DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The Amendment filed April 14, 2026, has been entered. Claims 1-20 are pending in the application. Applicant has submitted amendments to the claims along with other remarks. Applicant’s amendments regarding 112(a) have overcome the rejection. Applicant’s amendments regarding 101 have overcome the rejection. Claims 1-20 are still rejected by prior art references, refer to the following rejection for details.
Response to Arguments
Applicant’s arguments and amendments, see pp. 8-12 of the response, filed April 14, 2026, with respect to the rejection(s) of claim(s) 1-20 under § 102 have been fully considered but are not persuasive, please see the rejection for details.
Regarding claim 1, Applicant states that Draznin does not teach the “limited access portal as recited in independent claim 1 because the private network portal 230 is accessed via the web, meaning that the user device 280 is not limited to the private network portal 230 but can access other services via the web.” Remarks at 11. Although Applicant focuses on the figures of Draznin, the written specification of Draznin provides for limiting the user device to only those frequency bands associated with the private network. ([0024] According to an exemplary embodiment, customer device 180 may be provisioned (e.g., via a subscriber identity module (SIM) card or another secure element) to recognize particular network identifiers (e.g., associated with one or more of private networks 115 or another RAN) and to support particular radio frequency (RF) spectra. [0010] The focus in the industry has gravitated toward applying broadband cellular network standards, such as Long Term Evolution (LTE) and 5G standards, to private wireless networks using unlicensed or shared radio frequency (RF) spectrum. [0023] Customer device 180 may support one or multiple radio access technologies (RATs, such as, 4G, 5G, etc.) and various portions of the radio spectrum (e.g., multiple frequency bands, multiple carrier frequencies, licensed, unlicensed, etc.). Draznin also equates the enterprise network 115 in Fig. 1 with a private network in [0015]. Further, in [0015-16] Draznin states that the enterprise network may be a standalone network and “one or more servers for customer devices 180.” Therefore, Draznin teaches the elements of the amended claims.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1 and 11 recite the limitation “attaching the one or more devices to the core enterprise network . . . to a limited access portal” and “subsequent to attaching the one or more devices . . . providing to the one or more devices a limited access portal.” This claim appears to recite a double inclusion. “where a claim directed to a device can be read to include the same element twice, the claim may be indefinite.” Ex parte Kristensen, 10 USPQ2d 1701 (Bd. Pat. App. & Inter. 1989). These elements are recited in different steps, but the claim appears to reference the same element twice. It is unclear if these elements are intended to be combined into one step or multiple steps.
Correction or clarification is required.
Claim Rejections - 35 USC § 102
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claims 1-5 and 11-15 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by U.S. Publication No. 2020/0366677 (hereinafter “Draznin”).
Regarding claim 1, Draznin teaches: A method comprising: receiving at a core enterprise network of a private cellular network a device identifier from one or more devices that are to interact with the core enterprise network that do not include a Subscriber Identity Module (SIM) ([0019] Additionally, or alternatively, authentication proxy 122 may authenticate a particular customer device 180 based on a customer device identity, such as a Permanent Equipment Identifier (PEI).) ([0064] Process 600 may include providing a profile configuration template . . . For example, user capability management function 210 may provide a subscription profile); based on the device identifier, attaching the one or more devices to the core enterprise network ([0060] FIG. 5 illustrates communications for network attachment by a customer device after provisioning, according to implementations described herein. [0061] As shown in FIG. 5, customer device 180-1 may submit a connection request 502 to access device 120. For example, customer device 180-1 may send a radio resource control (RRC) Connection Request message to access device 120 using a shared spectrum. Authentication proxy 122 of access device 120 may access a subscription profile cache (e.g., corresponding to retrieved subscription profiles 424) and determine that customer device 180-1 is registered with private network 115. Authentication proxy 122 may perform a local authentication 506 for customer device 180-1 (e.g., without relying on communications with core network 204) using the subscription profile information.) with limited access, in which the one or more devices are limited to a limited access portal and prevented from accessing to other network services of the core enterprise network prior