DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office Action is based on the Preliminary Amendment submitted on September 04, 2024. Claims 1-20 are amended. Claims 1-20 are pending.
Information Disclosure Statement
The Information Disclosure Statement (IDS) filed on April 22, 2025 has been considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 1, 11, and 20
Claims 1, 11, and 20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The specification, while being enabling for certain embodiments, does not enable one of ordinary skill in the art to make and the full scope of the claimed invention without undue experimentation.
Claim 1 recites obtaining “well-known information of the communication system” and further recites that “the at least two nodes are configured to obtain the well-known information.” The claim does not specify the type of well-known information or require that the information be obtainable by all participating Layer-2 nodes. Accordingly, under the broadest reasonable interpretation, the claim encompassed any information of the communication system that could serve as the recited well-known information.
The specification, however, consistently describes a narrower class of well-known information. Paragraph [0062] states that the well-known information “may be a MAC address of one of the nodes” and “may also be other identification information of the node, for example, a node identifier, provided that the well-known information may be obtained by another node on the same layer 2 network” Likewise, paragraph [0123] discloses that the subnet center may generate the well-known information, “provided that the subnet center 30 can send the information to another node and the information can be obtained by all the nodes on the same layer 2 network.”
These disclosures consistently condition the disclosed well-known information on its availability to the participating Layer-2 nodes. This condition is integral to the disclosed invention because each node independently forms the same well-known key from the same well-known information using the preset key derivation algorithm. Unless each participating node can obtain the same well-known information, the nodes cannot independently derive the same well-known key required to perform the claimed encryption and decryption operations.
The specification therefore enables only embodiments in which the well-known information is obtainable by the participating Layer-2 nodes. It does not provide guidance, working examples, or any disclosure demonstrating that other categories of communication-system information encompassed by the claims – but not obtainable by all participating nodes – can be used while still permitting each node to independently derive the same well-known key.
Considering the factors set forth in In re Wands, 858 F.2d 731 (Fed. Cir. 1988), the breadth of the claims exceeds the scope of the enabling disclosure. Although the level of ordinary skill in the art is relatively high and the technology is generally predictable, the specification provides enabling guidance only for well-known information satisfying the disclosed availability condition. The specification contains no teaching identifying what additional forms of communication-system information, if any, would permit the claimed independent key-generation process to function. Consequently, one of ordinary skill in the art would be required to engage in undue experimentation to determine which additional forms of communication system information falling within the scope of the claims would successfully allow all participating nodes to derive the same well-known key and perform the claimed invention.
Accordingly, the specification does not enable the full scope of the claimed “well-known information of the communication system,” and independent Claims 1, 11, and 20 fail to satisfy the enablement requirement of 35 U.S.C $112(a).
Claims 2-10
Claims 2-10 depend, directly or indirectly, from Claim 1 and are rejected under 35 U.S.C. 112(a) for the same reasons discussed with respect to Claim 1.
Claims 7 and 9 do not cure the enablement deficiency. Claim 7 narrows the well-known information to “a second MAC address of a target node,” and Claim 9 narrows the well-known information to “a second MAC address of the subnet center.” However, neither claim requires that the recited MAC address be obtainable by all participating Layer-2 nodes, which is the condition consistently disclosed throughout the specification for independently deriving the same well-known key. Accordingly, Claims 7 and 9 remain broader that the enabling disclosure and therefore are rejected on the same basis as Claim 1.
Claims 12-19
Claims 12-19 depend, directly or indirectly, from Claim 11 and are rejected under 35 U.S.C. 112(a) for the same reason discussed with respect to Claim 11.
None of Claims 12-19 adds limitations requiring that the recited well-known information be obtainable by all participating Layer-2 nodes. Accordingly, these claims likewise encompass subject matter beyond the scope of the enabling disclosure.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 11, and 20 are rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay - Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), and further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”)
Regarding Claim 1, Buesker teaches a communication system comprising: at least two nodes belonging to a layer 2 network, configured to communicate with each other, and comprising a first node, “Referring to FIG. 1, an illustrative example of a system 100 that includes one or more data link groups is shown. The system 100 includes a wireless network 101, such as a data link group network or a neighbor aware network (NAN). The wireless network 101 may include multiple devices, such as representative devices 120, a second device 108, and a first device 110.” [Col. 3, lines 9-15], and “Each of the devices 108, 110, 120 may be a wireless communication device configured to transmit data, to receive data, or both, from one or more other wireless communication devices included in the wireless network 101” [Col. 3, lines 52-56], and “The wireless network 101 may include or correspond to one or more data link groups (e.g., one or more meshes or mesh networks). As used herein, a data link group may include an infrastructure-less peer-to-peer network, such as an ad-hoc network. The data link group may include multiple devices that are able to form a network, such as a decentralized wireless network” [Col. 3, lines 16-23]
wherein the at least two nodes are configured to obtain the well-known information, “Additionally, each device of the data link group may use common security credentials that may be exchanged in band or out of band with one or more communication channels used by the data link group.” [Col. 3, lines 23-25], and “For example, the devices of the data link group may share a security credential, such as a group key (e.g., a common group key), to enable communication. To illustrate, each device of the data link group may use the group key to encode, decode, or both, group messages.” [Col. 5, line 4-8]
obtain a first media access control (MAC) address of the first node, “the first device 110 may generate the second data 152 based on a media access control (MAC) identifier (e.g., a MAC address 160) of the first device 110” [Col. 6, line 67 to line 2, Col. 7], and “In some implementations, the MAC address 160 may include 48 bits. Additionally or alternatively, the second data 152 may include 64 bits. The first device 110 may generate the second data 152 based on the MAC address 160 in accordance with IEEE 64-bit Extended Unique Identifier (EUI-64) format.” [Col. 7, lines 2-7]
However, Buesker does not explicitly teach:
form a well-known key based on the well-known information and a preset key derivation algorithm;
form a first random number;
form first plaintext data based on the first MAC address and the first random number;
encrypt the first plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain first encrypted data; and
form a first network layer address based on the first encrypted data.
Li teaches form a well-known key based on the well-known information and a preset key derivation algorithm, “The access point negotiates with each station of the at least two stations about a shared encryption key, and the access point obtains an encryption key Ekey used to encrypt the new MAC address of the station” [Col. 10, lines 14-17], and “In this embodiment, a TK that is obtained by directly intercepting 128 bits of a PTK may be used as an Ekey 1; or a key that is obtained by intercepting 128 bits from remaining bits of a PTK after a KCK (Key Confirmation Key, key confirmation key), a KEK (Key Encryption Key, key encryption key), and a TK are intercepted is used as an Ekey 1; or after the access point and the station 1 exchange random numbers (Nonce), an Ekey 1 is derived by using the random numbers of the access point and the station 1 and a TK; or after the access point and the station 1 exchange random numbers (Nonce), an Ekey 1 is derived by using the random numbers of the access point and the station 1, a timestamp (timestamp) and a TK” [Col. 10, lines 37-49], and “There are multiple derivation methods, for example, after a hash algorithm operation SHA-256 is performed by using a random number, a timestamp, and a TK, high-order 128 bits or low-order 128 bits are intercepted.” [Col. 10, lines 49-53]
It would have been obvious to one of ordinary skill in the art to incorporate Li’s key-derivation technique into Buesker’s data-link communication system because both references are directed to securing IEEE 802.11 wireless communications, and using Li’s derived shared encryption key in Buesker’s system would have predictably improved protection of communications involving device-identifying information.
