Prosecution Insights
Last updated: August 16, 2026
Application No. 19/101,098

IMPROVED SECURITY ESTABLISHMENT METHODS AND SYSTEMS

Non-Final OA §103§112
Filed
Feb 04, 2025
Priority
Aug 12, 2022 — EU 22190117.6 +29 more
Examiner
SHIN, KYUNG H
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Koninklijke Philips N.V.
OA Round
1 (Non-Final)
82%
Grant Probability
Favorable
1-2
OA Rounds
1y 5m
Est. Remaining
92%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
797 granted / 972 resolved
+24.0% vs TC avg
Moderate +10% lift
Without
With
+10.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
19 currently pending
Career history
988
Total Applications
across all art units

Statute-Specific Performance

§101
14.8%
-25.2% vs TC avg
§103
55.1%
+15.1% vs TC avg
§102
23.8%
-16.2% vs TC avg
§112
5.6%
-34.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 972 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 1. Claims 1 - 6, 9 - 11, 13 - 15, 17, 18 are pending. Claims 7, 8, 12, 16 are canceled. Claims 1, 2, 14, 15 are independent. File date on 2-4-2025. 35 USC § 112(f) Analysis 2. The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. 3. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Such claim limitations are in claim 17. Because these claim limitation(s) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, they are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. A review of the specification shows that the following appears to be the corresponding structure described in the specification for the 35 U.S.C. 112(f) limitations. The specification in paragraph [0038] discloses the following: Paragraph [0038]: Various embodiments may be implemented in one or a combination of hardware, firmware, and software. Embodiments of the invention may also be implemented as instructions stored on a machine-readable medium, which may be read and executed by at least one processor to perform the operations described herein. A machine-readable medium may include any mechanism for storing or transmitting information in a form readable by a machine (for example, a computer) The Applicant has defined the means for performing the indicated steps as computing software executing by a computing system (i.e. a computing system comprising a CPU or processor executing a sequence of instructions or software). The specification has disclosed sufficient structure and steps to perform the indicated “means for” functions. If applicant does not intend to have these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitations recite sufficient structure to perform the claimed function so as to avoid them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 103 4. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5. Claims 1 - 3, 5, 10, 11, 13 - 15, 17, 18 are rejected under 35 U.S.C. 103 as being unpatentable over Zhao et al. (US PGPUB No. 20080313462) in view of Lee et al. (Patent No. TW 202046759 A). Regarding Claim 1, Zhao discloses an apparatus for controlling a security establishment process between a first communication device (A) and a second communication device (B) over a transmission link. (Zhao ¶ 027: a secure peer link establishment is started. A first message from mesh point A is sent to mesh point B in which a random number, RA, generated by mesh point A is inserted in this first message. A first message from mesh point B is sent to mesh point A in which a random number, RB, generated by mesh point B is inserted in this first message.; ¶ 028: the temporal key is computed, where the temporal key is the data encryption key, TK. After the two parties exchange the random numbers, RA and RB, using the first two messages of the mesh link establishment protocol, the TK is derived ,,, This process binds the derived keys to the MPA and MPB identifiers of party A and party B, respectively. The unique identifiers MPA and MPB may be the MAC addresses of mesh point A and mesh point B, respectively. In various embodiments, the derived keys may be used only for communication between mesh point A and mesh point B. With kdf based on a pseudo-random function,) Zhao does not explicitly disclose an apparatus adapted to use at least a portion of other-purpose information for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process. However, Lee discloses wherein the apparatus is adapted to use at least a portion of other-purpose information for implicit signaling of a key derivation parameter for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process. (Lee page 48: The network entity 305 can use the master key and the identification code of the UE 115-b to derive the UE specific key. For example, the network entity 305 may execute a key derivation function, where the key derivation function accepts the primary key and one or more identifiers of the UE 115-b (other-purpose information) as input and outputs the UE-specific initial AS security key.