DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The Amendment filed on July 15, 2026 has been entered.
Claims 1-20 are pending.
Claims 4 and 10-11 have been amended.
Claims 1-20 are rejected.
Response to Arguments
Applicant's arguments filed on July 15, 2026 have been fully considered but they are not persuasive.
Regarding the Claim 1 limitation, “receiving information about a management service outsourcing device,” Applicant argues as follows:
Claim 1 requires a step of receiving, by an exposure governance management function entity, information about a management service outsourcing device from a third-party device. The Examiner cited paragraphs [0043], [0045], [0046], and [0080] of Ping et al., noting that the ACF is viewed as the third-party device, and the ANAF is viewed as the claimed management service outsourcing device that invokes a network management capability, and the claimed information about a management service outsourcing device is allegedly met by the identity status, authentication policies, and access control policies. The Examiner also made clear that although Ping et al. is seen as teaching a step of receiving information about a management service outsourcing device from a third-party device, it is not received specifically by an exposure governance management function entity. The Examiner did cite, however, since paragraph [0045] is cited and since it notes that the access control enforcement point 140 can be implemented as an EGMF. Thus, the Applicant will consider the IF 301 of Ping et al. to be an EGMF in the analysis.
Ping teaches that “Integration Fabric (IF) 301 … may be considered as the access control enforcement point 140 shown in FIG. 1.” Ping teaches that “The access control enforcement point 140 can be implemented as an Integration Fabric (IF) or an Exposure Governance Management Function (EGMF).” ([0045]). However, it should be noted that EGMF has additional responsibilities in addition to access control enforcement, including exposure control, policy enforcement, and coordination with other working groups. Thus, IF 301 encompasses only one aspect of EGMF functionality. The following paragraphs of Ping further explain the role of IP 301:
The process 300 may also involve Integration Fabric (IF) 301, which may be considered as the access control enforcement point 140 shown in FIG. 1, or CDIF 220 or 25 DIF 211 and 231 shown in FIG. 2. It is to be understood that the IF 301 can be replaced by other interacting functions, entities or modules in other framework or system. Ping, paragraph [0058], emphasis added.
In a registration process 300 shown in FIG. 3, the MnSP 120 may send 305 a registration request to the IF 301 to register MnS to IF 301. The request may include service type, security level of the service, domain of the service, authentication mechanism 30 supported by the MnS producer, etc. Ping, paragraph [0059], emphasis added.
Then the IF 301 may send 310 the registration information of the MnSP 120 to ANAF 131, to register the MnS in authentication system. According to the requirements of the MnSP 120, the ANAF 131 may create 315 a new record for the MnS. The ANAF 131 may also assign an authentication group for the MnSP 120. Ping, paragraph [0060], emphasis added.
Therefore, the role of the IF 301 in the Ping disclosure is one of EGMF, but also other functions, including access control enforcement point.
Regarding the ANAF, Applicant next argues as follows:
Paragraph [0070] of Ping et al. explains that the IF 301 (seen as an EGMF) receives from the ANAF 131 of the ACF 130 (seen as the claimed third party device) the created identity, agreed authentication mechanism and the preliminary information. The Applicant understands that the Examiner has mapped the ANAF 131 to the claimed management service outsourcing device but believes that the MnSC 110 probably is better mapped to the management service outsourcing device, and further in the analysis the Examiner appears to make the switch to the MnSC 110. (emphasis added).
It is not clear what is meant by ‘mapped” in this argument, and Examiner respectfully disagrees with the contention that there is an incorrect “mapping.”. The Office Action explains that “[a]n access control function (ACF) 130 comprises an Authentication Administrative Function (ANAF) 131 … ([0043]).” and that “The ANAF 131 supports authentication functions associated with the MnSC 110, who can be a human consumer, and one or more MnSP 120 in one or multiple management domains, such as identity management, credential management, and authentication policy management ([0046]).” In short, the ANAF 131 is responsible for establishing (see paragraph [0068]-[0069]) and authenticating both the MnSC (a human user) and the MnSP (a management service provider) by way of IF 301.
Regarding the authentication mechanism, Applicant next argues as follows:
[T]he "created identity, agreed authentication mechanism and the preliminary information" seem to be about the MnSC 110 and not the ANAF 131. For example, paragraph [0068] explains that "[t]he ANAF 131 may create 406 an identity for the MnSC 110." The created identity is about the MnSC 110, not about the ANAF 131. Additionally, the same paragraph notes that the "preferred authentication mechanism [is] of the MnSC 110" again indicating that the agreed authentication mechanism is about the MnSC 110, not about the ANAF 131. Lastly, paragraph [0069] adds that "the ANAF131 may also obtain some preliminary information for the MnSC 110 from ARAF 132."
The arguments are confusing, but Applicant seems to be conflating the network entities requiring authentication, i.e. MnSC and MnSP, with the aspect of the system which performs the authentication, ANAF 131. Ping teaches as follows:
In general, the ANAF 131 may support authentication functions associated with
the MnSC 110 and one or more MnSP 120 in one or multiple management domains, such as identity management, credential management, and authentication policy management, etc. Paragraph [0046].
