DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office Action is in response to the Amendment filed on 03/13/2026.
In the instant Amendment, claim 42 has been amended; and claims 33, 44, 51-52 are independent claims. Claims 33-52 have been examined and are pending. This Action is made Final
Claim objections
Claims 33-52 are objected to because of the following informalities:
• Claims 33, 44, 51-52: Several terms are introduced such as: “a wireless communications device, a network slice, a communications network, one or more attributes, an attribute- based access policy, and a slice manager”, that appear to provide antecedent basis and context for limitations in the body of the claims, but the claims does not clearly indicate which preamble terms are intended to be limiting and how such terms are structurally and functionally related to the claimed steps.
Appropriate correction is required.
Response to Arguments
Applicant arguments regarding the abstract are persuasive. Since the present application entered the national stage under 35U.S.C 371 and the abstract was previously published as part of the international application publication, the objection to the abstract is withdrawn.
Applicant’s amendment to claim 42 has been considered and is persuasive in overcoming the rejection under 35 U.S.C. 112 (a) and 112 (b). Accordingly, the rejections are withdrawn. However, the Examiner does not agree that the amendment is merely a “minor” change, as replacing “encrypted” with “generated” substantively changes the claimed cryptographic operation and scope of the claim.
Applicant's arguments filed 03/13/2026 regarding the objection to the preamble of claims 33, 44, and 51-52 have been fully considered but they are not persuasive.
The objection is not based merely on the length of the preambles. Rather, the preambles of independent claims 33, 44, 51, and 52 recite substantive limitations that are necessary to understand the later claim steps, including “the wireless communications device having one or more attributes associated with it” and “at least one of the one or more attributes fulfilling an attribute-based access policy of the network slice.” Because the body of the claims later relies on the “one or more attributes,” the “attribute-based access policy,” and the relationship between the attributes and the policy, the preamble language gives life, meaning, and vitality to the claims and affects claim scope. See MPEP § 2111.02. However, the claims do not clearly define what qualifies as an “attribute,” how the attribute is “associated with” the wireless communications device, or how an attribute “fulfills” the attribute-based access policy. Thus, the extended preamble language creates uncertainty as to which features are required claim limitations and how the metes and bounds of the claims are determined. See MPEP §§ 2173.05(e), 2173.05(m). Accordingly, the objection is maintained.
Applicant's arguments filed 03/13/2026 regarding the 103 rejection of claims 33-52 have been fully considered but they are not persuasive.
Applicant argues that the phrase “such that the encrypted access key is decryptable via the secret key” is not intended use”
The Examiner agrees that the phrase expresses a functional relationship between the recited secret key and encrypted access key. However, under the broadest reasonable interpretation, this limitation does not require any particular decryption algorithm, message syntax, or key-container format. It merely requires that the encrypted access key be recoverable or usable through the secret key. As applied in the rejection, Ben Henda teaches network-slice authentication resulting in shared secret material and derivation or use of slice security context therefrom, while Goyal teaches encrypting a symmetric/access key under an attribute-based policy such that only a key generated from the relevant attributes can recover that key. The combination therefore teaches the claimed functional relationship.
