DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 11/06/2024 and 07/23/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Drawings
The drawings are objected to because:
Figure 1 should be designated by a legend such as --Prior Art-- because only that which is old is illustrated. See MPEP § 608.02(g) (see page 1 line 19 to page 2 line 24).
The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they include the following reference character(s) not mentioned in the description:
“210”; “250”, (see figure 2);
“2610A”; “2610B”; “2612A”; “2612B”; “2612C”; “2612D” (see figure 26);
“3008A”; “3008B” (see figure 30)
Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Specification
The disclosure is objected to because of the following informalities:
The recitation in page 29 line 35 “2610a-b” seems to be improper because it is improperly constructed (see figure 26); it is suggested to be changed to “2610A-B”
The recitation in page 30 line 3 “2612a-b” seems to be improper because it is improperly constructed (see figure 26); it is suggested to be changed to “2612A-B”
The recitation in page 31 line 34 “2612c and/or 2612d” seems to be improper because it is improperly constructed (see figure 26); it is suggested to be changed to “2612C and/or 2612D”
The recitation in page 32 line 16 “2612c and/or 2612d” seems to be improper because it is improperly constructed (see figure 26); it is suggested to be changed to “2612C and/or 2612D”
The recitation in page 32 line 23 “2610b” seems to be improper because it is improperly constructed (see figure 26); it is suggested to be changed to “2610B”
The recitation in page 32 line 24 “2610b” seems to be improper because it is improperly constructed (see figure 26); it is suggested to be changed to “2610B”
The recitation in page 41 line 20 “3008a-b” seems to be improper because it is improperly constructed (see figure 30); it is suggested to be changed to “3008A-B”
The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification.
35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, requires the specification to be written in “full, clear, concise, and exact terms.” The specification is with terms which are not clear, concise and exact. The specification should be revised carefully in order to comply with 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112.
Appropriate correction is required.
Claim Objections
Claim 95 is objected to because of the following informalities:
The recitation in line 4 of claim 95 “processing circuitry operably coupled to the the communication interface circuitry” seems to be improper, because it is improperly constructed; it is suggested to be changed to “processing circuitry operably coupled to the communication interface circuitry” (delete one “the”)
Appropriate correction is required.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 74-95 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by 3GPP ("3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)", 3GPP STANDARD; TECHNICAL SPECIFICATION; 3GPP TS 33.501, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE; 650, ROUTE DES LUCIOLES; F-06921 SOPHIA-ANTIPOLIS CEDEX; FRANCE vol. SA WG3, no. V17.6.0 17 June 2022 (2022-06-17), pages 1-292).
Regarding claims 74 and 94, 3GPP discloses user equipment, UE, configured to communicate with a communications network via at least a first access network without registering with the communications network, receiving from the communications network an authentication-related message ("17. The NSWOF shall send the EAP-success and MSK to WLAN AN over the SWa interface. The EAP-Success message is forwarded from WLAN AN to the UE" pages 264, 265); generating the following based on the authentication-related message a first security key usable for establishing a secure connection with the first access network, and one or more second security keys usable for communicating with the communications network ("On receiving the EAP-Success message, the UE derives EMSK from CK' and IK' as described in RFC 5448 and Annex F. The ME uses the most significant 256 bits of the EMSK as the KAUSF and then calculates KSEAF in the same way as the AUSF. The UE shall derive the KAMF from the KSEAF, the ABBA parameter and the SUPI according to Annex A.7.": page 46); establishing a secure connection with the first access network based on the first security key ("18. Upon receiving the EAP-Success message, the UE derives the MSK as specified in step 11, if it has not derived the MSK earlier. The UE uses MSK to perform 4-way handshake to establish a secure connection with the WLAN AN." pages 264, 265); and registering with the communication network based on at least one of the second security keys ("...decide to run a new primary authentication and a NAS SMC procedure (which activates the new 5G NAS security context based on the KAMF derived during the primary authentication run) after the Registration Request.": page 78).
