Prosecution Insights
Last updated: August 15, 2026
Application No. 18/833,666

Authentication Mechanism for Access to an Edge Data Network Based on TLS-PSK

Final Rejection §103
Filed
Jul 26, 2024
Priority
Jan 28, 2022 — nonprovisional of PCTCN2022074625
Examiner
GERGISO, TECHANE
Art Unit
2408
Tech Center
2400 — Computer Networks
Assignee
Apple Inc.
OA Round
2 (Final)
84%
Grant Probability
Favorable
3-4
OA Rounds
1y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
720 granted / 852 resolved
+26.5% vs TC avg
Strong +24% interview lift
Without
With
+24.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
15 currently pending
Career history
876
Total Applications
across all art units

Statute-Specific Performance

§101
14.0%
-26.0% vs TC avg
§103
56.4%
+16.4% vs TC avg
§102
11.4%
-28.6% vs TC avg
§112
10.7%
-29.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 852 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Based on the applicant’s amendment, the objection of claim 1, 3, 4, 8, 9, 15, and 16 for informalities has been withdrawn. Based on the applicant’s amendment, the rejection of claims 1-5 under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention has been withdrawn. Based on the applicant’s amendment, the rejection of claims 6-19 under 35 U.S.C. 101 as being directed to non-statutory subject matter has been has been withdrawn. Applicant’s arguments, see pages 6-8, filed on 02/03/2026, with respect to the rejection of claims 1-19 under 35 U.S.C. 102 as being unpatentable over RAJADURAI (US 20220116774 A1—hereinafter—"RAJADURAI”) have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Gundavelli et al. (US 20210194728 A1—hereinafter- “Gundavelli”). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 5-8, 10, 14-15 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over RAJADURAI (US 20220116774 A1—hereinafter—"RAJADURAI”) in view of Gundavelli et al. (US 20210194728 A1—hereinafter- “Gundavelli”). As per claim 1: RAJADURAI discloses an apparatus (Figure 1: UE; [0048] User Equipment (UEs)/user devices 202) comprising: a processing circuitry (Figure 2: UE 202) configured: perform primary authentication between a user equipment (UE) and the core network ([0021] authentication and establishment of secure connection for accessing edge computing services is provided. Performing, by a User Equipment (UE), an authentication with a core network (CN) using subscription credentials. The method includes deriving, by the UE, an edge configuration server specific key (K.sub.ECS) for at least one edge computing service, on performing the authentication with the CN. The method includes initiating, by the UE, a secure connection establishment procedure with a server by establishing a pre-shared key (PSK) based on the derived edge configuration server specific key (K.sub.ECS), for the establishment of the secure connection for accessing the at least one edge computing service. [0041-0043] Enable an authentication prior to an actual communication between a UE/client and a server, by provisioning required credentials and establish a secure session/connection between the UE and the server for accessing edge computing services, based on a successful authentication and authorization of the UE and the server. The UE includes an Edge Enabler Client (EEC), and the server includes an Edge Configuration Server (ECS). An Authentication and Key Management for Applications (AKMA) network service for the authentication and authorization of the UE and the server for the edge computing services. The AKMA network service establishes the required credentials between the UE and the server to perform the authentication and to establish the secure connection for the edge computing services. The UE derives a Pre-shared (PSK) key based on an AKMA application key and indicates an AKMA key identifier (ID) to the server to establish a secure Transport Layer Security (TLS) connection/session with the server for the edge computing services. In an example, the UE indicates the AKMA key ID to the server in Transport Layer Security messages. In another example, the UE indicates the AKMA key ID to the server in a service provisioning request. Based on the indicated AKMA key ID, the server obtains the PSK by contacting an AKMA anchor function (AAnF) using information in the AKMA key ID. Once the server obtains the PSK, a mutual authentication is performed between the UE and the server using the PSK and the secure TLS connection/session is established between the UE and the server based on the successful authentication and authorization of the UE and the server. Network access credentials (Subscription credentials/Universal Subscriber Identity Module (USIM) credentials) for edge computing user authentication and authorization. After a successful authentication procedure, embodiments herein issue/derive a temporary key (e.g., Access token or security Key) for authorizing the access to an Edge Enabler Server (EES)); generate a first credential based on a second credential, wherein the second credential is used for primary authentication between the UE and a core network (Figure 2: between UE 202 and CN 204; [0056] When the UE 202 wants to access the edge computing services, the UE 202 performs an authentication with the CN 204 using subscription credentials. In an example, the subscription credentials may include security credentials/Universal Subscriber Identity Module (USIM) credentials provided by a Mobile Network Operator (MNO) to access the CN 204/RAT supported by the CN 204. In an example, the authentication performed with the CN 204 may be a primary network access authentication procedure as specified in the 3GPP TS 33.501, clause 6.1. On performing the authentication with the CN 204, the UE 202 and the CN 204 generate an authentication server function key. In an example, if the CN 204 is a 5GC, then the authentication server function key may be a key K.sub.AUSF. [0107] At step 1A, the MT 308a initiates the network access authentication procedure (i.e., a primary authentication and key agreement specified in the 3GPP TS 33.501, clause 6.1). On completion of the network access authentication procedure, the MT 308a and the AUSF 406 are in possession (successful generation) of the key K.sub.AUSF. [0108] At step 2A, the EEC 310 of the UE 202 derives the AKMA key as specified in the 3GPP TS 33.535 and optionally the further keys like the edge configuration server specific key (K.sub.ECS) key (K.sub.ECS) for the edge computing services. The edge configuration server specific key (K.sub.ECS) is the