DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 07/22/2026 have been fully considered but they are not persuasive. Applicant argues, on page 7 second paragraph, that the serial number is not a serial number of the user device as Rao teaches serial number 420 of node 165. Griot is directed to generating a password for authentication of a user equipment. Rao is directed to an offline authentication method of a node (see Rao [0010]). Rao applies a hash function on the node serial number to generate a password for the node. However, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have applied the hashing function of Rao to the serial number of the UE in Griot to generate a password for the UE to arrive at the invention. Therefore, the argued limitation would be obvious in view of the combination of Griot and Rao.
Applicant argues, on page 8 second paragraph, that in Rao, the node 165 is not the device based identifier of the user device. However, Rao is directed to authentication of the node 165 using a node password generated from the node serial number, and by applying the hash function of Rao to authenticate a user device in Griot, the hash function would be applied to the user device identifier to generate a password for the user device. Therefore, the argued limitation would be obvious in view of the combination of Griot and Rao.
Applicant argues, on page 8 last paragraph, that the motivation to combine Griot and Rao is not supported. Applicant argues further, on page 9 fourth and fifth paragraph, that the motivation of improving the authentication and authorization is conclusory and unsupported. The examiner respectfully disagrees. This argument is conclusory and based on unsupported with evidence or persuasive argument. It is well known to a person of ordinary skill in the art that a password generate by a hash function is stronger than a simple password, and that would have improved authentication and authorization.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Griot et al. (US 2015/0282042 A1) in view of Rao et al. (US 2015/0128254 A1).
Regarding claim 1, Griot et al. teach A method comprising:
receiving, by a computing device and from a user device, a request for the user device to access a wireless communication service (Griot [0052] UE 106 can request attachment from MME112 (e.g., using EAP), via eNB 108), wherein the request comprises comprising a device-based identifier of the user device and a password (Griot [0038] a UE can determine whether and/or which credentials are needed to communicate with the eNB to receive the service, and can provide the appropriate credentials ... credentials can include an identifier of the UE (e.g., international mobile subscriber identity (IMSI), security root key (Ki) or other USIM credentials), username/password) previously determined by the computing device (Griot [0038] credentials for the service can be provisioned to the UE by the eNB or other network component).
Griot et al. do not teach
The password previously determined based on the device-based identifier and a predefined function;
determining, based on the device-based identifier of the request, via the predefined function, a second password;
authenticating, based on the second password corresponding with the password, the user device; and
authorizing the user device to access the wireless communication service.
In a similar endeavor, Rao et al. teach
The password previously determined based on the device-based identifier and a predefined function (Rao [0044]-[0045] processor 230 uses username 155, serial number 420, shared secret 430, authorization level 440, and lifespan 410 to generate password 140 in accordance with hash function 232A... serial number 420 is the serial number of node 165) ;
determining, based on the device-based identifier of the request, via the predefined function, a second password (Rao [0059]-[0060 processor 340 uses username 155, serial number 515, shared secret 525, selected authorization level 565, and current time 315 to (i) generate a string 572, in accordance with hash function 232B... Recall that hash function 232B is a functional equivalent of hash function 232A);
authenticating, based on the second password corresponding with the password, the user device (Rao [0059] determine whether string 572 matches password 140, i.e., whether string 572 and password 140 are identical to one another); and
authorizing the user device to access the wireless communication service (Rao Fig. 5 step 580 Grant access with selected level, [0064] a match between string 572 and password 140 means that the selected authorization level 565 that was used in step 570 to generate string 572 is the same as authorization level 440 as specified in step 435 of method 400, and is also the authorization level to which lineman 180 is entitled. Thus, method 500 has effectively deduced authorization level 440 from password 140).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Griot et al. password by incorporating Rao et al. password generation by hash functions by applying the hash function of Rao to the UE identifier of Griot to generate a strong password for the UE to arrive at the invention
The motivation of doing so would have improved the authentication and authorization by using a stronger password.
Regarding claim 2, the combination of Griot et al. and Rao et al. teaches The method of claim 1, further comprising receiving, by the computing device and from the user device, a request for a connection profile (Griot [0054] the UE 106 may include a network/service connecting component 306, as described further herein, to request information regarding network service), the request comprising the device-based identifier of the user device Griot [0092] transmitting a request to establish a connection with the network ... the request may include an IMSI or other substantially unique identifier of the UE 106. In one example, credential requesting component 810 may use an International Mobile Station Equipment Identity (IMEI) in the request).
