Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Interpretation
In dependent claim recites the limitation “at least one processor circuit to be programmed based on the machine readable instruction to”. Since the limitation recites “to be programmed”, but not actually programmed, it appears that the effective limitation of the claim is “apparatus comprising: interface circuitry; machine readable medium and at least one processor circuit to be programmed”. Examiner suggests “at least one processor circuit [[to be]] programmed”.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1, 6, 8-9, 13, 16-17, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli et al. US 20220060893 A1 (hereinafter Gundavelli) in view of Kim et al. US 20210281998 A1 (hereinafter Kim).
Regarding claim 1, Gundavelli teaches
An apparatus comprising: interface circuitry; machine readable instructions; and at least one processor circuit to be programmed based on the machine readable instructions to:
generate first credentials (a signed eSIM profile/non-SIM profile with corresponding credentials) associated with a first network (enterprise SNPN 130) based on second credentials (preconfigured/shared credentials) associated with a second network (different access (e.g., enterprise Wi-Fi access credentials)), the first credentials including first location data corresponding to a dedicated private network (DPN) (enterprise SNPN 130);
(“e.g., communications units, receiver(s), transmitter(s), antenna(s) and/or antenna array(s), processor(s), memory element(s), baseband processor(s) (modems), etc., controllers, software, logic”[0023] “This approach involves the UE 102 having some form of preconfigured/shared credentials for connecting to the enterprise network 120, but for a different access (e.g., enterprise Wi-Fi access credentials) than an access provided via enterprise SNPN 130.”[0034] “The enterprise network 120, after validating the credentials of the UE as part of the UE's access authentication (over a different access) and by checking the device capabilities and an enterprise SNPN policy (via enterprise authentication server 123) can dynamically generate via enterprise management system 121/SNPN credential manager logic 122 a signed eSIM profile/non-SIM profile with corresponding credentials and network identifiers associated with the enterprise SNPN 130, which can enable the UE 102 to connect to enterprise SNPN 130.”[0039] “enterprise SNPN 130 may be implemented as any combination of WWA access network(s) (e.g., 4G/5G/nG/CBRS access network(s)) that are managed/operated by the enterprise entity associated with enterprise network 120.”[0029] “the SNPN credential manager logic 122 may utilize one or more parameters, such as any combination of: Enterprise User Identity, private WWA network metadata/identifiers, location/location information for UE 102 and/or, optionally, Wi-Fi Service Set Identifier (SSID) (e.g., for an On-Premise use case).”[0040] “an eSIM profile or package (e.g., characterized as one subtype of SNPN credential) may include IMSI, Integrated Circuit Card Identifier (ICCID) ICCID, security algorithms, authentication/security key(s), etc. along with network identifier metadata that may include PLMN ID, NID, APN/DNN, operating frequencies, etc. specific to a given location and SSID.”[0042] “In one example, separate eSIM profile metadata could be generated if the enterprise user is in an enterprise Germany Site (e.g., having different frequency bands, NID, and PLMN ID) as compared to a San Jose Site.”[0043])
cause a mobile device (UE 102) to program a programmable subscriber identity module (SIM) (eUICC 108) of the mobile device based on the first credentials (SNPN credentials);
(“the received SNPN credentials (e.g., eSIM profile or non-SIM credentials) may either be downloaded into eUICC 108 (e.g., SIM-based)” [0047] “enable translation and installation of one or more eSIM profile(s) (e.g., eSIM profile 131) into the eUICC chip 108 for the UE 102”[0048])
and permit the mobile device (UE 102) to access the DPN (enterprise SNPN 130)
(“the received SNPN credentials (e.g., eSIM profile or non-SIM credentials) may either be downloaded into eUICC 108 (e.g., SIM-based) or to a non-volatile memory such as memory/storage 106 (e.g., non-SIM) and can subsequently be used for network discovery of the enterprise SNPN 130 and for access authentication to connect to the enterprise SNPN 130. For example, eSIM profile 131 or non-SIM credentials 132 may enable UE 102 to connect to one or more private 3GPP WWA/4G/5G/nG/etc. access(es) of SNPN 130.”[0047]).
Gundavelli fails to teach permitting the mobile device to access a network based on a determination that second location data corresponding to the mobile device and included with the programmable SIM corresponds to the first location data. However, Kim teaches permitting the mobile device to access a network based on a determination that second location data (current location information) corresponding to the mobile device (user terminal/ electronic device 100) and included with the programmable SIM (the eUICC) corresponds to the first location data (PLMN information of the first profile).
