Prosecution Insights
Last updated: October 01, 2026
Application No. 18/984,893

SECURITY KEY UPDATE IN WIRELESS NETWORKS

Final Rejection §102§103
Filed
Dec 17, 2024
Priority
Jan 04, 2024 — provisional 63/617,611 +2 more
Examiner
NGUYEN, TRONG H
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Samsung Electronics Co., Ltd.
OA Round
2 (Final)
80%
Grant Probability
Favorable
3-4
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
446 granted / 560 resolved
+21.6% vs TC avg
Strong +57% interview lift
Without
With
+57.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
14 currently pending
Career history
570
Total Applications
across all art units

Statute-Specific Performance

§101
14.5%
-25.5% vs TC avg
§103
44.5%
+4.5% vs TC avg
§102
17.3%
-22.7% vs TC avg
§112
16.7%
-23.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 560 resolved cases

Office Action

§102 §103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-20 are pending. The 35 U.S.C. 112(b) rejection has been withdrawn in view of the claim amendment. Response to Arguments Applicant's arguments filed on 07/02/26 regarding the amended limitations in the independent claims have been fully considered but are moot in view of the new grounds of rejection presented below in view of newly found prior art. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1, 10, and 19 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Maemoto (US 20260230816). Claim 1, Maemoto discloses An electronic device comprising: at least one processor including processing circuitry; and memory storing instructions, wherein the instructions, when executed by the at least one processor individually or collectively, cause the electronic device to: (e.g. fig. 4, ¶32) receive, from a serving cell, a radio resource control (RRC) reconfiguration message including master security key update information for one or more candidate cells; (e.g. figs. 6, 8, ¶17, 123, 148-154: FIG. 8 is a diagram for describing a hierarchical structure of an RRC reconfiguration message according to the embodiment…The transmitter 211 of the base station 201 transmits the RRC reconfiguration message including the LTM configuration information to the UE 100. The receiver 112 of the UE 100 receives the RRC reconfiguration message from the base station 201 as the RRC message. The controller 120 of the UE 100 stores the LTM configuration information…The controller 120 performs the security key update procedure. For example, the controller 120 performs the security key update procedure based on the information for the security key update procedure included in the RRC reconfiguration information (RRC reconfiguration message) included in the LTM candidate configuration information (for example, ltm-CandidateConfig) of the candidate cell corresponding to the target cell. The controller 120 derives or updates the security key based on the information for the security key update procedure (hereinafter, may be referred to as key update information). The key update information may include, for example, at least one of the following information. Master key update information (for example, “MasterKeyUpdate”) Security key Identifier of the algorithm selected for a data radio bearer (DRB) and/or a signalling radio bearer (SRB) requested for the UE 100. [0153] UP integrity protection and encryption indication Counter information (for example, “sk-Counter” and “sk-counter-list”)). receive, from the serving cell, a medium access control (MAC) control element (CE) including a command indicating that a cell switch from the serving cell to a target cell among the one or more candidate cells is triggered; (e.g. fig. 6, ¶142: The transmitter 211 of the base station 201 transmits the cell switch command to the UE 100 by the MAC CE. The receiver 112 of the UE 100 receives the cell switch command from the base station 201 by the MAC CE.) perform the cell switch from the serving cell to the target cell; and (e.g. fig. 6, ¶143, 145: The controller 120 of the UE 100 performs the first cell switch according to the LTM configuration information in a case where the cell switch command is received from the base station 200 by the MAC CE.) perform a security update for the target cell based on master security key update information associated with the target cell. (e.g. fig. 6, ¶148-157: The controller 120 performs the security key update procedure. For example, the controller 120 performs the security key update procedure based on the information for the security key update procedure included in the RRC reconfiguration information (RRC reconfiguration message) included in the LTM candidate configuration information (for example, ltm-CandidateConfig) of the candidate cell corresponding to the target cell. The controller 120 derives or updates the security key based on the information for the security key update procedure (hereinafter, may be referred to as key update information). The key update information may include, for example, at least one of the following information. Master key update information (for example, “MasterKeyUpdate”) Security key Identifier of the algorithm selected for a data radio bearer (DRB) and/or a signalling radio bearer (SRB) requested for the UE 100. UP integrity protection and encryption indication Counter information (for example, “sk-Counter” and “sk-counter-list”)) Claims 10 and 19, these claims are rejected for similar reasons as in claim 1. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Wang (WO 2025065185) in view of Maemoto (US 20260230816). Claim 1, Wang discloses An electronic device comprising: at least one processor including processing circuitry; and memory storing instructions, wherein the instructions, when executed by the at least one processor individually or collectively, cause the electronic device to: (e.g. figs. 1A, 9, ¶28, 153-154) receive, from a serving cell, a radio resource control (RRC) reconfiguration message including update information for one or more candidate cells; (e.g. ¶64-65: The network device 120 may transmit 142 an RRC reconfiguration message to the terminal device 110 comprising a configuration (also referred to as an LTM configuration or an LTM candidate configuration herein) of one or multiple LTM candidate target cells. The terminal device 110 may store the configuration of LTM candidate target cell (s)) receive, from the serving cell, a medium access control (MAC) control element (CE) including a command indicating that a cell switch from the serving cell to a target cell among the one or more candidate cells is triggered; (e.g. fig. 1A, ¶79: Continuing to refer to FIG. 2, upon determination that an LTM cell switch from the cell 123-1 to the cell 131 is to be performed for the terminal device 110, the DU 123 may transmit 220, to the terminal device 110, a MAC CE indicating the LTM cell switch to the cell 131.) perform the cell switch from the serving cell to the target cell; and (e.g. ¶37, 71, 73, 80: Then the terminal device switches to a target candidate cell according to the cell switch command…Continuing to refer to FIG. 1A, in some scenarios, the terminal device 110 may receive a MAC CE indicating a cell switch from the cell 123-1 under control of the CU 121 to the cell 131. The cell 131 is not under control of the CU 121 or is under control of another CU. This procedure of the cell switch is called as an inter-CU LTM herein…In the solution, security key update information is included in an LTM cell switch command. In this way, a terminal device may update security keys during inter-CU LTM…If the MAC CE comprises the security key update information, the terminal device 110 may derive or update 240 a security key based on the security key update information in the MAC CE during LTM cell switch execution.) perform a security update for the target cell based on master security key update information associated with the target cell. (e.g. ¶80-85: If the MAC CE comprises the security key update information, the terminal device 110 may derive or update 240 a security key based on the security key update information in the MAC CE during LTM cell switch execution. In some embodiments, the terminal device 110 may indicate the security key update information from a MAC layer to an upper layer of the terminal device 110, and derive or update the security key by the upper layer based on the security key update information. In other words, upon reception of the LTM cell switch command MAC CE, the MAC layer of the terminal device 110 indicates the security key update information to the upper layer (e.g., RRC layer) of the terminal device 110. The RRC layer of the terminal device 110 derives or updates the security key based on the security key update information received from lower layer (e.g., MAC layer). In some embodiments, if the received indicator (e.g., key set change indicator) indicating that the key set is changed, the terminal device 110 may derive or update a master key based on a key (e.g., K.sub.AMF) for access and mobility management function (AMF). In some embodiments, the terminal device 110 may derive or update the master key (i.e., K.sub.gNB) at least based on the value of the NCC. In some embodiments, the terminal device 110 may use the received NCC value to derive or update the master key based on the current master key or a key NH (derived by mobile equipment (ME) and AMF to provide forward security). In some embodiments, the terminal device 110 may derive or update a secondary key (i.e., S-K.sub.gNB) based on the master key and the value of the received security key counter. Continuing to refer to FIG. 2, in some embodiments, if the MAC CE comprises the security key update information, the terminal device 110 may perform 250 a set of L2 procedures.) Although Wang discloses receive, from a serving