Prosecution Insights
Last updated: October 02, 2026
Application No. 18/105,597

METHOD AND SYSTEM FOR INVOKING APPLICATION PROGRAMMING INTERFACE, AND APPARATUS

Non-Final OA §103
Filed
Feb 03, 2023
Priority
Aug 06, 2020 — continuation of PCTCN2020107587
Examiner
COLIN, CARL G
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
Huawei Technologies Co., Ltd.
OA Round
3 (Non-Final)
48%
Grant Probability
Moderate
3-4
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 48% of resolved cases
48%
Career Allowance Rate
65 granted / 136 resolved
-10.2% vs TC avg
Strong +54% interview lift
Without
With
+54.1%
Interview Lift
resolved cases with interview
Typical timeline
4y 4m
Avg Prosecution
6 currently pending
Career history
145
Total Applications
across all art units

Statute-Specific Performance

§101
12.7%
-27.3% vs TC avg
§103
47.7%
+7.7% vs TC avg
§102
17.2%
-22.8% vs TC avg
§112
16.9%
-23.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 136 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The present office action is responsive to communication received on 1/5/2026. Claims 1, 3-12, and 14-20 are pending. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 2/16/2026 has been entered. Response to Arguments Applicant’s arguments, filed on 1/5/2026, with respect to the 35 U.S.C 103 rejection have been fully considered but they are not persuasive. Claim 1 has been amended to include the limitations of claim 2. Applicant argues that the prior art Bi fails disclose the amendments. Examiner respectfully disagrees because Bi discloses sending by the API providing network element (NEF) an authorization request to a permission storage network element, (UDM/UDR) wherein the authorization request comprises a second identifier of the terminal device (UE App identification or user permission information or license information), an identifier of the target application on a mobile network (UE identification) (See steps 1101-1103 on page 17, and steps 1301-1303 on page 18) disclosing NEF queries the UDM for the UE’s permission for the call or authorization, carrying user permission information and verification code (Step 1103); In Step 1303 discloses various identification in the query to be verified such as UE identification, calling ID, APP identification, and privacy identification information of the UE). Bi also discloses receiving, by the API-providing network element, an authorization response from the permission storage network element, wherein the authorization response comprises the authorization result (Bi Step 1202 the UDM determines whether the call is a call permitted or authorized by the UE according to the user information configuration and feeds the determination result back to the NEF). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1, 5, 7, 9, 10, 12, 16, 18, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bi et al (WO-2021159891-A1) in view of Yao et al.(US-20170068810-A1) and in view of Kim et al. (US-20220191650-A1). In regards to claim 1, Bi teaches a method for invoking an application programming interface(API) ,comprising: receiving, by API-providing network element, an API-invoking request for a target application from an application server, wherein the API-invoking request is for requesting to process information of a terminal device, and the API-invoking request comprises a first identifier of the terminal device and an identifier of the target application on the application server (Bi: In some optional embodiments, when receiving a call requested by the edge computing application server from the 3GPP network NEF as the AF, the NEF queries the UDM or UDR for the UE's permission or authorization for the call (Page 9), wherein the call calls the open network API to access the user's information, especially the private information (Page 13) and a request can contain an Application ID (Page 15) and UE ID (Page 18) ; obtaining, by the API-providing network element, an authorization result based on the first identifier of the terminal device and the identifier of the target application on the application server, wherein the authorization result indicates whether the application server is allowed to process the information of the terminal device (Bi: The permission network element (UDM or UDR) determines whether the call is a call permitted or authorized by the UE according to the user authorization configuration, and feeds the determination result back to the NEF (Page 17)., determining, by the API-providing network element based on the authorization result, whether to allow the application server to perform an operation on the information of the terminal device (Bi: When the NEF determines that the UE has approved or authorized the call, it allows the edge computing application server to call. (Page 17).). sending by the API providing network element (NEF) an authorization request to a permission storage network element, (UDM/UDR) wherein the authorization request comprises a second identifier of the terminal device (UE App identification or user permission information or license information), an identifier of the target application on a mobile network (UE identification) (See steps 1101-1103 on page 17, and steps 1301-1303 on page 18) disclosing Bi: NEF queries the UDM for the UE’s permission for the call or authorization, according to the user’s authorization and configuration (Step 1103); In Step 1303 Bi: discloses various identification in the query to be verified such as UE identification, calling ID, APP identification, and privacy identification information of the UE). Bi also discloses receiving, by the API-providing network element, an