DETAILED ACTION
This Final Office Action is in response to amendment filed on 06/11/2026. Claims 1, 8, and 15 have been amended. Claims 1-20 remain pending in the application.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined
under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to the amended claims, filed 06/11/2026, have been fully considered and are persuasive. The examiner agrees that no reference, alone or combined, teaches or suggests a default network slice that provides an isolated communication channel configured to handle authentication traffic between the user equipment and the cloud identity provider while preventing interference with network operations, as recited by amended claim 1.
However, a new ground(s) of rejection is made in view of Sokolov (US 9544287 B1). Sokolov remedies the deficiencies of Li in view of Andrews and Van den Dungen noted above. The rejection is necessitated by the claim amendments and is directly caused by the changes in the reply. Applicant's arguments are considered moot in light of the newly found prior art: Sokolov (US 9544287 B1). Please see detailed rejection below.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1,2,5,6,7,8,9,12,13,14,15,16,19, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Li (US 20230379704 A1) in view of Andrews (US 20220124486 A1) and in further view of Van den Dungen (US 20230137359 A1) and in further view of Sokolov (US 9544287 B1).
Regarding claim 1, Li teaches a computer system comprising: at least one hardware processor ([0039] “The present disclosure relates to a wireless device, comprising: [0040] a processor, configured to store a network slice-specific authentication and authorization, NSSAA, status comprising a plurality of records for a wireless terminal, and [0041] a communication unit configured to transmit, to an access and mobility management function, AMF, the NSSAA status”); and
at least one non-transitory memory storing instructions, which, when executed by the
at least one hardware processor, cause the computer system to (“Examples of the storage unit 312 include but are not limited to a SIM, ROM, flash memory, RAM, hard-disk, and optical data storage device. The communication unit 320 may be a transceiver and is used to transmit and receive signals (e.g. messages or packets) according to processing results of the processor 300. In an example, the communication unit 320 transmits and receives the signals via at least one antenna 322 shown in FIG. 3”):
receive, by a network slice-specific authentication and authorization function, a re-authentication notification for access by a user equipment to a network slice ([0009] “..storing a network slice-specific authentication and authorization, NSSAA, status comprising a plurality of records for a wireless terminal, and [0010] transmitting, to an access and mobility management function, AMF, the NSSAA status”; [0049] “The present disclosure relates to a wireless device, comprising a communication unit configured to: [0050] receive, from a network slice-specific authentication and authorization function, NSSAAF, a subscription of a registration event associated with a wireless terminal, [0051] “receive, from an access and mobility management function, AMF, a registration request for the wireless terminal”; [0052] “transmit, to the NSSAAF, a registration event notification based on the subscription”);
query a unified data management system to obtain subscription information associated with the user equipment ([0070] “The NSSAAF provides services to verify whether the UE is allowed to use a service provided by a specific network slice. [0086] 9) UDM: Unified Data Management”; [0087] The UDM stores long-term security credentials used in authentication. In addition, the UDM stores subscription information”);
update network slice access configurations based on the authentication status ([0135] “In an embodiment, the NSSAA status returned by the NSSAAF includes a list of binary records (e.g. comprising the S-NSSAI and/or the EAP authentication status). In an embodiment, the EAP authentication status indicates the result of the NSSAA procedure for the corresponding S-NSSAI” ; [0137] “In step 610, if step 609 is performed, the NSSAAF further updates the stored NSSAA status according to the result of the NSSAA procedure performed in step 609”); and
transmit the authentication status to an access and mobility function ([0039] “The present disclosure relates to a wireless device, comprising: [0040] a processor, configured to store a network slice-specific authentication and authorization, NSSAA, status comprising a plurality of records for a wireless terminal, and [0041] a communication unit configured to transmit, to an access and mobility management function, AMF, the NSSAA status”).
However, Li does not explicitly teach the limitation listed below.
