Prosecution Insights
Last updated: August 04, 2026
Application No. 17/421,724

METHOD AND APPARATUS FOR SECURITY

Non-Final OA §102§112
Filed
Jul 08, 2021
Priority
Jan 14, 2019 — nonprovisional of PCTCN2019071602
Examiner
SHOLEMAN, ABU S
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
Telefonaktiebolaget LM Ericsson
OA Round
5 (Non-Final)
79%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
617 granted / 785 resolved
+20.6% vs TC avg
Strong +27% interview lift
Without
With
+27.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
36 currently pending
Career history
830
Total Applications
across all art units

Statute-Specific Performance

§101
1.6%
-38.4% vs TC avg
§103
89.3%
+49.3% vs TC avg
§102
2.8%
-37.2% vs TC avg
§112
4.7%
-35.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 785 resolved cases

Office Action

§102 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 09/25/2025 has been entered. Response to Arguments Applicant’s arguments with respect to claim(s) are rejected under 103 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Applicant argued in the remark that Patel may show a 3GPP system, but fails to discloses a 3GPP 5G system that employs a Network Exposure Function(NEF) and an Authentication Service Function(AUSF) in the 5G code. Examiner reposefully disagrees. ITO US 2020/0280849 discloses [0002] In 3GPP (3rd Generation Partnership Project), specifications of a communication system called 5G (hereinafter, referred to as 5GS (5G System)) have been considered. The 5GS includes 3GPP Access. [0132] In FIG. 18, a security key KAUSF and a KSEAF are derived, in the UDM 37, from an integrity protection key IK and a cipher key CK without execution of a 5G-AKA. Applicant argued in the remark that there is no separate provisioning of session keys, instead the claimed techniques users the 5G primary authentication procedure executed during the UE registration of the 3GPP 5G network to authenticate the UE. Examiner respectfully disagrees. ITO US 2020/0280849 discloses [0085] The AMF 33 performs mobility management related to the UE 30. Further, the AMF 33 performs authentication processing related to the UE 30 in cooperation with the AUSF 36 and the UDM 37. The SMF 34 performs session management related to the UE 30. The UPF 35 relays U (User)-Plane data transmitted between the UE 30 and the Data Network 39. The U-Plane data may be referred to as user data. [0179] Next, the AMF 33 derives a security key KN3IWF related to Non-3GPP Access (S135). The security key KN3IWF is transmitted to the N3IWF 38. Next, the AMF 33 transmits a Create session request to a Target SMF 34_2 based on the received SM context. Further, the Target SMF 34_2 allocates resources for the session and transmits a Create session response to the AMF 33 (S136). 0180] Subsequently, the AMF 33 transmits the HO request to the N3IWF 38 (S137). The AMF 33 may select the N3IWF 38 based on the identification information transmitted from the UE 30. The HO request may include information on session and bearer establishment. In addition, the HO request may include a security context, security key identification information (KSI or KSI Set Identifier), information indicating whether required security configurations are necessary, and an algorithm to be used. The security configurations may be information on integrity protection and encryption. [0327] a key derivation unit configured to derive EMSK (Extended Master Session Key) during EAP-TLS (Extended Master Session Key) authentication processing; and [0331] an acquisition unit configured to acquire EMSK (Extended Master Session Key) during EAP-TLS (Extended Master Session Key) authentication processing. Specification The abstract of the disclosure is objected to because the use of the term 3GPP, which is a trade name or a mark used in commerce, has been noted in this application. The term should be accompanied by the generic terminology; furthermore the term should be capitalized wherever it appears or, where appropriate, include a proper symbol indicating use in commerce such as ™, SM , or ® following the term. Although the use of trade names and marks used in commerce (i.e., trademarks, service marks, certification marks, and collective marks) are permissible in patent applications, the proprietary nature of the marks should be respected and every effort made to prevent their use in any manner which might adversely affect their validity as commercial marks. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 23,26-30,34,36,41,44,46,61 and 63 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 23/44/61 and 63 are contains the trademark/trade name 3GPP. Where a trademark or trade name is used in a claim as a limitation to identify or describe a particular material or product, the claim does not comply with the requirements of 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph. See Ex parte Simpson, 218 USPQ 1020 (Bd. App. 1982). The claim scope is uncertain since the trademark or trade name cannot be used properly to identify any particular material or product. A trademark or trade name is used to identify a source of goods, and not the goods themselves. Thus, a trademark or trade name does not identify or describe the goods associated with the trademark or trade name. In the present case, the trademark/trade name is used to identify/describe in the specification and, accordingly, the identification/description is indefinite. