Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1-27 remain for examination. Claims 1-3, 5-7, 9-11, 13-15, and 21 have been amended. Applicant's arguments filed on 05/26/2026 have been fully considered but they are moot in view of the new ground(s) of rejection necessitated by the amendments. Accordingly, this action has been made final.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1, 8-9, 13-14, 16, 19-22, 25-27 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Rajput U.S. Patent Application Publication No. 20220272541 A1 (hereinafter " Rajput").
As to claim 1, Rajput teaches a method performed by a Unified Data Management (UDM), comprising (Rajput Pa. [0036]) [a UDM function 104 that manages user data]: registering a user equipment (UE in the UDM after receiving a registration message from an Access and Mobility Management Function (AMF) (Rajput Pa. [0082]) can be implemented at any network function (NF) that processes or forwards AMF location service messages, including a visited SEPP of the UE and the AMF at which the UE is registered]; after registering the UE, sending to the AMF an authentication request message for initiating a primary authentication procedure for the UE (Rajput Pa. [0052]) [performed by a visited SEPP in obtaining and storing UE subscription identification information and authentication result information from the Nausf authentication procedure. Referring to FIG. 5, when a UE registers with an AMF, the AMF sends an Nausf_UEAuthentication_Authenticate request message to the home network of the UE, as indicated by line 1 of the message flow diagram. The Nausf_UEAuthentication_Authenticate request message includes the subscription concealed identifier (SUCI) and an identifier for the serving network in which the UE is currently located. In line 2 of the message flow diagram, V-SE PP 126B forwards the in a Nausf_UEAuthentication_Authenticate request message], (Rajput Pa. [0010]) [A method for mitigating location tracking and DoS attacks that utilize an AMF location service includes receiving, at a network function (NF), an authentication response message from a home public land mobile network (HPLMN) of a user equipment (UE)], wherein the authentication request message includes a subscription permanent identifier (SUPI) associated with the UE (Rajput Pa. [0010]) [he method further includes extracting, by the NF and from the authentication response message, a subscription identifier and an indicator of an authentication result for the UE]; and receiving a response message from the AMF based on the authentication request message (Rajput Pa. [0013]) [receiving an authentication response message includes receiving an Nausf_UEAuthentication message containing an authentication result parameter and a subscription permanent identifier (SUPI)], wherein the response message indicates an authentication status of the UE (Rajput Pa. [0055]) [responds to the Nudm_UEAuthentication request message by sending an Nudm_UEAuthentication response message containing an authentication result parameter and the SUPI of the UE. The value of the authentication result parameter indicates whether the authentication of the UE was successful or not.]
As to claim 8, Rajput teaches wherein the UDM is associated with a 5G Core (5GC), and the UE is a 5G compliant UE (Rajput Pa. [0041]) [3GPP network architecture for 5G networks is that the Namf_Location service defined in 3GPP TS 29.518 does not require resource object level authorization before providing location information for a UE]
As to claims 9, 16, 22, claims 9, 16, 22 recite the claimed that contain respectively similar limitations as claim 1; therefore, they are rejected under the same rationale.
As to claim 20, Rajput teaches wherein determining whether to perform the primary authentication procedure comprises inspecting a mark indicating whether the UE is to be authenticated (Rajput Pa. [0010]) [the indicator of the authentication result for the UE]
As to claim 21, Rajput teaches wherein the method further comprises, upon determining that the primary authentication procedure is to be performed, initiating primary authentication with the UE (Rajput Pa. [0010]) [A method for mitigating location tracking and DoS attacks that utilize an AMF location service includes receiving, at a network function (NF), an authentication response message from a home public land mobile network (HPLMN) of a user equipment (UE)], and thereafter sending the response message to the UDM to indicate the authentication status of the UE Rajput Pa. [0055]) [responds to the Nudm_UEAuthentication request message by sending an Nudm_UEAuthentication response message containing an authentication result parameter and the SUPI of the UE. The value of the authentication result parameter indicates whether the authentication of the UE was successful or not.]
As to claim 26, claim 26 recites the claimed that contain similar limitations as claim 20; therefore, it is rejected under the same rationale.
As to claim 27, claim 27 recites the claimed that contain respectively similar limitations as claim 21; therefore, it is rejected under the same rationale.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2-7, 10-12, 15, 17-18, 23-24 are rejected under 35 U.S.C. 103 as being unpatentable over Rajput US 20220272541 A1, in view of Baskaran US 20250184729 A1.
As to claim 2, Rajput fails wherein the authentication request message comprises a re-authentication notification request.
However, Baskaran discloses wherein the authentication request message comprises a re-authentication notification request (Baskaran Pa. [0093]) [maintain the at least one expiration time or the lifetime of the authentication duration along with a UE subscription permanent identifier (SUPI) configured to trigger a reauthentication]
Thus, before the effective filing date of the claimed invention, it would have been recognized by one of ordinary skill in the art, that applying the known technique taught by Baskaran to the authentication system of Rajput would have yield predictable results and resulted in an improved system, namely, a system that would initiate primary authentication (Baskaran Pa. [0002])
As to claim 3, the combination of Rajput and Baskaran discloses wherein the authentication request message further comprises a per-UE authentication policy (Baskaran Pa. [0059]) [authentication related to the SUPI according to the home network operator policy]
Thus, before the effective filing date of the claimed invention, it would have been recognized by one of ordinary skill in the art, that applying the known technique taught by Baskaran to the authentication system of Rajput would have yield predictable results and resulted in an improved system, namely, a system that would initiate primary authentication (Baskaran Pa. [0002])
As to claim 4, the combination of Rajput and Baskaran discloses wherein the response message indicates whether the UE is reachable by the AMF (Baskaran Pa. [0002]) [Upon receiving the reauthentication request from the internal network function, the UDM checks whether the primary reauthentication for the UE is to be initiated, or whether the request is to be rejected, based on the operator policy.]
