Prosecution Insights
Last updated: August 17, 2026
Application No. 18/161,507

GRANULAR USER CONSENT AND ITS ENFORCEMENT

Final Rejection §103
Filed
Jan 30, 2023
Priority
Jan 31, 2022 — provisional 63/267,387
Examiner
LEUNG, ROBERT B
Art Unit
2494
Tech Center
2400 — Computer Networks
Assignee
Qualcomm Incorporated
OA Round
4 (Final)
84%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
529 granted / 626 resolved
+26.5% vs TC avg
Strong +17% interview lift
Without
With
+17.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
22 currently pending
Career history
638
Total Applications
across all art units

Statute-Specific Performance

§101
12.7%
-27.3% vs TC avg
§103
42.9%
+2.9% vs TC avg
§102
13.0%
-27.0% vs TC avg
§112
20.2%
-19.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 626 resolved cases

Office Action

§103
DETAILED ACTION Response to Arguments Claims 1-3 and 6-30 are currently pending. Claims 4 and 5 were canceled. Claims 1, 4, 13, 16, and 29 were amended. Response: Claim Rejections – 35 USC § 103 Applicant argues on pp. 9-10 of the REMARKS filed on May 27, 2026 that US 2023/0319533 (“Ly”) and US 2012/0208503 (“Johansson”) do not disclose the amended features recited in independent claims 1 and 13. Applicant points out that in [Johansson, ¶0009, 0028], the centralized server terminates the MDT session and the OAM is left out of the revocation process, which does not disclose (and contradicts with) “terminate the data processing task based on the user consent result in response to reception of the user consent result from the second network node…” as recited in independent claim1 and similarly in independent claim 13. However, the Examiner respectfully disagrees. Applicant’s arguments do not elaborate how Johansson does not teach the amended features. The OAM being left out of the revocation process has no bearing on the combined teachings of Ly and Johansson to the claimed invention. Ly discloses a NWDAF and a UDM/UDR, corresponding to the first and second network nodes, respectively, in claims 1 and 13. These components in Ly are analogous to the “first network node”, which is consistent with the originally filed specifications: “a first network node 191 (e.g., …a network data analytics function (NWDAF)) …” [0048]) and the “second network node”, which is also consistent with the originally filed specifications: “a second network node 191’ (e.g., a UDM)…” [0048]. The UDM/UDR, according to [Ly, ¶0150], checks for a user consent and returns a response (i.e., a “reception of the user consent result from the second network node”), which can be sent to a NRF to forward to the NWDAF. The user equipment (UE) grants (provides consent) permissions for the NWDAF to perform data collection by the way of the UDM/UDR, which communicates user consent information, such as expiration time (i.e. a status), to the NWDAF [Ly, ¶0112, 0181]. Therefore, if permission for data collection, or a trace session, can be granted, it can also be revoked to stop the data collection. Johansson was introduced to provide disclosures of explicitly terminating data collection, or trace sessions. A user can revoke consent, which is handled by a centralized server according to [Johansson, Abstract, ¶0009]. While Johansson does not explicitly recite the components, such as NWDAF, UDM/UDR, or the like, similar those in Ly, the primary concept of enabling a user to control their data collection based on their consent was apparent. For example, the centralized server in Johansson can be analogous to the NWDAF in Ly. Thus, the combined teachings of Ly and Johansson disclosed the amended features to independent claims 1 and 13. Applicant’s arguments on pp. 9-10 of the REMARKS regarding independent claims 16 and 29 have been fully considered and are persuasive. Therefore, the 35 U.S.C. 103 rejection of claims 16 and 29 over Ly in view of Johansson has been withdrawn. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-3 and 6-15 are rejected under 35 U.S.C. 103 as being unpatentable over US 2023/0319533 to Ly et al. (hereinafter, “Ly”) in view of US 2012/02085031 to Johansson (hereinafter, “Johansson”). As per claim 1: Ly discloses: An apparatus for wireless communication at a first network node (a Network Data Analytics Function (NWDAF) operating in a 5G system [Ly, ¶0046]), comprising: a memory; and at least one processor coupled to the memory and configured to (nodes/functional entities of the network are implemented in computing systems comprising a processor and memory [Ly, ¶0233-0235]): transmit, to a second network node, first information associated with granular user consent control, the first information being further associated with a data processing task and a user equipment (UE) (“The NWDAF performs an NUDM_SDM_Get service operation to first obtain user consent from the one or more UEs from UDM/UDR. The operation may include identifiers for the one or more UEs, a group ID, the types of data to be collected, a list of application IDs that data is collected from, one or more Analytics IDs, the expected time duration of data collection, whether data is anonymized or aggregated, what data transformation functions to process the data with, etc.” [Ly, ¶0149; Fig. 11(Step 1)]; herein, the UDM/UDR is the “second network node”); receive, from the second network node, a user consent result associated with the data processing task and a user of the UE based on the granular user consent control (“The UDM/UDR returns a response of all the UEs that user consent is allowed for data collection based on the types of data, the application IDs, whether data needs to be anonymized and/or aggregated, an expiration time for the data and the associated expiration options, etc.” [Ly, ¶0150; Fig. 11(Step 2)]); and terminate the data processing task based on the user consent result in response to reception of the user consent result from the second network node (“The NWDAF, based on pre-configuration or after having discovered an AF that has the capability to collect the desired UE data, sends an EventExposure _Subscribe service operation to the AF via the NEF. The NWDAF may provide the AF information about the user consent, such as the consent for certain data types or from certain applications…” [Ly, ¶0151]; furthermore, “After the user consent policy has been disseminated and applied, the network needs to ensure the policy is enforced until the expiration of the policy or until the user revokes the user consent. The NWDAF may manage the enforcement of the user consent policy by maintaining expiration of the user consent for each UE and with a list of consumers the data has been shared with. The NWDAF may manage the expiration time internally and notify all consumers of the UE data upon expiry of the user consent. The UDM/UDR may alternatively manage the expiration time of the user consent and the NWDAF and other data consumers may subscribe to get notification at the expiry of the user consent. The existing service operations of the UDM/UDR or NWDAF may be enhanced to allow for the enforcement of the user consent.” [Ly, ¶0181]) Ly does not explicitly disclose the data collection, or the “data processing”, is a “trace session” and that “the user consent result is associated with a revocation of the trace session that is already ongoing”. However, Johansson is directed to analogous art of managing user consent for minimization drive test (MDT) [Johansson, Abstract]. Johansson discloses: a trace session (MDT is a feature where user equipment (UE) collects measurements and report the measured