DETAILED ACTION
1. This office action is in response to an amendment filed on 01/02/2026. Claims 1-50 were canceled and claims 51-64 are pending. Claims 51, 57-58 are independent. Each independent claim is amended.
Notice of Pre-AIA or AIA Status
2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
4. Applicant’s arguments filed on January 2, 2026, with regarding to the 35 U.S.C. 103 rejection directed to the independent claims 51, 57-28 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
5. Applicant’s representative in particular argued that the following amended (underlined and bolded) claim limitations recited in independent claims 51, 57-58 isn’t disclosed by the references/prior arts of the record namely by the combination of 3G9910 and 3GPP12, “
Regarding independent claims 51, 57 and 58, it has been argued that the following underlined amended claim limitation is not disclosed by the combination of 3G9910 and 3GPP12, “
Examiner would like to point out that, the newly founded prior US Publication No. 2019/0098502 A1 to Torvinen et al discloses each and every amended and underlined claim limitation. Torvinen discloses:
performing a primary authentication procedure with an authentication server function (AUSF) of an onboarding network (ON) to obtain a key KAUSF for secure communication between the UE the ON [Para. 0111, KAUSF and Para. 0114, “primary authentication between UE and the network” Para. 0111 teaches that the provisioning key is a user-equipment-specific-shared secret in the home network and may be derived from the home network master key identified as “KAUSF “ created when the user equipment authenticates with the network. Para. 0114 teaches that the provisioning-key function can be co-located with the authentication server function when the provisioning key is derived from the key created by primary authentication. Note 3GPP10 teaches that the onboarding network (ON) is different from the non-public network]
; receiving, from a unified data management (UDM) function of the ON, UE credentials wherein the UE credentials are encrypted by the AUSF based on KAUSF [Para. 0135, “UE 1 via the UDM 7 which forwards the privacy key(s} and para. 0121, “he AUSF 5/PKPF 10 protects the privacy key(s) (received from SIDF 6 in step 4) with the provisioning key by calculating a MAC (e.g., as described above with respect to FIG. 12) and constructing MAC-P (step 6). In some embodiments, the privacy key may also be encrypted.” Para. 0135 teaches that the authentication server function sends provisioned security material to the user equipment through the unified data management function. Para. 0121 teaches that the authentication server function/provisioning-key function protects the provisional privacy key and that the privacy key may also be encrypted. Read with paragraph 0111, the encryption/protection key is derived from KAUSF. The 3GPP10 on figure 6, 6.x.2-1, steps 3 and 4] teaches that the provisional security material is the credential for non-public network access ] and
Torvinen also discloses:
decrypting the encrypted UE credentials based on KAUSF [Para. 0124, “UE creates the same provisioning key as the AUSF “ and para. 0121, “encrypted” Para. 0121, teaches that the credential-like privacy key may be encrypted by the authentication server function/provisioning-key function. Para. 0124, teaches that the user equipment creates the same provisioning key as the authentication server function/provisioning-key function. Because the same shared provisioning key is derived from KAUSF under para. 0111, the user equipment necessarily has the corresponding KAUSF based keying material to recover and store the encrypted provisioned key material. This verification steps also broadly meets the decryption step.]
Regarding independent claims 57, it has been argued that the following underlined amended claim limitation is not disclosed by the combination of 3G9910 and 3GPP12, “
receiving, from a unified data management (UDM) function of the ON, unencrypted UE credentials for the UE [Para. 0118, “privacy key” para. 0117, UDM 7, para. 0118 teaches that the authentication server function receives provision able privacy key before the authentication server function/provisioning key function protects them. Para. 0117, teaches that the unified data management colocation path. In other words this teaches an authentication server function receiving unprotected credential-like key material and then protecting/encrypting it for delivery to the user equipment] encrypting the UE credentials based on KAUSF; and sending the encrypted UE credentials to the UDM function of the ON.[Para. 0121, “encrypted” and para. 0135, “via the UDM 7”, Para. 0121 teaches that the authentication server function/provisioning key function protects the provisioned key material and that it may be encrypted. Para. 0135 teaches sending that provisioned key material through the unified data management function and para. 0111 ties the provisioning key to KAUSF. Thus, this teaches server-side sequences r: receive unprotected credential like material, protect/encrypt it using KAUSF. d derived key material, and send it through the unified data management function.
