Detailed Action
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This is in response to Application with case number 18/997,423, filed on 1/21/2025 in which claims 71-85 are presented for examination.
Status of Claims
Claims 71-85 are pending, of which claims 71, 81, and 85 are in independent form.
Specification
The examiner notes that the Specification does not include any URL links and Trademark terms requiring capitalization.
The examiner notes that the abstract is in narrative form and is limited to a single paragraph on a separate sheet within the range of 50 to 150 words in length. In addition, the examiner notes that the abstract is not using legal phraseology often used in patent claims.
IDS
References cited in the IDS filed on 2/24/2025 have been considered by the examiner.
Priority
Applicant’s claim for benefit of priority based on IN202241056765 filed on 10/3/2022 is acknowledged by the examiner.
Allowable Subject Matter
Claims 77-79 and 82-84 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim(s) 71, 73-76, 80, 81, and 85 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Automated Certificate Management in SBA; (Release 18)”, 2022-07-06, hereinafter 3GPP.
As to claim 71, 3GPP teaches a first entity implementing at least a first network function of a core network for a mobile communication system, the first entity comprising: at least one processor; and at least one memory including computer program code, the at least one memory and computer program code configured to, with the at least one processor, cause the first entity to perform:
receiving a digital certificate certifying a cryptographic key for the first entity (see Fig. 6.3.2-1, p. 19; “The operator CA generates the certificate for the NF and sends a signed response to the NF (or to the Certificate Management NF) which includes the issued certificate,,,,”, 4th para. On page 20, “If the purpose of the issued certificates is not restricted, i.e., the type of operations for which a public key contained in the certificate can be used are not specified, those certificates could be used for another purpose than intended, violating the CA policies, and increasing the risk of cross-protocol attacks.”);
wherein the digital certificate indicates one or more purposes for which the digital certificate certifies the cryptographic key (see section 5.7.2 and 5.7.3: “If the purpose of the issued certificates is not restricted, i.e., the type of operations for which a public key contained in the certificate can be used are not specified, those certificates could be could be used for another purpose than intended, violating the CA policies, and increasing the risk of cross-protocol attacks. … The Network Functions should be able to indicate the purpose of the certificate being requested in the CSR (certificate Signing Request) to the operator CA.”); and
sending the digital certificate to a second entity implementing at least a second network function of the core network for the mobile communication system (see page 18, top of page “… a certificate management NF in the same security trust domain of the NF(s) and private CA, that is capable to deliver end entity certificates issued by the private CA to the NFs as a central certificate management entity in the security trust domain.”; see Fig. 6.3.1-2).
As to claims 81 and 85, claims 81 and 85 includes similar limitations as claim 71 and thus claims 81 and 85 are rejected under the same rationale as in claim 71.
As to claim 73, 3GPP teaches the first entity according to claim 71, wherein the digital certificate conforms to ITU-T X.509 standard for public key infrastructures (see page 13 section 5.8.1).
As to claim 74, 3GPP teaches the first entity according to claim 71, wherein the digital certificate includes a field populated by one or more identifier values indicating the one or more purposes (see Fig. 6.3.2-1, p. 19; “The operator CA generates the certificate for the NF and sends a signed response to the NF (or to the Certificate Management NF) which includes the issued certificate,,,,”, 4th para. On page 20, “If the purpose of the issued certificates is not restricted, i.e., the type of operations for which a public key contained in the certificate can be used are not specified, those certificates could be used for another purpose than intended, violating the CA policies, and increasing the risk of cross-protocol attacks.”)
As to claim 75, in view of claim 71, 3GPP teaches the first entity according to claim 71, wherein the digital certificate includes a field supporting free text, and the field includes free text indicating the one or more purposes (see Fig. 6.3.2-1, p. 19; “The operator CA generates the certificate for the NF and sends a signed response to the NF (or to the Certificate Management NF) which includes the issued certificate,,,,”, 4th para. On page 20, “If the purpose of the issued certificates is not restricted, i.e., the type of operations for which a public key contained in the certificate can be used are not specified, those certificates could be used for another purpose than intended, violating the CA policies, and increasing the risk of cross-protocol attacks.”)
As to claim 76, in view of claim 75, 3GPP teaches wherein the field supporting free text also indicates a subject name (see Fig. 6.3.2-1, p. 19; “The operator CA generates the certificate for the NF and sends a signed response to the NF (or to the Certificate Management NF) which includes the issued certificate,,,,”, 4th para. On page 20, “If the purpose of the issued certificates is not restricted, i.e., the type of operations for which a public key contained in the certificate can be used are not specified, those certificates could be used for another purpose than intended, violating the CA policies, and increasing the risk of cross-protocol attacks.”).
As to claim 80, in view of claim 71, 3GPP teaches wherein the at least one memory and computer program code are further configured to, with the at least one processor, cause the first entity to request the digital certificate from a certificate authority (see Fig. 6.3.2-1, p. 19; “The operator CA generates the certificate for the NF and sends a signed response to the NF (or to the Certificate Management NF) which includes the issued certificate,,,,”, 4th para. On page 20, “If the purpose of the issued certificates is not restricted, i.e., the type of operations for which a public key contained in the certificate can be used are not specified, those certificates could be used for another purpose than intended, violating the CA policies, and increasing the risk of cross-protocol attacks.”)
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 72, is/are rejected under 35 U.S.C. 103 as being unpatentable over 3GPP, in view of Olsson et al. (US 2026/0156113 A1) hereinafter Olsson.
As to claim 72, 3GPP does not explicitly teach but Olsson teaches the first entity according to claim 71, wherein the one or more purposes comprise one or more of: establishing a secure logical connection between the first and second entities; or verifying client credential assertion tokens; or verifying access tokens: or verifying service request (see para. [0065]-[0070] “[0065] Suppose that a secure connection establishment procedure is performed between a TLS client and a TLS server. The procedure is typically performed as follows: [0066] During initiation of connection establishment, the TLS client sends a ClientHello message to the TLS server message. [0067] The TLS server responds with a ServerHello message followed by a CertificateRequest message, and other additional messages depending on the TLS version and options. [0068] The TLS client responds with a Certificate message containing the TLS client's certificate (or certificate chain) that was issued by the TLS client's Certification Authority. [0069] The TLS server receives the messages from the TLS client and checks the validity of the TLS client's certificate by a revocation check to a CRL database or an OCSP server. [0070] If the revocation check is not successful, the TLS handshake/connection establishment procedure is aborted. If on the other hand, the revocation check is successful, secure connection is established between the TLS client and the TLS server.”).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, having the teachings of 3GPP and Olsson before him or her, to modify the scheme of 3GPP by including Olsson. The suggestion/motivation for doing so would have been to follow TLS handshake protocol between two end points so that a secure connection can be established at the conclusion of successful procedure of TLS handshake protocol.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HEE K SONG whose telephone number is (571)270-3260. The examiner can normally be reached on M-F 9:00 am – 5:00 pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867 . The fax phone number for the organization where this application or proceeding is assigned is 571-273-7291.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HEE K SONG/PRIMARY Examiner, Art Unit 2497