Regarding claim 3, the combination of Griot et al. and Rao et al. teaches The method of claim 1, wherein the request to access the wireless communication service further comprises an extensible authentication protocol tunneled transport layer security request (Griot [0115] authentication requesting component 1310 can determine the type of EAP authentication.. the EAP authentication type can include at least one of EAP-transport layer security (EAP-TLS), EAP-tunneled TLS) having an inner identifier and an outer identifier, wherein the inner identifier comprises the device-based identifier (Griot [0038] credentials can include ..username/password pairs) and the outer identifier comprises the authentication identifier (Griot [0113] a new IE indicating EAP authentication, a specific IMSI or other UE identifier. Note: authentication identifier is interpreted as the IE indicating EAP authentication and the username is interpreted as the device-based identifier since Griot [0038] teaches the username as the UE identifier)
Regarding claim 4, the combination of Griot et al. and Rao et al. teaches The method of claim 1, further comprising determining, by the computing device and, based on inputting the device-based identifier into the predefined function, the password (Rao [0044] password 140 is a hash value generated from a data set of username 155, serial number 420).
Regarding claim 5, the combination of Griot et al. and Rao et al. teaches The method of claim 1, further comprising
determining that the second password matches the password (Rao [0059] determine whether string 572 matches password 140, i.e., whether string 572 and password 140 are identical to one another).
Regarding claim 6, the combination of Griot et al. and Rao et al. teaches The method of claim 2, wherein the device-based identifier comprises one or more of an international mobile equipment identifier (IMEI) or an international mobile subscriber identifier (IMSI) (Griot [0105] UE 106 may identify itself by using its IMEI), the method further comprising validating, based on the one or more of the IMEI or the IMSI, the request for the connection profile (Griot [0072] the credentials expected are USIM credentials that can be validated by an AAA server at an HPLMN of the UE 106, Griot [0038] credentials for the service can be provisioned to the UE by the eNB or other network component).
Regarding claim 7, the combination of Griot et al. and Rao et al. teaches The method of claim 1, further comprising:
determining a type of authentication based on an authentication identifier (Griot
[0052] UE 106 can indicate an authentication type as well. MME 112 can provide the credentials (and/or requested authentication type) to AAA server 122, Griot [0113] a new IE indicating EAP authentication); and
switching, based on the type of authentication (Griot [0113] EAP authentication) , from a first authentication procedure to a second authentication procedure, wherein the first authentication procedure is based on user provided credentials (Griot [0038] credentials can include ..username/password pairs) and the second authentication procedure is based on generated credentials (Griot [0038] credentials can include an identifier of the UE (e.g., international mobile subscriber identity (IMSI), security root key (Ki) or other USIM credentials), username/password pairs... for example, credentials for the service can be provisioned to the UE by the eNB or other network component), wherein the generated credentials are based on the device-based identifier (Griot [0113] a new IE indicating EAP authentication, a specific IMSI or other UE identifier).
Regarding claim 8, Griot et al. teaches A method comprising:
receiving, by a computing device and from a user device, a device-based identifier associated with the user device (Griot [0038] a UE .. can provide the appropriate credentials; . . credentials can include an identifier of the UE);
determining a password for the user device (Griot [0038] credentials can include an identifier of the UE (e.g., international mobile subscriber identity (IMSI), security root key (Ki) or other USIM credentials), username/password pairs... for example, credentials for the service can be provisioned to the UE by the eNB or other network component);
sending, to the user device, the password (Griot [0038] credentials for the service can be provisioned to the UE by the eNB);
receiving, from the user device, an authentication request for accessing the wireless communication service (Griot [0052] UE 106 can request attachment from MME 112 (e.g., using EAP), via eNB 108, by specifying the credentials received from the service provider network 104), wherein the authentication request comprises the device based identifier and the password (Griot [0051] the UE 106 can provide the appropriate username/password PIN, etc. for the service).;
Griot et al. do not teach
determining, based on the device-based identifier and a hash function, a password for the user device;
determining, based on the device-based identifier of the authentication request and the hash function, a second password
determining, the second password matches the password; and
sending, to the user device and based on the second password matching the password, an authorization to access the wireless communication service.