(“the user terminal may deliver current location information of the user terminal (e.g., PLMN information provided from a network, coordinate information capable of being obtained through a GPS, or the like) to the eUICC. The eUICC may compare information of the profiles installed in the eUICC with the transmitted location information and may select and enable a suitable profile.”[0004] “The electronic device 100 may compare the location information with information of the previously enabled profile, that is, a first profile.”[0083] “when a current location corresponds to PLMN information of the first profile, in operation 505, the electronic device 100 may maintain the first profile.”[0084]” When there is the profile corresponding to the current location information in the profile list database 151, in operation 511, the electronic device 100 may determine whether the profile is the only profile (N=1) corresponding to the current location information. For example, when the profile corresponding to the current location information is only one second profile, in operation 513, the electronic device 100 may change the enabled profile from the first profile to the second profile.”[0086] “the CP 120 may perform registration with a network 10 using the enabled second profile.”[0078])
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Kim’s teaching of location based eUICC profile selection technique with Gundavelli’s teaching of SNPN credential provisioning system. A person of ordinary skill in the art would have been motivated to apply the location/site specific SNPN profiles of Gundavelli to automatically select and use the appropriate enterprise private network profile for the UE’s current location, thereby preventing use of an incorrect site specific profile and improving network selection and access management.
Regarding claim 6, limitations of parent claim 1 have been discussed above. Gundavelli teaches
wherein one or more of the at least one processor circuit (enterprise management system 121/SNPN credential manager logic 122) is to generate the first credentials (dynamically generat[ed] …signed eSIM profile/non-SIM profile with corresponding credentials) based on whether the second credentials (preconfigured/shared enterprise Wi-Fi access credentials) correspond to a wireless fidelity (Wi-Fi) network (enterprise Wi-Fi access) associated with the DPN (enterprise SNPN 130).
(“This approach involves the UE 102 having some form of preconfigured/shared credentials for connecting to the enterprise network 120, but for a different access (e.g., enterprise Wi-Fi access credentials) than an access provided via enterprise SNPN 130.”[0034]” UE 102 is to perform/complete an EAP-based authentication through any of: directly connecting to an enterprise WLA access (e.g., an enterprise Wi-Fi access) operated by the enterprise entity associated with enterprise network 120, connecting to some Wi-Fi OpenRoaming™ HotSpot that is associated with the enterprise entity”[0036] “The enterprise network 120, after validating the credentials of the UE as part of the UE's access authentication (over a different access) and by checking the device capabilities and an enterprise SNPN policy (via enterprise authentication server 123) can dynamically generate via enterprise management system 121/SNPN credential manager logic 122 a signed eSIM profile/non-SIM profile with corresponding credentials and network identifiers associated with the enterprise SNPN 130”[0039]” the SNPN credential manager logic 122 may utilize one or more parameters, such as any combination of: Enterprise User Identity, private WWA network metadata/identifiers, location/location information for UE 102 and/or, optionally, Wi-Fi Service Set Identifier (SSID)”[0040] “The SNPN credentials manager logic 122 utilizes the parameters (enterprise user/UE 102 ID, private WWA (4G/5G/nG) network identifiers, the location information for UE 102 and the SSID, to generate the SNPN credentials”[0066] “enterprise SNPN 130 may be implemented as any combination of WWA access network(s) (e.g., 4G/5G/nG/CBRS access network(s)) that are managed/operated by the enterprise entity associated with enterprise network 120.”[0029])
Regarding claim 8, limitations of parent claim 1 have been discussed above. Gundavelli teaches
wherein the first credentials (SNPN credentials/ eSIM profile) are first access credentials associated with a cellular network (enterprise SNPN 130), and the second credentials (preconfigured/shared credentials) are second access credentials (enterprise Wi-Fi access credentials) associated with a wireless fidelity (Wi-Fi) network (enterprise WLA access/ enterprise Wi-Fi access).
