DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Examiner acknowledges the following data:
Parent data
18899050 filed 09/27/2024 is a Continuation of PCT/CN2022/103475, filed 07/01/2022.
Information Disclosure statements
The information disclosure statements (IDS) were submitted and filed on 09/27/2024 and 07/10/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Griot et al (US 2016/0088515) in view of Takahashi (US 2017/0118180).
Regarding claim 1, Griot et al discloses wireless communication method comprising (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3):
receiving, by a wireless communication terminal from a wireless communication node, a broadcast signal (Access terminal (AT) 116 (wireless communication terminal) may be in communication with antennas 112 and 114, where antennas 112 and 114 transmit information to AT 116 (wireless communication terminal) over forward link 120 and receive information from AT 116 over reverse link 118. In a FDD (Frequency Division Duplex) system, communication links 118, 120, 124, and 126 may use different frequencies (broadcast signal) for communication. For example, forward link 120 may use a different frequency (broadcast signal) than that used by reverse link 118, [0046], lines 4-9); and
transmitting, by the wireless communication terminal to the wireless communication node, a secure data packet with an encryption based on at least one of: the broadcast signal (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4).
Griot et al does not specifically disclose concept of secure data packet with an encryption based on at least one locally-stored information.
However, Takahashi specifically teaches concept of secure data packet with an encryption based on at least one locally-stored information (For plaintext to ciphertext data, the storage destination location and encryption key associated with the data are verified against the security level of the physical network from which the packet was sent. For ciphertext to plaintext data, the storage area and decrypt key associated with the data are verified against the security level of the physical network the data is destined for, [0154], lines 1-4).
At the time the invention was filed, it would have been obvious for one of ordinary skill in the art to have modified system of Griot et al with concept of secure data packet with an encryption based on at least one locally-stored information of Takahashi. One of ordinary skill in the art would have been motivated to make this modification in order to improve security processing (e.g., in a multi-tenancy or other architecture), (Takahashi, [0005], line 1).
Regarding claim 2, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the locally-stored information comprises at least one of (The controller/processor 304 may be configured to access instructions stored in the memory 306 to perform the procedures for secure connectionless uplink data transmission, in accordance with certain aspects of the present disclosure discussed below, [0067], lines 2-4):
information stored in universal subscriber identity module (USIM), a transmission session count maintained by both the wireless communication terminal and a core network, or information that the wireless communication terminal is able to obtain in an idle or inactive state (certain types of devices, such as machine-type communications (MTC) devices and enhanced MTC (eMTC) devices, etc., may be expected to be in a low power state (e.g., an idle state) for most of the time. However, in general, each time a mobile terminated (MT) or mobile originated (MO) data connection is required, the device transitions from the idle state to a connected state, [0069], lines 1-4).
Regarding claim 3, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the broadcast signal comprises at least one of: a synchronization signal, a resource allocation indication, a paging message, or connectionless security parameters (The instructions in the memory 306 may be executable to implement the methods described herein, for example, to allow a UE to securely transmit data during an uplink connectionless transmission, [0064], lines 6-8).
Regarding claim 4, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the secure data packet comprises at least one of (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4):
an identifier of the wireless communication terminal, a ciphertext, a Message Authentication Code (MAC) of the ciphertext, a public key of the wireless communication terminal, a Subscription Concealed Identifier (SUCI), an SUCI-MAC, or a home network (HN) public key indicator (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10);
wherein the identifier of the wireless communication terminal comprises at least one of (one or more ATs 116, 122, 130 and AP(s) 100 may communicate with the core network (not shown). The AP 100 may be connected by an S1 interface to the core network (not shown). The core network may include a Mobility Management Entity (MME) (e.g., as illustrated in FIGS. 8-9), a Home Subscriber Server (HSS) (not shown), [0050], lines 1-3):
a Subscription Permanent Identifier (SUPI), a SUCI, a value of ng-5G-S-TMSI-Part1, a random number, or a value of resume Identity (At 406, the UE may send MSG 3 using the grant. At 408, the eNB may decode MSG 3 and either echo back the RRC (Radio Resource Control) signaling message or send an UL grant (e.g., DCI 0) scrambled with a cell radio network temporary identifier (C-RNTI), [0068], lines 5-7).
