DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office Action is in response to the Amendment filed on 02/06/2026.
In the instant Amendment, claims 1, 10, and 17 have been amended; and claims 1, 9, and 17 are independent claims. Claims 1-20 have been examined and are pending. This Action is made Final
Response to Arguments
In light of Applicant’s amendments, 112 (b) and 101 have been withdrawn.
Applicants’ arguments filed on 02/06/2026 with respect to claims 1, 10, and 17 have been considered but are moot in view of the new ground(s) of rejection, which were necessitated by amendment.
The rejection under 35 U.S.C. 112(a) is maintained. The specification does not adequately describe the specifically claimed NEF/UDF/UDM-based workflow, although the specification generally states that signatures or biometric characteristics may be identified and compared, it does not sufficiently teach how the claimed acoustic-signature matching or network-configuration matching is actually performed across the full scope of the claim, including the extraction, representation, comparison, and matching criteria for the claimed signatures/configurations. According to MPEP 2161.01, it is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015). Applicant’s reliance on paragraphs [0054]-[0055] is not persuasive. Those paragraphs state that a token authentication system can identify a biometric characteristic in a first token and detect the same biometric characteristic in a second token. However, the claim specifically requires determining whether a first acoustic signature comprising a first waveform matches a second acoustic signature comprising a second waveform. The cited disclosure does not explain how the acoustic signature is extracted, how the waveform is analyzed, what constitutes the biometric characteristic, or what comparison technique or threshold is used to determine a match. Therefore, the disclosure does not enable the full scope of the claimed acoustic-signature matching without undue experimentation, and also does not clearly convey possession of the specifically claimed waveform-based matching.
Applicant's arguments filed 02/06/2026 with respect to the 35 USC 101 rejection have been fully considered but they are not persuasive.
The limitations in the claims under its broadest reasonable interpretation covers performance of the limitations being an abstract idea directed to mental process and/or mathematical concepts. The steps can be performed by a human in the mind by using pencil and paper but for the recitation of generic computing such as generic computer. The amendment has failed to preclude the limitations recited in the claims from being performed manually by a human via a mental process or by a human using pencil and paper.
The amended 5G elements do not integrate the abstract idea into a practical application or add significantly more. The claimed efficient computing by applying the abstract idea on a computer does not integrate the judicial exception into a practical application or provide inventive concepts (see MPEP 2106.05(f)).
Although Applicant contends that the claim improves the accuracy of authenticity determination by leveraging network-connection information associated with a token/user, the alleged benefit is, at most, an improvement to the abstract idea of determining authenticity, not an improvement to the functioning of a computer or to another technology or technical field. The claim merely uses generic 5G network components (e.g., core network node, NEF, UDM/UDF, mobile devices) to receive data, store/retrieve data, compare voice and network-configuration information, and transmit a yes/no result. The claim does not recite a specific technical mechanism that changes how the network operates or how the recited components function. Instead, the claim is directed to a result-focused determination of whether the same user generated two data sets. Such result-oriented language, including “to determine whether the user generated” the data, does not recite how the purported improvement is technically achieved and therefore does not integrate the abstract idea into a practical application.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 1-9 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Claims 1-3 and 6 are rejected under 35 U.S.C. 112(a) for lack of written description because the specification fails to reasonably convey to a person of ordinary skill in the art that the inventor had possession of an NEF configured to perform the recited determinations—namely, (i) determining whether a first acoustic signature of first voice data matches a second acoustic signature of second voice data, and (ii) determining whether a first network configuration matches a second network configuration. The disclosure describes the NEF as a 5G interface for secure communication and API access, it does not describe that the NEF performs or is configured to perform data analysis. The only described operation of the NEF involve mediating access between the network and external databases/APIs, and it does not disclose any algorithm, processing steps, models, data structures, or identification of external services invoked by the NEF to carry out acoustic-signature matching or network-configuration comparison. The specification attributes analytical and comparison logic to a separate “token authentication system”, not to the NEF. The specification therefore presents only results to be achieved, without describing how the NEF performs the claimed functions, which is insufficient to demonstrate possession of the claimed invention as of the filing date. See Ariad Pharm., Inc. v. Eli Lilly & Co., 598 F.3d 1336, 1351–52 (Fed. Cir. 2010) (en banc); MPEP § 2163; Lockwood v. American Airlines, Inc., 107 F.3d 1565, 1572 (Fed. Cir. 1997).
Claims 4-5, and 7-9 are based on rejected claims 1-3, and 6 and are rejected based on their dependency of these claims and for not overcoming the ground of rejection applied to the parent claims.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, and 6-9 are rejected under 35 U.S.C. 103 as being unpatentable over Bykampadi et al. (US Pub. App. No. 2022/0353255 A1; Hereinafter “Bykampadi”) in view of Skerpac et al. (US Pub. App. No. 20130132091 A1; Hereinafter “Skerpac”) and Park et al. (US Pub. App. No. 2016/0080263 A1; Hereinafter “Park”).