to authentication ([0033] Exposure function 220 may expose capabilities and features of provider network 125 (or particularly core network 204) to customer devices 180 based on instructions); subsequent to attaching the one or more devices to the core enterprise network, providing to the one or more devices a limited access portal that is configured to receive one or more user authentication credentials from the one or more devices ([0065] Process 600 may include providing a profile configuration template (block 610) and receiving provisioning parameters for end devices in a private network (block 620). For example, user capability management function 210 may provide a subscription profile form to a registered user via private network portal 230. Using the subscription profile form, the user may provide structured input for subscription profile for multiple customer devices 180. User capability management function 210 may receive the user input via private network portal 230.) using the same transmit and receive infrastructure of the private cellular network and without using a separate Wi-Fi or public data network (Private Network Portal 230); receiving from the one or more devices the one or more user authentication credentials ([0034] Access to data and/or services via private network portal 230 may be restricted, for example, to users with registered accounts and secure passwords (or other credentials). [0070] Process 700 may further include retrieving a corresponding subscription profile for the end device (block 730), and authenticating the end device based on the retrieved subscription profile (block 740). For example, in response to a connection request, authentication proxy 122 executing on access device 120 may retrieve a subscription profile for the corresponding customer device 180 and user information from the subscription profile to authenticate the customer device 180.); authenticating the one or more user authentication credentials ([0070] For example, in response to a connection request, authentication proxy 122 executing on access device 120 may retrieve a subscription profile for the corresponding customer device 180 and user information from the subscription profile to authenticate the customer device 180.); and providing full access to network services of the core enterprise network to the one or more devices when the one or more user authentication credentials are authenticated by the core enterprise network, wherein the interactions between the core enterprise network and the one or more devices are done using a transmit and receive infrastructure of the private cellular network ([0072] If the end device is authenticated (block 740—Yes), process 700 may include determining if the end device requires a mobility connection (block 760). For example, if authentication proxy 122 finds a subscription profile for the customer device 180 and authenticates customer device 180, authentication proxy 122 may determine (e.g., based on the subscription profile) whether customer device 180 is provisioned for private network access or public network access.).
Regarding claim 2, Draznin inherently teaches: linking the device identifier to the one or more user authentication credentials; and automatically providing full access to the network services based on the linking when the one or more devices disconnect from and then subsequently are attached again to the core enterprise network (linking a device identifier to one or more user authentication credentials (Draznin teaches these elements inherently via 24.501 v17.7.1 - 4.4.2.6, Change of security keys: “When the AMF initiates a re-authentication to create a new 5G NAS security context, the messages exchanged during the authentication procedure are integrity protected and ciphered using the current 5G NAS security context, if any. Both UE and AMF shall continue to use the current 5G NAS security context, until . . . .”).
Regarding claim 3, Draznin teaches: wherein the device identifier includes an International Mobile Equipment Identity (IMEI) (Additionally, or alternatively, authentication proxy 122 may authenticate a particular customer device 180 based on a customer device identity, such as a Permanent Equipment Identifier (PEI).).
Regarding claim 4, Draznin teaches: wherein the one or more user authentication credentials include one or more of an email address, a username, a password, or a network authentication certificate ([0034] Access to data and/or services via private network portal 230 may be restricted, for example, to users with registered accounts and secure passwords (or other credentials).).
Regarding claim 5, Draznin teaches: wherein the transmit and receive infrastructure of the private cellular network is configured for one of 4G LTE or 5G. ([0010] Private networks using cellular wireless standards are a promising connectivity model. The focus in the industry has gravitated toward applying broadband cellular network standards, such as Long Term Evolution (LTE) and 5G standards, to private wireless networks using unlicensed or shared radio frequency (RF) spectrum).
