DETAILED ACTION
Claims 1-25 are pending in this action.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-8, 11-18 and 21-25 are rejected under 35 U.S.C. 103 unpatentable over Miel et al. (US PGPUB No. 2024/0297887) [hereinafter “Miel”] in view Beckett III et al. (US PGPUB No. 2010/0169474) [hereinafter “Beckett”].
As per claim 1, Miel teaches a function entity service producer (FESP) comprising: a processor; and a transceiver, wherein the processor and the transceiver are configured to: receive a session request message from a function entity service consumer (FESC) (Abstract, user device requesting secure service), wherein the session request message comprises at least an indication of services the FESC is requesting ([0019], user makes an authentication request for a requested service) and an indication of a condition that the service function is to apply when determining whether to send a service notification pursuant to the subscription ([0019], user and user device characteristics are cross-checked initially and also continuously during an authenticated session to determine whether the user device meets and continues to meet a trust threshold), receive a trust index of the FESC from a trust management function (TMF), wherein the trust index is at least one of a trust index of the FESC or a trust index of a user of the FESC ([0011] and [0017], these user and user device characteristics are compiled into a trustworthiness level/score for comparison with the threshold at the onset of the session), determine to authenticate the session request based on the trust index being greater than a threshold ([0011], user device is authenticated if determined to be trustworthy based on trust level/score), receive an updated trust index of the FESC from the TMF based at least in part on the condition being met ([0011], if there is a change in the security posture of the device or user, see [0018]-[0019], the trust level/score will be updated see also [0016]), and send the service notification to the FESC based at least in part on the updated trust index of the FESC being greater than the threshold ([0060], allowing access device to begin a secure session with resource, i.e. secure service, after calculating and updating a trust score that is above the threshold) (Examiner Note: this would involve some sort of notification to the access device).
Miel does not explicitly teach the session request as a subscription request. Beckett teaches the session request to be a subscription request ([0020], service provider accepting subscribers and generating a subscriber reputation score based on network activity).
At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Miel with the teachings of Beckett, the session request to be a subscription request, to extend the continuous trust evaluation from session relationships to subscription relationships.
As per claim 2, the combination of Miel and Beckett teaches the FESP of claim 1, wherein the trust index is a metric that indicates a level of trustworthiness and is based on a trust evaluation of one or more trust indicators (Miel; [0011], accessing trustworthiness of user continuously based on security posture which includes indicators such as status, location and actions see [0018]).
As per claim 3, the combination of Miel and Beckett teaches the teaches the FESP of claim 2, wherein the trust indicators comprise factors related to at least one of security, privacy, resilience, performance, robustness, scalability, reputation, availability, accuracy, reliability, or consistency (Miel; [0018] and [0046]-[0047], various security and risk events and behaviors are monitored that can affect security and reliability of the user or device) see also (Beckett; [0020], subscriber reputation score).
As per claim 4, the combination of Miel and Beckett teaches the teaches the FESP of claim 1, wherein the processor and the transceiver are further configured to determine to not authenticate the subscription request based on the trust index being less than the threshold and to send a response message to the FESC indicating the subscription request cannot be accepted (Miel; [0014] and [0060], not authenticating a session or not reauthenticating user for a new session based on a policy that includes a score being below a threshold and alerting the user see also [0052] initial trust level of authentication).
As per claim 5, the combination of Miel and Beckett teaches the FESP of claim 1, wherein the processor and the transceiver are further configured to send a subscription update or cancellation request message to the FESC to adjust or cancel the subscription based on the updated trust index of the FESC being less than the threshold (Miel; [0014]-[015] and [0051], alerting user of an event that lowers trust level below a threshold and what is required to reinstate full permissions, i.e. adjustment of permissions were made see also [0056]).
As per claim 6, the combination of Miel and Beckett teaches the FESP of claim 1, wherein the processor and the transceiver are further configured to subscribe to the TMF to receive the trust index and updated trust indices of the FESC over a duration (Miel; Fig. 1 and [0017], network including a network security agent “subscribes” to the authentication service for trust calculations by the trust engine and policy engine see also [0033]).
As per claim 7, the combination of Miel and Beckett teaches the FESP of claim 1, wherein the processor and the transceiver are further configured to send a request for the updated trust index, to the TMF, in response to the condition being met (Miel; [0047], trust level is calculated by and obtained form authentication service or trust engine see [0017]).
As per claim 8, the combination of Miel and Beckett teaches the FESP of claim 1, wherein the processor and the transceiver are further configured to send a response to the FESC indicating successful subscription based on the transceiver and the processor determining to authenticate the subscription request (Miel; [0041], user and user device is notified of a successful authentication by subsequent actions including setting up a secure communication with the network).
