Prosecution Insights
Last updated: August 17, 2026
Application No. 18/782,737

AUTHENTICATION IN ACCESS NETWORK SHARING ENVIRONMENT

Non-Final OA §103
Filed
Jul 24, 2024
Priority
Jul 26, 2023 — IN 202311050329
Examiner
WINN, JUSTIN HUYNH
Art Unit
Tech Center
Assignee
Nokia Corporation
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-60.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
2 currently pending
Career history
2
Total Applications
across all art units

Statute-Specific Performance

§103
50.0%
+10.0% vs TC avg
§102
28.6%
-11.4% vs TC avg
§112
21.4%
-18.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 0 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Acknowledgment is made of applicant’s claim for foreign priority under 35 U.S.C. 119 (a)-(d). Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55. Information Disclosure Statement The information disclosure statement filed November 14, 2024 fails to comply with 37 CFR 1.98(a)(2), which requires a legible copy of each cited foreign patent document; each non-patent literature publication or that portion which caused it to be listed; and all other information or that portion which caused it to be listed. Specifically, the following non-patent literature publications were not present: "3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 18)", 3GPP TS 23.501, V18.2.2, July, 2023, pp. 1-694. “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Service requirements for the 5G system; Stage 1 (Release 19)", 3GPP TS 22.261, V19.3.0, June, 2023, 121 pages. It has been placed in the application file, but the information referred to therein has not been considered. Specification The disclosure is objected to because of the following informalities: page 22, line 13 refers to a "second access management entity network". This inclusion of "network" appears to be unintentional. Figure 6A is said to illustrate an embodiment where the “hosting AMF acts as a relay AMF … (consistent with protocol stack configuration 500 of Fig. 5A)” on page 17, lines 2-4. This conflicts with the statement that “The hosting AMF 606 is the main AMF”, also referring to Figure 6A/protocol stack configuration 500 of Fig. 5A, on page 18, line 10. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claim(s) 1-5, 7, 8, 10-14, 17, 18, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Li et al. (US Patent Publication 20210195399 A1, hereinafter Li) in view of Lopes et al. (US Patent Publication 20240389177 A1, hereinafter Lopes). Regarding claim 1, Li discloses an apparatus comprising: at least one processor (p. 0053, “According to a fourteenth aspect, an embodiment of this application provides a communications apparatus, including a processor and a memory”); and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to be configured as a first access management entity in a first communication network, wherein the first communication network has a radio access network associated therewith (p. 0096 “The processor 301 is configured to invoke the computer program code stored in the memory 302, to perform a function of a core network device in the following method embodiments…”, claim 1 “…the first access and mobility management function network element is located in the first network” p. 0098 “The communications interface 303 is configured to communicate with a RAN network element or a core network device”, Fig. 2 depicts connection between first network AMF and RAN), the first access management entity being configured to: establish a a second message to a second access and mobility management function network element … and the second access and mobility management function network element is located in the second network”, p. 0104 “A second network may be an operator network, … a subscribed network of a user, … or a network to which a user subscribes”); and facilitate authentication of the user equipment in conjunction with the second access management entity over the a second message to a second access and mobility management function network element, wherein the second message is used to request to register the terminal device with the second network, the second message comprises the second identification information, and the second access and mobility management function network element is located in the second network”, p. 0083 “The terminal device 23 includes various devices with a wireless communication function, for example, … user equipment (UE)…”; registration of the terminal device to the second network’s AMF implies utilization of the radio access network associated with the first network). Although Li does disclose the apparatus establishing a connection with a second access management entity in a second communication network to which user equipment subscribes, it does not characterize that connection as being secure. In the same field of endeavor, Lopes discloses an apparatus establishing a secure connection with a second access management entity in a second communication network to which user equipment subscribes (p. 0032 “… the second network operator may instead use the RAN deployed by the first network operator to support communications for the second network operator UEs within the RAN”, p. 0111, “In some cases, the interface used for the connection between network operators may be a secure transport communication link 125 including IP connectivity or stream transmission control protocol (STCP)/IP … Further, to support such connections between AMFs of different network operators, network operators may have to cooperate with each other to establish connectivity across secure domains. For example, inter-operator connections (e.g., the communication link 125 between the local AMF 320 and the remote AMF 330) may use existing interfaces (e.g., N32 interface) between security edge protection proxies (SEPPs) of different PLMNs or different network operators”). Therefore, it would have been obvious to a person of ordinary skill in the art before the effectivedate of the claimed invention to apply a secure protocol in the connection between AMFs as disclosed in