AKMA application key (K.sub.AF) derived as specified in the 3GPP TS 33.535. [0163] Embodiments herein enable an authentication of the UE prior to an actual communication between the UE and the ECS by provisioning required credentials and establish a secure session/connection between the UE and the ECS for accessing the edge computing services, based on a successful authentication and authorization of the UE and the ECS. Embodiments herein use an AKMA network service for authentication and establishment of the secure connection between the UE and the ECS. The AKMA network service is an authentication and key agreement service, where access to an application function (AF)/server (for example, the ECS) and establishment of the secure connection between the UE and the AF is based on network access security credentials established during a primary authentication of the UE); generate an identifier corresponding to the first credential ([0032] FIG. 6 depicts an example sequence diagram, where the UE and the server/ECS use a Transport Layer Security (TLS) with pre-shared key (PSK)-based authentication for securing a connection to access edge computing services, where details of an application key identifier is carried by TLS protocol messages to establish a PSK during a TLS establishment procedure. [0042] Embodiments herein use an Authentication and Key Management for Applications (AKMA) network service for the authentication and authorization of the UE and the server for the edge computing services. The AKMA network service establishes the required credentials between the UE and the server to perform the authentication and to establish the secure connection for the edge computing services. The UE derives a Pre-shared (PSK) key based on an AKMA application key and indicates an AKMA key identifier (ID) to the server to establish a secure Transport Layer Security (TLS) connection/session with the server for the edge computing services. In an example, the UE indicates the AKMA key ID to the server in Transport Layer Security messages. In another example, the UE indicates the AKMA key ID to the server in a service provisioning request. Based on the indicated AKMA key ID, the server obtains the PSK by contacting an AKMA anchor function (AAnF) using information in the AKMA key ID. Once the server obtains the PSK, a mutual authentication is performed between the UE and the server using the PSK and the secure TLS connection/session is established between the UE and the server based on the successful authentication and authorization of the UE and the server. [0033] FIG. 7 depicts an example sequence diagram, where the UE and the ECS use the TLS with PSK-based authentication for securing the connection to access the edge computing services, where the details of the application key identifier is carried by a service provisioning request to establish the PSK before the TLS establishment procedure); and perform, after the primary authentication, an authentication procedure with an edge configuration server (ECS) for access to an edge data network based on transport layer security (TLS)-pre-shared key (PSK) protocols using the first credential ([0105] FIG. 6 depicts an example sequence diagram, where the UE 202 and the server/ECS 208a use the TLS with PSK-based authentication for securing the connection to access the edge computing services, where details of the application key ID/AKMA key identity is carried by the TLS protocol messages to establish the PSK during the TLS session establishment procedure, according to an embodiment of the disclosure). RAJADURAI does not explicitly disclose the credential used for primary authentication between the UE and the core network is generated using authentication vector generation. Gundavelli, in analogous art however, disclose the credential used for primary authentication between the UE and the core network is generated using authentication vector generation ([0094] At 310, CTF 130 communicates a DIAMETER-based Authentication-Information-Request (Auth Info Request or ‘AIR’) message to AAA/NPF/HSS 136 including the IMSI, a Public Land Mobile Network Identity (PLMNID), and the TAI. At 312, AAA/NPF/HSS 136 validates the TAI+PLMNID for the client 102 and generates an authentication vector using authentication techniques such as Evolved Packet System Authentication and Key Agreement (EPS-AKA) functionality that may be facilitated via EPS-AKA logic configured for AAA/NPF/HSS 136. The authentication vector may be represented as {AUTN, RAND, XRES, and KASME}, in which ‘AUTN’ is an authentication token, ‘RAND’ is a random challenge, ‘XRES’ is an expected response to the challenge, and ‘KASME’ (Access Security Management Entity Key) is a root key. In at least one embodiment, the EPS-AKA logic configured for AAA/NPF/HSS 136 can perform operations for generating the authentication vector according to techniques as prescribed at least by RFC 5448 and RFC 4187. [0095] Although techniques presented herein are discussed with reference to EPS-AKA mechanisms for cellular authentication, this is not meant to limit the broad scope of the present disclosure. In various implementations, other authentication mechanisms/protocols may be utilized (e.g., Extensible Authentication Protocol-Transport Layer Security (EAP-TLS), EAP-Tunneled TLS (EAP-TTLS), etc.) as may be understood in the art, now known here and/or hereinafter developed, which may or may not result in the generation of different authentication vectors/authentication information that may be utilized for authenticating users/devices to various access types. [0096] Upon generation of the authentication vector, AAA/NPF/HSS 136 sends an Authentication-Information-Answer (Auth Info Answer or ‘AIA ’) message to CTF 130 at 312 including the authentication vector. At 314, authentication of the client 102 for the cellular access is performed between CTF 130 and client 102 using the authentication vector. For example, the authentication vector can be used to perform an authentication between the client 102 and the CTF 130 to generate a shared key that can further be used to generate security keys, such as a cipher key (CK) and an integrity key (IK), that can be used to secure AS (Access Stratum) communications between the client 102 and the cellular AP 122 and also to secure NAS (Non-Access Stratum) communications between the client 102 and the CTF 130). Therefore, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the invention to modify the claimed limitations of the credential used for primary authentication between