Prosecution Insights
Last updated: August 17, 2026
Application No. 17/982,943

SYSTEMS AND METHODS FOR SECURE USER SESSION AT ENDPOINT DEVICE OVER ACCESS-RESTRICTED CELLULAR NETWORK MANAGED BY AN ENTERPRISE

Non-Final OA §103
Filed
Nov 08, 2022
Examiner
AVERY, BRIAN WILLIAM
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
DELL PRODUCTS, L.P.
OA Round
3 (Non-Final)
60%
Grant Probability
Moderate
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 60% of resolved cases
60%
Career Allowance Rate
53 granted / 88 resolved
+2.2% vs TC avg
Strong +55% interview lift
Without
With
+55.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
19 currently pending
Career history
119
Total Applications
across all art units

Statute-Specific Performance

§101
2.2%
-37.8% vs TC avg
§103
71.3%
+31.3% vs TC avg
§102
9.1%
-30.9% vs TC avg
§112
15.9%
-24.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 88 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to the amendment filed on 3/03/2026. Claims 1-20 are currently pending in the filing of 3/03/2026, and claims 1-20 were pending in the previous filing of 5/13/2025. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 3/03/2026 has been entered. Response to Applicant’s Amendments / Arguments Regarding 35 U.S.C. § 103 The applicant’s remarks, on pages 9-21 of the response / amendment, the applicant argues the features which allegedly distinguish over the previously cited references cited in the 35 U.S.C. § 103 rejections. Applicant’s arguments have been considered but are moot in view of the new ground(s) of rejection. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over US 20220060893 to Gundavelli et al. (hereinafter Gundavelli), in view of US 20220104005 to Xiong et al. (hereinafter Xiong), in view of US 20220014900 to Gandhi et al. (hereinafter Gandhi). Regarding claim 1, Gundavelli teaches, A method of initiating a secure user session for a managed client information handling system through a restricted access secure wireless wide area network (WWAN), comprising: (fig. 1 and [0029] teach enterprise standalone non-public network (SNPN) wireless wide area (WWA) access network 130 requiring SNPN credentials.) executing code instructions, via hardware processing resources at an information technology (IT) management server, of a secure user session initiation system ([0021], [0023] and fig. 1, enterprise management system 121, which issues SNPN credentials, is part of enterprise network 120. [0044] teaches secure delivery of SNPN credential, for the enterprise network 120. [0106] teaches the eUICC 107 and enterprise applications 104 of UE 102 being used to communicate with enterprise server 120/123.) to secure access to an enterprise system corporate resource or to trusted internet protocol addresses (fig. 1, data networks 140, see also, [0016] describing enterprise data networks providing enterprise services and [0018] teaching services.) and limit other network accesses for a managed client information handling system; (fig. 1, data networks 140, which is accessed through enterprise SNPN WWA 130. [0018] teaching enterprise services, where the services are implemented through a private network.) receiving, at a network interface device (fig. 1, WWA 110) of the IT management server, security configuration settings for the managed client information handling system ([0035] teaches UE 102 connects through access network 110 to obtain SNPN credentials from enterprise network 120. Abstract teaches EAP in which the UE 102 connects to enterprise authentication server 123 / enterprise network 120 / “enterprise identity provider”, as shown in figs.1 & 2.) including an address of an enterprise identity provider, authorization to access an enterprise system corporate resource, and identification of a trusted internet protocol address; ([0036] teaches EAP-based secondary authentication using enterprise authentication server 123 / “enterprise identity provider”. [0037] teaches receiving SNPN credential objects including an eSIM profile and network identifier metadata to connect to SNPN WWA 130. [0041] teaches network identifier data being used to identify Data Network Name (DNN).) transmitting, via the network interface device, client information handling system security policies to a secure user session agent at the managed client information handling system ([0038] access network 110 is used to pass SNPN credentials between UE 102 and enterprise network 120.) identifying a selected restricted access secure WWAN carrier from a plurality of available restricted access secure WWAN carriers and instruction to initiate a secure user session on a restricted access secure WWAN link ([0037] teaches the SNPN credentials may be an eSIM profile and network identifier metadata to enable UE 102 to connect to enterprise SNPN 130 / “restricted access secure WWAN”. [0016-17] teach that multiple different “non-public networks” (NPNs) may be selected. Additionally, [0017] teaches the use of eUICC / eSIM which are well known as having the ability to store and manage different network profiles.) transmitting a secure access provisioning instruction to ([0029] teaches UE 102 and enterprise SNPN 10 being connected after obtaining SNPN credentials from enterprise network 120. Fig. 1 shows a connections between enterprise network 120 and enterprise SNPN 130, which is connected to data network 140. [0037-39] teaches components of enterprise network 120 generating the SNPN / eSIM profiles, where the SNPN includes the eSIM profile. See also, figs. 3b & 3c steps 310 to 336 and [0032-39] teaching accessing a private 4g or 5g network using the SNPN credential.) Gundavelli fails to teach provisioning the eSIM profile from the restricted access network, However, to Xiong teaches, transmitting a secure access provisioning instruction to the restricted access secure WWAN carrier for provisioning of a restricted access eSIM profile to the managed client information handling system (Xiong, [0045] teaches restricted provisioning of eSIMs.) limiting the restricted access secure WWAN wireless link established to transceive data between the managed client information handling system and the . (Xiong, Abstract & fig. 5E teach enterprise management of eSIM provisioning.