Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
EXAMINER’S NOTE: The claims have been reviewed and considered under the new guidance pursuant to the 2019 Revised Patent Subject Matter Eligibility Guidance (PEG 2019) issued January 7, 2019.
This communication is in response to Applicant’s Amendment filed on 31 December 2025. Claims 1-3, 6-7, 9-14, 16, and 18-20 have been amended. Claims 1-20 remain pending.
Response to Arguments
Applicant's arguments filed 31 December 2025 have been fully considered but they are not persuasive.
In light of the newly added claim amendments – “wherein the first access type indicates an access technology, and wherein the wireless device holds a non-access stratum (NAS) security context comprising: a first value of a first NAS counter of the first access path; and a second value of a second NAS counter of the second access path”, “sending the first NAS message via the first access path of the first access type”, “sending the second NAS message via the second access path of the first access type”, and “generating the security context comprising the first value of the first NAS counter of the first access path; and updating the security context with the second value of the second NAS counter of the second access path; and wherein the security context indicates a 5G NAS security context” the teachings of Li et al. still applies and will be shown below in the 102 rejection.
In light of the Applicant’s arguments for claims 1, 11, and 20, the Applicant traverses that the prior art, Li et al. fail to disclose, suggest, or teach the claimed limitation “establishing a first access path of a first access type and a second access path of the first access type”.
The Examiner respectfully disagrees and asserts that Li et al. discloses two access paths to connection of a UE within the network in paragraphs 95 and 119, i.e., With reference to the network architecture shown in FIG. 2, the terminal may access the AMF node via both the 3GPP access technology and the non-3GPP access technology. The 3GPP access technology may be simply represented as 3GPP, and the non-3GPP access technology may be simply represented as non-3GPP. A path 1 in FIG. 2 is a path over which the terminal accesses the AMF node via the 3GPP, and a path 2 is a path over which the terminal accesses the AMF node via the non-3GPP, in other words, the terminal may access the AMF node via the N3IWF node. When the terminal accesses the AMF node via both the 3GPP and non-3GPP, if the terminal needs to send a NAS message to the AMF node, in a possible implementation, the NAS message may be split into at least two message blocks, where one or more of the message blocks are transmitted via the 3GPP, and one or more of the message blocks are transmitted via the non-3GPP. For example, the NAS message may be divided into a message block 1, a message block 2, a message block 3, a message block 4, and a message block 5. The message blocks 2 and 4 are transmitted via the 3GPP, and the message blocks 1, 3, and 5 are transmitted via the non-3GPP. In another possible implementation, the terminal may transmit an entire NAS message via the 3GPP, and transmit another entire NAS message via the non-3GPP. The first parameter is an input parameter used when the terminal performs security protection on a NAS message, and the first parameter is used to indicate an access technology used to transmit the NAS message. The terminal can support at least two access technologies, and can separately maintain a corresponding NAS COUNT for each of the at least two access technologies. For example, the at least two access technologies comprise a 3GPP access technology and a different access technology that can share the same 3GPP network core network device with the 3GPP access technology, for example, a non-3GPP access technology or a fixed network access technology. Optionally, that the first parameter indicates the access technology used to transmit the NAS message may be further understood to mean that the first parameter is used to indicate a transmission path used by the terminal to transmit the NAS message. For example, the terminal and the AMF node may separately maintain a corresponding NAS COUNT for each transmission path without distinguishing access technologies. If the transmission path used to transmit the NAS message is a path 1, a NAS COUNT corresponding to the path 1 is used. If the transmission path used to transmit the NAS message is a path 2, a NAS COUNT corresponding to the path 2 is used. It may be understood that a transmission path corresponds to an access technology. For example, referring to FIG. 2, an access technology used when data is transmitted on the path 1 is the 3GPP access technology, and an access technology used when data is transmitted on the path 2 is the non-3GPP access technology.
In light of the Applicant’s arguments for claims 1, 11, and 20, the Applicant traverses that the prior art, Li et al. fail to disclose, suggest, or teach the claimed limitation “computing a first message authentication code (MAC) for a first NAS message, based on the first value of the first NAS counter of the first access path and computing a second MAC for a second NAS message, based on the second value of the second NAS counter of the second access path”.
The Examiner respectfully disagrees and asserts that Li et al. discloses the determining of integrity may be based on computing the first MAC and the second MAC wherein a comparison with the MAC in the first and second NAS messages is made to determine if the first MAC and second MAC are equal, the determining of integrity is deemed as successful and the AMF update the NAS uplink COUNT by increasing the value as shown in paragraphs 112-115, 163, and 255-256, i.e., FIG. 4 shows a process of performing integrity protection and integrity protection verification on a NAS message. A message (MESSAGE) is a message on which integrity protection needs to be performed, and may be a NAS message. An EPS integrity algorithm (EIA) is shown in FIG. 4. An integrity protection method is as follows: a transmit end performs EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION) to obtain an expected message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds. If the terminal accesses the AMF node using the non-3GPP access technology for the first time, the first uplink NAS COUNT corresponding to the non-3GPP access technology may be set to 0 or a random number. Alternatively, when the terminal has accessed the AMF node via the 3GPP access technology, if a NAS COUNT maintenance method is the method 1 described above (i.e., after a NAS message is sent, a NAS COUNT used in the NAS message is increased by 1 and stored; and when a NAS message needs to be sent a next time, security protection is performed on the NAS message using the stored NAS COUNT), it may be determined that the first uplink NAS COUNT is an uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the terminal. If the terminal stores at least two uplink NAS COUNTs corresponding to the 3GPP access technology and the terminal cannot determine an uplink NAS COUNT used by a previous NAS message, a largest uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the terminal is selected, and security protection is performed on the NAS message. If a NAS COUNT maintenance method is the method 2 described above (i.e., after a NAS message is sent, when a NAS message needs to be sent a next time, a stored NAS COUNT is increased by 1 to determine a new NAS COUNT, and security protection is performed on the NAS message using the new NAS COUNT), it may be determined that the first uplink NAS COUNT is a sum of 1 and an uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the terminal. If the terminal stores at least two uplink NAS COUNTs corresponding to the 3GPP access technology and the terminal cannot determine an uplink NAS COUNT used by a previous NAS message, a largest uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the terminal is selected and is increased by 1, and security protection is performed on the NAS message using the uplink NAS COUNT increased by 1. The N3IWF node sends an EAP-5G-Success message to the terminal and the terminal receives the EAP-5G-Success message.
