DETAILED ACTION
Authorization for Internet Communications
The examiner encourages Applicant to submit an authorization to communicate with the examiner via the Internet by making the following statement (from MPEP 502.03):
“Recognizing that Internet communications are not secure, I hereby authorize the USPTO to communicate with the undersigned and practitioners in accordance with 37 CFR 1.33 and 37 CFR 1.34 concerning any subject matter of this application by video conferencing, instant messaging, or electronic mail. I understand that a copy of these communications will be made of record in the application file.”
Please note that the above statement can only be submitted via Central Fax (not Examiner's Fax), Regular postal mail, or EFS Web using PTO/SB/439.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Election/Restrictions
Applicant’s election without traverse of claim 1 – 9 and 21 - 30 in the reply filed on 05/15/2026 is acknowledged.
Priority
Should applicant desire to obtain the benefit of foreign priority under 35 U.S.C. 119(a)-(d) prior to declaration of an interference, a certified English translation of the foreign application must be submitted in reply to this action. 37 CFR 41.154(b) and 41.202(e).
Failure to provide a certified translation may result in no benefit being accorded for the non-English application.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 02/05/2025, 08/11/2025 and 07/23/2026 is being considered by the examiner.
Claim Objections
Claim 26 is objected to because of the following informalities:
Regarding claim 26; the preamble of the claim does not commensurate with its base claim.
Appropriate correction is required.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1 – 9 and 21 – 30 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Choyi et al., (US 2021/0314171 A1) (hereinafter “Choyi”).
Choyi discloses;
Regarding claim 1, a secure communication method [i.e., see figures 3A – 3B), (page 3, para 0035), (page 4, para 0038)], comprising:
receiving, by a first network element [i.e., xNF 130-1 (see figures 1 and 3B)], first information [i.e., NF profile i.e., xNF profile (page 3, para 0037), (see ref. 314 of figure 3A)] and a first signature [i.e., digitally sign certificate request token (CRT) (see ref. 314 of figure 3A), (page 3, para 0037)] from a network management network element [i.e., management function 110 may digitally sign the CRT (page 3, para 0037), (see figures 3A – 3B) i.e., the management function 110 may forward the xNF package, the tokens, and the xNF profile (with the CRT) to VIM 120 for deployment (page 3, para 0037), (see ref. 316 of figure 3A)], wherein the first signature is generated based on a private key of the network management network element and the first information [i.e., management function 110 may use a private key to digitally sign CRT 400 (page 5, para 0052), (see figure 4) i.e., binding the CRT 400 with the xNF profile (page 3, para 0036), (see ref. 314 of figure 3A)], and the first information is used to describe the first network element [i.e., the xNF profile may include the description and configuration requirements for xNF 130-1 (page 3, para 0037)];
sending, by the first network element, the first information and the first signature [i.e., binding the CRT to the CSR (see ref. 336 of figure 3B), (page 4, para 0040)] to a certificate issuing network element [i.e., xNF 130-1 send CSR and CRT to PKI system 140 (see ref. 192 of figure 1 and ref. 340 of figure 3B), (page 4, para 0040) i.e., PKI system 140 includes certificate authority 142 (page 2, para 0020), (see figure 1)], wherein the first information is used to obtain a first certificate [i.e., the PKI system 140 receive the CSR and CRT, process the CSR and issue a certificate (e.g., X.509 certificate) (page 4, para 0041)], and the first certificate is used to prove an identity of the first network element [i.e., PKI system 140 to authenticate an xNF (page 4, para 0045) Note; establishing trust is the intended purpose of a certificate]; and
receiving, by the first network element, the first certificate from the certificate issuing network element [i.e., xNF 130-1 may receive an X.509 certificate from PKI system 140 (see ref. 360 of figure 3C, ref. 342 of figure 3B and see ref. 196 of figure 1), (page 4, para 0041 and 0044), (page 2, para 0024)].
Regarding claim 2, the secure communication method according to claim 1, wherein the first certificate comprises the first information [i.e., generate X.509 Certificate based on CSR and CRT (see ref. 358 of figure 3C), (page 4, para 0044) i.e., the CRT 400 includes a CAL 420 that provide a subset of attributes that can be used to generate a digital certificate (page 5, para 0050), (see figure 4)].
Regarding claim 3, the secure communication method according to claim 1, further comprising:
sending, by the first network element, first indication information to the certificate issuing network element, wherein the first indication information is used to obtain information used to verify the first signature [i.e., the CRT includes a key identifier (see ref. 430 of figure 4), (page 4, para 0046) i.e., key identifier filed 430 may include an ID for the private key to be used exchanges (page 5, para 0052) Note; this key identifier tells the PKI which signing key or certificate should be used to verify the CRT signature Thus, the CRT itself carries indication information identifying the management signer].
