DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The Amendment filed April 20, 2026, has been entered. Claims 1-11, 13-18, and 20-23 are pending in the application. Applicant has submitted amendments to the claims along with other remarks. Claims 1-11, 13-18, and 20-23 are still rejected by prior art references, refer to the following rejection for details.
Response to Arguments
Applicant’s arguments and amendments, see pp. 9-15 of the response, filed June 30, 2025, with respect to the rejection(s) of claim(s) 1-11, 13-18, and 20-23 under § 103 have been fully considered and are persuasive. However, upon further consideration for the amendments, a new ground(s) of rejection is made in view of new reference, please see the rejection for details.
Claim Rejections - 35 USC § 103
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claims 1-4, 6-7, 13-17, and 20-23 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Publication No. 2023/0070253 (hereinafter “Rajadurai”) in view of U.S. Publication No. 2022/0240085 (hereinafter “Long”).
Regarding claim 1, Rajadurai teaches: A method for establishing secure communication, comprising: receiving (e.g., Fig. 6, Step 2k), by a terminal device (Fig. 6, UE), a first message from a first network element (Fig. 6, EDN CS), wherein the first message comprises an identifier ([0091] EES token) of a second network element (e.g., Fig. 6, EES-1) and first indication information (e.g., [0091] KECS key), and the first indication information indicates a candidate authentication mechanism associated with the second network element ([0091] If the UE 101 is authorized to access the EES-1 (111), then the ECS 110 generates EES token and provides the EES token to the UE 101 in a secure way (the token is encrypted using the KECS key or other derived keys or using the established SSL/TLS session).); and establishing, by the terminal device, a communication connection with the second network element based on the candidate authentication mechanism ([0035] for authorizing the UE 101 to access to the EES 111, Step 3A); wherein the first network element is an edge configuration server (ECS) (Fig. 6, EDN CS), and the second network element is an edge enabler server (EES) (e.g., Fig. 6, EES-1).
Rajadurai teaches that an AMF (109) can comprise an ECS (112) and an EES (111). It is not entirely clear that Rajadurai teaches: first indication information indicates a candidate authentication mechanism.
However, in the same field of endeavor, Long teaches: first indication information indicates a candidate authentication mechanism (properties: authType: $ref: ′#/components/schemas/AuthType′ 5gAuthData: oneOf: - $ref: ′#/components/schemas/Av5gAka′).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Rajadurai to include the feature of a candidate authentication mechanism and a combination of Rajadurai with Long renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing a candidate authentication mechanism).
Regarding claim 2, Rajadurai teaches: further comprising: sending, by the terminal device, a second message to the first network element, wherein the first message is a response message of the second message (Step 2C).
Regarding claim 3, Rajadurai does not explicitly teach: wherein the candidate authentication mechanism is at least one first authentication mechanism used when the terminal device establishes the communication connection with the second network element, and the second message comprises a network type used by the terminal device to access the second network element, and the at least one first authentication mechanism is an authentication mechanism that corresponds to the network type.
However, in the same field of endeavor, Long teaches: wherein the candidate authentication mechanism is at least one first authentication mechanism (5gAka) used when the terminal device establishes the communication connection with the second network element, and the second message comprises a network type used by the terminal device to access the second network element (Table 2: UEAuthenticationCtx: type: object properties: authType: $ref: ′#/components/schemas/AuthType′ 5gAuthData: oneOf: - $ref: ′#/components/schemas/Av5gAka′), and the at least one first authentication mechanism is an authentication mechanism that corresponds to the network type (Table 2: /ue-authentications/{authCtxId}/5g-aka).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Rajadurai to include the feature of a candidate authentication mechanism and a combination of Rajadurai with Long renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing a candidate authentication mechanism).
Regarding claim 4, Rajadurai does not explicitly teach: wherein the second message comprises at least one second authentication mechanism supported by the terminal device, and the at least one first authentication mechanism is comprised in the at least one second authentication mechanism.
However, in the same field of endeavor, Long teaches: wherein the second message comprises at least one second authentication mechanism supported by the terminal device (SUPI, SUCI, GUTI), and the at least one first authentication mechanism is comprised in the at least one second authentication mechanism (FIG. 2)1.
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Rajadurai to include the feature of a candidate authentication mechanism and a combination of Rajadurai with Long renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing a candidate authentication mechanism).
Regarding claim 6, Rajadurai teaches: generating, by the terminal device, a first key and a first key identifier ([0079] K EES =KDF{K AKMA , EES IP Address, AKMA Key ID, other possible parameters}) that correspond to a target authentication mechanism, wherein the target authentication mechanism is one of the at least one first authentication mechanism; and sending, by the terminal device, a communication connection establishment request to the second network element, wherein the communication connection establishment request comprises the first key identifier (Fig. 6, 3B; [0035] The temporary keys can be referred to as EES tokens. [0079] K EES =KDF{K AKMA , EES IP Address, AKMA Key ID, other possible parameters}).
