Prosecution Insights
Last updated: August 17, 2026
Application No. 18/874,315

SECURE COMMUNICATION METHOD AND APPARATUS

Non-Final OA §102§103
Filed
Dec 12, 2024
Priority
Jun 20, 2022 — nonprovisional of PCTCN2022099964
Examiner
LIU, ZHE
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
Beijing Xiaomi Mobile Software Co., Ltd.
OA Round
1 (Non-Final)
72%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
108 granted / 150 resolved
+14.0% vs TC avg
Strong +58% interview lift
Without
With
+58.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 12m
Avg Prosecution
19 currently pending
Career history
167
Total Applications
across all art units

Statute-Specific Performance

§101
5.7%
-34.3% vs TC avg
§103
62.0%
+22.0% vs TC avg
§102
5.4%
-34.6% vs TC avg
§112
22.5%
-17.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 150 resolved cases

Office Action

§102 §103
DETAILED ACTION The following claims are pending in this office action: 1-14 and 16-21 The following claims are new: - The following claims are cancelled: 15 and 22-24 Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Drawings The drawings filed on 12/12/2024 are accepted. Information Disclosure Statement The information disclosure statement (IDS) submitted on 12/12/2024 has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, an initialed and dated copy of Applicant’s IDS form 1449 filed 12/12/2024 is attached to the instant Office action. Specification The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1, 7, 12 and 16-21 are rejected under 35 USC § 102(a)(2) as being anticipated by Khare et al. (US Pub. 2023/0345246) (hereinafter “Khare”). As per claim 1, Khare teaches a secure communication method, ([Khare, para. 0050] “AKMA (Authentication and Key Management for Application) is a feature that leverages an operator authentication infrastructure to secure communications between a UE 106 and an AF 222”) applied to an authentication and key management for applications (AKMA) authentication proxy, ([para. 0056] “an AKMA authentication proxy 602 ... to execute AKMA authentication procedures (e.g., key request procedure) on behalf of the AF(s) 222”) wherein the method comprises: receiving a service request of a target application server sent by a user equipment (UE), wherein the service request carries identification information of the target application server and an AKMA key identifier (A-KID) of the UE; ([Khare, para. 0075] “UE 106 sends an Application Session Establishment Request message 1201 [service request] to AKMA authentication proxy 602 ... UE 106 may be programmed with an Authentication Proxy (AP) identity (AP_ID) of AKMA authentication proxy 602, and sends the Application Session Establishment Request message 1201 to AKMA authentication proxy 602 ... UE 106 includes the A-KID [carries A-KID] and the AF identity [caries identification information] for AF 222-1 [of a target application server] (e.g., AF1_ID) in the Application Session Establishment Request message 1201”) performing authentication and authorization on the UE according to the A-KID and the identification information of the target application server, and determining whether to authorize the UE to access the target application server; and ([Khare, para. 0076-0077] “proxy controller 904 determines whether a key derivation procedure has been performed for UE 106 [performing authentication and authorization on the UE] ... determine whether or not it stores a KAF key mapped to the AF identity [according to the identification information of the target application server] ... Proxy controller 904 sends an Nnef_AKMA_ApplicationKey_Get Request message 1206 ... verify whether the subscriber is authorized to use AKMA based on the presence of the UE-specific KAKMA key 704 identified by the A-KID [according to the A-KID] ... derives the KAF key [authorize the UE to access the application target server] ... AF 222-1 based on the AF1_ID ... sends an ... Response message 1207 to AKMA authentication proxy 602”) in response to authorizing the UE to access the target application server, forwarding the service request and an authentication result of the UE to the target application server. ([Khare, para. 0078-0079] “proxy controller 904 of AKMA authentication proxy 602 receives the key response message [in response to authorizing the UE to access the target application server as per above] ... Proxy controller 904 forwards or redirects the Application Session Establishment Request message 1201 to AF 222-1 [forwarding the service request] ... Proxy controller 904 includes the KAF key [and an authentication result of the UE] ... in the Application Session Establishment Request message 1201”) As per claim 7, Khare teaches claim 1. Khare also teaches wherein after sending the service request and the authentication result of the UE to the target application server, the method further comprises: ([Khare, para. 0079] “Proxy controller 904 forwards or redirects the Application Session Establishment Request message 1201 to AF 222-1 [sending the service request] ... Proxy controller 904 includes the KAF key [and an authentication result of the UE} ... in the Application Session Establishment Request message 1201”) sending a service response of the target application server to the UE. ([Khare, para. 0079] “in response to the Application Session Establishment Request message 1201 being forwarded by AKMA authentication proxy 602, [after sending the service request and the authentication request] AF 222-1 sends an Application Session Establishment Response message 1204 to UE 106 [sending a service response of the target application server to the UE]”; [0056; Fig. 6B] the response is sent by the proxy as “An AKMA authentication proxy ... resides ... between a UE 106 and a plurality of AFs 222” and so the service response necessarily is sent first to the Proxy to be sent to the UE) As per claim 12, Khare teaches a secure communication method, ([Khare, para. 0050] “AKMA (Authentication and Key Management for Application) is a feature that leverages an operator authentication infrastructure to secure communications between a UE 106 and an AF 222”) applied to a user equipment (UE), ([para. 0050] “AKMA reuses the 5G primary authentication procedure to authenticate a UE 106”) wherein the method comprises: sending a service request of a target application server to an authentication and key management for applications (AKMA) authentication proxy, wherein the service request carries identification information of the target application server and an AKMA key identifier (A-KID) of the UE; and ([Khare, para. 0075] “UE 106 sends an Application Session Establishment Request message 1201 [service request] to AKMA authentication proxy 602 ... UE 106 may be programmed with an Authentication Proxy (AP) identity (AP_ID) of AKMA