Therefore, the rejection in view of the reasons above and below in view of Li et al. will be maintained.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Li et al. (Pub No. 2019/0274051).
Referring to the rejection of claim 1, Li et al. discloses a wireless device, comprising:
one or more processors; (See Li et al., para. 289, i.e., processing unit, item 1202)
and memory storing instructions, wherein the instructions, when executed by the one or more processors, cause the wireless device at least to perform: (See Li et al., para. 289-290, i.e., storage unit, item 1201 is disclosed as memory)
establishing a first access path of a first access type and a second access path of the first access type; (See Li et al., para. 34-39, 95, and 119, i.e., at least two access technologies include a first access technology and a second access technology. If the access technology used to transmit the NAS message is the first access technology, before the core network device determines the first parameter, the core network device may receive a first message, where security protection is performed on the first message using the NAS key and an uplink NAS COUNT corresponding to the second access technology, and the first message carries a bit, some bits, or all bits of the uplink NAS COUNT corresponding to the second access technology. The first message carries first indication information, and the first indication information is used to indicate an access technology corresponding to a bit, some bits, or all bits of the uplink NAS COUNT carried in the first message. The first indication information indicates a transmission path corresponding to a bit, some bits, or all bits of the uplink NAS COUNT carried in the first message. The core network device determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that are corresponding to the first access technology, and then the core network device sends a second message to the terminal, where the second message includes one or both of the second uplink NAS COUNT and the first downlink NAS COUNT that are corresponding to the first access technology the terminal may access the AMF node via both the 3GPP access technology and the non-3GPP access technology. The 3GPP access technology may be simply represented as 3GPP, and the non-3GPP access technology may be simply represented as non-3GPP. A path 1 in FIG. 2 is a path over which the terminal accesses the AMF node via the 3GPP, and a path 2 is a path over which the terminal accesses the AMF node via the non-3GPP, in other words, the terminal may access the AMF node via the N3IWF node. When the terminal accesses the AMF node via both the 3GPP and non-3GPP, if the terminal needs to send a NAS message to the AMF node, in a possible implementation, the NAS message may be split into at least two message blocks, where one or more of the message blocks are transmitted via the 3GPP, and one or more of the message blocks are transmitted via the non-3GPP. For example, the NAS message may be divided into a message block 1, a message block 2, a message block 3, a message block 4, and a message block 5. The message blocks 2 and 4 are transmitted via the 3GPP, and the message blocks 1, 3, and 5 are transmitted via the non-3GPP. In another possible implementation, the terminal may transmit an entire NAS message via the 3GPP, and transmit another entire NAS message via the non-3GPP)
wherein the first access type indicates an access technology, and wherein the wireless device holds a non-access stratum (NAS) security context comprising: (See Li et al., para. 83, i.e., there are two types of radio access technologies: a 3GPP access technology (for example, a radio access technology used in a 3G, 4G, or 5G system) and a non-3GPP access technology. The 3GPP access technology is an access technology that complies with a 3GPP standard specification. An access network using the 3GPP access technology is a radio access network (RAN). An access network device in the 5G system is referred to as a next generation base station or next generation nodeB (gNB). The non-3GPP access technology is an access technology that does not comply with the 3GPP standard specification, for example, a radio technology represented by a Wi-Fi access point (AP)
a first value of a first NAS counter of the first access path; and a second value of a second NAS counter of the second access path; (See Li et al., para. 175-178, i.e., access type information may comprise access type indication information (such as an access type of a radio access technology (RAT) type) that is explicitly indicated in an N2 message. Alternatively, access type information may comprise access type indication information that is added in the NAS message. The AMF node may determine an access type based on a source of the first message when there is no access type indication information. For example, if a source address of the message is a base station, an access type is 3GPP access; if a source address of the message is an N3IWF node, an access type is non-3GPP access; if a source address of the message is a device connected to a fixed network, an access type is fixed network access. When the first indication information indicates the non-3GPP access technology, if the first message carries a complete first NAS COUNT and the AMF node determines that the terminal has accessed the AMF node, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the non-3GPP access technology and that is stored by the AMF node. If the first NAS COUNT is greater than the previously received uplink NAS COUNT, the verification succeeds. However, if the first NAS COUNT is less than the previously received uplink NAS COUNT, the authentication fails, in which case access of the terminal is rejected and the terminal is informed of a failure reason. Optionally, if the AMF node determines that the terminal has not accessed the AMF node using the non-3GPP access technology, the AMF node stores the first NAS COUNT as the uplink NAS COUNT corresponding to the non-3GPP access technology, or the AMF node determines that the uplink NAS COUNT corresponding to the non-3GPP access technology is 0. If the first message carries a part of the first NAS COUNT, the AMF node first recovers the complete first NAS COUNT, and then verifies or saves the first NAS COUNT according to the foregoing method for processing the first NAS COUNT. When the first indication information indicates the 3GPP access technology, if the first message carries a complete NAS COUNT corresponding to the 3GPP access technology, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the AMF node. If the first NAS COUNT is greater than the previously received uplink NAS COUNT, the verification succeeds. However, if the first NAS COUNT is less than the previously received uplink NAS COUNT, the authentication fails. If the first message carries a part of a NAS COUNT corresponding to the 3GPP access technology, the AMF node first recovers the complete NAS COUNT, and then verifies the recovered complete COUNT using the foregoing method for verifying the NAS COUNT. The AMF node determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that correspond to the first access technology)
computing a first message authentication code (MAC) for a first NAS message, based on the first value of the first NAS counter of the first access path; (See Li et al., para. 115 and 176, i.e., computing to obtain a first message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds and if the first message carries a complete first NAS COUNT and the AMF node determines that the terminal has accessed the AMF node, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the non-3GPP access technology and that is stored by the AMF node)
computing a second MAC for a second NAS message, based on the second value of the second NAS counter of the second access path; (See Li et al., para. 115 and 178, i.e., computing to obtain a second message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds and if the second message uses the AMF node determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that correspond to the first access technology. The second uplink NAS COUNT is 0, and further, all or some bits of the second uplink NAS COUNT are 0. The second uplink NAS COUNT is a downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the core network device stores at least two downlink NAS COUNTs corresponding to the second access technology, the second uplink NAS COUNT is a largest downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device)
