Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 21-30, 32-39, 41 and 42 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 21, 35, 36, 41 and 42 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Zhang et al. (WO 2019041802)
Zhang et al. discloses a system for receiving, by a service discovery function network element, a service discovery request message, wherein the service discovery request message requests the service discovery function network element to provide a network function network element of a first type (paragraph 0100); and determining, by the service discovery function network element, during a service discovery procedure triggered by the service discovery request message, whether a first certificate of a first network function network element of the first type is valid: and when it is determined that a first certificate of a first network function network clement of the first type is valid, in response to determining that the first certificate is valid, sending, by the service
identification information of the first network function network element [0102 – 104, 0106, 0108, 0114, 0127, 260).
While Zhang et al. discloses the utilization of identity-based technology of the discovery of the network function element, Zhang et al. discloses that “The difference between identity-based technology and certificate-based asymmetric security technology is that the public key PK can be an ID, that is, a user identity.”, see paragraph [0260]. Thus, employing certificate as claimed would have been an obvious modification of Zhang et al. to a person having ordinary skills in the art.
Claim(s) 22, 23, 25-30 and 32-35, 37 are rejected under 35 U.S.C. 103 as being unpatentable over Zhang et al. (WO 2019041802) in view of Martinez De Cruz et al. (WO 2021/008716)
Regarding claim 22, Zhang et al. does not explicitly disclose a certificate status protocol list. Zhang discloses validity of a certificate during a validity time period, see paragraph [0122]. Nonetheless, in a similar field of endeavor, De La Cruz et al. discloses a system comprising: a service discovery function network element (Fig. 5B, NRF 106, page 1, lines 19-20 "discovery of services and of NFs producing them is provided by a network repository function (NRF); a service discovery request message (page 14, lines 34-35, "the service consumer NF 107D sends an NnrfJMFDiscovery request to te NRF 107"); and wherein the service discovery request message requests the service discovery function network element to provide a network function network element of a first type (page 14, lines 34-35, "This request indicates at least a particular NF type as a selection criterion"); and determined that a first certificate of a first network function network element of the first type is valid, sending, by the service discovery function network element, a service discovery response message comprising identification information of the first network function network element (page 15, lines 1-5, "the NRF106 consults its data repository 106A for matching NF profiles of one or more service producer NFs 107E and returns an Nnrf_FNDiscovery response. This response contains the NF profiles matching the one or more criteria indicated in step 1201. De La Cruz et al. further discloses validity of a certificate during a validity time period.
Given the teachings of De La Cruz et al., a person having ordinary skills in the art would have been motivated to modify Zhan et al. so as to make real-time verification of certificate desirable, and to prevent expired certificate from being used.
Regarding claim 23, see page 17, and Fig. 5 D, De La Cruz.
Regarding claim 25, see pages 16-17, De La Cruz
Regarding claim 27, see page 15, lines 1-5, De La Cruz.
Regarding claim 28, see page 15, lines 1-5, De La Cruz.
Regarding claim 29, page 10, line 4 to page 11, line 29, De La Cruz.
Regarding claim 30, see page 17, line 35 to page 19, line 8, De La Cruz.
Regarding claims 32-35, see page 9, line 11-19, De La Cruz.
Claim(s) 24 and 26, are rejected under 35 U.S.C. 103 as being unpatentable over Zhang et al. (WO 2019041802) in view of Martinez De La Cruz et al. (WO 2021/008716) further in view of "Security enforcement using PKI IN Semantic Web".
Regarding claims 24 and 26, The combined system of Zhang et al. and Martinez De La Cruz et al. is silent in regards to the details of determining that certificates are valid by querying a certificate revocation list, such as claimed. However, using certificate revocation list, such as claimed is well known in the art, as evidenced by "Security enforcement using PKI IN Semantic Web". "Security enforcement using PKI IN Semantic Web" teaches the employment of certificate revocation list (CRL), and OCSP (online certificate status protocol) for the purpose of checking status of a certificate online (locally), see section IX (A). [It is also noted that CRLs can be downloaded and stored locally at the client].
Thus, given the teachings of "Security enforcement using PKI IN Semantic Web", a person having ordinary skills in the art would have been motivated to modify De La Cruz et al. with the teachings of "Security enforcement using PKI IN Semantic Web" [see section IX(A)] so as to make real-time verification possible, and to prevent expired certificate from being used.