Andrews further teaches identify a cloud identity provider based on the network slice and the subscription information ([0014, 0016] discloses CSM used/identified to grant requests based on device profile, network slice, and devices assigned to employees, [0059] “The secure network slice orchestration system in an embodiment may communicate with the CSM platform 341, which may be located in a cloud-based network or environment 340. For example, the CSM platform 341 may be a Dell Unified Workspace® platform, a Workspace One® platform, a Microsoft Intune® platform, or a VMware Airwatch®. The CSM platform 341 determines and monitors adherence to security measures in place at each of the plurality of endpoint computing devices managed by the CSM platform 341. The CSM platform 341 in an embodiment may operate to manage security credentials, distribution of proprietary applications, performance metrics, or communication capabilities across several computing devices of a company. For example, a CSM platform 341 may track which endpoint computing devices are issued to which employees, or which employees may access a given endpoint computing device”), examiner interprets CSM platform 341 as cloud identity provide and employees information as subscription information,
send an identity provider notification to the user equipment using a default network slice ([0070] “Upon establishment of each of the network slices, based on the number of security tiers and the QoS metrics, the secure network slice orchestrator 330 in an embodiment may communicate the identity and QoS metrics aftrssociated with each of these established network slices to the CSM platform 341. For example, the secure network slice orchestrator 330 may transmit an identification of network slices in the 5G NRFR1 low-band (e.g., below 1 GHz), the 5G NRFR1 mid-band (e.g., between 1 GHz and 6 GHz), and 5G mm-Wave NRFR2 high-band (e.g., above 6 GHz), made available at the RAN system 320 for distribution to the endpoint computing devices (e.g., 350, 360, 370, or 380). In some embodiments, the secure network slice orchestrator 330 may transmit an identification of a plurality of network slices within a single band (e.g., a plurality of network slices within the 5G mm-Wave NRFR2 high-band, as described above with reference to FIG. 2)” [0096] “For example, in an embodiment described with reference to FIG. 3, the CSM platform 341 in an embodiment may communicate to the secure network slice orchestrator 330 the number of security tiers in which each of the endpoint computing devices registered at the CSM platform 341 may be placed. This information, along with QoS metrics associated with radio frequency spectrum portions received at the RAN system 320 from the core network system may inform the number of network slices into which the secure network slice orchestrator 330 separates these radio frequency spectrum portions”), examiner interprets the CSM platform 341 informing the number of network slicers as an identity provider notification using network slice;
facilitate out-of-band authentication between the user equipment and the cloud identity provider ([0076] “In yet another example, the CSM platform 341 in an embodiment may associate endpoint computing device 380, belonging to the out-of-band control security tier, with a network slice (e.g., network slice 227 described with reference to FIG. 2) facilitating communication within the 5G NRFR1 public low-band, between 1 GHz and 6 GHz, and also associated with the out-of-band control security tier”; [0094] “In still another example, the endpoint computing device 380 may comprise any endpoint computing device accessible by the MDM platform via out-of-band controls, and may be associated within a security profile identifying the endpoint computing device 380 (e.g., by its MAC address, SID, or DDID) with the out-of-band, highest available security tier”);
receive an authentication status from the cloud identity provider ([0080] “In an embodiment, the CSM platform 341 may also transmit an instruction to the secure network slice orchestrator 330 to allow any endpoint computing devices requesting access to a given network slice identified within its communication profile to access that given network slice. As described in greater detail below with respect to FIG. 4, the secure network slice orchestrator 330 may then only grant endpoint computing devices that are thus authorized to access a requested network slice access to that requested network slice ”, examiner interprets the authentication status as the identified network slice or instruction along with its communication profile to authenticate the endpoint computing devices.
Li in view of Andrews are analogous in wireless communication method for use in network slice-specific authentication. Therefore, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to have modified Li in view to incorporate the teachings of Andrews to implement a cloud identity provider or a cloud-based environment. Doing so would ensure user identities and access permissions within cloud environments are secure (Andrews [0059] “The secure network slice orchestration system in an embodiment may communicate with the CSM platform 341, which may be located in a cloud-based network or environment 340”).