sending the first NAS message via the first access path of the first access type, wherein the first NAS message comprises the first MAC; (See Li et al., para. 115, 119, and 176, i.e., sending the first NAS first message comprises the first message authentication code for integrity (MAC-I) or a NAS-MAC and The first parameter is an input parameter used when the terminal performs security protection on a NAS message, and the first parameter is used to indicate an access technology used to transmit the NAS message. The terminal can support at least two access technologies, and can separately maintain a corresponding NAS COUNT for each of the at least two access technologies. For example, the at least two access technologies comprise a 3GPP access technology and a different access technology that can share the same 3GPP network core network device with the 3GPP access technology, for example, a non-3GPP access technology or a fixed network access technology. Optionally, that the first parameter indicates the access technology used to transmit the NAS message may be further understood to mean that the first parameter is used to indicate a transmission path used by the terminal to transmit the NAS message. For example, the terminal and the AMF node may separately maintain a corresponding NAS COUNT for each transmission path without distinguishing access technologies. If the transmission path used to transmit the NAS message is a path 1, a NAS COUNT corresponding to the path 1 is used. If the transmission path used to transmit the NAS message is a path 2, a NAS COUNT corresponding to the path 2 is used. It may be understood that a transmission path corresponds to an access technology. For example, referring to FIG. 2, an access technology used when data is transmitted on the path 1 is the 3GPP access technology, and an access technology used when data is transmitted on the path 2 is the non-3GPP access technology)
and sending the second NAS message via the second access path of the first access type, wherein the second NAS message comprises the second MAC. (See Li et al., para. 115, 119, and 178, i.e., sending the second NAS message comprises the second message authentication code XNAS-MAC and The first parameter is an input parameter used when the terminal performs security protection on a NAS message, and the first parameter is used to indicate an access technology used to transmit the NAS message. The terminal can support at least two access technologies, and can separately maintain a corresponding NAS COUNT for each of the at least two access technologies. For example, the at least two access technologies comprise a 3GPP access technology and a different access technology that can share the same 3GPP network core network device with the 3GPP access technology, for example, a non-3GPP access technology or a fixed network access technology. Optionally, that the first parameter indicates the access technology used to transmit the NAS message may be further understood to mean that the first parameter is used to indicate a transmission path used by the terminal to transmit the NAS message. For example, the terminal and the AMF node may separately maintain a corresponding NAS COUNT for each transmission path without distinguishing access technologies. If the transmission path used to transmit the NAS message is a path 1, a NAS COUNT corresponding to the path 1 is used. If the transmission path used to transmit the NAS message is a path 2, a NAS COUNT corresponding to the path 2 is used. It may be understood that a transmission path corresponds to an access technology. For example, referring to FIG. 2, an access technology used when data is transmitted on the path 1 is the 3GPP access technology, and an access technology used when data is transmitted on the path 2 is the non-3GPP access technology)
Referring to the rejection of claim 2, Li et al. discloses wherein the instructions, when executed, further cause the wireless device at least to perform: incrementing, by the wireless device, the first value of the first NAS counter of the first access path; (See Li et al., para. 98-100, i.e., A start value of the NAS COUNT is 0. An uplink NAS COUNT is increased by 1 each time the terminal sends one NAS message to the core network device, and a downlink NAS COUNT is increased by 1 each time the core network device sends one NAS message to the terminal. After an authentication process from the terminal to the core network device is completed, both the uplink NAS COUNT and the downlink NAS COUNT are set to 0. After a NAS message is sent, a stored NAS COUNT is increased by 1 and is stored. When a NAS message needs to be sent a subsequent time, security protection is performed on the NAS message using the stored NAS COUNT)
and incrementing, by the wireless device, the second value of the second NAS counter of the second access path. (See Li et al., para. 101-102, i.e., After a NAS message is sent, when a NAS message needs to be sent a subsequent time, a stored NAS COUNT is increased by 1 to obtain a new NAS COUNT, and security protection is performed on the NAS message using the new NAS COUNT. After receiving the NAS message, the terminal and the core network device may verify whether a received NAS COUNT is reused, to be more specific, verify whether the NAS COUNT carried in the NAS message is greater than a previously received NAS COUNT)
Referring to the rejection of claim 3, Li et al. discloses wherein a value of a NAS counter, of the first NAS counter and the second NAS counter, is a NAS uplink COUNT value, and wherein the NAS uplink COUNT value is part of a NAS COUNT; and the NAS COUNT is based on an encoding of at least one of: a padding byte; a NAS overflow; and a NAS sequence number (SQN). (See Li et al., para. 97, 101, and 125, i.e., NAS COUNT includes 24 bits including a 16-bit NAS overflow and an 8-bit Sequence Number. After a NAS message is sent, when a NAS message needs to be sent a subsequent time, a stored NAS COUNT is increased by 1 to obtain a new NAS COUNT, and security protection is performed on the NAS message using the new NAS COUNT. all or some bits of the parameter COUNT in the input parameters may be used to indicate the access technology used to transmit the NAS message. For example, if the COUNT includes 8 all-0 padding bits and a NAS COUNT, the first parameter may be some or all bits of the 8 bits)
Referring to the rejection of claim 4, Li et al. discloses wherein the instructions, when executed, further cause the wireless device at least to perform: modifying by the wireless device, a most significant octet of the NAS COUNT to be associated with the first access path of the first access type. (See Li et al., para. 126, i.e., the parameter BEARER in the input parameters may be used to indicate the access technology used to transmit the NAS message, or to indicate an access path used to transmit the NAS message, where the first parameter may be a bit some bits, or all bits of the BEARER. For example, the first 3 bits may be selected to indicate the access technology used to transmit the NAS message)
Referring to the rejection of claim 5, Li et al. discloses wherein the most significant octet of the NAS count holds a unique arbitrary value to be associated with the first access path of the first access type or the second access path of the first access type. (See Li et al., para. 266, i.e., The AMF node determines, based on access type information in the N2 message, the access technology used to transmit the N2 message. For example, the access type information comprises RAT type (an access type) information, such that it is determined that a NAS COUNT corresponding to the 3GPP access technology may be used. The AMF node may verify, using an uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the AMF node, an uplink NAS COUNT carried in the N2 message)
Referring to the rejection of claim 6, Li et al. discloses wherein generating the security context comprising the first value of the first NAS counter of the first access path; (See Li et al., para. 192-193, i.e., the terminal accesses the untrusted non-3GPP network, and the terminal has been authenticated by a 3GPP network and has a NAS security context. The NAS security context includes a NAS key, a key identifier, and a NAS COUNT corresponding to the 3GPP access technology. Optionally, the NAS context further includes a NAS COUNT corresponding to the non-3GPP access technology. If the terminal has accessed the AMF node via the non-3GPP access technology, the NAS COUNT corresponding to the non-3GPP access technology is not 0. If the terminal has not accessed the AMF node via the non-3GPP access technology, the NAS COUNT corresponding to the non-3GPP access technology is 0. The NAS key may be one or both of an encryption key and an integrity protection key)
and updating the security context with the second value of the second NAS counter of the second access path; (See Li et al., para. 268, i.e., if the AMF node determines the second uplink NAS COUNT and the first downlink NAS COUNT that correspond to the non-3GPP access technology, the AMF node may further update the NAS key. This embodiment of this application provides four methods for updating the NAS key)
and wherein the security context indicates a 5G NAS security context. (See Li et al., para. 269-276, i.e., generate new Kamf (nKamf) using old Kamf (oKamf), and after the AMF node generates nKamf, generate a new NAS key based on nKamf. Kamf is a root key of the AMF node. Herein, nKamf=KDF (oKamf, a freshness parameter). The freshness parameter may be an uplink NAS COUNT previously received by the AMF node, a COUNT, a parameter sent by the terminal to the AMF node, or a parameter that is negotiated between the terminal and the AMF node)
*According to the Applicant’s specification, the 5G NAS security context is defined as key KAMF with an associated key set identifier as disclosed in paragraph 0299.
