Prosecution Insights
Last updated: October 02, 2026
Application No. 18/576,042

ESTABLISHING A TRUST RELATIONSHIP BETWEEN AN APPLICATION ENTITY AND A WIRELESS COMMUNICATION NETWORK

Non-Final OA §103
Filed
Jan 02, 2024
Priority
Jul 02, 2021 — GR 20210100453 +2 more
Examiner
WRIGHT, BRYAN F
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
Lenovo (United States) Inc.
OA Round
3 (Non-Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
641 granted / 820 resolved
+20.2% vs TC avg
Strong +24% interview lift
Without
With
+24.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
21 currently pending
Career history
847
Total Applications
across all art units

Statute-Specific Performance

§101
13.4%
-26.6% vs TC avg
§103
56.5%
+16.5% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
9.0%
-31.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 820 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 09/02/2026 has been entered. Claims 1, 2, 9, 12, 16 and 17 are amended. Claims 1-20 are pending. Response to Arguments Examiner’s Remarks - Claim Objection The examiner suggest that the applicant replace the term “equipment” to either “device or apparatus”. The examiner maintains the objection. Examiner’s Remarks - 35 USC § 112 The examiner withdraws the rejection in view of applicant’s claim amendment(s). Examiner’s Remarks - 35 USC § 103 – Independent claims 1 and 16 The applicant has amended independent claims 1 and 16 to include the new feature(s) of, “receive, at the application entity from the first network function, a credential generated by the first network function; send, from the application entity to the second network function, a message comprising the credential; receive a result of the authentication from at least one of the first and second network functions, the application entity being authenticated by the second network function in response to the second network function verifying that the credential is associated with the first network function”. In view of the new claim amendment(s) the examiner introduces the teachings of prior art reference CHOYI et al. (US Patent Publication No. 2024/0064144) to the record. The examiner contends that CHOYI teaches trust relationships and utilizes credentials for access control. See rejections below. The examiner notes that applicant’s arguments with respect to claim(s) 1 and 16 pertaining to prior art reference GUO have been considered but are moot because the new ground of rejection does not rely on the GUO reference. See rejections below. Examiner’s Remarks - 35 USC § 103 – Independent claims 9 and 12 The applicant has amended independent claims 9 and 12 to include the new feature(s) of, “wherein the application entity is authenticated by the second network function in response to the second network function verifying that the CCA token, received by the second network function from the application entity, is associated with the first network function”. In view of the new claim amendment(s) the examiner introduces the teachings of prior art reference CHOYI et al. (US Patent Publication No. 2024/0064144) to the record. The examiner contends that CHOYI teaches trust relationships and utilizes credentials for access control. See rejections below. The examiner notes that applicant’s arguments with respect to claim(s) 9 and 12 pertaining to prior art reference GUO have been considered but are moot because the new ground of rejection does not rely on the GUO reference. See rejections below. With regards to applicant’s remarks of, “Chang therefore contains no entity corresponding to the claimed application entity that receives a credential from one network function and carries it to a second network function with which it has no prior trust relationship. Moreover, the access token of Chang is generated by mechanism 316-the element the Office Action maps to the second network function-and not by the element mapped to the first network function”, the examiner respectfully disagrees. The examiner notes that applicants’ current independent claim structure does not restrict or limit the implementation/interpretation of the said application entity. As such, the examiner contends there are many reasonable implementations/interpretations that are afforded from such claim structure. Additionally, the examiner notes that applicant’s argued feature(s) of, “application entity that receives a credential from one network function and carries it to a second network function with which it has no prior trust relationship”, is currently not explicitly recited in the claim current independent claim structure. With regards to applicant’s remarks of, “There is no third-party issuer that generates a credential vouching for a different entity. Further, Tran expressly provides that "A service registry 106 can have an existing trust relationship with each of the first application 108, the second application 110, and the third application 112," id. at 1 [0019], so Tran does not describe authentication of an entity across a trust gap at all”, the examiner respectfully disagrees. The examiner notes that applicant’s argued feature(s) of, “there is no third-party issuer that generates a credential vouching for a different entity” and “authentication of an entity across a trust gap” are not explicitly recited in the current claim structure of applicant’s independent claims. (EMPHASIS) Claim Objections Claims 1-15 are objected to because of the following informalities: “equipment”. The examiner recommends that the applicant replace “equipment” with “device or apparatus”. Appropriate correction is required. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 2 and 7-17 are rejected under 35 U.S.C. 103 as being unpatentable over Chang et al. (US Patent Publication No. 2015/0074395 and Chang hereinafter) in view of TRAN (US Patent Publication No. 2018/0219863) and further in view of CHOYI et al. (US Patent Publication No. 2024/0064144 and CHOYI hereinafter). As to claims 1 and 16, Chang teaches a network equipment (NE) for wireless communication, comprising: at least one memory (i.e., …teaches in par. 0005 the following: “The system/apparatus may comprise one or more processors and a memory coupled to the one or more processors.”); and at least one processor coupled with the at least one memory and configured to cause the NE to (i.e., …teaches in par. 0005 the following: “The system/apparatus may comprise one or more processors and a memory coupled to the one or more processors.”): send, from an application entity, a request to a first network function to authenticate the application entity to a second network function that does not have a trust relationship with the application entity (i.e., …teaches in par. 0032 the following: “To establish the trust relationship, administrator 308 of device 302 initiates a registration request to register the one or more applications with the one or more resources via a user interface (UI) to trust relationship establishment mechanism 306. Administrator 308 may then submit the registration request and, by sending the registration request via trust relationship establishment mechanism 306, trust relationship establishment mechanism 306 may send the registration request to trust relationship establishment mechanism 316 as an authorized registration request. Those skilled in the art will recognize that trust relationship establishment mechanism 306 may send additional credential data in the registration request to trust relationship establishment mechanism 316 to enable trust relationship establishment mechanism 316 to validate authenticity of subsequent request in a next trust establishment operation.”), the request comprising at least one verifiable parameter for authenticating the application entity (i.e., …teaches in par. 0032 the following: “may include in the registration request one or more registration artifacts, such as a redirection uniform resource identifier (URI), a requested scope that identifies a role of the requesting one or more applications, a local state of device 302, an identifier representing the administrator 308, a public key or certificate for the one or more applications, any additional authentication data associated with the application or the user of the application, the one or more resources to be accessed, or the like.”. …teaches in par. 0035 the following: “If trust relationship establishment mechanism 316 verifies that the redirection URI included with the access token request is the same as the redirection URI provided with the registration request, the trust relationship establishment mechanism 316 sends an access token back to trust relationship establishment mechanism 306 via trust relationship establishment mechanism 316.”); and a processor that establish a trust relationship between the application entity and the second network function wherein the application entity can communicate with the second network function in response to the application entity being authenticated (i.e., …teaches in par. 0035 the following: “the access token may be used by resource-side system to grant application side devices and users authorized access to resource side resources.”). Chang does not expressly the first network function having a trust relationship with the application entity and the second network function. In this instance the examiner notes the teachings of prior art reference Tran. TRAN teaches in par. 0020 the following: “The service registry 106 can authenticate the registration requests using the pre-established trust relationship. The system 100 creates the trust relationship by binding each of the first application 108, the second application 110 and the third application 112 to a service instance of the service registry…”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teaching of Chang with the teachings of TRAN by having their system comprise an enhanced application security process. One would have been motivated to do so to provide a simple and effective means to configure application security, wherein the enhanced application security process helps to prevent unauthorized applications in the network and makes it easier to ensure network system security. The system of Chang and Tran does not expressly teach: receive, at the application entity from the first network function, a credential generated by the first network function; send, from the application entity to the second network function, a message comprising the credential; receive a result of the authentication from at least one of the first and second network functions, the application entity being authenticated by the second network function in response to the second network function verifying that the credential is associated with the first network function. In this instance the examiner notes the teachings of prior art reference CHOYI. With regards to applicant’s claim limitation element of, “receive, at the application entity from the first network function, a credential generated by the first network function”, teaches in par. 0019 the following: “a credential registration and provisioning”. CHOYI teaches in par. 0037 the following: “an access tokens refer to credentials used to access protected resource”. Teaches in par. 0040 the following: “The SLMF 310 may use the services of a Credential Management Function (CMF) 312,”. With regards to applicant’s claim limitation element of, “send, from the application entity to the second network function, a message comprising the credential”, teaches in par. 0049 the following: “a set of generated credentials shared can be shared between two entities and can be used in order to generate another set of credentials”. With regards to applicant’s claim limitation element of, “receive a result of the authentication from at least one of the first and second network functions”, teaches in par. 0037 the following: “the authorization server can vouch that an entity has the appropriate privileges”. With regards to applicant’s claim limitation element of, “the application entity being authenticated by the second network function in response to the second network function verifying that the credential is associated with the first network function”, teaches in par. 0074 the following: “The credentials may be used both by the Devices as well as the Del 604 in order to mutually authenticate the messages sent between the Devices and the Del 604.