As per claim 1, Bykampadi teaches a fifth generation (5G) telecommunication system comprising (Bykampadi: para [29], fig. 1, “FIG. 1 depicts a non-roaming reference architecture of a 5G system”):
A core network node comprising: at least one hardware processor; and at least one non-transitory memory storing instructions, which, when executed by the at least one hardware processor, cause the core network node of the 5G telecommunication system to (Bykampadi: para [17-19], fig. 1, “This specification also describes computer-readable instructions, optionally stored on a non-transitory computer-readable memory medium, which, when executed by computing apparatus, causes performance of a method according to any one of the first to fourth aspects…FIG. 1 is an example of a telecommunications network system architecture”):
receive, at the core network node from a first mobile device of a user, first data associated with the user (Bykampadi: para [89-94], “In operation S2.6, the first instance of the NF service consumer 22 may share the received access token with the other instances in the set of which the first instance is a member. In this way, the other instances of the NF service consumer, including the second instance of the NF service consumer 26, can access and make use of the access token… the NF service producer 24 may have previously received the NF set identifier for the first instance of the NF service consumer 22….the NF service consumer 22 and the NF service producer 24 have previously established a connection e.g. a mutually authenticated TLS connection such 3o as may be used in intra-PLMN scenarios”);
store, at the core network node via a network exposure function (NEF), the first data and the first network configuration (Bykampadi: para[69-95], fig. 2-3, “The access token may be stored as context data, for instance, using an unstructured data storage function (UDSF), the context data being accessible to all instances of the NF service consumer in the set. As will be appreciated, the sharing of the access token is not limited to UDSF. Instead, the access token may be shared with the other NF consumer instances in the set in any suitable way, for instance via one or more messages passed between the NF consumer instances.”)
obtain, at the core network node from a second mobile device, second data and a second network configuration associated with the second data (Bykampadi: para[63-101], fig. 2A, “the second instance of the NF service consumer 26 may send a request for the service to the NF service producer 24. Similarly to the request sent by the first instance of the NF service consumer 22 in operation S2.7, the service request includes the access token. The service request may additionally include the NF set identifier for the second instance of the NF service consumer 26. In addition or alternatively, the service request may include the identifier of the instance of the NF service consumer 26, which sends the service request.”);
determine, at the core network node, by retrieving the first network configuration via the NEF at the core network node, whether the first network configuration matches the second network configuration to determine whether the user generated the first voice data and the second voice data ( Bykampadi teaches validation of access tokens by an NF service producer through NEF-exposed interfaces, i.e. determination via the NEF, where ‘via’ is understood broadly to mean by way of or using the NEF as the communication and policy-control conduit.”, para[94-105], fig. 2, “In operation S2.12, the NF service producer 24 validates the received access token. This may be similar to operation S2.8.”, para[94], “In operation S2.8, the NF service producer 24 validates the received access token….validation may comprise the NF service producer 24 determining whether the previously-received NF set identifier corresponds with or matches the NF set identifier which is present in the access token”, “validation of the access token may additionally consider other information elements which are included in the access token. For instance, it may include determining, based on the duration for which the access token is valid, that the access token has not expired. Also, it may include determining based on information included in the access token (e.g. the NF Instance identifier of the specific NF service producer 24 to which the access token relates and/or the NF service name(s) for which the access token is authorised for use) that the access token authorises access to a service that is provided by the NF service producer 24…..If the access token is not successfully validated, access to the service is denied. However, if the access token is successfully validated, the service is provided to the second instance of the NF service consumer 26 as illustrated in operation S2.13” the examiner would like to be noted that the “to determine whether the user…” is a result oriented statement of purpose or use that does not add meaningful technical steps beyond the already recited comparison operations);
Bykampadi does not explicitly teach voice-based data, nor does it disclose determining whether acoustic signatures of voice data match.
However, in the related art, Skerpac teaches voice data (Skerpac: para[178], “he 2012 Rutgers Speaker Verification Report shows a series of verification performance numbers for voice biometric models constructed from different types of voice data from the various channels and sessions as well as variations in the amount of speech used to train the model for enrollment and various numbers of phrases used for verification. For biometric assurance purposes, the BCM provides the transparency security managers require for a speaker biometric system that utilizes different types of voice data across biometric enrollment sessions and enrolls a wide variety of users.”);
extract a first network configuration for the user (Skerpac: para[156-159], fig. 1, “The DPSS security controller (1000) and request manager (1060) check that the user exists and that the required user profiles (11070) and security policies (1040) are known. A sub-session is created by the session manager (1080) to manage one challenge/response round trip associated with the generated one-time pass phrase.”, “A session can comprise of the generation and verification of multiple pass phrases depending on the authentication requirements of the application and user. Each new pass phrase challenge is associated with a distinct randomly generated sub-session (SubID) within the session with its own time-out parameter. This is the unique identifier for the one-time pass phrase. Pre-established security policies (1040) and customer application and user preferences determine the rules (1050) under which the session will operate (i.e., number of prompts, language set, audio requirements, etc).” );
determine, by retrieving the first voice data, whether a first acoustic signature, comprising a first waveform, of the first voice data matches a second acoustic signature, comprising a second waveform, of the second voice data (Skerpac: para [105], [158-161], [120], “the authentication process obtains quality speech input, performs high quality secure signal processing and creates the representative digital forms of both the voice information used for speaker recognition and voice information used for speech recognition for each phrase. In one embodiment, the input information is processed in memory at the remote or local unit, combined into one date and time stamped record, encrypted and, optionally, digitally signed prior to communication with the controller assuming the controller is resident on another machine. The controller verifies the optional signature and decrypts the information in memory and matches against information stored in the n-dimensional database. Authentication is considered successful if both matching results are successful”);
in response to determining that the first acoustic signature matches the second acoustic signature and determining that the first network configuration matches the second network configuration, transmit, to the second mobile device from the core network node, an indication that the second voice data corresponds to the user (Skerpac: para[22-59], [105], [108], [164], “Authentication is considered successful if both matching results are successful”, para[152] “Master audio tokens are also effective in detecting playback attacks since a `negative biometric` technique (which does not allow the master voice to pass speaker verification test successfully) can indicate that an attacker has tried to automate the return of the audio token as input to authentication (i.e. not live voice of an authentic or imposter user).”, “sending an authentication passed result to said given customer application if said session authentication flag is positive, sending authentication failed result to said given customer application if said session authentication flag is false.”); and
in response to determining that either the first acoustic signature does not match the second acoustic signature or that the first network configuration does not match the second network configuration, transmit, from the core network node to the second mobile device, an indication that the second voice data does not correspond to the user (Skerpac: para[22-59], [105], [108], [164], “Authentication is considered successful if both matching results are successful”, para[152] “Master audio tokens are also effective in detecting playback attacks since a `negative biometric` technique (which does not allow the master voice to pass speaker verification test successfully) can indicate that an attacker has tried to automate the return of the audio token as input to authentication (i.e. not live voice of an authentic or imposter user).”, “sending an authentication passed result to said given customer application if said session authentication flag is positive, sending authentication failed result to said given customer application if said session authentication flag is false.”).