Li and Andrews discloses the above limitations. Andrews further discloses in e.g. [0016] “If the CSM platform has granted the requesting endpoint computing device access to the requested network slice(s),”, indicating the CSM identified in the system receiving a request and accordingly grant access based on authentication, however, the combination of Li and Andrews does not explicitly teach the limitation listed below. Van den Dungen further teaches transmit a client-initiated backchannel authentication request to the identified cloud identity provider ([0038] “In some embodiments, one or more of the regions of the CSP 102 may be connected with one or more other regions within the CSP 102 by one or more back channels. For example, the login region 104 is connected to the first region 106 and the second region 108 by a back channel 110 in the illustrated embodiment. The back channels may connect to routers and/or switches of the regions, where the routers and/or switches may act as access points to the regions for the back channels”; [0054] “The authentication information being duplicated to multiple regions and being retrievable through back channels, as described in relation to the system arrangement 100, may provide for login to the CSP 102 from multiple regions within the CSP 102”), examiner interprets CSP as Cloud Identity Provider.
Li in view of Andrews and Van den Dungen are analogous in wireless communication method for use in network authentication. Therefore, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to have modified Li in view of Andres to incorporate the teachings of Van den Dungen to implement backchannel authentication to the cloud identity provider. Doing so would ensure authentication is flexible and secure (Van den Dungen [0029 ]“The IDCS stripe may be replicated in the regions via synchronized back channel communications. A login selection may provide the customer with one or more domains that are available for login from which the customer can select”).
Although Li discloses receiving by a network slice-specific authentication and authorization function, a re-authentication notification for access by a user equipment to a network slice, Andrews further discloses identifying a cloud identity provider based on the network slice and the subscription information, and Van den Dungen further transmitting a client-initiated backchannel authentication request to the identified cloud identity provider, the combination of Li, Andrews, and Van den Dungen does not explicitly teach providing an isolated communication channel configured to handle authentication traffic between the user equipment and the cloud identity provider while preventing interference with network operations.
However, in this instance the examiner notes the teachings of art reference Sokolov. Sokolov further disclose providing an isolated communication channel configured to handle authentication traffic between the user equipment and the cloud identity provider while preventing interference with network operations ([Col 9, lines 34-51] “The systems described herein may provide the authentication credential associated with the user to an identity provider of the cloud-based application in a variety of ways. In some examples, completion module 110 may provide authentication credential 216 to identity provider 214(1) by including authentication credential 216 within communication 218. For example, if network device 206 receives communication 218 as communication 218 is routed from endpoint device 202(1) to application 212(1), completion module 110 may, at network device 206, insert, incorporate, or otherwise include authentication credential 216 within communication 218 and then forward communication 218, including authentication credential 216, to identity provider 214(1). Additionally or alternatively, completion module 110 may provide authentication credential 216 to identity provider 214(1) by including authentication credential 216 within a separate communication directed to identity provider 214(1)); [Col 9, lines 65-67, Col 10 lines 1-8] “Completion module 110 may then authenticate identity provider 214(1) at network device 206 (e.g., by verifying certificate signed by identity provider 214(1)). Next, identity provider 214(1) may request authentication of network device 206. In response to this request, completion module 110 may sign a portion of data (e.g., data that is unique to a particular SSL session and is known by both parties) with authentication credential 216. Completion module 110 may then submit the signed data to identity provider 214(1) (e.g., via TCP keep-alive packets or a separate channel), where the signature may be verified”).
Li in view of Andrews, Van den Dungen, and Sokolov are analogous in wireless communication method for use in network authentication. Therefore, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to have modified Li in view of Andres to incorporate the teachings of Van den Dungen to implement an isolated communication channel configured to handle authentication traffic between the user equipment and the cloud identity provider while preventing interference with network operations. Doing so would ensure authentication is flexible and secure (Sokolov [Col 4, lines 35 - 40] “Furthermore, exemplary system 100 may include a completion module 110 that causes the network device to complete at least a portion of the authentication process for the user by providing the authentication credential associated with the user from the network device to an identity provider of the cloud-based application”).
Regarding the non-transitory storage medium comprising claim 8 and the computer-implemented method 15, the claim recite similar limitations as the computer system claim 1, therefore, rejected based on the same rationale as claim 1.