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teaching of Chang and TRAN with the teachings of CHOYI by having their system comprise an enhanced security management process. One would have been motivated to do so to provide a simple and effective means to manage access control within a network, wherein the enhanced security management process helps to prevent unauthorized access within the network and makes it easier to ensure network access is controlled. As to claims 2 and 17, the system of Chang, Tran and CHOYI as applied to claim 1 above teaches trust relationship, specifically Chang teaches a NE of claim 1, wherein the at least one processor is configured to cause the NE to receive, from the first network function, a network address identifier ("NAI") of the second network function (i.e., …teaches in par. 0032 the following: “To establish the trust relationship, administrator 308 of device 302 initiates a registration request to register the one or more applications with the one or more resources via a user interface (UI) to trust relationship establishment mechanism 306. Administrator 308 may include in the registration request one or more registration artifacts, such as a redirection uniform resource identifier (URI), a requested scope that identifies a role of the requesting one or more applications, a local state of device 302, an identifier representing the administrator 308, a public key or certificate for the one or more applications, any additional authentication data associated with the application or the user of the application, the one or more resources to be accessed, or the like.”), and a client credential assertion ("CCA") token associated with the first network function (i.e., …teaches in par. 0032 the following: “To establish the trust relationship, administrator 308 of device 302 initiates a registration request to register the one or more applications with the one or more resources via a user interface (UI) to trust relationship establishment mechanism 306. Administrator 308 may include in the registration request one or more registration artifacts, such as a redirection uniform resource identifier (URI), a requested scope that identifies a role of the requesting one or more applications, a local state of device 302, an identifier representing the administrator 308, a public key or certificate for the one or more applications, any additional authentication data associated with the application or the user of the application, the one or more resources to be accessed, or the like.”). As to claim 7, the system of Chang, Tran and CHOYI as applied to claim 1 above teaches trust relationship, specifically Chang teaches a NE of claim 1, wherein the at least one processor is configured to cause the NE to determine application entity information for the application entity, the application entity information comprising at least one of an application entity identifier, an application identifier, and management information for authenticating the application entity with a mobile wireless communication network (i.e., …teaches in par. 0003 the following: “an authorization code and a symmetric key”). As to claim 8, the system Chang, Tran and CHOYI as applied to claim 7 above teaches trust relationship, specifically Chang teaches a NE of claim 7, wherein the management information comprises a service description associated with the application entity (i.e., …teaches in par. 0032 the following: “scope that identifies a role of the requesting one or more applications” …teaches in par. 0032 the following: “any additional authentication data associated with the application”.), the service description translated into a slice blueprint at the second network function to derive an application identifier (i.e., …teaches in par. 0032 the following: “scope that identifies a role of the requesting one or more applications” …teaches in par. 0034 the following: “verifiable authentication data,”.). As to claim 9, Chang teaches a network equipment (NE) for wireless communication, comprising: at least one memory (i.e., …teaches in par. 0005 the following: “The system/apparatus may comprise one or more processors and a memory coupled to the one or more processors. The memory may comprise instructions which, when executed by the one or more processors, cause the one or more processors to perform various ones of, and combinations of, the operations outlined above with regard to the method illustrative embodiment”); and at least one processor coupled with the at least one memory and configured to cause the NE to (i.e., …teaches in par. 0005 the following: “The system/apparatus may comprise one or more processors and a memory coupled to the one or more processors. The memory may comprise instructions which, when executed by the one or more processors, cause the one or more processors to perform various ones of, and combinations of, the operations outlined above with regard to the method illustrative embodiment”): generate, at a first network function, a client credential assertion ("CCA") token for the first network function (i.e., …teaches in par. 0032 the following: “…device 302 initiates a registration