However, Buesker and Li do not explicitly teach:
form a first random number;
form first plaintext data based on the first MAC address and the first random number;
encrypt the first plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain first encrypted data; and
form a first network layer address based on the first encrypted data.
Pebay-Peyroula teaches form a first random number, “The generation of the token comprises the encryption of a random number by means of the secret key. The token is thus the encrypted from a random number, as a result of a cryptographic computation made in the secure device SE.” [Col. 4, lines 10-13], and “The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 19-24]
form first plaintext data based on the first MAC address and the first random number, “In a first example illustrated in FIGS. 1 and 2, the random number N is concatenated with a unique identifier UID of the secure device before encryption by means of the secret key. The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 16-24]
encrypt the first plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain first encrypted data, “The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 19-24], and “In this example, a symmetrical encryption algorithm E is used, and the decryption algorithm is noted D such that if B=E(A, KSE), then A=D(B, KSE).” [Col. 4, lines 32-35]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the combined teachings of Buesker and Li by incorporating Pebay-Peyroula’s technique of generating a random number, concatenating the random number with a unique device identifier, and symmetrically encrypting the concatenation because doing so would have predictably protected device-identifying information while maintaining secure communications. A person of ordinary skill in the art would have recognized Buesker’s MAC address as the unique identifier of the communicating Layer-2 node and would have used that MAC address as the unique device identifier in Pebay-Peyroula’s encryption process.
The combination of Buesker, Li, and Pebay-Peyroula does not explicitly teach form a first network layer address based on the first encrypted data.
Imadali teaches form a first network layer address based on the first encrypted data, “The result of the binary conversions is stored in an intermediate form representing a 51-bit ordered sequence (510). The intermediate object obtained is unique and is used in following steps (312, 314, 316) to generate three entities: an IPv6 address interface identifier (IID) (512); a ULA prefix (514); and a complete IPv6 address (516).” [0084-0087], and “The communication controller also uses the interface identifier (512) and the ULA prefix (514) generated from the VIN to form a complete IPv6 address (516) assigned to its internal interface(s) within the vehicle.” [0097]
It would have been obvious to one of ordinary skill in the art at the time of the invention to further modify the combined teachings of Buesker, Li, and Pebay-Peyroula by incorporating Imadali’s technique for generating a network-layer address from encrypted identifier-derived information because doing so would have predictably enabled generation of a network-layer address while maintaining compatibility with conventional IPv6 network-layer communications.
Regarding Claim 11, Buesker teaches a method implemented by a first node of a layer 2 network, “Referring to FIG. 1, an illustrative example of a system 100 that includes one or more data link groups is shown. The system 100 includes a wireless network 101, such as a data link group network or a neighbor aware network (NAN). The wireless network 101 may include multiple devices, such as representative devices 120, a second device 108, and a first device 110.” [Col. 3, lines 9-15], and “Each of the devices 108, 110, 120 may be a wireless communication device configured to transmit data, to receive data, or both, from one or more other wireless communication devices included in the wireless network 101” [Col. 3, lines 52-56], and “The wireless network 101 may include or correspond to one or more data link groups (e.g., one or more meshes or mesh networks). As used herein, a data link group may include an infrastructure-less peer-to-peer network, such as an ad-hoc network. The data link group may include multiple devices that are able to form a network, such as a decentralized wireless network” [Col. 3, lines 16-23]
and wherein the method comprises:
obtaining well-known information of the layer 2 network, “Additionally, each device of the data link group may use common security credentials that may be exchanged in band or out of band with one or more communication channels used by the data link group.” [Col. 3, lines 23-25], and “For example, the devices of the data link group may share a security credential, such as a group key (e.g., a common group key), to enable communication. To illustrate, each device of the data link group may use the group key to encode, decode, or both, group messages.” [Col. 5, line 4-8]
obtaining a first media access control (MAC) address of the first node, “the first device 110 may generate the second data 152 based on a media access control (MAC) identifier (e.g., a MAC address 160) of the first device 110” [Col. 6, line 67 to line 2, Col. 7], and “In some implementations, the MAC address 160 may include 48 bits. Additionally or alternatively, the second data 152 may include 64 bits. The first device 110 may generate the second data 152 based on the MAC address 160 in accordance with IEEE 64-bit Extended Unique Identifier (EUI-64) format.” [Col. 7, lines 2-7]
However, Buesker does not explicitly teach:
forming a well-known key based on the well-known information and a preset key derivation algorithm;
forming a first random number;
forming first plaintext data based on the first MAC address of the node and the first random number;
encrypting the first plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain first encrypted data; and
forming a first network layer address based on the first encrypted data.
Li teaches forming a well-known key based on the well-known information and a preset key derivation algorithm, “The access point negotiates with each station of the at least two stations about a shared encryption key, and the access point obtains an encryption key Ekey used to encrypt the new MAC address of the station” [Col. 10, lines 14-17], and “In this embodiment, a TK that is obtained by directly intercepting 128 bits of a PTK may be used as an Ekey 1; or a key that is obtained by intercepting 128 bits from remaining bits of a PTK after a KCK (Key Confirmation Key, key confirmation key), a KEK (Key Encryption Key, key encryption key), and a TK are intercepted is used as an Ekey 1; or after the access point and the station 1 exchange random numbers (Nonce), an Ekey 1 is derived by using the random numbers of the access point and the station 1 and a TK; or after the access point and the station 1 exchange random numbers (Nonce), an Ekey 1 is derived by using the random numbers of the access point and the station 1, a timestamp (timestamp) and a TK” [Col. 10, lines 37-49], and “There are multiple derivation methods, for example, after a hash algorithm operation SHA-256 is performed by using a random number, a timestamp, and a TK, high-order 128 bits or low-order 128 bits are intercepted.” [Col. 10, lines 49-53]
It would have been obvious to one of ordinary skill in the art to incorporate Li’s key-derivation technique into Buesker’s data-link communication system because both references are directed to securing IEEE 802.11 wireless communications, and using Li’s derived shared encryption key in Buesker’s system would have predictably improved protection of communications involving device-identifying information.
However, Buesker and Li do not explicitly teach:
forming a first random number;
forming first plaintext data based on the first MAC address of the node and the first random number;
encrypting the first plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain first encrypted data; and
forming a first network layer address based on the first encrypted data.
Pebay-Peyroula teaches forming a first random number, “The generation of the token comprises the encryption of a random number by means of the secret key. The token is thus the encrypted from a random number, as a result of a cryptographic computation made in the secure device SE.” [Col. 4, lines 10-13], and “The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 19-24]
forming first plaintext data based on the first MAC address of the node and the first random number, “In a first example illustrated in FIGS. 1 and 2, the random number N is concatenated with a unique identifier UID of the secure device before encryption by means of the secret key. The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 16-24]
encrypting the first plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain first encrypted data, “The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 19-24], and “In this example, a symmetrical encryption algorithm E is used, and the decryption algorithm is noted D such that if B=E(A, KSE), then A=D(B, KSE).” [Col. 4, lines 32-35]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the combined teachings of Buesker and Li by incorporating Pebay-Peyroula’s technique of generating a random number, concatenating the random number with a unique device identifier, and symmetrically encrypting the concatenation because doing so would have predictably protected device-identifying information while maintaining secure communications. A person of ordinary skill in the art would have recognized Buesker’s MAC address as the unique identifier of the communicating Layer-2 node and would have used that MAC address as the unique device identifier in Pebay-Peyroula’s encryption process.