In a similar endeavor, Rao et al. teach
determining, based on the device-based identifier and a hash function, a password for the user device (Rao [0044]-[0045] processor 230 uses username 155, serial number 420, shared secret 430, authorization level 440, and lifespan 410 to generate password 140 in accordance with hash function 232A... serial number 420 is the serial number of node 165);
sending, to the user device, the password (Rao [0051]-[0053] method 400 provides password 140 to NOC operator 120. Prior to the commencement of method 500, NOC operator 120 provides password 140 to technician 180... from technician 180, processor 340 receives username 155 and password 140) ;
determining, based on the device-based identifier of the authentication request and the hash function, a second password (Rao [0059]-[0060 processor 340 uses username 155, serial number 515, shared secret 525, selected authorization level 565, and current time 315 to (i) generate a string 572, in accordance with hash function 232B... Recall that hash function 232B is a functional equivalent of hash function 232A. Note: the second password in the claim is interpreted as the string 572 of Rao);;
determining, the second password matches the password(Rao [0059] determine whether string 572 matches password 140, i.e., whether string 572 and password 140 are identical to one another); and
sending, to the user device and based on the second password matching the password (Rao [0063] If string 572 matches password 140, then password 140 is deemed to be valid,), an authorization to access the wireless communication service (Rao [0066] processor 340 grants technician 180 access to node 165 with selected authorization level 565)..
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Griot et al. password by incorporating Rao et al. password generation by hash functions by applying the hash function of Rao to the UE identifier of Griot to generate a strong password for the UE to arrive at the invention
The motivation of doing so would have improved the authentication and authorization by using a stronger password.
Regarding claim 9, the combination of Griot et al. and Rao et al. teaches The method of claim 8, further comprising associating the device-based identifier with the password (Rao [0044]-[0045] processor 230 uses username 155, serial number 420, shared secret 430, authorization level 440, and lifespan 410 to generate password 140 in accordance with hash function 232A... serial number 420 is the serial number of node 165).
The motivation of doing so would have improved the authentication and authorization.
Regarding claim 10, the combination of Griot et al. and Rao et al. teaches The method of claim 8, further comprising determining, based on the device-based identifier, a service identifier for the wireless communication service (Griot [0045] provide network identification information and service identification information to one or more UEs),.
Regarding claim 11, the combination of Griot et al. and Rao et al. teaches The method of claim 8, wherein sending, to the user device, the password comprises, sending, to the user device a connection profile (Griot [0038] credentials for the service can be provisioned to the UE by the eNB or other network component)comprising the device-based identifier and the password (Griot [0038] credentials can include ..username/password pairs), wherein the connection profile is sent to the user device based on receiving a connection profile request from the user device (Griot [0054] the UE 106 may include a network/service connecting component 306, as described further herein, to request information regarding network service).
Regarding claim 12, the combination of Griot et al. and Rao et al. teaches The method of claim 8, further comprising authenticating the user device based on a type of authentication indicated by an authentication identifier ((Griot [0113] a new IE indicating EAP authentication, a specific IMSI or other UE identifier. Note: authentication identifier is interpreted as the IE indicating EAP authentication), wherein the type of authentication is associated with the wireless communication service (Griot [0115] authentication requesting component 1310 can determine the type of EAP authentication.. the EAP authentication type can include at least one of EAP-transport layer security (EAP-TLS), EAP-tunneled TLS).
Regarding claim 13, the combination of Griot et al. and Rao et al. teaches The method of claim 8, wherein sending the authorization to access the wireless communication service comprises sending, to the user device a message indicating the user device is authorized to access the wireless communication service Griot [0116] Once the authentication is performed, authentication component 1314 can communicate an authentication status back to the UE 106).
Regarding claim 14, the combination of Griot et al. and Rao et al. teaches The method of claim 8, wherein the device-based identifier comprises one or more of an international mobile equipment identifier (IMEI) or an international mobile subscriber identifier (IMSI) (Griot [0113] a new IE indicating EAP authentication, a specific IMSI or other UE identifier.).
Regarding claim 15, Griot et al. teaches A method comprising:
receiving, by a user device and from a computing device, a connection profile (Griot [0038] credentials for the service can be provisioned to the UE by the eNB or other network component) comprising a device-based identifier of the user device and a password (Griot [0038] credentials can include an identifier of the UE (e.g., international mobile subscriber identity (IMSI), security root key (Ki) or other USIM credentials), username/password pairs);
sending, to the computing device and based on the connection profile, an authentication request for accessing a wireless communication service (Griot [0052] UE 106 can request attachment.. by specifying the credentials received from the service provider network 104), wherein the authentication request comprises the device-based identifier and the password (Griot [0038] credentials can include an identifier of the UE (e.g., international mobile subscriber identity (IMSI), security root key (Ki) or other USIM credentials), username/password pairs).