authentication proxy 602, and sends the Application Session Establishment Request message 1201 to AKMA authentication proxy 602 ... UE 106 includes the A-KID [carries A-KID] and the AF identity [caries identification information] for AF 222-1 [of a target application server] (e.g., AF1_ID) in the Application Session Establishment Request message 1201”) receiving response information returned by the AKMA authentication proxy. ([Khare, para. 0079] “in response to the Application Session Establishment Request message 1201 being forwarded by AKMA authentication proxy 602, AF 222-1 sends an Application Session Establishment Response [receiving response information] message 1204 to UE 106 [receiving by the UE]”; [0056; Fig. 6B] the response is returned by the AKMA authentication proxy as “An AKMA authentication proxy ... resides ... between a UE 106 and a plurality of AFs 222” and so the service response necessarily is sent first to the Proxy to be returned to the UE) As per claim 16, Khare teaches a secure communication method, ([Khare, para. 0050] “AKMA (Authentication and Key Management for Application) is a feature that leverages an operator authentication infrastructure to secure communications between a UE 106 and an AF 222”) applied to a target application server, ([para. 0056] “AFs 222 may rely on AKMA authentication proxy 602 to execute AKMA authentication procedures”) wherein the method comprises: receiving a service request of a user equipment (UE) and an authentication result of the UE sent by an authentication and key management for applications (AKMA) authentication proxy, wherein the service request carries identification information of the target application server and an AKMA key identifier (A-KID) of the UE; and ([Khare, para. 0075] “the A-KID and the AF identity for AF 222-1 (e.g., AF1_ID) in the Application Session Establishment Request message 1201”; [para. 0079] “Proxy controller 904 forwards or redirects the Application Session Establishment Request message 1201 to AF 222-1 [receiving, by the AF, the service request of a user equipment] ... Proxy controller 904 includes the KAF key [and an authentication result of the UE] ... in the Application Session Establishment Request message 1201”) sending a service response of the service request to the UE through the AKMA authentication proxy according to the authentication result of the UE. ([Khare, para. 0079] “in response to the Application Session Establishment Request message 1201 being forwarded by AKMA authentication proxy 602 [according to the authentication result of the UE – see para. 0077: “verify whether the subscriber is authorized to use AKMA based on the presence of the UE-specific KAKMA key 704 identified by the A-KID ... derives the KAF keys based on the AF identities and the KAKMA key”], AF 222-1 sends an Application Session Establishment Response [sending a service response of the service request] message 1204 to UE 106 [sending to the UE]”; [0056; Fig. 6B] the response is returned through the AKMA authentication proxy as “An AKMA authentication proxy ... resides ... between a UE 106 and a plurality of AFs 222” and so the service response necessarily is sent first to the Proxy to be returned to the UE) As per claim 17, Khare teaches claim 16. Khare also teaches wherein sending the service response of the service request to the UE through the AKMA authentication proxy according to the authentication result of the UE comprises: ([Khare, para. 0079] “in response to the Application Session Establishment Request message 1201 being forwarded by AKMA authentication proxy 602, [according to the authentication result] AF 222-1 sends an Application Session Establishment Response message 1204 to UE”; [0056; Fig. 6B] the response is returned through the AKMA authentication proxy as “An AKMA authentication proxy ... resides ... between a UE 106 and a plurality of AFs 222” and so the service response necessarily is sent first to the Proxy to be returned to the UE) in response to the UE passing an authentication and authorization of the AKMA authentication proxy, returning the service response to the UE through the AKMA authentication proxy. ([Khare, para. 0077] “Proxy controller 904 sends an Nnef_AKMA_ApplicationKey_Get Request message 1206 [of the AKMA authentication proxy] ... verify whether the subscriber is authorized to use AKMA based on the presence of the UE-specific KAKMA key 704 identified by the A-KID [passing an authentication and authorization] ... derives the KAF key ... AF 222-1 based on the AF1_ID ... sends an ... Response message 1207 to AKMA authentication proxy 602”; [para. 0078-0079] “proxy controller 904 of AKMA authentication proxy 602 receives the key response message [in response to authorizing the UE passing an authentication and authorization of the AKMA authentication proxy] ... Proxy controller 904 forwards or redirects the Application Session Establishment Request message 1201 to AF 222-1... Proxy controller 904 includes the KAF key [and an authentication result of the UE] ... in the Application Session Establishment Request message 1201 ... in response to the Application Session Establishment Request message 1201 being forwarded by AKMA authentication proxy 602, [in response to the forwarding which is in response to the verification/passing an authentication and authorization] AF 222-1 sends an Application Session Establishment Response message 1204 to UE 106”) As per claim 18, Khare teaches claim 17. Khare also teaches wherein receiving the service request of the UE and the authentication result of the UE sent by the AKMA authentication proxy comprises: ([Khare, para. 0075] “the A-KID and the AF identity for AF 222-1 (e.g., AF1_ID) in the Application Session Establishment Request message 1201”; [para. 0079] “Proxy controller 904 forwards or redirects the Application Session Establishment Request message 1201 to AF 222-1 [receiving, by the AF, the service request of a user equipment] ... Proxy controller 904 includes the KAF key [and an authentication result of the UE] ... in the Application Session Establishment Request message 1201”) receiving the service request of the UE, the authentication result of the UE, and identity information of the UE sent by the AKMA authentication proxy. ([Khare, para. 0075] “the A-KID... in the Application Session Establishment Request message 1201”; [para. 0079] “Proxy controller 904 forwards or redirects the Application Session Establishment Request message 1201 to AF 222-1 [receiving the service request of the UE] ... Proxy controller 904 includes the KAF key [and an authentication result of the UE] ... SUPI [identity information of the UE – see para. 0044: “SUPI is a globally unique 5G identifier allocated to each subscriber”] ... in the Application Session Establishment Request message 1201”) As per claim 