Prosecution Insights
Last updated: October 01, 2026
Application No. 18/724,121

AUTHENTICATION SUPPORT FOR AN ELECTRONIC DEVICE TO CONNECT TO A TELECOMMUNICATIONS NETWORK

Non-Final OA §103
Filed
Jun 25, 2024
Priority
Dec 27, 2021 — provisional 63/266,036 +2 more
Examiner
ARYAL, AAYUSH
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
Nederlandse Organisatie Voor Toegepast-natuurwetenschappelijk Onderzoek Tno
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
1m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
98 granted / 113 resolved
+28.7% vs TC avg
Moderate +8% lift
Without
With
+8.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
8 currently pending
Career history
124
Total Applications
across all art units

Statute-Specific Performance

§101
3.7%
-36.3% vs TC avg
§103
60.1%
+20.1% vs TC avg
§102
19.8%
-20.2% vs TC avg
§112
11.4%
-28.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 113 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/26/2024 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Objections Claim 18 is objected to because of the following informalities: Regarding Claim 18, applicant uses a ‘;’ instead of ‘:’ after the limitation “The authentication support system according to claim 17, wherein;” Appropriate correction is required. Allowable Subject Matter Claims 6-8,13 and 19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Regarding Claims 6 and 7 prior art does not explicitly disclose the electronic device is configured to include the validity parameter in the network access request to the second network and the telecommunication system is configured to receive and process the validity parameter; the electronic device and/or the authentication support system is configured to provide the validity parameter to the second network after transmission of the network access request from the electronic device; the telecommunication system is configured to refuse the network access request based on the validity parameter. Claim 7 is allowed due to its dependency to Claim 6. Regarding Claim 8, prior art does not explicitly disclose the authentication support system is configured to at least partly encrypt the derived device identifier and/or derived device credential and, prestore the at least partly encrypted derived device identifier and/or derived device credential and to transmit the at least partly encrypted derived device identifier and/or the at least partly encrypted derived device credential over the first network to the electronic device; Regarding Claim 13, prior art does not explicitly disclose the telecommunication system is configured to participate in a re- authentication procedure with the electronic device using the derived device credential, and wherein, the telecommunication system is configured to re-calculate the derived device credential for the re-authentication procedure based on the received derived device identifier. Regarding Claim 19, prior art does not explicitly disclose the authentication support system is configured to perform the authentication support function by executing a one-way function to obtain the derived device credential from at least the gateway device credential and the electronic device identifier; the telecommunication system is configured to execute a one-way function to obtain the derived device credential from at least the gateway device credential and the electronic device identifier. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1,5,9,11-12,14,17-18, 20-23 are rejected under 35 U.S.C. 103 as being unpatentable over Kunz (WO20210245629) in view of Ahmavaara (WO2010056944) herein after ‘Kalle’. Regarding Claim 1, Kunz discloses and wherein the gateway device identifier and the associated at least one gateway device credential are obtainable by the authentication support system, (Paragraph [0068] E.N. The Service Provider (gateway) send the standalone non-public network (SNPN) verification information regarding the user equipment (UE), See Figure 2) wherein the electronic device is configured to: [[-]] provide an electronic device identifier over the first network to the authentication support system; (Paragraph [0066] E.N. the UE sends a Registration Request with the NAI (e.g., in the form of ‘pseudonym@realm’ or ‘usemame@realm’) of the Service Provider as UE identity to the AMF/SEAF) [[-]] receive over the first network, at least: [[i)]] a derived device identifier obtained from the authentication support system based on at least the gateway device identifier and the electronic device identifier; [[ii)]] a derived device credential obtained from the authentication support system based on at least the gateway device credential and the electronic device identifier; (Figure 4A and Paragraph [0070] E.N. The AAA Server may follow the normal key derivation and derives the Master Key (“MK”) from CK', IK', e.g., using the input to the key derivation according to IETF RFC 5448, i.e., MK = PRF' (IK' | CK', "EAR-AKA' " | Identity), with PRF as Pseudo- Random number Function and Identity as username in the subscription profile of the Service Provider, where the symbol ‘|’ indicates a concatenation operation to build the input string.) [[-]] store the derived device identifier and derived device credential in the electronic device; (Figure 2 Element 225 E.N. The keys are sent to the UE after the authentication process) [[-]] include the derived device identifier received over the first network in a network access request; [[-]] transmit the network access request including the derived device identifier over the second network to the telecommunication system; (Figure 4A E.N. The procedure for registration using an external authentication and key agreement between a user equipment and a service provider and SNPN is disclosed) [[-]] participate in an authentication procedure with the telecommunication system over the second network after transmitting the network access request and use the derived device credential in the authentication procedure with the telecommunication system. (Figure 4A E.N. The Service Provider and the SNPN communicate and determine if the