information [Johansson, ¶0002]); and the user consent result is associated with a revocation of the trace session that is already ongoing (when a user consent information changes, such as the user revoking consent, a centralized server updates the user consent information and forwards a signaling message to terminate a current MDT [Johansson, ¶0009]) Thus, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to implement any type of data collection session in Ly, such as an MDT session, and enable users to revoke consents to stop data collection in real-time. MDT was a well-known technique in cellular systems for measuring and assessing network coverage and capacity for network optimization. The application of MDT was further suggested as one of the data type transport in [Ly, ¶0127-0128]. As per claim 2: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: wherein the granular user consent control is based on at least one of an area, a public land mobile network (PLMN), a radio access technology (RAT), a radio network controller (RNC), a target area, a slice, a service associated with the data processing task, a carrier frequency, a time, a UE power status, available UE computational power, or the user of the UE (a user consent profile has parameters that allow a user to specify what types of data to share and user equipment (UE) specific data, such as battery level and memory usage [Ly, ¶0159]; there are 11 categories of types of data user consent described in [Ly, ¶0160-0164] that include, but not limited to, locations, time, network protocols, MNO, etc.). As per claim 3: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: wherein the user consent result is further based on second information from the UE or the first information, the first information indicates at least one of an area, a public land mobile network (PLMN), a radio access technology (RAT), a radio network controller (RNC), a target area, or a carrier frequency (“…user consent is required in order for the network to collect data from the UE. A user consent profile may be maintained to specify the parameters for the user consent and may be comprised of the types of data the user is granting the network to collect…” [Ly, ¶0158]; the communication system include multiple access systems and one or more channel access schemes, include base stations in RANs that offer communication access for the UEs [Ly, ¶0045, 0193]), and the second information includes a UE power status or an indication of available UE computational power (battery level and memory usage are also parameters defined in the user consent profile [Ly, ¶0159]). As per claim 6: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: wherein the trace session is based on a service associated with a service identifier (ID) (initiating data collection (an MDT session in view of Rácz) from the UE by using one or more application IDs whose data should be collected [Ly, ¶0153]). As per claim 7: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: wherein the first network node is a data collection requesting entity associated with the data processing task or a data processor associated with the data processing task (the NWDAF provides data analytics to service consumers and can subscribe to collect data [Ly, ¶0046]). As per claim 8: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: wherein the first network node corresponds to at least one of an operations, administration, and maintenance (OAM), a radio access network (RAN), or a network data analytics function (NWDAF) (NWDAF, [Ly, ¶0148]), and the second network node corresponds to a unified data management (UDM) (UDM/UDR [Ly, ¶0149]). As per claim 9: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: the at least one processor being further configured to: receive, from the second network node, an updated user consent result associated with the data processing task and the user of the UE based on the granular user consent control; and handle the data processing task based on the updated user consent result (“If user consent is present in the UDM/UDR, the UDM/UDR may contact the AMF(s) that are associated with each UE and initiate a UE Configuration Update procedure with each UE in order to send UE Data Collection Information to each UE as previously described. The content of the UE Data Collection Information may be based on information that was received from the NWDAF.” [Ly, ¶0150; Fig. 11(Step 2)]; the update renews user consents (which in turn, provides the NWDAF with user consents) [Ly, ¶0175]). As per claim 10: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: wherein the transmission of the first information to the second network node corresponds to a request for the user consent result (“An event triggers the NWDAF to start data collection for one or more UEs.” [Ly, ¶0149; Fig. 11(Step 1)]). As per claim 11: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: wherein the first network node receives second information from the UE and forwards the second information from the UE to the second network node (“…UEs may trigger data collection and analytics generation from the NWDAF during PDU session establishment procedure by including an indication that may be used to request data collection and analytics from the NWDAF. The indication may be used to select appropriate Analytic IDs, or a list of Analytic IDs may be specified by the UE in addition to providing the indication.” [Ly, ¶0080]; this request corresponds to the triggered event of the NWDAF described in [Ly, ¶0149; Fig. 11(Step 1)]). As per claim 12: Ly in view of Johansson disclose all limitations of claim 1. Furthermore, Ly discloses: further comprising a transceiver coupled to the at least one processor (communication circuity for connecting to and communicating on the network [Ly, ¶0238]). As per claim 13: Claim 13 is different from overall scope of claim 1 but recites substantially similar subject matter as claim 1. Specifically, claim 13 is a method corresponding to the functions of the apparatus of claim 1. Ly discloses all these functions (a method) as applied in the rejection of claim 1. Thus, the rejection of claim 1 is also applicable to claim 13. As per claim 14: Claim 14 incorporates all limitations of claim 13 and is a method corresponding to claim 2. Therefore, the rejections of claims 2 and 13 are also applicable to claim 14. As per claim 15: Claim 15 incorporates all limitations of claim 13 and is a method corresponding to claim 3. Therefore, the rejections of claims 3 and 13 are also applicable to claim 15. Allowable Subject Matter Claims 16-30 are allowable The same reasons for allowable subject matter provided in Allowable Subject Matter of the Non-Final Rejection dated Feb. 27, 2026 are applicable herein. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 2014/0052871: The consent status of a user device is received to determine if data collection by a network operator can be performed. See ¶0033. US 2013/0324106: A mobile management entity (MME) checks if a particular subscriber has provided consent for MDT measurements to be carried out by the subscriber’s mobile terminal. See ¶0077. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ROBERT B LEUNG whose telephone number is (571)270-1453. The examiner can normally be reached Mon - Thurs: 10am-7pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JUNG KIM can be reached at 571-272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ROBERT B LEUNG/Primary Examiner, Art Unit 2494 1 Cited by Examiner on June 9, 2025.
Read full office action