cell, a radio resource control (RRC) reconfiguration message including update information for one or more candidate cells (e.g. ¶65: The network device 120 may transmit 142 an RRC reconfiguration message to the terminal device 110 comprising a configuration (also referred to as an LTM configuration or an LTM candidate configuration herein) of one or multiple LTM candidate target cells), Wang does not appear to explicitly disclose the RRC reconfiguration message including master security key update information. However, Maemoto discloses receive, from a serving cell, a radio resource control (RRC) reconfiguration message including master security key update information for one or more candidate cells (e.g. figs. 6, 8, ¶17, 123, 148-154: FIG. 8 is a diagram for describing a hierarchical structure of an RRC reconfiguration message according to the embodiment…The transmitter 211 of the base station 201 transmits the RRC reconfiguration message including the LTM configuration information to the UE 100. The receiver 112 of the UE 100 receives the RRC reconfiguration message from the base station 201 as the RRC message. The controller 120 of the UE 100 stores the LTM configuration information…The controller 120 performs the security key update procedure. For example, the controller 120 performs the security key update procedure based on the information for the security key update procedure included in the RRC reconfiguration information (RRC reconfiguration message) included in the LTM candidate configuration information (for example, ltm-CandidateConfig) of the candidate cell corresponding to the target cell. The controller 120 derives or updates the security key based on the information for the security key update procedure (hereinafter, may be referred to as key update information). The key update information may include, for example, at least one of the following information. Master key update information (for example, “MasterKeyUpdate”) Security key Identifier of the algorithm selected for a data radio bearer (DRB) and/or a signalling radio bearer (SRB) requested for the UE 100. [0153] UP integrity protection and encryption indication Counter information (for example, “sk-Counter” and “sk-counter-list”)). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the features described by Maemoto into the invention of Wang for the purpose of enabling the UE to perform the security update procedure based on the information for the security key update procedure included in the RRC reconfiguration information (RRC reconfiguration message) thereby increasing the flexibility and convenience of the system. Claim 2, Wang-Maemoto discloses The electronic device of claim 1, wherein the instructions, when executed by the at least one processor individually or collectively, further cause the electronic device to: receive, from the serving cell, a master security key update identifier for each candidate cell; (Wang, e.g. ¶76-79) maintain a variable to store a master security key update identifier for the serving cell; and perform the security update based on a determination that a master security key update identifier of the target cell is different from the master security key update identifier for the serving cell stored in the variable. (Wang, e.g. ¶80-85) Claim 3, Wang-Maemoto discloses The electronic device of claim 2, wherein the instructions, when executed by the at least one processor individually or collectively, further cause the electronic device to replace the master security key update identifier stored in the variable with the master security key update identifier of the target cell. (Wang, e.g. ¶80-85) Claim 4, Wang-Maemoto discloses The electronic device of claim 1, wherein the instructions, when executed by the at least one processor individually or collectively, further cause the electronic device to receive a list of master security update information including one or more entries for a respective candidate cell, each entry comprising master security key update information. (Wang, e.g. ¶76-79) Claim 5, Wang-Maemoto discloses The electronic device of claim 4, wherein the instructions, when executed by the at least one processor individually or collectively, further cause the electronic device to perform the security update based on master security key update information in a predetermined entry or an entry indicated in the list of master security update information associated with the target cell. (Wang, e.g. ¶80-85) Claim 6, Wang-Maemoto discloses The electronic device of claim 5, wherein the instructions, when executed by the at least one processor individually or collectively, further cause the electronic device to remove the predetermined entry or the entry indicated in the list of master security update information associated with the target cell. (Wang, e.g. ¶80-85) Claim 7, Wang-Maemoto discloses The electronic device of claim 