Prosecution Insights
Last updated: October 01, 2026
Application No. 18/414,861

LAYER-2 SECURITY ENHANCEMENTS

Non-Final OA §103
Filed
Jan 17, 2024
Priority
Jan 18, 2023 — GR 20230100033
Examiner
FIELDS, COURTNEY D
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Apple Inc.
OA Round
3 (Non-Final)
84%
Grant Probability
Favorable
3-4
OA Rounds
7m
Est. Remaining
80%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
565 granted / 672 resolved
+26.1% vs TC avg
Minimal -4% lift
Without
With
+-4.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
17 currently pending
Career history
690
Total Applications
across all art units

Statute-Specific Performance

§101
15.3%
-24.7% vs TC avg
§103
43.5%
+3.5% vs TC avg
§102
27.0%
-13.0% vs TC avg
§112
6.5%
-33.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 672 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 2. EXAMINER’S NOTE: The claims have been reviewed and considered under the new guidance pursuant to the 2019 Revised Patent Subject Matter Eligibility Guidance (PEG 2019) issued January 7, 2019. 3. This communication is in response to Applicant’s RCE Amendment filed on 03 August 2026. Claims 4-5 have been canceled. Claims 1, 6, 8, 13, and 18-20 have been amended. Claims 1-2 and 6-20 remain pending. Continued Examination Under 37 CFR 1.114 4. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03 August 2026 has been entered. Response to Arguments 5. Applicant’s arguments, see pages 7-9, filed 03 August 2026, with respect to the rejection of claims 1-2 and 4-20 in view of Hui et al. (Pub No. 2023/0217463) and Kim et al. (Pub No. 2022/0240094) has been fully considered, but are moot in view of the new grounds of rejection. In light of the newly amended claim limitations, a new ground of rejection is hereby presented in view of Ho et al. (Pub No. 2010/0157904). Claim Rejections - 35 USC § 103 6. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 7. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 8. Claims 1-2 and 6-20 are rejected under 35 U.S.C. 103 as being unpatentable over Hui et al. (Pub No. 2023/0217463) in view of Kim et al. (Pub No. 2022/0240094) and in further view of Ho et al. (Pub No. 2010/0157904). Referring to the rejection of claim 1, Hui et al. discloses a method comprising: generating a layer-2 (L2) header block for a medium access control (MAC) subprotocol data unit (subPDU), the MAC subPDU comprising a MAC service data unit (SDU) that includes an internet protocol (IP) packet; (See Hui et al., para. 81-82, 193-196, and Fig. 4A, i.e., the four protocols MAC, item 222, RLC, item 223, PDCP, item 224, and SDAP, item 225 makes up layer-2 header block to generate a MAC PDU subheader, the MAC PDU comprises a MAC SDU that includes an IP packet) ciphering at least a portion of the L2 header block in a MAC layer; (See Hui et al., para. 82, i.e., the PDCP, item 224 performs IP-header compression and ciphering and forward its output to the RLC, item 223. The RLC, item 223 performs segmentation and forwards its output to the MAC, item 222) and assembling a transport block that includes the ciphered portion of the L2 header block in the MAC subPDU. (See Hui et al., para. 82-83 and Fig. 4B, i.e., The MAC, item 222 multiplex a number of RLC PDUs and attach a MAC subheader to an RLC PDU to form a transport block. The MAC subheaders may be entirely located at the beginning of the MAC PDU, reduce processing time and associated latency because the MAC PDU subheaders may be computed before the full MAC PDU is assembled. The MAC PDU is assembled via a format of a MAC subheader (SDU) and MAC control elements (CEs). The PDCP, item 224 performs IP-header compression and ciphering, forwards the output to RLC, item 223. The RLC, item 223 forwards the output to the MAC, item 222. The MAC, item 222 attaches a MAC subheader to form a transport block – MAC SDU with an IP packet portion n) Hui et al. fail to explicitly disclose wherein the at least the ciphered portion of the L2 header block comprises a M MACI. Kim et al. discloses a method and system for enhancing security when a UE and a base station perform data communication in a next-generation mobile communication system. Kim et al. discloses wherein the at least the ciphered portion of the L2 header block comprises a MAC Message Authentication Code (M MACI), a Service Data Adaptation Protocol (SDAP) header, a Packet Data Convergence Protocol (PDCP) header, and a Radio Link Control (RLC) header. (See Kim et al., para. 83, 121-164, 189-200 and Fig. 1D, 1GA-1GC, i.e., the portions