DETAILED ACTION
This communication is responsive to the Application No. 19/037,769 filed on January 27, 2025. Claims 1-20 are pending and are directed towards METHOD FOR AUTHENTICATION AND DEVICE.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 01/27/2025, 05/12/2026 and 09/02/2026 were Acknowledge. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner.
Specification
The use of the term (WI-FI), which is a trade name or a mark used in commerce, has been noted in this application. The term should be accompanied by the generic terminology; furthermore the term should be capitalized wherever it appears or, where appropriate, include a proper symbol indicating use in commerce such as ™, SM , or ® following the term.
Although the use of trade names and marks used in commerce (i.e., trademarks, service marks, certification marks, and collective marks) are permissible in patent applications, the proprietary nature of the marks should be respected and every effort made to prevent their use in any manner which might adversely affect their validity as commercial marks.
Claim Objections
Claims 8 and 20 objected to because of the following informalities:
Typo of the word “fouth” which should be “fourth”.
Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-8, 10, 12-13, 17 and 20 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 recites the limitation “method for authentication, applicable to a station (STA)” which is vague and not clear whether this method is performed by the SAT or not.
Claims 2, 10 and 17 recite the acronym “LAN” which is not defined.
Claims 4-5, 12-13 recite the acronym “EAP” which is not defined.
Claims 8 and 20 recite the acronym “DHss” which is not defined.
Claims 3, 6-7 are rejected by dependency.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-6, 9-14 and 16-18 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Ho et al. US 2024/0314555 A1 (hereinafter “Ho”).
As per claims 1, 9 and 16, Ho teaches method for authentication, applicable to a station (STA), the method comprising:
performing an authentication process by transmitting authentication frames between the STA and an access point (AP), wherein a first field in the authentication frame indicates that at least one of the following authentication modes is used: extended pre-association security negotiation (PASN) supporting fast initial link setup (FILS) shared key authentication with perfect forward security, extended PASN supporting FILS public key authentication, or extended PASN supporting 802.1X authentication (authentication and encryption of signaling, and more specifically, to the encryption of information exchanged during an association procedure between an STA and an AP. As earlier described, 802.1X EAP frames may be carried via 802.11 Authentication frames, e.g., in order to authenticate an STA according to the 802.1X protocol prior to association by the STA. Moreover, the PASN protocol or a variation thereof, such as Extended PASN (EPASN) (further described, infra), may be implemented to protect (e.g., encrypt and authenticate to provide for data security, data privacy, data integrity, and so forth) 802.11 Association frames and improve user privacy—for example, exposure of private information carried in Association Request and Association Response frames may be avoided, even when sent in the clear). As further described by the present disclosure, some EPASN information for encryption of 802.11 Association frames and some 802.1X parameters may be combined together in a frame. Ho, para [0028])( An example of an authentication protocol may include IEEE 802.1X with the Extensible Authentication Protocol (EAP), which may provide an authentication framework that the IEEE 802.11 standards adopt. IEEE 802.1X delineate EAP encapsulation over local area networks (LANs), referred to as EAP over LAN or EAPoL. The EAPoL protocol may enable an AP to validate the identity of an STA before permitting the STA network access. In an implementation of EAPoL, 802.1X EAP frames may be carried via 802.11 Authentication frames. Ho, para [0025]).
As per claims 2, 10 and 17, Ho teaches the method according to claims 1, 9 and 16, wherein the authentication frames comprise: a first authentication frame transmitted by the STA to the AP, wherein the first authentication frame indicates a start of an Extensible Authentication Protocol over LAN (EAPOL) (The method may be performed by a station (STA) or one or more components thereof and may include transmitting, over a wireless local area network (WLAN) prior to authentication by an access point (AP), a first Extensible Authentication Protocol Over a Local Area Network (EAPoL) frame including first information associated with an EAPoL protocol and second information associated with an encryption protocol. Ho, para [0006])( The STA 604 may begin the authentication procedure by transmitting an EAPoL Start frame 626 to the AP 602. The EAPoL Start frame 626 may be implemented as an 802.11 Authentication frame. Ho, para [0059]).
As per claims 3, 11 and 17, Ho teaches the method according to claims 1, 9 and 16, wherein the authentication frames comprise: a second authentication frame transmitted by the AP to the STA, wherein the second authentication frame indicates an Extensible Authentication Protocol (EAP) request/identity message ( In response to the EAPoL Start frame 626, the AP 602 may transmit an EAP Request Identity frame 628 to the STA 604. The EAP Request Identity frame 628 includes a request for the STA 604 to provide information identifying the STA 604. Ho, para [0060]).
As per claims 4 , 12 and 17, Ho teaches the method according to claims 1, 9 and 16, wherein the authentication frames comprise: a third authentication frame transmitted by the STA to the AP, wherein the third authentication frame indicates an EAP response (Upon receiving the EAP Request Identity frame 628, the STA 604 may transmit an EAP Response Identity frame 630 to the AP 602. The EAP Response Identity frame 630 may include information identifying the STA 604 for authentication, such as a username or other outer identity information. Ho, para [0060]).