Regarding claim 5, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the secure data packet has an integrity protection based on at least one of (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4):
the broadcast signal (The instructions in the memory 306 may be executable to implement the methods described herein, for example, to allow a UE to securely transmit data during an uplink connectionless transmission, [0064], lines 6-8);
wherein at least one of an encryption key for an encryption of a ciphertext or an integrity protection key for a MAC of the ciphertext is derived based on a long-term key and connectionless security parameters (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10).
Griot et al does not specifically disclose concept of secure data packet with an encryption based on at least one locally-stored information.
However, Takahashi specifically teaches concept of secure data packet with an encryption based on at least one locally-stored information (For plaintext to ciphertext data, the storage destination location and encryption key associated with the data are verified against the security level of the physical network from which the packet was sent. For ciphertext to plaintext data, the storage area and decrypt key associated with the data are verified against the security level of the physical network the data is destined for, [0154], lines 1-4).
At the time the invention was filed, it would have been obvious for one of ordinary skill in the art to have modified system of Griot et al with concept of secure data packet with an encryption based on at least one locally-stored information of Takahashi. One of ordinary skill in the art would have been motivated to make this modification in order to improve security processing (e.g., in a multi-tenancy or other architecture), (Takahashi, [0005], line 1).
Regarding claim 6, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein a shared key is generated based on a public key of the wireless communication terminal, a private key of the wireless communication terminal, and an HN public key, and wherein at least one of an encryption key for an encryption of a ciphertext or an integrity protection key for a MAC of the ciphertext is derived based on the shared key (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10).
Regarding claim 7, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein a ciphertext in the secure data packet is encrypted based on an HN public key (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4);
wherein a pair of public key and private key of the wireless communication terminal are generated for an encryption of a ciphertext (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10);
wherein the wireless communication terminal receives a positive or negative acknowledgement indicating whether the secure data packet is demodulated successfully (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4);
wherein the secure data packet is transmitted via backscattering an excitation signal (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4).
Regarding claim 8, Griot et al discloses wireless communication method comprising (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3):
transmitting, by a wireless communication node to a wireless communication terminal, a broadcast signal (Access terminal (AT) 116 (wireless communication terminal) may be in communication with antennas 112 and 114, where antennas 112 and 114 transmit information to AT 116 (wireless communication terminal) over forward link 120 and receive information from AT 116 over reverse link 118. In a FDD (Frequency Division Duplex) system, communication links 118, 120, 124, and 126 may use different frequencies (broadcast signal) for communication. For example, forward link 120 may use a different frequency (broadcast signal) than that used by reverse link 118, [0046], lines 4-9); and
receiving, by the wireless communication node from the wireless communication terminal, a secure data packet with an encryption based on at least one of: the broadcast signal (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4).
Griot et al does not specifically disclose concept of secure data packet with an encryption based on at least one locally-stored information.
However, Takahashi specifically teaches concept of secure data packet with an encryption based on at least one locally-stored information (For plaintext to ciphertext data, the storage destination location and encryption key associated with the data are verified against the security level of the physical network from which the packet was sent. For ciphertext to plaintext data, the storage area and decrypt key associated with the data are verified against the security level of the physical network the data is destined for, [0154], lines 1-4).
At the time the invention was filed, it would have been obvious for one of ordinary skill in the art to have modified system of Griot et al with concept of secure data packet with an encryption based on at least one locally-stored information of Takahashi. One of ordinary skill in the art would have been motivated to make this modification in order to improve security processing (e.g., in a multi-tenancy or other architecture), (Takahashi, [0005], line 1).
Regarding claim 9, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the wireless communication node transmits to a core network node at least one of an identifier of the wireless communication terminal, connectionless security parameters, the secure data packet, a public key of the wireless communication terminal, a Subscription Concealed Identifier (SUCI), or an Subscription Concealed Identifier Message Authentication Code (SUCI-MAC) (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10).