The combination of Buesker, Li, and Pebay-Peyroula does not explicitly teach forming a first network layer address based on the first encrypted data.
Imadali teaches forming a first network layer address based on the first encrypted data, “The result of the binary conversions is stored in an intermediate form representing a 51-bit ordered sequence (510). The intermediate object obtained is unique and is used in following steps (312, 314, 316) to generate three entities: an IPv6 address interface identifier (IID) (512); a ULA prefix (514); and a complete IPv6 address (516).” [0084-0087], and “The communication controller also uses the interface identifier (512) and the ULA prefix (514) generated from the VIN to form a complete IPv6 address (516) assigned to its internal interface(s) within the vehicle.” [0097]
It would have been obvious to one of ordinary skill in the art at the time of the invention to further modify the combined teachings of Buesker, Li, and Pebay-Peyroula by incorporating Imadali’s technique for generating a network-layer address from encrypted identifier-derived information because doing so would have predictably enabled generation of a network-layer address while maintaining compatibility with conventional IPv6 network-layer communications.
Regarding Claim 20, Buesker teaches an electronic device comprising: “Referring to FIG. 8, an illustrative example of a wireless communication device 800 is shown. The device 800 may correspond to at least one of the devices (e.g., the first device 110, the second device 108, or both) of the system 100 of FIG. 1.” [Col. 19, lines 40-44]
a memory configured to store instructions, “The device 800 includes a processor 810 (e.g., a digital signal processor (DSP) or a central processing unit (CPU)) coupled to a memory 832” [Col. 19, lines 45-47], and “The memory 832 may include instructions 868.” [Col. 19, lines 50-51]
one or more processors coupled to the memory and configured to execute the instructions to cause the electronic device to: “the processor 810 configured to execute the instructions 868 of FIG. 8” [Col. 22, lines 11-12]
obtain well-known information of a layer 2 network, “Additionally, each device of the data link group may use common security credentials that may be exchanged in band or out of band with one or more communication channels used by the data link group.” [Col. 3, lines 23-25], and “For example, the devices of the data link group may share a security credential, such as a group key (e.g., a common group key), to enable communication. To illustrate, each device of the data link group may use the group key to encode, decode, or both, group messages.” [Col. 5, line 4-8]
obtain a media access control (MAC) address of the electronic device, “the first device 110 may generate the second data 152 based on a media access control (MAC) identifier (e.g., a MAC address 160) of the first device 110” [Col. 6, line 67 to line 2, Col. 7], and “In some implementations, the MAC address 160 may include 48 bits. Additionally or alternatively, the second data 152 may include 64 bits. The first device 110 may generate the second data 152 based on the MAC address 160 in accordance with IEEE 64-bit Extended Unique Identifier (EUI-64) format.” [Col. 7, lines 2-7]
However, Buesker does not explicitly teach:
form a well-known key based on the well-known information and a preset key derivation algorithm;
form a random number;
form plaintext data based on the MAC address and the first random number;
encrypt the plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain encrypted data; and
form a network layer address based on the encrypted data.
Li teaches form a well-known key based on the well-known information and a preset key derivation algorithm, “The access point negotiates with each station of the at least two stations about a shared encryption key, and the access point obtains an encryption key Ekey used to encrypt the new MAC address of the station” [Col. 10, lines 14-17], and “In this embodiment, a TK that is obtained by directly intercepting 128 bits of a PTK may be used as an Ekey 1; or a key that is obtained by intercepting 128 bits from remaining bits of a PTK after a KCK (Key Confirmation Key, key confirmation key), a KEK (Key Encryption Key, key encryption key), and a TK are intercepted is used as an Ekey 1; or after the access point and the station 1 exchange random numbers (Nonce), an Ekey 1 is derived by using the random numbers of the access point and the station 1 and a TK; or after the access point and the station 1 exchange random numbers (Nonce), an Ekey 1 is derived by using the random numbers of the access point and the station 1, a timestamp (timestamp) and a TK” [Col. 10, lines 37-49], and “There are multiple derivation methods, for example, after a hash algorithm operation SHA-256 is performed by using a random number, a timestamp, and a TK, high-order 128 bits or low-order 128 bits are intercepted.” [Col. 10, lines 49-53]
It would have been obvious to one of ordinary skill in the art to incorporate Li’s key-derivation technique into Buesker’s data-link communication system because both references are directed to securing IEEE 802.11 wireless communications, and using Li’s derived shared encryption key in Buesker’s system would have predictably improved protection of communications involving device-identifying information.
However, Buesker and Li do not explicitly teach:
form a random number;
form plaintext data based on the MAC address and the first random number;
encrypt the plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain encrypted data; and
form a network layer address based on the encrypted data.
Pebay-Peyroula teaches form a random number, “The generation of the token comprises the encryption of a random number by means of the secret key. The token is thus the encrypted from a random number, as a result of a cryptographic computation made in the secure device SE.” [Col. 4, lines 10-13], and “The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 19-24]
form plaintext data based on the MAC address and the first random number, “In a first example illustrated in FIGS. 1 and 2, the random number N is concatenated with a unique identifier UID of the secure device before encryption by means of the secret key. The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 16-24]
encrypt the plaintext data based on the well-known key and a preset symmetric encryption algorithm to obtain encrypted data, “The generation of the token GT1 thus comprises drawing a random number N, concatenating the random number N with the unique identifier UID of the secure device and encrypting the concatenation N|UID by means of an encryption algorithm E and the secret key KSE preserved by the secure device SE.” [Col. 4, lines 19-24], and “In this example, a symmetrical encryption algorithm E is used, and the decryption algorithm is noted D such that if B=E(A, KSE), then A=D(B, KSE).” [Col. 4, lines 32-35]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the combined teachings of Buesker and Li by incorporating Pebay-Peyroula’s technique of generating a random number, concatenating the random number with a unique device identifier, and symmetrically encrypting the concatenation because doing so would have predictably protected device-identifying information while maintaining secure communications. A person of ordinary skill in the art would have recognized Buesker’s MAC address as the unique identifier of the communicating Layer-2 node and would have used that MAC address as the unique device identifier in Pebay-Peyroula’s encryption process.
The combination of Buesker, Li, and Pebay-Peyroula does not explicitly teach form a network layer address based on the encrypted data.