request to register the one or more applications with the one or more resources via a user interface (UI) to trust relationship establishment mechanism 306. Administrator 308 may include in the registration request one or more registration artifacts, such as a redirection uniform resource identifier (URI), a requested scope that identifies a role of the requesting one or more applications, a local state of device 302, an identifier representing the administrator 308, a public key or certificate for the one or more applications, any additional authentication data associated with the application or the user of the application, the one or more resources to be accessed, or the like.”); send from the first network function, an authentication request to a second network function for authenticating an application entity (i.e., …teaches in par. 0032 the following: “then submit the registration request and, by sending the registration request via trust relationship establishment mechanism 306, trust relationship establishment mechanism 306 may send the registration request to trust relationship establishment mechanism 316 as an authorized registration request.”), the authentication request comprising the CCA token of the first network function (i.e., …teaches in par. 0032 the following: “…device 302 initiates a registration request to register the one or more applications with the one or more resources via a user interface (UI) to trust relationship establishment mechanism 306. Administrator 308 may include in the registration request one or more registration artifacts, such as a redirection uniform resource identifier (URI), a requested scope that identifies a role of the requesting one or more applications, a local state of device 302, an identifier representing the administrator 308, a public key or certificate for the one or more applications, any additional authentication data associated with the application or the user of the application, the one or more resources to be accessed, or the like.”), receive, at the first network function from the second network function, a response to the authentication request comprising a network address identifier ("NAI") for the second network function (i.e., …teaches in par. 0033 the following: “response back to trust relationship establishment mechanism 306 via trust relationship establishment mechanism 316 using the redirection URI provided by the trust relationship establishment mechanism 306.”); and send, from the first network function to the application entity, the response to the authentication request comprising the NAI for the second network function and the CCA token of the first network function for establishing a security association between the application entity and the second network function (i.e., …teaches in par. 0033 the following: “response back to trust relationship establishment mechanism 306 via trust relationship establishment mechanism 316 using the redirection URI provided by the trust relationship establishment mechanism 306.” …teaches in par. 0035 the following: “verifies that the redirection URI included with the access token request matches the redirection URI provided with the registration request. If trust relationship establishment mechanism 316 verifies that the redirection URI included with the access token request is the same as the redirection URI provided with the registration request, the trust relationship establishment mechanism 316 sends an access token back to trust relationship establishment mechanism 306 via trust relationship establishment mechanism 316. … the access token may be used by resource-side system to grant application side devices and users authorized access to resource side resources”). Chang does not expressly teach: the application entity having a trust relationship with the first network function and not the second network function. In this instance the examiner notes the teachings of prior art reference Tran. TRAN teaches in par. 0025 the following: “Each of the first application 108, second application 110 and third application 112 can perform authentication of the respective invocation request using the received token through the service registry 106.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teaching of Chang with the teachings of TRAN by having their system comprise an enhanced application security process. One would have been motivated to do so to provide a simple and effective means to configure application security, wherein the enhanced application security process helps to prevent unauthorized applications in the network and makes it easier to ensure network system security. The system of Chang and TRAN does not expressly teach: wherein the application entity is authenticated by the second network function in response to the second network function verifying that the CCA token, received by the second network function from the application entity, is associated with the first network function. In this instance the examiner notes the teachings of prior art reference CHOYI. With regards to applicant’s claim limitation element of, “wherein the application entity is authenticated by the second network function in response to the second network function verifying that the CCA token”, teaches in par. 0074 the following: “The credentials may be used both by the Devices as well as the Del 604 in order to mutually authenticate the messages sent between the Devices and the Del 604.”. With regards to applicant’s claim limitation element of, “received by the second network function from the application entity, is associated with the first network function”, teaches in par. 0047 the following: “The AF may have a trust relationship with the TEL The AF and the Dev_A may perform a security association by means of an authentication process (either directly or indirectly) by leveraging the trust relationships with the TEL An associated security context may be created that is shared between the Dev_A and the AF.