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 23,26-30,34,36,41,44,46,61 and 63 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Ito et al US 2020/0280849. As per claim 23. Ito discloses a method implemented at a first network function (NF) of a core network of a 3rd Generation Partnership Project (3GPP) Fifth Generation (5G) wireless communication system (0002 The 5GS includes 3GPP Access and Non-3GPP Access as an access network.), wherein at least one share key is generated during a mutual authentication procedure between the core network and a user equipment (UE) to authorize the UE access to the 3GPP 5G wireless communication system ( [0137] FIG. 23 shows that a Key Hierarchy supports an EAP-TLS (Extensible Authentication Protocol-Transport Layer Security). A PMK (Pre Master Key) is derived from the key security key K by execution of an EAP-TLS based on PSK (Pre-Shared Key). Subsequently, keys MSK and EMSK are derived from the key PMK by execution of EAP-TLS based on Certificates. Next, the UDM 37 derives a security key KSEAF from the key MSK, and further derives a security key KAUSF from the key MSK. The keys MSK and EMSK may be derived from the security key K by execution of the EAP-TLS based on PSK. In the EAP-TLS based on PSK, a PSK ID is transmitted from the UE as a part of the UE Security Capabilities in a registration request. The security key K may be PSK.) and wherein a key material is based on the at least one share key-is stored in a second NF of the core network and in the UE for use in secure communication between an application function (AF) and the UE, in which the first NF is a Network Exposure Function (NEF) and the second NF is an Authentication Service Function (AUSF) ( [0140] First, the AMF 33 transmits a 5G-AIR (5G-Authentication Identifier Request) to the AUSF 36 (S31). The 5G-AIR includes an SUCI (Subscription Concealed Identifier) related to the UE 30. Next, the AUSF 36 executes de-concealment of the SUCI with the UDM 37 in order to obtain a SUPI (Subscription Permanent Identifier). Specifically, the AUSF 36 transmits the SUCI to the UDM 37. Further, the UDM 37 retrieves the SUPI from the SUCI. [0141] Then, the UDM 37 transmits the SUPI to the AUSF 36. [0142] Subsequently, the AUSF 36 retrieves a transformed AV or AV* (S33). The transformed AV includes RAND, AUTN, and XRES*. The AV* includes RAND, AUTN, XRES*, and security key KSEAF. Next, the AUSF 36 calculates HXRES* (Hash XRES) (S34). For example, the AUSF 36 calculates the HXRES* related to the XRES* using SHA-256 as a hash function). the method comprising: receiving a request, at the core network, from an application function (AF) the AF for the key material, wherein the request includes a key deriving input parameter to identify the key material (0128 N1 message is transmitting information on the access network, which is used by the UE 30 , i.e. application function AF and an N1 message is used in steps S21 and S23 instead of the NAS SMC message and the NAS Security Mode Complete message in FIG. 15. The N1 message transmitted in step S21 includes a 5G KSI, an N1-instance-indicator, a Parameters to derive NAS integrity and encryption keys, and an N1-MAC. The N1 message from the application NAS of the UE sends the parameters, i.e. to the NAS, i.e. core network/ network work function); obtaining the key material from the second NF based on the key deriving input parameter, wherein the key material is obtained in response to sending a request or subscription to the second NF (0133 in the AUSF 36, i.e. second NF, a security key KSEAF is derived from the security key KAUSF. 0131 deriving the security key KSEAF, will be described with reference to FIG. 17. In the UDM 37, an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key) are derived from a security key K. Subsequently, a security key KAUSF is derived, in the UDM 37, from the integrity protection key IK and the cipher key CK by execution of a 5G-AKA. In the UDM 37, a KSEAF is derived from the integrity protection key IK and the cipher key CK. Wherein the AUSF second NF derived the a security key from the parameters of the N1 message and [0136] In FIG. 22, a security key KAUSF is derived, in the UDM 37, from an integrity protection key 5G-IK and a cipher key 5G-CK by execution of a 5G-AKA from an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key). Subsequently, a security key KASME and an EKASME are derived, in the AUSF 36, from the integrity protection key 5G-IK and the cipher key 5G-CK. Next, a security key KSEAF is derived, in the AUSF 36, from the security key KASME. ); and providing the key material to the AF for the AF to communicate with an application client of the UE, wherein the application client of the UE uses the key material stored in the UE(0155 the AUSF 36 transmits, i.e. providing, a 5G-AIA to the AMF 33 (S66). The 5G-AIA includes HXRES, RAND, and indicator for use of KAUSF. Subsequently, the AMF 33 transmits, i.e. providing an Auth-Req to the UE 30 (S67). The Auth-Req includes RAND and Indicator for use of KAUSF and [0162] Next, the AMF 33 transmits an Auth-Req to the UE 30 (S83). The Auth-Req includes RAND, AUTN, AV-ID, and Re-auth