Imadali teaches form a network layer address based on the encrypted data, “The result of the binary conversions is stored in an intermediate form representing a 51-bit ordered sequence (510). The intermediate object obtained is unique and is used in following steps (312, 314, 316) to generate three entities: an IPv6 address interface identifier (IID) (512); a ULA prefix (514); and a complete IPv6 address (516).” [0084-0087], and “The communication controller also uses the interface identifier (512) and the ULA prefix (514) generated from the VIN to form a complete IPv6 address (516) assigned to its internal interface(s) within the vehicle.” [0097]
It would have been obvious to one of ordinary skill in the art at the time of the invention to further modify the combined teachings of Buesker, Li, and Pebay-Peyroula by incorporating Imadali’s technique for generating a network-layer address from encrypted identifier-derived information because doing so would have predictably enabled generation of a network-layer address while maintaining compatibility with conventional IPv6 network-layer communications.
Claims 2, 9, 10, and 12 are rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay-Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”), and further in view of Lee et al. (US 10129746 B2, hereinafter “Lee”)
Regarding Claim 2, Buesker, Li, Pebay-Peyroula and Imadali disclose the limitations of claim 2 as recited above in the rejection of claim 1. However, the combination applied to claim 1 does not explicitly teach:
a subnet center coupled to the at least two nodes and
configured to send a first broadcast message to the at least two nodes;
wherein the first broadcast message carries the well-known information, and
receive the first broadcast message from the subnet center; and
further obtain the well-known information by parsing the first broadcast message;
Lee teaches a communication system containing an access point device, a home appliance, and mobile terminal, a subnet center coupled to the at least two nodes, “The communication system according to one embodiment of the present disclosure, designated by reference numeral 50, may include a home appliance 200, an access point (AP) device 400, a server 500, a network 550, and a mobile terminal 600.” [Col. 2, lines 8-12], and “The access point ( AP ) device 400 may provide the internal network 10 for proximate electronic devices …the access point device 400 may assign the electronic devices within a range of the internal network 10 wireless channels” [Col. 2, lines 26-31]
configured to send a first broadcast message to the at least two nodes, “Referring to FIG. 11(c), one example of a beacon signal transmitted from the access point device 400 is shown.” [Col. 17, lines 9-10]
wherein the first broadcast message carries the well-known information, “The communication unit 222 may receive a beacon signal including the identifier information” [Col. 4, lines 62-63], and “A “ BSS ID ” item 1432 included in the beacon signal 1430 may represent MAC address information related to the access point device 400” [Col. 17, lines 12-14]
receive the first broadcast message from the subnet center, “The home appliance 200 may receive a beacon signal from the access point device 400” [Col. 12, lines 60-61]
further obtain the well-known information by parsing the first broadcast message, “The home appliance 200 may extract identifier information, encoding method information, and authentication method information from the beacon signal” [Col. 17, lines 20-22]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the wireless communication system of Buesker to utilize Lee’s technique of broadcasting network information in an access point beacon, including BSSID (MAC address) and associated network information, so that participating nodes can obtain common network information from a standard beacon transmission. Doing so would have predictably provide a centralized and standardized mechanism for distributing network configuration information to the nodes while reducing manual configuration and improving interoperability within the wireless local area network.
Regarding Claim 9, Buesker, Li, Pebay-Peyroula, Imadali, and Lee disclose the limitations of claim 9 as recited above in the rejection of claim 2. The rejection of Claim 2 is incorporated. Claim 2 further recites: wherein the well-known information is a second MAC address of the subnet center. However, the combination of Buesker, Li, Pebay-Peyroula, and Imadali teaches deriving cryptographic information using shared or common information, but does not expressly teach that the well-known information is specially a second MAC address of the subnet center.
Lee teaches an access point (AP) device that functions as the central node of an internal wireless network, “The access point (AP) device 400 may provide the internal network 10 for proximate electronic devices.” [Col. 5, lines 26-27], and “the access point device 400 may assign the electronic devices within a range of the internal network 10 wireless channels of a prescribed communication type and perform wireless data communication through these channels” [Col. 2, lines 29-33], and further “the mobile terminal 600 may set information, which is related to any one access point device 400 among a plurality of access point devices 400 stored therein, to the access point device 400 with respect to the home appliance 200 and, based on this setting, transmit a media access control (MAC) address of the corresponding access point device 400 to the home appliance 200.” [Col. 2, line 62 to line 1, Col. 3], and “The controller 270 may access the access point device 400 based on the received MAC address information for product registration of the home appliance 200.” [Col. 5, lines 6-8], and “a “BSS ID” item 1424 included in the third address information 1416 represents MAC address information related to the access point device 400 that the mobile terminal 600 has accessed.” [Col. 16, line 66 to line 1, Col. 17], and “The home appliance 200 may detect the access point device 400 that the mobile terminal 600 has accessed by comparing the “BSS ID” item 1432 in the beacon signal 1430 with the “BSS ID” item 1424 in the starting signal” [Col. 17, lines 15-18]
It would have been obvious to one of ordinary skill in the art to modify the system of Buesker, Li, Pebay-Peyroula, and Imadali to use the MAC address of the subnet center as the well-known information, as taught by Lee, because the access-point MAC address provides a unique, commonly available identifier that enables participating nodes to consistently identify the central network node and establish communications using shared network information.
Regarding Claim 10, Buesker, Li, Pebay-Peyroula, Imadali, and Lee disclose the limitations of claim 10 as recited above in the rejection of claim 2. Lee further teaches wherein the subnet center is a WI-FI access point, and wherein the at least two nodes are stations, “The access point ( AP ) device 400 may provide the internal network 10 for proximate electronic devices” [Col. 2, lines 26-27], and “the access point device 400 may provide a wireless network” [Col. 2, lines 28-29], and “the access point device 400 may assign the electronic devices within a range of the internal network 10 wireless channels of a prescribed communication type and perform wireless data communication through these channels” [Col. 2, lines 29-33], and “the communication unit 222 may receive a MAC address of the access point device 400 from the mobile terminal 600” [Col. 4, lines 47-49], and “The controller 270 may access the access point device 400 based on the received MAC address information for product registration of the home appliance 200.” [Col. 5, lines 6-8], and “The home appliance 200 may detect the access point device 400 that the mobile terminal 600 has accessed by comparing the “BSS ID” item 1432 in the beacon signal 1430 with the “BSS ID” item 1424 in the starting signal” [Col. 17, lines 15-18]
A person of ordinary skill in the art would have understood that the mobile terminal 600 and home appliance 200 communicating with the Wi-Fi access point are IEEE 802.11 stations (STAs) associated with the access point.
It would have been obvious to one of ordinary skill in the art to incorporate Lee’s Wi-Fi access point architecture into the communication system of Buesker, Li, Pebay-Peyroula, and Imadali because using a conventional IEEE 802.11 access point with associated stations provides a well-known wireless local area networking topology for coordinating communications among network nodes.
Regarding Claim 12, Buesker, Li, Pebay-Peyroula and Imadali disclose the limitations of claim 12 as recited above in the rejection of claim 11. However, the combination applied to claim 11 does not explicitly teach:
receiving a first broadcast message from a subnet center in the layer 2 network,
wherein the first broadcast message carries the well-known information; and
further obtaining the well-known information by parsing the first broadcast message.