A person of ordinary skill in the art, before the effective filing data of the invention, seeking to improve authentication integrity in a 5G service-based network, would have found it obvious to incorporate Skerpac’s voice-token verification process into Bykampadi’s NEF/UDF-based token authorization system as both address credential validation and user authentication. Using biometric voice tokens within the 5G token-exchange framework would have been a predictable way to enhance spoof-resistance while maintaining standard service authorization while verifying a user’s identity (Skerpac, para. [17]).
Bykampadi in view of Skerpac does not teach wherein the first network configuration includes a first ordered list of network components associated with a connection with the first mobile device, and wherein the second network configuration includes a second ordered list of network components.
However, in the related art, Park teaches wherein the first network configuration includes a first ordered list of network components associated with a connection with the first mobile device, and wherein the second network configuration includes a second ordered list of network component (Park: fig. 4, 6, para[60-70], “The network function table 194 may store and manage a set of NF list entries for each service used by a user. That is, a network function order the NF list may be fixed or may be dynamically changed with reference to a topology state or a traffic processing state. The determination of NF list of NF functions for each service and each user may be made according to service level agreement between a service provider and the user. The network function table 194 may further include a default NF list entry that is not associated with the service table 192 and the user table 193. The default NF list entry may be preferably a list of essential NFs of the SDN network that process the received packet.” It teaches a set of NF list entries, not just for one but for services used by users. ).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing data of the invention, to update the modify Bykampadi and represent the network configuration associated with a device connection as an ordered list of network functions, as taught by Park in order to manage packet paths on a per-user and per-service basis and to account for topology state and traffic processing state when determining the path through the network (park: para [02]).
As per claim 2, Bykampadi in view of Skerpac and Park teaches the independent claim 1. Skerpac teaches wherein the instructions for determining that the first acoustic signature matches the second acoustic signature cause the 5G telecommunication system to: determine the first acoustic signature associated with a first speaker of the first voice data; determine the second acoustic signature associated with a second speaker of the second voice data; and determine, based on a match between the first acoustic signature and the second acoustic signature, that the second voice data is associated with the user (Skerpac: para [22-59], “verifying if a set of extracted speech recognition features are representative of the random pass phrase using said speech recognition language and acoustic models……matching a set of extracted speaker recognition features of said concatenated audio to a registered speaker biometric model of a registered user; [0058] setting a biometric match flag on if the previous step is positive; setting a session authentication flag to positive if the minimum number of phrases flag is on and the biometric match flag is on; and [0059] sending an authentication passed result to said given customer application if said session authentication flag is positive, sending authentication failed result to said given customer application if said session authentication flag is false.”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to combine the token authentication system of Bykampadi with the verification of spoken one-time pass phrases of Skerpac, it will prevents spoofing while verifying a user's identity (Skerpac: para [17]).
As per claim 6, Bykampadi in view of Skerpac and Park teaches the independent claim 1. Skerpac teaches wherein the instructions cause the 5G telecommunication system to, in response to determining that either the first acoustic signature does not match the second acoustic signature or that the first network configuration does not match the second network configuration, terminate a connection to a third mobile device associated with the second voice data (Skerpac: para[105], “the authentication process obtains quality speech input, performs high quality secure signal processing and creates the representative digital forms of both the voice information used for speaker recognition and voice information used for speech recognition for each phrase. In one embodiment, the input information is processed in memory at the remote or local unit, combined into one date and time stamped record, encrypted and, optionally, digitally signed prior to communication with the controller assuming the controller is resident on another machine. The controller verifies the optional signature and decrypts the information in memory and matches against information stored in the n-dimensional database. Authentication is considered successful if both matching results are successful..”).
A person of ordinary skill in the art, before the effective filing data of the invention, seeking to improve authentication integrity in a 5G service-based network, would have found it obvious to incorporate Skerpac’s voice-token verification process into Bykampadi’s NEF/UDF-based token authorization system as both address credential validation and user authentication. Using biometric voice tokens within the 5G token-exchange framework would have been a predictable way to enhance spoof-resistance while maintaining standard service authorization while verifying a user’s identity (Skerpac, para. [17]).