type. Subsequently, the UE 30 performs Network authentication (S84). Subsequently, the UE 30 transmits an Auth-Res to the AMF 33 (S85). The Auth-Res includes RES*. The RES* is calculated in step S84). As per claim 26. Ito discloses the method according to claim 23, wherein the request or subscription includes the key deriving input parameter ( [0187] Next, the Target AMF 33_2 transmits a 5G-AIR to the AUSF 36 (S172). The 5G-AIR includes a 5G-GUTI/SUCI/SUPI. Further, the 5G-AIR includes AV ID and SN name. Next, the AUSF 36 executes a de-concealment of SUCI with the UDM 37 to obtain a SUPI (Subscription Permanent Identifier) (S173).). As per claim 27. Ito discloses the method according to claim 23, further comprising; determining: whether the AF is permitted to access a network exposure service for the UE ( [0161] The AN type is information indicating an access network. The authentication restrictions are information on an authentication method supported by the UE 30 or an authentication method permitted by the UE 30. For example, the authentication method supported by the UE 30 may be EAP-TLS based on certificates.); whether derivation of the key material is supported for the UE([0074] The communication terminal 10 includes a communication unit 11 and a key derivation unit 12. The communication unit 11 and the key derivation unit 12 may be software or modules in which processing is executed by a processor executing a program stored in a memory. Alternatively, the communication unit 11 and the key derivation unit 12 may be hardware such as a circuit or a chip); whether the derivation of the key material is permitted for the key deriving input parameter; or any combination thereof([0076] The key derivation unit 12 derives a security key for gateway device used for security processing of a message transmitted using a defined protocol with the gateway device. The key derivation unit 12 derives a security key for gateway device from a security key for core network device used for security processing of a message transmitted using a defined protocol with the core network device). As per claim 28. Ito discloses the method according to claim 27, wherein said determining is based on subscription information of the UE( 0081 A UE 30 can communicate with an AMF 33 of the HPLMN or the VPLMN via both the HPLMN or the VPLMN and the Non-3GPP Access.). As per claim 29. Ito discloses the method according to claim 23, further comprising: discovering the second NF based on an identifier of the UE, the key deriving input parameter, or both the second NF based on the identifier of the UE and the key deriving input parameter (0123 transmitting information on the access network used by the UE 30 will be described below with reference to FIG. 15. First, the AMF 33 transmits a NAS SMC message to the UE 30 (S11). The NAS SMC message includes KSI (Key Set Identifier), Replayed UE Security capabilities, Allowed NSSAI (Network Slice Selection Assistance Information), NAS Algorithms, N1-instance-indicator, Parameters to derive NAS integrity and encryption keys, and NAS-MAC (NAS-Message Authentication Code). [0171] First, a Source AMF 33_1 transmits a Relocation Request to an AUSF 36 (S111). The Relocation Request includes 5G-GUTI, UE security capabilities, and old security key KSEAF. Next, the AUSF 36 derives a security key KSEAF* using old security key KSEAF, PLMN ID, PLMN count or SN count, and SN name (S112). For example, as shown in FIG. 33, when the old security key KSEAF, PLMN ID, PLMN count or SN count, and SN name are input to a KDF, the security key KSEAF* is derived.). As per claim 30. Ito discloses the method according to claim 29, wherein discovering the second NF based on the identifier of the UE, the key deriving input parameter, or both, comprises: sending a discovering request or subscription to a third NF, wherein the discovering request or subscription includes the identifier of the UE, the key deriving input parameter, or both ([0122] Subsequently, the UE 30 synchronizes the N3G_Count value using the value received from the AMF 33. Further, the UE 30 derives a security key using the synchronized N3G_Count value as an input parameter of the KDF. ); and receiving a response including information regarding the second NF from the third NF([0126] Subsequently, the UE 30 derives security keys KAMF, KNASint, and KNASenc using the received parameters (S12). Next, the UE 30 transmits a NAS Security Mode Complete message to the AMF 33 (S13). The NAS Security Mode Complete message includes a NAS-MAC and a Replayed allowed NSSAI). As per claim 34. Ito discloses the method according to claim 23, wherein the key deriving input parameter comprises: a type of the AF, an application type, an application identifier, a user identifier, an address of the UE, an association session, a context identifier, a disambiguating label string for key deriving, a random number, a key deriving domain, a key deriving function scheme, a type of the at least one share key, a date indication, a time indication, network specific information, or any combination thereof ( [0140] First, the AMF 33 transmits a 5G-AIR (5G-Authentication Identifier Request) to the AUSF 36 (S31). The 5G-AIR includes an SUCI (Subscription Concealed Identifier) related to the UE 30. Next, the AUSF 36 executes de-concealment