Lee teaches receiving a first broadcast message from a subnet center in the layer 2 network, “The home appliance 200 may receive a beacon signal from the access point device 400” [Col. 12, lines 60-61]
wherein the first broadcast message carries the well-known information, “The communication unit 222 may receive a beacon signal including the identifier information” [Col. 4, lines 62-63], and “A “ BSS ID ” item 1432 included in the beacon signal 1430 may represent MAC address information related to the access point device 400” [Col. 17, lines 12-14]
further obtaining the well-known information by parsing the first broadcast message, “The home appliance 200 may extract identifier information, encoding method information, and authentication method information from the beacon signal” [Col. 17, lines 20-22]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the wireless communication system of Buesker to utilize Lee’s technique of broadcasting network information in an access point beacon, including BSSID (MAC address) and associated network information, so that participating nodes can obtain common network information from a standard beacon transmission. Doing so would have predictably provide a centralized and standardized mechanism for distributing network configuration information to the nodes while reducing manual configuration and improving interoperability within the wireless local area network.
Claims 3 and 13 are rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay-Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”), further in view of Lee et al. (US 10129746 B2, hereinafter “Lee”), and further in view of Tal et al. (US 11606688 B2, hereinafter “Tal”)
Regarding Claim 3, Buesker, Li, Pebay-Peyroula, Imadali, and Lee disclose the limitations of claim 3 as recited above in the rejection of claim 2. However, the combination applied to claim 2 does not explicitly teach:
the subnet center is further configured to form a second random number;
send a second broadcast message to the at least two nodes, wherein the second broadcast message carries the second random number;
and wherein the first node is further configured to further form the well-known key by:
receiving the second broadcast message from the subnet center;
setting the second random number as a salt of the preset key derivation algorithm;
and forming the well-known key based on the salt.
Tal teaches the subnet center is further configured to form a second random number, “Once a downlink key change event is triggered, a random salt is generated by the master and transmitted in plaintext to all devices (240)” [Col. 22, lines 32-34], and “Note that the salt 266 is generated using a CSPRNG 264, described in more detail infra.” [Col. 17, lines 24-25]
send a second broadcast message to the at least two nodes, wherein the second broadcast message carries the second random number, “Once a downlink key change event is triggered, a random salt is generated by the master and transmitted in plaintext to all devices (240)” [Col. 22, lines 32-34]. Figure 22 expressly shows:
MASTER on the left;
ALL DEVICES on the right; and
An arrow labeled “SALT (P/T)” from the master to all devices.
wherein the first node is further configured to further form the well-known key by:
receiving the second broadcast message from the subnet center, “Once a downlink key change event is triggered, a random salt is generated by the master and transmitted in plaintext to all devices (240). Both the master and the devices then compute a new session key using the salt and the previously stored master key, using a key derivation function (KDF), e.g., multiple iterations of the SHA block.” [Col. 22, lines 32-37]
setting the second random number as a salt of the preset key derivation algorithm, “The key derivation algorithm, generally referenced 260, is performed by both the master and the devices in generating session keys. The algorithm combines ( e.g., concatenates) a permanent key that may comprise either the master key or the device key 262 (e.g., 256 bits) with a salt 256 (e.g., 128 bits) to generate a message (e.g., 384 bits).” [Col. 17, lines 12-18]
forming the well-known key based on the salt, “Both the master and the device N then compute a new session key using the salt and the previously stored device key using a key derivation function (KDF), e.g., multiple iterations of the SHA block.” [Col. 22, lines 42-46], and “The second digest is hashed a third time 272 in this example to generate a third digest. This third digest is used as the session key. In general, the SHA is repeated M times.” [Col. 17, lines 21-24]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the communication system of Buesker, as further modified by Li, Pebay-Peyroula, Imadali, and Lee to employ Tal’s technique of generating random number used as a salt at a centralized device, transmitting the salt to participating devices, and deriving a shared key from the transmitted salt using key derivation function, because both references are directed to securely establishing shared cryptographic keys among communicating network devices. Applying Tal’s key-update mechanism would have predictably enabled the centralized distribution of fresh key-derivation material while improving the security of subsequently generated shared keys through periodic key refresh using newly generated random salt.
Regarding Claim 13, Buesker, Li, Pebay-Peyroula, Imadali, and Lee disclose the limitations of claim 13 as recited above in the rejection of claim 12. However, the combination applied to claim 12 does not explicitly teach:
receiving a second broadcast message from the subnet center, wherein the second broadcast message carries a second random number of the subnet center;
setting the second random number as a salt of the preset key derivation algorithm; and
forming the well-known key based on the salt.
Tal teaches receiving a second broadcast message from the subnet center, “Once a downlink key change event is triggered, a random salt is generated by the master and transmitted in plaintext to all devices (240). Both the master and the devices then compute a new session key using the salt and the previously stored master key, using a key derivation function (KDF), e.g., multiple iterations of the SHA block.” [Col. 22, lines 32-37]
setting the second random number as a salt of the preset key derivation algorithm, “The key derivation algorithm, generally referenced 260, is performed by both the master and the devices in generating session keys. The algorithm combines ( e.g., concatenates) a permanent key that may comprise either the master key or the device key 262 (e.g., 256 bits) with a salt 256 (e.g., 128 bits) to generate a message (e.g., 384 bits).” [Col. 17, lines 12-18]
forming the well-known key based on the salt, “Both the master and the device N then compute a new session key using the salt and the previously stored device key using a key derivation function (KDF), e.g., multiple iterations of the SHA block.” [Col. 22, lines 42-46], and “The second digest is hashed a third time 272 in this example to generate a third digest. This third digest is used as the session key. In general, the SHA is repeated M times.” [Col. 17, lines 21-24]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the communication system of Buesker, as further modified by Li, Pebay-Peyroula, Imadali, and Lee to employ Tal’s technique of generating random number used as a salt at a centralized device, transmitting the salt to participating devices, and deriving a shared key from the transmitted salt using key derivation function, because both references are directed to securely establishing shared cryptographic keys among communicating network devices. Applying Tal’s key-update mechanism would have predictably enabled the centralized distribution of fresh key-derivation material while improving the security of subsequently generated shared keys through periodic key refresh using newly generated random salt.
Claims 4 and 14 are rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay - Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”), further in view of Trisno et al. (US 7096257 B2, hereinafter “Trisno”), and further in view of Narayanan et al. (US 20070233832 A1, hereinafter “Narayanan”),
Regarding Claim 4, Buesker, Li, Pebay-Peyroula, and Imadali disclose the limitations of claim 4 as recited above in the rejection of claim 1. However, the combination applied to claim 1 does not explicitly teach wherein the first node is further configured to:
obtain first information about a routing table wherein the first information comprises globally unique identifiers of the at least two nodes and target network layer addresses corresponding to the globally unique identifiers; and
when the routing table comprises a first target network layer address that is the same as the first network layer address;
Trisno teaches obtain first information about a routing table wherein the first information comprises globally unique identifiers of the at least two nodes and target network layer addresses corresponding to the globally unique identifiers, “Each row in address table 400 is a record, with each record corresponding to one of the nodes in the network. Each record includes three fields. Field 410 identifies the node, field 420 contains the unique identifier for the node (i.e., MAC address in this example), and field 430 identifies the corresponding network address for the node (i.e., IP address).” [Col. 6, lines 40-46], and “A MAC address is a unique 6 byte (48 bit) address that is burned into each networking product by the manufacturer in order to uniquely identify that particular product.” [Col. 6, lines 16-19]
However, Trisno does not explicitly teach when the routing table comprises a first target network layer address that is the same as the first network layer address.