19, Khare teaches a secure communication apparatus, ([Khare, para. 0050] “AKMA (Authentication and Key Management for Application) is a feature that leverages an operator authentication infrastructure [apparatus] to secure communications between a UE 106 and an AF 222”) applied to an authentication and key management for applications (AKMA) authentication proxy, ([para. 0056] “an AKMA authentication proxy 602 ... to execute AKMA authentication procedures (e.g., key request procedure) on behalf of the AF(s) 222”) wherein the apparatus comprises: a transceiver; ([Khare, para. 0064] “AKMA authentication proxy 602 includes ... a network interface component ... hardware ... to exchange control plane messages or signaling with other network elements”) a memory; and ([Khare, para. 0064-0065] “AKMA authentication proxy 602 includes ... memory”) a processor, respectively connected to the transceiver and the memory, and configured to, by executing computer-executable instructions on the memory, control the transceiver to receive and send a wireless signal, and implement the secure communication method according to claim 1. ([Khare, para. 0065] “AKMA authentication proxy 602 includes... one or more processors 930 that execute instructions 934 (i.e., computer readable code) for software that are loaded into memory 932 ... A processor 930 comprises an integrated hardware circuit [connected to the transceiver and the memory] configured to execute instructions 934 to provide the functions of AKMA authentication proxy [control the transceiver to receive and send a wireless signal, and implement the secure communications method]”) As per claim 20, Khare teaches a secure communication apparatus, ([Khare, para. 0050] “AKMA (Authentication and Key Management for Application) is a feature that leverages an operator authentication infrastructure [apparatus] to secure communications between a UE 106 and an AF 222”) applied to a user equipment (UE), wherein the apparatus comprises: ([para. 0050] “AKMA reuses the 5G primary authentication procedure to authenticate a UE 106”) a transceiver; ([Khare, para. 0064] “AKMA authentication proxy 602 includes ... a network interface component ... hardware ... to exchange control plane messages or signaling with other network elements”) a memory; and ([Khare, para. 0064-0065] “AKMA authentication proxy 602 includes ... memory”) a processor, respectively connected to the transceiver and the memory, and configured to, by executing computer-executable instructions on the memory, control the transceiver to receive and send a wireless signal, and implement the secure communication method according to claim 12. ([Khare, para. 0065] “AKMA authentication proxy 602 includes... one or more processors 930 that execute instructions 934 (i.e., computer readable code) for software that are loaded into memory 932 ... A processor 930 comprises an integrated hardware circuit [connected to the transceiver and the memory] configured to execute instructions 934 to provide the functions of AKMA authentication proxy [control the transceiver to receive and send a wireless signal, and implement the secure communications method]”) As per claim 21, Khare teaches a secure communication apparatus, ([Khare, para. 0050] “AKMA (Authentication and Key Management for Application) is a feature that leverages an operator authentication infrastructure [apparatus] to secure communications between a UE 106 and an AF 222”) applied to a target application server, wherein the apparatus comprises: ([para. 0056] “AFs 222 may rely on AKMA authentication proxy 602 to execute AKMA authentication procedures”) a transceiver; ([Khare, para. 0064] “AKMA authentication proxy 602 includes ... a network interface component ... hardware ... to exchange control plane messages or signaling with other network elements”) a memory; and ([Khare, para. 0064-0065] “AKMA authentication proxy 602 includes ... memory”) a processor, respectively connected to the transceiver and the memory, and configured to, by executing computer-executable instructions on the memory, control the transceiver to receive and send a wireless signal, and implement the secure communication method according to claim 16. ([Khare, para. 0065] “AKMA authentication proxy 602 includes... one or more processors 930 that execute instructions 934 (i.e., computer readable code) for software that are loaded into memory 932 ... A processor 930 comprises an integrated hardware circuit [connected to the transceiver and the memory] configured to execute instructions 934 to provide the functions of AKMA authentication proxy [control the transceiver to receive and send a wireless signal, and implement the secure communications method]”) Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 2-5 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Khare as applied to claims 1 and 12 above and in view of Rajadurai et al. (US Pub. 2022/0116774) (hereinafter “Rajadurai”). As per claim 2, Khare teaches claim 1. Khare does not clearly teach wherein before receiving the service request of the target application server sent by the user equipment (UE), the method further comprises: receiving a session establishment request sent by the UE, wherein the session establishment request carries the A-KID of the UE; establishing a transport layer security protocol TLS connection with the UE according to the A-KID of the UE; wherein receiving the service request of the target application server sent by the UE comprises: receiving the service request sent by the UE through the established TLS connection. However, Rajadurai teaches wherein before receiving the service request of the target application server sent by the user equipment (UE), the method further comprises: ([Rajadurai, para. 0124] “the initial provisioning request [receiving the service request of the target application server sent by the user equipment] ... protected ... by the established TLS session [making establishing the TLS session steps performed before receiving the service request]”) receiving a session establishment request sent by the UE, wherein the session establishment request carries the A-KID of the UE; ([Rajadurai, para. 0112] “the UE 202 initiates the TLS session establishment with the ECS 208a by ... send the “Client Hello message” of the TLS protocol to the ECS 208a [receiving a session establishment request sent by the UE] ... The “Client Hello message” includes the AKMA ID, [A-KID of the UE] as to establish the PSK as part of the TLS session establishment procedure”) establishing a transport layer security protocol TLS connection with the UE according to the A-KID of the UE; ([Rajadurai, para. 0114-0115] “based on the AKMA Key ID ... establish the secure TLS session”) wherein receiving the service request of the target application server sent by the