As per claim 7, Bykampadi in view of Skerpac and Park teaches the independent claim 1. Skerpac teaches wherein the first voice data is associated with an image, a three-dimensional model, an audio recording, a digital avatar, or a voice recording (Skerpac: para[170], “A unique automation method to capture, record, and process this enrollment data across channels and sessions is an embodiment of this invention. Representative speech features are obtained from the recordings. Any text independent speaker recognition enrollment and subsequent verification methodology can be utilized by the Audio Collection and Enrollment System (ACES).”).
A person of ordinary skill in the art, before the effective filing data of the invention, seeking to improve authentication integrity in a 5G service-based network, would have found it obvious to incorporate Skerpac’s voice-token verification process into Bykampadi’s NEF/UDF-based token authorization system as both address credential validation and user authentication. Using biometric voice tokens within the 5G token-exchange framework would have been a predictable way to enhance spoof-resistance while maintaining standard service authorization while verifying a user’s identity (Skerpac, para. [17]).
As per claim 8, Bykampadi in view of Skerpac and Park teaches the independent claim 1. Bykampadi teaches wherein the first network configuration comprises a device identifier, biometric data including a retina scan, or user credentials (Bykampadi: para [91-95], “This may include determining whether the identifier of the set of network function service consumers (the NF set identifier) included in the access token corresponds with or matches an identifier of a set of network function service consumers of which the first instance of the NF service consumer is a member… lso, it may include determining based on information included in the access token (e.g. the NF Instance identifier of the specific NF service producer 24 to which the access token relates and/or the NF service name(s) for which the access token is authorised for use) that the access token authorises access to a service that is provided by the NF service producer 24.”).
As per claims 9, Bykampadi in view of Skerpac and Park teaches the independent claim 1. Bykampadi teaches wherein the first network configuration includes an indication of a communication path between a node associated with the 5G telecommunication system and the first mobile device (Bykampadi: para[65-66], fig. 2A, “In the context of a 5G network, the access token request may be sent via the service-based interface exhibited by the NRF (referred to as Nnrf)….The access token request may additionally include one or any combination of the following information elements: [0067] an NF instance identifier of the requesting first instance of the NF service consumer 22; [0068] an indication of an NF type of the requesting first instance of the NF service consumer 22; [0069] an indication of an NF type of the NF service producer 24; [0070] an indication of the NF service name(s) of the NF service producer 24; [0071] an NF Instance identifier of the specific NF service producer 24 for which the access token is requested; [0072] a PLMN identifier of the requesting first instance of the NF service consumer 22; and [0073] a PLMN identifier of the NF service producer 24.”).
Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over Bykampadi et al. (US Pub. # 2022/0353255 A1; Hereinafter “Bykampadi”) in view of Skerpac et al. (US Pub. # 20130132091 A1; Hereinafter “Skerpac”), Park et al. (US Pub. App. No. 2016/0080263 A1; Hereinafter “Park”) and Garner et al. (US Pat. # 10979423 B1; Hereinafter “Garner”).
As per claim 3, Bykampadi in view of Skerpac and Park teaches the independent claim 1.
Bykampadi in view of Skerpac and Park does not teach segment the first voice data to generate a first voice segment; segment the second voice data to generate a second voice segment; and determine, in response to determining that the first voice segment matches the second voice segment, that the second voice data is associated with the user.
However, in the related art, Garner teaches segment the first voice data to generate a first voice segment; segment the second voice data to generate a second voice segment (Garner: fig. 3, col. 8, line 15-55, “A user may request secured information from a voice-enabled service of a device. A first audio segment may be transmitted to the device (e.g., at operation 305). A second audio segment describing the first audio segment may be received from the device (e.g., at operation 310). Features may be extracted from the second audio segment (e.g., at operation 315). The features may include text extracted from the second audio segment by a natural language processor, voice characteristics of a voice included in the second audio segment (e.g., tone, amplitude, timbre, etc.), sounds identified in the second audio segment, etc. The extracted features may be compared to elements of a stored description of the first audio segment (e.g., at operation 320). The stored description may be included in a profile of the user and may include text, voice characteristics of a voice used to create the stored description, sounds identified in the stored description, etc. If the features extracted from the second audio segment do no match the elements of the stored description of the first audio segment, authentication of the user may be denied (e.g., at operation 330); and
determine, in response to determining that the first voice segment matches the second voice segment, that the second voice data is associated with the user (Garner: fig. 3, col. 8, line 15-55, “If the features extracted from the second audio segment do no match the elements of the stored description of the first audio segment, an authentication token generated from the first audio segment and the stored description may be validated (e.g., at operation 335). For example, it may be determined that a threshold number of elements extracted from the second audio segment match elements of the stored description. The authentication token may then be authenticated as corresponding to the user providing the second audio segment. The device of the user may be authenticated using the token (e.g., at operation 340). For example, the device may have captured and transmitted the second audio segment and may be authorized for output of the secured data using the authentication token based on the features extracted from the second audio segment matching the elements of the stored audio description.”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to combine the modified token authentication system of Bykampadi with the Garner, it will protect the user from hacking (Garner: col. 2)
Claims 4-5 are rejected under 35 U.S.C. 103 as being unpatentable over Bykampadi et al. (US Pub. # 2022/0353255 A1; Hereinafter “Bykampadi”) in view of Skerpac et al. (US Pub. # 20130132091 A1; Hereinafter “Skerpac”), Park et al. (US Pub. App. No. 2016/0080263 A1; Hereinafter “Park”), and Ben Hen et al. (WO 2019/011751 A1; Hereinafter “Ben Hen”).