Regarding claim 4, the secure communication method according to claim 1, further comprising:
sending, by the first network element, a type of the first certificate to the certificate issuing network element [i.e., the management function 110 may include a certificate attribute list (CAL) with the CRT, where the CAL can be used to customize certificate for each xNF (page 1, para 0013)].
Regarding claim 5, the secure communication method according to claim 1, further comprising:
sending, by the first network element, a public key of the first network element to the certificate issuing network element [i.e., XNF-1 130 may generate a public/private key pair and generate a CSR 190 using the private key of the asymmetric key pair (page 4, para 0039), (see ref. 332 – 340 of figure 3B) i.e., PKI system 140 may generate a certificate (e.g., an X.509v3 certificate) based on the public key in the CSR (page 2, para 0024), (page 4, para 0044)].
Regarding claim 6, the secure communication method according to claim 1, wherein the first information comprises at least one of a first instance identifier [i.e., subject field 406 Instance.CHE.LocationInfo.5GS may include an identifier for the xNF package to be instantiated (see ref. 406 of figure 4), (page 4, para 0047)], a first type [i.e., CHF (see ref. 406 of figure 4), (page 4, para 0047)], a first fully qualified domain name [i.e., the xNF obtains the FQDN of the PKI from the CRT (see ref. 330 of figure 3B and figure 4), (page 4, para 0039)], a first internet protocol address [i.e., the xNF obtains the FQDN of the PKI from the CRT (see ref. 330 of figure 3B and figure 4), (page 4, para 0039)], or a first public land mobile network identifier [i.e., (see figure 1)], the first instance identifier identifies the first network element [i.e., subject field 406 Instance.CHE.LocationInfo.5GS may include an identifier for the xNF package to be instantiated (see ref. 406 of figure 4), (page 4, para 0047)], the first type indicates a type of the first network element [i.e., CHF (see ref. 406 of figure 4), (page 4, para 0047)], the first fully qualified domain name or the first internet protocol address indicates an address of the first network element [i.e., the xNF obtains the FQDN of the PKI from the CRT (see ref. 330 of figure 3B and figure 4), (page 4, para 0039)], and the first public land mobile network identifier indicates a network area in which the first network element is located [i.e., (see figure 1)].
Regarding claim 7, the secure communication method according to claim 1, further comprising:
obtaining, by the first network element, second information, wherein the second information comprises at least one of an identifier of the certificate issuing network element [i.e., xNF 130-1 may use the audience address field i.e., Audience: “RegistrationAuthority.PKI@xy.com” of the CRT to obtain a FQDN of PKI system 140 (see ref. 404 of figure 4), (page 4, para 0039)] or first duration [i.e., validity period filed 423 may include a time period (e.g., a start and end date) that a digital certificate will be valid (page 5, para 0051), (see ref. 423 of figure 4)], the identifier of the certificate issuing network element is used to send the first information and the first signature to the certificate issuing network element [i.e., xNF 130-1 may use the audience address field i.e., Audience: “RegistrationAuthority.PKI@xy.com” of the CRT to obtain a FQDN of PKI system 140 (see ref. 404 of figure 4), (page 4, para 0039)], and the first duration indicates a validity period of the first certificate [i.e., validity period filed 423 may include a time period (e.g., a start and end date) that a digital certificate will be valid (page 5, para 0051), (see ref. 423 of figure 4)].
Regarding claim 8, the secure communication method according to claim 7, further comprising:
sending, by the first network element, the second information to the certificate issuing network element [i.e., xNF 130-1 send CSR and CRT to PKI system 140 (see ref. 192 of figure 1 and ref. 340 of figure 3B), (page 4, para 0040) i.e., PKI system 140 includes certificate authority 142 (page 2, para 0020), (see figure 1)].
Regarding claim 9, the secure communication method according to claim 7, wherein the second information is received from the network management network element, and the first signature is generated based on the private key of the network management network element, the first information, and the second information [i.e., management function 110 may use a private key to digitally sign CRT 400 (page 5, para 0052), (see figure 4) i.e., binding the CRT 400 with the xNF profile (page 3, para 0036), (see ref. 314 of figure 3A)].