Regarding claim 10, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the wireless communication node receives from a core network node at least one of (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10):
an encryption key for an encryption of a ciphertext, an integrity protection key for an MAC of the ciphertext, a Subscription Permanent Identifier (SUPI), a plaintext decrypted from the ciphertext, or a positive or negative acknowledgement indicating whether the secure data packet is demodulated successfully (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4).
Regarding claim 11, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the wireless communication node receives connectionless security parameters from the core network node (The instructions in the memory 306 may be executable to implement the methods described herein, for example, to allow a UE to securely transmit data during an uplink connectionless transmission, [0064], lines 6-8);
wherein an encryption key received from a core network node is used to decrypt a ciphertext received from the wireless communication terminal (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10);
wherein an integrity protection key received from a core network node is used to generate an MAC for an integration check of a ciphertext received from the wireless communication terminal (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10).
Regarding claim 12, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the wireless communication node transmits a positive or negative acknowledgement indicating whether the secure data packet is demodulated successfully to the wireless communication terminal in response to receiving another positive or negative acknowledgement from a core network node, receiving a plaintext of a ciphertext of the secure data packet, or the ciphertext of the secure data packet being demodulated successfully based on an encryption key received from a core network node (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4).
Regarding claim 13, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the broadcast signal comprises at least one of (The instructions in the memory 306 may be executable to implement the methods described herein, for example, to allow a UE to securely transmit data during an uplink connectionless transmission, [0064], lines 6-8):
a synchronization signal, a resource allocation indication, a paging message, or connectionless security parameters (The instructions in the memory 306 may be executable to implement the methods described herein, for example, to allow a UE to securely transmit data during an uplink connectionless transmission, [0064], lines 6-8).
Regarding claim 14, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the secure data packet comprises at least one of: an identifier of the wireless communication terminal, a ciphertext, a Message Authentication Code (MAC) of the ciphertext, a public key of the wireless communication terminal, a Subscription Concealed Identifier (SUCI), an SUCI-MAC, or a home network (HN) public key indicator (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4);
wherein the identifier of the wireless communication terminal comprises at least one of (one or more ATs 116, 122, 130 and AP(s) 100 may communicate with the core network (not shown). The AP 100 may be connected by an S1 interface to the core network (not shown). The core network may include a Mobility Management Entity (MME) (e.g., as illustrated in FIGS. 8-9), a Home Subscriber Server (HSS) (not shown), [0050], lines 1-3):
a Subscription Permanent Identifier (SUPI), a SUCI, a value of ng-5G-S-TMSI-Part1, a random number, or a value of resume Identity (At 406, the UE may send MSG 3 using the grant. At 408, the eNB may decode MSG 3 and either echo back the RRC (Radio Resource Control) signaling message or send an UL grant (e.g., DCI 0) scrambled with a cell radio network temporary identifier (C-RNTI), [0068], lines 5-7)..
Regarding claim 15, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the secure data packet has an integrity protection based on at least one of (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4):
the broadcast signal (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4).
Griot et al does not specifically disclose concept of secure data packet with an encryption based on at least one locally-stored information.
However, Takahashi specifically teaches concept of secure data packet with an encryption based on at least one locally-stored information (For plaintext to ciphertext data, the storage destination location and encryption key associated with the data are verified against the security level of the physical network from which the packet was sent. For ciphertext to plaintext data, the storage area and decrypt key associated with the data are verified against the security level of the physical network the data is destined for, [0154], lines 1-4).
At the time the invention was filed, it would have been obvious for one of ordinary skill in the art to have modified system of Griot et al with concept of secure data packet with an encryption based on at least one locally-stored information of Takahashi. One of ordinary skill in the art would have been motivated to make this modification in order to improve security processing (e.g., in a multi-tenancy or other architecture), (Takahashi, [0005], line 1).