of the SUCI with the UDM 37 in order to obtain a SUPI (Subscription Permanent Identifier). Specifically, the AUSF 36 transmits the SUCI to the UDM 37. Further, the UDM 37 retrieves the SUPI from the SUCI. And [0143] Next, the AUSF 36 transmits a 5G-AIA (5G-Authentication Identifier Answer) to the AMF 33 (S35). The 5G-AIA includes AV* or transformed AV, AV ID, and HXRES*. The AV ID is identification information for identifying the AV* or the transformed AV). As per claim 36. Ito discloses the method according to claim 23, wherein the at least one share key comprises: a key for an Authentication Server Function (AUSF) the AUSF, KAUSF,a key for SEcurity Anchor Function (SEAF), KSEAF,a key for Access and Mobility Management Function (AMF), KAMF,a key for a protection of Non-Access Stratum (NAS) signalling with a particular integrity algorithm, KNASint,a key for a protection of NAS signalling with a particular encryption algorithm, KNASenc,a key for Non-3rd Generation Partnership Project (Non-3GPP) access InterWorking Function, KN3IWF,a key for Next Generation Radio Access Network, KgNB,a key for a protection of Radio Resource Control (RRC) signalling with a particular integrity algorithm, KRRCint,a key for the protection of RRC signalling with a particular encryption algorithm,KRRCenc,a key for a protection of user plane (UP) traffic with a particular encryption algorithm,KUPint,a key for a protection of UP traffic between Mobile Equipment (ME) and gNB with a particular integrity algorithm, KuPenc, or any combination thereof ([0154] Next, the AUSF 36 retrieves a security key KAUSF corresponding to the UE 30 (S63). Subsequently, the AUSF 36 derives a new security key KSEAF using security keys KAUSF, PLMN ID, PLMN count or SN (Serving Network) count, and SN name (S64). Subsequently, the AUSF 36 calculates XRES using the security key KAUSF and the RAND, and further calculates HXRES (S65). And [0155] Next, the AUSF 36 transmits a 5G-AIA to the AMF 33 (S66). The 5G-AIA includes HXRES, RAND, and indicator for use of KAUSF. Subsequently, the AMF 33 transmits an Auth-Req to the UE 30 (S67). The Auth-Req includes RAND and Indicator for use of KAUSF. [0156] Next, the UE 30 calculates a new security key KSEAF using the security keys KAUSF, PLMN ID, PLMN count or SN count, and SN name (S68). Subsequently, the UE 30 calculates RES using the security key KAUSF and the RAND (S69). Subsequently, the UE 30 transmits an Auth-Res to the AMF 33 (S70). The Auth-Res includes RES. [0157] Next, the AMF 33 compares the HREX with the HXRES to determine whether the HRES and the HXRES coincide with each other (S72). The AMF 33 determines that the UE 30 is a valid UE when the HRES and the HXRES coincide with each other. Subsequently, the AMF 33 transmits a 5G-AC to the AUSF 36 (S73). The 5G-AC includes RES. [0158] Steps S64 and S68 may be omitted. In addition, steps S65 and S69 may be omitted when the AUSF 36 requests XRES from an ARPF (Authentication Credential Repository and Processing Function) entity. Further, when the security key KAUSF does not depend on SN, it can be used between PLMNs. When the security key KAUSF depends on the SN, the security key KAUSF can be used in the PLMN without using the security keys KAUSF, PLMN ID, PLMN count or SN count, and SN name). As per claim 41. Ito discloses a method implemented at a second network function (NF) of a core network of a 3rd Generation Partnership Project (3GPP) Fifth Generation (5G) wireless communication system ( 0002 The 5GS includes 3GPP Access and Non-3GPP Access as an access network), wherein at least one share key is generated during a mutual authentication procedure between the core network and a user equipment (UE) to authorize the UE access to the 3GPP 5G wireless communication system and wherein a key material is based on the at least one share key-is stored in the second NF of the core network and in the UE for use in secure communication between an application function (AF) and the UE, in which the second NF is an Authentication Service Function (AUSF)( [0137] FIG. 23 shows that a Key Hierarchy supports an EAP-TLS (Extensible Authentication Protocol-Transport Layer Security). A PMK (Pre Master Key) is derived from the key security key K by execution of an EAP-TLS based on PSK (Pre-Shared Key). Subsequently, keys MSK and EMSK are derived from the key PMK by execution of EAP-TLS based on Certificates. Next, the UDM 37 derives a security key KSEAF from the key MSK, and further derives a security key KAUSF from the key MSK. The keys MSK and EMSK may be derived from the security key K by execution of the EAP-TLS based on PSK. In the EAP-TLS based on PSK, a PSK ID is transmitted from the UE as a part of the UE Security Capabilities in a registration request. The security key K may be PSK( [0140] First, the AMF 33 transmits a 5G-AIR (5G-Authentication Identifier Request) to the AUSF 36 (S31). The 5G-AIR includes an SUCI (Subscription Concealed Identifier) related to the UE 30. Next, the AUSF 36 executes de-concealment of the SUCI with the UDM 37 in order to obtain a SUPI (Subscription Permanent Identifier). Specifically, the AUSF 36 transmits the SUCI to the UDM 37. Further, the UDM 37 retrieves the SUPI from the SUCI. [0141] Then, the UDM 37 transmits the SUPI to the AUSF 36. [0142] Subsequently, the