of the layer-2 header block comprising a MAC-I, item 1d-15 and 1d-30, a SDAP header, item 1d-01 and 1d-45, PDCP header, item 1d-05 and 1d-40, and RLC header, item 1d-10 and 1d-35) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date the claimed invention was made to combine Hui et al.’s sidelink inter-UE coordination information transmissions modified with Kim et al.’s method and system for enhancing security when a UE and a base station perform data communication in a next-generation mobile communication system. Motivation for such an implementation would enable an integrity protection procedure, or a ciphering procedure is configured in the PDCP layer, the transmission PDCP layer may apply a header compression procedure to the upper layer data, perform an integrity protection procedure on header compressed data or PDCP header, attach a 4-byte MAC-I field to the back, and apply a ciphering procedure to the data to which the integrity protection procedure is applied and the MAC-I field. (See Kim et al., para. 192) The combination of Hui et al. and Kim et al. fail to explicitly disclose ciphering at least a portion of the MAC SDU based on a ciphering offset that indicates a length value corresponding to at least one of an IP header or a portion of the IP packet in the MAC SDU and including the ciphered portion of the MAC SDU. Ho et al. discloses a method and apparatus for optimizing headers for efficient processing of data packets for ciphering offsets. Ho et al. discloses ciphering at least a portion of the MAC SDU based on a ciphering offset that indicates a length value corresponding to at least one of an IP header or a portion of the IP packet in the MAC SDU and including the ciphered portion of the MAC SDU. (See Ho et al., para. 53-57, 63-66, 75-76, i.e., partially ciphered MAC SDUs of a MAC PDU having a PDCP payload and header comprising a plurality of IP packets and a length indicator for at least one of the IP packets. Ciphering is performed by a ciphering machine 802 between a mask and each PDCP SDU in the payload. The mask is generated by running a ciphering sequence number (Count-C) through another ciphering machine using a ciphering key (CK). The Count-C includes a long sequence number (referred to as a Hyper Frame Number (HFN)) and the SN for the SDU being ciphered. The PDCP LI fields are ciphered, so that the PDCP ciphering offset can start from beginning or after a fixed header (e.g., after the PDCP SN). In one configuration, the receiver may use the Count-C to compute the SN, thereby eliminating the need for the SN in the RLC header.) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date the claimed invention was made to combine Hui et al.’s sidelink inter-UE coordination information transmissions and Kim et al.’s method and system for enhancing security when a UE and a base station perform data communication in a next-generation mobile communication system modified with Ho et al.’s method and apparatus for optimizing headers for efficient processing of data packets for ciphering offsets. Motivation for such an implementation would enable a separate offset for at least each of the partial PDCP PDUs wherein each of the offsets are configured to support deciphering the corresponding PDCP PDU. (See Ho et al., para. 9) Referring to the rejection of claim 2, (Hui et al. and Kim et al. modified by Ho et al.) discloses wherein the L2 header block comprises at least one of a MAC Sub-PDU header (MAC SH), the M MACI, the SDAP header, the PDCP header, or the RLC header. (See Hui et al., para. 81-82 and Fig. 4A, i.e., a layer-2 header block comprising at least one of the following: SDAP header, item 225, PDCP header, item 224, and RLC header, item 223) Referring to the rejection of claim 6, (Hui et al. and Kim et al. modified by Ho et al.) discloses the method further comprising: integrity protecting at least a second portion of the L2 header block. (See Kim et al., para. 192-193, i.e., integrity protection of a second portion of the L2 header as disclosed in Figs. 1g-20 and 1g-30) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 7, (Hui et al. and Kim et al. modified by Ho et al.) discloses wherein the second portion of the L2 header block comprises one of: a combination of a first MAC SH of a plurality of MAC SHs, the SDAP header, the PDCP header, and the RLC header; (See Kim et al., para. 194, i.e., the transmitted data has a repeated structure such as header (MAC subheader, RLC header, PDCP header, or SDAP header) and data, header (MAC subheader, RLC header, PDCP