Prosecution Insights
Last updated: August 15, 2026
Application No. 18/621,955

PRIMARY AUTHENTICATION METHOD AND APPARATUS

Final Rejection §102§103§112
Filed
Mar 29, 2024
Priority
Sep 30, 2021 — CN 202111166048.6 +1 more
Examiner
NOEL, LYDIA LOUIS-FILS
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Huawei Technologies Co., Ltd.
OA Round
2 (Final)
68%
Grant Probability
Favorable
3-4
OA Rounds
7m
Est. Remaining
90%
With Interview

Examiner Intelligence

Grants 68% — above average
68%
Career Allowance Rate
66 granted / 97 resolved
+10.0% vs TC avg
Strong +22% interview lift
Without
With
+22.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
17 currently pending
Career history
134
Total Applications
across all art units

Statute-Specific Performance

§101
5.7%
-34.3% vs TC avg
§103
61.5%
+21.5% vs TC avg
§102
9.4%
-30.6% vs TC avg
§112
19.2%
-20.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 97 resolved cases

Office Action

§102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to Application Response Filed on 02/18/2026. In the instant Amendment, claims 1-13, and 15-20 have been amended; and claims 1, 9, and 14 are independent claims. Claims 1-20 have been examined and are pending. This Action is made Final Response to Arguments In light of Applicant’s amendments, objection to claims 9-13 has been withdrawn. In light of Applicant’s amendments 112 (b) rejection of claims 3-6, 11, and 16-19 have been withdrawn. The 112(a) rejection of claims 3, 11, and 16, is withdrawn as applicant amendments and para [99] provide adequate writing description. Applicants’ arguments filed on 02/18/2026 with respect to the 102 rejection of claims 1 and 14 have been considered but are not persuasive. Applicant argues “the result of the reauthentication confirmation procedure cannot reasonably correspond to "a cause for rejecting the triggering of the primary authentication procedure" of claim 1. Applicants note that transmitting the result of the primary reauthentication procedure in the reauthentication confirmation message is a passively endured outcome and cannot reasonably correspond to an active action of rejecting the triggering of the primary authentication procedure, let alone feedback the reason for rejecting the reauthentication to the AUSF.”. Applicant’s argument is not persuasive. Applicant’s argument improperly narrows the claim by requiring the rejection cause information to be used by the home network device or to perform an additional technical operation. The claim only requires that the first authentication response message comprise information indicating a cause for rejecting the triggering of the primary authentication procedure. Zamora discloses that the AMF determines that the primary reauthentication procedure is unsuccessful when the communication device is not available, for example, when the communication device is turned off or in airplane mode, and transmits a reauthentication confirmation message including the result of the procedure. Under the broadest reasonable interpretation, information indicating that the procedure was unsuccessful because the UE was not available correspond to rejection cause information indicating a cause for not procedure with or completing the requested primary authentication procedure. Applicant’s distinction between a “result and a “cause” is not persuasive because Zamora does not merely disclose an unexplained failure result. Zamora expressly identifies the reason for the failure, namely that the communication device is not available, such being off or in airplane mode. The claim do not require a specifically named “cause code”, a particular field format, or do not require the home network device to take further action based on the rejection cause information. Furthermore, Applicant’s characterization of the information as a “passively endured outcome” does not distinguished the claim because the claim does not recite any functional use of the rejection cause information beyond its inclusion in the response message. Accordingly, Zamora’s disclosed failure information, including the reason that the UE is unavailable, reasonably teaches the claimed rejection cause information. Applicants’ arguments filed on 02/18/2026 with respect to the 103 rejection of independent claim 9 have been considered but are not persuasive. Applicant argues “The Office acknowledged that Zamora does not disclose or suggest "the first request message is used to request a first authentication vector for the terminal device" of claim 9. (See Office Action, page 14). In fact, Zamora does not disclose or suggest any authorization vector…. Furthermore, TS129.503, as applied by the Office, does not disclose or suggest "the first request message is used to request a first authentication vector for the terminal device; and sending, by the user data management device, a first response message to the authentication server function device in response to rejecting a determination to return the first authentication vector, wherein the first response message comprises second rejection cause information, and the second rejection cause information indicates a cause for rejecting to return the first authentication vector" of claim 9.”