PNG
media_image1.png
505
728
media_image1.png
Greyscale
Regarding claims 84 and 95, 3GPP discloses receiving, from a user equipment, UE, via a first access network, a first authentication message that includes an identifier associated with user credentials for the communication network ("4. The EAP Response/ Identity message shall be routed over the SWa interface towards the NSWOF based on the realm part of the SUCI. NOTE 1: NSWOF acts as SBI/AAA proxy between the AUSF and the WLAN Access Network.": page 264); sending, to a second NNF of the communications network, an authentication request that includes the identifier and an indication that the UE should be authenticated for accessing the first access network and for registration with the communications network ("5. The NSWOF shall send the message Nausf_UE Authentication_Authenticate Request with SUCI, Access Network Identity and NSWO indicator towards the AUSF. NSWO indicator is used to indicate to the AUSF that the authentication request is for Non-seamless WLAN offload purposes. The NSWOF shall set the Access Network Identity to "5G:NSWO".": page 264); receiving the following from the second NNF: an authentication response indicating that the UE is authenticated according to the indication, and a first security key usable for establishing a secure connection between the UE and the first access network (''8. The AUSF shall store XRES for future verification. The AUSF shall send the EAP-Request/AKA'-Challenge message to the NSWOF in a Nausf_UE Authentication_Authenticate Response message."; (".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF."): pages 264, 265); and forwarding the first security key to the first access network and the authentication response to the UE via the first access network ("17. The NSWOF shall send the EAP-success and MSK to WLAN AN over the SWa interface.": pages 264, 265).
Regarding claim 75, 3GPP discloses claim 74, 3GPP also discloses the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; the communications network is a fifth-generation (5G) network; and the one or more second security keys include KAUSF, KSEAF, and KAMF (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 76, 3GPP discloses claim 75, 3GPP also discloses the first access network a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF" …”17. The NSWOF shall send the EAP-success and MSK to WLAN AN over the SWa interface. The EAP-Success message is forwarded from WLAN AN to the UE. 18. Upon receiving the EAP-Success message, the UE derives the MSK as specified in step 11, if it has not derived the MSK earlier. The UE uses MSK to perform 4-way handshake to establish a secure connection with the WLAN AN.”)
Regarding claim 77, 3GPP discloses claim 75, 3GPP also discloses registering with the communications network is based on KAMF (pages 44-46, 94-95, 263-265 "On receiving the EAP-Success message, the UE derives EMSK from CK' and IK' as described in RFC 5448 and Annex F. The ME uses the most significant 256 bits of the EMSK as the KAUSF and then calculates KSEAF in the same way as the AUSF. The UE shall derive the KAMF from the KSEAF, the ABBA parameter and the SUPI according to Annex A.7.")
Regarding claim 78, 3GPP discloses claim 74, 3GPP also discloses an EAP-Request message or an EAP-Success message (pages 44-46, 94-95, 263-265 "17. The NSWOF shall send the EAP-success and MSK to WLAN AN over the SWa interface. The EAP-Success message is forwarded from WLAN AN to the UE.")
Regarding claim 79, 3GPP discloses claim 74, 3GPP also discloses sending to the first access network a first authentication message including an identifier associated with user credentials for the communications network and receiving from the first access network a second authentication message responsive to the first authentication message (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 80, 3GPP discloses claim 79, 3GPP also discloses one of the following applies: the first authentication message includes an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network; or the second authentication message includes an indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 81, 3GPP discloses claim 79, 3GPP also discloses at least one of the following applies: the first authentication message is an EAP Response/Identity message and the second authentication message is an EAP-Request message; and the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI) (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UEAuthentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 82, 3GPP discloses claim 74, 3GPP also discloses an identifier associated with the first access network, and generating the first security key and the one or more second security keys is based on the identifier associated with the first access network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 83, 3GPP discloses claim 74, 3GPP also discloses one of the following: the secure connection with the first access network, or a second access network different than the first access network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 85, 3GPP discloses claim 84, 3GPP also discloses one of the following: the first access network is a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network; the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; and the first authentication message is an EAP Response/Identity message and the authentication response is an EAP-Success message (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF" … “17. The NSWOF shall send the EAP-success and MSK to WLAN AN over the SWa interface. The EAP-Success message is forwarded from WLAN AN to the UE.18. Upon receiving the EAP-Success message, the UE derives the MSK as specified in step 11, if it has not derived the MSK earlier. The UE uses MSK to perform 4-way handshake to establish a secure connection with the WLAN AN.”)
Regarding claim 86, 3GPP discloses claim 84, 3GPP also discloses sending the authentication request is based on determining that the UE should be authenticated for accessing the first access network and for registration with the communications network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication _Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF" … “17. The NSWOF shall send the EAP-success and MSK to WLAN AN over the SWa interface. The EAP-Success message is forwarded from WLAN AN to the UE. 18. Upon receiving the EAP-Success message, the UE derives the MSK as specified in step 11, if it has not derived the MSK earlier. The UE uses MSK to perform 4-way handshake to establish a secure connection with the WLAN AN.”)