header, or SDAP header), the first MAC SH; the plurality of MAC SHs; (See Kim et al., para. 211 and Fig. 1J, i.e., when configuring the MAC PDU (data unit composed of a plurality of MAC subPDUs), the MAC layer configures downlink data based on the MAC subPDU and the padding may be positioned at the end of the MAC PDU composed of MAC subPDUs); or a second combination of the plurality of MAC SHs, the SDAP header, the PDCP header, and the RLC header. The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 8, (Hui et al. and Kim et al. modified by Ho et al.) discloses further comprising: integrity protecting, based on an integrity protection offset, at least a second portion of the MAC SDU, wherein the second portion of the MAC SDU includes at least one of: the IP header or the portion of the IP packet. (See Kim et al., para. 192-193, 214, 244, and 248, i.e., integrity protection of a second portion of the IP header as disclosed in Figs. 1g-20 and 1g-30. An integrity protection procedure or integrity verification procedure is configured in the MAC layer, the logical identifier of the MAC subheader may be checked and the first field may be checked, and an integrity verification procedure may be applied to the entire MAC PDU or the data portion to which integrity protection is applied to determine integrity. When the integrity protection procedure is configured in the MAC layer, the receiver may read the first field of the constant size before or after each data to which integrity protection is applied, always attaching only the first field 1L-27 of a constant size to before or after 1L-22 and 1L-24 the data (data with Integrity Protection applied, MAC SDU or MAC subPDU), defining a second field in the MAC subheader 1L-21 of the data to indicate whether the integrity protection procedure has been applied (or whether data protection procedures have been applied), and indicating that the first field exists before or after the data, this will reduce the overhead by the size of the MAC subheader) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 9, (Hui et al. and Kim et al. modified by Ho et al.) discloses wherein the IP packet is a first encrypted IP packet, and the method further comprising: establishing a secure data radio bearer (DRB) with a receiver; mapping, using a traffic flow template (TFT) filter, a second unsecured IP packet to a secure quality of service (QoS) flow, wherein the unsecured IP packet is not ciphered or integrity protected; and mapping the secure QoS flow to the secure DRB. (See Hui et al., para. 63 and 74, i.e., The SDAPs, items 215 and 225 perform mapping between the one or more QoS flows and one or more data radio bearers. The SDAP, item 215 at the UE, item 210 may be informed of the mapping between the QoS flows and the data radio bearers through reflective mapping received from the gNB, item 220. For reflective mapping, the SDAP at the gNB marks the downlink packets with a QoS flow indicator (QFI), which may be observed by the SDAP 215 at the UE 210 to determine the mapping between the QoS flows and the data radio bearers. The filtering for routing traffic flows to one or more DNs is handled by the QoS) Referring to the rejection of claim 10, (Hui et al. and Kim et al. modified by Ho et al.) discloses further comprising: in the secure DRB, performing at least one of: ciphering the unsecured IP packet; or integrity protecting the unsecured IP packet. (See Hui et al., para. 74-75, i.e., the PDCP, item 224 performs ciphering the IP packet that is mapped to the data radio bearer to prevent unauthorized decoding of data transmitted over the air interface) Referring to the rejection of claim 11, (Hui et al. and Kim et al. modified by Ho et al.) discloses further comprising: mapping the first encrypted IP packet to a second DRB different from the secure DRB. (See Hui et al., para. 81, i.e., the SDAP, item 225 maps the encrypted IP packets n and n+1 to a first data radio bearer, item 402 and maps the encrypted IP packet m to a second data radio bearer, item 404) Referring to the rejection of claim 12, (Hui et al. and Kim et al. modified by Ho et al.) discloses further comprising: transmitting the transport block to a receiver. (See Hui et al., para. 108, i.e., RRC messages are transmitted between the UE and the RAN using signaling data radio bearers and the MAC multiplex control-plane and user-plane data into the same transport block to the receiver for broadcasting information) Referring to the rejection of claim 13, (Hui et al. and Kim et al. modified by Ho et