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teaching of Chang and TRAN with the teachings of CHOYI by having their system comprise an enhanced security management process. One would have been motivated to do so to provide a simple and effective means to manage access control within a network, wherein the enhanced security management process helps to prevent unauthorized access within the network and makes it easier to ensure network access is controlled. As to claim 10, the system of Chang, Tran and CHOYI as applied to claim 9 above teaches trust relationship, specifically Chang teaches a NE of claim 9, wherein the at least one processor is configured to cause the NE to determine a first secret token at the first network function in response to a request to authenticate the application entity to the second network function that has a trust relationship with the first network function and does not have a trust relationship with the application entity (i.e., …teaches in par. 0033 the following: “response back to trust relationship establishment mechanism 306 via trust relationship establishment mechanism 316 using the redirection URI provided by the trust relationship establishment mechanism 306.” …teaches in par. 0035 the following: “verifies that the redirection URI included with the access token request matches the redirection URI provided with the registration request. If trust relationship establishment mechanism 316 verifies that the redirection URI included with the access token request is the same as the redirection URI provided with the registration request, the trust relationship establishment mechanism 316 sends an access token back to trust relationship establishment mechanism 306 via trust relationship establishment mechanism 316. … the access token may be used by resource-side system to grant application side devices and users authorized access to resource side resources”). As to claim 11, the system of Chang, Tran and CHOYI as applied to claim 10 above teaches trust relationship, specifically Chang teaches a NE of claim 10, wherein the authentication request further comprises the first secret token, an identifier for the first network function, and an application identifier for the application entity for verifying the authentication request and authenticating the application entity (i.e., …teaches in par. 0032 the following: “may include in the registration request one or more registration artifacts, such as a redirection uniform resource identifier (URI), a requested scope that identifies a role of the requesting one or more applications, a local state of device 302, an identifier representing the administrator 308, a public key or certificate for the one or more applications, any additional authentication data associated with the application or the user of the application, the one or more resources to be accessed, or the like.”). As to claim 12, Chang teaches a network equipment (NE) for wireless communication, comprising: at least one memory (i.e., …teaches in par. 0005 the following: “The system/apparatus may comprise one or more processors and a memory coupled to the one or more processors. The memory may comprise instructions which, when executed by the one or more processors, cause the one or more processors to perform various ones of, and combinations of, the operations outlined above with regard to the method illustrative embodiment”); and at least one processor coupled with the at least one memory and configured to cause the NE to (i.e., …teaches in par. 0005 the following: “The system/apparatus may comprise one or more processors and a memory coupled to the one or more processors. The memory may comprise instructions which, when executed by the one or more processors, cause the one or more processors to perform various ones of, and combinations of, the operations outlined above with regard to the method illustrative embodiment”): receive, at a first network function, an authentication request from an application entity device that does not have a trust relationship with the first network function (i.e., …teaches in par. 0032 the following: “… request via trust relationship establishment mechanism 306, trust relationship establishment mechanism 306 may send the registration request to trust relationship establishment mechanism 316 as an authorized registration request.” …teaches in par. 0033 the following: “Upon trust relationship establishment mechanism 316 receiving the registration request from trust relationship establishment mechanism 306, trust relationship establishment mechanism 316 validates that the registration request is a valid registration request from an associated trust relationship establishment mechanism.”.), the authentication request comprising a client credential assertion ("CCA") token of a second network function that has a trust relationship with the first network function and the application entity (i.e., …teaches in par. 0032 the following: “device 302 initiates a registration request to register the one or more applications with the one or more resources via a user interface (UI) to trust relationship establishment mechanism 306. Administrator 308 may include in the registration request one or more registration artifacts, such as a redirection uniform resource identifier (URI), a requested scope that identifies a role of the requesting one or more applications, a local state of device 302, an identifier representing the administrator 308, a public key or certificate for the one or more applications, any additional authentication data associated with the application or the user of the application, the one or more resources to be accessed, or the like”); send, from the first network function to the