As per claims 5, 13 and 17, Ho teaches the method according to claims 1, 9 and 16, wherein the authentication frames comprise: a fourth authentication frame transmitted by the AP to the STA, wherein the fourth authentication frame indicates an EAP success (the AP 602 may transmit an EAP Success frame 644 to the STA 604 indicating such permission. Ho, para [0063]).
As per claims 6, 14 and 18, Ho teaches the method according to claims 1, 9 and 16, wherein a pairwise transient key (PTK) generated in the authentication process is used to encrypt and decrypt association request and response messages (The STA 604 and the AP 602 further establish a pairwise master key (PMK) 646. In addition, the STA 604 and the AP 602 perform a four-way handshake 648, e.g., according to the IEEE 802.11 standard. Using the PMK 646 and via the four-way handshake 648, the STA 604 and the AP 602 may further establish a pairwise transient key (PTK) 650, which the STA 604 and the AP 602 may use to secure data via encryption. Ho, para [0064]).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 7, 15 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. US 2024/0314555 A1 (hereinafter “Ho”) in view of Park et al. US 2015/0040195 A1 (hereinafter “Park”).
As per claims 7, 15 and 19, Ho teaches the method according to claims 1, 9 and 16, wherein a pairwise transient key (PTK) generated in the authentication process is used to encrypt and decrypt a data communication message (The STA 604 and the AP 602 further establish a pairwise master key (PMK) 646. In addition, the STA 604 and the AP 602 perform a four-way handshake 648, e.g., according to the IEEE 802.11 standard. Using the PMK 646 and via the four-way handshake 648, the STA 604 and the AP 602 may further establish a pairwise transient key (PTK) 650, which the STA 604 and the AP 602 may use to secure data via encryption. Ho, para [0064]);
Ho does not explicitly teach wherein the data communication message comprises a group key handshake message, the group key handshake message being used to distribute at least one of a group temporal key (GTK), an integrity group temporal key (IGTK), or a Beacon integrity group temporal key (BIGTK).
However, Park teaches wherein the data communication message comprises a group key handshake message, the group key handshake message being used to distribute at least one of a group temporal key (GTK), an integrity group temporal key (IGTK), or a Beacon integrity group temporal key (BIGTK) (A group key handshake process is performed when a change of a GTK is requested after data is exchanged based on a key generated through a 4-way handshake, and is performed for the security of a frame transmitted to a group address between the STA 280 and the AP 290. Like a PTK, a GTK generated as described above is hierarchically managed and then transferred to an MAC protocol for encryption and decryption. Park, para [0055]) (The association response frame transmitted by the AP2 320 may include an EAPOL-key at which a PTK, a GTK, and an IGTK have been installed. Park, para [0091]).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to modify the system of Ho in view of Park. One would be motivated to do so, to enhance the security of the communicated messages.
Claim(s) 8 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. US 2024/0314555 A1 (hereinafter “Ho”) in view of in view of Hsiao et al. US 2020/0127829 A1 (hereinafter “Hsiao”)
As per claims 8 and 20, Ho teaches the method according to claims 1 and 16. Ho does not explicitly teach wherein the method further comprising: generating a fouth pairwise transient key (PTK) based on the a fouth pairwise master key (PMK) and a sixth DHss, wherein the sixth DHss is a shared key generated based on a public key of a supplicant of the STA and a public key of an authenticator of the AP.
However, Hsiao teaches generating a fouth pairwise transient key (PTK) based on the a fouth pairwise master key (PMK) and a sixth DHss, wherein the sixth DHss is a shared key generated based on a public key of a supplicant of the STA and a public key of an authenticator of the AP (the AP and STA implement a cryptographic key exchange, preferably using Diffie-Hellman (DH) key exchange, with key material carried in the management frames. To this end, preferably the AP provides its DH public key in a beacon, and in a probe response; the STA provides its DH public key in an association request. After exchanging these public keys, the AP and STA compute a DH shared secret key (the WLAN shared secret). This key is then used to generate the PMK and PTK used to encrypt subsequent communications over the channel... Each of the AP and STA then dynamically compute the WLAN shared key, e.g., at the AP as DH (AP private key|STA public key), and at the STA as DH (STA private key|AP public key). Once this dynamic pre-shared key is generated, the AP uses it to compute the PMK. The AP then handshakes with the STA, and each side uses the PMK to generate the PTK. Hsiao, para [0006-007])
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to modify the system of Ho in view of Hsiao. One would be motivated to do so, to enhance the security of the system by generating PTK using PMK and DHs.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
A. Benoit et al. US 2016/0360404 A1 directed to flexible configuration and authentication of wireless devices.
B. Henry et al. US 2022/0377554 A1 directed to access point verification using crowd sourcing.
C. Kneckt et al. US 2023/0147562 A1 directed to privacy enhanced BSS and discovery mechanisms.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KHALID M ALMAGHAYREH whose telephone number is (571)272-0179. The examiner can normally be reached Monday - Thursday 8AM-5PM EST & Friday variable.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, RUPAL DHARIA can be reached at (571)272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Respectfully Submitted
/KHALID M ALMAGHAYREH/Primary Examiner, Art Unit 2492