Regarding claim 87, 3GPP discloses claim 86, 3GPP also discloses one of the following: an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network, wherein the indication is included in the first authentication message; or local policy of the first NNF that each UE authentication should be for accessing the first access network and for registration with the communications network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UEAuthentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 88, 3GPP discloses claim 84, 3GPP also discloses sending to the UE via the first access network a second authentication message that includes an indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UEAuthentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF" … “17. The NSWOF shall send the EAP-success and MSK to WLAN AN over the SWa interface. The EAP-Success message is forwarded from WLAN AN to the UE. 18. Upon receiving the EAP-Success message, the UE derives the MSK as specified in step 11, if it has not derived the MSK earlier. The UE uses MSK to perform 4-way handshake to establish a secure connection with the WLAN AN.”)
Regarding claim 89, 3GPP discloses claim 88, 3GPP also discloses EAP-Request message (pages 44-46, 94-95, 263-265 ".3 The AUSF shall send the EAP-Request/AKA'-Challenge message to the SEAF in a Nausf_UE Authentication_ Authenticate Response message" … “8. The AUSF shall store XRES for future verification. The AUSF shall send the EAP-Request/AKA'-Challenge message to the NSWOF in a Nausf_UE Authentication_Authenticate Response message.”)
Regarding claim 90, 3GPP discloses claim 88, 3GPP also discloses one of the following: sending the second authentication message is responsive to determining, based on local policy, that the UE should be authenticated for accessing the first access network and for registration with the communications network; or the method further comprising receiving the second authentication message from the second NNF, wherein the received second authentication message is forwarded to the UE via the first access network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 91, 3GPP discloses claim 84, 3GPP also discloses one of the following: the indication that the UE should be authenticated for accessing the first access network and for registration with the communications network is implicit from the authentication request sent to the second NNF; and the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI) (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF" … “5. The NSWOF shall send the message Nausf_UE Authentication_Authenticate Request with SUCI, Access Network Identity and NSWO indicator towards the AUSF.”)
Regarding claim 92, 3GPP discloses claim 84, 3GPP also discloses the communications network is a fifth-generation (5G) network; the first NNF is a non-seamless wireless LAN offload function (NSWOF); and the second NNF is one of the following: an access and mobility management function (AMF) separate from the NSWOF, an AMF combined with the NSWOF, or an authentication support function (AUSF) (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF.")
Regarding claim 93, 3GPP discloses claim 92, 3GPP also discloses an address of an AMF that supports registration of the UE with the communications network (pages 44-46, 94-95, 263-265 ".16. The AUSF shall send Nausf_UE Authentication_Authenticate Response message with EAP-Success and MSK key to NSWOF. The AUSF may optionally provide the SUPI to NSWOF. 17. The NSWOF shall send the EAP-success and MSK to WLAN AN over the SWa interface. The EAP-Success message is forwarded from WLAN AN to the UE")
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 74-95 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 81-102 of copending Application No. 18/863,501 (reference application). Although the claims at issue are not identical, they are not patentably distinct from each other because claims 74-95 of the present application are obvious from claims 81-102 of copending Application No. 18/863,501 (reference application) because they are a combination of claims 81-102 of copending Application No. 18/863,501 with a finite number of possible combinations. See KSR. In the KSR case, the Court stated that in certain circumstances what is obvious to try is also obvious, such as where "there is a design need or market pressure to solve a problem, and there are a finite number of identified, predictable solutions, a person of ordinary skill has good reason to pursue the known options within his or her technical grasp. If this leads to the anticipated success, it is likely the product not of innovation but of ordinary skill and common sense." Regarding hindsight, the Court found that "[r]igid preventive rules that deny fact finders recourse to common sense . . . are neither necessary under our case law nor consistent with it." The Court stated that "familiar items may have obvious uses beyond their primary purposes," analogizing an obvious invention to the fitting together of pieces to a puzzle. The Court in this regard further stated that the person of ordinary skill is also a person of ordinary creativity, and not "an automaton."
This is a provisional nonstatutory double patenting rejection because the patentably indistinct claims have not in fact been patented.