Therefore, Examiner respectfully disagrees with the conclusion that “the Examiner has mapped the ANAF 131 to the claimed management service outsourcing device but instead believes that the MnSC 110 probably is better mapped to the management service outsourcing device.” With respect to the term “mapped” in this argument, Examiner notes that a database is disclosed that stores registration information. Ping teaches the “the IF 301 may record the registration procedures of the MnSP 120 in database” (paragraph [0065]). Examiner respectfully disagrees with the statement that “Examiner has mapped the ANAF 131 to the claimed management service outsourcing device,” since Ping defines the ANAF as an Authentication Administrative Function which “supports authentication functions associated with the MnSC 110 and one or more MnSP 120 in one or multiple management domains, such as identity management, credential management, and authentication policy management” (paragraph [0046]).
Regarding the supposed lack of a network management capability, Applicant next argues as follows:
The Examiner never actually identified, in the Office action, any network management capability that is seen as both exposed to the ACF 130 and invoked by the ANAF 131, or by the MnSC 110. The Applicant believes, however, that the Examiner may be citing paragraph [0080] in this regard. Paragraph [0080] notes that "the security policy may be updated dynamically," that is, dynamically updating a security policy could be seen as an example of the claimed network management capability.
Examiner respectfully disagrees that a network management capability was not identified. The analysis regarding the first limitation of Claim 1 includes the statement that:
The ANAF 131 supports authentication functions associated with the MnSC 110, who can be a human consumer, and one or more MnSP 120 in one or multiple management domains, such as identity management, credential management, and authentication policy management ([0046]).
It is well known in the networking arts that authentication is an important aspect of network management. Therefore, Examiner respectfully disagrees with Applicant’s conclusion that a network management capability was not identified in the Ping disclosure, since authentication of network entities is performed.
Regarding security policy, Applicant next argues that:
[N]either the ANAF 131 or the MnSC 110 is configured to invoke the network management capability of dynamically updating the security policy, this network management capability is invoked instead by the IF 301. Accordingly, Ping et al. does not teach a management service outsourcing device configured to invoke a network management capability exposed to a third-party device.
It is not clear what claim limitation is being argued, since none of the claims recite “dynamically updating the security policy.” Therefore, Examiner respectfully disagrees that this argument is relevant to the instant claim rejections.
Regarding information about a management service, Applicant’s next argument is as follows:
Lastly, the information about the management service outsourcing device is required by claim 1 to comprise information about a management service that can be invoked by the management service outsourcing device. That is, if the claimed information about the management service outsourcing device were information about the ANAF 131, then the information about the ANAF 131 would need to include information about a management service that the ANAF 131 can invoke. Similarly, if the claimed information about the management service outsourcing device were information about the MnSC 110, then the information about the MnSC 110 would need to include information about a management service that the MnSC 110 can invoke. Above, the Applicant discussed the claimed network management capability, but this is a different claim limitation than the management service. The rejection also fails to indicate what the management service might be in Ping et al. The Applicant cannot find a management service in Ping et al. that is invoked by either ANAF 131 or MnSC 110 that is different from the network management capability of dynamically updating the security policy. Thus, Ping et al. does not teach that the information about the management service outsourcing device comprises information about a management service.
Applicant’s argument appears to be with respect to the last portion of the Claim 1 “receiving” limitation, which recites “the information about the management service outsourcing device comprises information about a management service that can be invoked by the management service outsourcing device.” Examiner respectfully disagrees with the conclusion that Ping does not teach the subject matter.
The Office Action states that “[t]he ANAF 131 and ARAF 132 update identity status, authentication policies and access control policies according to security status change of the MnSC and MnSP received from Analytics or intelligence function ([0080]).” Clearly, the “identity status, authentication policies and access control policies according to security status change” constitute information about the MnSP, which is the management service that is shown as being invoked. Therefore, the argument is not persuasive.
Regarding the last two steps of Claim 1, Applicant next argues as follows:
Claim 1 has two additional steps. One is a determining step, performed by the exposure governance management function entity, the IF 301 of Ping et al., and based on the information (e.g., the identity status, authentication policies, and access control policies) about the management service outsourcing device (either ANAF 131 or MnSC 110). This step determines information used for authenticating an identity of the management service outsourcing device (either ANAF 131 or MnSC 110). The Examiner here cited paragraph [0072] which teaches that the IF 301 interacts with the ANAF 131 to authenticate the MnSC 110. Here, what is determined is whether the MnSC 110 can be authenticated, and the authentication is performed by the IF 301.
Applicant does not seem to argue against the Office Action interpretation of the two limitations, but instead merely cites paragraph [0072]. Examiner believes that paragraph [0072] fully discloses the steps of “determining … information used for authenticating an identity of the management service outsourcing device” and “sending the information used for authenticating the identity of the management service outsourcing device to the management service outsourcing device.” Paragraph [0072] of the Ping disclosure teaches as follows:
The MnSC 110 may log in 412 IF 301 with identity and credential in
agreed authentication mechanism(s), which are obtained in the registration process. The IF 301, as authentication enforcement point, may interact with ANAF 131, to authenticate 416 the MnSC 110 based on agreed authentication policy, as well as the security context of the identity of the MnSC 110 (e.g. time, place, security status of the identity, etc.).