the UE and the core network disclosed by RAJADURAI is generated using authentication vector generation. This modification would have been obvious because a person having ordinary skill in the art would have been motivated by the desire to provide interworking between SDA/enterprise fabric data and control plane elements as well as between a cellular control plane function (referred to herein as a cellular termination function (CTF)) to provide for the creation and/or deletion of radio and core network QoS bearer(s) by extending the techniques in which the Locator/Identity (ID) Separation Protocol (LISP) control plane is used for an SDA/enterprise fabric and providing end-to-end QoS and bringing a unique value to the SDA/enterprise fabric as suggested by Gundavelli ([0016]). As per claim 2: RAJADURAI discloses the apparatus of claim 1, wherein performing the authentication procedure comprises establishing a TLS security tunnel with the ECS based on a pre-shared key, wherein the pre-shared key comprises the first credential ([0065] In an embodiment, the UE 202 may send the application key ID to the ECS 208a in a first message/TLS protocol message by parallelly initiating the secure connection establishment procedure with the ECS 208a. Thus, the UE 202 may send the application key ID to the ECS 208a as part of the secure establishment procedure. Sending the application key ID to the ECS 208a in the TLS protocol message includes sending EEC details to the ECS 208a in the TLS protocol message. In an example, the TLS protocol message may include a “Client Hello message”, or the like. The EEC details may be carried in a vendor ID payload within the TLS protocol message. The EEC details may include an EEC ID, a UE ID, and the application key ID. On receiving the application key ID from the UE 202 in the TLS protocol message, the ECS 208a sends a key request including the received application key ID to the AAnF 206 to identify an application security context in the AAnF 206 for fetching the edge configuration server specific key (K.sub.ECS)). As per claim 3: RAJADURAI discloses the apparatus of claim 1, wherein the core network comprises an authentication server function (AUSF) configured to perform the primary authentication with the UE and the second credential ([0075] On completion of the network access authentication procedure with the CN 204, the MT 308a generates the authentication key (K.sub.AUSF). The MT 308a stores the generated authentication key (K.sub.AUSF) in the memory 304. [0077] For providing the support functions to the application client(s) 312, the EEC 310 may establish the secure connection with the ECS 208a and the EES 208b. For establishing the secure connection with the ECS 208a, the EEC 310 derives the AKMA key (K.sub.AKMA), on generating the authentication key (K.sub.AUSF) by the MT 308a. The EEC 310 also derives the edge configuration server specific key (K.sub.ECS)/AKMA application key (K.sub.AF) based on the AKMA key (K.sub.AKMA)). As per claim 5: RAJADURAI discloses the apparatus of claim 1, wherein the core network derives the first credential independently from the UE and provides the first credential to the ECS ([0114] On receiving the “Client Hello message” from the UE 202, at step 2F, the ECS 208a contacts the AAnF 206 (using the AKMA key ID) to obtain the corresponding AKMA application key (K.sub.ECS/K.sub.AF) of the UE 202. Based on the AKMA Key ID, at step 2G, the AAnF 206 provides the AKMA application key (K.sub.ECS) to the ECS 208a and optionally corresponding (K.sub.ECS/K.sub.AF) lifetime in the key response). As per claim 6: RAJADURAI discloses an edge configuration server (ECS) comprising a processing circuitry (Figure 2: ECS 208a; Figure 6 & 7: ECS ) configured to: receive a first credential from a network function ([0114] On receiving the “Client Hello message” from the UE 202, at step 2F, the ECS 208a contacts the AAnF 206 (using the AKMA key ID) to obtain the corresponding AKMA application key (K.sub.ECS/K.sub.AF) of the UE 202. Based on the AKMA Key ID, at step 2G, the AAnF 206 provides the AKMA application key (K.sub.ECS) to the ECS 208a and optionally corresponding (K.sub.ECS/K.sub.AF) lifetime in the key response), wherein the first credential is derived based on second credential used for primary authentication between a user equipment (UE) and a core network ([0108] At step 2A, the EEC 310 of the UE 202 derives the AKMA key as specified in the 3GPP TS 33.535 and optionally the further keys like the edge configuration server specific key (K.sub.ECS) key (K.sub.ECS) for the edge computing services. The edge configuration server specific key (K.sub.ECS) is the AKMA application key (K.sub.AF) derived as specified in the 3GPP TS 33.535. [0163] Embodiments herein enable an authentication of the UE prior to an actual communication between the UE and the ECS by provisioning required credentials and establish a secure session/connection between the UE and the ECS for accessing the edge computing services, based on a successful authentication and authorization of the UE and the ECS. Embodiments herein use an AKMA network service for authentication and establishment of the secure connection between the UE and the ECS. The AKMA network service is an authentication and key agreement service, where access to an application function (AF)/server (for example, the ECS) and establishment of the secure connection between the UE and the AF is based on network access security credentials established during a primary authentication of the UE); wherein the first credential is derived based on second credential used for primary authentication between a user equipment (UE) and a core network (Figure 2: between UE 202 and CN 204; [0056] When the UE 202 wants to access the edge computing services, the UE 202 performs an authentication with the CN 204 using subscription credentials. In an example, the subscription credentials may include security credentials/Universal Subscriber Identity Module (USIM) credentials provided by a Mobile Network Operator (MNO) to access the CN 204/RAT supported by the CN 204. In an example, the authentication performed with the CN 204 may be a primary network access authentication procedure as specified in the 3GPP TS 33.501, clause 6.1. On performing the authentication with the CN 204, the UE 202 and the CN 204 generate an authentication server function key. In an example, if the CN 204 is a 5GC, then the authentication server function key may be a key K.sub.AUSF. [0107] At step 1A, the MT 308a initiates the network access