6. Thus, in response to the 35 U.S.C. 103 rejection set forth in the previous office action, applicant amended at least each independent claims 51, 57-58, presumably to overcome the 35 U.S.C. 103 rejection set forth in the previous office action. Since, the newly amended claims changed the scope and necessitated new grounds of rejection, applicant’s arguments are moot. The analysis of the claims under consideration, as amended, follows in the corresponding section below.
Applicant’s representative is encouraged to call to the office and schedule a telephone interview to discuss how the claims could be amended to overcome the ground of rejection and expedite the prosecution of the application.
Claim Rejections - 35 USC § 103
7. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
8. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or non-obviousness.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
9. Claims 51-64 are rejected under 35 U.S.C. 103 as being unpatentable over NPL Document, titled 3rd Generation Partnership Project: 3GPP TR 23.700-07 V1.1.0 (October 2020) (herein after referred as 3GPP10) in view of 3rd Generation Partnership Project: 3GPP TS 33.501 V17.0.0 (December 2020) (3GPP12) (Both prior arts are submitted with the IDS) and further in view of Vesa Torvinen (Torvinen) US Publication No. 20190098502 A1, (March 28, 2019)
The following is referring to independent claims 51, 57 and 58 and dependent claim 64
As per independent claim 51, 3GPP10 discloses a method for a user equipment (UE) to obtain security credentials for accessing a non-public network (NPN) [See 6.X.2.1: ..The NPN credential is for authentication with the SNPN…”], the method comprising:
performing a primary authentication procedure See 6.X.1:…”UE onboarding …UE is registered in the PLMN….];
receiving, from a unified data management (UDM) function, encrypted UE credentials for accessing the NPN [See figure 6.X.2-1, Steps 3 and 4]; and
decrypting the encrypted UE credentials [See figure 6.X.2-1, Step 5];
3GPP10 substantially discloses all the limitation recited the claim. Furthermore 3GPP10 further disclose a primary authentication procedure and obtaining a Nudm SDM_Notification Notify” including the encrypted UE credentials to be decrypted, but doesn’t explicitly disclose the following underlined claim limitation “performing a primary authentication procedure to obtain a key KAUSF and decrypting the encrypted UE credentials based on KAUSF”. In other word, 3GPP10 doesn’t disclose limitation that …the credentials are decrypted based on a key/KAUSF obtained during the primary authentication procedure.
However, 3GPP12 discloses the underlined claim limitation, ““performing a primary authentication procedure to obtain a key KAUSF and decrypting the encrypted UE credentials based on KAUSF” OR…the credentials are decrypted based on a key/KAUSF obtained during the primary authentication procedure [See, A. 19, page 199, section 6.15.2.1, UDM transmits encrypted UE parameters to a UE using a Nudm_SDM_Notification service equation, wherein the parameter are protected using the KAUSF obtained during a primary authentication procedure.
3GPP10 and 3GPP12 are an analogous/in the same field of endeavor as they both are directed to non-public networks.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to implement in the system of 3GPP12 a mechanism or a feature such as “performing a primary authentication procedure to obtain a key KAUSF and decrypting the encrypted UE credentials based on KAUSF” as per teaching 3GPP12 for obtaining the credential and access a non-public network (NPN) securely. [See 3GPP12 at least page 9]
The combination of 3GPP10 and 3GPP12 doesn’t explicitly disclose the following amended underlined claim limitation:
performing a primary authentication procedure with an authentication server function (AUSF) of an onboarding network (ON) to obtain a key KAUSF for secure communication between the ON
; receiving, from a unified data management (UDM) function of the ON, UE credentials wherein the UE credentials are encrypted by the AUSF based on KAUSF
However, Torvinen discloses the above underlined claim limitation:
performing a primary authentication procedure with an authentication server function (AUSF) of an onboarding network (ON) to obtain a key KAUSF for secure communication between the ON [Para. 0111, KAUSF and Para. 0114, “primary authentication between UE and the network” Para. 0111 teaches that the provisioning key is a user-equipment-specific-shared secret in the home network and may be derived from the home network master key identified as “KAUSF “ created when the user equipment authenticates with the network. Para. 0114 teaches that the provisioning-key function can be co-located with the authentication server function when the provisioning key is derived from the key created by primary authentication. Note 3GPP10 teaches that the onboarding network (ON) is different from the non-public network]