Examiner respectfully disagrees with the statement that the “the authentication is performed by the IF 301.” IF 301 is defined as an “authentication enforcement point,” but it is ANAF131 that performs the authentication of MnSC 110.
Regarding the determining step of Claim 1, Applicant next argues as follows:
Claim 1 has two additional steps. One is a determining step, performed by the exposure governance management function entity, the IF 301 of Ping et al., and based on the information (e.g., the identity status, authentication policies, and access control policies) about the management service outsourcing device (either ANAF 131 or MnSC 110). This step determines information used for authenticating an identity of the management service outsourcing device
(either ANAF 131 or MnSC 110). The Examiner here cited paragraph [0072] which teaches that the IF 301 interacts with the ANAF 131 to authenticate the MnSC 110. Here, what is determined is whether the MnSC 110 can be authenticated, and the authentication is performed by the IF 301.
Examiner respectfully disagrees. As was state above, IF 301 is defined as an “authentication enforcement point,” but it is ANAF131 that performs the authentication of MnSC 110.
Regarding the limitation that recites the sending of authentication information, Applicant next argues as follows:
The final step of claim 1 is sending, by the exposure governance management function entity (seen as IF 301), the information used for authenticating the identity of the management service outsourcing device (namely, the authentication of ANAF 131 or MnSC 110) to the management service outsourcing device (ANAF 131 or MnSC 110). As noted above, the Examiner here seems to have come around to the Applicant's position that the MnSC 110 better aligns with the claimed management service outsourcing device. Here, the Examiner cited paragraph [0074] with the note that the "indication of the authentication status of the MnSC maps to the claimed "information used for authenticating an identity." But in Ping et al., "[a]fter the MnSC 110 is authenticated, the ANAF 131 (not the IF 301) sends "an indication of the authentication status ... to the ARAF 132" (paragraph [0074]). Therefore, Ping et al. does not teach sending, by an exposure governance management function entity, to a management service outsourcing device, information used for authenticating an identity of the management service outsourcing device.
Examiner respectfully disagrees. The Office Action notes that “The indication of the authentication status of the MnSC is equivalent to “information used for authenticating an identity.” As is shown in figure 1 of the Ping disclosure, both the ANAF and the ARAF are components of the access control function (ASF 130), and as stated in paragraph [0045], “both the MnSC 110 and the MnSP 120 … interact with the ACF 130.” In other words, both MnSC 110 and MnSP 120 are authenticated via ACF 130. The term “management service outsourcing device” is not used in the Ping disclosure, and to further define exactly what it is, the instant specification states as follows:
The exposure governance management function entity determines, based on the information about the management service outsourcing device, information used for authenticating an identity of the management service outsourcing device. The exposure governance management function entity sends the information used for authenticating the identity of the management service outsourcing device to the management service outsourcing device. Specification, paragraph [0007], emphasis added.
Applicant states that: “the Examiner here seems to have come around to the Applicant's position that the MnSC 110 better aligns with the claimed management service outsourcing device.” Examiner agrees with Applicant’s interpretation, since the Office Action states as follows:
[After the MnSC 110 is authenticated, the ANAF 131 sends an indication of the authentication status of the MnSC 110 to the ARAF 132 and synchronizes the identity information of the MnSC 110 with authorization system ([0074]).] (NOTE: The indication of the authentication status of the MnSC is equivalent to “information used for authenticating an identity.”)
In addition, figures 1 and 4 show that the ACF 130, which comprises both the ANAF 131 and ARAF 132, perform the authentication for both the MnSC 110 and MnSP 120, both of which may be seen as “management service outsourcing devices.”
Therefore, it appears that no difference exists between Applicant’s interpretation of the “sending” limitation and that provided in the Office Action.
Regarding the patentability of Claim 1, Applicant concludes the analysis as follows:
For all of these reasons the Applicant contends that claim 1 is patentable over the combination of Ping et al. and 3GPP TS. Accordingly, the Applicant requests that the Examiner withdraw the rejection of claim 1, and the rejections of claims 2-5 depending therefrom, under 35 U.S.C. 103. Independent claims 6, 9, and 14 are similarly patentable over Ping et al. in view of 3GPP TS. the Applicant therefore requests that the Examiner withdraw the rejections of claims 6, 9, and 14, and the rejections of claims 7 and 8, 10-13, and 15-20 depending therefrom, under 35 U.S.C. 103.
For all the reasons stated above, Examiner respectfully disagrees. The rejection of Claim 1 under 35 U.S.C. 103 has been sustained.
Regarding the rejection of Claim 4, Applicant next argues as follows:
The Applicant would like to additionally note the further patentability of claim 4. Claim 4 requires, in part, that the information about the management service outsourcing device comprises an internet protocol (IP) address of the management service outsourcing device. The one cited paragraph of Ping et al. (paragraph [0074]) says nothing about an IP address. Claim 20 is also further patentable for the same reason.
