Prosecution Insights
Last updated: October 02, 2026
Application No. 18/769,995

METHOD AND APPARATUS FOR SECURITY CONTEXT HANDLING DURING INTER-SYSTEM CHANGE

Non-Final OA §102
Filed
Jul 11, 2024
Priority
Oct 04, 2018 — nonprovisional of PCTFI2018050714 +1 more
Examiner
SAMLUK, JESSE PAUL
Art Unit
2411
Tech Center
2400 — Computer Networks
Assignee
Nokia Corporation
OA Round
1 (Non-Final)
47%
Grant Probability
Moderate
1-2
OA Rounds
1y 1m
Est. Remaining
93%
With Interview

Examiner Intelligence

Grants 47% of resolved cases
47%
Career Allowance Rate
27 granted / 58 resolved
-11.4% vs TC avg
Strong +46% interview lift
Without
With
+46.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
27 currently pending
Career history
108
Total Applications
across all art units

Statute-Specific Performance

§101
0.4%
-39.6% vs TC avg
§103
72.9%
+32.9% vs TC avg
§102
19.7%
-20.3% vs TC avg
§112
7.1%
-32.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 58 resolved cases

Office Action

§102
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement Acknowledgment is made of the information disclosure statements filed on May 13, 2025, November 4, 2025, January 21, 2026, February 25, 2026, June 15, 2026, and July 10, 2026. U.S. patent applications, foreign patents, and non-patent literature documents have been considered. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-18 are rejected under 35 U.S.C. 102(a)(1) as being unpatentable by "3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals;Non-Access-Stratum (NAS) protocol for 5G System (5GS);Stage 3 (Release 15)", 3GPP TS 24.501, V15.1.0, September 2018, pp. 1-338; herein referred to as “3GPP TS 24.501”. This reference is provided in the information disclosure statement dated May 13, 2025. Regarding Claim 1, 3GPP TS 24.501 discloses: An access and mobility management function of a 5G system, comprising: at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the access and mobility management function at least to perform: in an idle mode inter-system change of user equipment while in single registration mode: receiving from the user equipment a registration request message without integrity protection and encryption (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. (§ 4.8.1, p. 53) In order to interwork with E-UTRAN connected to EPC, the UE supporting both S1 mode and N1 mode can operate in single-registration mode or dual-registration mode (see 3GPP TS 23.501 [8]). Support of single-registration mode is mandatory for UEs supporting both S1 mode and N1 mode. and deriving a fresh 5G non-access stratum security context when interworking without a signaling channel between mobility management entities of an evolved packet system and the 5G system is not supported (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Note: Per Applicant’s specification paragraphs [0082] and [0083], after the reception of the registration request message without integrity protection and encryption (as shown here in the reference applied), having the AMF creating a fresh mapped security context or trigger an authentication and agreement is indicative of having internetworking without N26 not being supported. and an evolved packet system security context received from a source mobility management entity of the evolved packet system does not include non-access stratum security algorithms set to a null integrity protection algorithm and a null ciphering algorithm. (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Note: Since there is no integrity protection or encryption, the are no algorithms able to be set. Regarding Claim 2, 3GPP TS 24.501 discloses: The access and mobility management function of claim 1, wherein the deriving comprises: creating a fresh mapped non-access stratum security context. (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Regarding Claim 3, 3GPP TS 24.501 discloses: The access and mobility management function of claim 1, wherein the deriving comprises: creating a fresh native non-access stratum security context by triggering a primary authentication and key agreement procedure. (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Regarding Claim 4, 3GPP TS 24.501 discloses: The access and mobility management function of claim 1, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the access and mobility management function at least to perform: creating a fresh native non-access stratum security context by triggering a primary authentication and key agreement procedure when interworking without the signaling channel between the mobility management entities of the evolved packet system and the 5G system is not supported, (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Note: Per Applicant’s specification paragraphs [0082] and [0083], after the reception of the registration request message without integrity protection and encryption (as shown here in the reference applied), having the AMF creating a fresh mapped security context or trigger an authentication and agreement is indicative of having internetworking without N26 not being supported. and the evolved packet system