; receiving, from a unified data management (UDM) function of the ON, UE credentials wherein the UE credentials are encrypted by the AUSF based on KAUSF [Para. 0135, “UE 1 via the UDM 7 which forwards the privacy key(s} and para. 0121, “he AUSF 5/PKPF 10 protects the privacy key(s) (received from SIDF 6 in step 4) with the provisioning key by calculating a MAC (e.g., as described above with respect to FIG. 12) and constructing MAC-P (step 6). In some embodiments, the privacy key may also be encrypted.” Para. 0135 teaches that the authentication server function sends provisioned security material to the user equipment through the unified data management function. Para. 0121 teaches that the authentication server function/provisioning-key function protects the provisional privacy key and that the privacy key may also be encrypted. Read with paragraph 0111, the encryption/protection key is derived from KAUSF. The 3GPP10 on figure 6, 6.x.2-1, steps 3 and 4] teaches that the provisional security material is the credential for non-public network access ] and
Torvinen also teaches:
decrypting the encrypted UE credentials based on KAUSF [Para. 0124, “UE creates the same provisioning key as the AUSF “ and para. 0121, “encrypted” Para. 0121, teaches that the credential-like privacy key may be encrypted by the authentication server function/provisioning-key function. Para. 0124, teaches that the user equipment creates the same provisioning key as the authentication server function/provisioning-key function. Because the same shared provisioning key is derived from KAUSF under para. 0111, the user equipment necessarily has the corresponding KAUSF based keying material to recover and store the encrypted provisioned key material. This verification steps also broadly meets the decryption step.]
3GPP10, 3GPP12 and Torvinen are an analogous/in the same field of endeavor as they all are directed to authentication.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to implement in the system of 3GPP10 AND 3GPP12 a mechanism or a feature such as “performing a primary authentication procedure with an authentication server function (AUSF) of an onboarding network (ON) to obtain a key KAUSF for secure communication between the ON; receiving, from a unified data management (UDM) function of the ON, UE credentials” as per teaching of Torvinen because this enhance the security of the system by addressing secure fifth generation provisioning of user-equipment security material using authentication-server-function and unified-data-management signaling, and also enhances the security of the system by protecting non-public network credentials with an already established KAUSF based key.
As per independent claim 57, 3GPP10 discloses a method for an authentication server function (AUSF) ) [See at least “AF” figure 6.X.2-1] to facilitate user equipment (UE) access to a non-public network (NPN) different than ON [figure 6.X.2-1]
the method comprising:
performing a primary authentication procedure [See 6.X.1:…”UE onboarding …UE is registered in the PLMN….];
receiving, from a unified data management (UDM) function, unencrypted UE credentials for the UE to access the NPN [See figure 6.X.2-1, Step 2] and
encrypting the UE credentials [See figure 6.X.2-1, Step 2]; and sending the encrypted UE credentials to the UDM function [See figure 6.X.2-1, Step 2-4].
3GPP10 substantially discloses all the limitation recited the claim. Furthermore 3GPP10 further disclose a a primary authentication procedure and obtaining a Nudm_SDM_Notification Notify” including the encrypted UE credentials to be decrypted, but doesn’t explicitly disclose the following underlined claim limitation “performing a primary authentication procedure to obtain a key KAUSF and encrypting or decrypting the encrypted UE credentials based on KAUSF”. In other word, 3GPP10 doesn’t disclose limitation that …the credentials are encrypted or decrypted based on a key/KAUSF obtained during the primary authentication procedure.
However, 3GPP12 discloses the underlined claim limitation, “performing a primary authentication procedure to obtain a key KAUSF and decrypting or encrypted the encrypted UE credentials based on KAUSF” OR…the credentials are decrypted or encrypted based on a key/KAUSF obtained during the primary authentication procedure [See, A. 19, page 199, section 6.15.2.1, UDM transmits encrypted UE parameters to a UE using a Nudm_SDM_Notification service equation, wherein the parameter are protected using the KAUSF obtained during a primary authentication procedure.