Regarding claim 7, Rajadurai does not explicitly teach: wherein the candidate authentication mechanism is at least one third authentication mechanism supported by the second network element.
However, in the same field of endeavor, Long teaches: wherein the candidate authentication mechanism is at least one third authentication mechanism (SUPI) supported by the second network element.
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Rajadurai to include the feature of a candidate authentication mechanism and a combination of Rajadurai with Long renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing a third authentication mechanism).
Regarding claim 13, Rajadurai teaches: wherein the candidate authentication mechanism comprises at least one of the following: an authentication and key management for applications (AKMA) service ([0005]), a generic bootstrapping architecture (GBA) service ([0107]), and a certificate mechanism (e.g., [0049]).
Regarding claim 14, Rajadurai teaches: An apparatus (Fig. 6, UE), comprising a processor coupled to a memory storing instructions and configured to execute the instructions to cause the apparatus to: receive (e.g., Fig. 6, Step 2k), by a terminal device (Fig. 6, UE), a first message from a first network element (Fig. 6, EDN CS), wherein the first message comprises an identifier ([0091] EES token) of a second network element (e.g., Fig. 6, EES-1) and first indication information (e.g., [0091] KECS key), and the first indication information indicates a candidate authentication mechanism associated with the second network element ([0091] If the UE 101 is authorized to access the EES-1 (111), then the ECS 110 generates EES token and provides the EES token to the UE 101 in a secure way (the token is encrypted using the KECS key or other derived keys or using the established SSL/TLS session).); and establish, by the terminal device, a communication connection with the second network element based on the candidate authentication mechanism ([0035] for authorizing the UE 101 to access to the EES 111, Step 3A); wherein the first network element is an edge configuration server (ECS) (Fig. 6, EDN CS), and the second network element is an edge enabler server (EES) (e.g., Fig. 6, EES-1).
Rajadurai teaches that an AMF (109) can comprise an ECS (112) and an EES (111). It is not entirely clear that Rajadurai teaches: first indication information indicates a candidate authentication mechanism.
However, in the same field of endeavor, Long teaches: first indication information indicates a candidate authentication mechanism (properties: authType: $ref: ′#/components/schemas/AuthType′ 5gAuthData: oneOf: - $ref: ′#/components/schemas/Av5gAka′).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Rajadurai to include the feature of a candidate authentication mechanism and a combination of Rajadurai with Long renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing a candidate authentication mechanism).
Regarding claim 15, Rajadurai teaches: wherein the instructions further cause the apparatus to send a second message to the first network element, wherein the first message is a response message of the second message (Step 2C). Rajadurai does not explicitly teach: the candidate authentication mechanism is at least one first authentication mechanism used when the apparatus establishes the communication connection with the second network element, and the second message comprises a network type used by the apparatus to access the second network element, and the at least one first authentication mechanism is an authentication mechanism that corresponds to the network type.
However, in the same field of endeavor, Long teaches: the candidate authentication mechanism is at least one first authentication mechanism (5gAka) used when the apparatus establishes the communication connection with the second network element, and the second message comprises a network type used by the apparatus to access the second network element (Table 2: UEAuthenticationCtx: type: object properties: authType: $ref: ′#/components/schemas/AuthType′ 5gAuthData: oneOf: - $ref: ′#/components/schemas/Av5gAka′), and the at least one first authentication mechanism is an authentication mechanism that corresponds to the network type (Table 2: /ue-authentications/{authCtxId}/5g-aka).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Rajadurai to include the feature of a candidate authentication mechanism and a combination of Rajadurai with Long renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing a candidate authentication mechanism).
Regarding claim 16, Rajadurai teaches: wherein the second message comprises at least one second authentication mechanism supported by the apparatus, and the at least one first authentication mechanism is comprised in the at least one second authentication mechanism.
However, in the same field of endeavor, Long teaches: wherein the second message comprises at least one second authentication mechanism supported by the apparatus (SUPI, SUCI, GUTI), and the at least one first authentication mechanism is comprised in the at least one second authentication mechanism (FIG. 2)2.
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Rajadurai to include the feature of a candidate authentication mechanism and a combination of Rajadurai with Long renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing a candidate authentication mechanism).
Regarding claim 17, Rajadurai teaches: wherein the instructions further cause the apparatus to establish the communication connection by: generating a first key and a first key identifier ([0079] K EES =KDF{K AKMA , EES IP Address, AKMA Key ID, other possible parameters}) that correspond to a target authentication mechanism, wherein the target authentication mechanism is one of the at least one first authentication mechanism; and sending a communication connection establishment request to the second network element, wherein the communication connection establishment request comprises the first key identifier (Fig. 6, 3B; [0035] The temporary keys can be referred to as EES tokens. [0079] K EES =KDF{K AKMA , EES IP Address, AKMA Key ID, other possible parameters}).