Prosecution Timeline

Show 2 earlier events
Sep 09, 2025
Response Filed
Nov 03, 2025
Final Rejection mailed — §103
Jan 05, 2026
Response after Non-Final Action
Feb 03, 2026
Request for Continued Examination
Feb 13, 2026
Response after Non-Final Action
Feb 27, 2026
Non-Final Rejection mailed — §103
May 27, 2026
Response Filed
Aug 04, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12694109
Systems and Methods for Detecting, Localizing, and Visualizing Manipulations of Portable Document Format Files
2y 5m to grant Granted Jul 28, 2026
Patent 12688307
SYSTEMS AND METHODS FOR CYBERSECURITY RISK ASSESSMENT
1y 8m to grant Granted Jul 21, 2026
Patent 12682056
TECHNIQUES FOR DETECTING ANOMALIES IN DATA FILES
2y 2m to grant Granted Jul 14, 2026
Patent 12671596
AUTHENTICATION APPARATUS, AUTHENTICATION TARGET APPARATUS, IMAGE FORMING APPARATUS, REPLACEMENT UNIT, AND AUTHENTICATION METHOD
2y 6m to grant Granted Jun 30, 2026
Patent 12657299
Ransomware Detection Training Using Variable Levels Of Encryption
2y 4m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+17.1%)
2y 6m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 626 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month