Present Application
Copending Application No. 18/863,501
74. A method for a user equipment (UE) configured to communicate with a communications network via at least a first access network, the method comprising:
without registering with the communications network, receiving from the communications network an authentication-related message; generating the following based on the authentication-related message:
a first security key usable for establishing a secure connection with the first access network, and one or more second security keys usable for communicating with the communications network;
establishing a secure connection with the first access network based on the first security key; and
registering with the communications network based on at least one of the second security keys
82. A method for a user equipment (UE) configured to communicate with a communications network via at least a first access network, the method comprising:
without registering with the communications network, receiving from the communications network an
identifier associated with the first access network and an indication of security algorithms to use when communicating with the communications network; based on the identifier associated with the first access network, generating
a first security key usable for establishing a secure connection with the first access network;
generating one or more second security keys for communicating with the communications network using the indicated security algorithms
establishing a secure connection with the first access network based on the first security key; and
registering with the communications network using the indicated security algorithms
75. The method of claim 74, wherein: the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; the communications network is a fifth-generation (5G) network; and the one or more second security keys include KAUSF, KSEAF, and KAMF
83. The method of claim 82, wherein: the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; the communications network is a fifth-generation (5G) network; and the one or more second security keys include KAUSF, KSEAF, and KAMF
76. The method of claim 75, wherein the first access network a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network
84. The method of claim 83, wherein the first access network is a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network
77. The method of claim 75, wherein registering with the communications network is based on KAMF
85. The method of claim 82, wherein registering with the communications network is based on KAMF
78. The method of claim 74, wherein the authentication-related message is an EAP-Request message or an EAP-Success message
88. The method of claim 86, wherein at least one of the following applies: the first authentication message is an EAP Response/Identity message and the second authentication message is an EAP-Request message; the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI); and the indication of the security algorithms is included in a data parameter of the second authentication message, with the data parameter being encrypted and/or integrity protected
79. The method of claim 74, further comprising: sending to the first access network a first authentication message including an identifier associated with user credentials for the communications network; and
receiving from the first access network a second authentication message responsive to the first authentication message
86. The method of claim 81, further comprising: sending to the first access network a first authentication message including an identifier associated with user credentials for the communications network and an indication of security algorithms supported by the UE; and receiving from the first access network a second authentication message responsive to the first authentication message, wherein the second authentication message includes the indication of security algorithms to use
80. The method of claim 79, wherein one of the following applies: the first authentication message includes an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network; or the second authentication message includes an indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network
86. The method of claim 81, further comprising: sending to the first access network a first authentication message including an identifier associated with user credentials for the communications network and an indication of security algorithms supported by the UE; and receiving from the first access network a second authentication message responsive to the first authentication message, wherein the second authentication message includes the indication of security algorithms to use
81. The method of claim 79, wherein at least one of the following applies: the first authentication message is an EAP Response/Identity message and the second authentication message is an EAP-Request message; and the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI)
88. The method of claim 86, wherein at least one of the following applies: the first authentication message is an EAP Response/Identity message and the second authentication message is an EAP-Request message; the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI); and the indication of the security algorithms is included in a data parameter of the second authentication message, with the data parameter being encrypted and/or integrity protected
82. The method of claim 74, wherein the authenticated-related message
includes an identifier associated with the first access network, and generating the first security key and the one or more second security keys is based on the identifier associated with the first access network
86. The method of claim 81, further comprising: sending to the first access network a first authentication message including an identifier associated with user credentials for the communications network and an indication of security algorithms supported by the UE; and receiving from the first access network a second authentication message responsive to the first authentication message, wherein the second authentication message includes the indication of security algorithms to use
83. The method of claim 74, wherein registering with the communications network is via one of the following: the secure connection with the first access network, or a second access network different than the first access network
90. The method of claim 81, wherein registering with the communications network is via one of the following: the secure connection with the first access network, or a second access network different than the first access network.
84. A method for a first network node or function (NNF) of a communications network, the method:
receiving, from a user equipment (UE) via a first access network, a first authentication message that includes an identifier associated with user credentials for the communications network;
sending, to a second NNF of the communications network, an authentication request that includes the identifier and an indication that the UE should be authenticated for accessing the first access network and for registration with the communications network; receiving the following from the second NNF: an authentication response indicating that the UE is authenticated according to the indication, and a first security key usable for establishing a secure connection between the UE and the first access network; and
forwarding the first security key to the first access network and the authentication response to the UE via the first access network
91. A method for a first network node or function (NNF) of a communications network, the method:
receiving, from a user equipment (UE) via a first access network, a first authentication message that includes an identifier associated with user credentials for the communications network and an indication of security algorithms supported by the UE;
sending, to a second NNF of the communications network, an authentication request that includes the identifier and the indication of security algorithms supported by the UE;