. Applicant's arguments fail to comply with 37 CFR 1.111(b) because they amount to a general allegation that the claims define a patentable invention without specifically pointing out how the language of the claims patentably distinguishes them from the references. Applicant’s arguments regarding TS 129.503 are not persuasive because they are conclusory and do not substantively address the cited teaching of TS 129.503. Applicant argues that Zamora does not disclose an authentication vector, but the rejection relies on TS 129.503 for that limitation. In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Ts 129.503 teaches that the AUSF requests the UDM to select an authentication method, calculate a fresh authentication vector if required, and provide the authentication information to the AUSF. Therefore, TS 29.503 teaches that the first request message from the AUSF to the UDM is used to request authentication vector for the terminal device. Applicant has not explained why this disclosure fails to meet claimed invention, and merely attacking Zamora individually does not overcome the rejection based on the combined teachings. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (B) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 3, 11, 16 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention. Claims 3, 11, and 16 disclose: “…the preset duration being between a first time and a second time…”. According to MPEP § 2173.05(a), the meaning of every term used in a claim should be apparent from the prior art or from the specification and drawings at the time the application is filed. Claim language may not be "ambiguous, vague, incoherent, opaque, or otherwise unclear in describing and defining the claimed invention." In re Packard, 751 F.3d 1307, 1311, 110 USPQ2d 1785, 1787 (Fed. Cir. 2014). Applicants need not confine themselves to the terminology used in the prior art, but are required to make clear and precise the terms that are used to define the invention whereby the metes and bounds of the claimed invention can be ascertained. During patent examination, the pending claims must be given the broadest reasonable interpretation consistent with the specification. In re Morris, 127 F.3d 1048, 1054, 44 USPQ2d 1023, 1027 (Fed. Cir. 1997); In re Prater, 415 F.2d 1393, 162 USPQ 541 (CCPA 1969). The limitation “…the preset duration being between a first time and a second time…” does not clearly recite the timing relationship disclosed in the specification. The specification, (e.g. para [99]) describes comparing an absolute value of a difference between the first time and the second time to the preset duration. The claim language, by contrast, states that the preset duration is “between” the first time and the second time, which create ambiguity as to whether the preset duration is the interval between the two times, a threshold compared to the interval, or another configured value. Therefore, the metes and bounds of the claimed timing condition remain unclear. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1-2, 14-15 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Zamora et al. (U.S. Pub. No. 2022/0408249 A1; Hereinafter “Zamora”). As per claims 1, 14, Zamora teaches a primary authentication method, comprising (Zamora: para[43], [59-61], fig. 1-2, 8 “he HN initiated primary authentication/re-authentication procedure”): receiving, by an access and mobility management function device, a first authentication request message from a home network device (Zamora: para [42-53], [66-68], [75], “The UDM initiates a request to the AMF to initiate a primary authentication procedure for a given communication via the AUSF…. The AUSF 600 in operation 4 forwards the re-authentication notification to the AMF 500 using a Nausf_UEAuthentication_ReAuthentication Notification. The AUSF 600 selects the AMF instance indicated by the UDM”), wherein the first authentication request message comprises an identifier of a terminal device (Zamora: para [41-43], [59-61], “In operation 2, the UDM stores the authentication status of the communication device (e.g., the SUPI, authentication result, timestamp, and the serving network name)….the HN initiated primary authentication/re-authentication procedure in one embodiment is triggered by the UDM based on the authentication status of the communication device stored in step 2 of FIG. 1 together with other information (e.g. HPLMN configuration, communication