authentication procedure (i.e., a primary authentication and key agreement specified in the 3GPP TS 33.501, clause 6.1). On completion of the network access authentication procedure, the MT 308a and the AUSF 406 are in possession (successful generation) of the key K.sub.AUSF. [0108] At step 2A, the EEC 310 of the UE 202 derives the AKMA key as specified in the 3GPP TS 33.535 and optionally the further keys like the edge configuration server specific key (K.sub.ECS) key (K.sub.ECS) for the edge computing services. The edge configuration server specific key (K.sub.ECS) is the AKMA application key (K.sub.AF) derived as specified in the 3GPP TS 33.535. [0163] Embodiments herein enable an authentication of the UE prior to an actual communication between the UE and the ECS by provisioning required credentials and establish a secure session/connection between the UE and the ECS for accessing the edge computing services, based on a successful authentication and authorization of the UE and the ECS. Embodiments herein use an AKMA network service for authentication and establishment of the secure connection between the UE and the ECS. The AKMA network service is an authentication and key agreement service, where access to an application function (AF)/server (for example, the ECS) and establishment of the secure connection between the UE and the AF is based on network access security credentials established during a primary authentication of the UE); perform an authentication procedure with the UE for access to an edge data network based on transport layer security (TLS)-pre-shared key (PSK) protocols using the first credential ([0065] In an embodiment, the UE 202 may send the application key ID to the ECS 208a in a first message/TLS protocol message by parallelly initiating the secure connection establishment procedure with the ECS 208a. Thus, the UE 202 may send the application key ID to the ECS 208a as part of the secure establishment procedure. Sending the application key ID to the ECS 208a in the TLS protocol message includes sending EEC details to the ECS 208a in the TLS protocol message. In an example, the TLS protocol message may include a “Client Hello message”, or the like. The EEC details may be carried in a vendor ID payload within the TLS protocol message. The EEC details may include an EEC ID, a UE ID, and the application key ID. On receiving the application key ID from the UE 202 in the TLS protocol message, the ECS 208a sends a key request including the received application key ID to the AAnF 206 to identify an application security context in the AAnF 206 for fetching the edge configuration server specific key (K.sub.ECS). [0105] FIG. 6 depicts an example sequence diagram, where the UE 202 and the server/ECS 208a use the TLS with PSK-based authentication for securing the connection to access the edge computing services, where details of the application key ID/AKMA key identity is carried by the TLS protocol messages to establish the PSK during the TLS session establishment procedure, according to an embodiment of the disclosure). receive a service provisioning request from the UE, wherein the service provisioning request comprises an identifier corresponding to the first credential ([0042] Embodiments herein use an Authentication and Key Management for Applications (AKMA) network service for the authentication and authorization of the UE and the server for the edge computing services. The AKMA network service establishes the required credentials between the UE and the server to perform the authentication and to establish the secure connection for the edge computing services. The UE derives a Pre-shared (PSK) key based on an AKMA application key and indicates an AKMA key identifier (ID) to the server to establish a secure Transport Layer Security (TLS) connection/session with the server for the edge computing services. In an example, the UE indicates the AKMA key ID to the server in Transport Layer Security messages. In another example, the UE indicates the AKMA key ID to the server in a service provisioning request); transmit a key request to the network function, wherein the network function is a network exposure function (NEF) configured to forward the key request to an authentication server function (AUSF) ([0042] Based on the indicated AKMA key ID, the server obtains the PSK by contacting an AKMA anchor function (AAnF) using information in the AKMA key ID. Once the server obtains the PSK, a mutual authentication is performed between the UE and the server using the PSK and the secure TLS connection/session is established between the UE and the server based on the successful authentication and authorization of the UE and the server); and receive a key response from the network function, wherein the key response comprises the first credential ([0057] On generating the authentication server function key, the CN 204 derives an authentication and authorization key. In an example, the authentication and authorization key may be an AKMA key (K.sub.AKMA). The CN 204 may derive the authentication and authorization key/AKMA key (K.sub.AKMA) in accordance with the 3GPP TS 33.535. The CN 204 communicates the derived authentication and authorization key/AKMA key (K.sub.AKMA) to the AAnF 206 in a key response). RAJADURAI does not explicitly disclose wherein the first credential is generated through authentication vector generation. Gundavelli, in analogous art however, disclose wherein the first credential is generated through authentication vector generation ([0094] At 310, CTF 130 communicates a DIAMETER-based Authentication-Information-Request (Auth Info Request or ‘AIR’) message to AAA/NPF/HSS 136 including the IMSI, a Public Land Mobile Network Identity (PLMNID), and the TAI. At 312, AAA/NPF/HSS 136 validates the TAI+PLMNID for the client 102 and generates an authentication vector using authentication techniques such as Evolved Packet System Authentication and Key Agreement (EPS-AKA) functionality that may be facilitated via EPS-AKA logic configured for AAA/NPF/HSS 136. The authentication vector may be represented as {AUTN, RAND, XRES, and KASME}, in which ‘AUTN’ is an authentication token, ‘RAND’ is a random challenge, ‘XRES’ is an expected response to the challenge, and ‘KASME’ (Access Security Management Entity Key) is a root key. In at least one embodiment, the EPS-AKA logic configured for AAA/NPF/HSS 136 can perform operations for generating the authentication vector according to techniques as prescribed at least by RFC 5448 and RFC 4187. [0095] Although techniques