user is able to access the said subscription network.) Kunz does not, but in related art, Kalle discloses An electronic device configured to communicate over a first network with an authentication support system and over a second network with a telecommunication system via a gateway device, (Figure 3 E.N. A diagram disclosing establishing a data connection between a remote station and a wireless network is shown.) wherein the electronic device has no subscription for access to the second network and the gateway device has a subscription to access the second network, (Paragraph [0047] E.N. For example, an internet retailer may desire to provide data connectivity to its website to remote stations, such as netbooks having equipment for cellular data connectivity, that have no subscription relationship with a provider of a wireless network. The internet retailer is willing to compensate the wireless provider for provisioning a data connection that provides access to just its web site without concern for the network's authentication of the remote device. the subscription including a gateway device identifier and at least one associated gateway device credential known in the telecommunication system, (Paragraph [0031] E.N. Based on determining that the remote station is a non-subscribing remote station that does not have an existing subscription relationship that supports establishment of a data connection using the wireless network, an initial connection identity (ICI) value is sent to the wireless network, wherein the ICI value includes a characteristic associated with a non-subscribing remote station.) Therefore, it would be obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to have modified Kunz to incorporate the teaching of Kalle because Kunz does not explicitly disclose devices not having subscription to access certain networks which is disclosed by Kalle. Incorporating the teachings of Kalle to Kunz allows for the user device/equipment to access networks they do not have a subscription to through a secure manner. Regarding Claim 5, Kunz in view of Kalle discloses the electronic device of Claim 1. Kunz further discloses wherein the derived device identifier is based on at least the gateway device identifier, the electronic device identifier and an additional changeable value and/or the derived device credential is based on at least the gateway device credential, the electronic device identifier and the additional changeable value. (Paragraph [0063] E.N. The Service Provider with its own identifier (i.e., SP-ID) has a business relationship (i.e., service agreement) with the SNPN and is allowed to use a certain number of subscriptions in the SNPN, identified by individual UE IDs which may be, for example, a Subscriber Permanent Identifier (“SUPI”), an International Mobile Subscriber Identifier (“IMSI”), Generic Public Subscription Identifier (“GPSI”), etc. The UE ID represents the temporary subscription identifier in the SNPN for the UE. The UE is a subscriber with the Service Provider, and both have their shared set of credentials which may or may not be stored in the Universal Subscriber Identity Module (“USIM”) in the UE. Also, this credentials may be a username/password, public/private key set, certificates, etc.) Regarding Claim 9, Kunz in view of Kalle discloses the electronic device of Claim 1. Kunz further discloses wherein the electronic device is configured to provide the electronic device identifier to the authentication support system in a secure manner over the first network; [[-]] the authentication support system is configured to receive the electronic device identifier from the electronic device in a secure manner over the first network. (Paragraph [0066] E.N. the UE sends a Registration Request with the NAI (e.g., in the form of ‘pseudonym@realm’ or ‘usemame@realm’) of the Service Provider as UE identity to the AMF/SEAF. The username of the NAI maybe set to anonymous if the EAP method of the Service Provider supports privacy, or to a pre-configured pseudonym or the subscription identifier of the Service Provider.) Regarding Claim 11, Kunz in view of Kalle discloses the electronic device of Claim 1. Kunz further discloses wherein the authentication support system is accommodated in the gateway device; or[[-]] the authentication support system is configured to obtain the gateway device identifier and the at least one associated gateway device credential over the first network. (Paragraph [0101] and Figure 4A E.N. the AAA Server sends the result of the authentication back in an authentication response to the AUP/AUSF. This message may include the CK’, IK’, validity time, Routing ID and, the NAI with the real username in the subscription profile of the AAA Server of the UE.) Regarding Claim 12, Kunz in view of Kalle discloses the electronic device of Claim 1. Kunz further discloses wherein the electronic device is configured to construct the network access request to enable the telecommunication system to recognize the derived device identifier in the network access request; [[-]] the telecommunication system is configured to recognize the derived device identifier in the received network access request. (Figure 2 and Paragraph [0067] E.N. the AMF/SEAF detects based on the realm of the NAI that the Registration Request is not from a subscriber of the SNPN but from a Service Provider. The AMF/SEAF authorizes the request by verifying the realm of the NAI and whether the SNPN has an active agreement with this Service Provider. The AMF/SEAF forwards the request to the AUP/AUSF which may be preconfigured for handling requests towards external Service Providers) Regarding Claim 14, Kunz in view of Kalle discloses the electronic device of Claim 1. Kunz further discloses wherein the second network is a 5G telecommunications network and wherein at least one of the following applies:[[-]] the gateway device identifier is a Subscription Permanent Identifier, SUPI; [[-]] the network access request is a registration request from the electronic device to a system running an Access and Mobility management Function, AMF, in the 5G telecommunications