AUSF 36 retrieves a transformed AV or AV* (S33). The transformed AV includes RAND, AUTN, and XRES*. The AV* includes RAND, AUTN, XRES*, and security key KSEAF. Next, the AUSF 36 calculates HXRES* (Hash XRES) (S34). For example, the AUSF 36 calculates the HXRES* related to the XRES* using SHA-256 as a hash function),the method, comprising: receiving a request or subscription from a first NF, which the first NF is a Network Exposure Function (NEF) of the core network, for the key material, wherein the key material is derived based on a key deriving input parameter sent by the AF and received by the first NF to identify the key material(0128 N1 message is transmitting information on the access network, which is used by the UE 30 , i.e. application function AF and an N1 message is used in steps S21 and S23 instead of the NAS SMC message and the NAS Security Mode Complete message in FIG. 15. The N1 message transmitted in step S21 includes a 5G KSI, an N1-instance-indicator, a Parameters to derive NAS integrity and encryption keys, and an N1-MAC. The N1 message from the application NAS of the UE sends the parameters, i.e. to the NAS, i.e. core network/ network work function and 0133 in the AUSF 36, i.e. second NF, a security key KSEAF is derived from the security key KAUSF. 0131 deriving the security key KSEAF, will be described with reference to FIG. 17. In the UDM 37, an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key) are derived from a security key K. Subsequently, a security key KAUSF is derived, in the UDM 37, from the integrity protection key IK and the cipher key CK by execution of a 5G-AKA. In the UDM 37, a KSEAF is derived from the integrity protection key IK and the cipher key CK. Wherein the AUSF second NF derived the a security key from the parameters of the N1 message and [0136] In FIG. 22, a security key KAUSF is derived, in the UDM 37, from an integrity protection key 5G-IK and a cipher key 5G-CK by execution of a 5G-AKA from an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key). Subsequently, a security key KASME and an EKASME are derived, in the AUSF 36, from the integrity protection key 5G-IK and the cipher key 5G-CK. Next, a security key KSEAF is derived, in the AUSF 36, from the security key KASME ); and providing the key material to the first NF for the first NF to provide the key material to the AF and for the AF to communicate with an application client of the UE, wherein the application client of the UE uses the key material stored in the UE( 0155 the AUSF 36 transmits, i.e. providing, a 5G-AIA to the AMF 33 (S66). The 5G-AIA includes HXRES, RAND, and indicator for use of KAUSF. Subsequently, the AMF 33 transmits, i.e. providing an Auth-Req to the UE 30 (S67). The Auth-Req includes RAND and Indicator for use of KAUSF and [0162] Next, the AMF 33 transmits an Auth-Req to the UE 30 (S83). The Auth-Req includes RAND, AUTN, AV-ID, and Re-auth type. Subsequently, the UE 30 performs Network authentication (S84). Subsequently, the UE 30 transmits an Auth-Res to the AMF 33 (S85). The Auth-Res includes RES*. The RES* is calculated in step S84). As per claim 44. Ito discloses the method according to claim 41, wherein the key deriving input parameter comprises: a type of the AF,an application type, an application identifier,a user identifier, an address of the UE, an association session, a context identifier,a disambiguating label string for key deriving, a random number, a key deriving domain,a key deriving function scheme,a type of the at least one share key, a date indication a time indication, network specific information, or any combination thereof ([0085] The AMF 33 performs mobility management related to the UE 30. Further, the AMF 33 performs authentication processing related to the UE 30 in cooperation with the AUSF 36 and the UDM 37. The SMF 34 performs session management related to the UE 30. The UPF 35 relays U (User)-Plane data transmitted between the UE 30 and the Data Network 39. The U-Plane data may be referred to as user data. And [0179] Next, the AMF 33 derives a security key KN3IWF related to Non-3GPP Access (S135). The security key KN3IWF is transmitted to the N3IWF 38. Next, the AMF 33 transmits a Create session request to a Target SMF 34_2 based on the received SM context. Further, the Target SMF 34_2 allocates resources for the session and transmits a Create session response to the AMF 33 (S136). And [0327] a key derivation unit configured to derive EMSK (Extended Master Session Key) during EAP-TLS (Extended Master Session Key) authentication processing; and [0331] an acquisition unit configured to acquire EMSK (Extended Master Session Key) during EAP-TLS (Extended Master Session Key) authentication processing; and ). As per claim 46. Ito discloses the method according to claim 41, wherein the at least one share key comprises: a key for an Authentication Server Function (AUSF) the AUSF, KAUSF,a key for SEcurity Anchor Function (SEAF), KSEAF, a key for Access and Mobility Management Function (AMF), KAMF, a key for a protection of Non-Access Stratum (NAS) signalling with a particular integrity algorithm, KNASint,a key for a protection of NAS signalling with a particular encryption algorithm, KNASenc,a key for Non-3rd Generation Partnership Project (Non-3GPP) access InterWorking Function, KN3IWF,a