UE comprises: ([Rajadurai, para. 0124] “In steps 2I-2J ... UE 202 initiates the service provisioning procedure [receives the service request of the target application server] with the ECS 208a”) receiving the service request sent by the UE through the established TLS connection. ([Rajadurai, para. 0124] “The message exchange ... the initial provisioning request [receiving the service request] ... protected ... by the established TLS session”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Khare with the teachings of Rajadurai to include wherein before receiving the service request of the target application server sent by the user equipment (UE), the method further comprises: receiving a session establishment request sent by the UE, wherein the session establishment request carries the A-KID of the UE; establishing a transport layer security protocol TLS connection with the UE according to the A-KID of the UE; wherein receiving the service request of the target application server sent by the UE comprises: receiving the service request sent by the UE through the established TLS connection. One of ordinary skill in the art would have been motivated to make this modification because this enables an authentication of the UE prior to an actual communication between the UE and the ECS establish a secure session/connection between the UE and the ECS for accessing the edge computing services, based on a successful authentication and authorization of the UE and the ECS providing confidentiality, integrity, and replay protection. (Rajadurai, para. 0124; and para. 0163) As per claim 3, Khare teaches claim 1. Khare does not clearly teach wherein performing authentication and authorization on the UE according to the A-KID and the identification information of the target application server, and determining whether to authorize the UE to access the target application server, comprises: determining whether a transport layer security protocol (TLS) connection has been established with the UE according to the A-KID; in response to the TLS connection having been established with the UE, determining whether to authorize the UE to access the target application server according to a pre- configured policy of the AKMA authentication proxy and the identification information of the target application server. However, Rajadurai teaches wherein performing authentication and authorization on the UE ([Rajadurai, para. 0041] “Embodiments herein disclose ... establish a secure session/connection between the UE and the server for accessing edge computing services, authentication and authorization of the UE and the server”) according to the A-KID and the identification information of the target application server, and determining whether to authorize the UE to access the target application server, comprises: ([para. 0024] “The controller is configured to receive an application key identifier (key ID) [according to the A-ID] ... fetch an edge configuration server specific key (KECS) from ... use the edge configuration server specific key (KECS) as the PSK ... to enable performing of a mutual authentication between the UE and the server using the PSK [determining whether to authorize the UE to access the target application server], to establish a secure connection for the at least one edge computing service”; [para. 0059] “the UE 202 derives the edge configuration server specific key ... using ... AF_ID [according to the identification information of the target application server]”) determining whether a transport layer security protocol (TLS) connection has been established with the UE according to the A-KID; ([Rajadurai, para. 0082] “The EEC 310 [the UE: see Fig. 3] may also be configured to initiate the service provisioning procedure with the ECS 208a, on establishing the secure connection/TLS session with the ECS 208a ... In response to the initiated service provisioning procedure, [determining whether a TLS connection has been established with the UE according to the A-KID”) in response to the TLS connection having been established with the UE, determining whether to authorize the UE to access the target application server ([Rajadurai, para. 0082] “The EEC 310 [the UE: see Fig. 3] may also be configured to initiate the service provisioning procedure with the ECS 208a, on establishing the secure connection/TLS session with the ECS 208a ... In response to the initiated service provisioning procedure, [in response to the TLS connection having been established with the UE] the EEC 310 may receive the access token for the EES 208b from the ECS 208a, if the UE 202 is authorized to access the respective EES 208b [determining whether to authorize the UE to access the target application server]”) according to a pre- configured policy of the AKMA authentication proxy ([para. 0130] “the EEC 310 requests the ECS 208a [of the AKMA authentication proxy] for a new access token ... The access token ... includes necessary parameters [according to a pre-configured policy] to identify a security context of the EEC 310 and parameters for verification of the authenticity of the EEC 310/UE 202”; [para. 0152] the ECS is mapped to “the AKMA authentication proxy” as the ECS performs AKMA authentication on behalf of the application server: “The EAS 208c obtains the access token validation service from the ECS ... to validate the access token received from the application client 312 of the UE 202 ... After successful validation of the access token, [an authentication using AKMA – see para, 0042] the application client 312 obtains the edge computing service from the EAS”) and the identification information of the target application server. ([para. 0083] the access token is also identification information of the target application server as: “The EEC 310 ... using the received access token to discover [identify] the one or more EASs 208c [target application server]”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Khare and Rajadurai for the same reasons as disclosed above. As per claim 4, Khare in view of Rajadurai teaches claim 3. Khare also teaches wherein the service request carries the identification information of the target application server and the A-KID of the UE. ([Khare, para. 0075] “UE 106 sends an Application Session Establishment Request message 1201 [service request] to AKMA authentication proxy 602 ... UE 106 may be programmed with an Authentication Proxy (AP) identity (AP_ID) of AKMA authentication proxy 602, and sends the Application Session Establishment Request message 1201 to AKMA authentication proxy 602 ... UE 106 includes the A-KID [carries A-KID] and the AF identity [caries identification information] for AF 222-1 [of a target application server] (e.g., AF1_ID) in the Application Session Establishment Request message 1201”) Khare does not clearly teach