Referring to the rejection of claim 7, Li et al. discloses wherein the wireless device is connected to an access and mobility management function (AMF) over the first access path of the first access type via a first access network and the second access path of the first access type via a second access network. (See Li et al., para. 83, 173-175 and 185-188, i.e., there are two types of radio access technologies: a 3GPP access technology (for example, a radio access technology used in a 3G, 4G, or 5G system) and a non-3GPP access technology. The 3GPP access technology is an access technology that complies with a 3GPP standard specification. An access network using the 3GPP access technology is a radio access network (RAN). An access network device in the 5G system is referred to as a next generation base station or next generation nodeB (gNB). The non-3GPP access technology is an access technology that does not comply with the 3GPP standard specification, for example, a radio technology represented by a Wi-Fi access point (AP). The AMF node receives the first message. The AMF node verifies, based on an uplink NAS COUNT corresponding to an access technology indicated by first indication information, a NAS COUNT carried in the first message. Access type information may comprise access type indication information (such as an access type of a radio access technology (RAT) type) that is explicitly indicated in an N2 message. Access type information may comprise access type indication information that is added in the NAS message. The AMF node may determine an access type based on a source of the first message when there is no access type indication information. The AMF node sends a second message to the terminal, where the second message includes one or both of the second uplink NAS COUNT and the first downlink NAS COUNT that correspond to the first access technology. The terminal receives the second message which carries second indication information, and the second indication information is used to indicate an access type corresponding to the first downlink NAS COUNT carried in the second message. Optionally, the second message may further carry indication information used to indicate the second uplink NAS COUNT carried in the second message. Optionally, the second indication information is used to indicate a transmission path corresponding to the first downlink NAS COUNT carried in the second message. Optionally, the second message may further carry indication information that is used to indicate a transmission path corresponding to the second uplink NAS COUNT carried in the second message)
Referring to the rejection of claim 8, Li et al. discloses wherein the first NAS counter and the second NAS counter are based on an encoding of at least one of: a NAS uplink COUNT value; and a NAS downlink COUNT value. (See Li et al., para. 178-180, i.e., The AMF node determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that correspond to the first access technology. The second uplink NAS COUNT is 0, and further, all or some bits of the second uplink NAS COUNT are 0. Alternatively, the second uplink NAS COUNT is a random number. The second uplink NAS COUNT are random numbers. For example, a Sequence Number part or a NAS overflow part of the second uplink NAS COUNT is a random number. In this case, a remaining part is 0. The second uplink NAS COUNT is a downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the core network device stores at least two downlink NAS COUNTs corresponding to the second access technology, the second uplink NAS COUNT is a largest downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the second uplink NAS COUNT is a sum of 1 and a downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the core network device stores at least two downlink NAS COUNTs corresponding to the second access technology, the second uplink NAS COUNT is a sum of 1 and a largest downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the first message received by the AMF node carries the first uplink NAS COUNT, the AMF node may determine that the second uplink NAS COUNT is the first uplink NAS COUNT, or that the second uplink NAS COUNT is a sum of 1 and the first uplink NAS COUNT)
Referring to the rejection of claim 9, Li et al. discloses wherein the computing the first MAC and the second MAC is additionally based on a bearer value. (See Li et al., para. 115, i.e., An integrity protection method is as follows: a transmit end performs EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION) to obtain an expected message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds)
Referring to the rejection of claim 10, Li et al. discloses wherein the instructions, when executed, further cause the wireless device at least to perform, determining a bearer value based on using a NAS connection identifier for the first access type and an identifier of the first access path. (See Li et al., para. 126 and 133, i.e., the parameter BEARER in the input parameters may be used to indicate the access technology used to transmit the NAS message, or to indicate an access path used to transmit the NAS message, where the first parameter may be a bit some bits, or all bits of the BEARER. For example, the first 3 bits may be selected to indicate the access type used to transmit the NAS message, if the first parameter is determined by the AMF node, the terminal may receive the first parameter from the AMF node, and if the first parameter comprises some bits in a NAS COUNT, after receiving the first parameter, the terminal may replace, with the first parameter, specified bits in the NAS COUNT stored by the terminal. Alternatively, if the first parameter comprises some bits in a BEARER, the terminal may replace specified bits in the BEARER with the first parameter)
Referring to the rejection of claim 11, Li et al. discloses a method comprising:
establishing, by a wireless device, a first access path of a first access type and a second access path of the first access type; (See Li et al., para. 34-39, 95, and 119, i.e., at least two access technologies include a first access technology and a second access technology. If the access technology used to transmit the NAS message is the first access technology, before the core network device determines the first parameter, the core network device may receive a first message, where security protection is performed on the first message using the NAS key and an uplink NAS COUNT corresponding to the second access technology, and the first message carries a bit, some bits, or all bits of the uplink NAS COUNT corresponding to the second access technology. The first message carries first indication information, and the first indication information is used to indicate an access technology corresponding to a bit, some bits, or all bits of the uplink NAS COUNT carried in the first message. The first indication information indicates a transmission path corresponding to a bit, some bits, or all bits of the uplink NAS COUNT carried in the first message. The core network device determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that are corresponding to the first access technology, and then the core network device sends a second message to the terminal, where the second message includes one or both of the second uplink NAS COUNT and the first downlink NAS COUNT that are corresponding to the first access technology the terminal may access the AMF node via both the 3GPP access technology and the non-3GPP access technology. The 3GPP access technology may be simply represented as 3GPP, and the non-3GPP access technology may be simply represented as non-3GPP. A path 1 in FIG. 2 is a path over which the terminal accesses the AMF node via the 3GPP, and a path 2 is a path over which the terminal accesses the AMF node via the non-3GPP, in other words, the terminal may access the AMF node via the N3IWF node. When the terminal accesses the AMF node via both the 3GPP and non-3GPP, if the terminal needs to send a NAS message to the AMF node, in a possible implementation, the NAS message may be split into at least two message blocks, where one or more of the message blocks are transmitted via the 3GPP, and one or more of the message blocks are transmitted via the non-3GPP. For example, the NAS message may be divided into a message block 1, a message block 2, a message block 3, a message block 4, and a message block 5. The message blocks 2 and 4 are transmitted via the 3GPP, and the message blocks 1, 3, and 5 are transmitted via the non-3GPP. In another possible implementation, the terminal may transmit an entire NAS message via the 3GPP, and transmit another entire NAS message via the non-3GPP)