al.) discloses further comprising: performing, based on an integrity protection offset integrity protection of at least a second portion of the MAC SDU, wherein the at least one of the integrity protection offset or the ciphering offset has a corresponding standardized index in a mapping table. (See Kim et al., para. 214, 244, and 248, i.e., RLC PDUs received based on the RLC serial number, segment information (SI field) or segment offset information (SO field) of the RLC header and then transmits the complete RLC SDU to the upper layer as a PDCP PDU, ciphering is applied to the received MAC PDU. An integrity protection procedure or integrity verification procedure is configured in the MAC layer, the logical identifier of the MAC subheader may be checked and the first field may be checked, and an integrity verification procedure may be applied to the entire MAC PDU or the data portion to which integrity protection is applied to determine integrity. When the integrity protection procedure is configured in the MAC layer, the receiver may read the first field of the constant size before or after each data to which integrity protection is applied, while performing the procedure proposed above, by without assigning or defining the logical channel identifier for the first field, without configuring the MAC subheader, always attaching only the first field 1L-27 of a constant size to before or after 1L-22 and 1L-24 the data (data with Integrity Protection applied, MAC SDU or MAC subPDU), defining a second field in the MAC subheader 1L-21 of the data to indicate whether the integrity protection procedure has been applied (or whether data protection procedures have been applied), and indicating that the first field exists before or after the data, this will reduce the overhead by the size of the MAC subheader) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 14, (Hui et al. and Kim et al. modified by Ho et al.) discloses further comprising determining the at least one of the integrity protection offset or the ciphering offset based on one of: a hardware capability of a transmitter performing the least one of ciphering or integrity protection, (See Hui et al., para. 57, i.e., a transmitter for ciphering is disclosed as a wireless device transmitter) a logical channel (LC) for the IP packet, (See Hui et al., para. 82-83, i.e., a logical channel for identifying the IP packet is disclosed) a radio bearer (RB) type for the IP packet, (See Hui et al., para. 76, i.e., a radio bearer for the IP packet is disclosed) a Quality of Service (QoS) flow for the IP packet, (See Hui et al., para. 74 and 81, i.e., a QoS flow for the IP packet is disclosed) application layer information for the IP packet, or a security class of the transmitter. Referring to the rejection of claim 15, (Hui et al. and Kim et al. modified by Ho et al.) discloses wherein determining the at least one of the integrity protection offset or the ciphering offset is based on the RB type comprises: determining that the RB type is a Voice over IP (VoIP); and in response, determining that the at least one of the integrity protection offset or the ciphering offset covers at least one of an IP header, a User Datagram Protocol (UDP) header, or a Real-time Transport Protocol (RTP) header. (See Kim et al., para. 86, 88, and 95, i.e., the UE through a radio channel perform real-time services such as Voice over IP (VoIP) through Internet protocol, serviced through shared channels, a device for scheduling by collecting status information, available transmission power status, and channel status of the UEs and the radio link control determines ciphering of an IP header) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 16, (Hui et al. and Kim et al. modified by Ho et al.) discloses wherein determining the at least one of the integrity protection offset or the ciphering offset is based on the security class of the transmitter comprises: determining that the transmitter is assigned a secure security class; and in response, determining that the at least one of the integrity protection offset or the ciphering offset covers the IP packet and an IP header. (See Kim et al., para. 189, i.e., if a ciphering procedure or security key setting information is configured in the PDCP layer, the UE may perform a ciphering procedure by deriving security keys from the RRC layer and applying the derived security keys when establishing or re-establishing the PDCP layer. As in 1G-05, when the PDCP layer receives data (e.g., PDCP SDU) from the upper layer, if the header