It is not clear what networking protocol Applicant believes is being utilized in the Ping network if not IP, but there are several indications that it is an IP-based network.
First and most clearly, Ping discloses:
[I]t is difficult to make sure IP address or FQDN of the client in the client request is same to subject or subject Alternative of the client certificate, especially if they're in different network domains,” where FQDN is an acronym for fully qualified domain name. Ping, paragraph [0040], emphasis added.
Since the “IP address” is directly mentioned in this paragraph, it would be reasonable to assume that the network of the Ping invention is an Internet Protocol based network, and therefore, IP addresses are inherent in the invention.
Ping also discloses evidence that the network is IP-based by the following:
Especially the Zero touch network and Service Management (ZSM) framework enables integration and coordination between multiple management domains to support zero-touch service management and orchestration. Ping, paragraph [0002].
Especially the Zero touch network and Service Management (ZSM) framework enables integration and coordination between multiple management domains to support zero-touch service management and orchestration. 3GPP related management system could be one or more management domain(s) of ZSM framework. The different management domains may belong to different administrative domains. Ping, paragraph [0035].
Since it is well-known in the networking arts that a ZSM framework operates across IP-based networks and relies on standard IP networking for communication between management domains, it is apparent that IP is the protocol used in the Ping invention, and that the addresses being utilized are IP addresses.
Therefore, the argument is not persuasive, and the rejection of Claim 4 has been sustained.
Regarding the rejection of Claim 5, Applicant next argues as follows:
The Applicant would additionally like to note the further patentability of claim 5. Claim 5 requires, in part, "receiving ... indication information [that] indicates the exposure governance management function entity to perform one or more operations of addition, deletion, modification, or query." The Examiner alleged that 3GPP TS teaches the equivalent of addition by virtue of teaching "additional management service abstraction." The Applicant points out that the additional management service abstraction is not, strictly speaking, the same thing as addition, rather it is portrayed as "equivalent to" addition, but no explanation is given to support this allegation of equivalence. Claims 8 and 18 are also further patentable for the same reason.
3GPP teaches in Section A.2 “Utilization of management services in network function management” that additional management service abstraction may be needed based on NF management services because of lack of trust relationship. Therefore, a person of ordinary skill in the art would presume that the operation of addition would be performed in some situations. The Office Actions explains that the additional management service abstraction is equivalent to “management function entity to perform one or more operation of addition,” and this is consistent with the requirement under MPEP 2111, that “the pending claims must be given their broadest reasonable interpretation consistent with the specification." Applicant’s argument is not persuasive, and Claims 5, 8, and 18 remain as rejected.
Applicant’s arguments conclude with the statement that “All claims are allowable, and the Applicant therefore requests a Notice of Allowance.” However, Examiner respectfully disagrees and the instant Office Action has maintained the claim rejections.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or non-obviousness.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Ping Jing et al. (WO 2022/000155 A1, hereinafter referred to as Ping Jing) in view of “Management and orchestration; Architecture framework (3GPP TS 128.533 version 16.7.0 Release 16)", 30 April 2021 (2021-04-30), pages 1-32, XP093278007 (hereinafter referred to as . 3GPP TS 128.533).
Regarding Claim 1,
Ping Jing teaches:
“receiving, …, information about a management service outsourcing device from a third-party device, wherein the management service outsourcing device is configured to invoke a network management capability exposed to the third-party device, and the information about the management service outsourcing device comprises information about a management service that can be invoked by the management service outsourcing device” (paragraphs [0043], [0045], [0046], [0080]; fig. 1, elements 110, 130, 131, 132, 140). [An access control function (ACF) 130 comprises an Authentication Administrative Function (ANAF) 131 and an Authorization Administrative Function (ARAF) 132 ([0043]). The Management Service Consumer (MnSC) 110 and the Management Service Provider (MnSP) 120 interact with the access control enforcement point 140 and interact with the ACF 130 via the access control enforcement point 140, respectively; the access control enforcement point 140 can be implemented as an Integration Fabric (IF) or an Exposure Governance Management Function (EGMF) ([0045]). The ANAF 131 supports authentication functions associated with the MnSC 110, who can be a human consumer, and one or more MnSP 120 in one or multiple management domains, such as identity management, credential management, and authentication policy management ([0046]). The ANAF 131 and ARAF 132 update identity status, authentication policies and access control policies according to security status change of the MnSC and MnSP received from Analytics or intelligence function ([0080]).] (NOTE: The Authentication Administrative Function (ANAF) is equivalent to the “management service outsourcing device that invokes a network management capability,” the access control function (ACF) to the “third-party device,” and the identity status, authentication policies and access control policies to the “information about a management service.”)
“determining, … based on the information about the management service outsourcing device, information used for authenticating an identity of the management service outsourcing device” (paragraph [0072]; fig. 1, elements 110, 131; fig. 3, element 301). [The MnSC 110 logs in to IF 301 with identity and credential in agreed authentication mechanism(s), which are obtained in the registration process, and the IF 301, as authentication enforcement point, interact with ANAF 131, to authenticate the MnSC 110 based on agreed authentication policy, as well as the security context of the identity of the MnSC 110 ([0072]).] (NOTE: The authentication policy, as well as the security context of the identity of the MnSC are equivalent to “information used for authenticating an identity.”)