receiving the following information from the second NNF: an indication of security algorithms for the UE to use when communicating with the communications network, an authentication response indicating that the UE is authenticated, and a first security key usable for establishing a secure connection between the UE and the first access network; and
forwarding the first security key to the first access network and forwarding, to the UE via the first access network, the authentication response and the indication of security algorithms for the UE to use
85. The method of claim 84, wherein at least one of the following applies: the first access network is a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network; the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; and the first authentication message is an EAP Response/Identity message and the authentication response is an EAP-Success message
92. The method of claim 91, wherein at least one of the following applies: the first access network is a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network; the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; the indication of security algorithms for the UE to use is received and forwarded in a data parameter of an EAP-Request message, with the data parameter being encrypted and/or integrity protected; and the first authentication message is an EAP Response/Identity message and the authentication response is an EAP-Success message
86. The method of claim 84, wherein sending the authentication request is based on determining that the UE should be authenticated for accessing the first access network and for registration with the communications network
93. The method of claim 91, wherein the authentication request also includes a second indication that the UE should be authenticated for accessing the first access network and for registration with the communications network, and the authentication response indicates that the UE is authenticated in accordance with the second indication
87. The method of claim 86, wherein determining that the UE should be authenticated for accessing the first access network and for registration with the communications network is based on one of the following: an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network, wherein the indication is included in the first authentication message; or local policy of the first NNF that each UE authentication should be for accessing the first access network and for registration with the communications network
95. The method of claim 94, wherein determining that the UE should be authenticated for accessing the first access network and for registration with the communications network is based on one of the following: an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network,
included in the first authentication message; or local policy of the first NNF that each UE authentication should be for accessing the first access network and for registration with the communications network
88. The method of claim 84, further comprising sending to the UE via the first access network a second authentication message that includes an indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network
96. The method of claim 95, further comprising, when determining that the UE should be authenticated is based on local policy, sending to the UE via the first access network a third indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network
89. The method of claim 88, wherein the second authentication message is an EAP-Request message
97. The method of claim 96, wherein the third indication is sent to the UE in a data parameter of an EAP-Request message, with the data parameter being encrypted and/or integrity protected
90. The method of claim 88, wherein one of the following applies:
sending the second authentication message is responsive to determining, based on local policy, that the UE should be authenticated for accessing the first access network and for registration with the communications network; or the method further comprising receiving the second authentication message from the second NNF, wherein the received second authentication message is forwarded to the UE via the first access network
99. The method of claim 91, wherein the authentication request
sent to the second NNF implicitly indicates that the UE should be authenticated for accessing the first access network and for registration with the communications network.
91. The method of claim 84, wherein at least one of the following applies: the indication that the UE should be authenticated for accessing the first access network and for registration with the communications network is implicit from the authentication request sent to the second NNF; and the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI)
99. The method of claim 91, wherein the authentication request sent to the second NNF implicitly indicates that the UE should be authenticated for accessing the first access network and for registration with the communications network.
92. The method of claim 84, wherein: the communications network is a fifth-generation (5G) network; the first NNF is a non-seamless wireless LAN offload function (NSWOF); and the second NNF is one of the following: an access and mobility management function (AMF) separate from the NSWOF, an AMF combined with the NSWOF, or an authentication support function (AUSF)
100. The method of claim 91, wherein: the communications network is a fifth-generation (5G) network; the first NNF is a non-seamless wireless LAN offload function (NSWOF); and the second NNF is one of the following: an access and mobility management function (AMF) separate from the NSWOF, an AMF combined with the NSWOF, or an authentication support function (AUSF)
93. The method of claim 92, wherein the authentication request also includes an address of an AMF that supports registration of the UE with the communications network
100. The method of claim 91, wherein: the communications network is a fifth-generation (5G) network; the first NNF is a non-seamless wireless LAN offload function (NSWOF); and the second NNF is one of the following: an access and mobility management function (AMF) separate from the NSWOF, an AMF combined with the NSWOF, or an authentication support function (AUSF)
94. A user equipment (UE) configured to communicate with a communications network via at least a first access network, the UE comprising: communication interface circuitry configured to communicate via the first access network; and processing circuitry operably coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: without registering with the communications network, receive from the communications network an authentication-related message; generate the following based on the authentication-related message:
a first security key usable for establishing a secure connection with the first access network, and one or more second security keys usable for communicating with the communications network; establish a secure connection with the first access network based on the first security key; and register with the communications network based on at least one of the second security keys
101. User equipment (UE) configured to communicate with a communications network via at least a first access network, the UE comprising: communication interface circuitry configured to communicate via the first access network; and processing circuitry operably coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: without registering with the communications network, receive from the communications network an
identifier associated with the first access network and an indication of security algorithms to use when communicating with the communications network; based on the identifier associated with the first access network, generate
a first security key usable for establishing a secure connection with the first access network;
establish a secure connection with the first access network based on the first security key; and register with the communications network using the indicated security algorithms