compression procedure is configured or the ciphering procedure is configured through the RRC message as in FIG. 1E, a header compression procedure is performed on the data or a ciphering procedure is performed on the data, a PDCP serial number is assigned, and a PDCP header is configured to transmit the data as a PDCP PDU to a lower layer) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 17, (Hui et al. and Kim et al. modified by Ho et al.) discloses the method further comprising: determining the at least one of the integrity protection offset or the ciphering offset by selecting at least one of a first portion of the IP packet to cipher or a second portion of the IP packet to integrity protect; and including the at least one of the integrity protection offset or the ciphering offset in a MAC subheader to signal the at least one of the integrity protection offset or the ciphering offset to a receiver. (See Kim et al., para. 214, 244, and 248, i.e., RLC PDUs received based on the RLC serial number, segment information (SI field) or segment offset information (SO field) of the RLC header and then transmits the complete RLC SDU to the upper layer as a PDCP PDU, ciphering is applied to the received MAC PDU. An integrity protection procedure or integrity verification procedure is configured in the MAC layer, the logical identifier of the MAC subheader may be checked and the first field may be checked, and an integrity verification procedure may be applied to the entire MAC PDU or the data portion to which integrity protection is applied to determine integrity. When the integrity protection procedure is configured in the MAC layer, the receiver may read the first field of the constant size before or after each data to which integrity protection is applied, while performing the procedure proposed above, by without assigning or defining the logical channel identifier for the first field, without configuring the MAC subheader, always attaching only the first field 1L-27 of a constant size to before or after 1L-22 and 1L-24 the data (data with Integrity Protection applied, MAC SDU or MAC subPDU), defining a new second field in the MAC subheader 1L-21 of the data to indicate whether the integrity protection procedure has been applied (or whether data protection procedures have been applied), and indicating that the first field exists before or after the data, this will reduce the overhead by the size of the MAC subheader) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 18, (Hui et al.) discloses a method to be performed by a receiving device, the method comprising: receiving a transport block comprising a medium access control (MAC) subprotocol data unit (subPDU), and a layer-2 (L2) header block for the MAC sub PDU, the MAC subPDU comprising a MAC service data unit (SDU) that includes an internet protocol (IP) packet; (See Hui et al., para. 81-82, 193-196, and Fig. 4A, i.e., the four protocols MAC, item 222, RLC, item 223, PDCP, item 224, and SDAP, item 225 makes up layer-2 header block to generate a MAC PDU subheader, the MAC PDU comprises a MAC SDU that includes an IP packet) Hui et al. fail to explicitly disclose wherein the at least the ciphered portion of the L2 header block comprises a M MACI and in a MAC layer of the receiving device, using an authentication algorithm and a ciphering algorithm to determine contents of a L2 header block of the MAC subPDU. Kim et al. discloses a method and system for enhancing security when a UE and a base station perform data communication in a next-generation mobile communication system. Kim et al. discloses wherein a ciphered portion of the L2 header block comprises a MAC Message Authentication Code (M MACI), a Service Data Adaptation Protocol (SDAP) header, a Packet Data Convergence Protocol (PDCP) header, and a Radio Link Control (RLC) header; (See Kim et al., para. 83, 121-164, 189-200 and Fig. 1D, 1GA-1GC, i.e., the portions of the layer-2 header block comprising a MAC-I, item 1d-15 and 1d-30, a SDAP header, item 1d-01 and 1d-45, PDCP header, item 1d-05 and 1d-40, and RLC header, item 1d-10 and 1d-35) Kim et al. discloses and in a MAC layer of the receiving device, using an authentication algorithm and a ciphering algorithm to determine contents of the L2 header block and the MAC SDU of the MAC subPDU. (See Kim et al., para. 236-237, i.e., the data protection procedure (ciphering procedure or integrity protection procedure) is configured in the MAC layer, when the integrity protection procedure is configured, the MAC layer may apply an