wherein the first access type indicates an access technology, and wherein the wireless device holds a non-access stratum (NAS) security context comprising: (See Li et al., para. 83, i.e., there are two types of radio access technologies: a 3GPP access technology (for example, a radio access technology used in a 3G, 4G, or 5G system) and a non-3GPP access technology. The 3GPP access technology is an access technology that complies with a 3GPP standard specification. An access network using the 3GPP access technology is a radio access network (RAN). An access network device in the 5G system is referred to as a next generation base station or next generation nodeB (gNB). The non-3GPP access technology is an access technology that does not comply with the 3GPP standard specification, for example, a radio technology represented by a Wi-Fi access point (AP)
a first value of a first NAS counter of the first access path; and a second value of a second NAS counter of the second access path; (See Li et al., para. 175-178, i.e., access type information may comprise access type indication information (such as an access type of a radio access technology (RAT) type) that is explicitly indicated in an N2 message. Alternatively, access type information may comprise access type indication information that is added in the NAS message. The AMF node may determine an access type based on a source of the first message when there is no access type indication information. For example, if a source address of the message is a base station, an access type is 3GPP access; if a source address of the message is an N3IWF node, an access type is non-3GPP access; if a source address of the message is a device connected to a fixed network, an access type is fixed network access. When the first indication information indicates the non-3GPP access technology, if the first message carries a complete first NAS COUNT and the AMF node determines that the terminal has accessed the AMF node, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the non-3GPP access technology and that is stored by the AMF node. If the first NAS COUNT is greater than the previously received uplink NAS COUNT, the verification succeeds. However, if the first NAS COUNT is less than the previously received uplink NAS COUNT, the authentication fails, in which case access of the terminal is rejected and the terminal is informed of a failure reason. Optionally, if the AMF node determines that the terminal has not accessed the AMF node using the non-3GPP access technology, the AMF node stores the first NAS COUNT as the uplink NAS COUNT corresponding to the non-3GPP access technology, or the AMF node determines that the uplink NAS COUNT corresponding to the non-3GPP access technology is 0. If the first message carries a part of the first NAS COUNT, the AMF node first recovers the complete first NAS COUNT, and then verifies or saves the first NAS COUNT according to the foregoing method for processing the first NAS COUNT. When the first indication information indicates the 3GPP access technology, if the first message carries a complete NAS COUNT corresponding to the 3GPP access technology, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the AMF node. If the first NAS COUNT is greater than the previously received uplink NAS COUNT, the verification succeeds. However, if the first NAS COUNT is less than the previously received uplink NAS COUNT, the authentication fails. If the first message carries a part of a NAS COUNT corresponding to the 3GPP access technology, the AMF node first recovers the complete NAS COUNT, and then verifies the recovered complete COUNT using the foregoing method for verifying the NAS COUNT. The AMF node determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that correspond to the first access technology)
computing, by the wireless device, a first message authentication code (MAC) for a first NAS message, based on the first value of the first NAS counter of the first access path; (See Li et al., para. 115 and 176, i.e., computing to obtain a first message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds and if the first message carries a complete first NAS COUNT and the AMF node determines that the terminal has accessed the AMF node, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the non-3GPP access technology and that is stored by the AMF node)
computing, by the wireless device, a second MAC for a second NAS message, based on the second value of the second NAS counter of the second access path; (See Li et al., para. 115 and 178, i.e., computing to obtain a second message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds and if the second message uses the AMF node determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that correspond to the first access technology. The second uplink NAS COUNT is 0, and further, all or some bits of the second uplink NAS COUNT are 0. The second uplink NAS COUNT is a downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the core network device stores at least two downlink NAS COUNTs corresponding to the second access technology, the second uplink NAS COUNT is a largest downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device)
sending, by the wireless device, the first NAS message via the first access path of the first access type, wherein the first NAS message comprises the first MAC; (See Li et al., para. 115, 119, and 176, i.e., sending the first NAS first message comprises the first message authentication code for integrity (MAC-I) or a NAS-MAC and The first parameter is an input parameter used when the terminal performs security protection on a NAS message, and the first parameter is used to indicate an access technology used to transmit the NAS message. The terminal can support at least two access technologies, and can separately maintain a corresponding NAS COUNT for each of the at least two access technologies. For example, the at least two access technologies comprise a 3GPP access technology and a different access technology that can share the same 3GPP network core network device with the 3GPP access technology, for example, a non-3GPP access technology or a fixed network access technology. Optionally, that the first parameter indicates the access technology used to transmit the NAS message may be further understood to mean that the first parameter is used to indicate a transmission path used by the terminal to transmit the NAS message. For example, the terminal and the AMF node may separately maintain a corresponding NAS COUNT for each transmission path without distinguishing access technologies. If the transmission path used to transmit the NAS message is a path 1, a NAS COUNT corresponding to the path 1 is used. If the transmission path used to transmit the NAS message is a path 2, a NAS COUNT corresponding to the path 2 is used. It may be understood that a transmission path corresponds to an access technology. For example, referring to FIG. 2, an access technology used when data is transmitted on the path 1 is the 3GPP access technology, and an access technology used when data is transmitted on the path 2 is the non-3GPP access technology)