device profile information). ”), the first authentication request message is used to trigger a primary authentication procedure on the terminal device, and the home network device is a network device in a home network of the terminal device (Zamora: para[42-43], “This enables the HN initiated procedures to progress successfully using a fresh security association with the communication device by defining a HN initiated primary authentication and primary re-authentication procedure (by the UDM or the AUSF) for a given communication device… The AMF 500 in operation 5 initiates a primary authentication procedure as defined in TS 33.501 [1] (section 6.1.2). In this case, the AMF may need to page/contact the UE before initiating this procedure”); and sending, by the access and mobility management function device, a first authentication response message to the home network device, in response to the access and mobility management function device rejecting the triggering of the primary authentication procedure (Zamora: para[62-65], [69-72], “In block 908, the processing circuitry 603 may receive a reauthentication confirmation message from the AMF. The reauthentication confirmation message may indicate success or failure of the reauthentication of the communication device…In block 910, the processing circuitry 603 may transmit a reauthentication result confirmation message to the UDM. The reauthentication result confirmation message may indicate success or failure of the reauthentication of the communication device”), wherein the first authentication response message comprises first rejection cause information, and the first rejection cause information indicates a cause for rejecting the triggering of the primary authentication procedure (Zamora: para [62-65], [69-72], [77-78], “the processing circuitry 503 may determine a result of the primary reauthentication procedure, the result indicating whether the primary reauthentication procedure was successful or unsuccessful. For example, if the communication device is not available (e.g., is turned off, in airplane mode, etc.), then the primary reauthentication procedure would not be successful. In block 1006, the processing circuitry 1006 may transmit a reauthentication confirmation message to the AUSF node, the reauthentication confirmation message including the result (e.g., successful or unsuccessful) of the primary reauthentication procedure.’’ A reauthentication confirmation message indicating failure due to not being able to contact the UE corresponds to the first rejection cause information). As per claims 2, 15, Zamora teaches the independent claim 1. Zamora teaches determining, by the access and mobility management function device, to reject the triggering of the primary authentication procedure on the terminal device based on the first authentication request message (Zamora: para[77-78], “the processing circuitry 503 may determine a result of the primary reauthentication procedure, the result indicating whether the primary reauthentication procedure was successful or unsuccessful. For example, if the communication device is not available (e.g., is turned off, in airplane mode, etc.), then the primary reauthentication procedure would not be successful. In block 1006, the processing circuitry 1006 may transmit a reauthentication confirmation message to the AUSF node, the reauthentication confirmation message including the result (e.g., successful or unsuccessful) of the primary reauthentication procedure.”). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 3 and 6, are rejected under 35 U.S.C. 103 as being unpatentable over Zamora et al. (U.S. Pub. No. 2022/0408249 A1; Hereinafter “Zamora”) in view and Murthy et al. (U.S. Pub. No. 2020/0112554 A1; Hereinafter “Murthy”). As per claims 3, 16, Zamora teaches the dependent claim 2. Zamora also teaches the 5G AMF/AUSF primary authentication environment, including triggering primary authentication procedures. Zamora does not explicitly teach determining, to reject the triggering of the primary authentication procedure in response to determining that a primary authentication procedure has been triggered on the terminal device within preset duration based on the identifier, the preset duration being between a first time and a second time However, in the related art, Murthy teaches determining, to reject the triggering of the primary authentication procedure in response to determining that a primary authentication procedure has been triggered on the terminal device within preset duration based on the identifier, the preset duration being between a first time and a second time (Murthy: para [116-121], “. In an example implementation, once the user authenticates successfully, the firewall will generate and store (e.g., cache) both the first factor authentication timestamp