wherein performing authentication and authorization on the UE according to the A-KID and the identification information of the target application server, and determining whether to authorize the UE to access the target application server, further comprises: in response to the TLS connection having not been established with the UE, establishing the TLS connection with the UE according to the A-KID, and requesting the UE to send a service request of the target application server after the TLS connection is established. However, Rajadurai teaches wherein performing authentication and authorization on the UE ([Rajadurai, para. 0041] “Embodiments herein disclose ... establish a secure session/connection between the UE and the server for accessing edge computing services, authentication and authorization of the UE and the server”) according to the A-KID and the identification information of the target application server, and determining whether to authorize the UE to access the target application server, further comprises: ([para. 0024] “The controller is configured to receive an application key identifier (key ID) [according to the A-ID] ... fetch an edge configuration server specific key (KECS) from ... use the edge configuration server specific key (KECS) as the PSK ... to enable performing of a mutual authentication between the UE and the server using the PSK [determining whether to authorize the UE to access the target application server], to establish a secure connection for the at least one edge computing service”; [para. 0059] “the UE 202 derives the edge configuration server specific key ... using ... AF_ID [according to the identification information of the target application server]”) in response to the TLS connection having not been established with the UE, establishing the TLS connection with the UE according to the A-KID, ([Rajadurai, para. 0111] “If there is no valid TLS session available with the ECS 208a, [in response to the TLS connection having not been established with the UE] then the steps ... performed to establish the secure TLS session between the UE 202 and the ECS 208a using the PSK based authentication ... In accordance with the PSK based authentication, the PSK may be established between the ECS 208a and the EEC 310 of the UE 202 using the AKMA procedure [according to the A-KID – see para. 0024 as per above]”) and requesting the UE to send a service request of the target application server after the TLS connection is established. ([Para. 0082] “initiate the service provisioning procedure with the ECS 208a, on establishing the secure connection/TLS session with the ECS 208”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Khare and Rajadurai for the same reasons as disclosed above. As per claim 5, Khare in view of Rajadurai teaches claim 2. Khare does not clearly teach wherein establishing the TLS connection with the UE according to the A-KID comprises: sending an AKMA application key request to an AKMA anchor function (AAnF), wherein the key request carries the A-KID and an application function identification of the AKMA authentication proxy, and the application function identification of the AKMA authentication proxy comprises: a fully qualified domain name (FQDN), and a Ua* security protocol identifier; receiving a first key KAF returned by the AAnF according to the A-KID and the application function identification of the AKMA authentication proxy; performing a mutual authentication with the UE and establishing the TLS connection with the UE based on the first key KAF and a second key KAF on the UE side. However, Rajadurai teaches wherein establishing the TLS connection with the UE according to the A-KID comprises: ([Rajadurai, para. 0105] “the UE 202 and the server/ECS 208a use the TLS with PSK-based authentication for securing the connection to access the edge computing services, where details of the application key ID/AKMA key identity is carried by the TLS protocol messages to establish the PSK during the TLS session establishment procedure”) sending an AKMA application key request to an AKMA anchor function (AAnF), ([Rajadurai, para. 0112] “UE 202 initiates the TLS session establishment with the ECS 208a by enabling the EEC 310 to send the “Client Hello message” of the TLS protocol to the ECS 208a ...The “Client Hello message” includes the AKMA ID, as to establish the PSK as part of the TLS session establishment procedure”; [para. 0065] “On receiving the application key ID from the UE 202 ... the ECS 208a sends a key request [AKMA application key request] ... to the AAnF”) wherein the key request carries the A-KID and an application function identification of the AKMA authentication proxy, and ([Rajadurai, para. 0065] “a key request including the received application key ID ... to identify an application security context [an application function identification as it is used to identify the application function] ... for fetching [identifying] the edge configuration server [application function – see para. 0053]”) the application function identification of the AKMA authentication proxy comprises: a fully qualified domain name (FQDN), and a Ua* security protocol identifier; ([para. 0060] “AF_ID=FQDN of AF∥Ua* security protocol identifier”) receiving a first key KAF returned by the AAnF according to the A-KID and the application function identification of the AKMA authentication proxy; ([Rajadurai, para. 0065] “the ECS 208a sends a key request including the received application key ID to the AAnF 206 to identify an application security context in the AAnF 206 for fetching the edge configuration server specific key ... The AAnF 206 sends the derived edge configuration server specific key (KECS) to the ECS 208a [receiving a first KAF – see para. 0062]”) performing a mutual authentication with the UE and establishing the TLS connection with the UE based on the first key KAF and a second key KAF on the UE side. ([Rajadurai, para. 0065] “Once the edge configuration server specific key ... is available at the UE 202 [second key KAF] and the ECS 208a, [second key KAF] the UE 202 and the ECS 208a derive the PSK ... On deriving the PSK, the UE 202 and the ECS 208a perform the mutual authentication using the PSK to establish the secure connection/secure channel [establishing the TLS connection] for accessing the edge computing services”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Khare and Rajadurai for the same reasons as disclosed above. As per claim 13, Khare teaches claim 12. Khare also teaches wherein before sending the service request of the target application server to the AKMA authentication proxy, the method further comprises: ([Khare, para. 0074; Fig. 12A] “A pre-requisite [to sending the service request – see Figure] is that primary authentication is successful and establishment of KAKMA is