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for an apparatus adapted to use at least a portion of other-purpose information for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process as taught by Lee. One of ordinary skill in the art would have been motivated to employ the teachings of Lee for the benefits achieved from the flexibility of a system that enables multiple types of input such as other purpose parameters as input to key generation functions. (Lee page 48) Regarding Claims 2, 15, Zhao discloses an apparatus for controlling a security establishment process between a first communication device (A) and a second communication device (B) over a transmission link and a method of controlling a security establishment process between a first communication device (A) and a second communication device (B) over a transmission link. (Zhao ¶ 027: a secure peer link establishment is started. A first message from mesh point A is sent to mesh point B in which a random number, RA, generated by mesh point A is inserted in this first message. A first message from mesh point B is sent to mesh point A in which a random number, RB, generated by mesh point B is inserted in this first message.; ¶ 028: the temporal key is computed, where the temporal key is the data encryption key, TK. After the two parties exchange the random numbers, RA and RB, using the first two messages of the mesh link establishment protocol, the TK is derived ,,, This process binds the derived keys to the MPA and MPB identifiers of party A and party B, respectively. The unique identifiers MPA and MPB may be the MAC addresses of mesh point A and mesh point B, respectively. In various embodiments, the derived keys may be used only for communication between mesh point A and mesh point B. With kdf based on a pseudo-random function,) Zhao does not explicitly disclose for a) read or receive other-purpose information to derive an implicit key derivation parameter from at least a portion of the other-purpose information (portion (entire portion) of identification code used by key derivation function), and for b) use the derived key derivation parameter for a key derivation function to obtain a key for the security establishment process, wherein the other-purpose information was exchanged for a purpose other than key derivation and wherein the apparatus is adapted to perform at least one of the combining the at least portion of the other-purpose information with a fixed number. However, Lee discloses wherein the apparatus is adapted to: a) read or receive other-purpose information to derive an implicit key derivation parameter from at least a portion of the other-purpose information; (Lee page 48: The network entity 305 can use the master key and the identification code of the UE 115-b to derive the UE specific key.; (identification code originally obtained for identification purposes, other-purpose information)) and b) use the derived key derivation parameter for a key derivation function to obtain a key for the security establishment process, wherein the other-purpose information was exchanged for a purpose other than key derivation and wherein the apparatus is adapted to perform at least one of the combining the at least portion of the other-purpose information with a fixed number and setting the count input value to a minimum value which depends on the received key derivation parameter. (Lee page 48: The network entity 305 can use the master key and the identification code of the UE 115-b to derive the UE specific key. For example, the network entity 305 may execute a key derivation function, where the key derivation function accepts the primary key and one or more identifiers of the UE 115-b (combining) as input and outputs the UE-specific initial AS security key. The UE identifier may include a Globally Unique Temporary Identifier (GUTI), Serving Temporary Mobile Subscriber Identity (S-TMSI), Temporary Mobile Subscriber Identity (TMSI), or one of these or other identifiers used in UE 115-b Any combination.; (inputs: primary key and one or more identifiers)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for a) read or receive other-purpose information to derive an implicit key derivation parameter from at least a portion of the other-purpose information (portion (entire portion) of identification code used by key derivation function), and for b) use the derived key derivation parameter for a key derivation function to obtain a key for the security establishment process, wherein the other-purpose information was exchanged for a purpose other than key derivation and wherein the apparatus is adapted to perform at least one of the combining the at least portion of the other-purpose information with a fixed number as taught by Lee. One of ordinary skill in the art would have been motivated to employ the teachings of Lee for the benefits achieved from the flexibility of a system that enables multiple types of input such as other purpose parameters as input to key generation functions. (Lee page 48) Regarding Claim 3, Zhao-Lee discloses the apparatus of claim 2, wherein the received key derivation parameter is a random parameter and wherein the apparatus is adapted to supply the key derivation parameter as input value to the key derivation function or to process the key derivation parameter to obtain at least one of a count input value and a salt input value of the key derivation function. (Zhao ¶ 028: where RA is a random bit string provided by A in its first link establishment message and RB is a random bit string provided by B in its first link establishment message. (random parameters) TK may be considered the mesh analog of the 802.11 data encryption key. This process binds the derived keys to the MPA and MPB identifiers of party A and party B, respectively. The unique identifiers MPA and MPB may be the MAC addresses of mesh point A and mesh point B, respectively. In various embodiments, the derived keys may be used only for communication between mesh point A and mesh point B.; (selected: adapted to supply the key derivation parameter as input value to the key derivation function, a salt input value of the key derivation function) Regarding Claim 5, Zhao-Lee discloses the apparatus of claim 1, wherein the second communication device (B) is comprised in a medical device or a personal healthcare device or a smart home device. (Zhao ¶ 040: communication device 600 may be realized as a portable wireless communication device, such as a personal digital assistant (PDA), a laptop or portable computer with wireless communication capability, a web tablet, a wireless telephone, a wireless headset, a pager, an instant messaging device, a digital camera, a television, a medical device, or other device that may receive and/or transmit information wirelessly; (selected: medical device)) Regarding Claim 10, Zhao-Lee discloses the apparatus of claim 1, including a preamble message. (Zhao ¶ 027: a secure peer link establishment is started. A first message from mesh point A is sent to mesh point B in which a random number, RA, generated by mesh point A is inserted in this first message. A first message from mesh point B is sent to mesh point A in which a random number, RB, generated by mesh point B is inserted in this first message.; ¶ 028: the temporal key is computed, where the temporal key is the data encryption key, TK. After the two parties exchange the random numbers, RA and RB, using the first two messages of the mesh link establishment protocol, the TK is derived ,,, This process binds the derived keys to the MPA and MPB identifiers of party A and party B, respectively. The unique identifiers MPA and MPB may be the MAC addresses of mesh point A and mesh point B, respectively. In various embodiments, the derived keys may be used only for communication between mesh point A and mesh point B. With kdf based on a pseudo-random function,; (first message, preamble message)) Zhao does not explicitly disclose the other-purpose information is a security establishment identifier. However, Lee discloses wherein the other-purpose information is a security establishment identifier. (Lee page 48: The network entity 305 can use the master key and the identification code of the UE 115-b to derive the UE specific key. For example, the network entity 305 may execute a key derivation function, where the key derivation function accepts the primary key and one or more identifiers of the UE 115-b as input and outputs the UE-specific initial AS security key.; (identifier utilized within generation of a security key)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for the other-purpose information is a security establishment identifier as taught by Lee. One of ordinary skill in the art would have been motivated to employ the teachings of Lee for the benefits achieved from the flexibility of a system that enables multiple types of input such as other purpose parameters as input to key generation functions. (Lee page 48) Regarding Claim 11, Zhao-Lee discloses the apparatus of claim 2, including a pseudorandom function. (Zhao ¶ 027: a secure peer link establishment is started. A first message from mesh point A is sent to mesh point B in which a random number, RA, generated by mesh point A is inserted in this first message. A first message from mesh point B is sent to mesh point A in which a random number, RB, generated by mesh point B is inserted in this first message.; ¶ 028: the temporal key is computed, where the temporal key is the data encryption key, TK. After the two parties exchange the random numbers, RA and RB, using the first two messages of the mesh link establishment protocol, the TK is derived ,,, This process binds the derived keys to the MPA and MPB identifiers of party A and party B, respectively. The unique identifiers MPA and MPB may be the MAC addresses of mesh point A and mesh point B, respectively. In various embodiments, the derived keys may be used only for communication between mesh point A and mesh point B. With kdf based on a pseudo-random function,) Zhao does not explicitly disclose the other-purpose information is read from a code pattern and/or exchanged through an out-of-band channel and/or expanded to a predetermined bitstring and/or used as an input to a pseudorandom function. However, Lee discloses wherein the other-purpose information is read from a code pattern and/or exchanged through an out-of-band channel and/or expanded to a predetermined bitstring and/or used as an input to a pseudorandom function. (Lee page 48: The network entity 305 can use the master key and the identification code of the UE 115-b to derive the UE specific key. For example, the network entity 305 may execute a key derivation function, where the key derivation function accepts the primary key and one or more identifiers of the UE 115-b as input and outputs the UE-specific initial AS security key.; (selected: used as an input to a pseudorandom function)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for the other-purpose information is read from a code pattern and/or exchanged through an out-of-band channel and/or expanded to a predetermined bitstring and/or used as an input to a pseudorandom function as taught by Lee. One of ordinary skill in the art would have been motivated to employ the teachings of Lee for the benefits achieved from the flexibility of a system that enables multiple types of input such as other purpose parameters as input to key generation functions. (Lee page 48) Regarding Claim 