Sheet 83 Sheet 84 Sheet 85 Sheet 86 Sheet 87 Sheet 88 Sheet 89 Sheet 90 Sheet 91 Sheet 92 Sheet 93 Sheet 94 Sheet 95 Sheet 96 Sheet 97 Sheet 98 Sheet 99 Sheet 100 Sheet 101 Sheet 102 Sheet 103 Sheet 104 Sheet 105 Sheet 106 Sheet 107 Sheet 108 Sheet 109 Sheet 110 Sheet 111 Sheet 112 Sheet 113 Sheet 114 Sheet 115 Sheet 116 Sheet 117 Sheet 118 Sheet 119 Sheet 120 Sheet 121 Sheet 122 Sheet 123 Sheet 124 Sheet 125 Sheet 126 Sheet 127 Sheet 128 Sheet 129 Sheet 130 Sheet 131 Sheet 132 Sheet 133 Sheet 134 Sheet 135 Sheet 136 Sheet 137 Sheet 138 Sheet 139 Sheet 140 Sheet 141 Sheet 142 Sheet 143 Sheet 144 Sheet 145 Sheet 146 Sheet 147 Sheet 148 Sheet 149 Sheet 150 Sheet 151 Sheet 152 Sheet 153 Sheet 154 Sheet 155 Sheet 156 Sheet 157 Sheet 158 Sheet 159 Sheet 160 Sheet 161 Sheet 162 Sheet 163 Sheet 164 Sheet 165 Sheet 166 Sheet 167 Sheet 168 Sheet 169 Sheet 170 Sheet 171 Sheet 172 Sheet 173 Sheet 174 Sheet 175 Sheet 176 Sheet 177 Sheet 178 Sheet 179 Sheet 180 Sheet 181 Sheet 182 Sheet 183 Sheet 184 Sheet 185 Sheet 186 Sheet 187 Sheet 188 Sheet 189 Sheet 190 Sheet 191 Sheet 192 Sheet 193 Sheet 194 Sheet 195 Sheet 196 Sheet 197 Sheet 198 Sheet 199 Sheet 200 Sheet 201 Sheet 202 Sheet 203 Sheet 204 Sheet 205 Sheet 206 Sheet 207 Sheet 208 Sheet 209 Sheet 210 Sheet 211 Sheet 212 Sheet 213 Sheet 214 Sheet 215 Sheet 216 Sheet 217 Sheet 218 Sheet 219 Sheet 220 Sheet 221 Sheet 222 Sheet 223 Sheet 224 Sheet 225 Sheet 226 Sheet 227 Sheet 228 Sheet 229 Sheet 230 Sheet 231 Sheet 232 Sheet 233 Sheet 234 Sheet 235 Sheet 236 Sheet 237 Sheet 238 Sheet 239 Sheet 240 Sheet 241 Sheet 242 Sheet 243 Sheet 244 Sheet 245 Sheet 246 Sheet 247 Sheet 248 Sheet 249 Sheet 250 Sheet 251 Sheet 252 Sheet 253 Sheet 254 Sheet 255 Sheet 256 Sheet 257 Sheet 258 Sheet 259 Sheet 260 Sheet 261 Sheet 262 Sheet 263 Sheet 264 Sheet 265 Sheet 266 Sheet 267 Sheet 268 Sheet 269 Sheet 270 Sheet 271 Sheet 272 Sheet 273 Sheet 274 Sheet 275 Sheet 276 Sheet 277 Sheet 278 Sheet 279 Sheet 280 Sheet 281 Sheet 282 Sheet 283 Sheet 284 Sheet 285 Sheet 286 Sheet 287 Sheet 288 Sheet 289 Sheet 290 Sheet 291 Sheet 292 Sheet 293 Sheet 294 Sheet 295 Sheet 296 Sheet 297 Sheet 298 Sheet 299 Sheet 300 Sheet 301 Sheet 302 Sheet 303 Sheet 304 Sheet 305 Sheet 306 Sheet 307 Sheet 308 Sheet 309 Sheet 310 Sheet 311 Sheet 312 Sheet 313 Sheet 314 Sheet 315 Sheet 316 Sheet 317 Sheet 318 Sheet 319 Sheet 320 Sheet 321 Sheet 322 Sheet 323 Sheet 324 Sheet 325 Sheet 326 Sheet 327
882 members in 15 offices
Priority claims23
| Document | Office | Kind | Date |
|---|---|---|---|
| 38502010 | United States of America | P | |
| 61385020 | United States of America | – | |
| 41850910 | United States of America | P | |
| 61418509 | United States of America | – | |
| 42257410 | United States of America | P | |