performed) obtaining an AKMA anchor key KAKMA and the A-KID based on a key KAUSF of an authentication service function (AUSF) network element; ([Khare, para. 0053] “generates the KAKMA key and the A-KID from the KAUSF key”) wherein KAKMA is used to obtain a key KAF in combination with the identification information of the target application server. ([Khare, para. 0058] “The KAF key 708 is derived from a KDF 800 using the KAKMA key 704 as an input key ... The input parameter ... is an address or identity (e.g., AF_ID 802) of an AF 222”) Khare does not clearly teach the key KAF is used to establish a transport layer security protocol (TLS) connection with the AKMA authentication proxy. However, Rajadurai teaches the key KAF is used to establish a transport layer security protocol (TLS) connection with the AKMA authentication proxy. ([Rajadurai, para. 0079] “derives the PSK based on the edge configuration server specific key (KECS) [the KAF – see para.0062]”; [para. 0081] “The EEC 310 authenticates the ECS 208a based on the received PSK from the ECS 208a ... The PSK sent by the EEC 310 may be used by the ECS 208a to authenticate the EEC 310 ... Once the EEC 310 and the ECS 208a have been authenticated and authorized successfully [key KAF is used], the secure connection/TLS session may be established between the EEC 310/UE 202 and the ECS 208a”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Khare and Rajadurai for the same reasons as disclosed above. Claims 6 is rejected under 35 U.S.C. 103 as being unpatentable over Khare as applied to claim 1 above, and further in view of Laitinen et al. (2011/0289315) (hereinafter “Laitinen”). As per claim 6, Khare teaches claim 1. Khare does not clearly teach wherein the identification information of the target application server at least comprises: a FQDN, a Ua* security protocol identifier, an IP address, and a port number. However, Laitinen teaches wherein the identification information of the target application server at least comprises: a FQDN, a Ua* security protocol identifier, an IP address, and a port number. ([Laitinen, para. 0141; para. 0144] “An example of the extended NAF_ID [identification information of the target application server] format is ... [protocol]FQDN[port][service] [UaSecProtED]”; [para. 0092] “FQDN ... provides enough information so that it can be converted into a physical IP address”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Khare with the teachings of Laitinen to include wherein the identification information of the target application server at least comprises: a FQDN, a Ua* security protocol identifier, an IP address, and a port number. One of ordinary skill in the art would have been motivated to make this modification because this approach provides sufficient granularity when constructing the identifier and enables having different keys for different services. (Laitinen, para. 0094) Claims 8-9 are rejected under 35 U.S.C. 103 as being unpatentable over Khare as applied to claim 1 above, and further in view of Guo et al. (US Pub. 2025/0267455) (hereinafter “Guo”) and Kolekar et al. (US Pub. 2022/033022) (hereinafter “Kolekar”) As per claim 8, Khare teaches claim 1. Khare does not clearly teach wherein in response to authorizing the UE to access the target application server, forwarding the service request and the authentication result of the UE to the target application server, comprises: determining whether the target application server has an authorization and needs to obtain identity information of the UE based on a pre-configured policy of the AKMA authentication proxy; in response to the target application server having the authorization and needing to obtain the identity information of the UE, sending the identity information of the UE, the service request and the authentication result of the UE to the target application server; in response to the target application server having no authorization or not needing to obtain the identity information of the UE, sending the service request and the authentication result of the UE to the target application server. However, Guo teaches wherein in response to authorizing the UE to access the target application server, ([Guo, para. 0102] “In generic bootstrapping architecture ... the AP ... handle the TLS security relation with the UE ... to assure the ASs that a request is coming from an authorized subscriber”) forwarding the service request ([para. 0113] “the AP ... forward to the AS(s) all the authentication results”) and the authentication result of the UE to the target application server, comprises: ([para. 0110] “the AP forwards the request from the UE to the AS”) determining whether the target application server has an authorization and needs to obtain identity information of the UE based on a pre-configured policy of the AKMA authentication proxy; ([Guo, para. 0098] “the AP may determine whether to establish a new TLS tunnel [determining whether the target application server has an authorization and needs to obtain identity information of the UE] for the application session based at least in part on local AP policy [based on a pre-configured policy of the AKMA authentication proxy]”; [para. 0110] establishing a new TLS tunnel indicates the AS does not have authorization and needs to obtain identity information of the UE as “The AP ... add an assertion of [authorization] identity of the subscriber [identity information] for use by [needed by] the AS, when the AP forwards the request from the UE to the AS”) in response to the target application server having the authorization and needing to obtain the identity information of the UE, sending the identity information of the UE, the service request and the authentication result of the UE to the target application server. ([Guo, para. 0113] “after successful authentication, [in response to the target application server having the authorization and needing to obtain the identity information of the UE] AP may pass the authentication result for a specific UE ID to the AS(s) [sending the authentication result of the UE] ... the AP could forward to the AS(s) all the authentication results based on UE service request(s) [sending the service request] ... The format could include the UE ID information [sending the identity information of the UE]”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Khare with the teachings of Guo to include wherein in response to authorizing the UE to access the target application server, forwarding the service request and the authentication result of the UE to the target application server, comprises: determining whether the target application server has an authorization and needs to obtain identity information of the UE based on a pre-configured policy of the AKMA authentication proxy; in response to the target application