As per claim 11, the substance of the claimed invention is identical or substantially similar to that of claim 1. Accordingly, this claim is rejected under the same rationale.
As per claim 12, the substance of the claimed invention is identical or substantially similar to that of claim 2. Accordingly, this claim is rejected under the same rationale.
As per claim 13, the substance of the claimed invention is identical or substantially similar to that of claim 3. Accordingly, this claim is rejected under the same rationale.
As per claim 14, the substance of the claimed invention is identical or substantially similar to that of claim 4. Accordingly, this claim is rejected under the same rationale.
As per claim 15, the substance of the claimed invention is identical or substantially similar to that of claim 5. Accordingly, this claim is rejected under the same rationale.
As per claim 16, the substance of the claimed invention is identical or substantially similar to that of claim 6. Accordingly, this claim is rejected under the same rationale.
As per claim 17, the substance of the claimed invention is identical or substantially similar to that of claim 7. Accordingly, this claim is rejected under the same rationale.
As per claim 18, the substance of the claimed invention is identical or substantially similar to that of claim 8. Accordingly, this claim is rejected under the same rationale.
As per claim 21, the substance of the claimed invention is identical or substantially similar to that of claim 1. Accordingly, this claim is rejected under the same rationale.
As per claim 22, the substance of the claimed invention is identical or substantially similar to that of claim 2. Accordingly, this claim is rejected under the same rationale.
As per claim 23, the substance of the claimed invention is identical or substantially similar to that of claim 3. Accordingly, this claim is rejected under the same rationale.
As per claim 24, the substance of the claimed invention is identical or substantially similar to that of claim 1. Accordingly, this claim is rejected under the same rationale.
As per claim 25, the substance of the claimed invention is identical or substantially similar to that of claim 4. Accordingly, this claim is rejected under the same rationale.
Claims 9-10 and 19-20 are rejected under 35 U.S.C. 103 unpatentable over Miel and Beckett in further view of Baskaran et al. (WO-2022096126-A1) [hereinafter “Baskaran”].
As per claim 9, the combination of Miel and Beckett teaches the FESP of claim 1, wherein the processor and the transceiver are further configured to store the updated trust index of the FESC to a least one storage (Miel; [0049], trust engine stores trust level/score and also stores updated level/score).
The combination of Miel and Beckett does not explicitly teach a permissioned distributed ledger (PDL) for storing accessible network data. PRIOR teaches a permissioned distributed ledger (PDL) for storing accessible network data ([0095], storing network users trust data in a permissioned distributed ledger).
At the time of filing, it would have been obvious to one of ordinary skill in the art to combine Miel and Beckett with the teachings of Baskaran, a permissioned distributed ledger (PDL) for storing accessible network data, to provide different ways to access and distribute network data that needs to be accessed on the fly.
As per claim 10, the combination of Miel, Beckett and Baskaran teaches the FESP of claim 9, wherein the processor and the transceiver are further configured to retrieve trust indices from the at least one PDL (Miel; [0049], trust indices are retrieved from authentication service and/or trust engine) with (Baskaran; [0095], storing network users trust data in a permissioned distributed ledger).
As per claim 19, the substance of the claimed invention is identical or substantially similar to that of claim 9. Accordingly, this claim is rejected under the same rationale.
As per claim 20, the substance of the claimed invention is identical or substantially similar to that of claim 10. Accordingly, this claim is rejected under the same rationale.
Response to Arguments
Applicant’s arguments with respect to the rejection of claims 1-25 under 35 U.S.C. 102 have been fully considered and are persuasive. Examiner has introduced and cited to new prior art references, Miel, Beckett and Baskaran. The rejection remains non-final.
To expedite prosecution, Examiner is open to conducting an interview to discuss claim amendments to overcome the current rejection and/or place the application in condition for allowance.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Mitchell et al. (US PGPUB No. 2023/0283591), Leong et al. (US PGPUB No. 2019/0340619), Michaelis (US PGPUB No. 2025/0286704), Liu et al. ("A Trust Model Based on Service Classification in Mobile Services," 2010 IEEE, Hangzhou, China, 2010, pp. 572-577, doi: 10.1109/GreenCom-CPSCom.2010.19) and Peng et al. ("Reputation-based Trust Update in Network Environment," 2008 International Symposium on Electronic Commerce and Security, Guangzhou, China, 2008, pp. 118-123, doi: 10.1109/ISECS.2008.211) all disclose various aspects of the claimed invention including using trust scores to authenticate interactions between network function types.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to PETER C SHAW whose telephone number is 571-270-7179.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached on 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/PETER C SHAW/Primary Examiner, Art Unit 2493 September 4, 2026