authorization response from the permission storage network element, wherein the authorization response comprises the authorization result (Bi: Step 1202 the UDM determines whether the call is a call permitted or authorized by the UE according to the user information configuration and feeds the determination result back to the NEF). But Bi does not explicitly disclose including reading, modifying, adding, and deleting a piece of information of the terminal device by the target application. However, Yao in a similar field of endeavor, teaches including reading, modifying, adding, and deleting a piece of information of the terminal device by the target application (Yao: An application program authorization permission list comprises one or more behavior permissions selectively authorized by a user such as reading a short message, writing a short message, or deleting & modifying a file [Paras [13],[68], [71]].). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bi to include granular application permissions, as taught by Yao, in order to improve access control and data protection. Bi does not explicitly disclose sending… operation indication information indicating the operation on the information of the terminal device. Kim, in the same field of endeavor, discloses a method for obtaining and managing location information of a mobile terminal device that teaches … an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include operation information in the authorization request as taught by Kim. The motivation to do so would be to improve the authentication method by specifying how the API is allowed to use the information when it is called. In regards to claim 5, the combination of Bi and Yao teach the method according to claim 1, wherein the obtaining, by the API-providing network element, the authorization result based on the first identifier of the terminal device and the identifier of the target application on the application server comprises: sending, by the API-providing network element, an authorization request to a permission storage network element, wherein the authorization request comprises a second identifier of the terminal device and an identifier of the target application on a mobile network (Bi: The UDM or UDR receives the NEF query on the call, where the query is to query whether the call is a UE permitted or authorized call (Page 17), where confirmation of whether the service is allowed to be invoked through the UE identification, the calling ID, the APP identification, and the privacy permission identification of the UE (Page 18).) ; receiving, by the API-providing network element, an authorization response from the permission storage network element, wherein the authorization response comprises a permission of the target application of the terminal device on the mobile network (Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).) ; and determining, by the API-providing network element, the authorization result based on the permission of the target application of the terminal device on the mobile network (Bi: When the NEF determines that the UE has approved or authorized the call, it allows the edge computing application server to call. (Page 17).). However, the combination of Bi and Yao does not explicitly disclose … operation indication information indicating the operation on the information of the terminal device. Kim, in the same field of endeavor, discloses a method for obtaining and managing location information of a mobile terminal device that teaches … an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include operation information, as taught by Kim, in determining the authorization result. The motivation to do so would be to improve the authentication method by specifying how the API is allowed to use the information when it is called. In regards to claim 7, the combination of Bi and Yao teach the method according to claim 1, wherein, when the application server is forbidden to perform the operation on the information of the terminal device, the API-providing network element sends an API-invoking response to the application server, wherein the API-invoking response indicates that the API-invoking request is rejected(Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).). In regards to claim 9, the combination of Bi and Yao teach the method according to claim 1, wherein the method further comprises: sending, by the API-providing network element, a permission request message to an access and mobility management network element, wherein the permission request comprises a second identifier of the terminal device and an identifier of the target application on a mobile network (Bi: The UDM or UDR receives the NEF query on the call, where the query is to query whether the call is a UE permitted or authorized call (Page 17), wherein confirmation of whether the service is allowed to be invoked through the UE identification, the calling ID, the APP identification, and the privacy permission identification of the UE (Page 18) .) ; receiving, by the API-providing network element, a permission response message from the access and mobility management network element, wherein the permission response message comprises a permission of the target application of the terminal device on the mobile network (Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).) ; and determining, by the API-providing network element based on the permission of the target application of the terminal device on the mobile network (Bi: When the NEF determines that the UE has approved or authorized the call, it allows the edge computing application server to call. (Page 17).). However, the