13, Zhao-Lee discloses a communication device comprising an apparatus according to claim 1. (Zhao ¶ 038: Various embodiments may be implemented in one or a combination of hardware, firmware, and software. Embodiments of the invention may also be implemented as instructions stored on a machine-readable medium, which may be read and executed by at least one processor to perform the operations described herein. A machine-readable medium may include any mechanism for storing or transmitting information in a form readable by a machine (for example, a communication device, an apparatus)) Claim 1: Zhao discloses an apparatus for controlling a security establishment process between a first communication device (A) and a second communication device (B) over a transmission link. (Zhao ¶ 027: a secure peer link establishment is started. A first message from mesh point A is sent to mesh point B in which a random number, RA, generated by mesh point A is inserted in this first message. A first message from mesh point B is sent to mesh point A in which a random number, RB, generated by mesh point B is inserted in this first message.; ¶ 028: the temporal key is computed, where the temporal key is the data encryption key, TK. After the two parties exchange the random numbers, RA and RB, using the first two messages of the mesh link establishment protocol, the TK is derived ,,, This process binds the derived keys to the MPA and MPB identifiers of party A and party B, respectively. The unique identifiers MPA and MPB may be the MAC addresses of mesh point A and mesh point B, respectively. In various embodiments, the derived keys may be used only for communication between mesh point A and mesh point B. With kdf based on a pseudo-random function,) Zhao does not explicitly disclose an apparatus adapted to use at least a portion of other-purpose information for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process. However, Lee discloses wherein the apparatus is adapted to use at least a portion of other-purpose information for implicit signaling of a key derivation parameter for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process. (Lee page 48: The network entity 305 can use the master key and the identification code of the UE 115-b to derive the UE specific key. For example, the network entity 305 may execute a key derivation function, where the key derivation function accepts the primary key and one or more identifiers of the UE 115-b as input and outputs the UE-specific initial AS security key.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for an apparatus adapted to use at least a portion of other-purpose information for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process as taught by Lee. One of ordinary skill in the art would have been motivated to employ the teachings of Lee for the benefits achieved from the flexibility of a system that enables multiple types of input such as other purpose parameters as input to key generation functions. (Lee page 48) Regarding Claim 14, Zhao-Lee discloses a method of controlling a security establishment process between a first communication device (A) and a communication device (B) over a transmission link, (Zhao ¶ 027: a secure peer link establishment is started. A first message from mesh point A is sent to mesh point B in which a random number, RA, generated by mesh point A is inserted in this first message. A first message from mesh point B is sent to mesh point A in which a random number, RB, generated by mesh point B is inserted in this first message.; ¶ 028: the temporal key is computed, where the temporal key is the data encryption key, TK. After the two parties exchange the random numbers, RA and RB, using the first two messages of the mesh link establishment protocol, the TK is derived ,,, This process binds the derived keys to the MPA and MPB identifiers of party A and party B, respectively. The unique identifiers MPA and MPB may be the MAC addresses of mesh point A and mesh point B, respectively. In various embodiments, the derived keys may be used only for communication between mesh point A and mesh point B. With kdf based on a pseudo-random function,) Zhao does not explicitly disclose using at least a portion of other-purpose information for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process wherein the other-purpose information was exchanged for a purpose other than key derivation and at least one of combining the at least portion of the other-purpose information with a fixed number and setting the count input value to a minimum value which depends on the received key derivation parameter. However, Lee discloses wherein the method comprises using at least a portion of other-purpose information for implicit signaling of a key derivation parameter for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process wherein the other-purpose information was exchanged for a purpose other than key derivation, (Lee page 48: The network entity 305 can use the master key and the identification code of the UE 115-b to derive the UE specific key. For example, the network entity 305 may execute a key derivation function, where the key derivation function accepts the primary key and one or more identifiers of the UE 115-b as input and outputs the UE-specific initial AS security key.), and at least one of combining the at least portion of the other-purpose information with a fixed number and setting the count input value to a minimum value which