DETAILED ACTION
This Office action is in response to a non-provisional utility patent application filed by Applicant on 11/25/2024.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Double Patenting
No conflicting application or issued patent was identified that would require a rejection under double patenting.
Claim Rejections - 35 USC § 101
The present application, as claimed, satisfies the requirements for patent-eligible subject matter under 35 U.S.C. 101.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 8, 14 rejected under 35 U.S.C. 103 as being unpatentable over Legacy (US 2014/0281524 A1, published Sep. 18, 2014) in view of Choi (US 2009/0328191 A1, published Dec. 31, 2009).
Regarding claim 1, Legacy discloses: an apparatus comprising processing circuitry configured to: negotiate with an Internet Security Protocol (IPSec) host device to determine whether both a user equipment (UE) and the IPsec host device are capable of supporting synchronization of IPSec information (the exchange of IKE messages to authenticate each other and negotiate security proposals. This initial handshake confirms that both devices support the same IKE version and cryptographic standards. Legacy ¶¶ 2 and 25–26.); and when both the UE and the IPsec host device are capable of supporting synchronization of IPSec information, receive IPSec information from the IPSec host device [over a dedicated channel], the IPSec information being configured to support encapsulation (fully negotiated instances with far-end nodes are synchronized to peer KM instances and incomplete instances are not. Legacy ¶¶ 34 and 36.).
Legacy does not disclose: synchronization of IPSec information over a dedicated channel.
However, Choi does disclose: synchronization of IPSec information over a dedicated channel (synchronizing SA state of a mobile communication terminal by establishing an IPSec tunnel. Choi ¶¶ 12–13.).
Therefore, it would have been prima facie obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the IPSec negotiation handshake and node state determination of Legacy with facilitating IPSec security information and processes over a dedicated secure IPSec tunnel based upon the teachings of Choi. The motivation being to transmit data packets through the tunnel in order to provide secure communications. Choi ¶ 6.
Regarding claim 8, Legacy in view of Choi discloses the limitations of claim 1, wherein the processing circuitry is further configured to: negotiate with an additional Internet Security Protocol (IPSec) host device to determine whether both the UE and the IPsec host device are capable of supporting synchronization of IPSec information; and when both the UE and the additional IPsec host device are capable of supporting synchronization of IPSec information, receive additional IPSec information from the additional IPSec host device (the exchange of IKE messages to authenticate each other and negotiate security proposals. This initial handshake confirms that both devices support the same IKE version and cryptographic standards. Legacy ¶¶ 2 and 25–26. Multiple devices include any appropriate number for receiving IPSec information. Legacy ¶¶ 27 and 36.), wherein the processing circuitry is configured to interface with the IPSec host device and the additional IPSec host device at the same time (Legacy ¶ 36.).
Regarding claim 14, Legacy in view of Choi discloses the limitations of claim 1, wherein the processing circuitry is further configured to maintain a database with the IPSec information (tracking SAs using a Security Association Database. Legacy ¶ 20.).
Claims 2–7, 16 rejected under 35 U.S.C. 103 as being unpatentable over Legacy in view of Choi in view of Liu (US 2023/0128433 A1, published Apr. 27, 2023).
Regarding claim 2, Legacy in view of Choi discloses the limitations of claim 1. Legacy in view of Choi does not disclose: wherein the processing circuitry is further configured to initiate a fetch of the IPSec information from the IPSec host device upon receipt of a quality of service (QoS) encapsulation rule from a network.
However, Liu does disclose: wherein the processing circuitry is further configured to initiate a fetch of the IPSec information from the IPSec host device upon receipt of a quality of service (QoS) encapsulation rule from a network (receiving a downlink data packet associated with downlink SPI. Liu Figure 9, element 910 and ¶¶ 133–134. Followed by requesting paired uplink SPI paired with downlink SPI. Liu Figure 9, element 912 and ¶ 135. Reply with paired uplink and downlink SPI information. Liu Figure 9, element 914 and ¶ 135. Communication between a UE and a RAN to enable NAS RQoS for ESP packets. Liu ¶ 132.).
Therefore, it would have been prima facie obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the IPSec negotiation handshake and node state determination of Legacy with enabling QoS encapsulation rules based upon the teachings of Liu. The motivation being a means of enabling network QoS rules for encapsulated packets between UE and RAN nodes. Liu ¶ 132.