Applicant argues “Ben Henda does not send a secret key”
Applicant arguments that Ben Henda describes mutual EAP-based key establishment rather than “sending a secret key” to the device, is not persuasive. Claim 33 does not exclude embodiments in which the secret key is established through an authentication exchange and then provided to, or made available at, the device for subsequent use. Ben Henda teaches a network-slice authentication framework in which a UE engages in slice-specific authentication, secret material is established for the target slice, and a new slice security context/access-enabling key is created and activated. Goyal teaches attribute-based encryption in which secret key material is generated from attributes/access structure and encrypted key material is recoverable only when the relevant attributes satisfy the policy. It would have been obvious to use Goyal’s attribute-based mechanism in Ben Henda’s slice-authentication environment so that slice-access key material is encrypted under a slice policy and recoverable via secret key material generated from UE attributes. Under the broadest reasonable interpretation, this teaches or at least suggests “sending a secret key … generated using” device attributes and “sending an encrypted access key … decryptable via the secret key.” Applicant’s arguments improperly read narrower implementation details into the claims from the specification
Applicant argues “The NAS SMC indication is not an encrypted access key”
Applicant argues that the NAS SMC indication of Ben Henda is not itself the claimed encrypted access key. This argument is not persuasive. The rejection is not limited to equating the indication, by itself, with the entire claimed encrypted access key. Rather, Ben Henda is relied upon for teaching slice-specific authentication, establishment of secret material, and creation/activation of a new slice security context, while Goyal is relied upon for teaching the specific attribute-based cryptographic mechanism in which key material is encrypted under an access policy and is recoverable only via a key generated from attributes. In the proposed combination, the slice access/security key of Ben Henda would have been encrypted according to Goyal’s attribute-based policy mechanism and provided to the UE for recovery via the attribute-derived secret key.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 33-39, 41-48, 51-52 are rejected under 35 U.S.C. 103 as being unpatentable over Ben Henda (U.S. Application US 20220070157 A1; Hereinafter “Ben Henda”) in view of Goyal et al. (“Attribute-Based Encryption for Fine-Grained Access Control of Encrypted Data” CCS 2006; Hereafter “Goyal”).
As per claims 33, 51, Nayak teaches a method for authenticating a wireless communications device to a network slice of a communications network (Ben Henda: fig. 1, para[43], [90-91],“the terminal device 200 decides to use services provided by network slice B…. A network slice authentication procedure is triggered between the terminal device 200 and the communication network 100 during which signaling messages are exchanged with the target AMF 300b and possibly involving other network functions, here exemplified by the Authentication, Authorization and Accounting (AAA) entity 500 of network slice B”, the wireless communications device having one or more attributes associated with it (Ben Henda: para[ 90-92], “For the network slice authentication, it could be the AUSF or any other entity not necessarily under the control of the network operator since this would allow using other than the 3GPP credentials for primary access. In the case of EAP, if the used EAP method is key generating such as EAP-TLS or EAP-PSK then a successful authentication result in the establishment of shared keys, i.e. the MSK and the Extended MSK (EMSK) between the terminal device 200 and the AAA entity”, the credential are treated as UE attributes for slice policy (credentials plus slice authorization), because the UE must satisfy slice B credentials), the method being performed by a slice manager of the communications network and comprising (Ben Henda: fig. 1, 4, para[90-92], “signaling messages are exchanged with the target AMF 300b and possibly involving other network functions, here exemplified by the Authentication, Authorization and Accounting (AAA) entity 500 of network slice B. It is possible that this AAA entity could be an authentication server which is external to the operator network and under the control entity served by network slice B”):
sending a secret key to the wireless communications device (terminal device 200) (Ben Henda: para[90-92], “For the network slice authentication, it could be the AUSF or any other entity not necessarily under the control of the network operator since this would allow using other than the 3GPP credentials for primary access….In the case of EAP, if the used EAP method is key generating such as EAP-TLS or EAP-PSK then a successful authentication result in the establishment of shared keys, i.e. the MSK and the Extended MSK (EMSK) between the terminal device 200 and the AAA entity. The MSK is sent to the authenticator alongside the authentication result, i.e. EAP-SUCCESS in this case. A secret is thereby established between the terminal device 200 and the target AMF 300b following a successful authentication. In some examples, this secret could be a network slice authentication key denoted by K.sub.SA, or the MSK in case EAP is used. In other examples this secret could be a token or a random string, etc.” the keys are derived from the credentials); and
sending an encrypted access key to the wireless communications device (NAS SM Command (indication) step 304, fig. 4), such that the encrypted access key is decryptable via the secret key (Ben Henda: para[91-96], “S303: The target AMF 300b creates a new security context using the received secret. One possibility is to use directly the received secret if it is a key or to derive a new K.sub.AMF′ from it using a key derivation function such as the one used in 3GPP standards. In another example the target AMF 300b uses the current AMF key and the received secret to derive the K.sub.AMF′. This latter example protects against a key leakage in one domain (AAA or Source AMF domains)…. The target AMF 300b activates the new security context using the NAS SMC procedure described in aforementioned document 3GPP TS 33.501 with the difference that the target AMF 300b indicates in the downlink message (of this step) that the new security context is created based on the secret resulting from the successful slice authentication. This indication could be a Boolean flag, or a value generated using the slice authentication secret. For example, in the case of EAP, it could be a hash of the MSK key and possibly a freshness parameter, e.g. the NAS downlink count value used in this message, etc”).