network; [[-]] the derived device identifier has a SUPI format or a concealed SUPI format, SUCI, wherein, (Paragraph [0063] E.N. The Service Provider with its own identifier (i.e., SP-ID) has a business relationship (i.e., service agreement) with the SNPN and is allowed to use a certain number of subscriptions in the SNPN, identified by individual UE IDs which may be, for example, a Subscriber Permanent Identifier (“SUPI”), an International Mobile Subscriber Identifier (“IMSI”), Generic Public Subscription Identifier (“GPSI”), etc. The UE ID represents the temporary subscription identifier in the SNPN for the UE. The UE is a subscriber with the Service Provider, and both have their shared set of credentials which may or may not be stored in the Universal Subscriber Identity Module (“USIM”) in the UE.) Regarding Claim 17, Kunz discloses obtain the gateway device identifier and at least one associated gateway device credential of the gateway device, perform an authentication support function, for the electronic device to access the second network using a network access request, to obtain at least: (Paragraph [0068] E.N. The Service Provider (gateway) send the standalone non-public network (SNPN) verification information regarding the user equipment (UE), See Figure 2) a derived device identifier obtained by the authentication support function based on at least the gateway device identifier and the electronic device identifier; a derived device credential obtained by the authentication support function based on at least the gateway device credential and the electronic device identifier; transmit the derived device identifier and the derived device credential over the first network to the electronic device. (Figure 4A E.N. The procedure for registration using an external authentication and key agreement between a user equipment and a service provider and SNPN is disclosed) Kunz does not, but in related art, Kalle discloses An authentication support system configured to communicate over a first network with an electronic device, wherein the electronic device is able to communicate with a telecommunication system over a second network via a gateway device and has no subscription for access to the second network, (Figure 3 E.N. A diagram disclosing establishing a data connection between a remote station and a wireless network is shown.) wherein the gateway device has a subscription for access to the second network, the subscription including a gateway device identifier and at least one associated gateway device credential known in the telecommunication system, wherein the authentication support system is configured to: receive an electronic device identifier from the electronic device over the first network; (Paragraph [0031] E.N. Based on determining that the remote station is a non-subscribing remote station that does not have an existing subscription relationship that supports establishment of a data connection using the wireless network, an initial connection identity (ICI) value is sent to the wireless network, wherein the ICI value includes a characteristic associated with a non-subscribing remote station.) Therefore, it would be obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to have modified Kunz to incorporate the teaching of Kalle because Kunz does not explicitly disclose devices not having subscription to access certain networks which is disclosed by Kalle. Incorporating the teachings of Kalle to Kunz allows for the user device/equipment to access networks they do not have a subscription to through a secure manner. Regarding Claim 18, Kunz in view of Kalle discloses the authentication support system of claim 17. Kunz further discloses wherein; the authentication support system is configured to store at least one of the derived device identifier, the derived device credential and a validity time parameter indicative of a validity time of at least one of the derived device identifier and the derived device credential, and wherein, the authentication support system is configured to provide at least one of the stored derived device identifier, the derived device credential and validity time parameter to the telecommunication system in a procedure separate from the authentication procedure; the telecommunication system is configured to obtain at least one of the stored derived device identifier, the derived device credential and a validity time parameter indicative of a validity time of at least one of the derived device identifier and the derived device credential from the authentication support system in a procedure separate from the authentication procedure. (Figure 4A, Paragraph [0073,0078] E.N. The AAA Server 209 may select the stored Routing ID for the SNPN as well as the validity time for one authentication period, i.e., after which the AMF/SEAF should trigger a re-authentication request. The AMF/SEAF may store the UE ID and the NAI from the Service Provider (e.g., usemame@realm) for potential re -authentications after expiry of the validity time. The AMF/SEAF may request the subscription profile from the UDM either based on the NAI or the UE ID.) Regarding Claim 20, Kunz discloses A telecommunication system for a second network storing a subscription of a gateway device, the subscription including a gateway device identifier and at least one associated gateway device credential, wherein the telecommunication system is configured to: WO20210245629 (Paragraph [0066] E.N. the UE sends a Registration Request with the NAI (e.g., in the form of ‘pseudonym@realm’ or ‘usemame@realm’) of the Service Provider as UE identity to the AMF/SEAF) recognize a derived device identifier in the network access request, wherein the derived device identifier is obtained based on at least the gateway device identifier and an electronic device identifier in an authentication support system communicating with the electronic device over a first network; determine the gateway device credential using at least the derived device identifier and the gateway device identifier; obtain a derived device credential for the electronic device based on at