Lopes, to the initiation of the subscribed terminal device’s connection to second AMF from first AMF disclosed in Li, in order to improve the security arrangement during communication of the otherwise exposed AMF messages. Regarding claim 2, Li in view of Lopes discloses the apparatus of claim 1, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured as a primary access management entity that maintains a security context of the user equipment (Li p. 0251, “For example, the first AMF network element may send a security context to the RAN network element, and the RAN network element stores the security context, and sends an acknowledgement message to the first AMF network element”; the contents of a security context are inherently related to a corresponding UE). Regarding claim 3, Li in view of Lopes discloses the apparatus of claim 2, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured to receive a first key from the second access management entity (Li p. 0013, “In a possible implementation, the communication method further includes: The first access and mobility management function network element receives a network key of the terminal device in the second network from the second access and mobility management function network element”). Regarding claim 4, Li in view of Lopes discloses the apparatus of claim 3, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured to perform one or more non-access stratum security procedures with the user equipment (Li p. 0131, “For example, the network key may be a key used by the first AMF network element to perform encryption and integrity protection on a non-access stratum (non access stratum, NAS) and an access stratum (AS); or the network key may be a key generated by the first AMF network element and used by the first AMF network element to perform encryption and integrity protection on a non-access stratum and an access stratum. For example, the network key may be KAMF.”, p. 0236 “Correspondingly, the first AMF network element receives the first registration request message from the terminal device.”, p. 0237, “The registration request message may be a non-access stratum (NAS) message”). Regarding claim 5, Li in view of Lopes discloses the apparatus of claim 3, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured to generate a second key based on the first key received from the second access management entity (Li p. 0131 “For example, the network key may be KAMF”, p. 0402, “a mobility management function key KAMF, where the first AMF network element may generate corresponding information such as KNASint and KNASenc based on KAMF, KNASint is a NAS integrity protection key, and KNASenc is a NAS encryption key”). Regarding claim 7, Li in view of Lopes discloses the apparatus of claim 1, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured as a relay access management entity that relays messages to the second access management entity that is configured as a primary access management entity that maintains a security context of the user equipment (Lopes p. 0087 “Therefore, the first network operator and the second network operator may use an AMF proxy function to provide connectivity between the RAN of the first network operator and a remote AMF of the second network operator. In some cases, the AMF proxy function may be referred to as a non-transparent proxy”, p. 0088 “The RAN of the first network operator may connect directly with the AMF proxy and the AMF proxy may connect with the AMF of first network operator and the AMF of the second network operator instead of the RAN providing such connections”, Li p. 0280 “the second AMF network element generates a NAS security key. For example, the second AMF network element generates the NAS security key based on KSEAF (an element that is in the authentication vector of the terminal device in the operator network and that is used to generate a key). In addition, the second AMF network element sends a security mode command message to the terminal device”; here, the AMF proxy function taken together with the AMF of the first network operator maps onto the first access management entity of the claimed invention). Regarding claim 8, Li in view of Lopes discloses the apparatus of claim 7, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured to maintain a mapping between an identifier of the user equipment (Lopes claim 2, “The apparatus of claim 1, wherein the instructions are further executable by the processor to cause the apparatus to: maintain a context that indicates the first mapping between a plurality of AMF UE identifiers … the plurality of AMF UE identifiers comprising the AMF UE identifier”) and an identifier of the second access management entity (p. 0115, “The identification message may include a set of globally unique AMF IDs (GUAMIs) associated with the AMFs connected to the AMF proxy 415…“, p. 0152 “…and where the second network operator associated with the second AMF is identified from the second GUAMI” p. 0033 “Traditionally, to support network sharing in this manner, the RAN may independently connect with an AMF of the first network operator and an AMF of the second network operator and may forward messages to a respective AMF depending on the network operator of the UE that sent the message to the RAN”, p. 0129 “At 540, the AMF proxy 510 may transmit a second message to the first AMF 515 via the second communication link based on the AMF UE 115 ID being for the first AMF 515 of the first network operator or the AMF proxy 510 may transmit the second message to the second AMF 520 via the third communication link based on the AMF UE 115 ID being for the second AMF 520 of the second network operator”; Lopes necessarily associates each UE identifier with the access management entity to which that UE’s messages are to be relayed; in order to route on a per-UE basis between to AMFs identified by their respective GUAMIs, the maintained context must associate each UE identifier with the AMF (i.e. the GUAMI) that serves it). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective date of the claimed invention to maintain a mapping between an identifier of the user equipment and an identifier of the second access management entity in order to route signals from a UE to a respective AMF. Regarding claim 10, Li discloses a method comprising: establishing, via a first access management entity in a first communication network that has a radio access network associated therewith (claim 1 “…the first access and mobility management function network element is located in the first network” p. 0098 “The communications interface 303 is configured to communicate with a RAN network element or a core network device”, Fig. 2 depicts connection between first network AMF and RAN), a a second message to a second access and mobility management function network element … and the second access and mobility management function network element is located in the second network”, p. 0104 “A second network may be an operator network, … a subscribed network of a user, … or a network to which a user subscribes”); and facilitating, via the first access management entity, authentication of the user equipment in conjunction with the second access management entity over the a second message to a second access and mobility management function network element, wherein the second message is used to request to register the terminal device with the second network, the second message comprises the second identification information, and the second access and mobility management function network element is located in the second network”, p. 0083 “The terminal device 23 includes various devices with a wireless communication function, for example, … user equipment (UE)…”; registration of the terminal device to the second network’s AMF implies utilization of the radio access network associated with the first network). Although Li does disclose the first access management entity establishing a connection with a second access management entity in a second communication network to which user equipment subscribes, it does not characterize that connection as being secure. In the same field of endeavor, Lopes discloses a first access management entity establishing a secure connection with a second access management entity in a second communication network to which user equipment subscribes (p. 0032 “… the second network operator may instead use the RAN deployed by the first network operator to support communications for the second network operator UEs within the RAN”, p. 0111, “In some cases, the interface used for the connection between network operators may be a secure transport communication link 125 including IP connectivity or stream transmission control protocol (STCP)/IP … Further, to support such connections between AMFs of different network operators, network operators may have to cooperate with each other to establish connectivity across secure domains. For example, inter-operator connections (e.g., the communication link 125 between the local AMF 320 and the remote AMF 330) may use existing interfaces (e.g., N32 interface) between security edge protection proxies (SEPPs) of different PLMNs or different network operators.”). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective date of the claimed invention to use a secure protocol in the connection between AMFs as disclosed in Lopes, to the initiation of the subscribed terminal device’s connection to second AMF from first AMF disclosed in Li, in order to improve the security arrangement during communication of the otherwise exposed AMF messages. Regarding claim 11, Li in view of Lopes discloses a non-transitory computer-readable storage medium having embodied therein executable program code that when executed by a processor causes the processor to perform the method of claim 10 (Li p. 0096 “The processor 301 is configured to invoke the computer program code stored in the memory 302, to perform a function of a core network device in the following method embodiments…”). Regarding claim 12, Li discloses an apparatus comprising: at least one processor (p. 0053, “According to a fourteenth aspect, an embodiment of this application provides a communications apparatus, including a processor and a memory”); and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to be configured as a first access management entity in a first communication network to which user equipment subscribes (p. 0096 “The processor 301 is configured to invoke the computer program code stored in the memory 302, to perform a function of a core network device in the following method embodiments…”, claim 1 “…the second access and mobility management function network element is located in the second network”, p. 104 “A second network may be an operator network, … a subscribed network of a user, … or a network to which a user subscribes”; here, the second AMF of Li maps to the first access management utility of the claimed invention), the first access management entity being configured to: establish a facilitate authentication of the user equipment in conjunction with the second access management entity over the function network element, the second message from the first access and mobility management function network element; and registering, by the second access and mobility management function network element, the terminal device with the second network based on the second identification information”, p. 0028, “The second access and mobility management function network element sends the authentication vector of the terminal device in the second network to the first access and mobility management function network element”, p. 0129 “The second AMF network element sends a network key of the terminal device in the second network to the first AMF network element”, p. 0083 “The terminal device 23 includes various devices with a wireless communication function, for example, … user equipment (UE)…”; registration of the terminal device with Li’s second network by way of Li’s first network implies utilization of the radio access network associated with Li’s first network). Although Li does disclose the apparatus establishing a