Ben Henda does not explicitly teach at least one of the one or more attributes fulfilling an attribute-based access policy; the secret key generated using the one or more attributes associated with the wireless communications device; the encrypted access key being encrypted using the access policy.
However, in the related art Goyal teaches at least one of the one or more attributes fulfilling an attribute-based access policy (Goyal: sect. 4.2, 8 “In an ABE system, a user’s keys and ciphertexts are labeled with sets of descriptive attributes and a particular key can decrypt a particular ciphertext only if there is a match between the attributes of the ciphertext and the user’s key… We develop a much richer type of attribute-based encryption cryptosystem and demonstrate its applications. In our system each ciphertext is labeled by the encryptor with a set of descriptive attributes Each private key is associated with an access structure that specifies which type of ciphertexts the key can decrypt. We call such a scheme a Key-Policy Attribute-Based Encryption (KP-ABE)”);
the secret key generated using the one or more attributes ( Goyal: section 4.4, sect. 8, “The simulator B runs A. A chooses the set of attributes γ it wishes to be challenged upon….A adaptively makes requests for the keys corresponding to any access structures T such that the challenge set γ does not satisfy T . Suppose A makes a request for the secret key for an access structure T where T (γ) = 0. To generate the secret key, B needs to assign a polynomial Qx of degree dx for every node in the access tree T…..The key corresponding to each leaf node is given using its polynomial as follows. Let i = att(x). Dx = g Qx(0) ti = g bqx(0) ri = B qx(0) ri g Qx(0) ti = g bqx(0) bβi = g qx(0) βi if att(x) ∈ γ, otherwise” see also 4.2, and 5.1)
the encrypted access key being encrypted using the access policy ( Goyal: sect. 4.2, 5.1, 8, “Each user is subscribed to a different “package”. The user package describes an access policy, which along with the set of attributes describing any particular item being broadcast,….Our KP-ABE system naturally offers a targeted broadcast system. A new symmetric key would be chosen and used to encrypt each item being broadcast, and then the KP-ABE system would be used to encrypt the symmetric key with the attributes associated with the item being broadcast.”)
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to have combine the teaching of Ben Henda’s slice-authentication secret with Goyal’s attribute-based key-generation mechanism to enforce slice-specifics access policies cryptographically, achieving finer-grained authorization, it will enforce slice access policies through attribute-bound keys and provide a secure and scalable slice authentication (Goyal, page 4 sect. 2).
Furthermore, Ben Henda also teaches the hardware components of claim 51 such a processor; and a memory (Ben Henda: fig. 10, para[141], “processing circuitry 310 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1210b (as in FIG. 12), e.g. in the form of a storage medium 330.”).
As per claim 34, Ben Henda in view of Goyal teaches the independent claim 33. Goyal teaches generating the secret key using the one or more attributes associated with the wireless communication device ( Goyal: section 4.4, sect. 8, “The simulator B runs A. A chooses the set of attributes γ it wishes to be challenged upon….A adaptively makes requests for the keys corresponding to any access structures T such that the challenge set γ does not satisfy T . Suppose A makes a request for the secret key for an access structure T where T (γ) = 0. To generate the secret key, B needs to assign a polynomial Qx of degree dx for every node in the access tree T…..The key corresponding to each leaf node is given using its polynomial as follows. Let i = att(x). Dx = g Qx(0) ti = g bqx(0) ri = B qx(0) ri g Qx(0) ti = g bqx(0) bβi = g qx(0) βi if att(x) ∈ γ, otherwise” see also 4.2, and 5.1)
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to modify Ben Henda’s slice-authentication procedure with Goyal’s attribute-based encryption key-policy mechanism in order to enforce slice admission using cryptographically bound UE attributes and slice-specific access policies, thereby allowing only devices whose attributes satisfy the slice policy to recover the slice access/security key. It will improve scalability and granularity of slice authorization, especially where different slices are intended for different classes of devices, services, or subscribers (Goyal, page 4 sect. 2).