Regarding claim 21, an apparatus [i.e., xNF 130-1 (see figures 1 and 3B) i.e., xNF may be implemented by one or more device 200 (see figure 2), (page 2, para 0026)], comprising:
a processor [i.e., processor (see ref. 220 of figure 2), (page 2, para 0027)]; and
a memory [i.e., memory (see ref. 230 of figure 2), (page 2, para 0027)] having instructions stored thereon [i.e., software (see ref. 235 of figure 2), (page 2, para 0027)] that, when executed by the processor [i.e., (see figure 2)], cause the apparatus to:
receive first information [i.e., NF profile i.e., xNF profile (page 3, para 0037), (see ref. 314 of figure 3A)] and a first signature [i.e., digitally sign certificate request token (CRT) (see ref. 314 of figure 3A), (page 3, para 0037)] from a network management network element [i.e., management function 110 may digitally sign the CRT (page 3, para 0037), (see figures 3A – 3B) i.e., the management function 110 may forward the xNF package, the tokens, and the xNF profile (with the CRT) to VIM 120 for deployment (page 3, para 0037), (see ref. 316 of figure 3A)], wherein the first signature is generated based on a private key of the network management network element and the first information [i.e., management function 110 may use a private key to digitally sign CRT 400 (page 5, para 0052), (see figure 4) i.e., binding the CRT 400 with the xNF profile (page 3, para 0036), (see ref. 314 of figure 3A)], and the first information is used to describe the apparatus [i.e., the xNF profile may include the description and configuration requirements for xNF 130-1 (page 3, para 0037)];
send the first information and the first signature [i.e., binding the CRT to the CSR (see ref. 336 of figure 3B), (page 4, para 0040)] to a certificate issuing network element [i.e., xNF 130-1 send CSR and CRT to PKI system 140 (see ref. 192 of figure 1 and ref. 340 of figure 3B), (page 4, para 0040) i.e., PKI system 140 includes certificate authority 142 (page 2, para 0020), (see figure 1)], wherein the first information is used to obtain a first certificate [i.e., the PKI system 140 receive the CSR and CRT, process the CSR and issue a certificate (e.g., X.509 certificate) (page 4, para 0041)], and the first certificate is used to prove an identity of the apparatus [i.e., PKI system 140 to authenticate an xNF (page 4, para 0045) Note; establishing trust is the intended purpose of a certificate]; and
receive the first certificate from the certificate issuing network element [i.e., xNF 130-1 may receive an X.509 certificate from PKI system 140 (see ref. 360 of figure 3C, ref. 342 of figure 3B and see ref. 196 of figure 1), (page 4, para 0041 and 0044), (page 2, para 0024)].
Regarding claim 22, the apparatus according to claim 21, wherein the first certificate comprises the first information [i.e., generate X.509 Certificate based on CSR and CRT (see ref. 358 of figure 3C), (page 4, para 0044) i.e., the CRT 400 includes a CAL 420 that provide a subset of attributes that can be used to generate a digital certificate (page 5, para 0050), (see figure 4)].
Regarding claim 23, the apparatus according to claim 21, wherein the apparatus is further caused to: send first indication information to the certificate issuing network element, wherein the first indication information is used to obtain information used to verify the first signature [i.e., the CRT includes a key identifier (see ref. 430 of figure 4), (page 4, para 0046) i.e., key identifier filed 430 may include an ID for the private key to be used exchanges (page 5, para 0052) Note; this key identifier tells the PKI which signing key or certificate should be used to verify the CRT signature Thus, the CRT itself carries indication information identifying the management signer].
Regarding claim 24, the apparatus according to claim 21, wherein the apparatus is further caused to: send a type of the first certificate to the certificate issuing network element [i.e., the management function 110 may include a certificate attribute list (CAL) with the CRT, where the CAL can be used to customize certificate for each xNF (page 1, para 0013)].
Regarding claim 25, the apparatus according to claim 21, wherein the apparatus is further caused to: send a public key of the apparatus to the certificate issuing network element [i.e., XNF-1 130 may generate a public/private key pair and generate a CSR 190 using the private key of the asymmetric key pair (page 4, para 0039), (see ref. 332 – 340 of figure 3B) i.e., PKI system 140 may generate a certificate (e.g., an X.509v3 certificate) based on the public key in the CSR (page 2, para 0024), (page 4, para 0044)].
Regarding claim 26, the secure communication method according to claim 21, wherein the first information comprises at least one of a first instance identifier [i.e., subject field 406 Instance.CHE.LocationInfo.5GS may include an identifier for the xNF package to be instantiated (see ref. 406 of figure 4), (page 4, para 0047)], a first type [i.e., CHF (see ref. 406 of figure 4), (page 4, para 0047)], a first fully qualified domain name [i.e., the xNF obtains the FQDN of the PKI from the CRT (see ref. 330 of figure 3B and figure 4), (page 4, para 0039)], a first internet protocol address [i.e., the xNF obtains the FQDN of the PKI from the CRT (see ref. 330 of figure 3B and figure 4), (page 4, para 0039)], or a first public land mobile network identifier [i.e., (see figure 1)], the first instance identifier identifies the apparatus [i.e., subject field 406 Instance.CHE.LocationInfo.5GS may include an identifier for the xNF package to be instantiated (see ref. 406 of figure 4), (page 4, para 0047)], the first type indicates a type of the apparatus [i.e., CHF (see ref. 406 of figure 4), (page 4, para 0047)], the first fully qualified domain name or the first internet protocol address indicates an address of the apparatus [i.e., the xNF obtains the FQDN of the PKI from the CRT (see ref. 330 of figure 3B and figure 4), (page 4, para 0039)], and the first public land mobile network identifier indicates a network area in which the apparatus is located [i.e., (see figure 1)].