and the second authentication timestamp(s) alongside the authentication profile in use within User ID, and use these timestamps as a measure to compare any future matches on the auth policy rule base….. Tracking the 1FA and 2FA timeouts per authentication profile allows admins to define stricter authentication requirements for IT personnel, while allowing an average enterprise user to authenticate at longer, preset intervals….. f the recorded timestamps do fall within the timeout window, then the firewall will “permit” access as per the Authentication Policy and proceed to evaluate security policy rules as shown at 408. If the 1FA/2FA timestamp is not within the desired window of time, then the firewall will proceed to challenge the user to authenticate via 1FA and 2FA as shown at 416, and update the 1FA and 2FA timestamps upon successful authentication as shown at 418 and 420”). It would have been obvious to one of ordinary skill in the art, to modify Zamora’s AMF authentication triggering process to use stored prior authentication timing information and a preset timeout window, as taught by Murthy, in order to avoid unnecessary repeated authentication challenge withing configured authentication validity interval while still requiring authentication when the previous authentication is stale ( Murthy; para [51] ). Claims 7-8, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Zamora et al. (U.S. Pub. No. 2022/0408249 A1; Hereinafter “Zamora”) in view of 3GPP TS 133.501 (“Security architecture and procedures for 5G System (3GPP TS 33.501 version 15.7.0 Release 15”; Hereinafter “TS 133.501”). As per claim 7, Zamora teaches the dependent claim 2. Zamora does not explicitly teach determining, by the access and mobility management function device, to reject the triggering of the primary authentication procedure in response to determining that a primary authentication procedure is being executed on the terminal device based on the identifier. However, in the related art, TS 133.501 teaches determining, by the access and mobility management function device, to reject the triggering of the primary authentication procedure in response to determining that a primary authentication procedure is being executed on the terminal device based on the identifier (TS 133.501: 6.9.5.1, “AMF shall not initiate any of the N2 procedures including a new key towards a UE if a NAS Security Mode Command procedure is ongoing with the UE.”). It would have been obvious to one of ordinary skill in the art, to apply the teaching of TS 133.501 to Zamora, it will prevent redundant and malicious authentication triggers and ensure security consistency across 5G core. As per claims 8, 20, Zamora in view of TS 133.501 teaches the dependent claim 7. 3GPP TS 133.501 teaches determining, by the access and mobility management function device, that the primary authentication procedure is being executed on the terminal device in response to the access and mobility management function device has triggered the primary authentication procedure on the terminal device corresponding to the identifier, and receives no corresponding authentication result (TS 133.503: 6.1.4.1-6.1.4.2, “UDM shall reply to AUSF with a Nudm_UEAuthentication_ResultConfirmation Response. Upon reception of subsequent UE related procedures (e.g. Nudm_UECM_Registration_Request from AMF) UDM may apply actions according to home operator’s policy to detect and achieve protection against certain types of fraud (e.g. as proposed in section 6.1.4.2)…….. For a visited network in the second category, the home network would only check that an authentication in a network visited by the subscriber was sufficiently recent (taking into account that there may have been a security context transfer between the visited networks).”). It would have been obvious to one of ordinary skill in the art, to apply the teaching of TS 133.501 to Zamora, it will prevent redundant and malicious authentication triggers and ensure security consistency across 5G core. Claims 4-5, 9-10, and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Zamora et al. (U.S. Pub. No. 2022/0408249 A1; Hereinafter “Zamora”) in view of 3GPP TS 129.503 (“5G System; Unified Data Management Services; Stage 3 (3GPP TS 129.503 version 16.4.0 Release 16)”; Hereinafter “TS 129.503”). As per claims 4, 17, Zamora teaches the dependent claim 2. Zamora does not explicitly teach determining, by the access and mobility management function device, to reject the triggering of the primary authentication procedure in response to determining, by the access and mobility management function device, that the home network device is not allowed to trigger the primary authentication procedure based on the identifier. However, in the related art, TS 129.503 teaches determining, by the access and mobility