connection with a second access management entity in a second communication network, wherein the second communication network has a radio access network associated therewith, it does not characterize that connection as being secure. In the same field of endeavor, Lopes discloses an apparatus establishing a secure connection with a second access management entity in a second communication network, wherein the second communication network has a radio access network associated therewith (p. 0032 “… the second network operator may instead use the RAN deployed by the first network operator to support communications for the second network operator UEs within the RAN”, p. 0111, “In some cases, the interface used for the connection between network operators may be a secure transport communication link 125 including IP connectivity or stream transmission control protocol (STCP)/IP … Further, to support such connections between AMFs of different network operators, network operators may have to cooperate with each other to establish connectivity across secure domains. For example, inter-operator connections (e.g., the communication link 125 between the local AMF 320 and the remote AMF 330) may use existing interfaces (e.g., N32 interface) between security edge protection proxies (SEPPs) of different PLMNs or different network operators”). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective date of the claimed invention to apply a secure protocol in the connection between AMFs as disclosed in Lopes, to the initiation of the subscribed terminal device’s connection to second AMF from first AMF disclosed in Li, in order to improve the security arrangement during communication of the otherwise exposed AMF messages. Regarding claim 13, Li in view of Lopes discloses the apparatus of claim 12, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured as a primary access management entity that maintains a security context of the user equipment (Li p. 0372, “The second AMF network element initiates a NAS security mode command (SMC) procedure to the terminal device”, p. 0373, “In this step, the terminal device successfully establishes a security context with the second AMF network element”). Regarding claim 14, Li in view of Lopes discloses the apparatus of claim 13, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured to perform one or more non-access stratum security procedures with the user equipment (Li p. 0279, “The second AMF network element initiates the NAS security procedure for the terminal device in the operator network”, p. 0280 “For example, when the second AMF network element successfully authenticates the terminal device, the second AMF network element generates a NAS security key. For example, the second AMF network element generates the NAS security key based on KSEAF (an element that is in the authentication vector of the terminal device in the operator network and that is used to generate a key). In addition, the second AMF network element sends a security mode command message to the terminal device”). Regarding claim 17, Li in view of Lopes discloses the apparatus of claim 12, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured to assist with key management for the second access management entity that is configured as a primary access management entity that maintains a security context of the user equipment (Li p. 0397, “The second AMF network element sends the network key of the terminal device to the first AMF network element.”, p. 0399, “Step S1005 may include: The second AMF network element determines the network key of the terminal device based on a local policy configuration”, p. 0251, “For example, the first AMF network element may send a security context to the RAN network element, and the RAN network element stores the security context, and sends an acknowledgement message to the first AMF network element”; the contents of a security context are inherently related to a corresponding UE). Regarding claim 18, Li in view of Lopes discloses the apparatus of claim 17, wherein, when facilitating authentication of the user equipment, the first access management entity is further configured to generate a first key (Li p. 0280, “For example, when the second AMF network element successfully authenticates the terminal device, the second AMF network element generates a NAS security key. For example, the second AMF network element generates the NAS security key based on KSEAF (an element that is in the authentication vector of the terminal device in the operator network and that is used to generate a key). In addition, the second AMF network element sends a security mode command message to the terminal device”) Regarding claim 20, Li discloses a method comprising: establishing, via a first access management entity in a first communication network to which user equipment subscribes (claim 1, “…the second access and mobility management function network element is located in the second network”, p. 0104 “A second network may be an operator network, … a subscribed network of a user, … or a network to which a user subscribes”; here, the second AMF of Li maps to the first access management utility of the claimed invention), a facilitating, via the first access management entity, authentication of the user equipment in conjunction with the second access management entity over the secure connection to enable the user equipment to utilize the radio access network associated with the second communication network to access the first communication network (claim 7, “receiving, by the second access and mobility management function network element, the second message from the first access and mobility management function network element; and registering, by the second access and mobility management function network element, the terminal device with the second network based on the second identification information”, p. 0028 “The second access and mobility management function network element sends the authentication vector of the terminal device in the second network to the first access and mobility management