presented herein are discussed with reference to EPS-AKA mechanisms for cellular authentication, this is not meant to limit the broad scope of the present disclosure. In various implementations, other authentication mechanisms/protocols may be utilized (e.g., Extensible Authentication Protocol-Transport Layer Security (EAP-TLS), EAP-Tunneled TLS (EAP-TTLS), etc.) as may be understood in the art, now known here and/or hereinafter developed, which may or may not result in the generation of different authentication vectors/authentication information that may be utilized for authenticating users/devices to various access types. [0096] Upon generation of the authentication vector, AAA/NPF/HSS 136 sends an Authentication-Information-Answer (Auth Info Answer or ‘AIA ’) message to CTF 130 at 312 including the authentication vector. At 314, authentication of the client 102 for the cellular access is performed between CTF 130 and client 102 using the authentication vector. For example, the authentication vector can be used to perform an authentication between the client 102 and the CTF 130 to generate a shared key that can further be used to generate security keys, such as a cipher key (CK) and an integrity key (IK), that can be used to secure AS (Access Stratum) communications between the client 102 and the cellular AP 122 and also to secure NAS (Non-Access Stratum) communications between the client 102 and the CTF 130). Therefore, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the invention to modify the claimed limitations of wherein the first credential disclosed by RAJADURAI is generated through authentication vector generation. This modification would have been obvious because a person having ordinary skill in the art would have been motivated by the desire to provide interworking between SDA/enterprise fabric data and control plane elements as well as between a cellular control plane function (referred to herein as a cellular termination function (CTF)) to provide for the creation and/or deletion of radio and core network QoS bearer(s) by extending the techniques in which the Locator/Identity (ID) Separation Protocol (LISP) control plane is used for an SDA/enterprise fabric and providing end-to-end QoS and bringing a unique value to the SDA/enterprise fabric as suggested by Gundavelli ([0016]). As per claim 7: RAJADURAI discloses the ECS of claim 6, wherein performing the authentication procedure comprises establishing a TLS security tunnel with the UE based on a pre-shared key, wherein the pre-shared key comprises the first credential ([0065] In an embodiment, the UE 202 may send the application key ID to the ECS 208a in a first message/TLS protocol message by parallelly initiating the secure connection establishment procedure with the ECS 208a. Thus, the UE 202 may send the application key ID to the ECS 208a as part of the secure establishment procedure. Sending the application key ID to the ECS 208a in the TLS protocol message includes sending EEC details to the ECS 208a in the TLS protocol message. In an example, the TLS protocol message may include a “Client Hello message”, or the like. The EEC details may be carried in a vendor ID payload within the TLS protocol message. The EEC details may include an EEC ID, a UE ID, and the application key ID. On receiving the application key ID from the UE 202 in the TLS protocol message, the ECS 208a sends a key request including the received application key ID to the AAnF 206 to identify an application security context in the AAnF 206 for fetching the edge configuration server specific key (K.sub.ECS)). As per claim 8: RAJADURAI discloses the ECS of claim 6, wherein the network function is an authentication server function (AUSF) configured to perform the primary authentication with the UE and the second credential ([0075] On completion of the network access authentication procedure with the CN 204, the MT 308a generates the authentication key (K.sub.AUSF). The MT 308a stores the generated authentication key (K.sub.AUSF) in the memory 304. [0077] For providing the support functions to the application client(s) 312, the EEC 310 may establish the secure connection with the ECS 208a and the EES 208b. For establishing the secure connection with the ECS 208a, the EEC 310 derives the AKMA key (K.sub.AKMA), on generating the authentication key (K.sub.AUSF) by the MT 308a. The EEC 310 also derives the edge configuration server specific key (K.sub.ECS)/AKMA application key (K.sub.AF) based on the AKMA key (K.sub.AKMA)). As per claim 10: RAJADURAI discloses the ECS of claim 6, further configured to: subscribe to an authentication server function (AUSF) service operation, wherein the network function is an AUSF and the AUSF service operation is configured to provide the first credential and the identifier to the ECS ([0056] When the UE 202 wants to access the edge computing services, the UE 202 performs an authentication with the CN 204 using subscription credentials. In an example, the subscription credentials may include security credentials/Universal Subscriber Identity Module (USIM) credentials provided by a Mobile Network Operator (MNO) to access the CN 204/RAT supported by the CN 204. In an example, the authentication performed with the CN 204 may be a primary network access authentication procedure as specified in the 3GPP TS 33.501, clause 6.1. On performing the authentication with the CN 204, the UE 202 and the CN 204 generate an authentication server function key. In an example, if the CN 204 is a 5GC, then the authentication server function key may be a key K.sub.AUSF. [0141] The EEC 310 initiates the service provisioning procedure with the ECS 208a (as specified in the clause 8.3 in the 3GPP TS 23.558). The service provisioning procedures may include at least one of, a request-response procedure, a subscribe-notify procedure (including, a subscription update procedure and a unsubscribe procedure). In an example herein, the EEC 310 initiates the service provisioning procedure with the ECS 208a by sending the service provisioning request to the ECS 208a. The service provisioning request/request message from the EEC 310 includes the AKMA key ID.). As per claim 14: RAJADURAI discloses an apparatus comprising a processing circuitry configured to: generate a first credential based on a second credential (Figure 2: between UE 202 and CN 204; [0056] When the UE 202 wants to access the edge computing services, the UE 202 performs an authentication with the CN 204 using subscription credentials. In an example, the subscription