As per claim 35, Ben Henda in view of Goyal teaches the independent claim 33. Ben Henda teaches generating the access key (Ben Henda: para[92-96], “S303: The target AMF 300b creates a new security context using the received secret. One possibility is to use directly the received secret if it is a key or to derive a new K.sub.AMF′ from it using a key derivation function such as the one used in 3GPP standards. In another example the target AMF 300b uses the current AMF key and the received secret to derive the K.sub.AMF′. This latter example protects against a key leakage in one domain (AAA or Source AMF domains)…. The target AMF 300b activates the new security context using the NAS SMC procedure described in aforementioned document 3GPP TS 33.501 with the difference that the target AMF 300b indicates in the downlink message (of this step) that the new security context is created based on the secret resulting from the successful slice authentication. This indication could be a Boolean flag, or a value generated using the slice authentication secret. For example, in the case of EAP, it could be a hash of the MSK key and possibly a freshness parameter, e.g. the NAS downlink count value used in this message, etc” the Examiner would like to notate that “such that the encrypted access key is decryptable via the secret key” is intended use).
Goyal teaches encrypting the access key using the attribute-based access policy (Goyal: sect. 4.2, sect. 5.1, “Encryption (m, γ,PK): To encrypt a message m ∈ G2 under a set of attributes γ, choose a random value s ∈ Zp and publish the ciphertext as: E = (γ, E0 = me(g1, g2) s , E00 = g s , {Ei = T(i) s }i∈γ). Key Generation (T , MK,PK) The algorithm outputs a key which enables the user to decrypt a message encrypted under a set of attributes γ, if and only if T (γ) = 1.”….. The algorithm DecryptNode(E, D, x) then proceeds as follows: For all nodes z that are children of x, it calls DecryptNode(E, D, z) and stores the output as Fz. Let Sx be an arbitrary kx-sized set of child nodes z such that Fz 6= ⊥. If no such set exists then the node was not satisfied and the function returns ⊥. Otherwise, we compute:.. and return the result”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to modify Ben Henda’s slice-authentication procedure with Goyal’s attribute-based encryption key-policy mechanism in order to enforce slice admission using cryptographically bound UE attributes and slice-specific access policies, thereby allowing only devices whose attributes satisfy the slice policy to recover the slice access/security key. It will improve scalability and granularity of slice authorization, especially where different slices are intended for different classes of devices, services, or subscribers (Goyal, page 4 sect. 2).
As per claim 36, Ben Henda in view of Goyal teaches the dependent claim 35. Ben Henda teaches wherein the access key is generated in response to the network slice being created (Ben Henda: para[90-92], “A network slice authentication procedure is triggered between the terminal device 200 and the communication network 100 during which signaling messages are exchanged with the target AMF 300b and possibly involving other network functions, here exemplified by the Authentication, Authorization and Accounting (AAA) entity 500 of network slice B……The target AMF 300b creates a new security context using the received secret. One possibility is to use directly the received secret if it is a key or to derive a new K.sub.AMF′ from it using a key derivation function such as the one used in 3GPP standards”).
As per claim 37, Ben Henda in view of Goyal teaches the independent claim 33. Goyal teaches determining an attribute- based access policy for the network slice (Goyal: sect. 4.2, 5.1, 8, “Each user is subscribed to a different “package”. The user package describes an access policy, which along with the set of attributes describing any particular item being broadcast, determine whether or not the user should be able to access the item. For example, a television user may want to subscribe to a package that allows him view episodes of “24” from either the current season or Season 3. This could be encoded as policy as (“24” AND (“Season:5” OR “Season:3”)).”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to modify Ben Henda’s slice-authentication procedure with Goyal’s attribute-based encryption key-policy mechanism in order to enforce slice admission using cryptographically bound UE attributes and slice-specific access policies, thereby allowing only devices whose attributes satisfy the slice policy to recover the slice access/security key. It will improve scalability and granularity of slice authorization, especially where different slices are intended for different classes of devices, services, or subscribers (Goyal, page 4 sect. 2).