3GPP10 and 3GPP12 are an analogous/in the same field of endeavor as they both are directed to non-public networks.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to implement in the system of 3GPP12 a mechanism or a feature such as “performing a primary authentication procedure to obtain a key KAUSF and decrypting the encrypted UE credentials based on KAUSF OR ” encrypting the unencrypted UE credentials based on KAUSF as per teaching 3GPP12 for significantly reducing the risk of credential breaches. [See 3GPP12 at least page 9]
The combination of 3GPP10 and 3GPP12 doesn’t explicitly disclose the following amended/underlined claim limitation:
an authentication server function (AUSF) of an onboarding network (ON)
; receiving, from a unified data management (UDM) function of the ON, unencrypted UE credentials for the UE
However, Torvinen discloses:
performing a primary authentication procedure with an authentication server function (AUSF) of an onboarding network (ON) to obtain a key KAUSF for secure communication between the ON [Para. 0111, KAUSF and Para. 0114, “primary authentication between UE and the network” Para. 0111 teaches that the provisioning key is a user-equipment-specific-shared secret in the home network and may be derived from the home network master key identified as “KAUSF “ created when the user equipment authenticates with the network. Para. 0114 teaches that the provisioning-key function can be co-located with the authentication server function when the provisioning key is derived from the key created by primary authentication. Note 3GPP10 teaches that the onboarding network (ON) is different from the non-public network]
receiving, from a unified data management (UDM) function of the ON, unencrypted UE credentials for the UE [Para. 0118, “privacy key” para. 0117, UDM 7, para. 0118 teaches that the authentication server function receives provision able privacy key before the authentication server function/provisioning key function protects them. Para. 0117, teaches that the unified data management colocation path. In other words this teaches an authentication server function receiving unprotected credential-like key material and then protecting/encrypting it for delivery to the user equipment]
Furthermore, Torvinen further discloses:
encrypting the UE credentials based on KAUSF; and sending the encrypted UE credentials to the UDM function of the ON.[Para. 0121, “encrypted” and para. 0135, “via the UDM 7”, Para. 0121 teaches that the authentication server function/provisioning key function protects the provisioned key material and that it may be encrypted. Para. 0135 teaches sending that provisioned key material through the unified data management function and para. 0111 ties the provisioning key to KAUSF. Thus, this teaches server-side sequences r: receive unprotected credential like material, protect/encrypt it using KAUSF. d derived key material, and send it through the unified data management function.
3GPP10, 3GPP12 and Torvinen are an analogous/in the same field of endeavor as they all are directed to authentication.
It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to implement in the system of 3GPP10 AND 3GPP12 a mechanism or a feature such as “an authentication server function (AUSF) of an onboarding network (ON)
; receiving, from a unified data management (UDM) function of the ON, unencrypted UE credentials for the UE” as per teaching of Torvinen because this enhance the security of the system by addressing secure fifth generation provisioning of user-equipment security material using authentication-server-function and unified-data-management signaling, and also enhances the security of the system by protecting non-public network credentials with an already established KAUSF based key.
As per independent claim 58, independent claim 58 is rejected for the same reason as that of the above independent claim 51.
As per dependent claim 52, the combination of 3GPP10, 3GPP12 and Torvinen discloses the method or system as applied to claim 51 above. Furthermore, 3GPP12 discloses the method/system, wherein, one of the following cryptographic algorithms or functions is used to decrypt the encrypted UE credentials: a hash message authentication code (HMAC) function; or a cryptographic algorithm used for protection of UE Parameter Update (UPU) procedure payloads. [See at least Annex A19 and A20 define the exact KDF functions (HMAC-SHA-256 and 6.15.2.2 specifies that UPU-MAC-IAUSF/UPU-MAC-IUE are calculated using KAUSF as input key and HMAC-based function]
As per dependent claim 59, dependent claim 59 is rejected for the same reason as that of the above dependent claim 52.
As per dependent claim 53, the combination of 3GPP10, 3GPP12 and Torvinen discloses the method or system as applied to claim 51 above. Furthermore, 3GPP12 discloses the method/system, wherein, one of the following keys is used to decrypt the UE credentials: KAUSF; or a key derived from KAUSF based on a Generic Bootstrapping Architecture (GBA), Key Derivation Function (KDF), and a specific FC value allocated for UPU key derivation.[ See at least 6.15.2.2, The AUSF and the UE shall associate a 16-bit CounterUPU with the key KAUSF…used as input into UPU-MAC derivation. Annex A.19/A. 20 specifies key derivation functions where KAUSF is input plus a Function Code (FC) value to produce the integrity keys]
As per dependent claim 60, dependent claim 60 is rejected for the same reason as that of the above dependent claim 53.