security context received from the source mobility management entity of the evolved packet system includes the non-access stratum security algorithms set to the null integrity protection algorithm and the null ciphering algorithm. (§ 4.4.2.1, pages 29- 30) As described in the subclause 4.8 in order to interwork with E-UTRAN connected to EPC, the UE supporting both S1 mode and N1 mode can operate in either single-registration mode or dual-registration mode. A UE operating in dual-registration mode shall independently maintain and use both EPS security context (see 3GPP TS 24.301 [15]) and 5G NAS security context. During inter-system change to S1 mode, the UE operating in dual-registration mode shall take into use an EPS security context and follow the handling of this security context as specified in 3GPP TS 24.301 [15]. c) When the AMF and the UE create a 5G NAS security context using null integrity and null ciphering algorithm during an initial registration procedure for emergency services, or a registration procedure for mobility and periodic registration update for a UE that has a PDU session for emergency services (see subclause 5.4.2.2), the AMF and the UE shall delete the previous current 5G NAS security context; d) When a new mapped 5G NAS security context or 5G NAS security context created using null integrity and null ciphering algorithm is taken into use during the inter-system change from S1 mode to N1 mode, the AMF and the UE shall not delete the previously current native 5G NAS security context, if any. Instead, the previously current native 5G NAS security context shall become a non-current native 5G NASs security context, and the AMF and the UE shall delete any partial native 5G NAS security context; Regarding Claim 5, 3GPP TS 24.501 discloses: The access and mobility management function of claim 1, wherein the at least one memory and the computer program code are further configured to, with the at least one processor, cause the access and mobility management function at least to perform: triggering a primary authentication and key agreement procedure when interworking without the signaling channel between the mobility management entities of the evolved packet system and the 5G system is supported. (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Note: Per Applicant’s specification paragraphs [0082] and [0084], after the reception of the registration request message without integrity protection and encryption (as shown here in the reference applied), having the AMF trigger an authentication and agreement is indicative of having internetworking without N26 being supported. Regarding Claim 6, 3GPP TS 24.501 discloses: The access and mobility management function of claim 1, wherein the signaling channel comprises an N26 interface. (§ 5.1.4.2, p. 65) Coordination between 5GMM and EMM with N26 interface At inter-system change from S1 mode to N1 mode, the UE shall enter substates 5GMM-REGISTERED.NORMAL-SERVICE and EMM-REGISTERED.NO-CELL-AVAILABLE and initiate a registration procedure for mobility and periodic registration update indicating "mobility registration updating" in the 5GS registration type IE of the REGISTRATION REQUEST message (see subclause 5.5.1.3). (§ 5.1.4.2, p. 65). Regarding Claim 7, Claim 7 is rejected on the same grounds of rejection set forth in claim 1. 3GPP TS 24.501 discloses: A method in an access and mobility management function of a 5G system, the method comprising: in an idle mode inter-system change of user equipment while in single registration mode: receiving, at the access and mobility management function from the user equipment, a registration request message without integrity protection and encryption (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. (§ 4.8.1, p. 53) In order to interwork with E-UTRAN connected to EPC, the UE supporting both S1 mode and N1 mode can operate in single-registration mode or dual-registration mode (see 3GPP TS 23.501 [8]). Support of single-registration mode is mandatory for UEs supporting both S1 mode and N1 mode. deriving, at the access and mobility management function, a fresh 5G non-access stratum security context when interworking without a signaling channel between mobility management entities of an evolved packet system and the 5G system is not supported (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Note: Per Applicant’s specification paragraphs [0082] and [0083], after the reception of the registration request message without integrity protection and encryption (as shown here in the reference applied), having the AMF creating a fresh mapped security context or trigger an authentication and agreement is indicative of having internetworking without N26 not being supported. and an evolved packet system security context received from a source mobility management entity of the evolved packet system does not include non-access stratum security algorithms set to a null integrity protection algorithm and a null ciphering algorithm. (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Note: Since there is no integrity protection or encryption, the are no algorithms able to be set. Regarding Claim 8, Claim 8 is rejected on the same grounds of rejection set forth in claim 2. Regarding Claim 9, Claim 9 is rejected on the same grounds of rejection set forth in claim 3. Regarding Claim 10, Claim 10 is rejected on the same grounds of rejection set forth in claim 4. Regarding Claim 11, Claim 11 is rejected on the same grounds of rejection set forth in claim 5. Regarding Claim 12, Claim 12 is rejected on the same grounds of rejection set forth in claim 6. Regarding Claim 13, Claim 13 is rejected on the same grounds of rejection set forth in claim 1. 