server having the authorization and needing to obtain the identity information of the UE, sending the identity information of the UE, the service request and the authentication result of the UE to the target application server. One of ordinary skill in the art would have been motivated to make this modification because such a framework may be used to reduce the consumption of authentication vectors, to reduce the likelihood of sequence number synchronization failures, and/or to relieve application servers of at least some security tasks. (Guo, para. 0105) Khare in view of Rajadurai does not clearly teach in response to the target application server having no authorization or not needing to obtain the identity information of the UE, sending the service request and the authentication result of the UE to the target application server. However, Kolekar teaches in response to the target application server having no authorization or not needing to obtain the identity information of the UE, ([Kolekar, para. 0079] “During the registration procedure, the UE may provide device-specific information, e.g., the default UE credential and corresponding identity (encoded in SUPI format) to the network ... A primary authentication ... performed ... SUPI may be of the type of NAI in the form of username@realm ... The “username” may be either “anonymous” or the UE identity can be omitted”) sending the service request ([para. 0255] “sends the Registration Request message [the service request] to the SEAF [target application server]”) and the authentication result of the UE to the target application server. ([Para. 0257] “sends an EAP-Success message to the SEAF”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Khare in view of Guo with the teachings of Kolekar to in response to the target application server having no authorization or not needing to obtain the identity information of the UE, sending the service request and the authentication result of the UE to the target application server. One of ordinary skill in the art would have been motivated to make this modification because this modification allows for a secure mechanism for provisioning on-demand connectivity for non-public networks. (Kolekar, para. 0067) As per claim 9, Khare in view of Guo and Kolekar teaches claim 8. Khare also teaches wherein after sending the identity information of the UE, the service request and the authentication result of the UE to the target application server, the method further comprises: ([Khare, para. 0079] “Proxy controller 904 forwards or redirects the Application Session Establishment Request message 1201 to AF 222-1 [sending the service request] ... Proxy controller 904 includes the KAF key [and an authentication result of the UE} ... in the Application Session Establishment Request message 1201”) sending corresponding authorization information and service response to the UE through service response information returned by the target application server. ([Para. 0079] “in response to the Application Session Establishment Request message 1201 being forwarded by AKMA authentication proxy 602, [after sending the service request and the authentication request] AF 222-1 sends an Application Session Establishment Response message 1204 to UE 106 [sending corresponding authorization information and service response of the target application server to the UE]”; [0056; Fig. 6B] the response is sent by the proxy as “An AKMA authentication proxy ... resides ... between a UE 106 and a plurality of AFs 222” and so the service response necessarily is sent first to the Proxy to be sent to the UE; [para. 0085; Fig. 15] the Application Session Establishment Response message is “authorization information” as the response is a precursor to the UE using the AF identity to encrypt communications with the AF) Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Khare in view of Guo and Kolekar as applied to claim 8 above, and further in view of Wang et al. (US Pub. 2024/0276217) (hereinafter “Wang”). As per claim 10, Khare in view of Guo and Kolekar teaches claim 8. Khare in view of Guo and Kolekar does not clearly teach wherein in response to the target application server having the authorization and needing to obtain the identity information of the UE, sending the identity information of the UE, the service request and the authentication result of the UE to the target application server, comprises: in response to the target application server not being within a 3GPP operator domain, sending a generic public subscription identifier (GPSI) of the UE to the target application server. However, Wang teaches wherein in response to the target application server having the authorization and needing to obtain the identity information of the UE, sending the identity information of the UE, the service request and the authentication result of the UE to the target application server, comprises: ([Wang, para. 0160] “the NF [target application server] ... determine whether the AF is authorized to obtain the corresponding second identifier (GPSI*) [having the authorization and needing to obtain the identity information of the US] based on the information descriptive of the one or more applications ... the corresponding second identifier (GPSI*) is sent to the AF in an AKMA response message [sending the identity information of the UE/service request as the request includes the identifier] together with an application-specific key (KAF) associated with the UE and the AF, [authentication result of the UE to the application server] based on a determination that the AF is authorized) in response to the target application server not being within a 3GPP operator domain, sending a generic public subscription identifier (GPSI) of the UE to the target application server. ([Wang, para. 0129-0133] “if the AF is external to the 3GPP network ... sends ... GPSI* obtained ... to the AF) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Khare in view of Guo and Kolekar with the teachings of Wang to include wherein in response to the target application server having the authorization and needing to obtain the identity information of the UE, sending the identity information of the UE, the service request and the authentication result of the UE to the target application server, comprises: in response to the target application server not being within a 3GPP operator domain, sending a generic public subscription identifier (GPSI) of the UE to the target application server. One of ordinary skill in the art would have been motivated to make this modification because the modification allows facilitating use of application-specific GPSIs for authentication, which is consistent with the needs associated with the increased use of a variety of Edge Computing (EC) applications with 3GPP networks. (Wang, para. 