combination of Bi and Yao does not explicitly disclose … operation indication information indicating the operation on the information of the terminal device. Kim, in the same field of endeavor, discloses a method for obtaining and managing location information of a mobile terminal device that teaches … an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include operation information, as taught by Kim, in determining the authorization result. The motivation to do so would be to improve the authentication method by specifying how the API is allowed to use the information when it is called. In regards to claim 10, Bi teaches a method for invoking an application programming interface (API), comprising: sending, by an application server, an API-invoking request for a target application to an API-providing network element, wherein the API- invoking request is for requesting to process information of a terminal device,(Bi: In some optional embodiments, when receiving a call requested by the edge computing application server from the 3GPP network NEF as the AF, the NEF queries the UDM or UDR for the UE's permission or authorization for the call (Page 9), wherein the call calls the open network API to access the user's information, especially the private information (Page 13) and a request can contain an Application ID (Page 15) and UE ID (Page 18) ; and receiving, by the application server, an API-invoking response from the API-providing network element, wherein the API-invoking response indicates that the API-invoking request is successfully performed or is rejected(Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).). obtaining, by the API providing network element, an authorization result or a permission of the target application of the terminal device on the mobile network based on the first identifier of the terminal device and the identifier of the target application on the application server from a permission storage network element; wherein the permission storage network element fails to find the permission of the target application of the terminal device on the mobile network; (Bi: The permission network element (UDM or UDR) determines whether the call is a call permitted or authorized by the UE according to the user authorization configuration, and feeds the determination result back to the NEF (Page 17), (step 1304, page 18, if the call is allowed, the UDM or UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license ID as 0)). But Bi does not explicitly disclose including reading, modifying, adding, and deleting a piece of information of the terminal device by the target application. However, Yao in a similar field of endeavor, teaches including reading, modifying, adding, and deleting a piece of information of the terminal device by the target application (Yao: An application program authorization permission list comprises one or more behavior permissions selectively authorized by a user such as reading a short message, writing a short message, or deleting & modifying a file [Paras [13],[68], [71]].). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bi to include granular application permissions, as taught by Yao, in order to improve access control and data protection. In regards to claim 12, Bi teaches an application programming interface (API)-providing network element, comprising a processor coupled to a memory storing instructions and configured to execute the instructions to cause the API-providing network element to: receive an API-invoking request for a target application from an application server, wherein the API-invoking request is for requesting to process information of a terminal device, and the API-invoking request comprises a first identifier of the terminal device and an identifier of the target application on the application server (Bi: In some optional embodiments, when receiving a call requested by the edge computing application server from the 3GPP network NEF as the AF, the NEF queries the UDM or UDR for the UE's permission or authorization for the call (Page 9), wherein the call calls the open network API to access the user's information, especially the private information (Page 13) and a request can contain an Application ID (Page 15) and UE ID (Page 18) ; obtain an authorization result based on the first identifier of the terminal device and the identifier of the target application on the application server, wherein the authorization result indicates whether the application server is allowed to process the information of the terminal device , (Bi: The permission network element (UDM or UDR) determines whether the call is a call permitted or authorized by the UE according to the user authorization configuration, and feeds the determination result back to the NEF (Page 17).; and determine based on the authorization result, whether to allow the application server to perform an operation on the information of the terminal device (Bi: When the NEF determines that the UE has approved or authorized the call, it allows the edge computing application server to call. (Page 17).). wherein the instructions cause the API providing network element to obtain the authorization result by sending an authorization request to a permission storage network element, (UDM/UDR) wherein the authorization request comprises a second identifier of the terminal device (UE App identification or user permission information or license information), an identifier of the target application on a mobile network (UE identification) (See steps 1101-1103 on page 17, and steps 1301-1303 on page 18) disclosing Bi: NEF queries the UDM for the UE’s permission for the