Regarding claim 2, Li in view of Andrews, van den Dungen, and Sokolov teaches all of the features of claim 1 listed above. Li teaches further the computer system of claim 1, wherein the instructions cause the computer system to: receive a revocation notification for the access by the user equipment to the network slice ([0190] “In an embodiment, the NSSAA status does not comprise at least one requested S-NSSAI (e.g. in the list of requested S-NSSAI) or at least one authentication status corresponding to the list of requested S-NSSAI expires or indicates a failure. In this embodiment, the wireless device may trigger an NSSAA procedure”; [0191] “FIG. 10 shows a flowchart of a process according to an embodiment of the present disclosure. The process shown in FIG. 10 may be used in a wireless device comprising (e.g. performing, or providing the service of) a UDM and comprises the following steps:”; [0192] “Step 1000: Receive, from a network slice-specific authentication and authorization function (NSSAAF), a subscription of a registration event associated with a wireless terminal. [0193] Step 1001: Receive, from an access and mobility management function (AMF), a registration request for the wireless terminal”; [0194] “Step 1002: Transmit, to the NSSAAF, a registration event notification based on the subscription”, further in [0119] and Figure 5 514);
transmit a callback notification to the access and mobility function to update an access status of the network slice ([0166] FIG. 8 shows a flowchart of a process according to an embodiment of the present disclosure. The process shown in FIG. 8 may be use in a wireless device comprising (e.g. performing, providing the service of) the NSSAAF and comprises the following steps: [0167] Step 800: Store a network slice-specific authentication and authorization (NSSAA) status comprising a plurality of records for a wireless terminal. [0168] Step 801: Transmit, to an access and mobility management function (AMF) the NSSAA status”; ([0152] “In an embodiment, the AMF registration event notification includes at least one of: [0153] the AMF Instance ID, [0154] a registration or deregistration action, [0155] an identifier of UE (e.g. UE ID) or [0156] optionally, the AMF callback URI for NSSAA Status notification (e.g. named as nssaaStatusCallbackUri) [0157] In this embodiment, the NSSAAF acquires the AMF callback URI for NSSAA Status notification and thus can use this callback URI to send the NSSAA status to the AMF”, where the NSSAA status is transmitted to the AMF with the intended use of receiving status or receiving updated status, etc.); and
send a message to the user equipment indicating that the network slice is unavailable ([0195] “In the process shown in FIG. 10, the wireless device (i.e. the UDM) receives, from an NSSAAF, a subscription of a registration event associated with a wireless terminal. Next, the wireless device receives, from an AMF, a registration request for the wireless terminal. Based on the subscription received in step 1000, the wireless device transmits, to the NSSAAF, a registration event notification”; [0190] “In an embodiment, the NSSAA status does not comprise at least one requested S-NSSAI (e.g. in the list of requested S-NSSAI) or at least one authentication status corresponding to the list of requested S-NSSAI expires or indicates a failure. In this embodiment, the wireless device may trigger an NSSAA procedure”).
Regarding the non-transitory storage medium comprising claim 9 and the computer implement method 16, the claim recite similar limitations as the computer system claim 2, therefore, rejected based on the same rationale as claim 2.
Regarding claim 5, Li in view of Andrews, Van den Dungen, and Sokolov teaches all of the features of claim 1 listed above. Li further teaches the computer system of claim 1, wherein the instructions to update the network slice access configurations cause the computer system to: store the authentication status for the network slice in a user equipment context maintained by the AMF ([0166] “FIG. 8 shows a flowchart of a process according to an embodiment of the present disclosure. The process shown in FIG. 8 may be use in a wireless device comprising (e.g. performing, providing the service of) the NSSAAF and comprises the following steps: [0167] Step 800: Store a network slice-specific authentication and authorization (NSSAA) status comprising a plurality of records for a wireless terminal”; [0168] “Step 801: Transmit, to an access and mobility maagement function (AMF) the NSSAA status”), examiner interprets the NSSAA status as authentication stuff for the network slice maintained by the AMF; and
notify the user equipment of changes to network slice availability based on the stored
authentication status ([0176] “In an embodiment, the registration event notification comprises at least one of an instance identification of the AMF, an action type indicating one of a registration or a deregistration, a uniform resource identifier for transmitting the NSSAA status or an identifier of the wireless terminal”).
Regarding the non-transitory storage medium comprising claim 12 and the computer implement method 19, the claim recite similar limitations as the computer system claim 5, therefore, rejected based on the same rationale as claim 5.