| 61422574 | United States of America | – | |
| 13229580 | United States of America | – | |
| 201113229580 | United States of America | A | |
| 13237827 | United States of America | – | |
| 201113237827 | United States of America | A | |
| 2011052662 | United States of America | W | |
| 13229580 | – | – | – |
| 13237827 | – | – | – |
| 61385020 | – | – | – |
| 61418509 | – | – | – |
| 61422574 | – | – | – |
| US1152662 | – | – | – |
| US20100385020P | – | – | – |
| US20100418509P | – | – | – |
| US20100422574P | – | – | – |
| US201113229580 | – | – | – |
| US201113237827 | – | – | – |
| WO2011US52662 | – | – | – |
Members882
| Document | Office | Kind | |
|---|---|---|---|
| CA2562469A1 | Canada | A1 | |
| EP1773005A1 | European Patent Office (EPO) | A1 | |
| US2007081547A1 | United States of America | A1 | |
| US7480042B1 | United States of America | B1 | |
| EP1773005B1 | European Patent Office (EPO) | B1 | |
| AT440426T | Austria | T | |
| ATE440426T1 | Austria | T1 | |
| DE602005016123D1 | Germany | D1 | |
| EP1773005B8 | European Patent Office (EPO) | B8 | |
| US7742164B1 | United States of America | B1 | |
| US2010188975A1 | United States of America | A1 | |
| US2010188990A1 | United States of America | A1 | |
| US2010188991A1 | United States of America | A1 | |
| US2010188992A1 | United States of America | A1 | |
| US2010188993A1 | United States of America | A1 | |
| US2010188994A1 | United States of America | A1 | |
| US2010188995A1 | United States of America | A1 | |
| US2010190470A1 | United States of America | A1 | |
| US2010191575A1 | United States of America | A1 | |
| US2010191576A1 | United States of America | A1 | |
| US2010191604A1 | United States of America | A1 | |
| US2010191612A1 | United States of America | A1 | |
| US2010191613A1 | United States of America | A1 | |
| US2010191846A1 | United States of America | A1 | |
| US2010191847A1 | United States of America | A1 | |
| US2010192120A1 | United States of America | A1 | |
| US2010192170A1 | United States of America | A1 | |
| US2010192207A1 | United States of America | A1 | |
| US2010192212A1 | United States of America | A1 | |
| CA2786746A1 | Canada | A1 | |
| CA2786749A1 | Canada | A1 | |
| CA2786752A1 | Canada | A1 | |
| CA2786815A1 | Canada | A1 | |
| CA2786825A1 | Canada | A1 | |
| CA2786828A1 | Canada | A1 | |
| CA2786830A1 | Canada | A1 | |
| CA2786832A1 | Canada | A1 | |
| CA2786864A1 | Canada | A1 | |
| CA2786865A1 | Canada | A1 | |
| CA2786868A1 | Canada | A1 | |
| CA2786870A1 | Canada | A1 | |
| CA2786873A1 | Canada | A1 | |
| CA2786875A1 | Canada | A1 | |
| CA2786876A1 | Canada | A1 | |
| CA2786878A1 | Canada | A1 | |
| CA2786881A1 | Canada | A1 | |
| CA2786884A1 | Canada | A1 | |
| CA2786886A1 | Canada | A1 | |
| CA2786887A1 | Canada | A1 | |