95. Network equipment configured to implement a first network node or function (NNF) of a communications network, the network equipment comprising: communication interface circuitry configured to communicate with user equipment (UEs) and with other NNFs of the communications network; and processing circuitry operably coupled to the the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: receive, from a UE via a first access network, a first authentication message that includes an identifier associated with user credentials for the communications network;
send, to a second NNF of the communications network, an authentication request that includes the identifier and an indication that the UE should be authenticated for accessing the first access network and for registration with the communications network;
receive the following from the second NNF:
an authentication response indicating that the UE is authenticated according to the indication, and
a first security key usable for establishing a secure connection between the UE and the first access network; and forward the first security key to the first access network and
the authentication response to the UE via the first access network
102. Network equipment configured to implement a first network node or function (NNF) of a communications network, the network equipment comprising: communication interface circuitry configured to communicate with user equipment (UEs) and with other NNFs of the communications network; and processing circuitry operably coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: receive, from a UE via a first access network, a first authentication message that includes an identifier associated with user credentials for the communications network and an indication of security algorithms supported by the UE;
send, to a second NNF of the communications network, an authentication request that includes the identifier and the indication of security algorithms supported by the UE;
receive the following information from the second NNF: an indication of security algorithms for the UE to use when communicating with the communications network,
an authentication response indicating that the UE is authenticated, and
a first security key usable for establishing a secure connection between the UE and the first access network; and forward the first security key to the first access network and
forward, to the UE via the first access network,
the authentication response and the indication of security algorithms for the UE to use
Claims 74-95 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 84-105 of copending Application No. 18/863,481 (reference application). Although the claims at issue are not identical, they are not patentably distinct from each other because claims 74-95 of the present application are obvious from claims 84-105 of copending Application 18/863,481 (reference application) because they are a combination of claims 84-105 of copending Application No. 18/863,481 with a finite number of possible combinations. See KSR
This is a provisional nonstatutory double patenting rejection because the patentably indistinct claims have not in fact been patented.
Present Application
Copending Application No. 18/863,481
74. A method for a user equipment (UE) configured to communicate with a communications network via at least a first access network, the method comprising:
without registering with the communications network, receiving from the communications network an authentication-related message; generating the following based on the authentication-related message:
a first security key usable for establishing a secure connection with the first access network, and one or more second security keys usable for communicating with the communications network;
establishing a secure connection with the first access network based on the first security key; and
registering with the communications network based on at least one of the second security keys
85. A method for a user equipment (UE) configured to communicate with a communications network via at least a first access network, the method comprising:
without registering with the communications network, receiving from the communications network an authentication-related message that includes the following: an identifier associated with the first access network, and at least one of a temporary UE identifier and a security key identifier; based on the identifier associated with the first access network, generating a first security key usable for establishing a secure connection with the first access network;
establishing a secure connection with the first access network based on the first security key; and
registering with the communications network based on the at least one of the temporary UE identifier and the security key identifier.
based on the identifier associated with the first access network and the at least one of the temporary UE identifier and the security key identifier, generating one or more second security keys usable for communicating with the communications network without need for further authentication of the UE
75. The method of claim 74, wherein: the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; the communications network is a fifth-generation (5G) network; and the one or more second security keys include KAUSF, KSEAF, and KAMF
86. The method of claim 85, wherein: the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; the communications network is a fifth-generation (5G) network; the temporary UE identifier is a 5G globally unique temporary identifier (GUTI); the security key identifier is a non-access stratum key set identifier (ngKSI); and the one or more second security keys include KAUSF, KSEAF, and KAMF
76. The method of claim 75, wherein the first access network a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network
87. The method of claim 86, wherein the first access network is a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network.
77. The method of claim 75, wherein registering with the communications network is based on KAMF
88. The method of claim 85, wherein registering with the communications network is based on KAMF.
78. The method of claim 74, wherein the authentication-related message is an EAP-Request message or an EAP-Success message
89. The method of claim 84, wherein the authentication-related message is an EAP-Request message or an EAP-Success message.
79. The method of claim 74, further comprising: sending to the first access network a first authentication message including an identifier associated with user credentials for the communications network; and receiving from the first access network a second authentication message responsive to the first authentication message
90. The method of claim 84, further comprising: sending to the first access network a first authentication message including an identifier associated with user credentials for the communications network; and receiving from the first access network a second authentication message responsive to the first authentication message.
80. The method of claim 79, wherein one of the following applies: the first authentication message includes an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network; or the second authentication message includes an indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network
91. The method of claim 90, wherein one of the following applies: the first authentication message includes an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network; or the second authentication message includes an indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network
81. The method of claim 79, wherein at least one of the following applies: the first authentication message is an EAP Response/Identity message and the second authentication message is an EAP-Request message; and the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI)
92. The method of claim 90, wherein at least one of the following applies: the first authentication message is an EAP Response/Identity message and the second authentication message is an EAP-Request message; and the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI).