As per claim 38, Ben Henda in view of Goyal teaches the independent claim 33. Ben Henda teaches receiving a request from the wireless communications device for the secret key (Ben Henda: para[91], “A network slice authentication procedure is triggered between the terminal device 200 and the communication network 100 during which signaling messages are exchanged with the target AMF 300b and possibly involving other network functions”, this inherently includes the UE requesting the slice authentication secret. See also Goyal page 25, phase 1.).
As per claim 39, Ben Henda in view of Goyal teaches the dependent claim 38, Ben Henda wherein the request indicates the one or more attributes associated with the wireless communications device (Ben Henda: para[91], “A network slice authentication procedure is triggered between the terminal device 200 and the communication network 100 during which signaling messages are exchanged with the target AMF 300b and possibly involving other network functions…In the case of EAP, if the used EAP method is key generating such as EAP-TLS or EAP-PSK then a successful authentication result in the establishment of shared keys, i.e. the MSK and the Extended MSK (EMSK) between the terminal device 200 and the AAA entity.”, slice authentication uses EAP-TLS/EAP-PSK, where the UE provide credential attributes (certificate, PSK identity) in the request. See also Goyal section A.2).
As per claim 41, Ben Henda in view of Goyal teaches the independent claim 33. Ben Henda teaches generating a secret master key and a corresponding public key for the slice manager, wherein the secret key is generated using the secret master key and the one or more attributes associated with the wireless communications device, and wherein the public key is available to the wireless communications device (Ben Henda: para[92], “One possibility is to use directly the received secret if it is a key or to derive a new K.sub.AMF′ from it using a key derivation function such as the one used in 3GPP standards. In another example the target AMF 300b uses the current AMF key and the received secret to derive the K.sub.AMF′. This latter example protects against a key leakage in one domain (AAA or Source AMF domains). More precisely, if the K.sub.AMF is compromised then the K.sub.AMF′ is not since the attacker does not know the secret and vice versa.”).
As per claim 42, Ben Henda in view of Goyal teaches the independent claim 33. Goyal teaches wherein the secret key is generated using attribute-based encryption (Goyal: sect. 4.2, 4.4, 4.4, 5.1, “Encryption (m, γ,PK): To encrypt a message m ∈ G2 under a set of attributes γ, choose a random value s ∈ Zp and publish the ciphertext as: E = (γ, E0 = me(g1, g2) s , E00 = g s , {Ei = T(i) s }i∈γ). Key Generation (T , MK,PK) The algorithm outputs a key which enables the user to decrypt a message encrypted under a set of attributes γ, if and only if T (γ) = 1.”….. The algorithm DecryptNode(E, D, x) then proceeds as follows: For all nodes z that are children of x, it calls DecryptNode(E, D, z) and stores the output as Fz. Let Sx be an arbitrary kx-sized set of child nodes z such that Fz 6= ⊥. If no such set exists then the node was not satisfied and the function returns ⊥. Otherwise, we compute:.. and return the result”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to modify Ben Henda’s slice-authentication procedure with Goyal’s attribute-based encryption key-policy mechanism in order to enforce slice admission using cryptographically bound UE attributes and slice-specific access policies, thereby allowing only devices whose attributes satisfy the slice policy to recover the slice access/security key. It will improve scalability and granularity of slice authorization, especially where different slices are intended for different classes of devices, services, or subscribers (Goyal, page 4 sect. 2).
As per claim 43, Ben Henda in view of Goyal teaches the independent claim 33. Goyal teaches wherein the wireless communications device is one among a plurality of wireless communications devices and wherein the secret key is a corresponding device- specific secret key; wherein each wireless communications device among the plurality of wireless communications devices has one or more attributes associated therewith, with at least one of the one or more attributes fulfilling an attribute-based access policy of the network slice; and wherein the method comprises sending a device-specific secret key to each wireless communications device among the plurality of wireless communications device, and sending the encrypted access key to the plurality of wireless communications devices, the encrypted access key being decryptable by each of the device-specific secret keys (Goyal: sect. 2, “Fine-grained access control systems facilitate granting differential access rights to a set of users and allow flexibility in specifying the access rights of individual users…. we introduce new techniques to implement fine grained access control. In our techniques, the data is stored on the server in an encrypted form while different users are still allowed to decrypt different pieces of data per the security policy. This effectively eliminates the need to rely on the storage server for preventing unauthorized data access…..In our construction each user’s key is associated with a tree-access structure where the leaves are associated with attributes. A user is able to decrypt a ciphertext if the attributes associated with a ciphertext satisfy the key’s access structure”).