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles, with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E). One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli with the added capability of using a limited / restricted provisioning network to obtain eSIM profiles, as taught by Xiong., for the purpose of increasing security by limiting access to the provisioning network and to increase network efficiency / user convenience by obtaining updated eSIMs using the restricted provisioning network. Gundavelli and Xiong fail to teach all of the following regarding enterprise resources, However, Gandhi teaches, transmitting, via the network interface device, client information handling system security policies to a secure user session agent at the managed client information handling system identifying a selected restricted access secure WWAN carrier from a plurality of available restricted access secure WWAN carriers and instruction to initiate a secure user session on a restricted access secure WWAN link to secure access to an enterprise system corporate resource or to trusted internet protocol addresses and limit other network accesses on a regular access unrestricted WWAN for the managed client information handling system; ([0036-38] teaches provisioning enterprise eSIM profiles to eUICC which may be activate or deactivate profiles based on enterprise policies. [0034] and [0039] teach that the enterprise devices may be standalone networking devices (e.g., SNPN). [0048] & [0102] teach addressing. See also [0014] & [0019-20] teaching the accessing of different networks including an eSIM for internal purposes, such as accessing different internal enterprise networks.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles and teaches standalone non-public networking (SPNN) (Title and abstract), with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E), with Gandhi, which also teaches standalone enterprise networks ([0034] & [0039]) where enterprises are being connected using eSIMs in eUICC profiles, and additionally teaches the provisioning of multiple enterprise eSIM profiles in the eUICC and activating and deactivating based on enterprise policies. ([0010] & [0034-38]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli and Xiong with the added capability of provisioning multiple enterprise eSIM policies and activating access to different enterprises, as taught by Gandhi, for the purpose of increasing security by using the eUICC to control the access to different enterprises / resources. Regarding claim 2, Gundavelli, Xiong, and Gandhi teach, The method of claim 1, wherein a regular access unrestricted WWAN of the regular WWAN carrier is utilized transmit client information handling system security policies and to provision the restricted access eSIM profile to the managed client information handling system. (Gundavelli, [0017] teaches that the networks may be wireless wide area (WWA) access network, such as a cellular.) (Gundavelli II, [0072] teaches that the network elements may be wireless local area (WLA) access network, wireless wide area (WWA).) Regarding claim 3, Gundavelli, Xiong, and Gandhi teach, The method of claim 1 further comprising: identifying the restricted access secure WWAN carrier from a list of subscribing secure WWAN carriers and selecting one based on location of the managed client information handling system. (Gundavelli, [0040] and [0042] teaches using the UE location to determine the WWAN.) (Gundavelli II, Abstract, teaches the using location to determine whether to use the first or second private network.) Regarding claim 5, Gundavelli, Xiong, and Gandhi teach, The method of claim 1 further comprising: transmitting the client information handling system security policies including a login requirement instruction to the managed client information handling system restricting access to the restricted access eSIM profile by a secure user session agent executing at the managed client information handling system until a login verification instruction has been received from an enterprise identity server. (Gundavelli, [0038-39] teach login being required to gain access to the eSIM profile, before providing the eSIM profile.) (Xiong, [0045-46] teach eSIM provisioning, [0056] teaches provisioning using authentication.) Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Xiong, in view of Gandhi, in view of US 20200344147 to Pianigiani et al. (hereinafter Pianigiani). Regarding claim 4, Gundavelli, Xiong, and Gandhi teach, The method of claim 1, wherein the restricted access secure WWAN carrier provides limited access for the managed information handling system on the restricted access secure WWAN link via (Gundavelli, fig. 1 see also rejection of claim 1.) Gundavelli, Xiong, and Gandhi fail to explicitly teach using a gateway link to establish restricted communications between a restricted network / resource and a client where a software layer is used by the system, However, Pianigiani teaches, wherein the restricted access secure WWAN carrier provides limited access for the managed information handling system on the restricted access secure WWAN link via a soft gateway established for the managed client information handling system and only such a soft gateway in a software layer is trusted by an enterprise server operating as an enterprise system edge gateway provider with the enterprise system corporate resource. (Pianigiani, Abstract teaches software defined network control. [0025] teaches the use of gateway devices and other edge devices that use a layer for private networking, in a network of tenants that connect to remote data centers.) (Gundavelli teaches the above discussed features other than the soft gateway and software layer) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles, with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E), with Gandhi, which also teaches standalone enterprise networks ([0034] & [0039]) where enterprises are being connected using eSIMs in eUICC profiles, and additionally teaches the provisioning of multiple enterprise eSIM profiles in the eUICC and activating and deactivating based on enterprise policies. ([0010] & [0034-38]), with Pianigiani, which also teaches secure connections between a client and a restricted resource (VPN), and further teaches the use of a gateway that is connected, via a layer, to the restricted resource / network. One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli, Xiong, and Gandhi with the added capability of utilizing a gateway in a software layer to connect a client and a restricted resource / private network, as taught by Pianigiani, for the purpose of increasing security and increasing computational efficiency. Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Xiong, in view of Gandhi, in view of US 20230011447 to Gundavelli et al. (hereinafter Gundavelli II). Regarding claim 6, Gundavelli, Xiong, and Gandhi teach, The method of claim 1 further comprising: Gundavelli, Xiong, and Gandhi fail to explicitly teach failing to connect to a new network, which results in the acquisition of new credentials being triggered, However, Gundavelli II teaches, receiving a notification of attempted unauthorized access to secure enterprise system resources from the managed client information handling system via a regular unrestricted WWAN to trigger establishment of the restricted access WWAN wireless link for the managed client information handling system. (Fig. 6a & 6b, steps 601-602, [0044-45], where a lack of credentials are detected which results in the UE not connecting to the new network due to the lack of credentials in steps 601-602. Then credentials are acquisition is triggered in steps 606 and 607 and [0045].) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles, with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E), with Gandhi, which also teaches standalone enterprise networks ([0034] & [0039]) where enterprises are being connected using eSIMs in eUICC profiles, and additionally teaches the provisioning of multiple enterprise eSIM profiles in the eUICC and activating and deactivating based on enterprise policies. ([0010] & [0034-38]), with Gundavelli II, which teaches provisioning eSIM profiles ([0018]), and additionally teaches initially using a public network to establish secure communications with an secure connection of SM-DP+, where an initial attempt to connect to a new network fails, and results in the acquisition of the appropriate credentials (eSIM) being triggered (due to the failure) ([0044-45]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli, Xiong, and Gandhi with the added capability of utilizing SM-DP+ for eSIM acquisition after a failure to connect to a new network, as taught by Gundavelli II. Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Xiong, in view of Gandhi, in view of US 20180014339 to Baek et al. (hereinafter Baek). Regarding claim 7, Gundavelli, Xiong, and Gandhi teach, The method of claim 1 further comprising: Xiong teaches, (Xiong, [0045] teaches provisioning eSIM, and [0046] teaches retrieves address for MNO SMDP.) Gundavelli, Xiong, and Gandhi fail to teach only allowing connection to an address that is included within the eSIM profile, However, Baek teaches, transmitting the client information handling system security policies including an automatic blocking instruction to the managed client information handling system to block attempts to transceive data with any IP addresses not identified as trusted IP addresses within the ([0141] teaches packet filtering the only allows communications where the address of the eSIM server is included as the destination address.) (Gundavelli teaches a new eSIM profile is loaded for a specific network, thus, other networks are precluded due to lack of eSIM profile. [0046] teaches using an agent.