Regarding claim 11, Draznin teaches: A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising: receive at a core enterprise network of a private cellular network a device identifier from one or more devices that are to interact with the core enterprise network that do not include a Subscriber Identity Module (SIM) ([0019] Additionally, or alternatively, authentication proxy 122 may authenticate a particular customer device 180 based on a customer device identity, such as a Permanent Equipment Identifier (PEI).) ([0064] Process 600 may include providing a profile configuration template . . . For example, user capability management function 210 may provide a subscription profile); based on the device identifier, attaching the one or more devices to the core enterprise network ([0060] FIG. 5 illustrates communications for network attachment by a customer device after provisioning, according to implementations described herein. [0061] As shown in FIG. 5, customer device 180-1 may submit a connection request 502 to access device 120. For example, customer device 180-1 may send a radio resource control (RRC) Connection Request message to access device 120 using a shared spectrum. Authentication proxy 122 of access device 120 may access a subscription profile cache (e.g., corresponding to retrieved subscription profiles 424) and determine that customer device 180-1 is registered with private network 115. Authentication proxy 122 may perform a local authentication 506 for customer device 180-1 (e.g., without relying on communications with core network 204) using the subscription profile information.) with limited access, in which the one or more devices are limited to a limited access portal and prevented from accessing to other network services of the core enterprise network prior to authentication ([0033] Exposure function 220 may expose capabilities and features of provider network 125 (or particularly core network 204) to customer devices 180 based on instructions); subsequent to attaching the one or more devices to the core enterprise network, provide to the one or more devices a limited access portal that is configured to receive one or more user authentication credentials from the one or more devices ([0065] Process 600 may include providing a profile configuration template (block 610) and receiving provisioning parameters for end devices in a private network (block 620). For example, user capability management function 210 may provide a subscription profile form to a registered user via private network portal 230. Using the subscription profile form, the user may provide structured input for subscription profile for multiple customer devices 180. User capability management function 210 may receive the user input via private network portal 230.) using the same transmit and receive infrastructure of the private cellular network and without using a separate Wi-Fi or public data network (Private Network Portal 230); receive from the one or more devices the one or more user authentication credentials ([0034] Access to data and/or services via private network portal 230 may be restricted, for example, to users with registered accounts and secure passwords (or other credentials). [0070] Process 700 may further include retrieving a corresponding subscription profile for the end device (block 730), and authenticating the end device based on the retrieved subscription profile (block 740). For example, in response to a connection request, authentication proxy 122 executing on access device 120 may retrieve a subscription profile for the corresponding customer device 180 and user information from the subscription profile to authenticate the customer device 180.); authenticate the one or more user authentication credentials ([0070] For example, in response to a connection request, authentication proxy 122 executing on access device 120 may retrieve a subscription profile for the corresponding customer device 180 and user information from the subscription profile to authenticate the customer device 180.); and provide full access to network services of the core enterprise network to the one or more devices when the one or more user authentication credentials are authenticated by the core enterprise network, wherein the interactions between the core enterprise network and the one or more devices are done using a transmit and receive infrastructure of the private cellular network ([0072] If the end device is authenticated (block 740—Yes), process 700 may include determining if the end device requires a mobility connection (block 760). For example, if authentication proxy 122 finds a subscription profile for the customer device 180 and authenticates customer device 180, authentication proxy 122 may determine (e.g., based on the subscription profile) whether customer device 180 is provisioned for private network access or public network access.).
Regarding claim 12, Draznin inherently teaches: linking the device identifier to the one or more user authentication credentials; and automatically providing full access to the network services based on the linking when the one or more devices disconnect from and then subsequently are attached again to the core enterprise network (linking a device identifier to one or more user authentication credentials (Draznin teaches these elements inherently via 24.501 v17.7.1 - 4.4.2.6, Change of security keys: “When the AMF initiates a re-authentication to create a new 5G NAS security context, the messages exchanged during the authentication procedure are integrity protected and ciphered using the current 5G NAS security context, if any. Both UE and AMF shall continue to use the current 5G NAS security context, until . . . .”).
Regarding claim 13, Draznin teaches: wherein the device identifier includes an International Mobile Equipment Identity (IMEI) (Additionally, or alternatively, authentication proxy 122 may authenticate a particular customer device 180 based on a customer device identity, such as a Permanent Equipment Identifier (PEI).).
Regarding claim 14, Draznin teaches: wherein the one or more user authentication credentials include one or more of an email address, a username, a password, or a network authentication certificate ([0034] Access to data and/or services via private network portal 230 may be restricted, for example, to users with registered accounts and secure passwords (or other credentials).).
Regarding claim 15, Draznin teaches: wherein the transmit and receive infrastructure of the private cellular network is configured for one of 4G LTE or 5G. ([0010] Private networks using cellular wireless standards are a promising connectivity model. The focus in the industry has gravitated toward applying broadband cellular network standards, such as Long Term Evolution (LTE) and 5G standards, to private wireless networks using unlicensed or shared radio frequency (RF) spectrum).
Claim Rejections - 35 USC § 103
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claims 6-8 and 16-18 are rejected under 35 U.S.C. 103 as being unpatentable over Draznin in view of U.S. Publication No. 2022/0322068 (hereinafter “Chughtai”)
Regarding claim 6, Draznin teaches that a customer device may be provisioned with a SIM card or another secure element; however, Draznin does not teach: wherein the one or more devices, while not including the SIM, do include an embedded-SIM (eSIM), the method further comprising: subsequent to authenticating the one or more user authentication credentials, generating at an eSIM generator of the core enterprise network an eSIM profile; and providing the eSIM profile to the one or more devices, the eSIM profile configured to cause the eSIM to function as a SIM, wherein the eSIM profile is provided to the one or more devices using the transmit and receive infrastructure of the private cellular network and without a need for a separate network.