As per claim 4, Bykampadi in view of Skerpac and Park teaches the independent claim 1.
Bykampadi in view of Skerpac and Park does not teach wherein the instructions for determining that the first network configuration matches the second network configuration cause the 5G telecommunication system to: determine, based on the first network configuration, a first communication path for the first mobile device; query the UDF for communication path information for a third mobile device associated with the second network configuration, wherein the communication path information is associated with an access and mobility management function (AMF); in response to the query for communication path information, receive an indication of a second communication path between a node associated with the 5G telecommunication system and the third mobile device, in response to the query for communication path information, receive an indication of a second communication path between a node associated with the 5G telecommunication system and the third mobile device.
However, in the related art, Ben Hen teaches wherein the instructions for determining that the first network configuration matches the second network configuration cause the 5G telecommunication system to: determine, based on the first network configuration, a first communication path for the first mobile device (Ben Hen: fig. 4 step 401-402, “The terminal device 400 sends a registration request to the SEAF/AMF. The registration request comprises a subscription identifier, such as an IMSI. In case this is an initial registration then the identifier is the permanent subscription identifier. In case the terminal device 400 has already registered to the visiting network 300, then the identifier is a temporary identifier. S402: The SEAF/AMF initiates the authentication procedure by sending an authentication request to the AUSF in the home network 200. The authentication request comprises the permanent subscription identifier of the terminal device 400.”);
query the UDF for communication path information for a third mobile device associated with the second network configuration, wherein the communication path information is associated with an access and mobility management function (AMF) (Ben Hen: step 403-405], “The AUSF retrieves authentication information from the UDM. In case the chosen authentication procedure is AKA based, then in addition to the authentication information (AVs), the AUSF retrieves a token from the UDM.S404: The AUSF performs an authentication procedure with the terminal device 400 through the SEAF/AMF using EAP-AKA' or EPS-AKA*, potentially based on the authentication information received from the UDM.”, “The token could be bound to the visiting network 300. More precisely, a visiting network 300 identifier could be used in the computation of the l8 integrity protection tag. That is, according to an embodiment the token is bound to the visiting network 300.”);
in response to the query for communication path information, receive an indication of a second communication path between a node associated with the 5G telecommunication system and the third mobile device (Ben Hen: step 405-408, “Any further interaction with the visiting network 300 involving the UDM could be based on the scheme defined by steps S4o6a, S406b, S406C, where the source node/function/entity/device in the visiting network 300 includes the token in any message or request to the UDM in the home network 200. A successful verification of the token in UDM when presented from a different AMF to which UDM originally provided the token to, an SMF or an SMSF, gives the same level of assurance to the home network 200. As above, in case of failure, the home network 200 could take further actions, e.g. require re-authentication.” ); and
compare the first communication path and the second communication path to determine that the first network configuration matches the second network configuration (Ben Hen: step 405-408, “A successful verification indicates that the visiting network 300 is genuine and that the terminal device 400 for which the token was issued in step S403 was successfully authenticated and is being served by this visiting network 300.” ).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to combine the modified token authentication system of Ben Hen with the Garner, it will prevent entities, nodes, devices, or functions outside the visiting network 300 to access terminal device specific data and functions (Ben Hen, page 2)
As per claim 5 , Bykampadi in view of Skerpac and Park teaches the independent claim 1.
Bykampadi in view of Skerpac Park does not teach, however, Ben Hen teaches determine a first user subscription identifier associated with the first network configuration; query the UDF to determine a second user subscription identifier associated with the second network configuration; and compare the first user subscription identifier with the second user subscription identifier to determine whether the first network configuration matches the second network configuration (Ben Hen: fig. 5, step 401-408 “The registration request comprises a subscription identifier, such as an IMSI. In case this is an initial registration then the identifier is the permanent subscription identifier. In case the terminal device 400 has already registered to the visiting network 300, then the identifier is a temporary identifier. S402: The SEAF/AMF initiates the authentication procedure by sending an authentication request to the AUSF in the home network 200. The authentication request comprises the permanent subscription identifier of the terminal device 400. S403: The AUSF retrieves authentication information from the UDM. In case the chosen authentication procedure is AKA based, then in addition to the authentication information (AVs), the AUSF retrieves a token from the UDM..”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to combine the modified token authentication system of Ben Hen with the Garner, it will prevent entities, nodes, devices, or functions outside the visiting network 300 to access terminal device specific data and functions (Ben Hen, page 2).
Claims 10, 13, 15-17, 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Bykampadi et al. (US Pub. # 2022/0353255 A1; Hereinafter “Bykampadi”) in view of Ciarniello et al. (US Pub. # 20160127902 A1; Hereinafter “Ciarniello”) and Park et al. (US Pub. App. No. 2016/0080263 A1; Hereinafter “Park”).