Regarding claim 20, Rajadurai teaches: Rajadurai teaches: wherein the candidate authentication mechanism comprises at least one of the following: an authentication and key management for applications (AKMA) service ([0005]), a generic bootstrapping architecture (GBA) service ([0107]), and a certificate mechanism (e.g., [0049]).
Regarding claim 21, Rajadurai teaches: Rajadurai teaches: wherein the terminal device comprises at least an application client (AC) (102) and an edge enabler client (EEC) (103).
Regarding claim 22, Rajadurai teaches: wherein the terminal device comprises at least an application client (AC) (102) and an edge enabler client (EEC) (103).
Regarding claim 23, Rajadurai teaches: wherein the first message is a response message for the terminal device to request registration or a response message for the terminal device to request to establish a protocol data unit (PDU) session ([0124]).
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Long in view of Rajadurai and further in view of 3GPP TS 29.509 version 15.5.1 Release 15 (hereinafter TS 29.509).
Regarding claim 5, the combination of Long and Rajadurai does not explicitly teach: wherein the second message further comprises priority information of the at least one second authentication mechanism, and the at least one second authentication mechanism is used for selecting the at least one first authentication mechanism.
However, in the same field of endeavor, TS 29.509 teaches: wherein the second message further comprises priority information of the at least one second authentication mechanism, and the at least one second authentication mechanism is used for selecting the at least one first authentication mechanism (Table 6.2.6.2.2-1: Definition of type SorInfo When present, this information contains the information needed to update the "Operator Controlled PLMN Selector with Access Technology" list stored in the USIM. It may contain an array of preferred PLMN/AccessTechnologies combinations in priority order. The first entry in the array indicates the highest priority and the last entry indicates the lowest. Or it may contain a secured packet. If no change of the "Operator Controlled PLMN Selector with Access Technology" list stored in the USIM is needed then this attribute shall be absent).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Long and Rajadurai to include the feature of priority information and a combination of the combination of Long and Rajadurai with TS 29.509 renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing priority information).
Claims 8, 11, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Rajadurai in view of Long and further in view of 3GPP TS 33.501 version 16.3.0 Release 16 (hereinafter TS 33.501).
Regarding claim 8, the combination of Rajadurai and Long does not explicitly teach: wherein the establishing, by the terminal device, the communication connection with the second network element based on the candidate authentication mechanism further comprises: determining, by the terminal device, a target authentication mechanism based on the at least one third authentication mechanism and assistance information, wherein the assistance information comprises at least one of the following: at least one second authentication mechanism supported by the terminal device and a network type used by the terminal device to access the second network element; generating, by the terminal device, a first key and a first key identifier that correspond to the target authentication mechanism; and sending, by the terminal device, a communication connection establishment request to the second network element, wherein the communication connection establishment request comprises the first key identifier.
However, in the same field of endeavor, TS 33.501 teaches: wherein the establishing, by the terminal device, the communication connection with the second network element based on the candidate authentication mechanism further comprises: determining, by the terminal device, a target authentication mechanism (Figure 6.1.3.1-1, Step 6, Auth-response) based on the at least one third authentication mechanism and assistance information (Figure 6.1.3.1-1, Step 4, Auth-req), wherein the assistance information comprises at least one of the following: at least one second authentication mechanism supported by the terminal device and a network type used by the terminal device to access the second network element (Step 4, The SEAF shall transparently forward the EAP-Request/AKA'-Challenge message to the UE in a NAS message Authentication Request message); generating, by the terminal device, a first key and a first key identifier that correspond to the target authentication mechanism (Step 5); and sending, by the terminal device, a communication connection establishment request to the second network element, wherein the communication connection establishment request comprises the first key identifier (Step 6).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Rajadurai and Long to include the feature of different authentication mechanisms and assistance information and a combination of Long with TS 33.501 renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing different authentication mechanisms and assistance information).
Regarding claim 11, the combination of Rajadurai and Long does not teach: wherein the method further comprising: generating, by the terminal device, a second key based on the first key and the identifier of the second network element; and performing, by the terminal device, security protection on the communication connection establishment request by using the second key, to generate a first message authentication code (MAC), wherein the communication connection establishment request further comprises the first MAC.
However, in the same field of endeavor, TS 33.501 teaches: wherein the method further comprising: generating, by the terminal device, a second key (A.18 SoR-MAC-IUE generation function, Figure 6.2.2-2) based on the first key and the identifier of the second network element (p. 198/251 The input key KEY shall be KAUSF); and performing, by the terminal device, security protection on the communication connection establishment request by using the second key, to generate a first message authentication code (MAC) (When deriving a SoR-MAC-IUE from KAUSF, the following parameters shall be used to form the input S to the KDF.), wherein the communication connection establishment request further comprises the first MAC (Figure 6.14.2.1-1, step 13).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Rajadurai and Long to include the feature of different authentication mechanisms and assistance information and a combination of Long with TS 33.501 renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing different authentication mechanisms and assistance information).