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles, with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E), with Gandhi, which also teaches standalone enterprise networks ([0034] & [0039]) where enterprises are being connected using eSIMs in eUICC profiles, and additionally teaches the provisioning of multiple enterprise eSIM profiles in the eUICC and activating and deactivating based on enterprise policies. ([0010] & [0034-38]), with Baek, which teaches restricting the IP address being accessed to only an IP address included in the eSIM profile. One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli, Xiong, and Gandhi with the added capability of connecting only to a specific address included in an eSIM profile, to increase security, as taught by Baek, for the purpose of increasing security. Claims 8-10 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Gundavelli II, in view of Xiong, in view of Gandhi. Regarding claim 8, Gundavelli teaches, An information technology (IT) management server information handling system executing code instructions of a secure user session initiation system, comprising: (fig. 1 and [0029] teach enterprise standalone non-public network (SNPN) wireless wide area (WWA) access network 130 requiring SNPN credentials.) a hardware processor receiving, via a network interface, (fig. 1, WWA 110) security configuration settings for a managed client information handling system ([0035] teaches UE 102 connects through access network 110 to obtain SNPN credentials from enterprise network 120. Abstract teaches EAP in which the UE 102 connects to enterprise authentication server 123 / enterprise network 120 / “enterprise identity provider”, as shown in figs.1 & 2.) from an IT administrator, (fig. 1, enterprise management system 121 and network 120.) including an address of an enterprise identity provider server, authorization to access an enterprise system corporate resource, and identification of a trusted internet protocol address; ([0036] teaches EAP-based secondary authentication using enterprise authentication server 123 / “enterprise identity provider”. [0037] teaches receiving SNPN credential objects including an eSIM profile and network identifier metadata to connect to SNPN WWA 130. [0041] teaches network identifier data being used to identify Data Network Name (DNN).) the hardware processor transmitting, via the network interface device, a first provisioning instruction to ([0029] teaches UE 102 and enterprise SNPN 10 being connected after obtaining SNPN credentials from enterprise network 120. Fig. 1 shows a connections between enterprise network 120 and enterprise SNPN 130. [0039] teaches components of enterprise network 120 generating the SNPN / eSIM profiles.) Gundavelli fails to explicitly teach failing to connect to a new network and then connecting to a new network, However, Gundavelli II teaches, the network interface device to receive a notification of attempted unauthorized access to secure enterprise system resources from a secure user session agent of a managed client information handling system via a first regular access unrestricted WWAN wireless link; and (Fig. 6a & 6b, steps 601-602, [0044-45], where a lack of credentials are detected which results in the UE not connecting to the new network due to the lack of credentials in steps 601-602. Then credential acquisition is triggered in steps 606 and 607, using SM-DP+ as described in [0045].) the network interface device transmitting an instruction including a managed client information handling system security policy for the secure user session agent to suspend or terminate all other network links at the managed client information handling system upon initiation of a restricted access secure WWAN link. the network interface device transmitting an instruction including a managed client information handling system security policy for the secure user session agent to suspend or terminate all other network links at the managed client information handling system, including with the first regular access WWAN wireless link, upon initiation of a restricted access secure WWAN link ([0019] teaches installing a new eSIM profile when the client moves to a new local that requires a new network, and the previous eSIM profile of the previous network is removed or deactivated.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles, with Gundavelli II, which teaches provisioning eSIM profiles ([0018]), and additionally teaches initially using a public network to establish secure communications with an secure connection of SM-DP+, where an initial attempt to connect to a new network fails, and results in the acquisition of the appropriate credentials (eSIM) being triggered (due to the failure) ([0044-45]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli with the added capability of utilizing SM-DP+ for eSIM acquisition after a failure to connect to a new network, as taught by Gundavelli II. Gundavelli and Gundavelli II fail to teach provisioning the eSIM profile from the restricted access network, However, to Xiong teaches, the hardware processor transmitting, via the network interface device, a first provisioning instruction to a second subscribing restricted access secure WWAN carrier for provisioning of a restricted access eSIM profile to the managed client information handling system (Xiong, [0045] teaches restricted provisioning of eSIMs.) limiting a restricted access secure WWAN wireless link on the second subscribing restricted access secure WWAN carrier, where the restricted access secure WWAN wireless link is established to limit transceiving data between the client information handling system and (Xiong, Abstract & fig. 5E teach enterprise management of eSIM provisioning.