call or authorization, according to the user’s authorization and configuration (Step 1103); In Step 1303 Bi: discloses various identification in the query to be verified such as UE identification, calling ID, APP identification, and privacy identification information of the UE). Bi also discloses receiving an authorization response from the permission storage network element, wherein the authorization response comprises the authorization result (Bi: Step 1202 the UDM determines whether the call is a call permitted or authorized by the UE according to the user information configuration and feeds the determination result back to the NEF). But Bi does not explicitly disclose including reading, modifying, adding, and deleting a piece of information of the terminal device by the target application. However, Yao in a similar field of endeavor, teaches including reading, modifying, adding, and deleting a piece of information of the terminal device by the target application (Yao: An application program authorization permission list comprises one or more behavior permissions selectively authorized by a user such as reading a short message, writing a short message, or deleting & modifying a file [Paras [13],[68], [71]].). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Bi to include granular application permissions, as taught by Yao, in order to improve access control and data protection. Bi does not explicitly disclose sending… operation indication information indicating the operation on the information of the terminal device. Kim, in the same field of endeavor, discloses a method for obtaining and managing location information of a mobile terminal device that teaches … an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include operation information in the authorization request as taught by Kim. The motivation to do so would be to improve the authentication method by specifying how the API is allowed to use the information when it is called. In regards to claim 16, the combination of Bi and Yao teach the API-providing network element according to claim 12, wherein the instructions further cause the API-providing network element to obtain by the authorization result by: sending an authorization request to a permission storage network element, wherein the authorization request comprises a second identifier of the terminal device and an identifier of the target application on a mobile network (Bi: The UDM or UDR receives the NEF query on the call, where the query is to query whether the call is a UE permitted or authorized call (Page 17), where confirmation of whether the service is allowed to be invoked through the UE identification, the calling ID, the APP identification, and the privacy permission identification of the UE (Page 18).) ; receiving an authorization response from the permission storage network element, wherein the authorization response comprises a permission of the target application of the terminal device on the mobile network (Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).) ; and determining the authorization result based on the permission of the target application of the terminal device on the mobile network (Bi: When the NEF determines that the UE has approved or authorized the call, it allows the edge computing application server to call. (Page 17).). However, the combination of Bi and Yao does not explicitly disclose … operation indication information indicating the operation on the information of the terminal device. Kim, in the same field of endeavor, discloses a method for obtaining and managing location information of a mobile terminal device that teaches … an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include operation information, as taught by Kim, in determining the authorization result. The motivation to do so would be to improve the authentication method by specifying how the API is allowed to use the information when it is called. In regards to claim 18, the combination of Bi and Yao teach the API-providing network element according to claim 12, wherein the instructions further cause the API-providing network element to send an API-invoking response to the application server when the application server is forbidden to perform the operation on the information of the terminal device , wherein the API-invoking response indicates that the API-invoking request is rejected(Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).). In regards to claim 20, the combination of Bi and Yao teach the API-providing network element according to claim 12, wherein the instructions further cause the API-providing network element to: send a permission request message to an access and mobility management network element, wherein the permission request comprises a second identifier of the terminal device and an identifier of the target application on a mobile network (Bi: The UDM or UDR receives the NEF query on the call, where the query is to query whether the call is a UE permitted or authorized call (Page 17), wherein confirmation of whether the service is allowed to be invoked through the UE identification, the calling ID, the APP identification, and the privacy permission identification of the UE (Page 18) .) ; receiving a permission response message from the access and mobility management network element, wherein the permission response message comprises a permission of the target application of the terminal device on the mobile network (Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).) ; and determining based on the permission of the target application of the terminal device on the mobile network perform the operation on the information