Claim(s) 36 and 38-39, are rejected under 35 U.S.C. 103 as being unpatentable over Zhang et al. in view of Martinez De La Cruz et al. (WO 2021/008716) further in view "3rd Generation Partnership Project: Technical Specification Group Services and System Aspects; Security Aspects: Study on security aspects of the 5G Service Based Architecture (SBA) (Release 16)", 3GPP DRAFT; 33855-130CL, 3 GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTER; 650, ROUTE DES LUCIOLES; F-06921 SOPHIA- ANTIPOLIS CEDEX; FRANCE, 16 November 2018 [3GPP TR 33.855 V1.3.0].
Regarding claims 36 and 38-39, Martinez De La Cruz discloses a system comprising: receiving, by a service discovery function network element (Fig. 5B, NRF 106, page 1, lines 19-20 "discovery of services and of NFs producing them is provided by a network repository function (NRF); a service discovery request message (page 14, lines 34-35, "the service consumer NF 107D sends an NnrfJMFDiscovery request to the NRF 107"); and wherein the service discovery request message requests the service discovery function network element to provide a network function network element of a first type (page 14, lines 34-35, "This request indicates at least a particular NF type as a selection criterion"); and determine that a first certificate of a first network function network element of the first type is valid, sending, by the service discovery function network element, a service discovery response message comprising identification information of the first network function network element (page 15, lines 1-5, "the NRF106 consults its data repository 106A for matching NF profiles of one or more
service producer NFs 107E and returns an Nnrf_FNDiscovery response. This response contains the NF profiles matching the one or more criteria indicated in step 1201. The NF profiles returned in step 1202 may include, inter alia, the respective caCertificates and identifier attributes.").
While Martinez De La Cruz et al. teaches substantial features of the claimed invention (above), Martinez De La Cruz et al. is silent in regards to the claimed condition
of "when it is determined that a first certificate of a first network function element of the first type is valid network function network element", such as claimed. However, a person having ordinary skill in the art, given the teachings of De La Cruz et al. would have recognized that the NFR (of De La Cruz et al.) is able to perform validation of a certificate of a service producer NF, before sending a response, such as taught by 3GPP TR 33.855 V1.3.0, see section 6.4.2.1, step 4) in order to avoid latency in the registration process and handshake failure to repository.
Regarding claim 38, see page 15, lines 1-5 (Martinez De La Cruz). Regarding claim 39, see page 15 (Martinez De La Cruz).
Claim 37, is rejected under 35 U.S.C. 103 as being unpatentable over Martinez De La Cruz et al. (WO 2021/008716) in view "3rd Generation Partnership Project: Techical Specification Group Services and System Aspects; Security Aspects: Study on security aspects of the 5G Service Based Architecture (SBA) (Release 16)", 3GPP DRAFT; 33855-130CL, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTER; 650, ROUTE DES LUCIOLES; F-06921 SOPHIA- ANTIPOLIS CEDEX; FRANCE, 16 November 2018 [3GPP TR 33.855 V1.3.0] further in view of "Security enforcement using PKI IN Semantic Web".
Regarding claim 37, the combined system is silent in regards to the details of determining that certificates are valid by querying a certificate revocation list, such as claimed. However, using certificate revocation list, such as claimed is well known in the art, as evidenced by "Security enforcement using PKI IN Semantic Web". "Security enforcement using PKI IN Semantic Web" teaches the employment of certificate
revocation list (CRL), and OCSP (online certificate status protocol) for the purpose of checking status of a certificate online (locally), see section IX (A). [It is also noted that CRLs can be downloaded and stored locally at the client].
Thus, given the teachings of "Security enforcement using PKI IN Semantic Web", a person having ordinary skills in the art would have been motivated to modify the combined system with the teachings of "Security enforcement using PKI IN Semantic Web" [see section IX(A)] so as to make real-time verification possible, and to prevent expired certificate from being used.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GLENTON B BURGESS whose telephone number is (571)272-3949. The examiner can normally be reached Monday-Friday, 8:30 am - 5:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/GLENTON B BURGESS/Supervisory Patent Examiner, Art Unit 2454