key for Next Generation Radio Access Network, KgNB,a key for a protection of Radio Resource Control (RRC) signalling with a particular integrity algorithm, KRRCint,a key for the protection of RRC signalling with a particular encryption algorithm,KRRCenc,a key for a protection of user plane (UP) traffic with a particular encryption algorithm,KUPint,a key for a protection of UP traffic between Mobile Equipment (ME) and gNB with a particular integrity algorithm, Kupenc, or any combination thereof ( 0088] A security key KgNB is used for security processing related to a message transmitted between the UE 30 and the gNB 31. A security key Knon-3gpp is used for security processing related to a message transmitted between the UE 30 and the N3IWF 38. A security key KAMF is used for security processing related to a message transmitted between the UE 30 and the AMF 33. [0089] Subsequently, a Key hierarchy according to the second example embodiment will be described with reference to FIG. 4. The Key hierarchy shown in FIG. 4 is applied to a multiple NAS (Non-Access Stratum) that enables the UE 30 to communicate with the AMF 33 via a plurality of access networks. In addition, the Key hierarchy shown in FIG. 4 indicates a security key generated in the UE 30 and the 5GC. [0090] The security key KSEAF is derived from a security key K that is mutually authenticated between the UE 30 and the AUSF 36. The security key K may be referred to as a long-term key. The security key KSEAF is transmitted to the AMF 33. The security key KAMF is derived from the security key KSEAF. A security key KNASint used for integrity protection and a security key KNASenc used for encryption are derived from the security key KAMF. The security key KNASint and the security key KNASenc may be referred to as a NAS security key. [0091] The security key KgNB is derived from the security key KAMF. A security key KRRCint, a security key KRRCenc, a security key KUPint, and a security key KUPenc are derived from the security key KgNB. The security key KRRCint and the security key KRRCenc are used to protect an RRC message transmitted between the UE 30 and the 3GPP Access 32. The security key KUPint and the security key KUPenc are used to protect U-Plane data transmitted between the UE 30 and the 3GPP Access 32. [0092] The security key Knon-3gpp is derived from the security key KAMF. The security key Knon-3gpp is used to protect a message transmitted between the UE 30 and the N3IWF 38. The security key KAMF and the KgNB may be updated at handover. In addition, the security key Knon-3gpp may be derived from the security key KSEAF ). As per claim 61. Ito discloses an apparatus implemented at a first network function (NF) of a core network of a 3rd Generation Partnership Project (3GPP) Fifth Generation (5G) wireless communication system (0002 The 5GS includes 3GPP Access and Non-3GPP Access as an access network), wherein at least one share key is generated during a mutual authentication procedure between the core network and a user equipment (UE) to authorize the UE access to the 3GPP 5G wireless communication system and wherein a key material is based on the at least one share key-is stored in a second NF of the core network and in the UE for use in secure communication between an application function (AF) and the UE ([0137] FIG. 23 shows that a Key Hierarchy supports an EAP-TLS (Extensible Authentication Protocol-Transport Layer Security). A PMK (Pre Master Key) is derived from the key security key K by execution of an EAP-TLS based on PSK (Pre-Shared Key). Subsequently, keys MSK and EMSK are derived from the key PMK by execution of EAP-TLS based on Certificates. Next, the UDM 37 derives a security key KSEAF from the key MSK, and further derives a security key KAUSF from the key MSK. The keys MSK and EMSK may be derived from the security key K by execution of the EAP-TLS based on PSK. In the EAP-TLS based on PSK, a PSK ID is transmitted from the UE as a part of the UE Security Capabilities in a registration request. The security key K may be PSK ), in which the first NF is a Network Exposure Function (NEF) and the second NF is an Authentication Service Function (AUSF), ( ( [0140] First, the AMF 33 transmits a 5G-AIR (5G-Authentication Identifier Request) to the AUSF 36 (S31). The 5G-AIR includes an SUCI (Subscription Concealed Identifier) related to the UE 30. Next, the AUSF 36 executes de-concealment of the SUCI with the UDM 37 in order to obtain a SUPI (Subscription Permanent Identifier). Specifically, the AUSF 36 transmits the SUCI to the UDM 37. Further, the UDM 37 retrieves the SUPI from the SUCI. [0141] Then, the UDM 37 transmits the SUPI to the AUSF 36. [0142] Subsequently, the AUSF 36 retrieves a transformed AV or AV* (S33). The transformed AV includes RAND, AUTN, and XRES*. The AV* includes RAND, AUTN, XRES*, and security key KSEAF. Next, the AUSF 36 calculates HXRES* (Hash XRES) (S34). For example, the AUSF 36 calculates the HXRES* related to the XRES* using SHA-256 as a hash function)the apparatus comprising: a processor; and a memory coupled to the processor, said memory containing instructions which, when executed by said processor, cause said apparatus to ( [0074] The communication terminal 10 includes a communication unit 11 and a key derivation unit 12. The communication