Regarding claim 6, Li in view of Andrews, van den Dungen, and Sokolov teaches all of the features of claim 1 listed above. Li further teaches the computer system of claim 1, wherein the instructions to receive the reauthentication notification cause the computer system to: receive a message that an access token associated with the network slice has expired; or receive a request from the cloud identity provider to re-authenticate the access of the user equipment ([0129] “In an embodiment, the NSSAA status consists of a list of records (e.g. comprising S-NSSAI(s)and/or EAP authentication status(es)) for a given UE. In an embodiment, each record indicates (e.g. comprises) an EAP-based authentication status for a given S-NSSAI. In an embodiment, the EAP authentication status indicates one of an EAP-Success or an EAP-Failure”; [0130] “In an embodiment, the NSSAA status stored by the NSSAAF may be associated with an expiry time. When the time expires, the stored NSSAA status should be regarded useless”).
Regarding the non-transitory storage medium comprising claim 13 and the computer implement method 20, the claim recite similar limitations as the computer system claim 6, therefore, rejected based on the same rationale as claim 6.
Regarding claim 7, Li in view of Andrews , van den Dungen, and Sokolov teaches all of the features of claim 1 listed above. Li further teaches the computer system of claim 1, wherein the instructions to transmit the authentication status cause the computer system to: send a success response when authentication is confirmed; or send a problem details response indicating authentication failure ([0121]” If an S-NSSAI is successfully verified by the NSSAA procedure, the AMF sets the NSSAA status of corresponding S-NSSAI to EAP-Success, otherwise set to the NSSAA status of the corresponding S-NSSAI to EAP-Failure. The AMF stores the NSSAA status of each S-NSSAI in the UE context, and the UE is also updated with the allowed NSSAI(s). Later on, if the UE requests a registration update, the AMF will not trigger the NS SAA procedure to those S-NS SAI(s) which status are set to the EAP-Success”).
Regarding the non-transitory storage medium comprising claim 14, the claim recite similar limitations as the computer system claim 7, therefore, rejected based on the same rationale as claim 7.
Claim(s) 3, 10, and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Li (US-20230379704-A1) in view of Andrews (US-20220124486-A1) in view of Van den Dungen (US-20230137359-A1) in view of Sokolov (US 9544287 B1) and in further view of Mylavarapu (US 20140237545 A1)
Regarding claim 3, Li in view of Andrews , Van den Dungen, and Sokolov teaches all of the features of claim 1 listed above. Li teaches further the computer system of claim 1, wherein the instructions of computer system to facilitate the out of-band authentication ([0076] “In yet another example, the CSM platform 341 in an embodiment may associate endpoint computing device 380, belonging to the out-of-band control security tier, with a network slice (e.g., network slice 227 described with reference to FIG. 2) facilitating communication within the 5G NRFR1 public low-band, between 1 GHz and 6 GHz, and also associated with the out-of-band control security tier”; [0094] “In still another example, the endpoint computing device 380 may comprise any endpoint computing device accessible by the MDM platform via out-of-band controls, and may be associated within a security profile identifying the endpoint computing device 380 (e.g., by its MAC address, SID, or DDID) with the out-of-band, highest available security tier”).
However, the combination of Li, Andrews, Van den Dungen, and Sokolov does not explicitly teach the limitation listed below. Mylavarapu teaches further enabling communication between the user equipment and the cloud identity provider while avoiding browser redirects ([0073] “The Network component is a purpose-built private network that allows an employer's IT team to either move traffic through their own VPN service, or a third-party VPN such as UPN 121. If a company has its VPN infrastructure, it's possible to embed its VPN client within the client. If your enterprise is without a VPN infrastructure, the VPN can be used by itself with complete security and confidence. Users can then securely access private cloud data that sits behind a firewall, such as Citrix or SharePoint, as well as public cloud services like salesforce.com and box.net”; [0075] “The Network component offers mobile workers: [0076] Isolated web browsing: On PCs and Macs, virtualization technology provides a read-only browser invulnerable to malware… [0078] Verified web destinations: Secure DNS look-up prevents browser redirects from poisoned DNS and other threats”).
