Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-10 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Each of claims 1 and 6 recite the limitations “in a case that the primary authentication is not performed …” and “in a case that the primary authentication is performed…”, however neither limitation is preceded with any indication on whether the “primary authentication” has been actually performed or not. In other words, claims 1 and 6 recite “based on a primary authentication” but this does not provide the requisite function of “primary authentication” being performed (or not performed). Thus, given the lack of any positively recited condition corresponding to the “primary authentication” actually being performed (or not), the examiner finds each of the respective results to said condition as being indefinite.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1, 2, and 5 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by “Wu” (US 2023/0232228).
Regarding Claim 1:
A method performed by a user equipment (UE) in a wireless network (Fig. 10), the method comprising:
receiving, from an upper layer of the UE (¶0074, “An edge enable client (EEC) is a peer entity on the terminal side device. The EEC is configured to register EEC information and AC information with the EES, perform security authentication and authorization …”; ¶0076, “An enable client (for example, the EEC) may be … implemented inside the AC”; i.e., the EEC, when implemented within an application client (AC) is considered to be operating within an application (upper) layer), a request for providing an authentication and key management for applications (AKMA) anchor key (KAKMA) and an AKMA key identifier (A-KID) (¶0154, “The edge enabler client registration request message includes capability information of the UE, and the capability information of the UE includes at least one second authentication mechanism supported by the UE. Optionally, the capability information of the UE may further include a network type used by the UE to access the EAS and priority information of the at least one authentication mechanism supported by the UE”; ¶0199), wherein the KAKMA and the A-KID are generated based on an authentication server function (AUSF) key (KAUSF) (¶0199, “If the UE can use the AKMA authentication mechanism (for example, the AUSF may determine, based on an AKMA indication received from a UDM, that the UE can use the AKMA authentication mechanism), after the primary identity authentication process succeeds, the AUSF generates, according to a definition in TS33.535, an AKMA key (KAKMA) and an identifier A-KID that corresponds to the AKMA key”; i.e., an AKMA key is derived from an AUSF key);
determining, using a non-access stratum (NAS) layer of the UE, whether the KAUSF based on a primary authentication is available (¶0179, “The NAS layer of the UE may perform the foregoing process of “determining the target authentication mechanism based on the at least one authentication mechanism supported by the ECS and the assistance information”, then the NAS layer sends the target authentication mechanism to the EEC, and the EEC establishes the communication connection with the ECS based on the target authentication mechanism”);
in case that the primary authentication is not performed and the KAUSF is not available, transmitting, from the NAS layer of the UE to the upper layer of the UE, a reject message in response to the request (The examiner notes that this limitation is contingent on the conditions of a primary authentication not being performed and the KAUSF not being available. However, when these conditions are not satisfied, the limitation which is contingent on such is not required to be performed and thus holds no patentable weight in a method/process claim - see MPEP 2111.04 (II)); and
in case that the primary authentication is performed and the KAUSF is available (Fig. 10, step 1003 indicates that primary authentication procedure was successful in step 1000a and deriving AKMA indicates that the KAUSF is available), notifying the upper layer of the UE and providing the A-KID and the KAKMA to the upper layer of the UE (¶0125, “A bottom layer of the terminal device generates the first key and the first key identifier based on the information that corresponds to the target authentication mechanism, and the bottom layer of the terminal device sends the first key identifier and the like to the EEC”; ¶203, “When the UE determines to communicate with the second network element, if the UE supports the AKMA, and the second network element also supports the AKMA (optionally, whether the second network element supports the AKMA may be determined based on the indication in step 1002), the UE derives the AKMA key and the A-KID according to the definition in TS33.535 … For the UE that supports the AKMA, the derivation of the AKMA key and the A-KID may be performed at any time after the primary authentication procedure and before the UE determines to communicate with the second network element by using the AKMA”).