(“UE 102, through completing the EAP-based authentication to the enterprise network 120 through any of these techniques, may obtain SNPN credentials associated with the enterprise private WWA (4G/5G/nG) access of enterprise SNPN 130.”[0037] “the received SNPN credentials (e.g., eSIM profile or non-SIM credentials) may either be downloaded into eUICC 108 (e.g., SIM-based) or to a non-volatile memory such as memory/storage 106 (e.g., non-SIM) and can subsequently be used for network discovery of the enterprise SNPN 130 and for access authentication to connect to the enterprise SNPN 130. For example, eSIM profile 131 or non-SIM credentials 132 may enable UE 102 to connect to one or more private 3GPP WWA/4G/5G/nG/etc. access(es) of SNPN 130.”[0047] “This approach involves the UE 102 having some form of preconfigured/shared credentials for connecting to the enterprise network 120, but for a different access (e.g., enterprise Wi-Fi access credentials) than an access provided via enterprise SNPN 130.”[0034] “UE 102 is to perform/complete an EAP-based authentication through any of: directly connecting to an enterprise WLA access (e.g., an enterprise Wi-Fi access) operated by the enterprise entity associated with enterprise network 120”[0036])
Regarding claim 9, limitations of parent claim 1 have been discussed above. Gundavelli teaches
wherein one or more of the at least one processor circuit is to cause transmission of a code (EAP-REQUEST message/ signed eSIM profile) to the mobile device via a wireless fidelity (Wi-Fi) network (public (OpenRoaming) WLA access network/infrastructure 110b/111b) not included in the DPN (SNPN for the enterprise), the code to cause the mobile device (UE 102) to program the programmable SIM based on the first credentials (SNPN credentials object).
(“the access network/infrastructure 110/111 is configured as a public (OpenRoaming) WLA access network/infrastructure 110b/111b (”[0085] “UE 102 can attach to an OpenRoaming HotSpot for the public (OpenRoaming) WWA access network/infrastructure 110b/111b and complete an authentication (e.g., a secondary authentication) to enterprise authentication server 123 (e.g., a home AAA server) for a Protocol Data Unit Session (PDU) session in order to obtain SNPN credentials from enterprise network 120.”[0086] “an access network that is different than the SNPN for the enterprise.”[0097] “the enterprise authentication server 123 sends the signed SNPN credentials object (202) to UE 102, as shown at 320, in an EAP-REQUEST message with various information/indications including but not limited to: Type=EAP-SNPN-CFG, SubType=SIM or Non-SIM (credential type indicator set depending on the type of credentials), Signed data=signed SNPN credentials object [e.g., signed eSIM profile or signed non-SIM credentials], and an operation type indicator, such as Operation=Installation and Activation.”[0068] “the received SNPN credentials (e.g., eSIM profile or non-SIM credentials) may either be downloaded into eUICC 108 (e.g., SIM-based)”[0047] “The eUICC manager logic 107 may be inclusive of any hardware, software, logic, etc. that interfaces with eUICC chip 108 via any combination of GSMA-defined ES10 interfaces, such as ES10a, ES10b, and ES10c interfaces, referred to collectively as the ‘ES10x’ interface in order to facilitate installing, activating, disabling, and/or deleting one or more eSIM profiles for the eUICC chip 108.”[0049]” Operation=Installation and Activation.”[0068] “the SNPN credential manager logic 122 generates the SNPN credentials (e.g., eSIM profile or non-SIM credentials) to enable UE 102 to connect to the enterprise SNPN 130… The generated SNPN credentials and network identifier metadata may be encapsulated in an SNPN credentials object.”[0066])
Regarding claim 13, claim 13 reflects article of manufacture comprising computer executable instructions for implementing apparatus in claim 1 and is rejected along the same rationale.
Regarding claim 16, limitations of parent claim 13 have been discussed above. Claim 16 reflects article of manufacture comprising computer executable instructions for implementing apparatus in claim 8 and is rejected along the same rationale.
Regarding claim 17, claim 17 reflects a method for implementing apparatus in claim 1 and is rejected along the same rationale.
Regarding claim 20, limitations of parent claim 17 have been discussed above. Claim 20 reflects method for implementing apparatus in claim 8 and is rejected along the same rationale.
Claims 2-4, 14-15, and 18-19 are rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli and Kim in view Further of Xu US 10827422 B1.
Regarding claim 2, limitations of parent claim 1 have been discussed above. Xu teaches method and apparatus
wherein one or more of the at least one processor circuit (Steering Application 40) is to repeatedly (periodically) verify that the second location data (longitude and latitude values) corresponds to the first location data (predefined values stored in database 45).