of the terminal device, (Bi: When the NEF determines that the UE has approved or authorized the call, it allows the edge computing application server to call. (Page 17).). However, Bi does not explicitly disclose … operation indication information indicating the operation on the information of the terminal device. Kim, in the same field of endeavor, discloses a method for obtaining and managing location information of a mobile terminal device that teaches … an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include operation information, as taught by Kim, in determining the authorization result. The motivation to do so would be to improve the authentication method by specifying how the API is allowed to use the information when it is called. Claim(s) 3 and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bi et al (WO-2021159891-A1) in view of Yao et al.(US-20170068810-A1), in view of Kim et al. (US-20220191650-A1) as applied to claim 1 and further in view of Huang et al. (WO-2018171092-A1). In regards to claim 3, the combination of Bi and Yao teach the method according to claim 1, wherein the obtaining, by the API-providing network element, the authorization result based on the first identifier of the terminal device and the identifier of the target application on the application server comprises: sending, by the API-providing network element, an authorization request to a permission storage network element, wherein the authorization request comprises a second identifier of the terminal device (Bi: The UDM or UDR receives the NEF query on the call, where the query is to query whether the call is a UE permitted or authorized call (Page 17),wherein confirmation of whether the service is allowed to be invoked through the UE identification, the calling ID, the APP identification, and the privacy permission identification of the UE (Page 18).); receiving, by the API-providing network element, an authorization response from the permission storage network element, (Bi: The permission network element (UDM or UDR) determines whether the call is a call permitted or authorized by the UE according to the user authorization configuration, and feeds the determination result back to the NEF (Page 17).) determining, by the API-providing network element, the authorization result based on the identifier of the target application on the application server (Bi: When the NEF determines that the UE has approved or authorized the call, it allows the edge computing application server to call. (Page 17).) an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) But, the combination of Bi, Yao, and Kim does not explicitly teach … wherein the authorization response comprises permissions of all applications corresponding to the terminal device on a mobile network or the authorization result is based on the permissions of all the applications corresponding to the terminal device on the mobile network, and operation indication information indicating the operation on the information of the terminal device. However, Huang in the same field of endeavor, teaches a method for updating terminal device permissions that discloses a server sending a permissions list for all apps on the terminal device based on the identifier of the terminal device (Huang: The terminal device obtains the first privilege list from the server, where the terminal device sends a trigger message to the server, where the trigger message includes The identification information of the terminal device (Page 03), and the permission list can include only the changed API permissions corresponding to all APKs, and can also include changed API permissions and unchanged API permissions for all APKs (Page 08).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include the permissions for all applications corresponding to the terminal device, as taught by Huang, in the authorization response and determining the authorization result based on the authorization response. The motivation to do so would be to improve efficiency by reducing the need for subsequent authorization queries. In regards to claim 14, the combination of Bi and Yao teach the API-providing network element according to claim 12, wherein the instructions further cause the API-providing network element to obtain by the authorization result by: sending an authorization request to a permission storage network element, wherein the authorization request comprises a second identifier of the terminal device (Bi: The UDM or UDR receives the NEF query on the call, where the query is to query whether the call is a UE permitted or authorized call (Page 17),wherein confirmation of whether the service is allowed to be invoked through the UE identification, the calling ID, the APP identification, and the privacy permission identification of the UE (Page 18).); receiving an authorization response from the permission storage network element, (Bi: The permission network element (UDM or UDR) determines whether the call is a call permitted or authorized by the UE according to the user authorization configuration, and feeds the determination result back to the NEF (Page 17).) determining the authorization result based on the identifier of the target application on the application server(Bi: When the NEF determines that the UE has approved or authorized the call, it allows the edge computing application server to call. (Page 17).) . an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) But, the combination of Bi,Yao, and Kim does not explicitly teach … wherein the authorization response comprises permissions of all applications corresponding to the terminal device on a mobile network