As per claims 10 and 17, Bykampadi teaches a non-transitory, computer-readable storage medium comprising instructions recorded thereon, wherein the instructions, when executed by at least one data processor of a telecommunication system, cause the telecommunication system to (Bykampadi: para [17-19], fig. 1, “This specification also describes computer-readable instructions, optionally stored on a non-transitory computer-readable memory medium, which, when executed by computing apparatus, causes performance of a method according to any one of the first to fourth aspects…FIG. 1 is an example of a telecommunications network system architecture”):
receive, from a first user device of a user, a first token associated with the user (Bykampadi: para [89-94], “In operation S2.6, the first instance of the NF service consumer 22 may share the received access token with the other instances in the set of which the first instance is a member. In this way, the other instances of the NF service consumer, including the second instance of the NF service consumer 26, can access and make use of the access token… the NF service producer 24 may have previously received the NF set identifier for the first instance of the NF service consumer 22….the NF service consumer 22 and the NF service producer 24 have previously established a connection e.g. a mutually authenticated TLS connection such 3o as may be used in intra-PLMN scenarios”);
store, via a network exposure function (NEF), the first token and the first profile information (Bykampadi: para[69-89], fig. 2-3, “The access token may be stored as context data, for instance, using an unstructured data storage function (UDSF), the context data being accessible to all instances of the NF service consumer in the set. As will be appreciated, the sharing of the access token is not limited to UDSF. Instead, the access token may be shared with the other NF consumer instances in the set in any suitable way, for instance via one or more messages passed between the NF consumer instances.”)
obtain, from a second user device, a second token and second profile information associated with the second token (Bykampadi: para[63-101], fig. 2A, “the second instance of the NF service consumer 26 may send a request for the service to the NF service producer 24. Similarly to the request sent by the first instance of the NF service consumer 22 in operation S2.7, the service request includes the access token. The service request may additionally include the NF set identifier for the second instance of the NF service consumer 26. In addition or alternatively, the service request may include the identifier of the instance of the NF service consumer 26, which sends the service request.”);
determine, by retrieving the first token via the NEF, whether the first token matches the second token (Bykampadi teaches validation of access tokens by an NF service producer through NEF-exposed interfaces, i.e. determination via the NEF, where ‘via’ is understood broadly to mean by way of or using the NEF as the communication and policy-control conduit.”, para[94-105], fig. 2, “In operation S2.12, the NF service producer 24 validates the received access token. This may be similar to operation S2.8.”, para[94], “In operation S2.8, the NF service producer 24 validates the received access token….validation may comprise the NF service producer 24 determining whether the previously-received NF set identifier corresponds with or matches the NF set identifier which is present in the access token. This may occur for instance when the NF service consumer 22 and the NF service producer 24 have previously established a connection e.g. a mutually authenticated TLS connection such 3o as may be used in intra-PLMN scenarios’”);
determine at the core network node, by retrieving the first profile information via the NEF, whether the first profile information matches the second profile information to determine whether the user generated the first token and the second token (Bykampadi: para[95-105], fig. 2, “validation of the access token may additionally consider other information elements which are included in the access token. For instance, it may include determining, based on the duration for which the access token is valid, that the access token has not expired. Also, it may include determining based on information included in the access token (e.g. the NF Instance identifier of the specific NF service producer 24 to which the access token relates and/or the NF service name(s) for which the access token is authorised for use) that the access token authorises access to a service that is provided by the NF service producer 24” the examiner would like to be noted that the “to determine whether the user…” is a result oriented statement of purpose or use that does not add meaningful technical steps beyond the already recited comparison operations);
in response to determining that the first token matches the second token and determining that the first profile information matches the second profile information, transmit, to the second user device, a token authentication message (Bykampadi: para[104-107], fig. 2, “If the access token is not successfully validated, access to the service is denied. However, if the access token is successfully validated, the service is provided to the second instance of the NF service consumer 26 as illustrated in operation S2.13.”); and
in response to determining that either the first token does not match the second token or that the first profile information does not match the second profile information, transmit, to the second user device, an authentication failure message (Bykampadi: para[104-107], fig. 2, “If the access token is not successfully validated, access to the service is denied. However, if the access token is successfully validated, the service is provided to the second instance of the NF service consumer 26 as illustrated in operation S2.13.”).
Bykampadi does not explicitly teach that the first profile information for the user is extracted from a unified data function.
However, in the related art, Ciarniello teaches extract, from a unified data function (UDF), first profile information for the user (Ciarniello: para[69-89], fig. 2-3, “Then, in the next, fourth phase (data processing phase 325) the authentication hub 220 extracts, decodes and stores (e.g., in a memory not shown) the token 245 contained in the received message 250 or in the data packet 251, retrieves and stores the user univocal identifier (e.g., the MSISDN) obtained by the SMSC 212 from the high-security, SIM-authenticated message link 235 through which the message 250 comprising the token 245 has been received or obtained by the network authentication function 213 which is able to retrieve the user univocal identifier used to establish the highly-secure data link 236 through which the message 251 comprising the token 245 has been received, and associates the same with the received token 245…. the authentication hub 220 extracts from the received message 250 the generation timestamp from the token 245 and, from the additional information 255 contained in the received message 250, the validity time, and possibly other pieces of the additional information 255, some of which, like the general information on the communication device 120, can be stored for statistical analysis.”, “stores the user univocal identifier (e.g., the MSISDN)…., and associates the same with the received token 245. In this way, the authentication hub 220 is able to securely and unambiguously determine the user who sent the token 245. The token 245 is deemed to be unique; should however the authentication hub 220 receive another token with the same value randomly generated by another devices it will discard it and not consider it valid for any authentication”);
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to have combine Bykampadi and extract the profile information from an external database as discussed in Ciarniello, it will enhance the security of the authentication process by ensuring that the data comes from a trusted system (Ciarniello: para [104]).