Li in view of Andrews, Van den Dungen, Sokolov, and Mylavarapu are analogous in wireless communication method for use in network authentication. Therefore, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to have modified Li in view of Andrews, Van den Dungen, and Sokolov to incorporate the teachings of Mylavarapu to implement enabling cloud identity provider and user equipment while avoiding browser redirects. Doing so would strengthen malware detection and appropriate course of action (Mylavarapu [0040] “An approach to solving key logging on the Windows and Mac platforms is installing a driver beneath the operating system that encrypts all keystrokes to the application within a secured virtualized operating system. This method will potentially stop key logging before it can take over the device. If key strokes are sent to third party servers, hackers will only see an encrypted stream of communications and will be unable to steal users' credentials for VPN or online cloud service”).
Regarding the non-transitory storage medium comprising claim 10 and the computer implement method 17, the claim recite similar limitations as the computer system claim 3, therefore, rejected based on the same rationale as claim 3.
Claim(s) 4,11, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Li (US-20230379704-A1) in view of Andrews (US-20220124486-A1) in view of Van den Dungen (US-20230137359-A1) in view of Sokolov (US 9544287 B1) and in further view of Mas Roisque (US 20210029046 A1).
Regarding claim 4, Li in view of Andrews, Van den Dungen, and Sokolov teaches all of the features of claim 1 listed above. However, the combination does not explicitly teach the limitation listed below. Mas Roisque further teaches the computer system of claim 1, wherein the instructions to receive the authentication status cause the computer system to: implement at least one of a poll mode that periodically requests the authentication status, a ping mode that waits for notification before requesting the authentication status, or a push mode that receives the authentication status
Directly ([0027] “Most probably because Policy and Charging Control, PCC, was the main use case, the Session Management Function, SMF, or Packet Gateway, PGW-C, to PFDF interaction for the retrieval of PFDs is assumed to be tied to the PCCs. When SMF/PGW-C receives a PCC with a certain application identification that triggers in SMF/PGW-C, it requests the corresponding PFD if not yet available. Actually, both pull and a push mode for PFDs retrieval require as input the application identification. This means that the SMF/PGW-U need to know the relevant application beforehand”).
Li in view of Andrews, van den Dunger, Sokolov, and Mas Roisque are analogous in wireless communication method for use in network authentication. Therefore, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to have modified Li in view of Andrews, van den Dunger, and Sokolov to incorporate the teachings of Mas Roisque to implement a poll or push mode that receives an authentication request. Doing so would ensure efficiency and resource usage for authentication (Mas Roisque [0027] “Most probably because Policy and Charging Control, PCC, was the main use case, the Session Management Function, SMF, or Packet Gateway, PGW-C, to PFDF interaction for the retrieval of PFDs is assumed to be tied to the PCCs. When SMF/PGW-C receives a PCC with a certain application identification that triggers in SMF/PGW-C, it requests the corresponding PFD if not yet available. Actually, both pull and a push mode for PFDs retrieval require as input the application identification. This means that the SMF/PGW-U need to know the relevant application beforehand. That is not an issue if the purpose is to enforce certain PCCs as that information is available from the Policy Control Function, PCF, or the Policy and Charging Rules Function, PCRF. This may be an issue for other use cases”).
Regarding the non-transitory storage medium comprising claim 11 and the computer implement method 18, the claim recite similar limitations as the computer system claim 4, therefore, rejected based on the same rationale as claim 4.
Conclusion
The prior art made of record and not relied upon is considered pertinent to the applicant’s
disclosure:
Caceres et al. (US 20210400572 A1) discloses a device configured to a network slice instance of the network slice ([0012] “The application may provide the token and information identifying the user to the entity (e.g., a network device associated with the entity). The application platform may determine a type of network slice to be utilized by the user to access the application and/or service based on the information identifying the user”).
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VIVIAN D. HO whose telephone number is (571)272-9957. The examiner can normally be reached M- TH 9:00 - 6:00; F 9:00-1:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VIVIAN D HO/Examiner, Art Unit 2497 /ELENI A SHIFERAW/Supervisory Patent Examiner, Art Unit 2497