| CA2786892A1 | Canada | A1 | |
| CA2786893A1 | Canada | A1 | |
| CA2786894A1 | Canada | A1 | |
| CA2786899A1 | Canada | A1 | |
| CA2787061A1 | Canada | A1 | |
| CA2787066A1 | Canada | A1 | |
| CA3055366A1 | Canada | A1 | |
| US2010195503A1 | United States of America | A1 | |
| US2010197266A1 | United States of America | A1 | |
| US2010197267A1 | United States of America | A1 | |
| US2010197268A1 | United States of America | A1 | |
| US2010198698A1 | United States of America | A1 | |
| US2010198939A1 | United States of America | A1 | |
| US2010199325A1 | United States of America | A1 | |
| US7778269B2 | United States of America | B2 | |
| US2010223600A1 | United States of America | A1 | |
| US2010272079A1 | United States of America | A1 | |
| CA2764888A1 | Canada | A1 | |
| DE102009030492A1 | Germany | A1 | |
| US2011085168A1 | United States of America | A1 | |
| AU2010208183A1 | Australia | A1 | |
| AU2010208294A1 | Australia | A1 | |
| AU2010208296A1 | Australia | A1 | |
| AU2010208297A1 | Australia | A1 | |
| AU2010208314A1 | Australia | A1 | |
| AU2010208316A1 | Australia | A1 | |
| AU2010208317A1 | Australia | A1 | |
| AU2010208483A1 | Australia | A1 | |
| AU2010208484A1 | Australia | A1 | |
| AU2010208485A1 | Australia | A1 | |
| AU2010208486A1 | Australia | A1 | |
| AU2010208488A1 | Australia | A1 | |
| AU2010208489A1 | Australia | A1 | |
| AU2010208543A1 | Australia | A1 | |
| AU2010208544A1 | Australia | A1 | |
| AU2010208545A1 | Australia | A1 | |
| AU2010208546A1 | Australia | A1 | |
| AU2010208547A1 | Australia | A1 | |
| AU2010208551A1 | Australia | A1 | |
| AU2010208552A1 | Australia | A1 | |
| AU2010208553A1 | Australia | A1 | |
| AU2010208554A1 | Australia | A1 | |
| AU2010208556A1 | Australia | A1 | |
| AU2010208557A1 | Australia | A1 | |
| AU2010208558A1 | Australia | A1 | |
| AU2010208565A1 | Australia | A1 | |
| US8023425B2 | United States of America | B2 | |
| KR20110108416A | Republic of Korea | A | |
| KR20110110360A | Republic of Korea | A | |
| KR20110110829A | Republic of Korea | A | |
| KR20110110830A | Republic of Korea | A |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 336960
- Publication, DOCDB
- 336960
- Publication, EPODOC
- MX336960
- Application
- 2013003138
- Application, DOCDB
- 2013003138
- Application, EPODOC
- MX20130003138
Titles2
- Spanish
- CONJUNTO DE SERVICIO DE OFERTA DE PUBLICIDAD A UN AGENTE DE DISPOSITIVO CON SELECCION DE SERVICIO EN DISPOSITIVO.
- English
- SET OF ADVERTISING OFFERING SERVICE TO A DEVICE AGENT WITH DEVICE SERVICE SELECTION.
Classification
- CPC, 14
- H04M15/41
- H04M15/44
- H04L65/00
- H04M15/42
- H04M15/53
- H04M15/73
- H04M15/8022
- H04W4/24
- H04M15/805
- H04M15/82
- G06Q30/04
- H04M15/80
- H04M15/8044
- H04L67/04
- IPC, 3
- H04M15 00
- H04W4 00
- H04W4 24