DETAILED ACTION
Claims 1-20 are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The Information Disclosure Statement(s) submitted by applicant on 05/05/2025 and 07/26/2024 has/have been considered. The submission is in compliance with the provisions of 37 CFR § 1.97. Form PTO-1449 signed and attached hereto.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Yang et al. (US Patent Application No. US 20230308874 A1) (Hereinafter Yang) in view of Huang et al. (US Patent Application No. 20250088364) (Hereinafter Huang).
As per claim 1, Yang discloses a method comprising: performing an association process with a Station (STA) (para 16, performing an association process between AP and a first device/STA. the AP may further perform an association with the first device)
receiving an initial Key Confirmation Key (KCK) (para 19, receiving/generating key confirmation keys during an initial security suite negotiation. the first PTk1 includes a first key confirmation key KVK1);
performing a four-way handshake to derive one or more keys using the PMKID (para17, When the first PMK1 is the same as the second PMK2, the AP may perform the 4-way handshake with the first device based on the PMK. ", par. [20] : "
both the AP and the first device can perform, based on the PMK, identity authentication through a 4-way handshake process, and generate a session key and a group transient key).
Yang further discloses the access point AP negotiates, based on a password, a pairwise master key PMK with a first device based on a twin base password encrypted key exchange TBPEKE protocol, where the password is a shared key between the AP and the first device; and then the AP performs a 4 way handshake with the first device based on the PMK ,…. the AP and the first device can perform, based on the PMK, identity authentication through a 4-way handshake process ", i.e. the PMK is identified based on the PMKID which is based on the exchanged PTKs that included the KCK, i.e. the PMKID is determined based on the KCK (para 8, 20).
Yang does not explicitly disclose determining a Pairwise Master Key (PMK) Identifier (PMKID) based on the initial KCK. However, Huang explicitly discloses determining a Pairwise Master Key (PMK) Identifier (PMKID) based on the initial KCK (para 74, When the negotiated AKM uses PMKID derivation with (#3744)PTK-KCK as a parameter as defined in 12.7.1.3 (Pairwise key hierarchy), the PMKID derived from the PTK-KCK during the initial 4-way handshake is not changed during the lifetime of this PMKSA).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Yang and Huang. The motivation would have been to streamline key identification and maintain consistent security association.
The Examiner notes that this motivation applies to all dependent and/or otherwise subsequently addressed claims.
As per claim 2, claim is rejected for the same reasons and motivations, as claim 1, above. In addition, Yang discloses wherein the initial KCK is derived during an initial association and authentication process of the STA with an Access Point (AP) (para 19, deriving key confirmation keys during initial authentication/association, see Huang para 74).
As per claim 3, the claim is rejected for the same reasons and motivations as claim 1, above. In addition, Huang discloses wherein receiving the initial KCK comprises receiving the initial KCK from a cache wherein the AP sends the initial KCK to the cache after the initial association and authentication process (para 73, 82, opportunistic key caching and sending/retrieving cache identifiers) .
As per claim 4, claim is rejected for the same reasons and motivations, as claim 1, above. In addition, Huang discloses wherein determining the PMKID based on the initial KCK comprises applying a hash function to a concatenation of the initial KCK,
an address of authenticator, and an address of the STA (para 77, authenticator/Peer MAC addresses in PMKSA, also yang: para 25 KDF concatenation functions).
As per claim 5, claim is rejected for the same reasons and motivations as claim 1, above. In addition, Huang discloses wherein the STA stores the initial KCK, and wherein receiving the initial KCK comprises receiving the initial KCK from the STA (para 72, client storage and sending PMKIDs/credentials to the AP).
As per claim 6, claim is rejected for the same reasons and motivations, as claim 1, above. In addition, Yang discloses wherein receiving the initial KCK comprises receiving the initial KCK from a security association element stored by a cache, wherein the security association element comprises an STA ID field and a KCK field (para 76-77, lists fields in a PMKSA element, also see Yang: para 26).
As per claim 7, claim is rejected for the same reasons and motivations, as claim 1, above. In addition, Yang discloses further comprising: deriving a PMK based on the PMKID; and deriving a new Pairwise Transient Key (PTK) for the STA based on the PMK, wherein performing the four-way handshake to derive the one or more keys comprises using the new PTK (para 17-20, deriving PMKs, generating PTks, and executing 4- way handshake).
As per claims 8-14, claims are rejected for the same reasons and motivations as claims 1-7, above.
As per claims 15-14, claims are rejected for the same reasons and motivations as claims 1-4 and 6-7, above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Hwakes et al ( US 20130243194 A1) discloses client device is performing a 4-way handshake with an access point (AP), a pair-wise master key (PMK) is generated and additional keys, such as a pair-wise transient key (PTK), are derived from the PMK. The PTK remains valid for as long as the PMK remains valid; thus, without added security (such as PFS), an attacker may derive the PTK from a compromised PMK to decode transmissions between the client device and the AP during an effective lifetime of the compromised PMK. Instead of relying on derived keys that may remain valid for as long as the PMK may remain valid, the described techniques provide enhanced security by implementing PFS in the 4-way handshake.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMAD A SIDDIQI whose telephone number is (571)272-3976. The examiner can normally be reached Monday-Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl G Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MOHAMMAD A SIDDIQI/Primary Examiner, Art Unit 2493