1-20DETAILED ACTION
This is in response to the Information Disclosure Statement filed 8/14/2025.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Information Disclosure Statement
The information disclosure statements filed 8/14/2025 and 2/1/2025 have been considered.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim(s) 1-20 is/are rejected under 35 U.S.C. 102(a)(1) and/or 102(a)(2) as being anticipated by Bruner et al., US PGPub 2016/0174069 A1.
Regarding claim 1, Bruner et al. shows a communication method, comprising: obtaining, by a first network function network element, integrity-protected attestation information, wherein the attestation information comprises an attestation result and range indication information associated with the attestation result, the attestation result indicates whether the first network function network element is trustworthy, the range indication information indicates a validity range of the attestation result, and the range indication information comprises an identifier of the first network function network element [0022]; generating, by the first network function network element, a service request message ([0022]-[0023] i.e. requesting to attach and identity verification) in response to determining that a service provided by a second network function network element is to be requested, wherein the service request message comprises the attestation information and the identifier of the first network function network element ([0023]-[0024]); and sending, by the first network function network element, the service request message to the second network function network element (Fig. 1 and 6-7; [0021]-[0026]).
PNG
media_image1.png
684
640
media_image1.png
Greyscale
b. Regarding claim 2, Bruner et al. shows the method according to claim 1, wherein the range indication information further comprises at least one of or more of the following: configuration data of the first network function network element or a part of the configuration data; or an identifier of the second network function network element [0024]-[0025].
c. Regarding claim 3, Bruner et al. shows the method according to claim 1, wherein the method further comprises: sending, by the first network function network element, a remote attestation request to a verifier device (112; Fig. 1; [0023]-[0024]; i.e. AuC), wherein the remote attestation request comprises a measurement, and the measurement is used to indicate indicating a running status of the first network function network element; and the obtaining, by a first network function network element, the integrity-protected attestation information comprises is specifically: receiving, by the first network function network element, the attestation information from the verifier device, wherein the attestation information is associated with the measurement [0024].
d. Regarding claim 4, Bruner et al. shows the method according to claim 3, wherein the method further comprises: receiving, by the first network function network element, a freshness parameter from the second network function network element, wherein the remote attestation request further comprises the freshness parameter, and the attestation information is also associated with the freshness parameter ([0024]-[0025]; i.e. the AuC checks the sequence number ….. Increments…).
e. Regarding claim 5, Bruner et al. shows the method according to claim 4, wherein the range indication information further comprises the freshness parameter ([0024]-[0025]; i.e. the AuC checks the sequence number ….. Increments…).
f. Regarding claim 6, Bruner et al. shows the method according to claim 1, wherein the sending, by the first network function network element, the service request message to the second network function network element comprises: in response to the attestation result indicating that the first network function network element is trustworthy, sending, by the first network function network element, the service request message to the second network function network element ([0024]-[0025]; i.e. the AuC checks the sequence number ….. Increments…Also, the handshake and token generation on both sides.).
g. Regarding claim 7, Bruner et al. shows the method according to claim 1, wherein the range indication information further comprises time-validity information of the attestation result, and the time- validity information comprises at least one of: a generation time of the attestation result; a generation time and validity duration of the attestation result; a validity deadline of the attestation result; or a counter value of the attestation result ([0024]-[0025]; i.e. the AuC checks the sequence number ….. Increments…).
h. Regarding claim 8, Bruner et al. shows the method according to claim 1, wherein in response to the service being a registration service, the service request message further comprises configuration data of the first network function network element, and the service request message is used to request that the configuration data of the first network function network element be stored ([0024]-[0025]).
i. Regarding claim 9, Bruner et al. shows the method according to claim 1, wherein in response to the service being an authorization service, the attestation information further comprises a validity period of the attestation result, the service request message is used to request to obtain a first token for authorizing [0023]-[0024], the first token is used to authorize the first network function network element to access a service of a third network function network element [0025]-[0027], and the method further comprises: receiving, by the first network function network element, the first token and a validity period of the first token from the second network function network element [0023]-[0025], wherein the validity period of the first token is less than or equal to the validity period of the attestation result [0022]-[0026].