or the authorization result is based on the permissions of all the applications corresponding to the terminal device on the mobile network , and an operation indication information indicating the operation on the information of the terminal device. However, Huang in the same field of endeavor, teaches a method for updating terminal device permissions that discloses a server sending a permissions list for all apps on the terminal device based on the identifier of the terminal device (Huang: The terminal device obtains the first privilege list from the server, where the terminal device sends a trigger message to the server, where the trigger message includes The identification information of the terminal device (Page 03), and the permission list can include only the changed API permissions corresponding to all APKs, and can also include changed API permissions and unchanged API permissions for all APKs (Page 08).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include the permissions for all applications corresponding to the terminal device, as taught by Huang, in the authorization response and determining the authorization result based on the authorization response. The motivation to do so would be to improve efficiency by reducing the need for subsequent authorization queries. But, the combination of Bi, Yao, and Huang still does not explicitly disclose … operation indication information indicating the operation on the information of the terminal device. However, Kim in the same field of endeavor, discloses a method for obtaining and managing location information of a mobile terminal device that teaches … an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by the combination of Bi and Huang, to include operation information, as taught by Kim, in determining the authorization result. The motivation to do so would be to improve the authentication method by specifying how the API is allowed to use the information when it is called. Claim(s) 4 and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bi et al (WO-2021159891-A1) in view of Yao et al.(US-20170068810-A1), and in view of Kim et al. (US-20220191650-A1) as applied to claim 1, and further in view of Song et al. (KR-101310631-B1). In regards to claim 4, the combination of Bi and Yao teach the method according to claim 1, wherein the obtaining, by the API providing API-providing network element, the authorization result based on the first identifier of the terminal device and the identifier of the target application on the application server comprises: sending, by the API-providing network element, an authorization request to a permission storage network element, wherein the authorization request comprises an identifier of the target application on a mobile network (Bi: The UDM or UDR receives the NEF query on the call, where the query is to query whether the call is a UE permitted or authorized call (Page 17), wherein confirmation of whether the service is allowed to be invoked through the UE identification, the calling ID, the APP identification, and the privacy permission identification of the UE (Page 18).); ; receiving, by the API-providing network element, an authorization response from the permission storage network element, (Bi: The permission network element (UDM or UDR) determines whether the call is a call permitted or authorized by the UE according to the user authorization configuration, and feeds the determination result back to the NEF (Page 17).) ; and determining, by the API-providing network element, the authorization result based on the first identifier of the terminal device, an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) But, the combination of Bi, Yao, and Kim does not explicitly disclose … wherein the authorization response comprises permissions of all terminal devices corresponding to the target application on the mobile network or the permissions of all the terminal devices corresponding to the target application on the mobile network, and an operation indication information indicating the operation on the information of the terminal device included in the basis for determining the authorization result. However, Song in the same field of endeavor, teaches a method for controlling access to a network that discloses…wherein the authorization response comprises permissions of all terminal devices corresponding to the target application on the mobile network (Song: When authenticating the terminal, the authentication server transmits the group information to which the authenticated terminal belongs to the network access server together with the authentication result message, and receives the network access server. Can perform group-specific access control for the group (Page 04).). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include the group based permissions for authentication by the UDM or UDR, as taught by Song. The motivation to do so would be to enhance the method of Bi by providing structured and scalable access control. In regards to claim 15, the combination of Bi and Yao teach the API-providing network element according to claim 12, wherein the instructions further cause the API-providing network element to obtain by the authorization result by: sending an authorization request to a permission storage network element, wherein the authorization request comprises an identifier of the target application on a mobile network (Bi: The UDM or UDR receives the NEF query on the call, where the query is to query whether the call is a UE permitted or authorized call (Page 17), wherein confirmation of whether the service is allowed to be invoked through the UE identification, the