Regarding claim 3, Legacy in view of Choi in view of Liu discloses the limitations of claim 2, wherein the IPSec information from the IPSec host device comprises IPSec security associations (SAs) (Legacy ¶ 26.).
Regarding claim 4, Legacy in view of Choi in view of Liu discloses the limitations of claim 2, wherein the IPSec information from the IPSec host device comprises an uplink (UL) Security Protocol Index (SPI) created by the IPSec host device (reply with paired uplink and downlink SPI information to create the specific packet filter. Liu Figure 9, element 914 and ¶ 135.).
Regarding claim 5, Legacy in view of Choi in view of Liu discloses the limitations of claim 4, wherein the processing circuitry is further configured to implement the QOS encapsulation rule with the UL SPI (communication between a UE and a RAN to enable NAS RQoS for ESP packets. Liu ¶ 132.).
Regarding claim 6, Legacy in view of Choi discloses the limitations of claim 1, wherein the dedicated channel is an IPsec tunnel (synchronizing SA state of a mobile communication terminal by establishing an IPSec tunnel. Choi ¶¶ 12–13.).
Regarding claim 7, Legacy in view of Choi discloses the limitations of claim 1. Legacy in view of Choi does not disclose: wherein the processing circuitry is further configured to receive updates of IPSec information from the IPSec host device, wherein the updates of the IPSec information comprises a deletion of an uplink (UL) Security Protocol Index (SPI) previously created by the IPSec host device.
However, Liu does disclose: wherein the processing circuitry is further configured to receive updates of IPSec information from the IPSec host device, wherein the updates of the IPSec information comprises a deletion of an uplink (UL) Security Protocol Index (SPI) previously created by the IPSec host device (updating records to manage SPI values. Liu ¶ 6.).
Therefore, it would have been prima facie obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the IPSec negotiation handshake and node state determination of Legacy with managing and updating SPI values based upon the teachings of Liu. The motivation being a means of enabling network QoS rules for encapsulated packets between UE and RAN nodes. Liu ¶ 132.
Regarding claim 16, Legacy in view of Choi discloses the limitations of claim 1. Legacy in view of Choi does not disclose: wherein the processing circuitry is further configured to send a notification or unsolicited result code to the IPSec host device when a new downlink (DL) Security Protocol Index (SPI) is received as part of the IPSec information.
However, Liu does disclose: wherein the processing circuitry is further configured to send a notification or unsolicited result code to the IPSec host device when a new downlink (DL) Security Protocol Index (SPI) is received as part of the IPSec information (in response to receiving a downlink SPI, requesting paired uplink SPI paired with downlink SPI. Liu Figure 9, element 912 and ¶ 135.).
Therefore, it would have been prima facie obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the IPSec negotiation handshake and node state determination of Legacy with sending a notification when a downlink SPI is received based upon the teachings of Liu. The motivation being a means of enabling network QoS rules for encapsulated packets between UE and RAN nodes. Liu ¶ 132.
Claim 9 rejected under 35 U.S.C. 103 as being unpatentable over Legacy in view of Choi in view of Raleigh (US 2010/0195503 A1, published Aug. 5, 2010).
Regarding claim 9, Legacy in view of Choi discloses the limitations of claim 1. Legacy in view of Choi does not disclose: wherein upon receipt of a quality of service (QoS) encapsulation rule from a network, the processing circuitry is further configured to periodically poll the IPSec host device for the IPSec information.
However, Raleigh does disclose: wherein upon receipt of a quality of service (QoS) encapsulation rule from a network, the processing circuitry is further configured to periodically poll the IPSec host device for the IPSec information (Raleigh ¶ 131.).
Therefore, it would have been prima facie obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the IPSec negotiation handshake and node state determination of Legacy with periodically polling the IPSec host for information based upon the teachings of Raleigh. The motivation being to maintain updated network security information. Raleigh ¶ 131.
Claims 10–11 rejected under 35 U.S.C. 103 as being unpatentable over Legacy in view of Choi in view of Raleigh in view of Liu.
Regarding claim 10, Legacy in view of Choi in view of Raleigh discloses the limitations of claim 9. Legacy in view of Choi in view of Raleigh does not disclose: wherein the IPSec information comprises uplink (UL) and downlink (DL) Security Protocol Index (SPI) information.