“sending, … the information used for authenticating the identity of the management service outsourcing device to the management service outsourcing device” (paragraph [0074]; Fig. 1, elements 110, 131, 132,). [After the MnSC 110 is authenticated, the ANAF 131 sends an indication of the authentication status of the MnSC 110 to the ARAF 132 and synchronizes the identity information of the MnSC 110 with authorization system ([0074]).] (NOTE: The indication of the authentication status of the MnSC is equivalent to “information used for authenticating an identity.”)
Ping Jing makes reference to, but does not specifically teach:
“exposure governance management function entity.”
3GPP TS 128.533 teaches:
“exposure governance management function entity” Exposure governance management function (EGMF) shown in Figure A.2.1 is management function in network function model with the role of management service exposure governance (i.e. abstraction, simplification, filtering, etc.). When multiple NF management services are exposed to network management, the particular group of multiple NF management services can be represented by a set of NF management services function management (Section A.2 Utilization of management services in network).
Both Ping Jing and 3GPP TS 128.533 teach systems authentication of devices on the network, and those systems are comparable to that of the instant application. Because the two cited references are analogous to the instant application, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, to include in the Ping Jing disclosure, the use of Exposure Governance Management Function (EGMF), as taught by 3GPP TS 128.533. Such inclusion would have provided autonomous management and heterogeneity at all levels of the network, and would have been consistent with the rationale of using known techniques to improve similar devices (methods, or products) in the same way to show a prima facie case of obviousness (MPEP 2143(I)(C)) under KSR International Co. v. Teleflex Inc., 127 S. Ct. 1727, 82 USPQ2d 1385, 1395-97 (2007).
Regarding Claim 6,
Ping Jing teaches:
“sending, by a third-party device, information about a management service outsourcing device to an … entity, wherein the management service outsourcing device is configured to invoke a network management capability exposed to the third-party device, and the information about the management service outsourcing device comprises information about a management service that can be invoked by the management service outsourcing device” (paragraphs [0043], [0045], [0074]; fig. 1, elements 110, 130, 131, 132, 140 ). [An access control function (ACF) 130 comprises an Authentication Administrative Function (ANAF) 131 and an Authorization Administrative Function (ARAF) 132 ([0043]). The Management Service Consumer (MnSC) 110 and the Management Service Provider (MnSP) 120 interact with the access control enforcement point 140 and interact with the ACF 130 via the access control enforcement point 140, respectively; the access control enforcement point 140 can be implemented as an Integration Fabric (IF) or an Exposure Governance Management Function (EGMF) ([0045]). After the MnSC 110 is authenticated, the ANAF 131 may send an indication of the authentication status of the MnSC 110 to the ARAF 132 and synchronize the identity information of the MnSC 110 with authorization system ([0074]). (NOTE: The Authentication Administrative Function (ANAF) is equivalent to the “management service outsourcing device that invokes a network management capability,” the access control function (ACF) to the “entity,” and the identity status, authentication policies and access control policies to the “information about a management service that can be invoked by the management service outsourcing device.”)
“receiving, by the third-party device from the … entity, information used for authenticating an identity of the management service outsourcing device that is determined based on the information about the management service outsourcing device” (paragraph [0072]; fig. 1, elements 110, 131; fig. 3, element 301). [The MnSC 110 logs in to IF 301 with identity and credential in agreed authentication mechanism(s), which are obtained in the registration process, and the IF 301, as authentication enforcement point, interact with ANAF 131, to authenticate the MnSC 110 based on agreed authentication policy, as well as the security context of the identity of the MnSC 110 ([0072]).] (NOTE: The authentication policy, as well as the security context of the identity of the MnSC are equivalent to “information used for authenticating an identity.”)
“sending, by the third-party device, the information used for authenticating the identity of the management service outsourcing device to the management service outsourcing device” (paragraph [0080]). [The ANAF 131 and ARAF 132 update identity status, authentication policies and access control policies according to security status change of the MnSC and MnSP received from Analytics or intelligence function ([0080]; fig. 1, elements 131, 132).] (NOTE: The identity status, authentication policies and access control policies are equivalent to the “information used for authenticating the identity of the management service outsourcing device.”)
Ping Jing makes reference to, but does not specifically teach:
“exposure governance management function entity.”
3GPP TS 128.533 teaches:
“exposure governance management function entity” [Exposure governance management function (EGMF) shown in Figure A.2.1 is management function in network function model with the role of management service exposure governance (i.e. abstraction, simplification, filtering, etc.). When multiple NF management services are exposed to network management, the particular group of multiple NF management services can be represented by a set of NF management services function management (Section A.2 Utilization of management services in network).