j. Regarding claim 10, Bruner et al. shows an apparatus, comprising: at least one memory storing instructions; and at least one processor coupled to the at least one memory, and configured to execute the instructions to cause the apparatus to: obtain integrity-protected attestation information [0022]-[0023] cellular authentication, wherein the attestation information comprises an attestation result and range indication information associated with the attestation result[0024]-[0025], the attestation result indicates whether a first network function network element is trustworthy, the range indication information indicates a validity range of the attestation result, and the range indication information comprises an identifier of the first network function network element ([0022]-[0023] i.e. requesting to attach and identity verification); generate a service request message in response to [[when]] determining that a service provided by a second network function network element is to be requested, wherein the service request message comprises the attestation information and [[an]] the identifier of the first network function network element ([0023]-[0024]); and send the service request message to the second network function network element (Fig. 1 and 6-7; [0021]-[0026]).
k. Regarding claim 11, Bruner et al. shows the apparatus according to claim 10, wherein the range indication information further comprises at least one of or more of the following: configuration data of the first network function network element or a part of the configuration data; or an identifier of the second network function network element ([0023]-[0025]).
l. Regarding claim 12, Bruner et al. shows the apparatus according to claim 10, wherein the at least one processor is configured to execute the instructions to cause the apparatus further to: send a remote attestation request to a verifier device, wherein the remote attestation request comprises a measurement, and the measurement is used to indicate indicating a running status of the first network function network element; and obtain the obtaining integrity-protected attestation information by: receiving the attestation information from the verifier device, wherein the attestation information is associated with the measurement [0023]-[0025].
m. Regarding claim 13, Bruner et al. shows the apparatus according to claim 12, wherein the at least one processor is configured to execute the instructions to cause the apparatus further to: receive a freshness parameter from the second network function network element, wherein the remote attestation request further comprises the freshness parameter, and the attestation information is also associated with the freshness parameter [0024]-[0025].
n. Regarding claim 14, Bruner et al. shows the apparatus according to claim 13, wherein the range indication information further comprises the freshness parameter [0024]-[0025].
o. Regarding claim 15, Bruner et al. shows the apparatus according to claim 10, wherein the at least one processor is configured to execute the instructions to cause the apparatus to: send the service request message to the second network function network element comprises: in response to the attestation result indicates indicating that the first network function network element is trustworthy, sending the service request message to the second network function network element [0024]-[0025].
p. Regarding claim 16, Bruner et al. shows the apparatus according to claim 10, wherein the range indication information further comprises time-validity information of the attestation result, and the time-validity information comprises at least one of or more of the following: a generation time of the attestation result; a generation time and validity duration of the attestation result; a validity deadline of the attestation result; or a counter value of the attestation result [0024].
q. Regarding claim 17, Bruner et al. shows the apparatus according to claim 10, wherein in response to the service being a registration service, the service request message further comprises configuration data of the first network function network element, and the service request message is used to request that the configuration data of the first network function network element be stored ([0024]-[0025]).
r. Regarding claim 18, Bruner et al. shows the apparatus according to claim 10, wherein in response to the service being an authorization service, the attestation information further comprises a validity period of the attestation result, the service request message is used to request a first token for authorizing, the first network function network element to access a service of a third network function network element, and the at least one processor is configured to execute the instructions to cause the apparatus further to: receive the first token and a validity period of the first token from the second network function network element, wherein the validity period of the first token is less than or equal to the validity period of the attestation result([0024]-[0025]).
s. Regarding claim 19, Bruner et al. shows an apparatus, comprising; at least one memory storing instructions; and at least one processor coupled to the at least one memory, and configured to execute the instructions to cause the apparatus to: receive a service request message from a first network function network element, wherein the service request message is used to request a service, and the service request message comprises an identifier of the first network function network element; in response to the service request message further comprising integrity- protected attestation information [0023]-[0025], perform verification on verify the integrity protection of the attestation information; and in response to the verification on the integrity protection of the attestation information succeeded, determine, based on the attestation information, whether to provide the service for the first network function network element (Fig. 1 and 6-7; [0022]-[0026]).
t. Regarding claim 20, Bruner et al. shows the apparatus according to claim 19, wherein the at least one processor is configured to execute the instructions to cause the apparatus further to: in response to [[when]] the service request message not comprising comprises the integrity-protected attestation information, determinine determine, based on a preconfigured execution policy, whether to provide the service for the first network function network element ([0022]-[0026]).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Thakare et al., US PGPub 2010/0064135 A1, is cited for disclosing multiple systems, in Figures 2-6, involving various arrangements for wireless communication and verification processes, which are related to the instant application and authentication techniques which may add insight to the instant application.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SEAHVOSH J NIKMANESH whose telephone number is (571)270-5549. The examiner can normally be reached M-F 9-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yuwen Pan can be reached at (571)272-7855. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Seahvosh Nikmanesh/Examiner, Art Unit 2649 /YUWEN PAN/Supervisory Patent Examiner, Art Unit 2649