management function device, to reject the triggering of the primary authentication procedure in response to determining, by the access and mobility management function device, that the home network device is not allowed to trigger the primary authentication procedure based on the identifier (TS 129.503: 6.1.3.1-1, page 77-79, 5.3.2.2.2, subscription data includes “supportedFeatures” wich NF uses to authorize actions (permissions), “If the operation cannot be authorized due to e.g UE does not have required subcription data, the AMF does not support CAG feature and the UE is allowed to access 5GS via CAG cell(s) only, access barring, roaming restrictions or core network restriction, HTTP status code "403 Forbidden" should be returned including additional error information in the response body (in "ProblemDetails" element”). It would have been obvious to one of ordinary skill in the art, to apply the teaching of TS 129.503 to Zamora, it will prevent redundant and malicious authentication triggers and ensure security consistency across 5G core. As per claims 5, 18, Zamora in view of TS 129.503 teaches the dependent claim 4. 3GPP TS 29.503 teaches obtaining, by the access and mobility management function device, subscription data of the terminal device based on the identifier; and determining, by the access and mobility management function device that the home network device is not allowed to trigger the primary authentication procedure based on the subscription data (TS 129.503: 6.3.1 /table, page 77-79, NF uses “/supi” in URI to request data). It would have been obvious to one of ordinary skill in the art, to apply the teaching of TS 129.503 to Zamora, it will prevent redundant and malicious authentication triggers and ensure security consistency across 5G core. As per claim 9, Zamora teaches a primary authentication method, comprising (Zamora: para[43], [59-61], fig. 1-2, 8 “the HN initiated primary authentication/re-authentication procedure”): receiving, by a user data management device, a first request message from an authentication server function device (Zamora: para[41-43], “In operation 1 of FIG. 1, the AUSF can inform the UDM about the result and time of an authentication procedure with a communication device using a Nudm_UEAuthentication_ResultConfirmation Request.”), wherein the first request message comprises an identifier of a terminal device (Zamora: para[41-43], “This request shall include the subscription permanent identifier (SUPI), a timestamp of the authentication, the authentication type (e.g. EAP method or 5G-AKA), and the serving network name. In operation 2, the UDM stores the authentication status of the communication device (e.g., the SUPI, authentication result, timestamp, and the serving network name).”); and sending, by the user data management device, a first response message to the authentication server function device in response to rejecting to a determination to return the first authentication vector (Zamora: para[44-49], “In operation 204, the processing circuitry 703 may transmit a re-authentication notification to the AUSF 600 using a Nudm_UEAuthentication_ReAuthentication Notification. In another embodiment, the processing circuitry 703 may transmit a re-authentication request to the AUSF 600.”), wherein the first response message comprises second rejection cause information, and the second rejection cause information indicates a cause for rejecting to return the first authentication vector (Zamora: para[32-33], [44-49], “As previously indicated, the corresponding stage 3 specification TS 29.503 [2] defines specific REAUTHENTICATION_REQUIRED error code for Nudm_UECM services to indicate that “due to operator policies the user needs to be re-authenticated, e.g. last valid authentication is considered obsolete”. Upon reception of this error, the AMF is expected to trigger a primary (re-) authentication procedure for the UE.”). Zamora does not explicitly teach the first request message is used to request a first authentication vector for the terminal device. However, in the related art TS129.503 discloses the first request message is used to request a first authentication vector for the terminal device (TS 129.503: 5.4.2.1, “The Nudm_UEAuthentication service is used by the AUSF to request the UDM to select an authentication method, calculate a fresh authentication vector (AV) if required for the selected method, and provide it to the AUSF by means of the Get service operation. See 3GPP TS 33.501 [6] clause 14.2.2. The service may also be used by the AUSF to indicate.”, 5.4.2.2.2, “2b. If the operation cannot be authorized due to e.g UE does not have required subcription data, CAG ID is not in the allowed CAG list, access barring or roaming restrictions, HTTP status code "403 Forbidden" should be returned including additional error