Griot et al. do not teach
The password generated by the computing device based on the device-based identifier and a hash function;
causing, based on the authentication request, the computing device to determine a second password, based on the device-based identifier of the authentication request and the hash function, corresponds with the password;
receiving, based on the second password corresponding to the password, authorization to access the wireless communication service; and
accessing the wireless communication service.
In a similar endeavor, Rao et al. teach
The password generated by the computing device based on the device-based identifier and a hash function (Rao [0044]-[0045] processor 230 uses username 155, serial number 420, shared secret 430, authorization level 440, and lifespan 410 to generate password 140 in accordance with hash function 232A... serial number 420 is the serial number of node 165);
causing, based on the authentication request, the computing device to determine a second password, based on the device-based identifier of the authentication request and the hash function (Rao [0059]-[0060 processor 340 uses username 155, serial number 515, shared secret 525, selected authorization level 565, and current time 315 to (i) generate a string 572, in accordance with hash function 232B... Recall that hash function 232B is a functional equivalent of hash function 232A.Note: the second password in the claim is interpreted as the string 572 of Rao) , corresponds with the password (Rao [0063] If string 572 matches password 140);
receiving, based on the second password corresponding to the password (Rao [0063] If string 572 matches password 140, then password 140 is deemed to be valid) authorization to access the wireless communication service (Rao [0066] processor 340 grants technician 180 access to node 165 with selected authorization level 565).; and
accessing the wireless communication service (Rao Fig. 5 step 580 Grant access with selected level).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the examined application to have modified Griot et al. password by incorporating Rao et al. password generation by hash functions by applying the hash function of Rao to the UE identifier of Griot to generate a strong password for the UE to arrive at the invention
The motivation of doing so would have improved the authentication and authorization by using a stronger password.
Regarding claim 16, the combination of Griot et al. and Rao et al. teaches The method of claim 15, wherein the connection profile further comprises an authentication identifier and an encryption key (Griot [0072] credentials stored for a plurality of subscription providers, which may include username/password or PIN values, security keys)..
Regarding claim 17, the combination of Griot et al. and Rao et al. teaches The method of claim 15, wherein the authentication request comprises an extensible authentication protocol tunneled transport layer security request (Griot [0115] authentication requesting component 1310 can determine the type of EAP authentication.. the EAP authentication type can include at least one of EAP-transport layer security (EAP-TLS), EAP-tunneled TLS) having an inner identifier and an outer identifier, wherein the inner identifier comprises the device-based identifier (Griot [0038] credentials can include ..username/password pairs) and the outer identifier comprises an authentication identifier. (Griot [0113] a new IE indicating EAP authentication, a specific IMSI or other UE identifier.
Regarding claim 18, the combination of Griot et al. and Rao et al. teaches The method of claim 15, further comprising sending a request for the connection profile Griot [0054] the UE 106 may include a network/service connecting component 306, as described further herein, to request information regarding network service), wherein the connection profile is received in response to validation of the request based on the device-based identifier (Griot [0072] the credentials expected are USIM credentials that can be validated by an AAA server at an HPLMN of the UE 106, Griot [0038] credentials for the service can be provisioned to the UE by the eNB or other network component).
Regarding claim 19, the combination of Griot et al. and Rao et al. teaches The method of claim 15, wherein the hash function comprises a one-way hash function. (Rao [0021] Hashing is a non-reversible, or one-way, operation).
The motivation of doing so would have improved the authentication and authorization of service.
Regarding claim 20, the combination of Griot et al. and Rao et al. teaches The method of claim 15, wherein the authentication request further comprises an authentication identifier indicating a type of authentication associated with the wireless communication service (Griot [0113] a new IE indicating EAP authentication, a specific IMSI or other UE identifier. Note: authentication identifier is interpreted as the IE indicating EAP authentication ) and one or more services that the user device is authorized to access via the wireless communication service (Griot [0113] perform EAP authentication for hotspot network types).
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAID M ELNOUBI whose telephone number is (571)272-9732. The examiner can normally be reached Monday-Friday 9:30AM to 6:00PM ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kathy Wang-Hurst can be reached at 571-270-5371. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SAID M ELNOUBI/Examiner, Art Unit 2644