Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Specification
The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
The following title is suggested: A Secure Element for Providing Communication Over a Mobile Communication Network.
Since the Abstract (1st sentence) has similar language, Examiner suggests also deleting the 1st sentence in the Abstract since the Abstract should not repeat information in the title.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 8, 12 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Nordholt et al. (US 20130101121 A1; which has been provided in the International Search Report, IDS 11/12/2024 & NPL 11/12/2024).
Regarding claim 1, Nordholt discloses a secure element to securely communicate over a mobile communication network (Fig. 5 discloses QC card, wherein the secure element is interpreted as the QC card; [0028]; [0087]; Figs. 1 – 3 disclose mobile network), the secure element comprising:
a secure storage unit, in which a subscriber authentication key is stored (Fig. 5, memory 522; [0096] discloses “The memory (522) stores one or more keys that are produced based at least in part on the QC. For example, the memory (522) stores quantum keys produced in QKD between the QC card and the trusted authority. The memory (522) can also store other keys, such an initial pre-placed secret key used for authentication purposes… “; [0139] discloses similar);
and a secure control unit which is configured to firstly generate a session subscriber authentication key, and, based on receiving an authentication request from a core network entity, to authenticate the secure element to the core network entity using the previously generated session subscriber authentication key ([0136] discloses “The processor/FPGA (920) with protocol logic controls operations for user authentication. For example, when an encrypted message for user authentication is received from the QC card by conventional transmission over the optical fiber as a public channel, the processor/FPGA (920) determines a previously stored key in memory (922) and decrypts the message using the key. The processor/FPGA (920) analyzes the contents of the message (e.g., comparing the contents to stored biometric indicia, PIN, other identifying information, etc. for the user) and, if appropriate, authenticates the user.”; wherein the control unit is interpreted as element 920, which corresponds to 520 in Fig. 5; request interpreted as the encrypted message; Fig. 2 shows QC card in communication with several core network entities).
Regarding claim 8, Nordholt discloses the secure element is any of the group consisting of: a smart card, a subscriber identity module – SIM, an embedded SIM, an integrated SIM, a software application, and combinations thereof (Fig. 5 discloses QC card which is a form of smart card).
Claim 12 is similarly analyzed as claim 1, with claim 12 reciting equivalent method limitations.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2, 7 are rejected under 35 U.S.C. 103 as being unpatentable over Nordholt et al. (US 20130101121 A1; which has been provided in the International Search Report, IDS 11/12/2024 & NPL 11/12/2024) in view of Escott et al. (US 20110314287 A1).
Regarding claim 2, Nordholt does not disclose the secure control unit is further configured to receive an identity request from a terminal device and to generate the session subscriber authentication key based on the received identity request.
In the same field of endeavor, however, Escott discloses the secure control unit is further configured to receive an identity request from a terminal device and to generate the session subscriber authentication key based on the received identity request (Fig. 10, steps 1022, 1025; [0091] discloses “Upon receipt of the device identity or credential, the MME 1004 may send an Identity Request 1022 message, with an evolved/extended key set identifier (eKSI) and a device_challenge…. The device 1002 may then calculate a (composite) security key (K_ASME_D) 1025 based on the authentication key (e.g., K_ASME) and device authentication data (e.g., device response, etc.). …”; wherein device 1002 receives the identity request and the subscriber authentication key is interpreted as the (composite) security key (K_ASME_D) ).
Therefore, it would have been obvious to one having ordinary skill in the art, before the effective filing date of the invention, to use the method, as disclosed by Escott, in the system of Nordholt because using a composite security key would increase security as the composite key is generated using secure information from both sending and receiving parties.
Regarding claim 7, Nordholt does not disclose the identity request comprises a request parameter, in which a key generation indication is stored, wherein the secure control unit is configured to additionally generate the session subscriber authentication key based on the key generation indication.
In the same field of endeavor, however, Escott discloses the identity request comprises a request parameter, in which a key generation indication is stored, wherein the secure control unit is configured to additionally generate the session subscriber authentication key based on the key generation indication (Fig. 10, steps 1022, 1025; [0091] discloses “Upon receipt of the device identity or credential, the MME 1004 may send an Identity Request 1022 message, with an evolved/extended key set identifier (eKSI) and a device_challenge…. The device 1002 may then calculate a (composite) security key (K_ASME_D) 1025 based on the authentication key (e.g., K_ASME) and device authentication data (e.g., device response, etc.). …”; wherein th request parameter is interpreted as the eKSI).
Therefore, it would have been obvious to one having ordinary skill in the art, before the effective filing date of the invention, to use the method, as disclosed by Escott, in the system of Nordholt because using a composite security key would increase security as the composite key is generated using secure information from both sending and receiving parties.
Allowable Subject Matter
Claims 3 – 6, 9 - 11, 13 - 17 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Other Prior Art Cited
The prior art made of record and not relied upon is considered pertinent to the applicant’s disclosure.
The following patents/publications are cited to further show the state of the art with respect to authentication:
Frank (US 20060089123 A1) discloses Use of Information on Smartcards for Authentication and Encryption
Hoffman et al. (US 7729986 B1) discloses Smart Card Transactions Using Wireless Telecommunications Network.
Nyman et al. (US 7444513 B2) discloses Authentication In Data Communication.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ADOLF DSOUZA whose telephone number is (571)272-1043. The examiner can normally be reached Mon - Fri 9 AM - 5 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Chieh M Fan can be reached at 571-272-3042. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ADOLF DSOUZA/Primary Examiner, Art Unit 2632