82. The method of claim 74, wherein the authenticated-related message
includes an identifier associated with the first access network, and generating the first security key and the one or more second security keys is based on the identifier associated with the first access network
85 ..authentication-related message that
includes the following: an identifier associated with the first access network, and at least one of a temporary UE identifier and a security key identifier;
on the identifier associated with the first access network and the at least one of the temporary UE identifier and the security key identifier, generating one or more second security keys usable for communicating with the communications network without need for further authentication of the UE
83. The method of claim 74, wherein registering with the communications network is via one of the following: the secure connection with the first access network, or a second access network different than the first access network
91. The method of claim 90, wherein one of the following applies: the first authentication message includes an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network; or the second authentication message includes an indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network.
84. A method for a first network node or function (NNF) of a communications network, the method:
receiving, from a user equipment (UE) via a first access network, a first authentication message that includes an identifier associated with user credentials for the communications network;
sending, to a second NNF of the communications network, an authentication request that includes the identifier and an indication that the UE should be authenticated for accessing the first access network and for registration with the communications network; receiving the following from the second NNF: an authentication response indicating that the UE is authenticated according to the indication, and a first security key usable for establishing a secure connection between the UE and the first access network; and
forwarding the first security key to the first access network and the authentication response to the UE via the first access network
93. A method for a first network node or function (NNF) of a communications network, the method: receiving, from a user equipment (UE) via a first access network, a first authentication message that includes
an identifier associated with user credentials for the communications network; sending, to a second NNF of the communications network, an authentication request that includes the identifier associated with user credentials for the communications network; receiving the following information from the second NNF: at least one of a temporary UE identifier and a security key identifier, an authentication response indicating that the UE is authenticated, and a first security key usable for establishing a secure connection between the UE and the first access network; and forwarding the first security key to the first access network and forwarding the at least one of the temporary UE identifier and the security key identifier to the UE via the first access network.
85. The method of claim 84, wherein at least one of the following applies: the first access network is a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network; the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; and the first authentication message is an EAP Response/Identity message and the authentication response is an EAP-Success message
94. The method of claim 93, wherein at least one of the following applies: the first access network is a trusted wireless local area network (WLAN), a trusted non-3GPP access network, or a non-trusted non-3GPP access network; the first security key is a master session key (MSK) or a non-seamless wireless LAN offload (NSWO) key; the at least one of the temporary UE identifier and the security key identifier is received and forwarded in a data parameter of an EAP-Request message, with the data parameter being encrypted and/or integrity protected; and the first authentication message is an EAP Response/Identity message and the authentication response is an EAP-Success message
86. The method of claim 84, wherein sending the
authentication request is based on determining that the UE should be authenticated for accessing the first access network and for registration with the communications network
96. The method of claim 95, wherein the second indication is included in the authentication request based on determining that the UE should be authenticated for accessing the first access network and for registration with the communications network.
87. The method of claim 86, wherein determining that the UE should be authenticated for accessing the first access network and for registration with the communications network is based on one of the following: an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network, wherein the indication is
included in the first authentication message; or local policy of the first NNF that each UE authentication should be for accessing the first access network and for registration with the communications network
97. The method of claim 96, wherein determining that the UE should be authenticated for accessing the first access network and for registration with the communications network is based on one of the following: an indication that the UE is requesting authentication for accessing the first access network and for registration with the communications network,
included in the first authentication message; or local policy of the first NNF that each UE authentication should be for accessing the first access network and for registration with the communications network.
88. The method of claim 84, further comprising sending to the UE via the first access network a second authentication message that includes an indication that the communications network is authenticating the UE for accessing the first access network and for registration with the communications network
96. The method of claim 95, wherein the second indication is included in the authentication request based on determining that the UE should be authenticated for accessing the first access network and for registration with
the communications network.
89. The method of claim 88, wherein the second authentication message is an EAP-Request message
99. The method of claim 98, wherein the third indication is sent to the UE in a data parameter of an EAP-Request message, with the data parameter being encrypted and/or integrity protected.
90. The method of claim 88, wherein one of the following applies:
sending the second authentication message is responsive to determining, based on local policy, that the UE should be authenticated for accessing the first access network and for registration with the communications network; or the method further comprising
receiving the second authentication message from the second NNF, wherein the received second authentication message is forwarded to the UE via the first access network
100. The method of claim 99, further comprising
receiving the EAP-Request message from the second NNF, wherein the received EAP-Request message is forwarded to the UE via the first access network
91. The method of claim 84, wherein at least one of the following applies: the indication that the UE should be authenticated for accessing the first access network and for registration with the communications network is implicit from the authentication request sent to the second NNF; and the identifier associated with user credentials for the communications network is a subscription concealed identifier (SUCI)
101. The method of claim 93, wherein the authentication request sent to the second NNF implicitly indicates that the UE should be authenticated for accessing the first access network and for registration with the communications network.