Narayanan teaches when the routing table comprises a first target network layer address that is the same as the first network layer address, “At block 230, a determination whether or not the node ID established at block 210 is identical to respective ones of the node IDs on peer-to-peer network 100 is performed. The determination may include the processor at the assignment node comparing the node IDs of resources controlled by the assignment node to the node ID of the joining node.” [0035], and “At block 290, the joining node may generate a different node ID responsive to reception of the error message. Generating the different node ID for the joining node may include generating a new random bit stream and combining and/or concatenating the new random bit stream with the IP address and/or port number of the joining node. The processing from block 290 returns to block 210. That is, responsive to reception of the error message, the different node ID may be established for the joining node.” [0040]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the communication system of Buesker, as further modified by Li, Pebay-Peyroula, and Imadali, to incorporate Trisno’s routing-table technique together with Narayanan’s collision-detection and identifier-regeneration technique because Trisno teaches maintaining corresponding unique identifiers and network-layer addresses in a routing table, while Narayanan teaches determining whether a newly generated identifier duplicates an existing identifier and, upon detecting a duplicate, generating a new random value and repeating the identifier-generation process until the unique identifier is obtained. Applying these known techniques to the cryptographic network-layer address generation of the combined system would have predictably reduced address conflicts while preserving unique network-layer addresses for communicating nodes.
Regarding Claim 14, Buesker, Li, Pebay-Peyroula, and Imadali disclose the limitations of claim 14 as recited above in the rejection of claim 11. However, the combination applied to claim 11 does not explicitly teach:
obtaining first information about a routing table, wherein the first information comprises globally unique identifiers of nodes on the layer 2 network and target network layer addresses corresponding to the globally unique identifiers; and
when the routing table comprises a first target network layer address that is the same as the first network layer address;
Trisno teaches obtaining first information about a routing table, wherein the first information comprises globally unique identifiers of nodes on the layer 2 network and target network layer addresses corresponding to the globally unique identifiers, “Each row in address table 400 is a record, with each record corresponding to one of the nodes in the network. Each record includes three fields. Field 410 identifies the node, field 420 contains the unique identifier for the node (i.e., MAC address in this example), and field 430 identifies the corresponding network address for the node (i.e., IP address).” [Col. 6, lines 40-46], and “A MAC address is a unique 6 byte (48 bit) address that is burned into each networking product by the manufacturer in order to uniquely identify that particular product.” [Col. 6, lines 16-19]
However, Trisno does not explicitly teach when the routing table comprises a first target network layer address that is the same as the first network layer address.
Narayanan teaches when the routing table comprises a first target network layer address that is the same as the first network layer address, “At block 230, a determination whether or not the node ID established at block 210 is identical to respective ones of the node IDs on peer-to-peer network 100 is performed. The determination may include the processor at the assignment node comparing the node IDs of resources controlled by the assignment node to the node ID of the joining node.” [0035], and “At block 290, the joining node may generate a different node ID responsive to reception of the error message. Generating the different node ID for the joining node may include generating a new random bit stream and combining and/or concatenating the new random bit stream with the IP address and/or port number of the joining node. The processing from block 290 returns to block 210. That is, responsive to reception of the error message, the different node ID may be established for the joining node.” [0040]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the communication system of Buesker, as further modified by Li, Pebay-Peyroula, and Imadali, to incorporate Trisno’s routing-table technique together with Narayanan’s collision-detection and identifier-regeneration technique because Trisno teaches maintaining corresponding unique identifiers and network-layer addresses in a routing table, while Narayanan teaches determining whether a newly generated identifier duplicates an existing identifier and, upon detecting a duplicate, generating a new random value and repeating the identifier-generation process until the unique identifier is obtained. Applying these known techniques to the cryptographic network-layer address generation of the combined system would have predictably reduced address conflicts while preserving unique network-layer addresses for communicating nodes.
Claims 5 and 15 are rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay - Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”), and further in view of Ochikubo et al. (US 8824678 B2, hereinafter “Ochikubo”).
Regarding Claim 5, Buesker, Li, Pebay-Peyroula, and Imadali disclose the limitations of claim 5 as recited above in the rejection of claim 1. However, the combination applied to claim 1 does not explicitly teach wherein the at least two nodes further comprise a target node, and wherein the first node is further configured to: obtain a second network layer address of the target node, and decrypt the second network layer address based on the well-known key and the preset symmetric encryption algorithm to obtain a second MAC address of the target node.
Ochikubo teaches recovering a permanent MAC address associated with a received encoded address using a stored secret key and symmetric encryption algorithm, “At block 410, a MAC address is detected. The detected MAC address may be associated with a wireless access point at a particular location.” [Col. 5, lines 54-56], and further teaches using a stored secret key and an AES block cipher to decrypt the received encoded address information, “The value of the third most significant byte may be provided to an AES block cipher, along with a previously stored secret key. In accordance with an embodiment, the secret key corresponds to the encryption key used in block 350 of method 300” [Col. 6, lines 4-8], and further teaches recovering the permanent MAC address from the decrypted information, “At block 440, the three least significant bytes of the detected MAC address, along with the output value of the AES block cipher, may be provided to an XOR operator, which performs an XOR operation with the value of the output of the AES block cipher and the three least significant bytes of the detected MAC address. The output of the XOR operation may represent the three least significant bytes of the permanent MAC address.” [Col. 6, lines 18-25], and additional teaches “Processor 606 may be configured to determine a permanent MAC address associated with a received MAC address. Processor 606 may determine the permanent MAC address in accordance with method 400 of FIG. 4. For example, processor 606 may decrypt a portion of the received MAC address, and concatenate the decrypted portion of the received MAC address with a portion of the MAC address known to correspond to a manufacturers OUI.” [Col. 7, lines 52-59]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the communication system of Buesker, as further modified by Li, Pebay-Peyroula, and Imadali, to incorporate Ochikubo’s reverse cryptographic operation because Ochikubo teaches using a stored secret key and a symmetric encryption algorithm to recover a permanent MAC address from received encoded address information. Incorporating this known technique would have enabled an authorized node possessing the appropriate key to recover the underlying MAC address while preserving the encrypted address-generation framework of the combined communication system.
Regarding Claim 15, Buesker, Li, Pebay-Peyroula, and Imadali disclose the limitations of claim 15 as recited above in the rejection of claim 11. However, the combination applied to claim 11 does not explicitly teach obtaining a second network layer address of a target node on the layer 2 network, and decrypting the second network layer address based on the well-known key and the preset symmetric encryption algorithm to obtain a second MAC address of the target node.