However, in the same field of endeavor, Chughtai teaches: wherein the one or more devices, while not including the SIM, do include an embedded-SIM (eSIM) ([0003] Each eSIM profile may comprise a unique international mobile subscriber identity (IMSI) number that authenticates a subscriber to a mobile network operator (MNO).), the method further comprising: subsequent to authenticating the one or more user authentication credentials, generating at an eSIM generator of the core enterprise network an eSIM profile ([0132] In process 811, processing unit 155 of network device 150 forwards the eUICC ID information along with the associated information to the MNO of the selected cellular network. Upon receiving the eUICC ID information and associated information, the MNO of the selected cellular network may perform verification procedures. [0133] Alternatively, in M2M eSIM profile provisioning, the BSS may request a subscription management data preparation (SM-DP) server of the MNO to prepare at least one eSIM profile based on the information.); and providing the eSIM profile to the one or more devices, the eSIM profile configured to cause the eSIM to function as a SIM, wherein the eSIM profile is provided to the one or more devices using the transmit and receive infrastructure of the private cellular network and without a need for a separate network ([0069] However, when network device 200 does not have at least one eSIM profile or a removable SIM of MNO A available, network device 200 may send a request for an eSIM profile to cellular network 201a. In this exemplary scenario, network device 200 may connect to the core network 230 of cellular network 201a over interconnected networks 217 for sending the request. Continuing with the exemplary scenario, network device 200 may connect with interconnected networks 217 over a wired or wireless network connection. The wireless network connection may be established using Wi-Fi (RTM), Bluetooth (RTM), or a different cellular network for which network device 200 has at least one eSIM profile or removable SIM available. For example, the request for an eSIM profile of MNO A may be sent through web portal 226 provided by MNO A for its potential customers or subscribers. In one variant, the request may be sent using an application provided by MNO A. The application may be made available for downloading in web portal 226 by MNO A or may be built-in by a manufacturer of an eUICC or network device 200. When an eSIM profile is received in response to the request, network device 200 may access core network 230 through base station 229 using the eSIM profile information. Thus, network device 200 becomes capable of connecting to interconnected networks 217 or a host reachable through interconnected networks 217 over cellular network 201a. The invention disclosed herein may be beneficial for reducing data communication costs using cellular networks in a visited geographical area and increasing the flexibility of establishing data connections.).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Draznin to include the feature of provisioning an eSIM and a combination of Draznin with Chughtai renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., provisioning eSIMs).
Regarding claim 7, Draznin teaches the invention substantially as claimed in claim 6, but does not specifically teach: wherein the eSIM profile includes an International Mobile Subscriber Identity (IMSI).
However, in the same field of endeavor, Chughtai teaches: wherein the eSIM profile includes an International Mobile Subscriber Identity (IMSI) ([0003] Each eSIM profile may comprise a unique international mobile subscriber identity (IMSI) number that authenticates a subscriber to a mobile network operator (MNO).).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Draznin to include the feature of an IMSI and a combination of Draznin with Chughtai renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., an eSIM comprising an IMSI).
Regarding claim 8, Draznin teaches: receiving the eSIM profile from the one or more devices when the one or more devices disconnect from and subsequently are attached again to the core enterprise network; and automatically providing full access to the network services based on the received eSIM profile (Draznin teaches these elements inherently via 24.501 v17.7.1 - 4.4.2.6, Change of security keys: “When the AMF initiates a re-authentication to create a new 5G NAS security context, the messages exchanged during the authentication procedure are integrity protected and ciphered using the current 5G NAS security context, if any. Both UE and AMF shall continue to use the current 5G NAS security context, until . . . .”).
Regarding claim 16, Draznin teaches that a customer device may be provisioned with a SIM card or another secure element; however, Draznin does not teach: wherein the one or more devices, while not including the SIM, do include an embedded-SIM (eSIM), the method further comprising: subsequent to authenticating the one or more user authentication credentials, generating at an eSIM generator of the core enterprise network an eSIM profile; and providing the eSIM profile to the one or more devices, the eSIM profile configured to cause the eSIM to function as a SIM, wherein the eSIM profile is provided to the one or more devices using the transmit and receive infrastructure of the private cellular network and without a need for a separate network.
