DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim(s) 1-20 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Munshi et al. (Pub. No. US 2025/0279893).
Regarding claim 1. Munshi teaches a method of establishing a wireless connection by an access point (AP) (Munshi, the Abstract), comprising:
receiving an access request indicating that a client device is requesting access to a target network using Wi-Fi protected access 3 (WPA3) protocol created by the AP (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID);
acquiring a target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) or an alternate encryption protocol, e.g., Wi-Fi protected access 2 WPA2, and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID); and
controlling the client device to connect to the target network according to the WPA3 protocol using the target private PSK in response to the target private PSK being correct (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID, providing secured connection/access to a network).
Regarding claim 12. Munshi teaches a method for establishing a wireless connection by a client device (Munshi, the Abstract), comprising:
transmitting, to an access point (AP), an access request indicating that the client device is requesting access to a target network using Wi-Fi protected access 3 (WPA3) protocol created by the AP (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID);
providing, to the AP, a target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) or an alternate encryption protocol, e.g., Wi-Fi protected access 2 WPA2, and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID); and
performing a simultaneous authentication of equals (SAE) authentication process specified by the WPA3 protocol using the target private PSK in response to receiving a connection indication instructing the client device to establish a connection with the AP according to the WPA3 protocol (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID, providing secured connection/access to a network).
Regarding claim 17. Munshi teaches an access point (AP) (Munshi, the Abstract), comprising:
a memory (Munshi, Fig. 2, pp [21]), storing instructions thereon; and
a processor, coupled with the memory (Munshi, Fig. 2, pp [21]), the processor is configured to execute the instructions to cause the AP to:
receive an access request indicating that a client device is requesting access to a target network using Wi-Fi protected access 3 (WPA3) protocol created by the AP (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID);
acquire a target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) or an alternate encryption protocol, e.g., Wi-Fi protected access 2 WPA2, and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID); and
control the client device to connect to the target network according to the WPA3 protocol using the target private PSK in response to the target private PSK being correct (Munshi, Figs. 3A-3C, pp [23]-[25], [26]-[28] and [29]-[30]: access point 111 supports an enhanced simultaneous authentication of equals (SAE) authentication encryption protocol (e.g., Wi-Fi protected access 3 (WPA3) and supports enhanced SAE encryption may use a single pre-shared key PSK plus one or more additional passkeys per service set identifier SSID, providing secured connection/access to a network).
Regarding claim 2. Munshi teaches the method of claim 1, wherein the security protocol comprises:
Wi-Fi protected access 2 (WPA2) protocol (Munshi, pp [23], [26], [28]-[29]);
hypertext transfer protocol secure (HTTPS) protocol (Munshi, pp [23], [26], [28]-[29]); or
portal authentication protocol (Munshi, pp [23], [26], [28]-[29]).
Regarding claim 3. Munshi teaches the method of claim 2, wherein the security protocol is the WPA2 protocol, and wherein the acquiring the target private PSK comprises:
transmitting, to the client device, an access request response instructing the client device to establish a pre-connection with the AP according to the WPA2 protocol in response to receiving the access request (Munshi, pp [26]-[29]); and
acquiring, from the client device, the target private PSK during the establishment of the pre-connection with the client device according to the WPA2 protocol (Munshi, pp [26]-[29]).
Regarding claim 4. Munshi teaches the method of claim 1, wherein a set of private PSKs associated with the client device is not bound to a media access control (MAC) address, and the target private PSK being correct is determined based on the target private PSK matching one private PSK of the set of private PSKs (Munshi, pp [26]-[29]); or
the set of private PSKs is bound to a MAC address, and the target private PSK being correct is determined based on the target private PSK matching one private PSK of the set of private PSKs and the MAC address of the client device comprised in the access request matching the MAC address to which the set of private PSKs is bound (Munshi, pp [26]-[29]).
Regarding claim 5. Munshi teaches the method of claim 3, wherein controlling the client device to connect to the target network according to the WPA3 protocol comprises:
disconnecting the client device from the established pre-connection, such that the client device transmits another access request indicating that the client device is requesting access to the target network to the AP (Munshi, pp [23]-[25], [26]-[28]);
transmitting, to the client device, a connection indication instructing the client device to establish a connection with the AP according to the WPA3 protocol in response to receiving the other access request (Munshi, pp [23]-[25], [26]-[28]); and
performing the simultaneous authentication of equals (SAE) authentication process specified by the WPA3 protocol using the target private PSK (Munshi, pp [23]-[25], [26]-[28]).