unit 11 and the key derivation unit 12 may be software or modules in which processing is executed by a processor executing a program stored in a memory): receive a request, at the core network, from the AF for the key material, wherein the request includes a key deriving input parameter to identify the key material; ( 0128 N1 message is transmitting information on the access network, which is used by the UE 30 , i.e. application function AF and an N1 message is used in steps S21 and S23 instead of the NAS SMC message and the NAS Security Mode Complete message in FIG. 15. The N1 message transmitted in step S21 includes a 5G KSI, an N1-instance-indicator, a Parameters to derive NAS integrity and encryption keys, and an N1-MAC. The N1 message from the application NAS of the UE sends the parameters, i.e. to the NAS, i.e. core network/ network work function and 0133 in the AUSF 36, i.e. second NF, a security key KSEAF is derived from the security key KAUSF. 0131 deriving the security key KSEAF, will be described with reference to FIG. 17. In the UDM 37, an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key) are derived from a security key K. Subsequently, a security key KAUSF is derived, in the UDM 37, from the integrity protection key IK and the cipher key CK by execution of a 5G-AKA. In the UDM 37, a KSEAF is derived from the integrity protection key IK and the cipher key CK. Wherein the AUSF second NF derived the a security key from the parameters of the N1 message and [0136] In FIG. 22, a security key KAUSF is derived, in the UDM 37, from an integrity protection key 5G-IK and a cipher key 5G-CK by execution of a 5G-AKA from an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key). Subsequently, a security key KASME and an EKASME are derived, in the AUSF 36, from the integrity protection key 5G-IK and the cipher key 5G-CK. Next, a security key KSEAF is derived, in the AUSF 36, from the security key KASME) obtain, the key material from the second NF based on the key deriving input parameter, wherein the key material is obtained in response to sending a request or subscription to the second NF (0133 in the AUSF 36, i.e. second NF, a security key KSEAF is derived from the security key KAUSF. 0131 deriving the security key KSEAF, will be described with reference to FIG. 17. In the UDM 37, an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key) are derived from a security key K. Subsequently, a security key KAUSF is derived, in the UDM 37, from the integrity protection key IK and the cipher key CK by execution of a 5G-AKA. In the UDM 37, a KSEAF is derived from the integrity protection key IK and the cipher key CK. Wherein the AUSF second NF derived the a security key from the parameters of the N1 message and [0136] In FIG. 22, a security key KAUSF is derived, in the UDM 37, from an integrity protection key 5G-IK and a cipher key 5G-CK by execution of a 5G-AKA from an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key). Subsequently, a security key KASME and an EKASME are derived, in the AUSF 36, from the integrity protection key 5G-IK and the cipher key 5G-CK. Next, a security key KSEAF is derived, in the AUSF 36, from the security key KASME ); and provide the key material to the AF for the AF to communicate with an application client of the UE, wherein the application client of the UE to use the key material stored in the UE ( 0155 the AUSF 36 transmits, i.e. providing, a 5G-AIA to the AMF 33 (S66). The 5G-AIA includes HXRES, RAND, and indicator for use of KAUSF. Subsequently, the AMF 33 transmits, i.e. providing an Auth-Req to the UE 30 (S67). The Auth-Req includes RAND and Indicator for use of KAUSF and [0162] Next, the AMF 33 transmits an Auth-Req to the UE 30 (S83). The Auth-Req includes RAND, AUTN, AV-ID, and Re-auth type. Subsequently, the UE 30 performs Network authentication (S84). Subsequently, the UE 30 transmits an Auth-Res to the AMF 33 (S85). The Auth-Res includes RES*. The RES* is calculated in step S84). As per claim 63. Ito discloses an apparatus implemented at a second network function (NF) of a core network of a 3rd Generation Partnership Project (3GPP) Fifth Generation (5G) wireless communication system (0002 The 5GS includes 3GPP Access and Non-3GPP Access as an access network ), wherein at least one share key is generated during a mutual authentication procedure between the core network and a user equipment (UE) to authorize the UE access to the 3GPP 5G wireless communication system and wherein a key material is based on the at least one share key-is stored in the second NF of the core network and in the UE for use in secure communication between an application function (AF) and the UE ([0137] FIG. 23 shows that a Key Hierarchy supports an EAP-TLS (Extensible Authentication Protocol-Transport Layer Security). A PMK (Pre Master Key) is derived from the key security key K by execution of an EAP-TLS based on PSK (Pre-Shared Key). Subsequently, keys MSK and EMSK are derived from the key PMK by execution of EAP-TLS based on Certificates. Next, the UDM 37 derives a security key KSEAF from the key MSK, and further derives a security key KAUSF from the key MSK. The keys MSK and EMSK may be derived from the security key K by execution of the EAP-TLS based on PSK. In the EAP-TLS based on PSK, a PSK ID is transmitted