As per claims 44 and 52, Ben Henda teaches a method performed by a wireless communications device, for authenticating the wireless communications device to a network slice of a communications network (Ben Henda: fig. 1, para[43], [90-91],“the terminal device 200 decides to use services provided by network slice B…. A network slice authentication procedure is triggered between the terminal device 200 and the communication network 100 during which signaling messages are exchanged with the target AMF 300b and possibly involving other network functions, here exemplified by the Authentication, Authorization and Accounting (AAA) entity 500 of network slice B”), the wireless communications device having one or more attributes associated with it (Ben Henda: para [90-92], “For the network slice authentication, it could be the AUSF or any other entity not necessarily under the control of the network operator since this would allow using other than the 3GPP credentials for primary access. In the case of EAP, if the used EAP method is key generating such as EAP-TLS or EAP-PSK then a successful authentication result in the establishment of shared keys, i.e. the MSK and the Extended MSK (EMSK) between the terminal device 200 and the AAA entity” the credential are treated as UE attributes for slice policy (credentials plus slice authorization), because the UE must satisfy slice B credentials), the method comprising:
receiving a secret key (Ben Henda: para[90-92], “In the case of EAP, if the used EAP method is key generating such as EAP-TLS or EAP-PSK then a successful authentication result in the establishment of shared keys, i.e. the MSK and the Extended MSK (EMSK) between the terminal device 200 and the AAA entity. The MSK is sent to the authenticator alongside the authentication result, i.e. EAP-SUCCESS in this case. A secret is thereby established between the terminal device 200 and the target AMF 300b following a successful authentication. In some examples, this secret could be a network slice authentication key denoted by K.sub.SA, or the MSK in case EAP is used. In other examples this secret could be a token or a random string, etc.” the keys are derived from the credentials);
receiving an encrypted access key for the network slice, such that the encrypted access key is decryptable via the secret key (Ben Henda: para[92-96], “S303: The target AMF 300b creates a new security context using the received secret. One possibility is to use directly the received secret if it is a key or to derive a new K.sub.AMF′ from it using a key derivation function such as the one used in 3GPP standards. In another example the target AMF 300b uses the current AMF key and the received secret to derive the K.sub.AMF′. This latter example protects against a key leakage in one domain (AAA or Source AMF domains)…. The target AMF 300b activates the new security context using the NAS SMC procedure described in aforementioned document 3GPP TS 33.501 with the difference that the target AMF 300b indicates in the downlink message (of this step) that the new security context is created based on the secret resulting from the successful slice authentication. This indication could be a Boolean flag, or a value generated using the slice authentication secret. For example, in the case of EAP, it could be a hash of the MSK key and possibly a freshness parameter, e.g. the NAS downlink count value used in this message, etc” the Examiner would like to notate that “such that the encrypted access key is decryptable via the secret key” is intended use).
decrypting the encrypted access key using the secret key to obtain the access key (Ben Henda: para [50-60], [90-94], UE derives and validates the slice access key using the secret, UE “creates a new security context” based on the slice-auth secret. UE verifies the NAS SMC message using data derived from the secret (hash of MSK). This result in UE obtaining K_AMF’, i.e., the access key. Thus decrypting an encrypted access key suing the secret. ); and
authenticating the wireless communications device to the network slice using the access key (Ben Henda: para[92-95], UE activate the new security context using K_AMF’, completing the slice-authentication procedure. Resulting keys enable secure access to slice B. Thus the UE is authenticated to the slice using the derived access key.).
Ben Henda does not explicitly teach at least one of the one or more attributes fulfilling an attribute-based access policy.