Both Ping Jing and 3GPP TS 128.533 teach systems authentication of devices on the network, and those systems are comparable to that of the instant application. Because the two cited references are analogous to the instant application, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, to include in the Ping Jing disclosure, the use of Exposure Governance Management Function (EGMF), as taught by 3GPP TS 128.533. Such inclusion would have provided autonomous management and heterogeneity at all levels of the network, and would have been consistent with the rationale of using known techniques to improve similar devices (methods, or products) in the same way to show a prima facie case of obviousness (MPEP 2143(I)(C)) under KSR International Co. v. Teleflex Inc., 127 S. Ct. 1727, 82 USPQ2d 1385, 1395-97 (2007).
Regarding Claim 9,
Ping Jing teaches:
“obtaining, by a first device, authentication information, wherein the first device is a management service outsourcing device, and the management service outsourcing device is configured to invoke a network management capability exposed to a third-party device” (paragraphs [0080]; fig. 1, elements 110, 120, 131, 132). [The ANAF 131 supports authentication functions associated with the MnSC 110, who can be a human consumer, and one or more MnSP 120 in one or multiple management domains, such as identity management, credential management, and authentication policy management ([0046]). The Authentication Administrative Function (ANAF) 131 and ARAF 132 update identity status, authentication policies and access control policies according to security status change of the Management Service Consumer (MnSC) and the Management Service Provider (MnSP) received from Analytics or intelligence function ([0080]).] (NOTE: The Authentication Administrative Function (ANAF) is equivalent to the “management service outsourcing device,” the identity management, credential management, and authentication policy management to “a network management capability,” and the identity status, authentication policies and access control policies to the “information about a management service.”)
“sending, by the first device, the authentication information …” (paragraph [0074]; fig. 1, elements 110, 131, 132). [After the MnSC 110 is authenticated, the ANAF 131 may send an indication of the authentication status of the MnSC 110 to the ARAF 132 and synchronize the identity information of the MnSC 110 with authorization system ([0074]).] (NOTE: The indication of the authentication status of the MnSC is equivalent to “the authentication information.”)
Ping Jing makes reference to, but does not specifically teach:
“exposure governance management function entity.”
3GPP TS 128.533 teaches:
“exposure governance management function entity” [Exposure governance management function (EGMF) shown in Figure A.2.1 is management function in network function model with the role of management service exposure governance (i.e. abstraction, simplification, filtering, etc.). When multiple NF management services are exposed to network management, the particular group of multiple NF management services can be represented by a set of NF management services function management (Section A.2 Utilization of management services in network).
Both Ping Jing and 3GPP TS 128.533 teach systems authentication of devices on the network, and those systems are comparable to that of the instant application. Because the two cited references are analogous to the instant application, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, to include in the Ping Jing disclosure, the use of Exposure Governance Management Function (EGMF), as taught by 3GPP TS 128.533. Such inclusion would have provided autonomous management and heterogeneity at all levels of the network, and would have been consistent with the rationale of using known techniques to improve similar devices (methods, or products) in the same way to show a prima facie case of obviousness (MPEP 2143(I)(C)) under KSR International Co. v. Teleflex Inc., 127 S. Ct. 1727, 82 USPQ2d 1385, 1395-97 (2007).
Regarding Claim 14,
Ping Jing teaches:
“a first device and an exposure governance management function entity, wherein the exposure governance management function entity is configured” (paragraphs [0033], [0045]). [The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), and other devices ([0033]). The access control enforcement point 140 can be implemented as an Exposure Governance Management Function (EGMF) ([0045]).]
“receive information about a management service outsourcing device that comprises information about a management service that can be invoked by the management service outsourcing device” ” (paragraphs [0043], [0046], [0080]; fig. 1, elements 110, 130, 131, 132,). [An access control function (ACF) 130 comprises an Authentication Administrative Function (ANAF) 131 and an Authorization Administrative Function (ARAF) 132 ([0043]). The ANAF 131 supports authentication functions associated with the MnSC 110, who can be a human consumer, and one or more MnSP 120 in one or multiple management domains, such as identity management, credential management, and authentication policy management ([0046]). The ANAF 131 and ARAF 132 update identity status, authentication policies and access control policies according to security status change of the MnSC and MnSP received from Analytics or intelligence function ([0080]).] (NOTE: The Authentication Administrative Function (ANAF) is equivalent to the “management service outsourcing device that invokes a network management capability” and the identity status, authentication policies and access control policies to the “information about a management service that can be invoked by the management service outsourcing device.”)
“determine, based on the information about the management service outsourcing device, information used for authenticating an identity of the management service outsourcing device” (paragraph [0072]; fig. 1, elements 110, 131; fig. 3, element 301). [The MnSC 110 logs in to IF 301 with identity and credential in agreed authentication mechanism(s), which are obtained in the registration process, and the IF 301, as authentication enforcement point, interact with ANAF 131, to authenticate the MnSC 110 based on agreed authentication policy, as well as the security context of the identity of the MnSC 110 ([0072]).] (NOTE: The authentication policy, as well as the security context of the identity of the MnSC are equivalent to “information used for authenticating an identity.”)
“send the information used for authenticating the identity of the management service outsourcing device to the management service outsourcing device” (paragraph [0074]; fig. 1, elements 110, 131, 132,). [After the MnSC 110 is authenticated, the ANAF 131 may send an indication of the authentication status of the MnSC 110 to the ARAF 132 and synchronize the identity information of the MnSC 110 with authorization system ([0074]).] (NOTE: The indication of the authentication status of the MnSC is equivalent to “information for authenticating an identity.”)
