DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1- 3, 5 – 15, 18-19 and 49-52 have been considered but are moot based on new grounds of rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1- 3, 5 – 15, 18-19 and 49-52 are rejected under 35 U.S.C. 103 as being unpatentable over Mueck, publication number: US 2024/0298194 in view of Wang, publication number: US 2008/0126794.
As per claims 1, 49 and 50, Mueck teaches an authentication method, performed by a first certificate authority (CA), wherein the method comprises:
generating a first-type certificate based on a transport layer security (TLS) protocol;
wherein the first-type certificate is a certificate of an entity in a first security domain in which the first CA is located (TLS certificate authority issuing certificates for TLS clients in its domain, [0158]).
Mueck does not teach wherein the first certificate authority is a root certificate authority and wherein generating the first-type certificate based on the TLS protocol comprises: generating the first-type certificate signed based on a private key of the first root CA.
In an analogous art, Wang teaches wherein the first certificate authority is a root certificate authority and wherein generating the first-type certificate based on the TLS protocol comprises: generating the first-type certificate signed based on a private key of the first root CA. (using a private key to generate a certificate, server certificate being signed by trusted certificate authority, the trusted certificate authority is analogous to the first root CA, [0020], TLS based security session, [0019][0021][0043])
Therefore, it would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to modify Mueck’s certificate authority system to include a root certificate authority system as described in Wang’s proxy communication system for advantages of system scalability and simplification of certificate as further described in Wang [0035].
As per claim 2, the combination teaches further comprising: sending the first-type certificate to the entity (Mueck: TLS certificate authority issuing certificates for TLS clients in its domain, [0158]).
As per claim 3, the combination teaches wherein generating the first-type certificate based on the transport layer security (TLS) protocol comprises:
generating a root certificate, wherein the root certificate is used to generate the first-type certificate (Wang: proxy device signing server certificate, [0035-0036]).
As per claim 5, the combination teaches wherein the entity comprises at least
one of:
Root CA;
TLS server CA;
TLS client CA;
TLS proxy CA;
Interconnection CA;
TLS server;
TLS client; or
TLS proxy (Mueck: TLS client and TLS server, Fig. 4A, [0158])
As per claims 6 and 51, the combination teaches an authentication method, performed by an interconnection certificate authority (CA) in a first security domain in which a first CA is located, wherein the method comprises:
generating a second-type certificate based on a TLS protocol (Interconnection CA cross certifying TLS client or server of a peer domain, Fig. 4, [0158]);
wherein the second-type certificate is a certificate of an entity in a second security domain in which a second CA is located, and the second-type certificate is at least used for TLS verification between entities in the first security domain and the second security domain (Peer domain certification, 3GPP 33.310, Fig. 4, [0158]).
Mueck does not teach wherein the certificate authority is a root certificate authority and acquiring a first-type certificate generated based on a transport layer security (TLS) protocol, wherein the first-type certificate is signed based on a private key of the first root CA.
In an analogous art, Wang teaches wherein the certificate authority is a root certificate authority and acquiring a first-type certificate generated based on a transport layer security (TLS) protocol, wherein the first-type certificate is signed based on a private key of the first root CA (using a private key to generate a certificate, server certificate being signed by trusted certificate authority, the trusted certificate authority is analogous to the first root CA, [0020], TLS based security session, [0019][0021][0043])
Therefore, it would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to modify Mueck’s certificate authority system to include a root certificate authority system as described in Wang’s proxy communication system for advantages of system scalability and simplification of certificate as further described in Wang [0035].
As per claim 7, the combination teaches wherein the entity comprises at least one of:
TLS proxy CA;
TLS proxy;
TLS server or
TLS client (Mueck: TLS client and TLS server, Fig. 4A, [0158]).
As per claim 8, the combination teaches wherein generating the second-type certificate based on the transport layer security (TLS) protocol comprises:
generating a TLS proxy CA certificate of a TLS proxy CA signed based on a private key of the interconnection CA (Wang: certificate authority, [0023], proxy certificate, [0028]).