(“GPS module 46 is used to periodically obtain longitude and latitude values corresponding to the current location of mobile device 12. When mobile device 12 is connected to non-preferred PLMN 14, GPS module 46 is actuated to periodically obtain the current GPS location of mobile device 12. The GPS coordinates are used to determine whether mobile device 12 has entered a geographic area having Private LTE/5G network 22 coverage.”[col 7, lines 41-49] “If the current location of mobile device 12 is outside the coverage area of Private LTE/5G network 22, the method returns to step 204, and GPS module 46 continues to periodically collect and report data associated with a location of mobile device 12.”[col 8, lines 11-15] “Steering Application 40 compares the reported values against the predefined values stored in database 45 associated with the coverage area of Private LTE/5G network 22. Based on the results of this comparison, Steering Application 40 determines whether the current location of mobile device 12 is within the coverage area of Private LTE/5G network 22.”[col 5, lines 61-67])
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Xu’s teaching of periodic location verification technique with Gundavelli and Kim’s teaching of SNPN credential provisioning system. A person of ordinary skill in the art would have been motivated to make this modification for the benefit of continually determining whether the mobile device remains within the geographic area associated with the private network as the device changes location, thereby providing a known and predictable mechanism for maintaining location dependent private network access.
Regarding claim 3, limitations of parent claim 1 have been discussed above. Xu teaches method and apparatus
wherein one or more of the at least one processor circuit (Steering Application 40) is to prevent the mobile device (mobile device 12) from accessing the DPN (Private LTE/5G network 22) based on the second location data (obtain longitude and latitude values corresponding) not corresponding to the first location data (predefined values).
(“the preferred network may be a Private LTE network, a 5G network, or a Private 5G network.”[col 3, lines 54-55] “Steering Application 40 compares the reported values against the predefined values stored in database 45 associated with the coverage area of Private LTE/5G network 22.”[col 5, lines 61-64] “GPS module 46 is used to periodically obtain longitude and latitude values corresponding to the current location of mobile device 12.”[col 7, lines 41-44] “step 116 involves determining whether the current geographic location of mobile device 12 is within the coverage area of Private LTE/5G network 22. If it is determined that mobile device 12 is outside the coverage area of Private LTE/5G network 22”[col 6, lines 56-60] “when the mobile device leaves the coverage area of the preferred network, data payload exchange between the mobile device and network applications is suppressed.”[col 3, lines 65 -66 ] – [col 4, lines 1-2] “by denying a network connection, dropping data packets or throttling network speed.”[col 4, lines 5-6])
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Xu’s teaching of periodic location verification technique with Gundavelli and Kim’s teaching of SNPN credential provisioning system. A person of ordinary skill in the art would have been motivated to make this modification for the benefit of restricting private network connectivity to mobile devices that remain within the authorized geographic area of the private network, thereby providing a known and predictable location based access control mechanism.
Regarding claim 4, limitations of parent claim 1 have been discussed above. Xu teaches
wherein the first location data is indicative of a geographic area associated with the DPN, the second location data is indicative of a location of the mobile device, and one or more of the at least one processor circuit is to determine that the second location data corresponds to the first location data based on whether the location is within the geographic area.
(“the preferred network may be a Private LTE network, a 5G network, or a Private 5G network.”[col 3, lines 54-55] “The geographic coverage area of Private LTE/5G network 22 at least partially overlaps the geographic coverage area of PLMN 14.”[col 5, lines 17-20]” The steering application accesses a set of prestored attribute values associated with the geographical coverage area of the preferred network and compares prestored values against the set of values reported by the mobile device.”[col 3, lines 6-10] “GPS module 46 is configured to collect data—e.g., longitude and latitude coordinates—associated with a current location of mobile device 12.”[col 7, lines 64-67] “GPS module 46 is used to periodically obtain longitude and latitude values corresponding to the current location of mobile device 12.”[col 7, lines 41-44] “In step 208, it is determined whether the current location of mobile device 12 is within the coverage area of Private LTE/5G network 22.”[col 8, lines 8-11]).
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Xu’s teaching of geographic coverage determination technique with Gundavelli and Kim’s teaching of SNPN credential provisioning system. A person of ordinary skill in the art would have been motivated to make this modification for the benefit of providing a direct and objectively determinable geographic criterion for determining whether the mobile device satisfies the private network’s location requirement, thereby providing a known and predictable mechanism for controlling location dependent private network access.