“the first device is configured to receive the information used for authenticating the identity of the management service outsourcing device” (paragraph [0072]; fig. 1, elements 110, 131; fig. 3, element 301). [The MnSC 110 logs in to IF 301 with identity and credential in agreed authentication mechanism(s), which are obtained in the registration process, and the IF 301, as authentication enforcement point, interact with ANAF 131, to authenticate the MnSC 110 based on agreed authentication policy, as well as the security context of the identity of the MnSC 110 ([0072]).] (NOTE: The authentication policy, as well as the security context of the identity of the MnSC are equivalent to “information used for authenticating an identity.”)
“send authentication information …” (paragraph [0074]; fig. 1, elements 110, 131, 132). [After the MnSC 110 is authenticated, the ANAF 131 may send an indication of the authentication status of the MnSC 110 to the ARAF 132 and synchronize the identity information of the MnSC 110 with authorization system ([0074]).] (NOTE: The indication of the authentication status of the MnSC is equivalent to “the authentication information.”)
Ping Jing makes reference to, but does not specifically teach:
“exposure governance management function entity.”
3GPP TS 128.533 teaches:
“exposure governance management function entity” [Exposure governance management function (EGMF) shown in Figure A.2.1 is management function in network function model with the role of management service exposure governance (i.e. abstraction, simplification, filtering, etc.). When multiple NF management services are exposed to network management, the particular group of multiple NF management services can be represented by a set of NF management services function management (Section A.2 Utilization of management services in network).
Both Ping Jing and 3GPP TS 128.533 teach systems authentication of devices on the network, and those systems are comparable to that of the instant application. Because the two cited references are analogous to the instant application, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, to include in the Ping Jing disclosure, the use of Exposure Governance Management Function (EGMF), as taught by 3GPP TS 128.533. Such inclusion would have provided autonomous management and heterogeneity at all levels of the network, and would have been consistent with the rationale of using known techniques to improve similar devices (methods, or products) in the same way to show a prima facie case of obviousness (MPEP 2143(I)(C)) under KSR International Co. v. Teleflex Inc., 127 S. Ct. 1727, 82 USPQ2d 1385, 1395-97 (2007).
Regarding Claims 2 and 17,
Ping Jing in view of 3GPP TS 128.533 teaches all the limitations of parent Claims 1 and 14:
Ping Jing teaches:
“when the authentication information matches the information used for authenticating the identity of the management service outsourcing device, determining, by the exposure governance management function entity, that the first device is the management service outsourcing device” [The ANAF 131 and ARAF 132 update identity status, authentication policies and access control policies according to security status change of the MnSC and MnSP received from Analytics or intelligence function ([0080]).]
Ping Jing makes reference to, but does not specifically teach:
“exposure governance management function entity.”
3GPP TS 128.533 teaches:
“exposure governance management function entity” [Exposure governance management function (EGMF) shown in Figure A.2.1 is management function in network function model with the role of management service exposure governance (i.e. abstraction, simplification, filtering, etc.). When multiple NF management services are exposed to network management, the particular group of multiple NF management services can be represented by a set of NF management services function management (Section A.2 Utilization of management services in network).
Both Ping Jing and 3GPP TS 128.533 teach systems authentication of devices on the network, and those systems are comparable to that of the instant application. Because the two cited references are analogous to the instant application, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, to include in the Ping Jing disclosure, the use of Exposure Governance Management Function (EGMF), as taught by 3GPP TS 128.533. Such inclusion would have provided autonomous management and heterogeneity at all levels of the network, and would have been consistent with the rationale of using known techniques to improve similar devices (methods, or products) in the same way to show a prima facie case of obviousness (MPEP 2143(I)(C)) under KSR International Co. v. Teleflex Inc., 127 S. Ct. 1727, 82 USPQ2d 1385, 1395-97 (2007).
Regarding Claim 3,
Ping Jing in view of 3GPP TS 128.533 teaches all the limitations of parent Claim 2.
Ping Jing teaches:
“sending, by the exposure governance management function entity, first indication information to the first device, wherein the first indication information indicates that authentication on the first device succeeds” (paragraphs [0040], [0072]; fig. 1, elements 110, 131; fig. 3, element 301). [MnS consumer can be dynamically changed to make sure IP address is correct ([0040]). The MnSC 110 logs in to IF 301 with identity and credential in agreed authentication mechanism(s), which are obtained in the registration process, and the IF 301, as authentication enforcement point, interact with ANAF 131, to authenticate the MnSC 110 based on agreed authentication policy, as well as the security context of the identity of the MnSC 110 ([0072]).]
Ping Jing makes reference to, but does not specifically teach:
“exposure governance management function entity.”
3GPP TS 128.533 teaches:
“exposure governance management function entity” [Exposure governance management function (EGMF) shown in Figure A.2.1 is management function in network function model with the role of management service exposure governance (i.e. abstraction, simplification, filtering, etc.). When multiple NF management services are exposed to network management, the particular group of multiple NF management services can be represented by a set of NF management services function management (Section A.2 Utilization of management services in network).