credentials may include security credentials/Universal Subscriber Identity Module (USIM) credentials provided by a Mobile Network Operator (MNO) to access the CN 204/RAT supported by the CN 204. In an example, the authentication performed with the CN 204 may be a primary network access authentication procedure as specified in the 3GPP TS 33.501, clause 6.1. On performing the authentication with the CN 204, the UE 202 and the CN 204 generate an authentication server function key. In an example, if the CN 204 is a 5GC, then the authentication server function key may be a key K.sub.AUSF ), wherein the second credential is used for primary authentication between a user equipment (UE) and a core network [0107] At step 1A, the MT 308a initiates the network access authentication procedure (i.e., a primary authentication and key agreement specified in the 3GPP TS 33.501, clause 6.1). On completion of the network access authentication procedure, the MT 308a and the AUSF 406 are in possession (successful generation) of the key K.sub.AUSF. [0108] At step 2A, the EEC 310 of the UE 202 derives the AKMA key as specified in the 3GPP TS 33.535 and optionally the further keys like the edge configuration server specific key (K.sub.ECS) key (K.sub.ECS) for the edge computing services. The edge configuration server specific key (K.sub.ECS) is the AKMA application key (K.sub.AF) derived as specified in the 3GPP TS 33.535. [0163] Embodiments herein enable an authentication of the UE prior to an actual communication between the UE and the ECS by provisioning required credentials and establish a secure session/connection between the UE and the ECS for accessing the edge computing services, based on a successful authentication and authorization of the UE and the ECS. Embodiments herein use an AKMA network service for authentication and establishment of the secure connection between the UE and the ECS. The AKMA network service is an authentication and key agreement service, where access to an application function (AF)/server (for example, the ECS) and establishment of the secure connection between the UE and the AF is based on network access security credentials established during a primary authentication of the UE); wherein the second credential is used for primary authentication between a user equipment (UE) and a core network (Figure 2: between UE 202 and CN 204; [0056] When the UE 202 wants to access the edge computing services, the UE 202 performs an authentication with the CN 204 using subscription credentials. In an example, the subscription credentials may include security credentials/Universal Subscriber Identity Module (USIM) credentials provided by a Mobile Network Operator (MNO) to access the CN 204/RAT supported by the CN 204. In an example, the authentication performed with the CN 204 may be a primary network access authentication procedure as specified in the 3GPP TS 33.501, clause 6.1. On performing the authentication with the CN 204, the UE 202 and the CN 204 generate an authentication server function key. In an example, if the CN 204 is a 5GC, then the authentication server function key may be a key K.sub.AUSF. [0107] At step 1A, the MT 308a initiates the network access authentication procedure (i.e., a primary authentication and key agreement specified in the 3GPP TS 33.501, clause 6.1). On completion of the network access authentication procedure, the MT 308a and the AUSF 406 are in possession (successful generation) of the key K.sub.AUSF. [0108] At step 2A, the EEC 310 of the UE 202 derives the AKMA key as specified in the 3GPP TS 33.535 and optionally the further keys like the edge configuration server specific key (K.sub.ECS) key (K.sub.ECS) for the edge computing services. The edge configuration server specific key (K.sub.ECS) is the AKMA application key (K.sub.AF) derived as specified in the 3GPP TS 33.535. [0163] Embodiments herein enable an authentication of the UE prior to an actual communication between the UE and the ECS by provisioning required credentials and establish a secure session/connection between the UE and the ECS for accessing the edge computing services, based on a successful authentication and authorization of the UE and the ECS. Embodiments herein use an AKMA network service for authentication and establishment of the secure connection between the UE and the ECS. The AKMA network service is an authentication and key agreement service, where access to an application function (AF)/server (for example, the ECS) and establishment of the secure connection between the UE and the AF is based on network access security credentials established during a primary authentication of the UE); generate an identifier corresponding to the first credential ([0032] FIG. 6 depicts an example sequence diagram, where the UE and the server/ECS use a Transport Layer Security (TLS) with pre-shared key (PSK)-based authentication for securing a connection to access edge computing services, where details of an application key identifier is carried by TLS protocol messages to establish a PSK during a TLS establishment procedure. [0042] Embodiments herein use an Authentication and Key Management for Applications (AKMA) network service for the authentication and authorization of the UE and the server for the edge computing services. The AKMA network service establishes the required credentials between the UE and the server to perform the authentication and to establish the secure connection for the edge computing services. The UE derives a Pre-shared (PSK) key based on an AKMA application key and indicates an AKMA key identifier (ID) to the server to establish a secure Transport Layer Security (TLS) connection/session with the server for the edge computing services. In an example, the UE indicates the AKMA key ID to the server in Transport Layer Security messages. In another example, the UE indicates the AKMA key ID to the server in a service provisioning request. Based on the indicated AKMA key ID, the server obtains the PSK by contacting an AKMA anchor function (AAnF) using information in the AKMA key ID. Once the server obtains the PSK, a mutual authentication is performed between the UE and the server using the PSK and the secure TLS connection/session is established between the UE and the server based on the successful authentication and authorization of the UE and the server. [0033] FIG. 7 depicts an example sequence diagram, where the UE and the ECS use the TLS with PSK-based authentication for securing the connection to access the edge computing services, where the details of the