and sending, by the wireless device, the second NAS message via the second access path of the first access type, wherein the second NAS message comprises the second MAC. (See Li et al., para. 115, 119, and 178, i.e., sending the second NAS message comprises the second message authentication code XNAS-MAC and The first parameter is an input parameter used when the terminal performs security protection on a NAS message, and the first parameter is used to indicate an access technology used to transmit the NAS message. The terminal can support at least two access technologies, and can separately maintain a corresponding NAS COUNT for each of the at least two access technologies. For example, the at least two access technologies comprise a 3GPP access technology and a different access technology that can share the same 3GPP network core network device with the 3GPP access technology, for example, a non-3GPP access technology or a fixed network access technology. Optionally, that the first parameter indicates the access technology used to transmit the NAS message may be further understood to mean that the first parameter is used to indicate a transmission path used by the terminal to transmit the NAS message. For example, the terminal and the AMF node may separately maintain a corresponding NAS COUNT for each transmission path without distinguishing access technologies. If the transmission path used to transmit the NAS message is a path 1, a NAS COUNT corresponding to the path 1 is used. If the transmission path used to transmit the NAS message is a path 2, a NAS COUNT corresponding to the path 2 is used. It may be understood that a transmission path corresponds to an access technology. For example, referring to FIG. 2, an access technology used when data is transmitted on the path 1 is the 3GPP access technology, and an access technology used when data is transmitted on the path 2 is the non-3GPP access technology)
Referring to the rejection of claim 12, Li et al. discloses further comprising: incrementing, by the wireless device, the first value of the first NAS counter of the first access path; See Li et al., para. 98-100, i.e., A start value of the NAS COUNT is 0. An uplink NAS COUNT is increased by 1 each time the terminal sends one NAS message to the core network device, and a downlink NAS COUNT is increased by 1 each time the core network device sends one NAS message to the terminal. After an authentication process from the terminal to the core network device is completed, both the uplink NAS COUNT and the downlink NAS COUNT are set to 0. After a NAS message is sent, a stored NAS COUNT is increased by 1 and is stored. When a NAS message needs to be sent a subsequent time, security protection is performed on the NAS message using the stored NAS COUNT)
and incrementing, by the wireless device, the second value of the second NAS counter of the second access path. (See Li et al., para. 101-102, i.e., After a NAS message is sent, when a NAS message needs to be sent a subsequent time, a stored NAS COUNT is increased by 1 to obtain a new NAS COUNT, and security protection is performed on the NAS message using the new NAS COUNT. After receiving the NAS message, the terminal and the core network device may verify whether a received NAS COUNT is reused, to be more specific, verify whether the NAS COUNT carried in the NAS message is greater than a previously received NAS COUNT)
Referring to the rejection of claim 13, Li et al. discloses wherein a value of a NAS counter, of the first NAS counter and the second NAS counter, is a NAS uplink COUNT value, and wherein the NAS uplink COUNT value is part of a NAS COUNT; and the NAS COUNT is based on an encoding of at least one of: a padding byte; a NAS overflow; and a NAS sequence number (SQN). (See Li et al., para. 97, 101, and 125, i.e., NAS COUNT includes 24 bits including a 16-bit NAS overflow and an 8-bit Sequence Number. After a NAS message is sent, when a NAS message needs to be sent a subsequent time, a stored NAS COUNT is increased by 1 to obtain a new NAS COUNT, and security protection is performed on the NAS message using the new NAS COUNT. all or some bits of the parameter COUNT in the input parameters may be used to indicate the access technology used to transmit the NAS message. For example, if the COUNT includes 8 all-0 padding bits and a NAS COUNT, the first parameter may be some or all bits of the 8 bits)
Referring to the rejection of claim 14, Li et al. discloses further comprising: modifying, by the wireless device, a most significant octet of the NAS COUNT to be associated with the first access path of the first access type. (See Li et al., para. 126, i.e., the parameter BEARER in the input parameters may be used to indicate the access technology used to transmit the NAS message, or to indicate an access path used to transmit the NAS message, where the first parameter may be a bit some bits, or all bits of the BEARER. For example, the first 3 bits may be selected to indicate the access technology used to transmit the NAS message)
Referring to the rejection of claim 15, Li et al. discloses wherein the most significant octet of the NAS count holds a unique arbitrary value to be associated with the first access path of the first access type or the second access path of the first access type. (See Li et al., para. 266, i.e., The AMF node determines, based on access type information in the N2 message, the access technology used to transmit the N2 message. For example, the access type information comprises RAT type (an access type) information, such that it is determined that a NAS COUNT corresponding to the 3GPP access technology may be used. The AMF node may verify, using an uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the AMF node, an uplink NAS COUNT carried in the N2 message)
Referring to the rejection of claim 16, Li et al. discloses wherein generating the security context comprising the first value of the first NAS counter of the first access path; (See Li et al., para. 192-193, i.e., the terminal accesses the untrusted non-3GPP network, and the terminal has been authenticated by a 3GPP network and has a NAS security context. The NAS security context includes a NAS key, a key identifier, and a NAS COUNT corresponding to the 3GPP access technology. Optionally, the NAS context further includes a NAS COUNT corresponding to the non-3GPP access technology. If the terminal has accessed the AMF node via the non-3GPP access technology, the NAS COUNT corresponding to the non-3GPP access technology is not 0. If the terminal has not accessed the AMF node via the non-3GPP access technology, the NAS COUNT corresponding to the non-3GPP access technology is 0. The NAS key may be one or both of an encryption key and an integrity protection key)
and updating the security context with the second value of the second NAS counter of the second access path; (See Li et al., para. 268, i.e., if the AMF node determines the second uplink NAS COUNT and the first downlink NAS COUNT that correspond to the non-3GPP access technology, the AMF node may further update the NAS key. This embodiment of this application provides four methods for updating the NAS key)
and wherein the security context indicates a 5G NAS security context. (See Li et al., para. 269-276, i.e., generate new Kamf (nKamf) using old Kamf (oKamf), and after the AMF node generates nKamf, generate a new NAS key based on nKamf. Kamf is a root key of the AMF node. Herein, nKamf=KDF (oKamf, a freshness parameter). The freshness parameter may be an uplink NAS COUNT previously received by the AMF node, a COUNT, a parameter sent by the terminal to the AMF node, or a parameter that is negotiated between the terminal and the AMF node)
*According to the Applicant’s specification, the 5G NAS security context is defined as key KAMF with an associated key set identifier as disclosed in paragraph 0299.