Bykampadi in view of Ciarniello does not teach wherein the first profile information includes a first ordered list of network components associated with a connection with the first mobile device, and wherein the second profile information includes a second ordered list of network components.
However, in the related art, Park teaches wherein the first profile information includes a first ordered list of network components associated with a connection with the first mobile device, and wherein the second profile information includes a second ordered list of network component (Park: fig. 4, 6, para[60-70], “The network function table 194 may store and manage a set of NF list entries for each service used by a user. That is, a network function order the NF list may be fixed or may be dynamically changed with reference to a topology state or a traffic processing state. The determination of NF list of NF functions for each service and each user may be made according to service level agreement between a service provider and the user. The network function table 194 may further include a default NF list entry that is not associated with the service table 192 and the user table 193. The default NF list entry may be preferably a list of essential NFs of the SDN network that process the received packet.” It teaches a set of NF list entries, not just for one but for services used by users. ).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing data of the invention, to update the modify Bykampadi and represent the network configuration associated with a device connection as an ordered list of network functions, as taught by Park in order to manage packet paths on a per-user and per-service basis and to account for topology state and traffic processing state when determining the path through the network (Park: para [02]).
As per claim 13, Bykampadi in view of Ciarniello and Park teaches claim 1, Ciarniello teaches wherein the instructions for determining whether the first network configuration matches the second network configuration cause the 5G telecommunication system to: determine a first user subscription identifier associated with the first network configuration (Ciarniello: para[07], [71-88], “The MSISDN is a univocal code, known to the user, associated with a user subscription and with a user's SIM (Subscriber Identity Module).” “retrieves and stores the user univocal identifier (e.g., the MSISDN) obtained by the SMSC 212 from the high-security, SIM-authenticated message link 235 through which the message 250 comprising the token 245 has been received or obtained by the network authentication function 213 which is able to retrieve the user univocal identifier used to establish the highly-secure data link 236 through which the message 251 comprising the token 245 has been received, and associates the same with the received token 245.”);
query the UDF to determine a second user subscription identifier associated with the second network configuration; and compare the first user subscription identifier with the second user subscription identifier to determine whether the first network configuration matches the second network configuration (Ciarniello: para[84-98], “The authentication hub 220 performs an analysis phase (second phase 345 of the execution sequence) on the information comprised in the authentication request message 265. The authentication hub 220 firstly verifies if the service platform 115 indicated by the identifier comprised in the authentication request is qualified to apply for authentication requests to the authentication hub 220. In the negative case, the authentication request is rejected and a notification of such rejection may be sent to the provider-side authentication app 225.”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to have combine Bykampadi and extract the profile information from an external database as discussed in Ciarniello, it will enhance the security of the authentication process by ensuring that the data comes from a trusted system (Ciarniello: para [104]).
As per claims 15 and 19, Bykampadi in view of Ciarniello and Park teaches the independent claim 1. Bykampadi teaches wherein the first network configuration comprises a device identifier, biometric data including a retina scan, or user credentials (Bykampadi: para [91-95], “This may include determining whether the identifier of the set of network function service consumers (the NF set identifier) included in the access token corresponds with or matches an identifier of a set of network function service consumers of which the first instance of the NF service consumer is a member… lso, it may include determining based on information included in the access token (e.g. the NF Instance identifier of the specific NF service producer 24 to which the access token relates and/or the NF service name(s) for which the access token is authorised for use) that the access token authorises access to a service that is provided by the NF service producer 24.”).
As per claims 16, and 20, Bykampadi in view of Ciarniello and Park teaches the independent claim 1. Bykampadi teaches wherein the first network configuration includes an indication of a communication path between a node associated with the 5G telecommunication system and the first mobile device (Bykampadi: para[65-66], fig. 2A, “In the context of a 5G network, the access token request may be sent via the service-based interface exhibited by the NRF (referred to as Nnrf)….The access token request may additionally include one or any combination of the following information elements: [0067] an NF instance identifier of the requesting first instance of the NF service consumer 22; [0068] an indication of an NF type of the requesting first instance of the NF service consumer 22; [0069] an indication of an NF type of the NF service producer 24; [0070] an indication of the NF service name(s) of the NF service producer 24; [0071] an NF Instance identifier of the specific NF service producer 24 for which the access token is requested; [0072] a PLMN identifier of the requesting first instance of the NF service consumer 22; and [0073] a PLMN identifier of the NF service producer 24.”).
Claims 11, 14 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Bykampadi et al. (US Pub. # 2022/0353255 A1; Hereinafter “Bykampadi”) in view of Ciarniello et al. (US Pub. # 20160127902 A1; Hereinafter “Ciarniello”), Skerpac et al. (US 20130132091; Hereinafter “Skerpac”) and Park et al. (US Pub. App. No. 2016/0080263 A1; Hereinafter “Park”).
As per claim 11, Bykampadi in view of Ciarniello and Park teaches the independent claim 10.
Bykampadi in view of Ciarniello and Park does not teach determine a first signature associated with the first token; determine a second signature associated with the second token; and determine, based on a match between the first signature and the second signature, that the second token is associated with the user.