However, Liu does disclose: wherein the IPSec information comprises uplink (UL) and downlink (DL) Security Protocol Index (SPI) information (IPSec information comprises paired uplink and downlink SPI information. Liu ¶¶ 132–135.).
Therefore, it would have been prima facie obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the IPSec negotiation handshake and node state determination of Legacy with IPSec information being uplink and downlink SPI information based upon the teachings of Liu. The motivation being a means of enabling network QoS rules for encapsulated packets between UE and RAN nodes. Liu ¶ 132.
Regarding claim 11, Legacy in view of Choi in view of Raleigh in view of Liu discloses the limitations of claim 10, wherein the processing circuitry is further configured to poll the IPSec host device for the IPSec formation upon expiration of a polling timer having a predetermined time period (RQoS timer. Liu ¶ 92.).
Claims 18–20 rejected under 35 U.S.C. 103 as being unpatentable over Legacy in view of Liu.
Regarding claim 18, Legacy discloses: an apparatus comprising processing circuitry configured to: negotiate with an Internet Security Protocol (IPSec) host device to determine whether both a user equipment (UE) and the IPsec host device are capable of supporting synchronization of IPSec information (the exchange of IKE messages to authenticate each other and negotiate security proposals. This initial handshake confirms that both devices support the same IKE version and cryptographic standards. Legacy ¶¶ 2 and 25–26.); when both the UE and the IPsec host device are capable of supporting synchronization of IPSec information (fully negotiated instances with far-end nodes are synchronized to peer KM instances and incomplete instances are not. Legacy ¶¶ 34 and 36.).
Legacy does not disclose: at least one valid UDP/TCP encapsulation rule has been received from a network, initiate a fetch of the IPSec information from the IPSec host device upon detection of a first downlink (DL) Security Protocol Index (SPI) over a data path; upon detecting any new unknown DL SPI, transmit a request to the IPSec host device to provide uplink and downlink SPI (UL/DL SPI); and receive updated IPSec information comprising the UL/DL SPI from the IPSec host device.
However, Liu does disclose: at least one valid UDP/TCP encapsulation rule has been received from a network (received downlink ESP packet includes indicator to derive a QoS rule. Liu ¶ 134.), initiate a fetch of the IPSec information from the IPSec host device upon detection of a first downlink (DL) Security Protocol Index (SPI) over a data path (receiving a downlink data packet associated with downlink SPI. Liu Figure 9, element 910 and ¶¶ 133–134.); upon detecting any new unknown DL SPI, transmit a request to the IPSec host device to provide uplink and downlink SPI (UL/DL SPI) (requesting paired uplink SPI paired with downlink SPI. Liu Figure 9, element 912 and ¶ 135.); and receive updated IPSec information comprising the UL/DL SPI from the IPSec host device (reply with paired uplink and downlink SPI information to create the specific packet filter. Liu Figure 9, element 914 and ¶ 135.).
Therefore, it would have been prima facie obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the IPSec negotiation handshake and node state determination of Legacy with upon detecting a downlink packet SPI, requesting a paired uplink/downlink SPI from the IPSec host device based upon the teachings of Liu. The motivation being a means of enabling network QoS rules for encapsulated packets between UE and RAN nodes. Liu ¶ 132.
Regarding claim 19, Legacy in view of Liu discloses the limitations of claim 18, wherein the processing circuitry is further configured to receive an indication from the IPSec host device immediately upon the IPSec host device creating a new security association (SA) and/or deleting an old SA (updating records to manage SPI values. Liu ¶ 6.).
Regarding claim 20, Legacy in view of Liu discloses the limitations of claim 18, wherein the processing circuitry is further configured to disable requesting and receiving IPSec information from the IPSec host device when the UE has no valid UDP/TCP encapsulation rules (Liu ¶¶ 34 and 36.).
Allowable Subject Matter
Claims 12–13, 15, and 17 objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VANCE M LITTLE whose telephone number is (571) 270-0408. The examiner can normally be reached on Monday - Friday 9:30am - 5:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung (Jay) Kim can be reached on (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VANCE M LITTLE/Primary Examiner, Art Unit 2493