Regarding claim 6. Munshi teaches the method of claim 2, wherein the security protocol is the HTTPS protocol, and wherein the acquiring the target private PSK comprises:
acquiring the target private PSK from the access request in response to receiving the access request from an intermediate server associated with the AP via a first auxiliary network using the HTTPS protocol, and wherein the intermediate server is configured to transmit a list of networks comprising the target network to the client device via the first auxiliary network and to transmit a private PSK request for requesting the target private PSK to the client device via the first auxiliary network in response to the target network being selected (Munshi, Fig. 1, pp [16]-[18], [23], [32]).
Regarding claim 7. Munshi teaches the method of claim 6, wherein controlling the client device to connect to the target network according to the WPA3 protocol comprises:
transmitting, to the intermediate server, a verification result message indicating the target private PSK being correct via the first auxiliary network (Munshi, pp [23]-[25], [26]-[28], [32]).; and
performing a simultaneous authentication of equals (SAE) authentication process specified by the WPA3 protocol using the target private PSK, wherein the intermediate server is configured to transmit to the client device a connection indication instructing the client device to establish a connection with the AP according to the WPA3 protocol in response to receiving the verification result message (Munshi, pp [23]-[25], [26]-[28]).
Regarding claim 8. Munshi teaches the method of claim 2, wherein the security protocol is the portal authentication protocol, and wherein the acquiring the target private PSK comprises:
redirecting the client device to a portal server using the portal authentication protocol associated with the AP in response to receiving the access request from the client device via a second auxiliary network which is unencrypted and created by the AP, such that the portal server transmits to the client device a portal authentication request for requesting an identity credential of the client device (Munshi, pp [23]-[25], [26]-[28]);
receiving the identity credential of the client device from the portal server (Munshi, pp [23]-[25], [26]-[28]);
transmitting, to the portal server, an authentication result message indicating the authentication being successful in response to the identity credential being correct, such that the portal server transmits to the client device a private PSK setting indication instructing the client device to set the target private PSK (Munshi, pp [23]-[25], [26]-[28]); and
receiving the target private PSK from the portal server (Munshi, pp [23]-[25], [26]-[28]).
Regarding claim 9. Munshi teaches the method of claim 8, wherein the target private PSK being correct is based on a verification of the identity credential being successful (Munshi, pp [23]-[25], [26]-[28]).
Regarding claim 10. Munshi teaches the method of claim 8, wherein controlling the client device to connect to the target network according to the WPA3 protocol comprises:
disconnecting the client device from the second auxiliary network after receiving the target private PSK, such that the client device transmits another access request indicating that the client device is requesting access to the target network to the AP (Munshi, pp [23]-[25], [26]-[28]);
transmitting, to the client device, a connection indication instructing the client device to establish the connection with the AP according to the WPA3 protocol (Munshi, pp [23]-[25], [26]-[28]); and
performing a simultaneous authentication of equals (SAE) authentication process specified by the WPA3 protocol using the target private PSK (Munshi, pp [23]-[25], [26]-[28]).
Regarding claim 11. Munshi teaches the method of claim 10, further comprising:
transmitting a private PSK acknowledgment message to the portal server in response to receiving the target private PSK such that the portal server forwards the private PSK acknowledgment message to the client device (Munshi, pp [23]-[25], [26]-[28]).
Regarding claim 13. Munshi teaches the method of claim 12, wherein the security protocol comprises:
Wi-Fi protected access 2 (WPA2) protocol (Munshi, pp [23], [26], [28]-[29]);
hypertext transfer protocol secure (HTTPS) protocol (Munshi, pp [23], [26], [28]-[29]); or
portal authentication protocol (Munshi, pp [23], [26], [28]-[29]).
Regarding claim 14. Munshi teaches the method of claim 13, wherein the security protocol is the WPA2 protocol, and wherein the providing the target private PSK comprises:
receiving, from the AP, an access request response instructing the client device to establish a pre-connection with the AP according to the WPA2 protocol (Munshi, pp [23]-[25], [26]-[28]); and
establishing the pre-connection with the AP according to the WPA2 protocol such that the AP acquires the target private PSK during the establishment of the pre-connection (Munshi, pp [23]-[25], [26]-[28]).