depends on the received key derivation parameter. (Lee page 48: The network entity 305 can use the master key and the identification code of the UE 115-b to derive the UE specific key. For example, the network entity 305 may execute a key derivation function, where the key derivation function accepts the primary key and one or more identifiers of the UE 115-b as input and outputs the UE-specific initial AS security key. The UE identifier may include a Globally Unique Temporary Identifier (GUTI), Serving Temporary Mobile Subscriber Identity (S-TMSI), Temporary Mobile Subscriber Identity (TMSI), or one of these or other identifiers used in UE 115-b Any combination.; (inputs: primary key and one or more identifiers)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for using at least a portion of other-purpose information for use by a key derivation function provided at the second communication device (B) to obtain a key for the security establishment process wherein the other-purpose information was exchanged for a purpose other than key derivation and at least one of combining the at least portion of the other-purpose information with a fixed number and setting the count input value to a minimum value which depends on the received key derivation parameter as taught by Lee. One of ordinary skill in the art would have been motivated to employ the teachings of Lee for the benefits achieved from the flexibility of a system that enables multiple types of input such as other purpose parameters as input to key generation functions. (Lee page 48) Regarding Claim 17, Zhao-Lee discloses a computer program product comprising code means for producing the steps of claim 14 when run on a computer device. (Zhao ¶ 038: Various embodiments may be implemented in one or a combination of hardware, firmware, and software. Embodiments of the invention may also be implemented as instructions stored on a machine-readable medium, which may be read and executed by at least one processor to perform the operations described herein. A machine-readable medium may include any mechanism for storing or transmitting information in a form readable by a machine (for example, a computer); (system functions implemented as software code modules)) Regarding Claim 18, Zhao-Lee discloses a system comprising two or more communication devices according to claim 13. (Zhao ¶ 038: a secure peer link establishment is started. A first message from mesh point A is sent to mesh point B in which a random number, RA, generated by mesh point A is inserted in this first message. A first message from mesh point B is sent to mesh point A in which a random number, RB, generated by mesh point B is inserted in this first message.; ¶ 028: the temporal key is computed, where the temporal key is the data encryption key, TK. After the two parties exchange the random numbers, RA and RB, using the first two messages of the mesh link establishment protocol, the TK is derived ,,, This process binds the derived keys to the MPA and MPB identifiers of party A and party B, respectively. The unique identifiers MPA and MPB may be the MAC addresses of mesh point A and mesh point B, respectively. In various embodiments, the derived keys may be used only for communication between mesh point A and mesh point B. With kdf based on a pseudo-random function,) 6. Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Zhao in view of Lee and further in view of Selander et al. (Patent No. WO 2020151809 A1). Regarding Claim 4, Zhao-Lee discloses the apparatus of claim 1, Zhao does not explicitly disclose the first communication device (A) comprises a commissioning tool configured to use the security establishment process to interact with the second communication device (B) for at least one selected from a group of commissioning, configuring, authenticating and authorizing. However, Selander discloses wherein the first communication device (A) comprises a commissioning tool configured to use the security establishment process to interact with the second communication device (B) for at least one selected from a group of commissioning, configuring, authenticating and authorizing. (Selander page 4: there is provided a method of operating a network controller for enabling secure communication between network endpoints in a distributed network. The network controller has a secure channel with each of the network endpoints. According to the method, the network controller is providing, in connection with establishment of a network flow for communication between the network endpoints, symmetric keying material associated with and valid only for that network flow. The network controller is further enabling provisioning of the symmetric keying material to the network endpoints for allowing cryptographically secure communication between the network endpoints on a per-flow basis.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for the first communication device (A) comprises a commissioning tool configured to use the security establishment process to interact with the second communication device (B) for at least one selected from a group of commissioning, configuring, authenticating and authorizing as taught by Selander. One of ordinary skill in the art would have been motivated to employ the teachings of Selander for the benefits achieved from the enhanced security of a system that enables the configuration of secure communication between network-connected system. (Selander page 4) 7. Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Zhao in view of Lee and further in view of Boyen (US Patent No. 8,254,571). Regarding Claim 6, Zhao-Lee discloses the apparatus of claim 3. Zhao does not explicitly disclose the apparatus is adapted to compute the salt input value as a logical XOR combination of the received key derivation parameter and a transmitted own key derivation parameter, or as a logical XOR combination of the received and own key derivation parameters (R_B,R_A) and a preconfigured salt input value set, or as a hash function of the computed salt input values, or as a cryptographic function of a function of the received and own key derivation parameter (R_B,R_A), or as a subset of bits of the computed salt input value. However, Boyen discloses wherein the apparatus is adapted to compute the salt input value as a logical XOR combination of the received key derivation parameter and a transmitted own key derivation parameter, or as a logical XOR combination of the received and own key derivation parameters (R_B,R_A) and a preconfigured salt input value set, or as a hash function of the computed salt input values, or as a cryptographic function of a function of the received and own key derivation parameter (R_B,R_A), or as a subset of bits of the computed salt input value. (Boyen col 4: The hash function in a key derivation function may be applied in an iterative fashion. For example, in a first iteration, a hash function may receive a password and a salt as inputs. In each subsequent iteration, the output of the previous iteration may be used as the input for the hash function. The output of the hash function following the last iteration may be used as the key derivation function output.; (selected: a hash function of the computed salt input values)) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for the apparatus is adapted to compute the salt input value as a logical XOR combination of the received key derivation parameter and a transmitted own key derivation parameter, or as a logical XOR combination of the received and own key derivation parameters (R_B,R_A) and a preconfigured salt input value set, or as a hash function of the computed salt input values, or as a cryptographic function of a function of the received and own key derivation parameter (R_B,R_A), or as a subset of bits of the computed salt input value as taught by Boyen. One of ordinary skill in the art would have been motivated to employ the teachings of Boyen for the benefits achieved from the flexibility of a system the utilizes multiple processing parameters such as a salt value of a hash of a salt value in the processing of security keys. (Boyen col 4) 8. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Zhao in view of Lee and further in view of Atkinson et al. (US PGPUB No. 20210365547). Regarding Claim 9, Zhao-Lee discloses the apparatus of claim 2. Zhao does not explicitly disclose the apparatus is adapted to use the received key derivation parameter together with a shared password or a pre-shared salt input value associated to a connection to be established. However, Atkinson discloses wherein the apparatus is adapted to use the received key derivation parameter together with a shared password or a pre-shared salt input value associated to a connection to be established. (Atkinson ¶ 126: For exemplary application one (app one), an app one shared password may be derived from an app one shared public key and an app one shared private key. A key derivation function derives a derived key for app one by using inputs such as, for example, an app one shared password and the user/device app password.) It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Zhao for the apparatus is adapted to use the received key derivation parameter together with a shared password or a pre-shared salt input value associated to a connection to be established as taught by Atkinson. One of ordinary skill in the art would have been motivated to employ the teachings of Atkinson for the benefits achieved from the flexibility of a system that enables the utilization of multiple parameters such as shared password in the generation of security keys. (Atkinson ¶ 126) Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Kyung H Shin whose telephone number is (571)272-3920. The examiner can normally be reached M - F: 12pm - 8pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Joon H Hwang can be reached at 571-272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KYUNG H SHIN/ 7-11-2026Primary Examiner, Art Unit 2447
Read full office action

Prosecution Timeline

Feb 04, 2025
Application Filed
Jul 15, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706835
SMART LINK AGGREGATION AND/OR SELECTION FOR WEB TRAFFIC
2y 3m to grant Granted Aug 11, 2026
Patent 12706818
COLLECTING DEVICE, COLLECTING METHOD, AND COLLECTING PROGRAM
1y 12m to grant Granted Aug 11, 2026
Patent 12705311
COMMUNICATION GENERATION USING SPARSE INDICATORS AND SENSOR DATA
1y 11m to grant Granted Aug 11, 2026
Patent 12694415
METHODS, APPARATUS, AND ARTICLES OF MANUFACTURE TO DETERMINE UNIQUE AUDIENCE SIZE VIA CLUSTERED DATA
1y 9m to grant Granted Jul 28, 2026
Patent 12689642
THREAT EXPOSURE MANAGEMENT SYSTEM USING LARGE LANGUAGE MODELS
2y 7m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
82%
Grant Probability
92%
With Interview (+10.5%)
2y 11m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 972 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month