application entity, an authentication result in response to verifying the CCA token, the authentication result comprising a CCA token of the first network function for establishing a security association between the application entity and a third network function (i.e., …teaches in par. 0033 the following: “response back to trust relationship establishment mechanism 306 via trust relationship establishment mechanism 316 using the redirection URI provided by the trust relationship establishment mechanism 306.” …teaches in par. 0035 the following: “verifies that the redirection URI included with the access token request matches the redirection URI provided with the registration request. If trust relationship establishment mechanism 316 verifies that the redirection URI included with the access token request is the same as the redirection URI provided with the registration request, the trust relationship establishment mechanism 316 sends an access token back to trust relationship establishment mechanism 306 via trust relationship establishment mechanism 316. … the access token may be used by resource-side system to grant application side devices and users authorized access to resource side resources”). Chang does not expressly teach: verify, at the first network function, that the CCA token is associated with the second network function. In this instance the examiner notes the teachings of prior art reference Tran. TRAN teaches in par. 0023 the following: “The second application 110, authenticates the invocation request from the first application 108 using authentication token 126. The second application 110 authorizes the request because token 126 contains the initial token 124 that represents the user, showing that the first application 108 is acting on behalf of that user.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teaching of Chang with the teachings of TRAN by having their system comprise an enhanced application security process. One would have been motivated to do so to provide a simple and effective means to configure application security, wherein the enhanced application security process helps to prevent unauthorized applications in the network and makes it easier to ensure network system security. The system of Chang and TRAN does not expressly teach: wherein the application entity is authenticated by the third network function in response to the third network function verifying that the CCA token of the first network function, received by the third network function from the application entity, is associated with the first network function. In this instance the examiner notes the teachings of prior art reference CHOYI. With regards to applicant’s claim limitation element of, “wherein the application entity is authenticated by the third network function in response to the third network function verifying that the CCA token of the first network function”, teaches in par. 0074 the following: “The credentials may be used both by the Devices as well as the Del 604 in order to mutually authenticate the messages sent between the Devices and the Del 604.”. With regards to applicant’s claim limitation element of, “received by the third network function from the application entity, is associated with the first network function”, teaches in par. 0047 the following: “The AF may have a trust relationship with the TEL The AF and the Dev_A may perform a security association by means of an authentication process (either directly or indirectly) by leveraging the trust relationships with the TEL An associated security context may be created that is shared between the Dev_A and the AF.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to implement the teaching of Chang and TRAN with the teachings of CHOYI by having their system comprise an enhanced security management process. One would have been motivated to do so to provide a simple and effective means to manage access control within a network, wherein the enhanced security management process helps to prevent unauthorized access within the network and makes it easier to ensure network access is controlled. As to claim 13, the system of Chang, Tran and CHOYI as applied to claim 12 above teaches trust relationship, specifically Chang teaches a NE of claim 12, wherein the transceiver at least one processor is configured to cause the NE to receive, at the first network function, a first secret token in the authentication request and authenticating the application entity in response to the first secret token matching a first secret token that is previously-received from the second network function (i.e.,…teaches in par. 0035 the following: “access token request is validated, then trust relationship establishment mechanism 316 verifies that the redirection URI included with the access token request matches the redirection URI provided with the registration request.”). As to claim 14, the system of Chang, Tran and CHOYI as applied to claim 13 above teaches trust relationship, specifically Chang teaches a NE of claim 13, wherein the at least one processor is configured to cause the NE to: receive, at the first network function, an application identifier for the application entity in the authentication request (i.e., …teaches in par. 0034 the following: “The access token request includes the redirection URI, verifiable authentication data, as well as the symmetric key. Trust relationship establishment mechanism 306 then submits the access token request using the authorization code previously received from trust relationship establishment mechanism 316 and sends the access token request to trust relationship establishment mechanism 316.”), the application entity authenticated in response to the received application identifier matching an application identifier that is previously received from the second network function (i.e., …teaches