As per dependent claim 54, the combination of 3GPP10, 3GPP12 and Torvinen discloses the method or system as applied to claim 51 above. Furthermore, 3GPP12 discloses the method/system, wherein, the encrypted UE credentials are received in control plane (CP) non-access stratum (NAS) signaling from an access and mobility management function (AMF) associated with the NPN [See at least 6.15.1, Parameters Update is a control plane procedure supported by UDM. 6.15.2.1, the protected UPU data shall be carried in a NAS container and delivered via the AMF]
As per dependent claim 61, dependent claim 61 is rejected for the same reason as that of the above dependent claim 54.
As per dependent claim 55, the combination of 3GPP10, 3GPP12 and Torvinen discloses the method or system as applied to claim 51 above. Furthermore, 3GPP12 discloses the method/System, wherein, the primary authentication procedure is based on default UE credentials [See 6.1 and 6.1.1, the primary authentication in 5G is the 3GPP AKA procedure using default subscription credentials (SUPI/SUCI) stored in the USIM, these are default UE credentials used for initial primary authentication with AUSF/UDM]
As per dependent claim 62, dependent claim 62 is rejected for the same reason as that of the above dependent claim 55.
As per dependent claim 56, the combination of 3GPP10, 3GPP12 and Torvinen discloses the method or system as applied to claim 51 above. Furthermore, 3GPP12 discloses the method/System further comprising obtaining access to the NPN based on the decrypted UE credentials [6.15.1, after successful integrity verification of UPU Data (protected with KAUSF), the UE updates its parameters. Those parameters include credentials (eg. NPN configuration, SoR data). Once updated, UE uses them to access and operate in the target network (PLMN or NPN context, depending on configuration].
As per dependent claim 63, dependent claim 63 is rejected for the same reason as that of the above dependent claim 56.
As per dependent claim 64, dependent claim 64 is rejected for the same reason as that of the above independent claim 51.
Conclusion
10. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
A. US Publication No. 20220182821 A1 Bjerrum et al discloses MD10 may be configured to connect a non-public network (NPN) 30, 50. The NPN may comprise an (NPN) access network 30 with access network node(s), such as an access point (AP) of an IEEE802.11 based network or other non-3GPP access network, without however limiting to these examples. The NPN may comprise an NPN core network 50, which may comprise a set of appropriate core network functions 52, 54, 56. The NPN CN functions may be connected via the (NPN) access network 30 and/or the (PLMN) access network 20. The NPN may be a standalone NPN (SNPN), i.e. operated by an NPN operator and not relying on network functions provided by a PLMN, or a public network integrated NPN, i.e. a non-public network deployed with the support of a PLMN. Public network integrated NPNs can be enabled using network slicing.
B. US Publication No. 20230057968-A1 to Sharma discloses a user equipment for a mobile telecommunications system, including circuitry configured to: communicate with a non-public network authentication-authorization-accounting server and initiate a registration procedure with the mobile telecommunications system; and provide an authentication interface between the non-public network authentication-authorization-accounting server and an authentication server function entity in the mobile tele-communications system.
C. US Publication No. -20190373461 A1 to Ito discloses a communication system capable of achieving advanced security in a 5G communication system. The communication system according to the present disclosure includes: a communication terminal (10); an Access and Mobility Management (AMF) entity (20) configured to execute Mobility Management (MM) processing regarding the communication terminal (10); and a Session Management Function (SMF) entity (30) configured to execute Session Management (SM) processing regarding the communication terminal (10), in which the communication terminal (10) sends an MM message used in the MM processing, a first security key having been applied to the MM message, between the communication terminal and the AMF entity (20), and sends an SM message used in the SM processing, a second security key having been applied to the SM message, between the communication terminal and the SMF entity (30) via the AMF entity (20).
D. See the other cited prior arts.
11. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMSON B LEMMA whose telephone number is 571-272-3806. The examiner can normally be reached on M-F 8am-10pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor Yin-Chen Shaw can be reached on 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/SAMSON B LEMMA/Primary Examiner, Art Unit 2498