Referring to the rejection of claim 17, Li et al. discloses wherein the first NAS counter and the second NAS counter are based on an encoding of at least one of: a NAS uplink COUNT value; and a NAS downlink COUNT value. (See Li et al., para. 178-180, i.e., The AMF node determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that correspond to the first access technology. The second uplink NAS COUNT is 0, and further, all or some bits of the second uplink NAS COUNT are 0. Alternatively, the second uplink NAS COUNT is a random number. The second uplink NAS COUNT are random numbers. For example, a Sequence Number part or a NAS overflow part of the second uplink NAS COUNT is a random number. In this case, a remaining part is 0. The second uplink NAS COUNT is a downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the core network device stores at least two downlink NAS COUNTs corresponding to the second access technology, the second uplink NAS COUNT is a largest downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the second uplink NAS COUNT is a sum of 1 and a downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the core network device stores at least two downlink NAS COUNTs corresponding to the second access technology, the second uplink NAS COUNT is a sum of 1 and a largest downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the first message received by the AMF node carries the first uplink NAS COUNT, the AMF node may determine that the second uplink NAS COUNT is the first uplink NAS COUNT, or that the second uplink NAS COUNT is a sum of 1 and the first uplink NAS COUNT)
Referring to the rejection of claim 18, Li et al. discloses wherein the computing the first MAC or the second MAC is additionally based on a bearer value. (See Li et al., para. 115, i.e., An integrity protection method is as follows: a transmit end performs EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION) to obtain an expected message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds)
Referring to the rejection of claim 19, Li et al. discloses further comprising, determining, by the wireless device, a bearer value based on using a NAS connection identifier for the first access type and an identifier of the first access path. (See Li et al., para. 126 and 133, i.e., the parameter BEARER in the input parameters may be used to indicate the access technology used to transmit the NAS message, or to indicate an access path used to transmit the NAS message, where the first parameter may be a bit some bits, or all bits of the BEARER. For example, the first 3 bits may be selected to indicate the access type used to transmit the NAS message, if the first parameter is determined by the AMF node, the terminal may receive the first parameter from the AMF node, and if the first parameter comprises some bits in a NAS COUNT, after receiving the first parameter, the terminal may replace, with the first parameter, specified bits in the NAS COUNT stored by the terminal. Alternatively, if the first parameter comprises some bits in a BEARER, the terminal may replace specified bits in the BEARER with the first parameter)
Referring to the rejection of claim 20, Li et al. discloses a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors of a wireless device, cause the wireless device to perform:
establishing a first access path of a first access type and a second access path of the first access type; (See Li et al., para. 34-39, 95, and 119, i.e., at least two access technologies include a first access technology and a second access technology. If the access technology used to transmit the NAS message is the first access technology, before the core network device determines the first parameter, the core network device may receive a first message, where security protection is performed on the first message using the NAS key and an uplink NAS COUNT corresponding to the second access technology, and the first message carries a bit, some bits, or all bits of the uplink NAS COUNT corresponding to the second access technology. The first message carries first indication information, and the first indication information is used to indicate an access technology corresponding to a bit, some bits, or all bits of the uplink NAS COUNT carried in the first message. The first indication information indicates a transmission path corresponding to a bit, some bits, or all bits of the uplink NAS COUNT carried in the first message. The core network device determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that are corresponding to the first access technology, and then the core network device sends a second message to the terminal, where the second message includes one or both of the second uplink NAS COUNT and the first downlink NAS COUNT that are corresponding to the first access technology the terminal may access the AMF node via both the 3GPP access technology and the non-3GPP access technology. The 3GPP access technology may be simply represented as 3GPP, and the non-3GPP access technology may be simply represented as non-3GPP. A path 1 in FIG. 2 is a path over which the terminal accesses the AMF node via the 3GPP, and a path 2 is a path over which the terminal accesses the AMF node via the non-3GPP, in other words, the terminal may access the AMF node via the N3IWF node. When the terminal accesses the AMF node via both the 3GPP and non-3GPP, if the terminal needs to send a NAS message to the AMF node, in a possible implementation, the NAS message may be split into at least two message blocks, where one or more of the message blocks are transmitted via the 3GPP, and one or more of the message blocks are transmitted via the non-3GPP. For example, the NAS message may be divided into a message block 1, a message block 2, a message block 3, a message block 4, and a message block 5. The message blocks 2 and 4 are transmitted via the 3GPP, and the message blocks 1, 3, and 5 are transmitted via the non-3GPP. In another possible implementation, the terminal may transmit an entire NAS message via the 3GPP, and transmit another entire NAS message via the non-3GPP)
wherein the first access type indicates an access technology, and wherein the wireless device holds a non-access stratum (NAS) security context comprising: (See Li et al., para. 83, i.e., there are two types of radio access technologies: a 3GPP access technology (for example, a radio access technology used in a 3G, 4G, or 5G system) and a non-3GPP access technology. The 3GPP access technology is an access technology that complies with a 3GPP standard specification. An access network using the 3GPP access technology is a radio access network (RAN). An access network device in the 5G system is referred to as a next generation base station or next generation nodeB (gNB). The non-3GPP access technology is an access technology that does not comply with the 3GPP standard specification, for example, a radio technology represented by a Wi-Fi access point (AP)