calling ID, the APP identification, and the privacy permission identification of the UE (Page 18).); ; receiving an authorization response from the permission storage network element, (Bi: The permission network element (UDM or UDR) determines whether the call is a call permitted or authorized by the UE according to the user authorization configuration, and feeds the determination result back to the NEF (Page 17).) ; and determining the authorization result based on the first identifier of the terminal device, an operation indication information indicating the operation on the information of the terminal device (Kim: The edge application server may transmit a request message (e.g., an one-time reporting) for identifying the location of the UE on a one-off basis in operation (Paragraph 86), or a request for continuously identifying the location of the UE (Paragraph 88).) But, the combination of Bi, Yao, and Kim does not explicitly disclose … wherein the authorization response comprises permissions of all terminal devices corresponding to the target application on the mobile network or the permissions of all the terminal devices corresponding to the target application on the mobile network, and an operation indication information indicating the operation on the information of the terminal device included in the basis for determining the authorization result. However, Song in the same field of endeavor, teaches a method for controlling access to a network that discloses…wherein the authorization response comprises permissions of all terminal devices corresponding to the target application on the mobile network (Song: When authenticating the terminal, the authentication server transmits the group information to which the authenticated terminal belongs to the network access server together with the authentication result message, and receives the network access server. Can perform group-specific access control for the group (Page 04).). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include the group based permissions for authentication by the UDM or UDR, as taught by Song. The motivation to do so would be to enhance the method of Bi by providing structured and scalable access control. Claim(s) 6 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bi et al (WO-2021159891-A1) in view of Yao et al.(US-20170068810-A1), in view of Kim et al. (US-20220191650-A1) as applied to claim 1, and further in view of Ali et al. (US-12003543-B1). In regards to claim 6, the combination of Bi and Yao teach the method according to claim 1, wherein, when the application server is allowed to perform the operation on the information of the terminal device, the API-providing network element sends an API-invoking response to the application server, (Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).) . But, the combination of Bi and Yao does not explicitly disclose wherein the API-invoking response indicates that the API-invoking request is successfully performed. However, Ali in the same field of endeavor, discloses a method for modifying and validating API requests that teaches… wherein the API-invoking response indicates that the API-invoking request is successfully performed (Ali: On the other hand, when the API-validation agent returns a reply that indicates that the API call has been approved (i.e, the API call is valid), the API handler directs the API-processing module that is associated with the API call to perform the operation associated with the API call and to provide a reply message to the source of the API call to indicate the completion of this operation (Col 13: Lines 34-41, Page 18 of Provisional).) . Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include a reply message as taught by Ali. The motivation to do so would be to improve communication by ensuring the Application Server is notified that the API call was successfully completed after call was determined to be allowed. In regards to claim 17, the combination of Bi and Yao teach the API-providing network element according to claim 12, wherein the instructions further cause the API-providing network element to send an API-invoking response to the application server when the application server is allowed to perform the operation on the information of the terminal device , (Bi: UDM/UDR returns the user authorization identification information corresponding to NEF. If the call is allowed, the UDM/UDR returns the license identifier as 1. Otherwise, the UDM/UDR returns the license identifier as 0 (Page 18).) . But, the combination of Bi and Yao does not explicitly disclose wherein the API-invoking response indicates that the API-invoking request is successfully performed. However, Ali in the same field of endeavor, discloses a method for modifying and validating API requests that teaches… wherein the API-invoking response indicates that the API-invoking request is successfully performed (Ali: On the other hand, when the API-validation agent returns a reply that indicates that the API call has been approved (i.e, the API call is valid), the API handler directs the API-processing module that is associated with the API call to perform the operation associated with the API call and to provide a reply message to the source of the API call to indicate the completion of this operation (Col 13: Lines 34-41, Page 18 of Provisional).) . Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include a reply message as taught by Ali. The motivation to do so would be to improve communication by ensuring the Application Server is notified that the API call was successfully completed after call was determined to be allowed. Claim(s) 8, 11, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bi et al (WO-2021159891-A1) in view of Yao et al.