However, in the same field of endeavor, Chughtai teaches: wherein the one or more devices, while not including the SIM, do include an embedded-SIM (eSIM) ([0003] Each eSIM profile may comprise a unique international mobile subscriber identity (IMSI) number that authenticates a subscriber to a mobile network operator (MNO).), the method further comprising: subsequent to authenticating the one or more user authentication credentials, generating at an eSIM generator of the core enterprise network an eSIM profile ([0132] In process 811, processing unit 155 of network device 150 forwards the eUICC ID information along with the associated information to the MNO of the selected cellular network. Upon receiving the eUICC ID information and associated information, the MNO of the selected cellular network may perform verification procedures. [0133] Alternatively, in M2M eSIM profile provisioning, the BSS may request a subscription management data preparation (SM-DP) server of the MNO to prepare at least one eSIM profile based on the information.); and providing the eSIM profile to the one or more devices, the eSIM profile configured to cause the eSIM to function as a SIM, wherein the eSIM profile is provided to the one or more devices using the transmit and receive infrastructure of the private cellular network and without a need for a separate network ([0069] However, when network device 200 does not have at least one eSIM profile or a removable SIM of MNO A available, network device 200 may send a request for an eSIM profile to cellular network 201a. In this exemplary scenario, network device 200 may connect to the core network 230 of cellular network 201a over interconnected networks 217 for sending the request. Continuing with the exemplary scenario, network device 200 may connect with interconnected networks 217 over a wired or wireless network connection. The wireless network connection may be established using Wi-Fi (RTM), Bluetooth (RTM), or a different cellular network for which network device 200 has at least one eSIM profile or removable SIM available. For example, the request for an eSIM profile of MNO A may be sent through web portal 226 provided by MNO A for its potential customers or subscribers. In one variant, the request may be sent using an application provided by MNO A. The application may be made available for downloading in web portal 226 by MNO A or may be built-in by a manufacturer of an eUICC or network device 200. When an eSIM profile is received in response to the request, network device 200 may access core network 230 through base station 229 using the eSIM profile information. Thus, network device 200 becomes capable of connecting to interconnected networks 217 or a host reachable through interconnected networks 217 over cellular network 201a. The invention disclosed herein may be beneficial for reducing data communication costs using cellular networks in a visited geographical area and increasing the flexibility of establishing data connections.).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Draznin to include the feature of provisioning an eSIM and a combination of Draznin with Chughtai renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., provisioning eSIMs).Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Draznin to include the feature of provisioning an eSIM and a combination of Draznin with Chughtai renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., provisioning eSIMs).
Regarding claim 17, Draznin teaches the invention substantially as claimed in claim 16, but does not specifically teach: wherein the eSIM profile includes an International Mobile Subscriber Identity (IMSI).
However, in the same field of endeavor, Chughtai teaches: wherein the eSIM profile includes an International Mobile Subscriber Identity (IMSI) ([0003] Each eSIM profile may comprise a unique international mobile subscriber identity (IMSI) number that authenticates a subscriber to a mobile network operator (MNO).).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Draznin to include the feature of an IMSI and a combination of Draznin with Chughtai renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., an eSIM comprising an IMSI).
Regarding claim 18, Draznin teaches: receiving the eSIM profile from the one or more devices when the one or more devices disconnect from and subsequently are attached again to the core enterprise network; and automatically providing full access to the network services based on the received eSIM profile (Draznin teaches these elements inherently via 24.501 v17.7.1 - 4.4.2.6, Change of security keys: “When the AMF initiates a re-authentication to create a new 5G NAS security context, the messages exchanged during the authentication procedure are integrity protected and ciphered using the current 5G NAS security context, if any. Both UE and AMF shall continue to use the current 5G NAS security context, until . . . .”).
Claims 9-10 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Draznin in view of U.S. Publication No. 2017/0280324 (hereinafter “Beals”)
Regarding claim 9, Draznin teaches the invention substantially as claimed in claim 1, but does not specifically teach: wherein the one or more devices, while not including the SIM, do include an embedded-SIM (eSIM), the method further comprising: subsequent to authenticating the one or more user authentication credentials, generating at an authentication certificate generator of the core enterprise network a network authentication certificate; and providing the network authentication certificate to the one or more devices, the network authentication certificate configured to be stored in a secure memory location of the eSIM, wherein the network authentication certificate is provided to the one or more devices using the transmit and receive infrastructure of the private cellular network and without a need for a separate network.