Regarding claim 14, limitations of parent claim 13 have been discussed above. Claim 14 reflects article of manufacture comprising computer executable instructions for implementing apparatus in claim 3 and is rejected along the same rationale.
Regarding claim 15, limitations of parent claim 13 have been discussed above. Claim 15 reflects article of manufacture comprising computer executable instructions for implementing apparatus in claim 4 and is rejected along the same rationale.
Regarding claim 18, limitations of parent claim 17 have been discussed above. Claim 18 method for implementing apparatus in claim 3 and is rejected along the same rationale.
Regarding claim 19, limitations of parent claim 17 have been discussed above. Claim 19 method for implementing apparatus in claim 4 and is rejected along the same rationale.
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli and Kim in view Further of Agarwal US 20190289017 A1.
Regarding claim 5, limitations of parent claim 1 have been discussed above. Agarwal teaches wherein one or more of the at least one processor circuit (processor 30) is to provide the second credentials (shared-secret value) to at least one of a hash algorithm or hash function (cryptographic hash function (like SHA1, SHA-256 or MD5)) to generate the first credentials (generate a limited-use authentication credential).
(“the processor 30 may coordinate the operation of other components illustrated and execute program instructions stored in memory 32”[0030] “the processor 30 may execute program code of the native application 36 that causes the native application to provide the functionality described below”[0031] “the TLOTP may be the output of a cryptographic hash function (like SHA1, SHA-256 or MD5) taking as input a quantized measure of time determined by the user's mobile computing device, a quantized measure of geolocation determined by the user's mobile computing device, and a shared secret value possessed by the user's computing device and an authentication server.”[0022] “the mobile computing device 64 may generate a limited-use authentication credential from one or more cryptographic hash values based on the shared secret value, the coarser-geolocation value, a quantization of time, and the use-limiting value.”[0075] “the mobile computing device 64 may generate a limited-use authentication credential from a first cryptographic hash value based on the shared-secret value and the use-limiting value and a second cryptographic hash value based on the first cryptographic hash value and the coarser-geolocation based value.”[0082])
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Agarwal’s cryptographic hash based credential generation technique with Gundavelli and Kim’s credential generation system so that the existing authentication credentials are provide as input to a hash function when generating the SNPN credentials. This would predictably provide a secure one way mechanism for generating new network access credentials from established authentication information.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli and Kim in view Further of Namiranian et al. US 20190181901 A1 (hereinafter Namiranian).
Regarding claim 7, limitations of parent claim 1 have been discussed above. Namiranian teaches
The apparatus of claim 1, wherein one or more of the at least one processor circuit (MNO) is to generate a quick response code based on the first credentials (authentication credential and key information) , the quick response code to cause the mobile device (user equipment 108) to program the programmable SIM based on the first credentials (authentication credential and key information).
(“At block 502, the MNO generates an activation code such as a QR code, wherein the activation code comprises an SM-DP+ address corresponding to an SM-DP+ having a profile. At block 504, the MNO transmits the activation code to a user equipment. At block 506, the user equipment retrieves the SM-DP+ address based on the activation code. At block 508, the user equipment identifies an SM-DP+ correlating to the SM-DP+ address in the activation code. At block 510, the user equipment reaches the SM-DP+ to download the profile.”[0052] “each profile can include information related to a corresponding subscription manager and information for establishing a connection or for allowing communication with the subscription manager, and an authentication credential and key information for performing an authentication”[0027] “each SM-DP+ is configured to securely package profiles to be provisioned on the eUICC 104 of the user equipment 108.”[0025]).
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Namiranian’s QR code based eSIM provisioning technique with Gundavelli and Kim’s credential generation system so that a QR activation code identifies the server/profile containing the generated SNPN credentials and causes the UE to download and install that profile on the eUICC. This would predictably provide a known, user friendly mechanism for provisioning the generated private network credentials onto the programmable SIM.
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli and Kim in view Further of Shan et al. US 20210314899 A1 (hereinafter Shan).
Regarding claim 10, limitations of parent claim 1 have been discussed above. Gundavelli teaches
wherein one or more of the at least one processor circuit (enterprise management system 121/SNPN credential manager logic 122/ enterprise authentication server 123 ) is to cause transmission of a code (SNPN credentials object) to the mobile device (UE 102) via a radio nodes) included in the DPN (enterprise SNPN 130), the code to cause the mobile device to program the programmable SIM based on the first credentials (SNPN credential).