As per claim 9, the combination teaches further comprising: sending the second-type certificate to the entity (Mueck: issuing certificate, [0158], Wang: certificate authority, [0023], proxy certificate, [0028]).
As per claims 10 and 52, the combination teaches an authentication method, performed by a first-type entity in a first security domain in which a first certificate authority (CA) is located, wherein the method comprises:
acquiring a predetermined certificate based on a transport layer security (TLS) protocol,
wherein the predetermined certificate comprises at least one of:
a first-type certificate of an entity in the first security domain in which the first CA is located (issuing certificates to TLS clients in its domain, [0158]); or
a second-type certificate of an entity in a second security domain in which a second CA is located, and the second-type certificate is at least used for TLS verification between entities in the first security domain and the second security domain (creating cross certificates, [0158], Fig. 4).
Mueck does not teach wherein the certificate authority is a root certificate authority and wherein the first-type certificate is signed based on a private key of the first root CA.
In an analogous art, Wang teaches wherein the certificate authority is a root certificate authority and wherein the first-type certificate is signed based on a private key of the first root CA (using a private key to generate a certificate, server certificate being signed by trusted certificate authority, the trusted certificate authority is analogous to the first root CA, [0020], security session, [0019][0021][0043])
Therefore, it would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to modify Mueck’s certificate authority system to include a root certificate authority system as described in Wang’s proxy communication system for advantages of system scalability and simplification of certificate as further described in Wang [0035].
As per claim 11, the combination teaches wherein acquiring the predetermined certificate based on the transport layer security (TLS) protocol
comprises:
acquiring the predetermined certificate that is pre-configured; or,
receiving the predetermined certificate sent by the first root CA or an interconnection CA (Mueck: receiving certificate from interconnect certificate authority, Fig. 4, [0158]).
As per claim 12, the combination teaches wherein the first-type entity comprises at least one of:
TLS server CA;
TLS client CA; or
TLS proxy CA (Mueck: TLS client and TLS server, Fig. 4A, [0158]).
As per claim 13, the combination teaches further comprising:
generating a third-type certificate signed based on a private key of the first-type entity (Mueck: token 512, [0160]).
As per claim 14, the combination teaches further comprising:
sending a third-type certificate to a second-type entity, wherein the third-type certificate comprises a public key used to establish a TLS tunnel between different entities (Mueck: token 512 and TLS connection 516, [0160]. Wang: TLS [0019][0021][0043]).
As per claim 15, the combination teaches wherein the first-type entity comprises a TLS client CA; the second-type entity comprises a TLS client; and sending the third-type certificate to the second-type entity comprises:
sending a TLS client certificate to the TLS client (Mueck: sending client certificate to client, [0158]); or
wherein the first-type entity comprises a TLS server CA; the second-type entity comprises a TLS server; and sending the third-type certificate to the second-type entity comprises:
sending a TLS server certificate to the TLS server; or
wherein the first-type entity comprises a TLS proxy CA; the second-type entity comprises a TLS proxy; and sending the third-type certificate to the second-type entity comprises:
sending a TLS proxy certificate to the TLS proxy.
As per claim 18, the combination teaches wherein sending the third-type certificate to the second-type entity comprises:
sending a TLS client certificate and a TLS server certificate to the second-type entity (Mueck: creating cross certificates, [0158], Fig. 4).
As per claim 19, the combination teaches wherein the second-type entity comprises at least one of:
TLS server;
TLS client; or
TLS proxy (Mueck: TLS client and TLS server, Fig. 4A, [0158]).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to OLUGBENGA O IDOWU whose telephone number is (571)270-1450. The examiner can normally be reached Monday-Friday 8am - 5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached at 5712723804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/OLUGBENGA O IDOWU/Primary Examiner, Art Unit 2494