Both Ping Jing and 3GPP TS 128.533 teach systems authentication of devices on the network, and those systems are comparable to that of the instant application. Because the two cited references are analogous to the instant application, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, to include in the Ping Jing disclosure, the use of Exposure Governance Management Function (EGMF), as taught by 3GPP TS 128.533. Such inclusion would have provided autonomous management and heterogeneity at all levels of the network, and would have been consistent with the rationale of using known techniques to improve similar devices (methods, or products) in the same way to show a prima facie case of obviousness (MPEP 2143(I)(C)) under KSR International Co. v. Teleflex Inc., 127 S. Ct. 1727, 82 USPQ2d 1385, 1395-97 (2007).
Regarding Claim 4,
Ping Jing in view of 3GPP TS 128.533 teaches all the limitations of parent Claim 1.
Ping Jing teaches:
“sending, by the exposure governance management function entity, the information used for authenticating the identity of the management service outsourcing device to the management service outsourcing device based on the IP address of the management service outsourcing device” (paragraph [0074]; fig. 1, elements 110, 131, 132). [After the MnSC 110 is authenticated, the ANAF 131 may send an indication of the authentication status of the MnSC 110 to the ARAF 132 and synchronize the identity information of the MnSC 110 with authorization system ([0074]).] (NOTE: The indication of the authentication status of the MnSC is equivalent to “indication information.”)
Ping Jing makes reference to, but does not specifically teach:
“exposure governance management function entity.”
3GPP TS 128.533 teaches:
“exposure governance management function entity” [Exposure governance management function (EGMF) shown in Figure A.2.1 is management function in network function model with the role of management service exposure governance (i.e. abstraction, simplification, filtering, etc.). When multiple NF management services are exposed to network management, the particular group of multiple NF management services can be represented by a set of NF management services function management (Section A.2 Utilization of management services in network).
Both Ping Jing and 3GPP TS 128.533 teach systems authentication of devices on the network, and those systems are comparable to that of the instant application. Because the two cited references are analogous to the instant application, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, to include in the Ping Jing disclosure, the use of Exposure Governance Management Function (EGMF), as taught by 3GPP TS 128.533. Such inclusion would have provided autonomous management and heterogeneity at all levels of the network, and would have been consistent with the rationale of using known techniques to improve similar devices (methods, or products) in the same way to show a prima facie case of obviousness (MPEP 2143(I)(C)) under KSR International Co. v. Teleflex Inc., 127 S. Ct. 1727, 82 USPQ2d 1385, 1395-97 (2007).
Regarding Claims 5, 8, and 18,
Ping Jing in view of 3GPP TS 128.533 teaches all the limitations of parent Claim 1.
Ping Jing teaches:
“receiving, …, second indication information from the third-party device” (paragraph [0074]; fig. 1, elements 110, 131, 132). [After the MnSC 110 is authenticated, the ANAF 131 sends an indication of the authentication status of the MnSC 110 to the ARAF 132 and synchronize the identity information of the MnSC 110 with authorization system ([0074]).] (NOTE: The indication of the authentication status of the MnSC is equivalent to “indication information.”)
Ping Jing does not teach:
“exposure governance management function entity.”
“wherein the second indication information indicates the exposure governance management function entity to perform one or more operations of addition, deletion, modification, or query on the information about the management service outsourcing device.”
3GPP TS 128.533 teaches:
“exposure governance management function entity” [Exposure governance management function (EGMF) shown in Figure A.2.1 is management function in network function model with the role of management service exposure governance (i.e. abstraction, simplification, filtering, etc.). When multiple NF management services are exposed to network management, the particular group of multiple NF management services can be represented by a set of NF management services function management; NF management services are exposed as a bulk NF management service, by NF management function, and additional management service abstraction may be needed based on NF management services because of lack of trust relationship between management service provider/consumer cannot address management services (Section A.2 Utilization of management services in network).] (NOTE: The additional management service abstraction is equivalent to “management function entity to perform one or more operation of addition.)
Both Ping Jing and 3GPP TS 128.533 teach systems authentication of devices on the network, and those systems are comparable to that of the instant application. Because the two cited references are analogous to the instant application, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, to include in the Ping Jing disclosure, the use of Exposure Governance Management Function (EGMF), as taught by 3GPP TS 128.533. Such inclusion would have provided autonomous management and heterogeneity at all levels of the network, and would have been consistent with the rationale of using known techniques to improve similar devices (methods, or products) in the same way to show a prima facie case of obviousness (MPEP 2143(I)(C)) under KSR International Co. v. Teleflex Inc., 127 S. Ct. 1727, 82 USPQ2d 1385, 1395-97 (2007).
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to PHYLLIS A BOOK whose telephone number is (571)272-0698. The examiner can normally be reached M-F 10:00 am - 7:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, GLENTON BURGESS can be reached at 571-272-3949. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/PHYLLIS A BOOK/Primary Examiner, Art Unit 2454