However, in the related art Goyal teaches at least one of the one or more attributes fulfilling an attribute-based access policy (Goyal: sect. 4.2 “In an ABE system, a user’s keys and ciphertexts are labeled with sets of descriptive attributes and a particular key can decrypt a particular ciphertext only if there is a match between the attributes of the ciphertext and the user’s key… We develop a much richer type of attribute-based encryption cryptosystem and demonstrate its applications. In our system each ciphertext is labeled by the encryptor with a set of descriptive attributes Each private key is associated with an access structure that specifies which type of ciphertexts the key can decrypt. We call such a scheme a Key-Policy Attribute-Based Encryption (KP-ABE)…In our construction each user’s key is associated with a tree-access structure where the leaves are associated with attributes”, sect. 5.1, “Encryption (m, γ,PK): To encrypt a message m ∈ G2 under a set of attributes γ, choose a random value s ∈ Zp and publish the ciphertext as: E = (γ, E0 = me(g1, g2) s , E00 = g s , {Ei = T(i) s }i∈γ). Key Generation (T , MK,PK) The algorithm outputs a key which enables the user to decrypt a message encrypted under a set of attributes γ, if and only if T (γ) = 1.”….. The algorithm DecryptNode(E, D, x) then proceeds as follows: For all nodes z that are children of x, it calls DecryptNode(E, D, z) and stores the output as Fz. Let Sx be an arbitrary kx-sized set of child nodes z such that Fz 6= ⊥. If no such set exists then the node was not satisfied and the function returns ⊥. Otherwise, we compute:.. and return the result”);
the secret key generated using the one or more attributes ( Goyal: section 4.4, sect. 8, “The simulator B runs A. A chooses the set of attributes γ it wishes to be challenged upon….A adaptively makes requests for the keys corresponding to any access structures T such that the challenge set γ does not satisfy T . Suppose A makes a request for the secret key for an access structure T where T (γ) = 0. To generate the secret key, B needs to assign a polynomial Qx of degree dx for every node in the access tree T…..The key corresponding to each leaf node is given using its polynomial as follows. Let i = att(x). Dx = g Qx(0) ti = g bqx(0) ri = B qx(0) ri g Qx(0) ti = g bqx(0) bβi = g qx(0) βi if att(x) ∈ γ, otherwise” see also 4.2, and 5.1)
the encrypted access key being encrypted using the access policy ( Goyal: sect. 4.2, 5.1, 8, “Each user is subscribed to a different “package”. The user package describes an access policy, which along with the set of attributes describing any particular item being broadcast,….Our KP-ABE system naturally offers a targeted broadcast system. A new symmetric key would be chosen and used to encrypt each item being broadcast, and then the KP-ABE system would be used to encrypt the symmetric key with the attributes associated with the item being broadcast.”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to modify Ben Henda’s slice-authentication procedure with Goyal’s attribute-based encryption key-policy mechanism in order to enforce slice admission using cryptographically bound UE attributes and slice-specific access policies, thereby allowing only devices whose attributes satisfy the slice policy to recover the slice access/security key. It will improve scalability and granularity of slice authorization, especially where different slices are intended for different classes of devices, services, or subscribers (Goyal, page 4 sect. 2).
Furthermore, Ben Henda also teaches the hardware components of claim 52 such a processor; and a memory (Ben Henda: fig. 8, para[133], “Processing circuitry 210 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1210a (as in FIG. 12), e.g. in the form of a storage medium 233”).
As per claim 45, The method according to claim 44, wherein the network slice is a dynamically created network slice or a temporary network slice (Ben Henda: para[91], slice B is selected dynamically on-demand, this implies dynamic slice assignment).
As per claim 46, The method according to claim 44, wherein the method further comprises receiving a notification to authenticate to the network slice and an identifier of the network slice (Ben Henda: para[90-91], “The terminal device 200 decides to use services provided by network slice B. This could possibly result in additional signaling between the terminal device 200 and the Core Network and within the Core Network to redirect the terminal device 200 to the correct Network Function handling the access to network slice B. It is here assumed that this Network Function is the Target AMF 300b.” this requires the UE being notified of the target slice and its identifier (slice B)).
As per claim 47, The method according to claim 44, further comprising establishing a secure connection with a slice manager of the communications network, wherein the secret key is received from the slice manager using the secure connection (Ben Henda: para[90-93], EAP-based sluice authentication requires a secure, integrity-protected exchange. NAS SMC message is integrity protected using slice-auth secret).