information in the response body (in "ProblemDetails" element).”). It would have been obvious to one of ordinary skill in the art, in view of 3GPP TZ 129.503 describing that the authentication server obtain vector from the user data management based on UE identifier, to implement Zamora’s authentication credential request as a standardized request for an authentication vector to maintain 5G core compatibility and ensure interoperability with the core-network functions. As per claim 10, Zamora in view of TS 129.503 teaches the independent claim 9. TS 129.503 teaches wherein the method further comprises: determining, by the user data management device, to reject to return the first authentication vector based on the first request message (TS129.503: 5.4.2.2.3, “. If the operation cannot be authorized due to e.g. UE does not have required subcription data, HTTP status code "403 Forbidden" should be returned including additional error information in the response body (in "ProblemDetails" element). On failure, the appropriate HTTP status code indicating the error shall be returned and appropriate additional error information should be returned in the POST response body.”). It would have been obvious to one of ordinary skill in the art, in view of 3GPP TZ 129.503 describing that the authentication server obtain vector from the user data management based on UE identifier, to implement Zamora’s authentication credential request as a standardized request for an authentication vector to maintain 5G core compatibility and ensure interoperability with the core-network functions. Claims 6 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Zamora et al. (U.S. Pub. No. 2022/0408249 A1; Hereinafter “Zamora”) in view of 3GPP TS 129.503 (“5G System; Unified Data Management Services; Stage 3 (3GPP TS 129.503 version 16.4.0 Release 16)”; Hereinafter “TS 129.503”) and 3GPP TS 133.535 (“Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5GS) (3GPP TS 133.535 version 16.0.0 Release 16”; Hereinafter “TS 133.535”). As per claims 6, 19, Zamora in view of TS 129.503 teaches the dependent claim 4. 3GPP TS 133.535 teaches wherein the subscription data indicates that the terminal device does not support at least one of a steering of roaming procedure, a user equipment parameter update procedure or an authentication and key management for applications procedure (TS 133.535: 3.1, “AKMA subscription data: The data in the home operator's network indicating whether or not the subscriber is allowed to use AKMA.”). It would have been obvious to one of ordinary skill in the art, to apply the teaching of TS 133.535 to Zamora, it will prevent malicious authentication triggers and ensure security consistency across 5G core. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Zamora et al. (U.S. Pub. No. 2022/0408249 A1; Hereinafter “Zamora”) in view of 3GPP TS 129.503 (“5G System; Unified Data Management Services; Stage 3 (3GPP TS 29.503 version 16.4.0 Release 16)”; Hereinafter “TS 129.503”) and Murthy et al. (U.S. Pub. No. 2020/0112554 A1; Hereinafter “Murthy”). As per claim 11, Zamora in view of TS 129.503 teaches the dependent claim 10. Zamora in view of TS 129.503 also teaches the 5G AMF/AUSF primary authentication environment, including triggering primary authentication procedures. Zamora in view of TS 129.503 does not explicitly teach determining, to reject the triggering of the primary authentication procedure in response to determining that a primary authentication procedure has been triggered on the terminal device within preset duration based on the identifier, the preset duration being between a first time and a second time However, in the related art, Murthy teaches determining, to reject the triggering of the primary authentication procedure in response to determining that a primary authentication procedure has been triggered on the terminal device within preset duration based on the identifier, the preset duration being between a first time and a second time (Murthy: para [116-121], “. In an example implementation, once the user authenticates successfully, the firewall will generate and store (e.g., cache) both the first factor authentication timestamp and the second authentication timestamp(s) alongside the authentication profile in use within User ID, and use these timestamps as a measure to compare any future matches on the auth policy rule base….. Tracking the 1FA and 2FA timeouts per authentication profile allows admins to define stricter authentication requirements for IT personnel, while allowing an average enterprise user to authenticate at longer, preset intervals….. f the recorded timestamps do fall within the timeout window, then the firewall will “permit” access as per the Authentication Policy and proceed to evaluate security policy rules as shown at 408. If the 1FA/2FA timestamp