application key identifier is carried by a service provisioning request to establish the PSK before the TLS establishment procedure); and send the first credential to an edge configuration server (ECS) ([0042] Based on the indicated AKMA key ID, the server obtains the PSK by contacting an AKMA anchor function (AAnF) using information in the AKMA key ID. Once the server obtains the PSK, a mutual authentication is performed between the UE and the server using the PSK and the secure TLS connection/session is established between the UE and the server based on the successful authentication and authorization of the UE and the server), receive a key request from a network exposure function (NEF), wherein the NEF configured to forward the key request to the network function for the ECS ([0057] On generating the authentication server function key, the CN 204 derives an authentication and authorization key. In an example, the authentication and authorization key may be an AKMA key (K.sub.AKMA). The CN 204 may derive the authentication and authorization key/AKMA key (K.sub.AKMA) in accordance with the 3GPP TS 33.535. The CN 204 communicates the derived authentication and authorization key/AKMA key (K.sub.AKMA) to the AAnF 206 in a key response); and send a key response to the NEF, wherein the key response comprises the first credential and the NEF forwards the key response to the ECS ([0042] Embodiments herein use an Authentication and Key Management for Applications (AKMA) network service for the authentication and authorization of the UE and the server for the edge computing services. The AKMA network service establishes the required credentials between the UE and the server to perform the authentication and to establish the secure connection for the edge computing services. The UE derives a Pre-shared (PSK) key based on an AKMA application key and indicates an AKMA key identifier (ID) to the server to establish a secure Transport Layer Security (TLS) connection/session with the server for the edge computing services. In an example, the UE indicates the AKMA key ID to the server in Transport Layer Security messages. In another example, the UE indicates the AKMA key ID to the server in a service provisioning request). RAJADURAI does not explicitly disclose wherein the first credential is to be used by the ECS during an authentication procedure between the ECS and the UE. Gundavelli, in analogous art however, disclose wherein the first credential is to be used by the ECS during an authentication procedure between the ECS and the UE ([0094] At 310, CTF 130 communicates a DIAMETER-based Authentication-Information-Request (Auth Info Request or ‘AIR’) message to AAA/NPF/HSS 136 including the IMSI, a Public Land Mobile Network Identity (PLMNID), and the TAI. At 312, AAA/NPF/HSS 136 validates the TAI+PLMNID for the client 102 and generates an authentication vector using authentication techniques such as Evolved Packet System Authentication and Key Agreement (EPS-AKA) functionality that may be facilitated via EPS-AKA logic configured for AAA/NPF/HSS 136. The authentication vector may be represented as {AUTN, RAND, XRES, and KASME}, in which ‘AUTN’ is an authentication token, ‘RAND’ is a random challenge, ‘XRES’ is an expected response to the challenge, and ‘KASME’ (Access Security Management Entity Key) is a root key. In at least one embodiment, the EPS-AKA logic configured for AAA/NPF/HSS 136 can perform operations for generating the authentication vector according to techniques as prescribed at least by RFC 5448 and RFC 4187. [0095] Although techniques presented herein are discussed with reference to EPS-AKA mechanisms for cellular authentication, this is not meant to limit the broad scope of the present disclosure. In various implementations, other authentication mechanisms/protocols may be utilized (e.g., Extensible Authentication Protocol-Transport Layer Security (EAP-TLS), EAP-Tunneled TLS (EAP-TTLS), etc.) as may be understood in the art, now known here and/or hereinafter developed, which may or may not result in the generation of different authentication vectors/authentication information that may be utilized for authenticating users/devices to various access types. [0096] Upon generation of the authentication vector, AAA/NPF/HSS 136 sends an Authentication-Information-Answer (Auth Info Answer or ‘AIA ’) message to CTF 130 at 312 including the authentication vector. At 314, authentication of the client 102 for the cellular access is performed between CTF 130 and client 102 using the authentication vector. For example, the authentication vector can be used to perform an authentication between the client 102 and the CTF 130 to generate a shared key that can further be used to generate security keys, such as a cipher key (CK) and an integrity key (IK), that can be used to secure AS (Access Stratum) communications between the client 102 and the cellular AP 122 and also to secure NAS (Non-Access Stratum) communications between the client 102 and the CTF 130). Therefore, it would have been obvious to a person having ordinary skill in the art before the effective filing date of the invention to modify the claimed limitations of wherein the first credential disclosed by RAJADURAI is to be used by the ECS during an authentication procedure between the ECS and the UE. This modification would have been obvious because a person having ordinary skill in the art would have been motivated by the desire to provide interworking between SDA/enterprise fabric data and control plane elements as well as between a cellular control plane function (referred to herein as a cellular termination function (CTF)) to provide for the creation and/or deletion of radio and core network QoS bearer(s) by extending the techniques in which the Locator/Identity (ID) Separation Protocol (LISP) control plane is used for an SDA/enterprise fabric and providing end-to-end QoS and bringing a unique value to the SDA/enterprise fabric as suggested by Gundavelli ([0016]). As per claim 15: RAJADURAI discloses the of claim 14, wherein the network function is an authentication server function (AUSF) configured to perform the primary authentication with the UE and the second credential comprises KAUSF ([0075] On completion of the network access authentication procedure with the CN 204, the MT 308a generates the authentication key (K.sub.AUSF). The MT 308a stores the generated authentication key (K.sub.AUSF) in the memory 304. [0077] For providing the support functions to the application client(s) 312, the EEC 310 may establish