(“enterprise SNPN 130 may be implemented as any combination of WWA access network(s) (e.g., 4G/5G/nG/CBRS access network(s)) that are managed/operated by the enterprise entity associated with enterprise network 120… enterprise SNPN 130 may also include any combination of eNBs/gNBs/CBSDs and 4G/5G/nG mobile core network elements to facilitate UE 102 connecting to the enterprise SNPN 130 upon obtaining SNPN credentials from enterprise network 120”[0029] “access network infrastructure 111 may include any combination of radio nodes [sometimes referred to as access points (APs)]”[0026] “UE 102, through completing the EAP-based authentication to the enterprise network 120 through any of these techniques, may obtain SNPN credentials associated with the enterprise private WWA (4G/5G/nG) access of enterprise SNPN 130 …the SNPN credentials may be delivered via an SNPN credentials object, which may include an eSIM profile or a non-SIM profile/credentials for the UE 102 and network identifier metadata, as discussed below, to enable the UE 102 to connect to the enterprise SNPN 130.”[0037] “The enterprise network 120, after validating the credentials of the UE as part of the UE's access authentication (over a different access) and by checking the device capabilities and an enterprise SNPN policy (via enterprise authentication server 123) can dynamically generate via enterprise management system 121/SNPN credential manager logic 122 a signed eSIM profile/non-SIM profile with corresponding credentials and network identifiers associated with the enterprise SNPN 130”[0039] “the received SNPN credentials (e.g., eSIM profile or non-SIM credentials) may either be downloaded into eUICC 108 (e.g., SIM-based)”[0047]” following the provisioning/installation/activation of the SNPN credentials, UE 102 can now connect to the enterprise SNPN 130 using the provisioned SNPN credentials.”[0075])
Gundavelli fails to teach non-trusted. However Shan teaches a non-trusted access point (untrusted entities).
(“AMF 321 may also support NAS signalling with a UE 301 over an N3IWF interface for N3GPP access (e.g., the N2 reference point discussed herein)… The N3IWF is used to provide access to untrusted entities… N3IWF may also relay uplink and downlink control-plane NAS signalling between the UE 301 and AMF 321 via an N1 reference point between the UE 301 and the AMF 321, and relay uplink and downlink user-plane packets between the UE 301 and UPF 302.”[0049])
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Shan’s N3IWF based untrusted non 3GPP access technique with Gundavelli and Kim’s credential generation system so that the credential bearing esim provisioning message is transmitted to the UE through a non-trusted access path associated with the private cellular network. This would predictably allow the UE to obtain and install its private network eSIM credentials through a known secure untrusted non 3GPP access mechanism.
Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli and Kim in view Further of Gandhi et al. US 20220014900 A1 (hereinafter Gandhi).
Regarding claim 11, limitations of parent claim 1 have been discussed above. Gundavelli teaches
wherein one or more of the at least one processor circuit (enterprise management system 121/SNPN credential manager logic 122/ enterprise authentication server 123 ) is to cause transmission of a code (SNPN credentials object) to the mobile device (UE 102) via a radio nodes) included in the DPN (enterprise SNPN 130), the code to cause the mobile device to program the programmable SIM based on the first credentials (SNPN credential).
(“enterprise SNPN 130 may be implemented as any combination of WWA access network(s) (e.g., 4G/5G/nG/CBRS access network(s)) that are managed/operated by the enterprise entity associated with enterprise network 120… enterprise SNPN 130 may also include any combination of eNBs/gNBs/CBSDs and 4G/5G/nG mobile core network elements to facilitate UE 102 connecting to the enterprise SNPN 130 upon obtaining SNPN credentials from enterprise network 120”[0029] “access network infrastructure 111 may include any combination of radio nodes [sometimes referred to as access points (APs)]”[0026] “UE 102, through completing the EAP-based authentication to the enterprise network 120 through any of these techniques, may obtain SNPN credentials associated with the enterprise private WWA (4G/5G/nG) access of enterprise SNPN 130 …the SNPN credentials may be delivered via an SNPN credentials object, which may include an eSIM profile or a non-SIM profile/credentials for the UE 102 and network identifier metadata, as discussed below, to enable the UE 102 to connect to the enterprise SNPN 130.”[0037] “The enterprise network 120, after validating the credentials of the UE as part of the UE's access authentication (over a different access) and by checking the device capabilities and an enterprise SNPN policy (via enterprise authentication server 123) can dynamically generate via enterprise management system 121/SNPN credential manager logic 122 a signed eSIM profile/non-SIM profile with corresponding credentials and network identifiers associated with the enterprise SNPN 130”[0039] “the received SNPN credentials (e.g., eSIM profile or non-SIM credentials) may either be downloaded into eUICC 108 (e.g., SIM-based)”[0047]” following the provisioning/installation/activation of the SNPN credentials, UE 102 can now connect to the enterprise SNPN 130 using the provisioned SNPN credentials.”[0075])
Gundavelli fails to teach trusted. However Gandhi teaches a trusted (auth/MDM server 112) access point (Wi-Fi® access points) included in the DPN (private network).