is not within the desired window of time, then the firewall will proceed to challenge the user to authenticate via 1FA and 2FA as shown at 416, and update the 1FA and 2FA timestamps upon successful authentication as shown at 418 and 420”). It would have been obvious to one of ordinary skill in the art, to modify Zamora’s AMF authentication triggering process to use stored prior authentication timing information and a preset timeout window, as taught by Murthy, in order to avoid unnecessary repeated authentication challenge withing configured authentication validity interval while still requiring authentication when the previous authentication is stale ( Murthy; para [51] ). Claims 12-13 are rejected under 35 U.S.C. 103 as being unpatentable over Zamora et al. (U.S. Pub. No. 2022/0408249 A1; Hereinafter “Zamora”) in view of 3GPP TS 129.503 (“5G System; Unified Data Management Services; Stage 3 (3GPP TS 29.503 version 16.4.0 Release 16)”; Hereinafter “TS 129.503”) and 3GPP TS 133.501 (“Security architecture and procedures for 5G System (3GPP TS 133.501 version 15.7.0 Release 15”; Hereinafter “TS 133.501”). As per claim 12 Zamora in view of TS 129.503 and TS133.501 teaches the dependent claim 10. TS 133.501 teaches determining, by the user data management device, to reject to return the first authentication vector in response to determining, that a primary authentication procedure is being executed on the terminal device based on the identifier (TS 133.501: 6.9.5.1, “AMF shall not initiate any of the N2 procedures including a new key towards a UE if a NAS Security Mode Command procedure is ongoing with the UE.”). It would have been obvious to one of ordinary skill in the art, to have update Zamora with TS133.501, because doing so provides predictable control of authentication retry intervals withing the 5G core to improve consistency with the 5G procedures. As per claim 13, Zamora in view of TS 129.503 and TS 133.501 teaches the dependent claim 12. TS 129.503 teaches determining that the primary authentication procedure is being executed on the terminal device in response to the user data management device having sent a second authentication vector used to authenticate the terminal device corresponding to the identifier, and failing to receive an authentication result confirmation message corresponding to the second authentication vector (TS 129.503: 5.4.2.3.3, “The NF service consumer shall send a PUT request to the UDM. The payload of the body shall contain the indication to remove authentication result. 2a. On success, "204 No Content" shall be returned. The UDM shall remove the Authentication result of the UE by completely replacing the individual AuthEvent resource. 2b. On failure, the appropriate HTTP status code indicating the error shall be returned and appropriate additional error information should be returned. ”). It would have been obvious to one of ordinary skill in the art, to apply the teaching of TS 129.503 to Zamora, it will prevent redundant and malicious authentication triggers and ensure security consistency across 5G core. It would have been obvious to one of ordinary skill in the art, in view of 3GPP TZ 129.503 describing that the authentication server obtain vector from the user data management based on UE identifier, to implement Zamora’s authentication credential request as a standardized request for an authentication vector to maintain 5G core compatibility and ensure interoperability with the core-network functions. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to LYDIA L NOEL whose telephone number is (571)272-1628. The examiner can normally be reached Monday - Friday 9:00 - 5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571)-270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /L.L.N./Examiner, Art Unit 2437 /ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Mar 29, 2024
Application Filed
Nov 18, 2025
Non-Final Rejection mailed — §102, §103, §112
Feb 18, 2026
Response Filed
May 15, 2026
Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12647254
DATA FILE ENCRYPTION AND TRANSMISSION/RECEPTION SYSTEM AND DATA FILE ENCRYPTION AND TRANSMISSION/RECEPTION METHOD
3y 0m to grant Granted Jun 02, 2026
Patent 12632589
PRIVACY PRESERVING LOGGING
4y 1m to grant Granted May 19, 2026
Patent 12610231
Wireless Fine Time Measurement Authentication
4y 8m to grant Granted Apr 21, 2026
Patent 12587846
DEVICE, METHOD AND COMPUTER READABLE MEDIUM FOR RESISTING DOWNGRADE ATTACKS
2y 5m to grant Granted Mar 24, 2026
Patent 12563090
RESILIENT HIGH-BANDWIDTH STATE-TRANSITION COMPUTER
2y 9m to grant Granted Feb 24, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
68%
Grant Probability
90%
With Interview (+22.2%)
2y 11m (~7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 97 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month