0037) Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Khare as applied to claim 1 above, and further in view of Salmela et al. (US Pub. 2016/0119343) (hereinafter “Salmela”). As per claim 11, Khare teaches claim 1. Khare also teaches the application function identification comprises: a FQDN and a Ua* security protocol identifier corresponding to an application function. ([Khare, para. 0062] “The AF_ID is constructed as: AF_ID=FQDN of the AF∥Ua* security protocol identifier”) Khare does not clearly teach wherein the AKMA authentication proxy and the target application server have a same application function identification. However, Salmela teaches wherein the AKMA authentication proxy and the target application server have a same application function identification. ([Salmela, para. 0100] “a generate new IPv6 (Internet Protocol version 6) address step 33, in which a new IPv6 address ... is generated ... When the gateway is an explicit proxy, the IPv6 address can be for the ... gateway”; [para. 0104] “the gateway acts as a proxy ... between the client device and the application server ... During this operation as a proxy, the new IPv6 address is used for identification of, and routing to, the application server”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Khare with the teachings of Salmela to include wherein the AKMA authentication proxy and the target application server have a same application function identification. One of ordinary skill in the art would have been motivated to make this modification because in this way, end-to-end security between devices and the application server is achieved, where each client device connection is protected from other connections using the same gateway, even if communicating with the same application server. (Salmela, para. 0138) Claim 14 is rejected under 35 U.S.C. 103 as being unpatentable over Khare as applied to claim 12 above, and further in view of Salmela and Laitinen. As per claim 14, Khare teaches claim 12. Khare also teaches wherein sending the service request of the target application server to the AKMA authentication proxy comprises: obtaining an address of the AKMA authentication proxy ([Khare, para. 0075] “UE 106 sends an Application Session Establishment Request message 1201 [service request] to AKMA authentication proxy 602 ... UE 106 may be programmed [obtaining with an Authentication Proxy (AP) identity (AP_ID) of AKMA authentication proxy 602 [an address of the AKMA authentication proxy]”) and/or, wherein receiving the response information returned by the AKMA authentication proxy comprises: receiving error code information sent by the AKMA authentication proxy or a service response returned by the target application server. (Examiner interprets BRI of this limitation to be optional and non-limiting in accordance with the and/or language and as the other limitation is disclosed by Khare in view of Salmela and Laitinen) Khare does not clearly teach obtaining an address of the AKMA authentication proxy through the identification information of the target application server. However, Salmela teaches obtaining an address of the AKMA authentication proxy through the identification information of the target application server. ([Salmela, para. 0100] “a generate new IPv6 (Internet Protocol version 6) address step 33, in which a new IPv6 address [obtaining an address of the authentication proxy] ... is generated ... When the gateway is an explicit proxy, the IPv6 address can be for the ... gateway”; [para. 0104] “the gateway acts as a proxy ... between the client device and the application server ... During this operation as a proxy, the new IPv6 address is used for identification of, and routing to, the application server [through the identification information of the target application server]”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Khare and Salmela for the same reasons as disclosed above. Khare in view of Salmela does not clearly teach wherein the identification information of the target application server at least comprises: a fully qualified domain name (FQDN), a Ua* security protocol identifier, an IP address, and a port number of the target application server. However, Laitinen teaches wherein the identification information of the target application server at least comprises: a fully qualified domain name (FQDN), a Ua* security protocol identifier, an IP address, and a port number of the target application server. ([Laitinen, para. 0141; para. 0144] “An example of the extended NAF_ID [identification information of the target application server] format is ... [protocol]FQDN[port][service] [UaSecProtED]”; [para. 0092] “FQDN ... provides enough information so that it can be converted into a physical IP address”) It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Khare, Salmela and Laitinen for the same reasons as disclosed above. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Peng et al. (US Pub. 2013/0121252) discloses proxy server where an application identifier to a push application server where the application identifier is an identifier of a proxy service. Khare et al. (US Pub. 2023/0413045) discloses application servers may rely on an authentication proxy to execute AKMA procedures which is more cost efficient than executing AKMA procedures separately. Rajadurai et al. (US Pub. 2023/0070253) discloses ECS and EES act as proxies for the UE and an EAS when authenticating the UE during 3GPP AKMA operations. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZHE LIU whose telephone number is (571) 272-3634. The examiner can normally be reached on Monday - Friday: 8:30 AM to 5:30 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached on (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at (866) 217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call (800) 786-9199 (IN USA OR CANADA) or (571) 272-1000. /ZHE LIU/Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Dec 12, 2024
Application Filed
Jul 22, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705357
CONTROL APPARATUS
3y 1m to grant Granted Aug 11, 2026
Patent 12682091
CLASSIFIER AND CLASSIFIER BEHAVIOR MANAGER FOR DATA MANAGEMENT USING CONTENT-BASED DATASETS
3y 8m to grant Granted Jul 14, 2026
Patent 12682066
METHOD OF SPEEDING UP SECURE BOOT PROCESS AND ELECTRONIC DEVICE USING THE SAME
3y 1m to grant Granted Jul 14, 2026
Patent 12664269
Detecting and Protecting Against Cybersecurity Attacks Using Unprintable Tracking Characters
2y 3m to grant Granted Jun 23, 2026
Patent 12657302
LATENT-CONTEXT ALERT CORRELATION ENGINE IN A SECURITY MANAGEMENT SYSTEM
3y 3m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
72%
Grant Probability
99%
With Interview (+58.4%)
2y 12m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 150 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month