(“enterprise management node 110 and enterprise access network 120 may be considered an enterprise infrastructure 102, such as an enterprise network and/or the like, which may be managed and/or operated by an enterprise entity”[0022] “Enterprise access network 120 may include one or more WLA radio node(s) 122 (e.g., Wi-Fi® access point(s)) and one or more WWA radio node(s) (e.g., CBRS radio devices (CBSDs), 4G/LTE radio devices such as eNBs/eNodeBs, 5G and/or nG radio devices such as gNBs/gNodeBs, and/or the like).”[0030] “enterprises are also increasingly seeking to integrate private 3GPP accesses, such as 3GPP 4G/LTE, 5G, and/or nG into enterprise networks …A private network may also be referred to as a non-public network (NPN) in some instances.”[0016 - 0017] “Authentication services may include authenticating and/or authorizing one or more device(s) to connect to enterprise infrastructure 102”[0025] “the eSIM profile capability and WWA access network connectivity capability of a given enterprise UE can be determined during authentication of the UE to the enterprise infrastructure 102 through a WLA access network connection via a given WLA radio node 122 as the UE seeks to connect to the enterprise infrastructure 102 and is authenticated via auth/MDM server 112.”[0041] “enterprise UE 140, having an eSIM profile capability (e.g., capable of obtaining and installing/activating one or more eSIM profile(s)) and a WWA access network connectivity capability (e.g., capable of connecting to a WWA access network via one or more WWA radio node(s) 124) enrolls with the enterprise entity via auth/MDM server 112 over an existing connection, such as a WLA access network (e.g., Wi-Fi®) connection.”[0040] “auth/MDM server 112 can send an MDM command to enterprise UE 140 that triggers enterprise MDM client 146 on the device to download the eSIM profile 250 from enterprise eSIM store 116 via the WLAN”[0048] “The Payload 306 may include an eSIM profile to install and activate for a device (e.g., enterprise UE 140)”[0051] “The Install command code 312 may be utilized instruct a device to install and activate an eSIM profile either contained in the Payload 306 or an eSIM profile that is to be retrieved by the device”[0053] “enterprise MDM client 146 can use an existing operating system (OS) framework for enterprise UE to install and activate eSIM profile to eUICC 144”[0061])
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Gandhi’s authenticated enterprise WLAN access point technique with Gundavelli and Kim’s credential generation system so that the access point used to provide credential bearing eSIM provisioning information to the mobile device is a trusted enterprise access point included within the enterprise private network infrastructure. A person of ordinary skill in the art would have been motivated to make this modification for the benefit of securely provisioning private network credentials through an enterprise controlled and authenticated access point using an already established enterprise WLAN connection, thereby providing a known and predictable mechanism for onboarding and activating the mobile device for access to the enterprise private cellular network.
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Gundavelli and Kim in view Further of Opshaug et al. US 20210152410 A1 (hereinafter Opshaug).
Regarding claim 12, limitations of parent claim 1 have been discussed above. Gundavelli teaches
wherein the DPN (enterprise SNPN 130) includes at least one of a terrestrial network (eNBs/gNBs/CBSDs and 4G/5G/nG mobile core network) or a non-terrestrial network, and one or more of the at least one processor circuit (SNPN credentials manager logic 122) is to determine the second location [based on location information corresponding to the mobile device] (location information for UE 102) the mobile device (UE 102) attached to at least one of the terrestrial network (eNBs/gNBs/CBSDs and 4G/5G/nG mobile core network) or the non-terrestrial network.