Ochikubo teaches recovering a permanent MAC address associated with a received encoded address using a stored secret key and symmetric encryption algorithm, “At block 410, a MAC address is detected. The detected MAC address may be associated with a wireless access point at a particular location.” [Col. 5, lines 54-56], and further teaches using a stored secret key and an AES block cipher to decrypt the received encoded address information, “The value of the third most significant byte may be provided to an AES block cipher, along with a previously stored secret key. In accordance with an embodiment, the secret key corresponds to the encryption key used in block 350 of method 300” [Col. 6, lines 4-8], and further teaches recovering the permanent MAC address from the decrypted information, “At block 440, the three least significant bytes of the detected MAC address, along with the output value of the AES block cipher, may be provided to an XOR operator, which performs an XOR operation with the value of the output of the AES block cipher and the three least significant bytes of the detected MAC address. The output of the XOR operation may represent the three least significant bytes of the permanent MAC address.” [Col. 6, lines 18-25], and additional teaches “Processor 606 may be configured to determine a permanent MAC address associated with a received MAC address. Processor 606 may determine the permanent MAC address in accordance with method 400 of FIG. 4. For example, processor 606 may decrypt a portion of the received MAC address, and concatenate the decrypted portion of the received MAC address with a portion of the MAC address known to correspond to a manufacturers OUI.” [Col. 7, lines 52-59]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the communication system of Buesker, as further modified by Li, Pebay-Peyroula, and Imadali, to incorporate Ochikubo’s reverse cryptographic operation because Ochikubo teaches using a stored secret key and a symmetric encryption algorithm to recover a permanent MAC address from received encoded address information. Incorporating this known technique would have enabled an authorized node possessing the appropriate key to recover the underlying MAC address while preserving the encrypted address-generation framework of the combined communication system.
Claims 6 and 16 are rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay - Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”), further in view of Ochikubo et al. (US 8824678 B2, hereinafter “Ochikubo”), and further in view of Trisno et al. (US 7096257 B2, hereinafter “Trisno”)
Regarding Claim 6, Buesker, Li, Pebay-Peyroula, Imadali, and Ochikubo disclose the limitations of claim 6 as recited above in the rejection of claim 5. However, Buesker, Li, Pebay-Peyroula, Imadali, and Ochikubo do not explicitly teach wherein the first node is further configured to form a correspondence between the second MAC address and the second network layer address.
Trisno teaches wherein the first node is further configured to form a correspondence between the second MAC address and the second network layer address, “Each row in address table 400 is a record, with each record corresponding to one of the nodes in the network. Each record includes three fields. Field 410 identifies the node, field 420 contains the unique identifier for the node (i.e., MAC address in this example), and field 430 identifies the corresponding network address for the node (i.e., IP address)” [Col. 6, lines 40-46]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the communication system of Buesker, as further modified by Li, Pebay-Peyroula, Imadali, and Ochikubo, to incorporate Trisno’s address-table correspondence because Trisno teaches maintaining an association between a node’s MAC address and its corresponding network-layer address. Applying this known correspondence technique after Ochikubo’s recovery of the target MAC address would have predictably enabled the first node to associate the recovered MAC address with the corresponding network-layer address for subsequent network communication.
Regarding Claim 16, Buesker, Li, Pebay-Peyroula, Imadali, and Ochikubo disclose the limitations of claim 16 as recited above in the rejection of claim 15. However, Buesker, Li, Pebay-Peyroula, Imadali, and Ochikubo do not explicitly teach forming a correspondence between the second MAC address and the second network layer address.
Trisno teaches forming a correspondence between the second MAC address and the second network layer address, “Each row in address table 400 is a record, with each record corresponding to one of the nodes in the network. Each record includes three fields. Field 410 identifies the node, field 420 contains the unique identifier for the node (i.e., MAC address in this example), and field 430 identifies the corresponding network address for the node (i.e., IP address)” [Col. 6, lines 40-46]
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the communication system of Buesker, as further modified by Li, Pebay-Peyroula, Imadali, and Ochikubo, to incorporate Trisno’s address-table correspondence because Trisno teaches maintaining an association between a node’s MAC address and its corresponding network-layer address. Applying this known correspondence technique after Ochikubo’s recovery of the target MAC address would have predictably enabled the first node to associate the recovered MAC address with the corresponding network-layer address for subsequent network communication.
Claims 7 and 17 are rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay - Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”), and further in view of Meier et al. (US 20040103282 A1, hereinafter “Meier”).
Regarding Claim 7, Buesker, Li, Pebay-Peyroula, and Imadali disclose the limitations of claim 7 as recited above in the rejection of claim 1. However, the combination applied to claim 1 does not explicitly teach:
obtain a second MAC address of a target node;
wherein the target node is a primary node;
set the second MAC address as the well-known information.
Meier teaches obtain a second MAC address of a target node, “The MN may derive the PTK for the new AP once it determines the new BSSID it is roaming to and before the reassociation request is transmitted.” [0191], and “BSSID 1114: the AP's MAC address;” [0235]
wherein the target node is a primary node, “The parent node for a MN is the 802.11 parent AP.” [0351]
set the second MAC address as the well-known information, “The KRK and BTK are generated using a PRF with the NSK, BSSID, STA-ID, NonceSTA and NonceSCM as parameters.” [0184], and “GK = PRF-384(NSK, “Cisco Key Management Base Key Generator BSSID STA-ID | Noncesta NoncescM)” [0271]
It would have been obvious to one of ordinary skill in the art to modify the system of Buesker, as further modified by Li, Pebay-Peyroula, and Imadali, to use the MAC address of the parent access point as the well-known information because Meier teaches that the BSSID, which is the parent AP’s MAC address, is determined by the mobile node an used by both communicating nodes as a common input to the key derivation function, thereby enabling both nodes to derive corresponding cryptographic keys.
Regarding Claim 17, Buesker, Li, Pebay-Peyroula, and Imadali disclose the limitations of claim 17 as recited above in the rejection of claim 11. However, the combination applied to claim 11 does not explicitly teach:
obtaining a second MAC address of a target node;
wherein the target node is a primary node; and
setting the second MAC address as the well-known information.
Meier teaches obtain a second MAC address of a target node, “The MN may derive the PTK for the new AP once it determines the new BSSID it is roaming to and before the reassociation request is transmitted.” [0191], and “BSSID 1114: the AP's MAC address;” [0235]
wherein the target node is a primary node, “The parent node for a MN is the 802.11 parent AP.” [0351]
set the second MAC address as the well-known information, “The KRK and BTK are generated using a PRF with the NSK, BSSID, STA-ID, NonceSTA and NonceSCM as parameters.” [0184], and “GK = PRF-384(NSK, “Cisco Key Management Base Key Generator BSSID STA-ID | Noncesta NoncescM)” [0271]
It would have been obvious to one of ordinary skill in the art to modify the system of Buesker, as further modified by Li, Pebay-Peyroula, and Imadali, to use the MAC address of the parent access point as the well-known information because Meier teaches that the BSSID, which is the parent AP’s MAC address, is determined by the mobile node an used by both communicating nodes as a common input to the key derivation function, thereby enabling both nodes to derive corresponding cryptographic keys.
Claims 8 and 18 are rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay - Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”), further in view of Meier et al. (US 20040103282 A1, hereinafter “Meier”), and further in view of Holostov et al. (US 20120173620 A1, hereinafter “Holostov”)
Regarding Claim 8, Buesker, Li, Pebay-Peyroula, Imadali, and Meier disclose the limitations of claim 8 as recited above in the rejection of claim 7. However, the combination applied to claim 7 does not explicitly teach:
the target node is a communication initiator, and wherein the first node is further configured to further
set the target node as the primary node
in response to the target node being the communication initiator.