Regarding claim 18, Long teaches: wherein the candidate authentication mechanism is at least one third authentication mechanism (SUPI) supported by the second network element.
Long does not explicitly teach: wherein the establishing, by the terminal device, the communication connection with the second network element based on the candidate authentication mechanism further comprises: determining, by the terminal device, a target authentication mechanism based on the at least one third authentication mechanism and assistance information, wherein the assistance information comprises at least one of the following: at least one second authentication mechanism supported by the terminal device and a network type used by the terminal device to access the second network element; generating, by the terminal device, a first key and a first key identifier that correspond to the target authentication mechanism; and sending, by the terminal device, a communication connection establishment request to the second network element, wherein the communication connection establishment request comprises the first key identifier.
However, in the same field of endeavor, TS 33.501 teaches: wherein the candidate authentication mechanism is at least one third authentication mechanism supported by the second network element, and the instructions further cause the apparatus to establish the communication connection by: determining a target authentication mechanism (Figure 6.1.3.1-1, Step 6, Auth-response) based on the at least one third authentication mechanism and assistance information (Figure 6.1.3.1-1, Step 4, Auth-req), wherein the assistance information comprises at least one of the following: at least one second authentication mechanism supported by the terminal device and a network type used by the apparatus to access the second network element (Step 4, The SEAF shall transparently forward the EAP-Request/AKA'-Challenge message to the UE in a NAS message Authentication Request message); generating a first key and a first key identifier that correspond to the target authentication mechanism (Step 5); and sending, by the terminal device, a communication connection establishment request to the second network element, wherein the communication connection establishment request comprises the first key identifier (Step 6).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Rajadurai and Long to include the feature of different authentication mechanisms and assistance information and a combination of Rajadurai and Long with TS 33.501 renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing different authentication mechanisms and assistance information).
Claims 9-10 are rejected under 35 U.S.C. 103 as being unpatentable over Rajadurai in view of Long and further in view of TS 33.501 and TS 29.509.
Regarding claim 9, the combination of Long and TS 33.501 does not explicitly teach: wherein the assistance information further comprises at least one of the following: priority information of the at least one second authentication mechanism and priority information of the at least one third authentication mechanism.
However, in the same field of endeavor, TS 29.509 teaches: wherein the assistance information further comprises at least one of the following: priority information of the at least one second authentication mechanism and priority information of the at least one third authentication mechanism (Table 6.2.6.2.2-1: Definition of type SorInfo When present, this information contains the information needed to update the "Operator Controlled PLMN Selector with Access Technology" list stored in the USIM. It may contain an array of preferred PLMN/AccessTechnologies combinations in priority order. The first entry in the array indicates the highest priority and the last entry indicates the lowest. Or it may contain a secured packet. If no change of the "Operator Controlled PLMN Selector with Access Technology" list stored in the USIM is needed then this attribute shall be absent).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Rajadurai and Long to include the feature of priority information and a combination of Rajadurai and Long and TS 33.501 with TS 29.509 renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing priority information).
Regarding claim 10, the combination of Long, Rajadurai, and TS 33.501 does not explicitly teach: wherein the first message further comprises the priority information of the at least one third authentication mechanism.
However, in the same field of endeavor, TS 29.509 teaches: wherein the first message further comprises the priority information of the at least one third authentication mechanism (Table 6.2.6.2.2-1: Definition of type SorInfo When present, this information contains the information needed to update the "Operator Controlled PLMN Selector with Access Technology" list stored in the USIM. It may contain an array of preferred PLMN/AccessTechnologies combinations in priority order. The first entry in the array indicates the highest priority and the last entry indicates the lowest. Or it may contain a secured packet. If no change of the "Operator Controlled PLMN Selector with Access Technology" list stored in the USIM is needed then this attribute shall be absent).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Long, Rajadurai, and TS 33.501 to include the feature of priority information and a combination of Long, Rajadurai, and TS 33.501 with TS 29.509 renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., providing priority information).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JUSTIN BARRY whose telephone number is (571)272-0201. The examiner can normally be reached 8:00am EST to 5:00pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jinsong HU can be reached at (571) 272-3965. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAB/ Examiner, Art Unit 2643
/JINSONG HU/ Supervisory Patent Examiner, Art Unit 2643
1 The specification of this application (18/191,942) describes the first and second authentication mechanisms in [0177]
2 The specification of this application (18/191,942) describes the first and second authentication mechanisms in [0177]