Regarding claim 16, Griot et al discloses wireless communication method comprising (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3):
transmitting, by a core network node to a wireless communication node, information for a decryption of a secure data packet, wherein the secure data packet comprises a ciphertext encrypted based on at least one of: the broadcast signal (At 602, the BS (wireless communication node) receives a packet comprising encrypted data (secure data packet) from a user equipment (UE) that has not established a full radio resource control (RRC) connection. At 604, the BS communicates (broadcast signal) with a network entity to perform authentication of the UE. At 606, the BS (wireless communication node) receives, from the network entity (core network node), decryption information for decrypting the encrypted data after the network entity authenticates the UE. At 608, the BS (wireless communication node) uses the decryption information to decrypt the encrypted data, [0079], lines 1-4), and
wherein the information comprises at least one of: an encryption key for an encryption of the ciphertext or an integrity protection key for a Message Authentication Code (MAC) of a ciphertext, a Subscription Permanent Identifier (SUPI), a plaintext decrypted from the ciphertext by the wireless communication terminal, or a positive or negative acknowledgement indicating whether the secure data packet is demodulated successfully (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.) (encryption key for an encryption of the ciphertext), [0085], lines 7-8).
Griot et al does not specifically disclose concept of secure data packet comprises a ciphertext encrypted based on at least one locally-stored information.
However, Takahashi specifically teaches concept of secure data packet comprises a ciphertext encrypted based on at least one locally-stored information (For plaintext to ciphertext data, the storage destination location and encryption key associated with the data are verified against the security level of the physical network from which the packet was sent. For ciphertext to plaintext data, the storage area and decrypt key associated with the data are verified against the security level of the physical network the data is destined for, [0154], lines 1-4).
At the time the invention was filed, it would have been obvious for one of ordinary skill in the art to have modified system of Griot et al with concept of secure data packet comprises a ciphertext encrypted based on at least one locally-stored information of Takahashi. One of ordinary skill in the art would have been motivated to make this modification in order to improve security processing (e.g., in a multi-tenancy or other architecture), (Takahashi, [0005], line 1)
Regarding claim 17, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the core network node receives at least one of an identifier of the wireless communication terminal, connectionless security parameters, the secure data packet, a public key of the wireless communication terminal, a Subscription Concealed Identifier (SUCI), or an SUCI-MAC (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10).
Regarding claim 18, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the core network node derives at least one of (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10):
the encryption key for the encryption of the ciphertext or the integrity protection key for the MAC of the ciphertext according to a long-term key and connectionless security parameters (The instructions in the memory 306 may be executable to implement the methods described herein, for example, to allow a UE to securely transmit data during an uplink connectionless transmission, [0064], lines 6-8).
Regarding claim 19, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the core network node derives a shared key according to a home network (HN) public key, a HN private key, and a public key of the wireless communication terminal, and wherein the shared key is used to derive at least one of the encryption key for the encryption of the ciphertext or the integrity protection key for the MAC of the ciphertext (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10);
wherein the shared key is used to derive keys to check an integrity of a SUCI and to decrypt the SUCI (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10).
Regarding claim 20, Griot et al discloses wireless communication method (FIG. 3 illustrates various components that may be utilized in a wireless device 302 that may be employed within the wireless communication system illustrated in FIG. 1. The wireless device 302 is an example of a device that may be configured to implement the various methods described herein, [0063], lines 1-3), wherein the core network node decrypts the ciphertext according to an HN private key (The indicated encryption mechanism may be information related to one of the encryption mechanisms supported by the UE 802 and listed in the request (e.g., an initial sequence number, keys, etc.). In some cases, however, the connectionless setup response may indicate an encryption mechanism other than one listed by the UE in the request, [0085], lines 7-10).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FRANTZ BATAILLE whose telephone number is (571)270-7286. The examiner can normally be reached Monday-Friday 9:00 AM-5:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Akwasi Sarpong can be reached on 571-270-3438. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/FRANTZ BATAILLE/ Primary Examiner, Art Unit 2681