integrity protection procedure to all MAC PDUs 1K-16, generate a MAC-I (Message Authentication Code-Integrity) field) generated as a result of the integrity protection procedure, and place the first field at the beginning of the MAC PDU the integrity-protected MAC PDU or the first field if the integrity protection procedure is configured. The MAC layer can distinguish the first field as a MAC SDU, generate a MAC subheader including a logical channel identifier indicating the first field, attach the MAC subheader to the front of the first field to configure a MAC PDU, and then place the MAC PDU at the beginning of the MAC PDU) The combination of Hui et al. and Kim et al. fail to explicitly disclose a ciphered portion of the MAC SDU is determined to include at least one of an IP header or a portion of the IP packet based on a ciphering offset that indicates a length value corresponding to at least one of the IP header or the portion of the IP packet in the MAC SDU. Ho et al. discloses a method and apparatus for optimizing headers for efficient processing of data packets for ciphering offsets. Ho et al. discloses a ciphered portion of the MAC SDU is determined to include at least one of an IP header or a portion of the IP packet based on a ciphering offset that indicates a length value corresponding to at least one of the IP header or the portion of the IP packet in the MAC SDU. (See Ho et al., para. 53-57, 63-66, 75-76, i.e., partially ciphered MAC SDUs of a MAC PDU having a PDCP payload and header comprising a plurality of IP packets and a length indicator for at least one of the IP packets. Ciphering is performed by a ciphering machine 802 between a mask and each PDCP SDU in the payload. The mask is generated by running a ciphering sequence number (Count-C) through another ciphering machine using a ciphering key (CK). The Count-C includes a long sequence number (referred to as a Hyper Frame Number (HFN)) and the SN for the SDU being ciphered. The PDCP LI fields are ciphered, so that the PDCP ciphering offset can start from beginning or after a fixed header (e.g., after the PDCP SN). In one configuration, the receiver may use the Count-C to compute the SN, thereby eliminating the need for the SN in the RLC header.) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 19, (Hui et al. and Kim et al. modified by Ho et al.) discloses the method further comprising: determining, based on an integrity protection offset and the ciphering offset, a protected portion of the IP packet and the IP header; and in the MAC layer of the receiving device, using the authentication algorithm and the ciphering algorithm to determine contents of the protected portion of the IP packet and the IP header. (See Kim et al., para. 236-237, i.e., the data protection procedure (ciphering procedure or integrity protection procedure) is configured in the MAC layer, when the integrity protection procedure is configured, the MAC layer may apply an integrity protection procedure to all MAC PDUs 1K-16, generate a first field (e.g., digital signature (DS) field or MAC-I (Message Authentication Code-Integrity) field) generated as a result of the integrity protection procedure, and place the first field at the beginning of the MAC PDU the integrity-protected MAC PDU or the first field if the integrity protection procedure is configured) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Referring to the rejection of claim 20, (Hui et al.) discloses an apparatus comprising processing circuitry configured to perform operations comprising: generating a layer-2 (L2) header block for a medium access control (MAC) subprotocol data unit (subPDU), the MAC subPDU comprising a MAC service data unit (SDU) that includes an internet protocol (IP) packet; (See Hui et al., para. 81-82, 193-196, and Fig. 4A, i.e., the four protocols MAC, item 222, RLC, item 223, PDCP, item 224, and SDAP, item 225 makes up layer-2 header block to generate a MAC PDU subheader, the MAC PDU comprises a MAC SDU that includes an IP packet) ciphering at least a portion of the L2 header block in a MAC layer; (See Hui et al., para. 82, i.e., the PDCP, item 224 performs IP-header compression and ciphering and forward its output to the RLC, item 223. The RLC, item 223 performs segmentation and forwards its output to the MAC, item 222) and assembling a transport block that includes the ciphered portion of the L2 header block in the MAC subPDU. (See Hui et al., para. 82-83 and Fig. 4B, i.e., The MAC, item 222 multiplex a number of RLC PDUs and attach a MAC subheader to an