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles, with Gundavelli II, which teaches provisioning eSIM profiles ([0018]), and additionally teaches initially using a public network to establish secure communications with an secure connection of SM-DP+, where an initial attempt to connect to a new network fails, and results in the acquisition of the appropriate credentials (eSIM) being triggered (due to the failure) ([0044-45]), with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E). One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli and Gundavelli II and with the added capability of utilizing the new local network, operated by the same or a different carrier where the new local network is in a different location, to communicate with the user’s device and provide eSIM profiles to the user’s device to use the increased security of the private network in order to obtain eSIM profiles that allow access to the new network, as taught by Xiong, to increase security and user experience by automatically provisioning eSIM profiles to increase connectivity. Gundavelli , Gundavelli II, and Xiong fail to teach all of the following regarding enterprise resources, However, Gandhi teaches, the network interface device transmitting an instruction including a managed client information handling system security policy for the secure user session agent to suspend or terminate all other network links at the managed client information handling system, including with the first regular access WWAN wireless link, upon initiation of a restricted access secure WWAN link to limit accesses by the managed client information handling system to the enterprise system corporate resource or to the trusted internet protocol addresses identified in the managed client information handling system security policy for the secure user session agent. ([0036-38] teaches provisioning enterprise eSIM profiles to eUICC which may be activate or deactivate profiles based on enterprise policies. [0034] and [0039] teach that the enterprise devices may be standalone networking devices (e.g., SNPN). [0048] & [0102] teach addressing.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles and teaches standalone non-public networking (SPNN) (Title and abstract), with Gundavelli II, which teaches provisioning eSIM profiles ([0018]), and additionally teaches initially using a public network to establish secure communications with an secure connection of SM-DP+, where an initial attempt to connect to a new network fails, and results in the acquisition of the appropriate credentials (eSIM) being triggered (due to the failure) ([0044-45]), with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E), with Gandhi, which also teaches standalone enterprise networks ([0034] & [0039]) where enterprises are being connected using eSIMs in eUICC profiles, and additionally teaches the provisioning of multiple enterprise eSIM profiles in the eUICC and activating and deactivating based on enterprise policies. ([0010] & [0034-38]) One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli , Gundavelli II, and Xiong and with the added capability of provisioning multiple enterprise eSIM policies and activating access to different enterprises, as taught by Gandhi, for the purpose of increasing security by using the eUICC to control the access to different enterprises / resources. Regarding claim 9, Gundavelli, Gundavelli II, Xiong, and Gandhi teach, The IT management server information handling system of claim 8, Gundavelli teaches, wherein enterprise corporate resources include IP addresses located behind an enterprise firewall. (Fig. 1, enterprise SNPN WWA 130 is a restricted access network that provides access to enterprise network 140. [0134] teaches that the network elements may be a firewall.) Regarding claim 10, Gundavelli, Gundavelli II, Xiong, and Gandhi teach, The IT management server information handling system of claim 8 further comprising: Gundavelli teaches, the hardware processor determining the restricted access secure WWAN wireless link from the second subscribing restricted access secure WWAN carrier includes a pre-established subscription to operate the restricted access secure WWAN wireless link with limited access to the enterprise system corporate resource or trusted internet protocol address per the restricted access eSIM. ([0019] teaches SNPN credentials may broadly refer to any combination of Subscriber Identity Module (SIM) based or non-SIM based profiles and/or credentials, which indicate subscriptions. [0029] teaches UE 102 and enterprise SNPN 10 being connected after obtaining SNPN credentials from enterprise network 120. Fig. 1 shows a connections between enterprise network 120 and enterprise SNPN 130. [0039] teaches components of enterprise network 120 generating the SNPN / eSIM profiles.) Regarding claim 12, Gundavelli, Gundavelli II, Xiong, and Gandhi teach, The IT management server information handling system of claim 8 further comprising: the network interface device transmitting the instruction including the managed client information handling system security policy for the secure user session agent including a login requirement instruction to the managed client information handling system and restricting access to the restricted access secure WWAN link by a secure user session agent executing at the managed client information handling system until a login verification instruction has been received from the enterprise identity provider server. Claim 12 is rejected using the same basis of arguments used to reject claim 5 above. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Gundavelli II, in view of Xiong, in view of Gandhi, in view of Pianigiani. Regarding claim 11, Gundavelli, Gundavelli II, Xiong, and Gandhi teach, The IT management server information handling system of claim 8, Pianigiani teaches, wherein the restricted access secure WWAN carrier provides limited access for the managed information handling system on the restricted access secure WWAN link via a soft gateway established for the managed client information handling system and only such a soft gateway in a software layer is trusted by an enterprise server operating as an enterprise system edge gateway provider with the enterprise system corporate resource. Claim 11 is rejected using the same basis of arguments used to reject claim 4 above. Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Gundavelli II, in view of Xiong, in view of Gandhi, in view of Baek. Regarding claim 13, Gundavelli, Gundavelli II, Xiong, and Gandhi teach, The IT management server information handling system of claim 8 further comprising: Baek teaches, the network interface device transmitting the instruction including the managed client information handling system security policy for the secure user session agent including an automatic blocking instruction to the managed client information handling system to block attempts to transceive data with IP addresses not identified as trusted IP addresses within the restricted access eSIM profile by a secure user session agent executing at the managed client information handling system. Claim 13 is rejected using the same basis of arguments used to reject claim 7 above. Claims 14, 16, and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Gundavelli II, in view of Gandhi, in view of Xiong. Regarding claim 14, Gundavelli teaches, A managed client information handling system operating a secure user session initiation system comprising: (fig. 1, UE 102) a hardware processor, an embedded controller (EC), a memory, and a network interface device; ([0023] teaches processors, memory, and modems of UE 102.) an electronic subscriber identity module (eSIM) memory storing a first, regular access eSIM installed with a regular access profile to access a first regular access wireless wide area network (WWAN) link; (fig. 1, UE 102, which includes eSIM profile 131 stored in eUICC 108, may access network 111. See [0032-33] for eSIM description.) … an embedded universal integrated circuit card (eUICC) receiving, (fig. 1, eUICC 107) via the network interface device, a restricted access eSIM profile ([0035] teaches UE 102 connects through access network 110 to obtain SNPN credentials from enterprise network 120. See also, figs. 3b & 3c steps 310 to 336. [0029] teaches UE 102 and enterprise SNPN 10 being connected after obtaining SNPN credentials from enterprise network 120. Fig. 1 shows a connections between enterprise network 120 and enterprise SNPN 130, which is connected to data network 140. [0039] teaches components of enterprise network 120 generating the SNPN / eSIM profiles.) (Gundavelli II, which is further discussed below, explicitly teaches in [0019] transferring from a first to a second (new) local network \ “second restricted access secure WWAN”. [0046] teaches agent.) the hardware processor executing code instructions of the secure user session initiation system to automatically establish, via the network interface device, the second restricted access secure WWAN link using the restricted access eSIM; ([0037] teaches eSIM profile being used to enable UE 102 to connect to enterprise SNPN WWA 130 of fig. 1. See also, fig. 3c, step 336.) … the network interface device to transceive data, via the second restricted access secure WWAN link between the managed client information handling system and limited to the enterprise system corporate resource or the trusted internet protocol address determined for the managed client information handling system. (fig. 1 teaches, UE 102 connecting through enterprise SNPN WWA 130 to the data network 140 / “enterprise system corporate resource or the trusted internet protocol address”.) Gundavelli fails to explicitly teach failing to connect to a new network and then connecting to a new network, However, Gundavelli II teaches, the hardware processor executing code instructions of the secure user session agent to detect a blocked, unauthorized attempt by the managed client information handling system to access secure enterprise system corporate resources via the first regular access WWAN link; (Fig. 6a & 6b, steps 601-602, [0044-45], where a lack of credentials are detected which results in the UE not connecting to the new network due to the lack of credentials in steps 601-602.) the hardware processor executing code instructions of the secure user session agent to transmit notification of the unauthorized attempt to a remote information technology (IT) management server executing code instructions of a secure user session initiation system; (Then credential acquisition is triggered in steps 606 and 607, using SM-DP+ as described in [0045].) … the hardware processor executing code instructions of the secure user session agent to automatically terminate the first regular access WWAN link … ([0019] teaches transferring from a first local network / “first regular access WWAN link” to a second (new) local network \ “second restricted access secure WWAN”. [0019] also teaches installing a new eSIM profile when the client moves to a new local that requires a new network, and the previous eSIM profile of the previous network is removed or deactivated, which terminates all connections to the previous / first network.