in par. 0034 the following: “Further, by sending the access token request via trust relationship establishment mechanism 306, trust relationship establishment mechanism 306 may send the access token request to trust relationship establishment mechanism 316 as an authorized access token request. Those skilled in the art will recognize that trust relationship establishment mechanism 306 may use credential data sent to the trust relationship establishment mechanism 316 in a previous operation to create verifiable authentication data in the access token request.”); and in response to authenticating the application entity (i.e., …teaches in par. 0035 the following: “Upon trust relationship establishment mechanism 316 receiving the access token request from trust relationship establishment mechanism 306, trust relationship establishment mechanism 316 validates that the access token request is an authorized registration request from an associated trust relationship establishment mechanism by verifying the authorization code.”), send, from the first network function, the application identifier and an application entity identifier to the third network function for use in authenticating the application entity with the third network function (i.e., …teaches in par. 0035 the following: “The access token does not have an expiration time period and is signed with a token issuer public key. Those skilled in the art will recognize that a finite expiration time and a renewal token may be used to renew the access token in another embodiment.”). As to claim 15, the system of Chang, Tran and CHOYI as applied to claim 12 above teaches trust relationship, specifically Chang teaches a NE of any of claim 12, wherein the at least one processor is configured to cause the NE to: generate, at the first network function, a second secret token at the first network function, the second secret token sent to the third network function for use in authenticating the application entity with the third network function (i.e., …teaches in par. 0033 the following: “The symmetric key being a one-time use key that is generated per request and has an expiration time period.” …teaches in par. 0035 the following: “a renewal token may be used to renew the access token”.); send, from the first network function, the second secret token to the application entity for use in authenticating the application entity with the third network function (i.e., …teaches in par. 0034 the following: “generates an access token request to be sent to trust relationship establishment mechanism 306. The access token request includes the redirection URI, verifiable authentication data, as well as the symmetric key”. …teaches in par. 0035 the following: “a renewal token may be used to renew the access token”.). Allowable Subject Matter Claim 3 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: Applicant’s recital of, “send, from the application entity, a management message to the second network function using the NAI of the second network function, the second management message comprising an application entity identifier, an application identifier, and the CCA token of the first network function; and receive, from the second network function, a second secret token, an NAI of a third network function, and a CCA token associated with the second network function in response to the CCA token associated with the first network function being verified.”. Dependent claim 4 is allowed by way of its dependency on dependent claim 3. Dependent claim 5 is allowed by way of its dependency on dependent claim 3. Dependent claim 6 is allowed by way of its dependency on dependent claim 5. Claim 18 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: Applicant’s recital of, “send, from the application entity, a management message to the second network function using the NAI of the second network function, the management message comprising an application entity identifier, an application identifier, and the CCA token of the first network function; and receive, from the second network function, a second secret token, an NAI of a third network function, and a CCA token associated with the second network function in response to the CCA token associated with the first network function being verified”. Dependent claim 19 is allowed by way of its dependency on dependent claim 18. Dependent claim 20 is allowed by way of its dependency on dependent claim 18. Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRYAN F WRIGHT whose telephone number is (571)270-3826. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRYAN F WRIGHT/ Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Show 3 earlier events
Feb 25, 2026
Applicant Interview (Telephonic)
Mar 12, 2026
Response Filed
Jun 03, 2026
Final Rejection mailed — §103
Jul 29, 2026
Applicant Interview (Telephonic)
Aug 04, 2026
Response after Non-Final Action
Sep 02, 2026
Request for Continued Examination
Sep 07, 2026
Response after Non-Final Action
Sep 22, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744820
HIGHLY SCALABLE FOUR-DIMENSIONAL GEOSPATIAL DATA SYSTEM FOR SIMULATED WORLDS
2y 1m to grant Granted Sep 22, 2026
Patent 12719909
AUTOMATED VULNERABILITY AND THREAT LANDSCAPE ANALYSIS
3y 5m to grant Granted Aug 25, 2026
Patent 12712732
METHOD FOR AUTHENTICATION OF A SERVICE PROVIDER DEVICE TO A USER DEVICE
2y 9m to grant Granted Aug 18, 2026
Patent 12707015
IMAGE FORMING APPARATUS AND USER REGISTRATION METHOD FOR IMAGE FORMING APPARATUS
3y 2m to grant Granted Aug 11, 2026
Patent 12689613
Privileged remote access for Operational Technology (OT)/Internet of Things (IOT)/Industrial IOT (IIOT)/Industrial Control System (ICS)
4y 0m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+24.1%)
3y 2m (~5m remaining)
Median Time to Grant
High
PTA Risk
Based on 820 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month