Regarding claim 27, the apparatus according to claim 21, wherein the apparatus is further caused to:
obtain second information, wherein the second information comprises at least one of an identifier of the certificate issuing network element [i.e., xNF 130-1 may use the audience address field i.e., Audience: “RegistrationAuthority.PKI@xy.com” of the CRT to obtain a FQDN of PKI system 140 (see ref. 404 of figure 4), (page 4, para 0039)] or first duration [i.e., validity period filed 423 may include a time period (e.g., a start and end date) that a digital certificate will be valid (page 5, para 0051), (see ref. 423 of figure 4)], the identifier of the certificate issuing network element is used to send the first information and the first signature to the certificate issuing network element [i.e., xNF 130-1 may use the audience address field i.e., Audience: “RegistrationAuthority.PKI@xy.com” of the CRT to obtain a FQDN of PKI system 140 (see ref. 404 of figure 4), (page 4, para 0039)], and the first duration indicates a validity period of the first certificate [i.e., validity period filed 423 may include a time period (e.g., a start and end date) that a digital certificate will be valid (page 5, para 0051), (see ref. 423 of figure 4)].
Regarding claim 28, the apparatus according to claim 27, wherein the apparatus is further caused to:
send the second information to the certificate issuing network element [i.e., xNF 130-1 send CSR and CRT to PKI system 140 (see ref. 192 of figure 1 and ref. 340 of figure 3B), (page 4, para 0040) i.e., PKI system 140 includes certificate authority 142 (page 2, para 0020), (see figure 1)].
Regarding claim 29, the apparatus according to claim 27, wherein the second information is received from the network management network element, and the first signature is generated based on the private key of the network management network element, the first information, and the second information [i.e., management function 110 may use a private key to digitally sign CRT 400 (page 5, para 0052), (see figure 4) i.e., binding the CRT 400 with the xNF profile (page 3, para 0036), (see ref. 314 of figure 3A)].
Regarding claim 30, a non-transitory computer readable storage medium [i.e., memory (see ref. 230 of figure 2), (page 2, para 0027)] having instructions stored thereon [i.e., software (see ref. 235 of figure 2), (page 2, para 0027)] that, when executed by a processor [i.e., (see figure 2)], cause an apparatus to:
receive first information [i.e., NF profile i.e., xNF profile (page 3, para 0037), (see ref. 314 of figure 3A)] and a first signature [i.e., digitally sign certificate request token (CRT) (see ref. 314 of figure 3A), (page 3, para 0037)] from a network management network element [i.e., management function 110 may digitally sign the CRT (page 3, para 0037), (see figures 3A – 3B) i.e., the management function 110 may forward the xNF package, the tokens, and the xNF profile (with the CRT) to VIM 120 for deployment (page 3, para 0037), (see ref. 316 of figure 3A)], wherein the first signature is generated based on a private key of the network management network element and the first information [i.e., management function 110 may use a private key to digitally sign CRT 400 (page 5, para 0052), (see figure 4) i.e., binding the CRT 400 with the xNF profile (page 3, para 0036), (see ref. 314 of figure 3A)], and the first information is used to describe the apparatus [i.e., the xNF profile may include the description and configuration requirements for xNF 130-1 (page 3, para 0037)];
send the first information and the first signature [i.e., binding the CRT to the CSR (see ref. 336 of figure 3B), (page 4, para 0040)] to a certificate issuing network element [i.e., xNF 130-1 send CSR and CRT to PKI system 140 (see ref. 192 of figure 1 and ref. 340 of figure 3B), (page 4, para 0040) i.e., PKI system 140 includes certificate authority 142 (page 2, para 0020), (see figure 1)], wherein the first information is used to obtain a first certificate [i.e., the PKI system 140 receive the CSR and CRT, process the CSR and issue a certificate (e.g., X.509 certificate) (page 4, para 0041)], and the first certificate is used to prove an identity of the apparatus [i.e., PKI system 140 to authenticate an xNF (page 4, para 0045) Note; establishing trust is the intended purpose of a certificate]; and
receive the first certificate from the certificate issuing network element [i.e., xNF 130-1 may receive an X.509 certificate from PKI system 140 (see ref. 360 of figure 3C, ref. 342 of figure 3B and see ref. 196 of figure 1), (page 4, para 0041 and 0044), (page 2, para 0024)].
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED A RONI whose telephone number is (571)270-7806. The examiner can normally be reached M-F 9:00-5:00 pm (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SYED A RONI/Primary Examiner, Art Unit 2432