However, in the same field of endeavor, Beals teaches: wherein the one or more devices, while not including the SIM, do include an embedded-SIM (eSIM), the method further comprising: subsequent to authenticating the one or more user authentication credentials, generating within the core enterprise network a network authentication certificate; and providing the network authentication certificate to the one or more devices, the network authentication certificate configured to be stored in a secure memory location of the eSIM, wherein the network authentication certificate is provided to the one or more devices over the transmit and receive infrastructure of the private cellular network and without any communication through a public or external network ([0005] The server then provisions a digital cryptographic certificate to the non-SIM device. The certificate is linked to the related SIM-enabled device. When the non-SIM device is ready to connect to the paid Wi-Fi network, the non-SIM device presents the certificate to the server for authentication.).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Draznin to include the feature of a certificate for authentication and a combination of Draznin with Chughtai renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., using security context and a certificate).
Regarding claim 10, Draznin teaches: receiving the network authentication certificate from the one or more devices when the one or more devices disconnect from and subsequently are attached again to the core enterprise network; and automatically providing full access to the network services based on the received network authentication certificate (Draznin teaches these elements inherently via 24.501 v17.7.1 - 4.4.2.6, Change of security keys: “When the AMF initiates a re-authentication to create a new 5G NAS security context, the messages exchanged during the authentication procedure are integrity protected and ciphered using the current 5G NAS security context, if any. Both UE and AMF shall continue to use the current 5G NAS security context, until . . . .”).
Regarding claim 19, Draznin teaches the invention substantially as claimed in claim 11, but does not specifically teach: wherein the one or more devices, while not including the SIM, do include an embedded-SIM (eSIM), the method further comprising: subsequent to authenticating the one or more user authentication credentials, generating at an authentication certificate generator of the core enterprise network a network authentication certificate; and providing the network authentication certificate to the one or more devices, the network authentication certificate configured to be stored in a secure memory location of the eSIM, wherein the network authentication certificate is provided to the one or more devices using the transmit and receive infrastructure of the private cellular network and without a need for a separate network.
However, in the same field of endeavor, Beals teaches: wherein the one or more devices, while not including the SIM, do include an embedded-SIM (eSIM), the method further comprising: subsequent to authenticating the one or more user authentication credentials, generating within the core enterprise network a network authentication certificate; and providing the network authentication certificate to the one or more devices, the network authentication certificate configured to be stored in a secure memory location of the eSIM, wherein the network authentication certificate is provided to the one or more devices over the transmit and receive infrastructure of the private cellular network and without any communication through a public or external network ([0005] The server then provisions a digital cryptographic certificate to the non-SIM device. The certificate is linked to the related SIM-enabled device. When the non-SIM device is ready to connect to the paid Wi-Fi network, the non-SIM device presents the certificate to the server for authentication.).
Therefore, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify Draznin to include the feature of a certificate for authentication and a combination of Draznin with Chughtai renders the claim prima facie obvious within the described scope of the prior art and any indicated differences within the level of one of ordinary skill in the art (e.g., telecommunications engineer) according to a combination of known prior art elements with known methods to yield predictable results. MPEP 2143(I)(A) (e.g., using security context and a certificate).
Regarding claim 20, Draznin teaches: receiving the network authentication certificate from the one or more devices when the one or more devices disconnect from and subsequently are attached again to the core enterprise network; and automatically providing full access to the network services based on the received network authentication certificate (Draznin teaches these elements inherently via 24.501 v17.7.1 - 4.4.2.6, Change of security keys: “When the AMF initiates a re-authentication to create a new 5G NAS security context, the messages exchanged during the authentication procedure are integrity protected and ciphered using the current 5G NAS security context, if any. Both UE and AMF shall continue to use the current 5G NAS security context, until . . . .”).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
U.S. Publication No. 2022/0400375 (hereinafter “Schmitt”) related to a system and method for phone privacy
U.S. Publication No. 2020/0112854 (hereinafter “Namiranian”) related to machine-readable code-based eSIM profile download
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JUSTIN BARRY whose telephone number is (571)272-0201. The examiner can normally be reached 8:00am EST to 5:00pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jinsong HU can be reached at (571) 272-3965. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAB/ Examiner, Art Unit 2643
/JINSONG HU/ Supervisory Patent Examiner, Art Unit 2643