RLC PDU to form a transport block. The MAC subheaders may be entirely located at the beginning of the MAC PDU, reduce processing time and associated latency because the MAC PDU subheaders may be computed before the full MAC PDU is assembled. The MAC PDU is assembled via a format of a MAC subheader (SDU) and MAC control elements (CEs). The PDCP, item 224 performs IP-header compression and ciphering, forwards the output to RLC, item 223. The RLC, item 223 forwards the output to the MAC, item 222. The MAC, item 222 attaches a MAC subheader to form a transport block – MAC SDU with an IP packet portion n) Hui et al. fail to explicitly disclose wherein the at least the ciphered portion of the L2 header block comprises a M MACI. Kim et al. discloses a method and system for enhancing security when a UE and a base station perform data communication in a next-generation mobile communication system. Kim et al. discloses wherein the at least the ciphered portion of the L2 header block comprises a MAC Message Authentication Code (M MACI), a Service Data Adaptation Protocol (SDAP) header, a Packet Data Convergence Protocol (PDCP) header, and a Radio Link Control (RLC) header. (See Kim et al., para. 83, 121-164, 189-200 and Fig. 1D, 1GA-1GC, i.e., the portions of the layer-2 header block comprising a MAC-I, item 1d-15 and 1d-30, a SDAP header, item 1d-01 and 1d-45, PDCP header, item 1d-05 and 1d-40, and RLC header, item 1d-10 and 1d-35) The combination of Hui et al. and Kim et al. fail to explicitly disclose ciphering at least a portion of the MAC SDU based on a ciphering offset that indicates a length value corresponding to at least one of an IP header or a portion of the IP packet in the MAC SDU and the ciphered portion of the MAC SDU. Ho et al. discloses a method and apparatus for optimizing headers for efficient processing of data packets for ciphering offsets. Ho et al. discloses ciphering at least a portion of the MAC SDU based on a ciphering offset that indicates a length value corresponding to at least one of an IP header or a portion of the IP packet in the MAC SDU and the ciphered portion of the MAC SDU. (See Ho et al., para. 53-57, 63-66, 75-76, i.e., partially ciphered MAC SDUs of a MAC PDU having a PDCP payload and header comprising a plurality of IP packets and a length indicator for at least one of the IP packets. Ciphering is performed by a ciphering machine 802 between a mask and each PDCP SDU in the payload. The mask is generated by running a ciphering sequence number (Count-C) through another ciphering machine using a ciphering key (CK). The Count-C includes a long sequence number (referred to as a Hyper Frame Number (HFN)) and the SN for the SDU being ciphered. The PDCP LI fields are ciphered, so that the PDCP ciphering offset can start from beginning or after a fixed header (e.g., after the PDCP SN). In one configuration, the receiver may use the Count-C to compute the SN, thereby eliminating the need for the SN in the RLC header.) The rationale for combining Hui et al. and Kim et al. in view of Ho et al. is the same as claim 1. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to COURTNEY D FIELDS whose telephone number is (571)272-3871. The examiner can normally be reached IFP M-F 8am-4:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /COURTNEY D FIELDS/Examiner, Art Unit 2436 August 26, 2026 /SHEWAYE GELAGAY/Supervisory Patent Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Jan 17, 2024
Application Filed
Nov 28, 2025
Non-Final Rejection mailed — §103
Feb 25, 2026
Response Filed
Jun 05, 2026
Final Rejection mailed — §103
Aug 03, 2026
Request for Continued Examination
Aug 09, 2026
Response after Non-Final Action
Sep 09, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743522
PREVENTING VULNERABLE CODE UPLOAD/DOWNLOAD
3y 8m to grant Granted Sep 22, 2026
Patent 12732534
SYSTEMS AND METHODS FOR DETECTION OF DENIAL OF SERVICE ATTACKS FOR PROTOCOLS WITH HIGH BURST DATA RATES
3y 2m to grant Granted Sep 08, 2026
Patent 12732340
EVALUATING CONVOLUTIONS USING ENCRYPTED DATA
3y 1m to grant Granted Sep 08, 2026
Patent 12732805
INTEGRATED TERMINAL DEVICE AND CONTROL METHOD OF INTEGRATED TERMINAL DEVICE
1y 9m to grant Granted Sep 08, 2026
Patent 12732381
SYSTEMS AND METHODS FOR FACILITATING CRYPTOGRAPHIC ATTESTATION CHAINS USING BONDED ORACLES
1y 8m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
84%
Grant Probability
80%
With Interview (-4.0%)
3y 4m (~7m remaining)
Median Time to Grant
High
PTA Risk
Based on 672 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month