Regarding Claim 2:
The method of claim 1, further comprising:
performing the primary authentication with an AUSF entity and identifying the KAUSF, based on the primary authentication (Fig. 10, step 1000a & 1003);
generating the KAKMA and the A-KID from the KAUSF (¶0199, “If the UE can use the AKMA authentication mechanism (for example, the AUSF may determine, based on an AKMA indication received from a UDM, that the UE can use the AKMA authentication mechanism), after the primary identity authentication process succeeds, the AUSF generates, according to a definition in TS33.535, an AKMA key (KAKMA) and an identifier A-KID that corresponds to the AKMA key”); and
establishing communication with an application function (AF) server using the A-KID (Fig. 10, step 1004).
Regarding Claim 5:
The method of claim 2, wherein the establishing of the communication with the AF server comprises:
generating an AKMA application key (KAF) using the A-KID to access an application hosted by the AF server (Fig. 10, step 1003; ¶0203, “… the UE obtains the locally stored A-KID based on that the second network element supports the AKMA authentication mechanism, and includes the A-KID in step 1004. Further, the UE generates, based on the locally stored AKMA key, the K.sub.AF that corresponds to the second network element”);
establishing the communication with the AF server to access the application hosted by the AF server (Fig. 10, step 1004); and
transmitting, to the AF server, the A-KID over the established communication (Fig. 10, step 1004; ¶0204, “… and sends, to the second network element, a communication connection establishment request including the A-KID…”).
Claim(s) 6, 7, and 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over “Wu” (US 2023/0232228) in further view of “Chin” (US 2020/0092720).
Regarding Claim 6:
Wu teaches:
A user equipment (UE) in a wireless network (Fig. 10), the UE comprising:
a transceiver (¶0085, “The terminal device may be referred to as a terminal for short, and is a device having a wireless transceiver function … The terminal device sometimes may also be referred to as user equipment (UE)”); and
at least one processor coupled to the transceiver and configured to:
receive, from an upper layer of the UE (¶0074, “An edge enable client (EEC) is a peer entity on the terminal side device. The EEC is configured to register EEC information and AC information with the EES, perform security authentication and authorization …”; ¶0076, “An enable client (for example, the EEC) may be … implemented inside the AC”; i.e., the EEC, when implemented within an application client (AC) is considered to be operating within an application (upper) layer), a request for providing an authentication and key management for applications (AKMA) anchor key (KAKMA) and an AKMA key identifier (A-KID) (¶0154, “The edge enabler client registration request message includes capability information of the UE, and the capability information of the UE includes at least one second authentication mechanism supported by the UE. Optionally, the capability information of the UE may further include a network type used by the UE to access the EAS and priority information of the at least one authentication mechanism supported by the UE”; ¶0199),, wherein the KAKMA and the A-KID are generated based on an authentication server function (AUSF) key (KAUSF) (¶0199, “If the UE can use the AKMA authentication mechanism (for example, the AUSF may determine, based on an AKMA indication received from a UDM, that the UE can use the AKMA authentication mechanism), after the primary identity authentication process succeeds, the AUSF generates, according to a definition in TS33.535, an AKMA key (KAKMA) and an identifier A-KID that corresponds to the AKMA key”);
determine, using a non-access stratum (NAS) layer of the UE, whether the KAUSF based on a primary authentication is available (¶0179, “The NAS layer of the UE may perform the foregoing process of “determining the target authentication mechanism based on the at least one authentication mechanism supported by the ECS and the assistance information”, then the NAS layer sends the target authentication mechanism to the EEC, and the EEC establishes the communication connection with the ECS based on the target authentication mechanism”);
…
in case that the primary authentication is performed and the KAUSF is available (Fig. 10, step 1003 indicates that primary authentication procedure was successful in step 1000a and deriving AKMA indicates that the KAUSF is available), notifying the upper layer of the UE and providing the A-KID and the KAKMA to the upper layer of the UE (¶0125, “A bottom layer of the terminal device generates the first key and the first key identifier based on the information that corresponds to the target authentication mechanism, and the bottom layer of the terminal device sends the first key identifier and the like to the EEC”; ¶203, “When the UE determines to communicate with the second network element, if the UE supports the AKMA, and the second network element also supports the AKMA (optionally, whether the second network element supports the AKMA may be determined based on the indication in step 1002), the UE derives the AKMA key and the A-KID according to the definition in TS33.535 … For the UE that supports the AKMA, the derivation of the AKMA key and the A-KID may be performed at any time after the primary authentication procedure and before the UE determines to communicate with the second network element by using the AKMA”).