least the gateway device credential and the electronic device identifier; (Figure 4A E.N. The procedure for registration using an external authentication and key agreement between a user equipment and a service provider and SNPN is disclosed) participate in an authentication procedure with the electronic device over the second network after receiving the network access request and use the derived device credential in the authentication procedure with the electronic device. (Figure 4A E.N. The Service Provider and the SNPN communicate and determine if the user is able to access the said subscription network.) Kunz does not, but in related art, Kalle discloses receive a network access request over the second network from an electronic device not having a subscription for access to the second network; (Paragraph [0047] E.N. For example, an internet retailer may desire to provide data connectivity to its website to remote stations, such as netbooks having equipment for cellular data connectivity, that have no subscription relationship with a provider of a wireless network. The internet retailer is willing to compensate the wireless provider for provisioning a data connection that provides access to just its web site without concern for the network's authentication of the remote device. Therefore, it would be obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to have modified Kunz to incorporate the teaching of Kalle because Kunz does not explicitly disclose devices not having subscription to access certain networks which is disclosed by Kalle. Incorporating the teachings of Kalle to Kunz allows for the user device/equipment to access networks they do not have a subscription to through a secure manner. Examiner Note: Claims 21-23 contain the exact same limitations of Claims 1, 17 and 20 and are just combined to make a new independent claim. Regarding Claim 21, Claim 21 is rejected under 35 U.S.C. 103 as being unpatentable over Kunz in view of Kalle for the reasons set forth above with respect to claims 1 and 17. Claim 21 includes the limitations of Claims 1 and 17 combined and the combination would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to have modified Kunz to incorporate the teaching of Kalle because Kunz does not explicitly disclose devices not having subscription to access certain networks which is disclosed by Kalle. Incorporating the teachings of Kalle to Kunz allows for the user device/equipment to access networks they do not have a subscription to through a secure manner. Regarding Claim 22, Claim 22 is rejected under 35 U.S.C. 103 as being unpatentable over Kunz in view of Kalle for the reasons set forth above with respect to claims 1 and 20. Claim 22 includes the limitations of Claims 1 and 20 combined and the combination would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to have modified Kunz to incorporate the teaching of Kalle because Kunz does not explicitly disclose devices not having subscription to access certain networks which is disclosed by Kalle. Incorporating the teachings of Kalle to Kunz allows for the user device/equipment to access networks they do not have a subscription to through a secure manner. Regarding Claim 23, Claim 23 is rejected under 35 U.S.C. 103 as being unpatentable over Kunz in view of Kalle for the reasons set forth above with respect to claims 1, 17 and 20. Claim 23 includes the limitations of Claims 1, 17 and 20 combined and the combination would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to have modified Kunz to incorporate the teaching of Kalle because Kunz does not explicitly disclose devices not having subscription to access certain networks which is disclosed by Kalle. Incorporating the teachings of Kalle to Kunz allows for the user device/equipment to access networks they do not have a subscription to through a secure manner. Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Kunz (WO20210245629) in view of Ahmavaara (WO2010056944) herein after ‘Kalle’ and in further view of Smith (US20100254395). Regarding Claim 10, Kunz in view of Kalle discloses the electronic device of claim 1. Kunz and Kalle do not, but in related art, Smith discloses wherein the first network is a local network and the electronic device identifier is a local network identifier, such as a MAC address, of the electronic device. (Paragraph [0045] E.N. The local identifier may be a hardware identifier such as a media access control (MAC) address, a local network address such as an IP address, or any other device suitable for indicating a particular tactical node.) Therefore, it would be obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to have modified Kunz in view of Kalle to incorporate the teachings of Smith because Kunz and Kalle do not explicitly disclose MAC address which is disclosed by Smith. Incorporating the teachings of Smith to Kunz and Kalle allows for the use of MAC address to be some form of an identifier to the user device in order for the device to access networks that require subscriptions. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to AAYUSH ARYAL whose telephone number is (571)272-2838. The examiner can normally be reached 8:00 a.m. - 5:30 p.m.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AAYUSH ARYAL/Examiner, Art Unit 2435 /AMIR MEHRMANESH/Supervisory Patent Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Jun 25, 2024
Application Filed
Aug 18, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743541
MOUNTLESS QUERYING OF LISTING DATA
2y 3m to grant Granted Sep 22, 2026
Patent 12730894
PERSONALIZATION OF A SECURE ELEMENT
2y 7m to grant Granted Sep 08, 2026
Patent 12717948
ENFORCING LOCATION-BASED DATA PRIVACY RULES ACROSS NETWORKED WORKLOADS
2y 5m to grant Granted Aug 25, 2026
Patent 12705335
JOURNALING SYSTEM WITH SEGREGATED DATA ACCESS
2y 4m to grant Granted Aug 11, 2026
Patent 12705406
INFORMATION PROCESSING METHOD AND DEVICE AND PROCESSOR
2y 0m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
95%
With Interview (+8.2%)
2y 4m (~1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 113 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month