92. The method of claim 84, wherein: the communications network is a fifth-generation (5G) network; the first NNF is a non-seamless wireless LAN offload function (NSWOF); and the second NNF is one of the following: an access and mobility management function (AMF) separate from the NSWOF, an AMF combined with the NSWOF, or an authentication support function (AUSF)
102. The method of claim 93, wherein: the communications network is a 5G network; the temporary UE identifier is a 5G globally unique temporary identifier (GUTI); the security key identifier is a non-access stratum key set identifier (ngKSI); the first NNF is a non-seamless wireless LAN offload function (NSWOF); and the second NNF is one of the following: an access and mobility management function (AMF) separate from the NSWOF, an AMF combined with the NSWOF, or an authentication support function (AUSF).
93. The method of claim 92, wherein the authentication request also includes an address of an AMF that supports registration of the UE with the communications network
103. The method of claim 102, wherein the authentication request also includes an address of an AMF that supports registration of the UE with the communications network
94. A user equipment (UE) configured to communicate with a communications network via at least a first access network, the UE comprising: communication interface circuitry configured to communicate via the first access network; and processing circuitry operably coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: without registering with the communications network, receive from the communications network an authentication-related message; generate the following based on the authentication-related message:
a first security key usable for establishing a secure connection with the first access network, and one or more second security keys usable for communicating with the communications network; establish a secure connection with the first access network based on the first security key; and register with the communications network based on at least one of the second security keys
104. A user equipment (UE) configured to communicate with a communications network via at least a first access network, the UE comprising: communication interface circuitry configured to communicate via the first access network; and processing circuitry operably coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: without registering with the communications network, receive from the communications network an authentication-related message that includes the following: an identifier associated with the first access network, and at least one of a temporary UE identifier and a security key identifier; based on the identifier associated with the first access network, generate a first security key usable for establishing a secure connection with the first access network; establish a secure connection with the first access network based on the first security key; and register with the communications network based on the at least one of the temporary UE identifier and the security key identifier.
95. Network equipment configured to implement a first network node or function (NNF) of a communications network, the network equipment comprising: communication interface circuitry configured to communicate with user equipment (UEs) and with other NNFs of the communications network; and processing circuitry operably coupled to the the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: receive, from a UE via a first access network, a first authentication message that includes an identifier associated with user credentials for the communications network; send, to a second NNF of the communications network, an authentication request that includes the identifier and an indication that the UE should be authenticated for accessing the first access network and for registration with the communications network; receive the following from the second NNF: an authentication response indicating that the UE is authenticated according to the indication, and a first security key usable for establishing a secure connection between the UE and the first access network; and forward the first security key to the first access network and the authentication response
to the UE via the first access network
105. Network equipment configured to implement a first network node or function (NNF) of a communications network, the network equipment comprising: communication interface circuitry configured to communicate with user equipment (UEs) and with other NNFs of the communications network; and processing circuitry operably coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to: receive, from a UE via a first access network, a first authentication message that includes an identifier associated with user credentials for the communications network; send, to a second NNF of the communications network, an authentication request that includes the identifier associated with user credentials for the communications network; receive the following information from the second NNF: at least one of a temporary UE identifier and a security key identifier, an authentication response indicating that the UE is authenticated, and a first security key usable for establishing a secure connection between the UE and the first access network; and forward the first security key to the first access network and forward the at least one of the temporary UE identifier and the security key identifier
to the UE via the first access network.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Li (US 20240179525 A1) discloses secure communication method and apparatus.
Kunz (US 20230262463 A1) discloses mobile network authentication using a concealed identity.
Palanigounder (US 20230044847 A1) discloses 5G non-seamless wireless local area network offload.
Rajavelsamy (US 20240298174 A1) discloses method and systems for authenticating UE for accessing non-3GPP service.
Salkintzis (US 20250254639 A1) discloses registering with a mobile network after a first authentication with a WLAN access network.
Salkintzis (US 10986481 B2) discloses method to authenticate with a mobile communication network.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JUAN A TORRES whose telephone number is (571)272-3119. The examiner can normally be reached M-F 9-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kenneth N Vanderpuye can be reached at (571) 272-3078. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JUAN A TORRES/Primary Examiner, Art Unit 2634