Wu does not disclose:
in case that the primary authentication is not performed and the KAUSF is not available, transmitting, from the NAS layer of the UE to the upper layer of the UE, a reject message in response to the request; and
Chin teaches:
in case that the primary authentication is not performed and the KAUSF is not available (Fig. 6, step 602 indicating an authentication failure with a corresponding AUSF and therefore making a key shared with the AUSF not available), transmitting, from the NAS layer of the UE to the upper layer of the UE, a reject message in response to the request (Fig. 6, step 608; ¶0059, “At 608 the AUSF component 148 sends an EAP failure message EAP_FAILURE to the AMF component 146, which passes the message to the NAS component 142, which passes the message to the EAP component 144”; i.e., transmit a failure message from a NAS layer to an EAP (upper) layer of the UE responsive to the authentication failure); and
Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify Wu’s system for establishing a secure communication by enhancing Wu’s user equipment (UE) to forward, to an upper layer of the UE, a rejection message upon unsuccessful authentication with an AUSF, as taught by Chin, in order to determine whether to retry or abort the authentication process.
The motivation is to provide a rejection notice to active layers of user equipment when authentication fails with a designated entity in order for the layers to determine whether to retry or abort authentication. This may result in lessening the chances of registration failures as well as minimizing the delay for completing NAS layer procedures (Chin, ¶0050).
Regarding Claim 7:
The UE of claim 6, wherein Wu in view of Chin further teaches the at least one processor is further configured to:
perform the primary authentication with an AUSF entity and identifying the KAUSF, based on the primary authentication (Wu, Fig. 10, step 1000a & 1003);
generate the KAKMA and the A-KID from the KAUSF (Wu, ¶0199, “If the UE can use the AKMA authentication mechanism (for example, the AUSF may determine, based on an AKMA indication received from a UDM, that the UE can use the AKMA authentication mechanism), after the primary identity authentication process succeeds, the AUSF generates, according to a definition in TS33.535, an AKMA key (KAKMA) and an identifier A-KID that corresponds to the AKMA key”); and
establish communication with an application function (AF) server using the A-KID (Wu, Fig. 10, step 1004).
Regarding Claim 10:
The UE of claim 7, wherein Wu in view of Chin further teaches the at least one processor is further configured to:
generate an AKMA application key (KAF) using the A-KID to access an application hosted by the AF server (Wu, Fig. 10, step 1003; ¶0203, “… the UE obtains the locally stored A-KID based on that the second network element supports the AKMA authentication mechanism, and includes the A-KID in step 1004. Further, the UE generates, based on the locally stored AKMA key, the K.sub.AF that corresponds to the second network element”);
establish the communication with the AF server to access the application hosted by the AF server (Wu, Fig. 10, step 1004); and
transmit, to the AF server, the A-KID over the established communication (Wu, Fig. 10, step 1004; ¶0204, “… and sends, to the second network element, a communication connection establishment request including the A-KID…”).
Allowable Subject Matter
Claims 3, 4, 8, and 9 would be allowable if rewritten to overcome the rejection(s) under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), 2nd paragraph, set forth in this Office action and to include all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: The prior art of record does not teach or suggest, either alone or in combination, the subject matter recited within claims 3, 4, 8, and 9 including any intervening claims.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL B POTRATZ whose telephone number is (571)270-5329. The examiner can normally be reached on M-F 10 A.M. - 6 P.M. CST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached on 571-272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DANIEL B POTRATZ/Primary Examiner, Art Unit 2491