As per claim 48, The method according to claim 44, further comprising transmitting the one or more attributes associated with the wireless communications device to a slice manager of the communications network (Ben Henda: para[91], “A network slice authentication procedure is triggered between the terminal device 200 and the communication network 100 during which signaling messages are exchanged with the target AMF 300b and possibly involving other network functions…In the case of EAP, if the used EAP method is key generating such as EAP-TLS or EAP-PSK then a successful authentication result in the establishment of shared keys, i.e. the MSK and the Extended MSK (EMSK) between the terminal device 200 and the AAA entity.”, slice authentication uses EAP-TLS/EAP-PSK, where the UE provide credential attributes (certificate, PSK identity) in the request. See also Goyal section A.2).
Claims 40, 49-50 are rejected under 35 U.S.C. 103 as being unpatentable over Ben Henda (U.S. Application US 20220070157 A1; Hereinafter “Ben Henda”) in view of Goyal et al. (“Attribute-Based Encryption for Fine-Grained Access Control of Encrypted Data” CCS 2006; Hereafter “Goyal”) and Gigov et al. (U.S. Application US 20210374265 A1; Hereinafter “Gigov”).
As per claim 40, Ben Henda in view of Goyal teaches the dependent claim 38.
Ben Henda in view of Goyal does not explicitly teach verifying that the one or more attributes associated with the wireless communications device originate from a trusted application of the wireless communication device.
However, in the related art, Gigov teaches verifying that the one or more attributes associated with the wireless communications device originate from a trusted application of the wireless communications device (Gigov: para[76-79], “The Key Generation phase begins when the sender receives a set of attributes from the receiver. The sender first verifies the attributes: if the attributes supplied by the receiver do not align with the sender's expectations, the sender may terminate the process. Otherwise, using the verified attributes and the Master Secret Key, the sender generates a Private Key corresponding to these attributes (also referred to herein as a “Private ABE Key”) and communicates the Private Key to the receiver.”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to have combine the modified teaching of Ben Henda and verify the attributes as discussed in Gigov, it will minimize the attack surfaces available for malicious unauthorized access attempts while providing granular access control for file contents sharing (Goyal, para [119]).
As per claim 49, Ben Henda in view of Goyal teaches the independent claim 44. Ben Henda discloses EAP-TLS and EAP-TLS is based on certificates stored in secure storage (SIM, secure element TEE)).
Gigov teaches wherein the one or more attributes associated with the wireless communications device are stored by a trusted entity of the wireless communications device, wherein the trusted entity is trusted by a manager of the communications network (Gigov: para [65-67], “the secure sharing module 170 may include a trusted viewer 180 for securely viewing (or otherwise making available to a user) contents of files 126 shared by the sender device 120. The storage units 154 may be used in some embodiments to store encrypted data used by the secure sharing module 170, including encrypted files 174, encrypted files encryption keys 176, and encrypted private attribute-based encryption (ABE) keys 178, as described further below.”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to have combine the modified teaching of Ben Henda and verify the attributes as discussed in Gigov, it will minimize the attack surfaces available for malicious unauthorized access attempts while providing granular access control for file contents sharing (Goyal, para [119]).
As per claims 50, Ben Henda in view of Goyal teaches the dependent claim 49.
Ben Henda in view of Goyal does not explicitly teach wherein the trusted entity comprises an application of the wireless communications device.
However, in the related art, Gigov, wherein the trusted entity comprises an application of the wireless communications device (Gigov: para[135-137], “The sender device 120 and receiver device 150 include a sender secure sharing module 140 and receiver secure sharing module 170, respectively, as described above with reference to FIGS. 2-3. In some embodiments, these modules 140, 170 are trusted software applications signed cryptographically by a trusted authority.”).
Therefore, it would have been obvious to a person having ordinary skill in the art, before the effective filling date of the claimed invention, to have combine the modified teaching of Ben Henda and verify the attributes as discussed in Gigov, it will minimize the attack surfaces available for malicious unauthorized access attempts while providing granular access control for file contents sharing (Goyal, para [119]).
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LYDIA L NOEL whose telephone number is (571)272-1628. The examiner can normally be reached Monday - Friday 9:00 - 5:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571)-270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/L.L.N./Examiner, Art Unit 2437
/ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437