However, in the related art, Skerpac teaches determine a first signature associated with the first token; determine a second signature associated with the second token; and determine, based on a match between the first signature and the second signature, that the second token is associated with the user (Skerpac: para[105], “the authentication process obtains quality speech input, performs high quality secure signal processing and creates the representative digital forms of both the voice information used for speaker recognition and voice information used for speech recognition for each phrase. In one embodiment, the input information is processed in memory at the remote or local unit, combined into one date and time stamped record, encrypted and, optionally, digitally signed prior to communication with the controller assuming the controller is resident on another machine. The controller verifies the optional signature and decrypts the information in memory and matches against information stored in the n-dimensional database. Authentication is considered successful if both matching results are successful..”).
A person of ordinary skill in the art, before the effective filing data of the invention, seeking to improve authentication integrity in a 5G service-based network, would have found it obvious to incorporate Skerpac’s voice-token verification process into Bykampadi’s NEF/UDF-based token authorization system as both address credential validation and user authentication. Using biometric voice tokens within the 5G token-exchange framework would have been a predictable way to enhance spoof-resistance while maintaining standard service authorization while verifying a user’s identity (Skerpac, para. [17]).
As per claims 14, and 18, Bykampadi in view of Ciarniello and Park teaches the independent claim 10.
Skerpac teaches wherein the first voice data is associated with an image, a three-dimensional model, an audio recording, a digital avatar, or a voice recording (Skerpac: para[170], “A unique automation method to capture, record, and process this enrollment data across channels and sessions is an embodiment of this invention. Representative speech features are obtained from the recordings. Any text independent speaker recognition enrollment and subsequent verification methodology can be utilized by the Audio Collection and Enrollment System (ACES).”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to combine the token authentication system of Bykampadi with the verification of spoken one-time pass phrases of Skerpac, it will prevents spoofing while verifying a user's identity (Skerpac: para [17]).
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Bykampadi et al. (US Pub. # 2022/0353255 A1; Hereinafter “Bykampadi”) in view of Ciarniello et al. (US Pub. # 20160127902 A1; Hereinafter “Ciarniello”), Park et al. (US Pub. App. No. 2016/0080263 A1; Hereinafter “Park”)and Ben Hen et al. (WO 2019011751 A1; Hereinafter “Ben Hen”).
As per claim 12, Bykampadi in view of Skerpac and Park teaches the independent claim 10.
Bykampadi in view of Ciarniello Park does not teach wherein the instructions for determining that the first network configuration matches the second network configuration cause the 5G telecommunication system to: determine, based on the first network configuration, a first communication path for the first mobile device; query the UDF for communication path information for a third mobile device associated with the second network configuration, wherein the communication path information is associated with an access and mobility management function (AMF); in response to the query for communication path information, receive an indication of a second communication path between a node associated with the 5G telecommunication system and the third mobile device, in response to the query for communication path information, receive an indication of a second communication path between a node associated with the 5G telecommunication system and the third mobile device.
However, in the related art, Ben Hen teaches wherein the instructions for determining that the first network configuration matches the second network configuration cause the 5G telecommunication system to: determine, based on the first network configuration, a first communication path for the first mobile device (Ben Hen: fig. 4 step 401-402, “The terminal device 400 sends a registration request to the SEAF/AMF. The registration request comprises a subscription identifier, such as an IMSI. In case this is an initial registration then the identifier is the permanent subscription identifier. In case the terminal device 400 has already registered to the visiting network 300, then the identifier is a temporary identifier. S402: The SEAF/AMF initiates the authentication procedure by sending an authentication request to the AUSF in the home network 200. The authentication request comprises the permanent subscription identifier of the terminal device 400.”);
query the UDF for communication path information for a third mobile device associated with the second network configuration, wherein the communication path information is associated with an access and mobility management function (AMF) (Ben Hen: step 403-405], “The AUSF retrieves authentication information from the UDM. In case the chosen authentication procedure is AKA based, then in addition to the authentication information (AVs), the AUSF retrieves a token from the UDM.S404: The AUSF performs an authentication procedure with the terminal device 400 through the SEAF/AMF using EAP-AKA' or EPS-AKA*, potentially based on the authentication information received from the UDM.”, “The token could be bound to the visiting network 300. More precisely, a visiting network 300 identifier could be used in the computation of the l8 integrity protection tag. That is, according to an embodiment the token is bound to the visiting network 300.”);
in response to the query for communication path information, receive an indication of a second communication path between a node associated with the 5G telecommunication system and the third mobile device (Ben Hen: step 405-408, “Any further interaction with the visiting network 300 involving the UDM could be based on the scheme defined by steps S4o6a, S406b, S406C, where the source node/function/entity/device in the visiting network 300 includes the token in any message or request to the UDM in the home network 200. A successful verification of the token in UDM when presented from a different AMF to which UDM originally provided the token to, an SMF or an SMSF, gives the same level of assurance to the home network 200. As above, in case of failure, the home network 200 could take further actions, e.g. require re-authentication.” ); and
compare the first communication path and the second communication path to determine that the first network configuration matches the second network configuration (Ben Hen: step 405-408, “A successful verification indicates that the visiting network 300 is genuine and that the terminal device 400 for which the token was issued in step S403 was successfully authenticated and is being served by this visiting network 300.” ).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to combine the modified token authentication system of Ben Hen with the Garner, it will prevent entities, nodes, devices, or functions outside the visiting network 300 to access terminal device specific data and functions (Ben Hen, page 2)
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LYDIA L NOEL whose telephone number is (571)272-1628. The examiner can normally be reached Monday - Friday 9:00 - 5:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571)-270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/L.L.N./Examiner, Art Unit 2437
/ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437