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles, with Gundavelli II, which teaches provisioning eSIM profiles ([0018]), and additionally teaches initially using a public network to establish secure communications with an secure connection of SM-DP+, where an initial attempt to connect to a new network fails, and results in the acquisition of the appropriate credentials (eSIM) being triggered (due to the failure) ([0044-45]). One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli with the added capability of utilizing the new local network, operated by the same or a different carrier where the new local network is in a different location, to communicate with the user’s device and provide eSIM profiles to the user’s device to use the increased security of the private network in order to obtain eSIM profiles that allow access to the new network, as taught by Gundavelli II, for the purpose of increasing security and user convince by securely provisioning eSIM for connectivity. Gundavelli and Gundavelli II fail to teach all of the following regarding managed client information handling and enterprise resources, However, Gandhi teaches, an embedded universal integrated circuit card (eUICC) receiving, via the network interface device, a restricted access eSIM profile provisioned from a subscribing restricted access secure WWAN carrier and receive and execute instructions of a managed client information handling system security policy for the secure user session agent to limit a second restricted access secure WWAN link to transceive data between the managed client information handling system and the enterprise system corporate resource or trusted internet protocol address; ([0036-38] teaches provisioning enterprise eSIM profiles to eUICC which may be activate or deactivate profiles based on enterprise policies. [0034] and [0039] teach that the enterprise devices may be standalone networking devices (e.g., SNPN). [0048] & [0102] teach addressing.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles and teaches standalone non-public networking (SPNN) (Title and abstract), with Gundavelli II, which teaches provisioning eSIM profiles ([0018]), and additionally teaches initially using a public network to establish secure communications with an secure connection of SM-DP+, where an initial attempt to connect to a new network fails, and results in the acquisition of the appropriate credentials (eSIM) being triggered (due to the failure) ([0044-45]), with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E), with Gandhi, which also teaches standalone enterprise networks ([0034] & [0039]) where enterprises are being connected using eSIMs in eUICC profiles, and additionally teaches the provisioning of multiple enterprise eSIM profiles in the eUICC and activating and deactivating based on enterprise policies. ([0010] & [0034-38]) One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli and Gundavelli II with the added capability of provisioning multiple enterprise eSIM policies and activating access to different enterprises, as taught by Gandhi, for the purpose of increasing security by using the eUICC to control the access to different enterprises / resources. Gundavelli, Gundavelli II, and Gandhi fail to explicitly teach prohibiting access to a WWAN link, However, Xiong teaches, an embedded universal integrated circuit card (eUICC) receiving, via the network interface device, a restricted access eSIM profile provisioned from a subscribing restricted access secure WWAN carrier … (Xiong, [0045] teaches restricted provisioning of eSIMs.) … pursuant to instructions received at the eUICC of the managed client information handling system security policy for the secure user session agent to prohibit access on the first regular access WWAN link; and (Xiong, [0051] teaches deleting cellular plan.) Before the effective filing date of the invention, it would have been obvious to one of ordinary skill in the art to combine the teachings of Gundavelli, which teaches the provisioning of eSIM profiles for an enterprise / private network that allows access to enterprise data / services by using a public network to provision the eSIM profiles and teaches standalone non-public networking (SPNN) (Title and abstract), with Gundavelli II, which teaches provisioning eSIM profiles ([0018]), and additionally teaches initially using a public network to establish secure communications with an secure connection of SM-DP+, where an initial attempt to connect to a new network fails, and results in the acquisition of the appropriate credentials (eSIM) being triggered (due to the failure) ([0044-45]), with Gandhi, which also teaches standalone enterprise networks ([0034] & [0039]) where enterprises are being connected using eSIMs in eUICC profiles, and additionally teaches the provisioning of multiple enterprise eSIM profiles in the eUICC and activating and deactivating based on enterprise policies. ([0010] & [0034-38]), with Xiong, which also teaches provisioning of eSIMs (fig. 1 & [0034], and additionally teaches restricted provisioning of eSIM ([0045]) and enterprise management of eSIM provisioning (Abstract & fig. 5E). One of ordinary skill in the art would have been motivated to perform such an addition to provide Gundavelli, Gundavelli, II, and Gandhi with the added capability of the added capability of using a limited / restricted provisioning network to obtain eSIM profiles and to delete access to wireless networks, as taught by Xiong, for the purpose of increasing security by using the eUICC to control the access to different enterprises / resources. Regarding claim 16, Gundavelli, Gundavelli II, Gandhi, and Xiong teach, The managed client information handling system of claim 14, Gundavelli II teaches, wherein the hardware processor executing code instructions of the secure user session agent receives and executes instructions