3GPP TS 24.501 discloses: A computer readable medium embodying programmed instructions which, when executed by a processor, are operable for performing a method in an access and mobility management function of a 5G system, the method comprising: in an idle mode inter-system change of user equipment while in single registration mode: receiving, at the access and mobility management function from the user equipment, a registration request message without integrity protection and encryption; (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. (§ 4.8.1, p. 53) In order to interwork with E-UTRAN connected to EPC, the UE supporting both S1 mode and N1 mode can operate in single-registration mode or dual-registration mode (see 3GPP TS 23.501 [8]). Support of single-registration mode is mandatory for UEs supporting both S1 mode and N1 mode. deriving, at the access and mobility management function, a fresh 5G non-access stratum security context when interworking without a signaling channel between mobility management entities of an evolved packet system and the 5G system is not supported (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Note: Per Applicant’s specification paragraphs [0082] and [0083], after the reception of the registration request message without integrity protection and encryption (as shown here in the reference applied), having the AMF creating a fresh mapped security context or trigger an authentication and agreement is indicative of having internetworking without N26 not being supported. and an evolved packet system security context received from a source mobility management entity of the evolved packet system does not include non-access stratum security algorithms set to a null integrity protection algorithm and a null ciphering algorithm. (§ 4.4.2.5, p. 32-33) When a UE in 5GMM-IDLE mode establishes a new NAS signalling connection, has no current 5G NAS security context and performs a registration procedure after an inter-system change in idle mode from S1 mode to N1 mode, the UE shall send the REGISTRATION REQUEST message without integrity protection and encryption. The AMF may create a fresh mapped 5G NAS security context or may trigger a primary authentication and key agreement procedure to create a fresh native 5G NAS security context. The newly created 5G NAS security context is taken into use by initiating a security mode control procedure and this context becomes the current 5G NAS security context in both the UE and the AMF. This re-establishes the secure exchange of NAS messages. Note: Since there is no integrity protection or encryption, the are no algorithms able to be set. Regarding Claim 14, Claim 14 is rejected on the same grounds of rejection set forth in claim 2. Regarding Claim 15, Claim 15 is rejected on the same grounds of rejection set forth in claim 3. Regarding Claim 16, Claim 16 is rejected on the same grounds of rejection set forth in claim 4. Regarding Claim 17, Claim 17 is rejected on the same grounds of rejection set forth in claim 5. Regarding Claim 18, Claim 18 is rejected on the same grounds of rejection set forth in claim 6. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JESSE P. SAMLUK whose telephone number is (571)270-5607. The examiner can normally be reached M-F 9-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Derrick Ferris can be reached on 571-272-3123. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JESSE P. SAMLUK/Examiner, Art Unit 2411 /DERRICK W FERRIS/Supervisory Patent Examiner, Art Unit 2411
Read full office action

Prosecution Timeline

Jul 11, 2024
Application Filed
Sep 11, 2026
Non-Final Rejection mailed — §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12745238
Uplink Data Transmission for Random Access of Reduced Capability Device
4y 8m to grant Granted Sep 22, 2026
Patent 12720456
TIMING ADVANCE INDICATION METHOD, COMMUNICATION APPARATUS, AND STORAGE MEDIUM
4y 4m to grant Granted Aug 25, 2026
Patent 12696187
COMPONENT CARRIER GROUPING FOR CARRIER AGGREGATION IN WIRELESS COMMUNICATION NETWORKS
2y 5m to grant Granted Jul 28, 2026
Patent 12641511
SWITCHING CONTROL METHOD AND APPARATUS FOR SERVICE SERVER, ELECTRONIC DEVICE, AND STORAGE MEDIUM
3y 6m to grant Granted May 26, 2026
Patent 12634881
PAGING TRANSMISSION METHOD AND DEVICE
4y 10m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
47%
Grant Probability
93%
With Interview (+46.2%)
3y 3m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 58 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month