the secure connection with the ECS 208a and the EES 208b. For establishing the secure connection with the ECS 208a, the EEC 310 derives the AKMA key (K.sub.AKMA), on generating the authentication key (K.sub.AUSF) by the MT 308a. The EEC 310 also derives the edge configuration server specific key (K.sub.ECS)/AKMA application key (K.sub.AF) based on the AKMA key (K.sub.AKMA)). As per claim 17. RAJADURAI discloses the of claim 14, further configured to: receiving receive a subscription request from the ECS for an authentication server function (AUSF) service operation, wherein the AUSF service operation is configured to provide the first credential and the identifier to the ECS ([0056] When the UE 202 wants to access the edge computing services, the UE 202 performs an authentication with the CN 204 using subscription credentials. In an example, the subscription credentials may include security credentials/Universal Subscriber Identity Module (USIM) credentials provided by a Mobile Network Operator (MNO) to access the CN 204/RAT supported by the CN 204. In an example, the authentication performed with the CN 204 may be a primary network access authentication procedure as specified in the 3GPP TS 33.501, clause 6.1. On performing the authentication with the CN 204, the UE 202 and the CN 204 generate an authentication server function key. In an example, if the CN 204 is a 5GC, then the authentication server function key may be a key K.sub.AUSF. [0141] The EEC 310 initiates the service provisioning procedure with the ECS 208a (as specified in the clause 8.3 in the 3GPP TS 23.558). The service provisioning procedures may include at least one of, a request-response procedure, a subscribe-notify procedure (including, a subscription update procedure and a unsubscribe procedure). In an example herein, the EEC 310 initiates the service provisioning procedure with the ECS 208a by sending the service provisioning request to the ECS 208a. The service provisioning request/request message from the EEC 310 includes the AKMA key ID). BRI (Broadest Reasonable Interpretation) Considerations The above claims under examination have been given to them their BRI considerations consistent with the applicant’s disclosure as they would be interpreted by ordinary skill in the art (POSITA) at the time of filing of the invention. In order to construe, appraise boundary and scope of the claimed limitations, the following claim words or terms or phrases or languages have been given to them their BRI considerations and context in view of the applicant’s disclosure. For record clarity, BRI for the following claim words or terms or phrases or languages, the examiner recites descriptions from the applicant’s disclosure as follows: Credentials [Applicant’s Disclosure: 0044] During primary authentication, the AUSF 131 may generate a credential K.sub.AUSF via authentication vector generation. The K.sub.AUSF may then be used for other operations of the primary authentication procedure. Some characteristics of the K.sub.AUSF include, i) the K.sub.AUSF may be shared between the UE 110 and AUSF 131 and ii) the K.sub.AUSF may provide the basis of the subsequent 5G key hierarchy. However, reference to K.sub.AUSF is merely provided for illustrative purposes, the exemplary embodiments may apply to any similar type of 3GPP credential or information being used in in addition or instead of K.sub.AUSF. Credentials [Applicant’s Disclosure: 0045] The UE 110 and the AUSF 131 may then each independently generate credentials based on K.sub.AUSF. Throughout this description, these credentials may be referred to as “K.sub.edge” and “K.sub.edge ID.” However, reference to “K.sub.edge” and “K.sub.edge ID” is merely provided for illustrative purposes, different entities may refer to similar concepts by a different name and any appropriate credentials or parameters may be utilized. Credentials [Applicant’s Disclosure: 0046] In this example, the credential K.sub.edge may be generated using a key derivation function (KDF) and derived from the credential K.sub.AUSF. Those skilled in the art will understand that the KDF may be, for example, the KDF defined in Annex B.2.0 of 3GPP Technical Specification (TS) 33.220 or any other similar type of function. The K.sub.edgeID parameter may be used to uniquely identify a K.sub.edge parameter. The K.sub.edgeID parameter may be generated in any appropriate manner. Since the credential K.sub.AUSF is shared between the UE 110 and the AUSF 131, the UE 110 and the AUSF 131 may independently generate the same credentials. Credentials [Applicant’s Disclosure: 0047] Authentication for access to the edge data network may be performed after primary authentication between the UE 110 and the core network 130. In the exemplary embodiments described below, the credentials “K.sub.edge” and “K.sub.edge ID” may be used in the exemplary authentication procedure for access to the edge data network. However, the examples provided above related to generating these credentials were merely provided for illustrative purposes, the “K.sub.edge” and “K.sub.edge ID” may be derived in any appropriate manner. Conclusion The prior arts made of record and not relied upon are considered pertinent to applicant's disclosure. See the notice of reference cited in form PTO-892 for additional prior arts. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to TECHANE GERGISO whose telephone number is (571)272-3784. The examiner can normally be reached 9:30am to 6:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LINGLAN EDWARDS can be reached at (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TECHANE GERGISO/ Primary Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

Jul 26, 2024
Application Filed
Nov 03, 2025
Non-Final Rejection mailed — §103
Feb 03, 2026
Response Filed
May 12, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706759
KEY MANAGEMENT AND SERVICE PROCESSING
2y 0m to grant Granted Aug 11, 2026
Patent 12701017
Authentication with Cloud-Based Secure Enclave
2y 6m to grant Granted Aug 04, 2026
Patent 12700052
CROSS-CERTIFICATE METHOD AND DEVICE FOR ELECTRIC VEHICLE CHARGING
2y 0m to grant Granted Aug 04, 2026
Patent 12695599
METHOD FOR USING CRYPTOGRAPHIC KEYS IN A VEHICLE ON-BOARD COMMUNICATION NETWORK
3y 0m to grant Granted Jul 28, 2026
Patent 12647399
BYPASSING IKE FIREWALL FOR CLOUD-MANAGED IPSEC KEYS IN SDWAN FABRIC
2y 2m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+24.2%)
3y 1m (~1y 0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 852 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month