1, wherein: the command includes a master security update information identifier associated with the target cell; (Wang, e.g. ¶76-79) and the security update is performed based on master security update information identified by the master security update information identifier. (Wang, e.g. ¶80-85) Claim 8, Wang-Maemoto discloses The electronic device of claim 7, wherein: the master security key update information associated with the target cell is included in the command. (Wang, e.g. ¶76-79) Claim 9, Wang-Maemoto discloses The electronic device of claim 1, wherein the master security key update information for one or more candidate cells includes: a first field indicating whether the UE is required to derive a new master security key; and a second field including a parameter used to derive the new master security key. (Wang, e.g. ¶76-78, 82-84) Claims 10-18, these claims are rejected for similar reasons as in claims 1-9. Claim 19, Wang discloses A method of operating a base station (BS) for facilitating communication in a wireless network, the method comprising: (e.g. figs. 1A, 9, ¶29, 42, 153-154) transmitting, to a user equipment (UE), a radio resource control (RRC) reconfiguration message including update information for one or more candidate cells; and (e.g. ¶64-65: The network device 120 may transmit 142 an RRC reconfiguration message to the terminal device 110 comprising a configuration (also referred to as an LTM configuration or an LTM candidate configuration herein) of one or multiple LTM candidate target cells. The terminal device 110 may store the configuration of LTM candidate target cell (s)) transmitting, to the UE, a medium access control (MAC) control element (CE) including a command indicating that a cell switch from a serving cell of the BS to a target cell among the one or more candidate cells is triggered, (e.g. fig. 1A, ¶79: Continuing to refer to FIG. 2, upon determination that an LTM cell switch from the cell 123-1 to the cell 131 is to be performed for the terminal device 110, the DU 123 may transmit 220, to the terminal device 110, a MAC CE indicating the LTM cell switch to the cell 131.) wherein master security key update information associated with the target cell is used for a security update for the target cell. (e.g. ¶80-85: If the MAC CE comprises the security key update information, the terminal device 110 may derive or update 240 a security key based on the security key update information in the MAC CE during LTM cell switch execution. In some embodiments, the terminal device 110 may indicate the security key update information from a MAC layer to an upper layer of the terminal device 110, and derive or update the security key by the upper layer based on the security key update information. In other words, upon reception of the LTM cell switch command MAC CE, the MAC layer of the terminal device 110 indicates the security key update information to the upper layer (e.g., RRC layer) of the terminal device 110. The RRC layer of the terminal device 110 derives or updates the security key based on the security key update information received from lower layer (e.g., MAC layer). In some embodiments, if the received indicator (e.g., key set change indicator) indicating that the key set is changed, the terminal device 110 may derive or update a master key based on a key (e.g., K.sub.AMF) for access and mobility management function (AMF). In some embodiments, the terminal device 110 may derive or update the master key (i.e., K.sub.gNB) at least based on the value of the NCC. In some embodiments, the terminal device 110 may use the received NCC value to derive or update the master key based on the current master key or a key NH (derived by mobile equipment (ME) and AMF to provide forward security). In some embodiments, the terminal device 110 may derive or update a secondary key (i.e., S-K.sub.gNB) based on the master key and the value of the received security key counter. Continuing to refer to FIG. 2, in some embodiments, if the MAC CE comprises the security key update information, the terminal device 110 may perform 250 a set of L2 procedures.) Although Wang discloses transmitting, to a user equipment (UE), a radio resource control (RRC) reconfiguration message including update information for one or more candidate cells (e.g. ¶65: The network device 120 may transmit 142 an RRC reconfiguration message to the terminal device 110 comprising a configuration (also referred to as an LTM configuration or an LTM candidate configuration herein) of one or multiple LTM candidate target cells), Wang does not appear to explicitly disclose the RRC reconfiguration message including master security key update information. However, Maemoto discloses transmitting, to a user equipment (UE), a radio resource control (RRC) reconfiguration message including master security key update information for one or more candidate cells (e.g. figs. 6, 8, ¶17, 123, 148-154: FIG. 8 is a diagram for describing a hierarchical structure of an RRC reconfiguration message according to the embodiment…The transmitter 211 of the base station 201 transmits the RRC reconfiguration message including the LTM configuration information to the UE 100. The receiver 112 of the UE 100 receives the RRC reconfiguration message from the base station 201 as the RRC message. The controller 120 of the UE 100 stores the LTM configuration information…The controller 120 performs the security key update procedure. For example, the controller 120 performs the security key update procedure based on the information for the security key update procedure included in the RRC reconfiguration information (RRC reconfiguration message) included in the LTM candidate configuration information (for example, ltm-CandidateConfig) of the candidate cell corresponding to the target cell. The controller 120 derives or updates the security key based on the information for the security key update procedure (hereinafter, may be referred to as key update information). The key update information may include, for example, at least one of the following information. Master key update information (for example, “MasterKeyUpdate”) Security key Identifier of the algorithm selected for a data radio bearer (DRB) and/or a signalling radio bearer (SRB) requested for the UE 100. [0153] UP integrity protection and encryption indication Counter information (for example, “sk-Counter” and “sk-counter-list”)). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the features described by Maemoto into the invention of Wang for the purpose of enabling the UE to perform the security update procedure based on the information for the security key update procedure included in the RRC reconfiguration information (RRC reconfiguration message) thereby increasing the flexibility and convenience of the system. Claim 20, Wang-Maemoto discloses The method of claim 19, further comprising: transmitting, to the UE, a master security key update identifier for each candidate cell. (Wang, e.g. ¶76-79) Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Maemoto (US 20260222951) discloses a communication apparatus according to an embodiment comprises: a receiver configured to: receive, from a base station, an RRC message including LTM configuration information, the LTM configuration information including information associated with a serving cell and one or more LTM candidate information configurations to be added or modified, the information associated with the serving cell being used for determining whether or not to perform a security key update procedure, and receive, from the base station, a cell switch command MAC CE that triggers an LTM cell switch procedure; and a controller configured to perform the LTM cell switch procedure based on the cell switch command MAC CE. The controller is configured to determine, based on the information associated with the serving cell included in the LTM configuration information, whether or not to perform the security key update procedure in a case where the LTM cell switch procedure is performed. Lu (WO 2023010367 A1) discloses the RRC reconfiguration message is used to transfer the terminal equipment from the first cell to the second cell; since the first cell and the second cell belong to different owner CUs, the terminal equipment must update the A master key, the RRC reconfiguration message at least includes master key update information (MasterKeyUpdate) and synchronization reconfiguration information (ReconfigurationWithSync) for the terminal device to synchronize to the second cell. Applicant’s amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRONG NGUYEN whose telephone number is (571)270-7312. The examiner can normally be reached on Monday through Thursday 9:30 AM - 5:00 PM EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, GELAGAY SHEWAYE can be reached on (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TRONG H NGUYEN/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Dec 17, 2024
Application Filed
Mar 20, 2026
Non-Final Rejection mailed — §102, §103
Jul 02, 2026
Response Filed
Sep 04, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743510
TECHNIQUES FOR IMPROVED INSPECTION OF CONTAINER LAYERS
2y 1m to grant Granted Sep 22, 2026
Patent 12724873
TRUSTED EXECUTION ENVIRONMENT FOR DATA SHARING
3y 2m to grant Granted Sep 01, 2026
Patent 12717918
IMAGE FORMING APPARATUS AND CONTROL METHOD
3y 2m to grant Granted Aug 25, 2026
Patent 12712864
SYSTEMS AND METHODS FOR KEY ACCESS DISTRIBUTION AND MANAGEMENT
2y 10m to grant Granted Aug 18, 2026
Patent 12705401
MEMORY DEVICE AUTONOMOUS MEASUREMENT ATTESTATION
2y 0m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+57.1%)
3y 2m (~1y 4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 560 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month