(“enterprise SNPN 130 may be implemented as any combination of WWA access network(s) (e.g., 4G/5G/nG/CBRS access network(s)) that are managed/operated by the enterprise entity associated with enterprise network 120… enterprise SNPN 130 may also include any combination of eNBs/gNBs/CBSDs and 4G/5G/nG mobile core network elements to facilitate UE 102 connecting to the enterprise SNPN 130 upon obtaining SNPN credentials from enterprise network 120”[0029] “The SNPN credentials manager logic 122 utilizes the parameters (enterprise user/UE 102 ID, private WWA (4G/5G/nG) network identifiers, the location information for UE 102 and the SSID, to generate the SNPN credentials”[0066] “the UE could request to the authentication server that it needs WWA/5G SNPN credentials mapped to a WLA SSID for enterprise WLA access network 110a and specific to a given location (e.g., a particular enterprise campus, site, building, etc.)”[0098])
Gundavelli fails to teach data based on at least one of a time-of-arrival, an angle-of-arrival, a time-difference-of-arrival, or a multi-cell round trip time associated with communications from the mobile device . However Opshaug teaches data based on at least one of a time-of-arrival, an angle-of-arrival (Angles of arrival), a time-difference-of-arrival (TDOA/ OTDOA), or a multi-cell round trip time associated with communications from the mobile device (UE).
(“The server 143 (e.g., an LMF) and/or one or more other devices of the system 110 (e.g., one or more of the UEs 112-114) may be configured to determine locations of the UEs 112-114”[0033] “known position-determination techniques include RTT, multi-RTT, OTDOA (also called TDOA and including UL-TDOA and DL-TDOA), Enhanced Cell Identification (E-CID), DL.-AOD, UL-AoA, etc. RTT uses a time for a signal to travel from one entity to another and back to determine a range between the two entities…multi-RTT (also called multi-cell RTT), multiple ranges from one entity (e.g., a UE) to other entities (e.g,, TRPs) and known locations of the other entities may be used to determine the location of the one entity… TDOA techniques, the difference in travel times between one entity and other entities may be used to determine relative ranges from the other entities and those, combined with known locations of the other entities may be used to determine the location of the one entity. Angles of arrival and/or departure be used to help determine location of an entity. For example, an angle of arrival or an angle of departure of a signal combined with a range between devices (determined using signal, e.g., a travel time of the signal, a received power of the signal, etc.) and a known location of one of the devices may be used to determine a location of the other device. The angle of arrival or departure may be an azimuth angle relative to a reference direction such as true north. The angle of arrival or departure may be a zenith angle relative to directly upward from an entity (i.e,, relative to radially outward from a center of Earth). E-CID uses the identity of a serving cell, the timing advance (i.e., the difference between receive and transmit times at the UE), estimated timing and power of detected neighbor cell signals, and possibly angle of arrival (e.g., of a signal at the UE from the base station or vice versa) to determine location of the UE. In TD0A, the difference in arrival times at a receiving device of signals from different sources along with known locations of the sources and known offset of transmission times from the sources are used to determine the location of the receiving device.”[0058])
Accordingly, it would have been obvious to a person having of ordinary skill in the art before the effective filling date of the claimed invention to combine Opshaug’s cellular positioning technique with Gundavelli and Kim’s credential generation system determining the location information corresponding to the mobile device using knowing positioning techniques. A person of ordinary skill in the art would have been motivated to make this modification for the benefit of accurately determining the mobile device’s location using existing cellular radio measurements, thereby providing the location information used by the SNPN system for location dependent private network access through a known and predictable cellular positioning mechanism.
References Cited But Not Relied Upon
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Sicard et al (US 20220030423 A1 paragraphs [0021] [0025] [0029] ) is pertinent to authenticating a mobile device using enterprise credentials and provisioning a communication profile to a programmable SIM using an activation code.
Avula et al (US 20210051478 A1 paragraph [0010]) is pertinent to private network access using eSIM profiles containing network specific credentials.
Oswal et al (US 20210112382 A1 paragraph [0145] – [0166]) is pertinent to cross network onboarding and provisioning network access credentials to an eSIM.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FAVOUR O MADU whose telephone number is (571)272-9730. The examiner can normally be reached Monday - Friday 8am-6pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeanette Parker can be reached at (571) 270-3647. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/F.O.M./Examiner, Art Unit 2646
/JEANETTE J PARKER/Supervisory Patent Examiner, Art Unit 2646