Regarding claim 15. Munshi teaches the method of claim 13, wherein the security protocol is the HTTPS protocol, and wherein the providing the target private PSK comprises:
receiving a list of networks comprising the target network from an intermediate server associated with the AP via a first auxiliary network using the HTTPS protocol (Munshi, Fig. 1, pp [16]-[18], [23], [32]);
selecting the target network from the list of networks (Munshi, Fig. 1, pp [16]-[18], [23], [32]);
transmitting the target private PSK to the intermediate server via the first auxiliary network in response to receiving a private PSK request for the target private PSK of the client device from the intermediate server, wherein the intermediate server is configured to transmit the access request comprising the target private PSK to the AP in response to receiving the target private PSK (Munshi, Fig. 1, pp [16]-[18], [23], [32]).
Regarding claim 16. Munshi teaches the method of claim 13, wherein the security protocol is the portal authentication protocol, and wherein the providing the target private PSK comprises:
transmitting, to the AP, the access request via a second auxiliary network which is unencrypted and created by the AP, such that the AP redirects the client device to a portal server associated with the AP (Munshi, pp [23]-[25], [26]-[28]);
transmitting, to the portal server, an identity credential of the client device in response to receiving a portal authentication request from the portal server (Munshi, pp [23]-[25], [26]-[28]); and
transmitting, to the portal server, the target private PSK in response to receiving a private PSK setting indication from the portal server (Munshi, pp [23]-[25], [26]-[28]).
Regarding claim 18. Munshi teaches the AP of claim 17, wherein the security protocol is a Wi-Fi protected access 2 (WPA2) protocol, and wherein to acquire the target private PSK, the processor is configured to execute the instructions to cause the AP to:
transmit, to the client device, an access request response instructing the client device to establish a pre-connection with the AP according to the WPA2 protocol in response to receiving the access request (Munshi, pp [26]-[29]); and
acquire, from the client device, the target private PSK during the establishment of the pre-connection with the client device according to the WPA2 protocol (Munshi, pp [26]-[29]).
Regarding claim 19. Munshi teaches the AP of claim 17, wherein the security protocol is a hypertext transfer protocol secure (HTTPS) protocol, and wherein to acquire the target private PSK, the processor is configured to execute the instructions to cause the AP to:
acquire the target private PSK from the access request in response to receiving the access request from an intermediate server associated with the AP via a first auxiliary network using the HTTPS protocol, and wherein the intermediate server is configured to transmit a list of networks comprising the target network to the client device via the first auxiliary network and to transmit a private PSK request for requesting the target private PSK to the client device via the first auxiliary network in response to the target network being selected (Munshi, Fig. 1, pp [16]-[18], [23], [32]).
Regarding claim 20. Munshi teaches the AP of claim 17, wherein the security protocol is a portal authentication protocol, and wherein to acquire the target private PSK, the processor is configured to execute the instructions to cause the AP to:
redirect the client device to a portal server using the portal authentication protocol associated with the AP in response to receiving the access request from the client device via a second auxiliary network which is unencrypted and created by the AP, such that the portal server transmits to the client device a portal authentication request for requesting an identity credential of the client device (Munshi, pp [23]-[25], [26]-[28]);
receive the identity credential of the client device from the portal server (Munshi, pp [23]-[25], [26]-[28]);
transmit, to the portal server, an authentication result message indicating the authentication being successful in response to the identity credential being correct, such that the portal server transmits to the client device a private PSK setting indication instructing the client device to set the target private PSK (Munshi, pp [23]-[25], [26]-[28]); and
receive the target private PSK from the portal server (Munshi, pp [23]-[25], [26]-[28]).
Relevant reference(s) to the claims but not used in the rejection above
Neipris et al. (Pub. No. US 2024/0121609), teaches systems, methods, and non-transitory, machine-readable media may facilitate wireless network provisioning. The method provides wireless network access for a wireless device includes creating, in a cloud-based provisioning system, a wireless network access profile that includes a user identifier associated with the wireless device, receiving, on an access point, an authentication request sent from the wireless device, identifying, by the cloud-based provisioning system, the wireless device based on the user identifier associated with the wireless device, performing, on the cloud-based provisioning system, WPA3-based authentication to authenticate the wireless device, and providing, by the access point, network access to the wireless device.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HUY C HO whose telephone number is (571)270-1108. The examiner can normally be reached M-F 8AM-5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, KATHY WANG-HURST can be reached at (571)270-5371. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HUY C HO/Primary Examiner, Art Unit 2644