a first value of a first NAS counter of the first access path; and a second value of a second NAS counter of the second access path; (See Li et al., para. 175-178, i.e., access type information may comprise access type indication information (such as an access type of a radio access technology (RAT) type) that is explicitly indicated in an N2 message. Alternatively, access type information may comprise access type indication information that is added in the NAS message. The AMF node may determine an access type based on a source of the first message when there is no access type indication information. For example, if a source address of the message is a base station, an access type is 3GPP access; if a source address of the message is an N3IWF node, an access type is non-3GPP access; if a source address of the message is a device connected to a fixed network, an access type is fixed network access. When the first indication information indicates the non-3GPP access technology, if the first message carries a complete first NAS COUNT and the AMF node determines that the terminal has accessed the AMF node, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the non-3GPP access technology and that is stored by the AMF node. If the first NAS COUNT is greater than the previously received uplink NAS COUNT, the verification succeeds. However, if the first NAS COUNT is less than the previously received uplink NAS COUNT, the authentication fails, in which case access of the terminal is rejected and the terminal is informed of a failure reason. Optionally, if the AMF node determines that the terminal has not accessed the AMF node using the non-3GPP access technology, the AMF node stores the first NAS COUNT as the uplink NAS COUNT corresponding to the non-3GPP access technology, or the AMF node determines that the uplink NAS COUNT corresponding to the non-3GPP access technology is 0. If the first message carries a part of the first NAS COUNT, the AMF node first recovers the complete first NAS COUNT, and then verifies or saves the first NAS COUNT according to the foregoing method for processing the first NAS COUNT. When the first indication information indicates the 3GPP access technology, if the first message carries a complete NAS COUNT corresponding to the 3GPP access technology, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the 3GPP access technology and that is stored by the AMF node. If the first NAS COUNT is greater than the previously received uplink NAS COUNT, the verification succeeds. However, if the first NAS COUNT is less than the previously received uplink NAS COUNT, the authentication fails. If the first message carries a part of a NAS COUNT corresponding to the 3GPP access technology, the AMF node first recovers the complete NAS COUNT, and then verifies the recovered complete COUNT using the foregoing method for verifying the NAS COUNT. The AMF node determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that correspond to the first access technology)
computing a first message authentication code (MAC) for a first NAS message, based on the first value of the first NAS counter of the first access path; (See Li et al., para. 115 and 176, i.e., computing to obtain a first message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds and if the first message carries a complete first NAS COUNT and the AMF node determines that the terminal has accessed the AMF node, the AMF node determines whether the first NAS COUNT is greater than a previously received uplink NAS COUNT that corresponds to the non-3GPP access technology and that is stored by the AMF node)
computing a second MAC for a second NAS message, based on the second value of the second NAS counter of the second access path; (See Li et al., para. 115 and 178, i.e., computing to obtain a second message authentication code for integrity (MAC-I) or a NAS-MAC. An integrity protection verification method is as follows: performing EIA processing on the input parameters (the KEY, the COUNT, the MESSAGE, the BEARER, and the DIRECTION), to obtain an expected message authentication code for integrity (XMAC-I) or an XNAS-MAC; comparing the XMAC-I with the MAC-I; and if the XMAC-I is consistent with the MAC-I, determining that integrity protection verification succeeds and if the second message uses the AMF node determines one or both of a second uplink NAS COUNT and a first downlink NAS COUNT that correspond to the first access technology. The second uplink NAS COUNT is 0, and further, all or some bits of the second uplink NAS COUNT are 0. The second uplink NAS COUNT is a downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device. If the core network device stores at least two downlink NAS COUNTs corresponding to the second access technology, the second uplink NAS COUNT is a largest downlink NAS COUNT that corresponds to the second access technology and that is stored by the core network device)
sending the first NAS message via the first access path of the first access type, wherein the first NAS message comprises the first MAC; (See Li et al., para. 115, 119, and 176, i.e., sending the first NAS first message comprises the first message authentication code for integrity (MAC-I) or a NAS-MAC and The first parameter is an input parameter used when the terminal performs security protection on a NAS message, and the first parameter is used to indicate an access technology used to transmit the NAS message. The terminal can support at least two access technologies, and can separately maintain a corresponding NAS COUNT for each of the at least two access technologies. For example, the at least two access technologies comprise a 3GPP access technology and a different access technology that can share the same 3GPP network core network device with the 3GPP access technology, for example, a non-3GPP access technology or a fixed network access technology. Optionally, that the first parameter indicates the access technology used to transmit the NAS message may be further understood to mean that the first parameter is used to indicate a transmission path used by the terminal to transmit the NAS message. For example, the terminal and the AMF node may separately maintain a corresponding NAS COUNT for each transmission path without distinguishing access technologies. If the transmission path used to transmit the NAS message is a path 1, a NAS COUNT corresponding to the path 1 is used. If the transmission path used to transmit the NAS message is a path 2, a NAS COUNT corresponding to the path 2 is used. It may be understood that a transmission path corresponds to an access technology. For example, referring to FIG. 2, an access technology used when data is transmitted on the path 1 is the 3GPP access technology, and an access technology used when data is transmitted on the path 2 is the non-3GPP access technology)
and sending the second NAS message via the second access path of the first access type, wherein the second NAS message comprises the second MAC. (See Li et al., para. 115, 119, and 178, i.e., sending the second NAS message comprises the second message authentication code XNAS-MAC and The first parameter is an input parameter used when the terminal performs security protection on a NAS message, and the first parameter is used to indicate an access technology used to transmit the NAS message. The terminal can support at least two access technologies, and can separately maintain a corresponding NAS COUNT for each of the at least two access technologies. For example, the at least two access technologies comprise a 3GPP access technology and a different access technology that can share the same 3GPP network core network device with the 3GPP access technology, for example, a non-3GPP access technology or a fixed network access technology. Optionally, that the first parameter indicates the access technology used to transmit the NAS message may be further understood to mean that the first parameter is used to indicate a transmission path used by the terminal to transmit the NAS message. For example, the terminal and the AMF node may separately maintain a corresponding NAS COUNT for each transmission path without distinguishing access technologies. If the transmission path used to transmit the NAS message is a path 1, a NAS COUNT corresponding to the path 1 is used. If the transmission path used to transmit the NAS message is a path 2, a NAS COUNT corresponding to the path 2 is used. It may be understood that a transmission path corresponds to an access technology. For example, referring to FIG. 2, an access technology used when data is transmitted on the path 1 is the 3GPP access technology, and an access technology used when data is transmitted on the path 2 is the non-3GPP access technology)
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to COURTNEY D FIELDS whose telephone number is (571)272-3871. The examiner can normally be reached IFP M-F 8am-4:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/COURTNEY D FIELDS/Examiner, Art Unit 2436 April 29, 2026
/SHEWAYE GELAGAY/Supervisory Patent Examiner, Art Unit 2436