Holostov teaches a device imitating discovery and group formation, the target node is a communication initiator, “In step 200, a first device (which may or may not eventually turn out to be the group owner) may initiate discovery of one or more additional devices to form a P2P network group. In embodiments, the initiating device may send out a beacon including a request for other compatible devices to join the group. If and when devices respond to the discovery beacon, the initiating device may then send out an invitation for the responding devices to join the group in step 202.” [0026]
set the target node as the primary node, “Each of the device within P2P network 100 can exchange information with each other, with group owner device 104 acting as the hub. That is, all communications between peers 102, 108, 110, 112, 114 is routed through group owner 104.” [0025], and further “ the group owner may have a variety of responsibilities, including acting as the hub for all communications between group members.” [0040], and “In step 232, the devices negotiate by exchanging their calculated ownership metrics to determine which device has the highest ownership metric at group formation. That device is established as the group owner.” [0038]
in response to the target node being the communication initiator, “The initiating device may become the group owner” [0026], and “As indicated above, the initial group owner may alternatively be established by which device initiates the group. In such embodiments, the initiating device may remain as the group owner until the group dismisses the initial group owner, for example to replace the initial group owner with the device having the highest ownership metric” [0038], and “established by which device initiates the group” [0038]
It would have been obvious to a person of ordinary skill in the art to modify the communication system of Buesker, Li, Pebay-Peyroula, Imadali, and Meier by incorporating Holostov’s technique of establishing the communication initiator as the Group Owner (primary node), because doing so provides the deterministic and efficient mechanism for assigning the coordinating device during network formation, thereby simplifying group establishment and reducing coordination overhead while using known wireless networking techniques.
Regarding Claim 18, Buesker, Li, Pebay-Peyroula, Imadali, and Meier disclose the limitations of claim 18 as recited above in the rejection of claim 17. However, the combination applied to claim 17 does not explicitly teach:
the target node is a communication initiator, and wherein setting the target node as the primary node comprises
setting the target node as the primary node
in response to the target node being the communication initiator.
Holostov teaches a device imitating discovery and group formation, the target node is a communication initiator, “In step 200, a first device (which may or may not eventually turn out to be the group owner) may initiate discovery of one or more additional devices to form a P2P network group. In embodiments, the initiating device may send out a beacon including a request for other compatible devices to join the group. If and when devices respond to the discovery beacon, the initiating device may then send out an invitation for the responding devices to join the group in step 202.” [0026]
setting the target node as the primary node, “Each of the device within P2P network 100 can exchange information with each other, with group owner device 104 acting as the hub. That is, all communications between peers 102, 108, 110, 112, 114 is routed through group owner 104.” [0025], and further “ the group owner may have a variety of responsibilities, including acting as the hub for all communications between group members.” [0040], and “In step 232, the devices negotiate by exchanging their calculated ownership metrics to determine which device has the highest ownership metric at group formation. That device is established as the group owner.” [0038]
in response to the target node being the communication initiator, “The initiating device may become the group owner” [0026], and “As indicated above, the initial group owner may alternatively be established by which device initiates the group. In such embodiments, the initiating device may remain as the group owner until the group dismisses the initial group owner, for example to replace the initial group owner with the device having the highest ownership metric” [0038], and “established by which device initiates the group” [0038]
It would have been obvious to a person of ordinary skill in the art to modify the communication system of Buesker, Li, Pebay-Peyroula, Imadali, and Meier by incorporating Holostov’s technique of establishing the communication initiator as the Group Owner (primary node), because doing so provides the deterministic and efficient mechanism for assigning the coordinating device during network formation, thereby simplifying group establishment and reducing coordination overhead while using known wireless networking techniques.
Claim 19 is rejected under 35 USC § 103 as unpatentable over Buesker et al. (US 10110488 B2, hereinafter “Buesker”), in view of Li et al. (US 10382435 B2, hereinafter “Li”), further in view of Pebay - Peyroula (US 10057054 B2, hereinafter “Pebay-Peyroula”), further in view of Imadali et al. (US 20150215274 A1, hereinafter “Imadali”), and further in view of Perez (US 8438390 B2, hereinafter ”Perez”)
Regarding Claim 19, Buesker, Li, Pebay-Peyroula, and Imadali disclose the limitations of claim 19 as recited above in the rejection of claim 11. However, the combination applied to claim 11 does not explicitly teach wherein the first network layer address is an Internet Protocol (IP) version 6 (IPv6) local link address, and wherein forming the first network layer address comprises: setting high 64 bits of the IPV6 local link address; setting low 64 bits of the IPV6 local link address based on the first encrypted data; and forming the IPV6 local link address based on the high 64 bits and the low 64 bits.
Perez teaches an IPv6 link-local address formed from a high 64-bit portion and a low 64-bit interface identifier, “It can be appreciated that a host device or image forming apparatus when using stateless autoconfiguration generates a link-local address, which is one of the two types of local-use IPv6 addresses. The link-local addresses has “1111 1110 10” for the first ten bits. The generated address uses those ten bits followed by 54 zeroes and then the 64 bit interface identifier, which will typically be derived from the data link layer (MAC) address.” [Col. 5, lines 51-57], and further “The interface identifier is in turn appended to a prefix to form the 128-bit IPv6 address. The first-half 64 bits are allocated to a network prefix included in router advertisement (RA) from the router. The second-half 64 bits are allocated to a EUI-64 format interface ID as a 64-bit identifier decided by the IEEE. “ [Col. 1, lines 47-52]
It would have been obvious to modify the method of Buesker, as modified by Li, Pebay-Peyroula, and Imadali, to form the first network-layer address according to the IPv6 link-local address structure taught by Perez, because Perez teaches forming a 128-bit IPv6 address by appending a low 64-bit interface identifier to a high 64-bit prefix, thereby permitting the generated encrypted address information of the combined method to be used within a conventional IPv6 link-local address format.
Conclusion
The prior art made of record not relied upon and considered pertinent to Applicant’s disclosure:
Ho et al. (US 20220022033 A1) Fast basic service set transition for multi-link operation, discloses methods, devices and systems that facilitate mobility of wireless communication devices configured for multi-link operation (MLO). Particular aspects more specifically relate to facilitating fast basic service set (BSS) transitions by wireless communication devices that support MLO. For example, some aspects provide support for station (STA) multi-link device (MLD) roaming between access point (AP) MLDs, from an AP MLD to a non-MLO AP, or from a non-MLO AP to an AP MLD. In some aspects, a STA MLD may be configured to use a medium access control (MAC) service access point address (MAC-SAP address) of the AP MLD when re-associating or communicating with a legacy AP or with an AP MLD. In such aspects, the MAC-SAP address may be used by all STAs of the non-AP MLD for fast BSS transitions
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SANG PHUOC LE whose telephone number is (571)272-3659. The examiner can normally be reached Monday - Thursday 7:00 am - 5:30 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Charles Appiah can be reached at 571-272-7904. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
SANG PHUOC. LE
Examiner
Art Unit 2641
/SANG PHUOC LE/Examiner, Art Unit 2641
/CHARLES N APPIAH/Supervisory Patent Examiner, Art Unit 2641