function network element”, p. 0129 “The second AMF network element sends a network key of the terminal device in the second network to the first AMF network element”, p. 0083 “The terminal device 23 includes various devices with a wireless communication function, for example, … user equipment (UE)…”; registration of the terminal device with Li’s second network by way of Li’s first network implies utilization of the radio access network associated with Li’s first network). Although Li does disclose the first access management entity establishing a connection with a second access management entity in a second communication network, wherein the second communication network has a radio access network associated therewith, it does not characterize that connection as being secure. In the same field of endeavor, Lopes discloses a first access management entity establishing a secure connection with a second access management entity in a second communication network, wherein the second communication network has a radio access network associated therewith (p. 0032 “… the second network operator may instead use the RAN deployed by the first network operator to support communications for the second network operator UEs within the RAN”, p. 0111, “In some cases, the interface used for the connection between network operators may be a secure transport communication link 125 including IP connectivity or stream transmission control protocol (STCP)/IP … Further, to support such connections between AMFs of different network operators, network operators may have to cooperate with each other to establish connectivity across secure domains. For example, inter-operator connections (e.g., the communication link 125 between the local AMF 320 and the remote AMF 330) may use existing interfaces (e.g., N32 interface) between security edge protection proxies (SEPPs) of different PLMNs or different network operators”). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective date of the claimed invention to apply a secure protocol in the connection between AMFs as disclosed in Lopes, to the initiation of the subscribed terminal device’s connection to second AMF from first AMF disclosed in Li, in order to improve the security arrangement during communication of the otherwise exposed AMF messages. Claims 6, 9, 15, 16, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Li in view of Lopes and further in view of European Telecommunication Standards Institute Technical Specification 133 501 v16.7.1, hereinafter TS 33.501. Regarding claim 6, Li in view of Lopes discloses the apparatus of claim 5 (see claim 5 rejection above), but does not disclose, when facilitating authentication of the user equipment, the first access management entity is further configured to send the second key to the radio access network to enable the radio access network and the user equipment to perform one or more access stratum security procedures. In the same field of endeavor, TS 33.501 discloses when facilitating authentication of the user equipment, the first access management entity being further configured to send the second key to the radio access network to enable the radio access network and the user equipment to perform one or more access stratum security procedures (section 6.2.2.1 [page 52], “The AMF shall generate access network specific keys from KAMF. In particular, … the AMF shall generate KgNB and transfer it to the gNB … The NG-RAN (i.e., gNB or ng-eNB) receives KgNB and NH from the AMF. The ng-eNB uses KgNB as KeNB. The NG-RAN (i.e., gNB or ng-eNB) shall generate all further access stratum (AS) keys from KgNB and/or NH.”, section 6.9.2.1.1 [page 81], “Whenever an initial AS security context needs to be established between UE and gNB/ng-eNB, AMF and the UE shall derive a KgNB and a Next Hop parameter (NH). The KgNB and the NH are derived from the KAMF”). Therefore, it would have been obvious to a person of ordinary skill in the art before the effectivedate of the claimed invention to send a key to a radio access network from the first access management entity in order to secure the access stratum (UE-to-RAN) connection while maintaining compatibility with existing 5G infrastructure. Regarding claim 9, Li in view of Lopes discloses the apparatus of claim 8 (see claim 8 rejection above), but does not disclose, when facilitating authentication of the user equipment, the first access management entity being further configured to: receive a key from the second access management entity; and send the key to the radio access network to enable the radio access network and the user equipment to perform one or more access stratum security procedures. In the same field of endeavor, TS 33.501 discloses when facilitating authentication of the user equipment, the first access management entity being further configured to: receive a key from the second access management entity (section 6.9.2.1.2 [page 82], “1) Source AMF indicates AS key rekeying required meaning that the KAMF sent by source AMF to the target AMF is not in sync with current gNB/ng-eNB with keyAmfChangeInd (KAMF Change Indicator). 2) Source AMF indicates that the KAMF sent by source AMF to target AMF has been calculated using horizontal KAMF derivation with keyAmfHDerivationInd (KAMF Horizontal Derivation Indicator). 3) The target AMF indicates a horizontal KAMF derivation to the UE with K_AMF_change_flag in the NAS Container to tell the NAS layer of the UE to change KAMF. 4). The target AMF indicates anAS key re-keying to the gNB/ng eNB with NSCI (New Security Context Indicator)”); and send the key to the radio access network to enable the radio access network and the user equipment to perform one or more access stratum security procedures (section 6.9.2.1.1 [page 81], “Whenever an initial AS security context needs to be established between UE and gNB/ng-eNB, AMF and the UE shall derive a KgNB and a Next Hop parameter (NH). The KgNB and the NH are derived from the KAMF”; a connection between a UE and a gNB is inherently a connection to the gNB’s associated RAN). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective date of the claimed invention to send a key to a radio access network from the first access management entity in order to secure the access stratum (UE-to-RAN) connection while maintaining compatibility with existing 5G infrastructure. Regarding claim 15, Li in view of Lopes discloses the apparatus of claim 14, but does not disclose when facilitating authentication of the user equipment, the first access management entity being further configured to generate a key to enable the radio access network and the user equipment to perform one or more access stratum security procedures. In the same field of endeavor, TS 33.501 discloses when facilitating authentication of the user equipment, the first access management entity being further configured to generate a key (section A.9 shows a function deriving K_gNB from K_AMF; section 6.2.2.1 [page 52], “The AMF shall generate access network specific keys from KAMF. In particular, the AMF shall generate KgNB and transfer it to the gNB”) to enable the radio access network and the user equipment to perform one or more access stratum security procedures (section 6.9.2.1.1 [page 81], “Whenever an initial AS security context needs to be established between UE and gNB/ng-eNB, AMF and the UE shall derive a KgNB and a Next Hop parameter (NH). The KgNB and the NH are derived from the KAMF”). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective date of the claimed invention generate a key for access stratum security procedures in order to secure the access stratum (UE-to-RAN) connection while maintaining compatibility with existing 5G infrastructure. Regarding claim 16, Li in view of Lopes and further in view of TS 33.501 discloses the apparatus of claim 15, wherein, when facilitating authentication of the user equipment, the first access management entity being further configured to send the key to second access management entity for forwarding to the radio access network (section 6.9.2.1.2 [page 82], “1) Source AMF indicates AS key rekeying required meaning that the KAMF sent by source AMF to the target AMF is not in sync with current gNB/ng-eNB with keyAmfChangeInd (KAMF Change Indicator). 2) Source AMF indicates that the KAMF sent by source AMF to target AMF has been calculated using horizontal KAMF derivation with keyAmfHDerivationInd (KAMF Horizontal Derivation Indicator). 3) The target AMF indicates a horizontal KAMF derivation to the UE with K_AMF_change_flag in the NAS Container to tell the NAS layer of the UE to change KAMF. 4). The target AMF indicates anAS key re keying to the gNB/ng-eNB with NSCI (New Security Context Indicator).”, section 6.2.2.1 [page 52], “The AMF shall generate access network specific keys from KAMF. In particular, … the AMF shall generate KgNB and transfer it to the gNB … The NG-RAN (i.e., gNB or ng-eNB) receives KgNB and NH from the AMF. The ng-eNB uses KgNB as KeNB. The NG-RAN (i.e., gNB or ng-eNB) shall generate all further access stratum (AS) keys from KgNB and/or NH.”). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective date of the claimed invention to send a key to a radio access network from the second access management entity received from the first access management entity in order to, for example, secure the access stratum (UE-to-RAN) connection while maintaining compatibility with existing 5G infrastructure. Regarding claim 19, Li in view of Lopes discloses the apparatus 18 (see claim 18 rejection above), but does not disclose, when facilitating authentication of the user equipment, the first access management entity being further configured to send the first key to the second access management entity to enable the second access management entity to generate a second key based on the first key, wherein the second key is usable to enable the radio access network and the user equipment to perform one or more access stratum security procedures. In the same field of endeavor, TS 33.501 discloses when facilitating authentication of the user equipment, the first access management entity being further configured to send the first key to the second access management entity (section 6.9.2.1.2 [page 82], “1) Source AMF indicates AS key rekeying required meaning that the KAMF sent by source AMF to the target AMF is not in sync with current gNB/ng-eNB with keyAmfChangeInd (KAMF Change Indicator)”) to enable the second access management entity to generate a second key based on the first key (section A.9 shows a function deriving K_gNB from K_AMF; section 6.2.2.1 [page 52], “The AMF shall generate access network specific keys from KAMF. In particular, the AMF shall generate KgNB and transfer it to the gNB”), wherein the second key is usable to enable the radio access network and the user equipment to perform one or more access stratum security procedures (section 6.9.2.1.1 [page 81], “Whenever an initial AS security context needs to be established between UE and gNB/ng-eNB, AMF and the UE shall derive a KgNB and a Next Hop parameter (NH). The KgNB and the NH are derived from the KAMF”). Therefore, it would have been obvious to a person of ordinary skill in the art before the effective date of the claimed invention to send a key to a radio access network from the second access management entity received from the first access management entity to generate another key in order to, for example, secure the access stratum (UE-to-RAN) connection while maintaining compatibility with existing 5G infrastructure. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JUSTIN WINN whose telephone number is (571)270-5541. The examiner can normally be reached M-F, 9am to 5pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rafael Perez-Gutierrez can be reached at (571) 272-7915. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JUSTIN HUYNH WINN/Examiner, Art Unit 2642 /Rafael Pérez-Gutiérrez/Supervisory Patent Examiner, Art Unit 2642
Read full office action

Prosecution Timeline

Jul 24, 2024
Application Filed
Jul 27, 2026
Non-Final Rejection mailed — §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month