for the managed client information handling system security policy for the secure user session agent to suspend or terminate all other network links at the managed client information handling system upon initiation of a restricted access secure WWAN link. (Gundavelli II, [0019] teaches installing a new eSIM profile when the client moves to a new local that requires a new network, and the previous eSIM profile of the previous network is removed or deactivated. As a result of the new eSIM profile being loaded, all others are deleted, which suspends all other network links.) Regarding claim 18, Gundavelli, Gundavelli II, Gandhi, and Xiong teach, The managed client information handling system of claim 14 further comprising: the hardware processor executing code instructions of the secure user session agent to receive and execute instructions for the managed client information handling system security policy transmit verified login credentials to an enterprise identity server to permit access to the restricted enterprise system corporate resource or the trusted internet protocol address determined for the managed client information handling system via the restricted access secure WWAN link. Claim 18 is rejected using the same basis of arguments used to reject claim 5 above. Regarding claim 19, Gundavelli, Gundavelli II, Gandhi, and Xiong teach, The managed client information handling system of claim 14 further comprising: Gundavelli teaches, the network interface device receiving an address for an enterprise identity provider for transmission of verified login credentials for the managed client information handling system. (Gundavelli, [0036] teaches EAP-based secondary authentication using enterprise authentication server 123 / “enterprise identity provider”. [0037] teaches receiving SNPN credential objects including an eSIM profile and network identifier metadata to connect to SNPN WWA 130 or network 140. [0041] teaches network identifier data being used to identify Data Network Name (DNN).) Regarding claim 20, Gundavelli, Gundavelli II, Gandhi, and Xiong teach, The managed client information handling system of claim 14, wherein restricted enterprise corporate resources include plural trusted IP addresses located behind an enterprise firewall. (Gundavelli in Fig. 1, enterprise SNPN WWA 130 is a restricted access network that provides access to enterprise network 140. [0134] teaches that the network elements may be a firewall.) (Gundavelli II, in fig. 1 and [0015] teaches plural locations NPN(1-3).) Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Gundavelli II, in view of Gandhi, in view of Xiong, in view of Pianigiani. Regarding claim 15, Gundavelli, Gundavelli II, Gandhi, and Xiong teach, The managed client information handling system of claim 14, Pianigiani teaches, wherein the restricted access secure WWAN carrier provides limited access for the managed information handling system on the restricted access secure WWAN link via a soft gateway established by the secure user session agent at the managed client information handling system and only such a soft gateway in a software layer is trusted by an enterprise server operating as an enterprise system edge gateway provider with the restricted enterprise system corporate resource and the trusted IP address. Claim 15 is rejected using the same basis of arguments used to reject claim 4 above. Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli, in view of Gundavelli II, in view of Gandhi, in view of Xiong, in view of Baek. Regarding claim 17, Gundavelli, Gundavelli II, Gandhi, Xiong, and Baek teach, The managed client information handling system of claim 14 further comprising: the hardware processor executing code instructions of the secure user session agent receive and execute instructions for the managed client information handling system security policy to block an attempt to access a non-trusted IP address via any wireless link at the managed client information handling system. Claim 17 is rejected using the same basis of arguments used to reject claim 7 above. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRIAN WILLIAM AVERY whose telephone number is (571) 272-3942. The examiner can normally be reached on 9AM-5PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on (571) 272-3739. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /B.W.A./ /JASON K GEE/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Nov 08, 2022
Application Filed
Feb 13, 2025
Non-Final Rejection mailed — §103
May 13, 2025
Response Filed
Sep 30, 2025
Final Rejection mailed — §103
Mar 03, 2026
Request for Continued Examination
Mar 14, 2026
Response after Non-Final Action
Aug 05, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12676839
Digital Rights Management DRM Method, Apparatus, and System
3y 10m to grant Granted Jul 07, 2026
Patent 12665773
SYSTEM AND METHOD FOR AUTHENTICATION IN A CLIENT-SERVER CONNECTION USING CHALLENGE APPLIED TO A SECRET KEY
3y 2m to grant Granted Jun 23, 2026
Patent 12619703
AUTHORIZED REMOTE MOBILE DEVICE MANAGEMENT OF A TARGETED MANAGED DEVICE
3y 8m to grant Granted May 05, 2026
Patent 12609925
SYSTEMS AND METHODS FOR MONITORING DECENTRALIZED DATA STORAGE
4y 1m to grant Granted Apr 21, 2026
Patent 12587381
METHOD AND SYSTEM FOR MONITORING AND CONTROLLING HIGH RISK SUBSTANCES
4y 7m to grant Granted Mar 24, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
60%
Grant Probability
99%
With Interview (+55.0%)
3y 1m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 88 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month