(US-20170068810-A1), in view of Kim et al. (US-20220191650-A1) as applied to claim 1, and further in view of Tangudu et al. (US-20200275279-A1). In regards to claim 8, the combination of Bi and Yao teach the method according to claim 7, But, the combination of Bi, Yao, and Kim does not explicitly disclose … wherein the API- invoking response comprises a rejection cause, and the rejection cause indicates that the operation requested by the application server fails to be authorized. However, Tangudu in a similar field of endeavor, discloses a method for mitigating DOS attacks in a wireless network that teaches… wherein the API- invoking response comprises a rejection cause, and the rejection cause indicates that the operation requested by the application server fails to be authorized (Tangudu: On verifying that the UE 104 does not have the permissions to access the CAG cell/NPN , the UDM includes the reject message indicating that the UE 104 is not permitted (Paragraph 150).) . Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include a reply message as taught by Tangudu. The motivation to do so would be to improve communication by ensuring the Application Server is notified that the API call was the reason for rejection. In regards to claim 11, the combination of Bi and Yao teach the method according to claim 10, But, the combination of Bi, Yao, and Kim does not explicitly disclose … wherein, when the API-invoking response indicates that the API-invoking request is rejected, the API-invoking response comprises a rejection cause, and the rejection cause indicates that the operation requested by the application server fails to be authorized. However, Tangudu in a similar field of endeavor, discloses a method for mitigating DOS attacks in a wireless network that teaches… wherein, when the API-invoking response indicates that the API-invoking request is rejected, the API-invoking response comprises a rejection cause, and the rejection cause indicates that the operation requested by the application server fails to be authorized (Tangudu: On verifying that the UE 104 does not have the permissions to access the CAG cell/NPN , the UDM includes the reject message indicating that the UE 104 is not permitted (Paragraph 150).) . Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include a reply message as taught by Tangudu. The motivation to do so would be to improve communication by ensuring the Application Server is notified that the API call was the reason for rejection. In regards to claim 19, the combination of Bi and Yao teach the API-providing network element according to claim 18, But, the combination of Bi, Yao, and Kim does not explicitly disclose … wherein the API- invoking response comprises a rejection cause, and the rejection cause indicates that the operation requested by the application server fails to be authorized. However, Tangudu in a similar field of endeavor, discloses a method for mitigating DOS attacks in a wireless network that teaches… wherein the API- invoking response comprises a rejection cause, and the rejection cause indicates that the operation requested by the application server fails to be authorized (Tangudu: On verifying that the UE 104 does not have the permissions to access the CAG cell/NPN , the UDM includes the reject message indicating that the UE 104 is not permitted (Paragraph 150).) . Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the method of authorizing a call to access information on a UE device taught by Bi to include a reply message as taught by Tangudu. The motivation to do so would be to improve communication by ensuring the Application Server is notified that the API call was the reason for rejection. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. WO 2015077993 to Wang et al. discloses an authorization request comprising an identification of a terminal device and an identification of a target application. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Carl G Colin whose telephone number is (571) 272-3862. The examiner can normally be reached Monday-Thursday 8:00-5:00 PM, Friday 8-12 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amy Cohen Johnson can be reached at (571) 272-2238. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CARL G COLIN/Supervisory Patent Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Feb 03, 2023
Application Filed
Mar 28, 2025
Non-Final Rejection mailed — §103
Jun 12, 2025
Response Filed
Oct 07, 2025
Final Rejection mailed — §103
Jan 05, 2026
Response after Non-Final Action
Feb 16, 2026
Request for Continued Examination
Feb 25, 2026
Response after Non-Final Action
Sep 10, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12634114
RECURRENT NEURAL NETWORK-BASED USER IDENTITY MISAPPROPRIATION PREVENTION FROM PUBLIC DOMAINS AND CONNECTIONS
2y 1m to grant Granted May 19, 2026
Patent 12608469
SYSTEMS AND METHODS FOR STORAGE SYSTEM ATTACK DETECTION AND RESPONSE
3y 1m to grant Granted Apr 21, 2026
Patent 12592963
DETECTION DEVICE, DETECTION METHOD, AND DETECTION PROGRAM
2y 11m to grant Granted Mar 31, 2026
Patent 12554808
PUBLIC KEY EMBEDDED IN CONTENT FOR VERIFICATION OF AUTHORSHIP
2y 3m to grant Granted Feb 17, 2026
Patent 12547704
AUTOMATED DEPLOYMENT OF RELOCATABLE CODE BLOCKS AS AN ATTACK COUNTERMEASURE IN SOFTWARE
2y 9m to grant Granted Feb 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
48%
Grant Probability
99%
With Interview (+54.1%)
4y 4m (~8m remaining)
Median Time to Grant
High
PTA Risk
Based on 136 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month