from the UE as a part of the UE Security Capabilities in a registration request. The security key K may be PSK ), in which the second NF is an Authentication Service Function (AUSF) ([0140] First, the AMF 33 transmits a 5G-AIR (5G-Authentication Identifier Request) to the AUSF 36 (S31). The 5G-AIR includes an SUCI (Subscription Concealed Identifier) related to the UE 30. Next, the AUSF 36 executes de-concealment of the SUCI with the UDM 37 in order to obtain a SUPI (Subscription Permanent Identifier ), the apparatus comprising: a processor; and a memory coupled to the processor, said memory containing instructions which, when executed by said processor, cause said apparatus to ( [0074] The communication terminal 10 includes a communication unit 11 and a key derivation unit 12. The communication unit 11 and the key derivation unit 12 may be software or modules in which processing is executed by a processor executing a program stored in a memory): receive a request or subscription from a first NF, which the first NF is a Network Exposure Function (NEF) of the core network, for the key material, wherein the key material is derived based on a key deriving input parameter sent by the AF and received by the first NF to identify the key material (0128 N1 message is transmitting information on the access network, which is used by the UE 30 , i.e. application function AF and an N1 message is used in steps S21 and S23 instead of the NAS SMC message and the NAS Security Mode Complete message in FIG. 15. The N1 message transmitted in step S21 includes a 5G KSI, an N1-instance-indicator, a Parameters to derive NAS integrity and encryption keys, and an N1-MAC. The N1 message from the application NAS of the UE sends the parameters, i.e. to the NAS, i.e. core network/ network work function and 0133 in the AUSF 36, i.e. second NF, a security key KSEAF is derived from the security key KAUSF. 0131 deriving the security key KSEAF, will be described with reference to FIG. 17. In the UDM 37, an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key) are derived from a security key K. Subsequently, a security key KAUSF is derived, in the UDM 37, from the integrity protection key IK and the cipher key CK by execution of a 5G-AKA. In the UDM 37, a KSEAF is derived from the integrity protection key IK and the cipher key CK. Wherein the AUSF second NF derived the a security key from the parameters of the N1 message and [0136] In FIG. 22, a security key KAUSF is derived, in the UDM 37, from an integrity protection key 5G-IK and a cipher key 5G-CK by execution of a 5G-AKA from an integrity protection key IK (Integrity Key) and a cipher key CK (Cipher Key). Subsequently, a security key KASME and an EKASME are derived, in the AUSF 36, from the integrity protection key 5G-IK and the cipher key 5G-CK. Next, a security key KSEAF is derived, in the AUSF 36, from the security key KASME); and provide the key material to the first NF for the first NF to provide the key material to the AF and for the AF to communicate with an application client of the UE, wherein the application client of the UE to use the key material stored in the UE (0155 the AUSF 36 transmits, i.e. providing, a 5G-AIA to the AMF 33 (S66). The 5G-AIA includes HXRES, RAND, and indicator for use of KAUSF. Subsequently, the AMF 33 transmits, i.e. providing an Auth-Req to the UE 30 (S67). The Auth-Req includes RAND and Indicator for use of KAUSF and [0162] Next, the AMF 33 transmits an Auth-Req to the UE 30 (S83). The Auth-Req includes RAND, AUTN, AV-ID, and Re-auth type. Subsequently, the UE 30 performs Network authentication (S84). Subsequently, the UE 30 transmits an Auth-Res to the AMF 33 (S85). The Auth-Res includes RES*. The RES* is calculated in step S84). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABU S SHOLEMAN whose telephone number is (571)270-7314. The examiner can normally be reached EST: 9am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JORGE ORTIZ CRIADO can be reached at 571-272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ABU S SHOLEMAN/Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Show 7 earlier events
Mar 05, 2025
Non-Final Rejection mailed — §102, §112
Jun 05, 2025
Response Filed
Jun 25, 2025
Final Rejection mailed — §102, §112
Sep 25, 2025
Request for Continued Examination
Oct 02, 2025
Response after Non-Final Action
Apr 29, 2026
Non-Final Rejection mailed — §102, §112
Jul 24, 2026
Examiner Interview Summary
Jul 24, 2026
Applicant Interview (Telephonic)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689513
LEVERAGING USER'S VIRTUAL INTERACTIONS TO INFLUENCE PREFERRED MESSAGE COMMUNICATION TIMING
2y 7m to grant Granted Jul 21, 2026
Patent 12683784
DATA ANALYSIS SYSTEMS AND METHODS FOR DETECTING ANOMALIES IN TOKENIZED DATASETS
2y 11m to grant Granted Jul 14, 2026
Patent 12659742
ENSURING SECURE ATTACHMENT IN SIZE CONSTRAINED AUTHENTICATION PROTOCOLS
5y 0m to grant Granted Jun 16, 2026
Patent 12639471
IDENTITY BREACH NOTIFICATION AND REMEDIATION
2y 6m to grant Granted May 26, 2026
Patent 12591713
AUTOMATIC GENERATING ANALYTICS FROM BLOCKCHAIN DATA
4y 5m to grant Granted Mar 31, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+27.2%)
3y 0m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 785 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month