Thus, before the effective filing date of the claimed invention, it would have been recognized by one of ordinary skill in the art, that applying the known technique taught by Baskaran to the authentication system of Rajput would have yield predictable results and resulted in an improved system, namely, a system that would initiate primary authentication (Baskaran Pa. [0002])
As to claim 5, the combination of Rajput and Baskaran discloses wherein the method further comprises, prior to sending the authentication request message (Rajput Pa. [0014]) [storing the subscription identifier and the indicator of the authentication result includes storing the SUPI and the value of the authentication result parameter], determining whether the UE needs to authenticated, the determination as to whether the UE needs to be authenticated is based on the value of a counter, and the UDM sends the authentication request message as a result of determining that the UE needs to be authenticated (Baskaran Pa. [0041]) [The operator policy includes the details of the wait period for the new request, after the last successful authentication. If the operator policy allows, then the UDM requests the AMF currently serving the UE to initiate the primary authentication for the UE. Upon receiving the request from the UDM, the AMF or SEAF initiates the primary authentication (e.g., described in TS 33.501), resulting in the generation of fresh key material in the UE and in the network, if the primary authentication is performed successfully.]
Thus, before the effective filing date of the claimed invention, it would have been recognized by one of ordinary skill in the art, that applying the known technique taught by Baskaran to the authentication system of Rajput would have yield predictable results and resulted in an improved system, namely, a system that would initiate primary authentication (Baskaran Pa. [0002])
As to claim 6, the combination of Rajput and Baskaran discloses wherein the method further comprises, prior to sending the authentication request message, determining whether the UE needs to authenticated, the determination as to whether the UE needs to be authenticated is based on an authentication policy, and the UDM sends the authentication request message as a result of determining that the UE needs to be authenticated (Baskaran Pa. [0008]) [The AUSF may also initiate the reauthentication based on a reauthentication policy by a home network operator. The security information can include an AUSF key (K.sub.AUSF), an AKMA key (K.sub.AKMA), an authentication vector, a primary authentication status, and/or a primary authentication result. The AUSF can transmit the authentication message to the AAnF as an AKMA key (K.sub.AKMA) register request that includes a UE subscription permanent identifier (SUPI), an AKMA key identifier (A-KID)]
Thus, before the effective filing date of the claimed invention, it would have been recognized by one of ordinary skill in the art, that applying the known technique taught by Baskaran to the authentication system of Rajput would have yield predictable results and resulted in an improved system, namely, a system that would initiate primary authentication (Baskaran Pa. [0002])
As to claim 7, the combination of Rajput and Baskaran discloses wherein the method further comprises, prior to sending the authentication request message, determining whether the UE needs to authenticated, the determination as to whether the UE needs to be authenticated is based on a request from a network function, and the UDM sends the authentication request message as a result of determining that the UE needs to be authenticated (Baskaran Pa. [0041]) [The operator policy includes the details of the wait period for the new request, after the last successful authentication. If the operator policy allows, then the UDM requests the AMF currently serving the UE to initiate the primary authentication for the UE. Upon receiving the request from the UDM, the AMF or SEAF initiates the primary authentication (e.g., described in TS 33.501), resulting in the generation of fresh key material in the UE and in the network, if the primary authentication is performed successfully.]
(Baskaran Pa. [0008]) [The AUSF may also initiate the reauthentication based on a reauthentication policy by a home network operator. The security information can include an AUSF key (K.sub.AUSF), an AKMA key (K.sub.AKMA), an authentication vector, a primary authentication status, and/or a primary authentication result. The AUSF can transmit the authentication message to the AAnF as an AKMA key (K.sub.AKMA) register request that includes a UE subscription permanent identifier (SUPI), an AKMA key identifier (A-KID)]
Thus, before the effective filing date of the claimed invention, it would have been recognized by one of ordinary skill in the art, that applying the known technique taught by Baskaran to the authentication system of Rajput would have yield predictable results and resulted in an improved system, namely, a system that would initiate primary authentication (Baskaran Pa. [0002])
As to claims 10, 17, 23, claims 10, 17, 23 recite the claimed that contain respectively similar limitations as claim 2; therefore, they are rejected under the same rationale.
As to claims 11, 18, 24, claims 11, 18, 24 recite the claimed that contain respectively similar limitations as claim 3; therefore, they are rejected under the same rationale.
As to claims 12-15, claims 12-15 recite the claimed that contain respectively similar limitations as claims 4-7; therefore, they are rejected under the same rationale.
As to claim 19, claim 19 recites the claimed that contain similar limitations as claim 4; therefore, it is rejected under the same rationale.
As to claim 25, claim 25 recites the claimed that contain similar limitations as claim 5; therefore, it is rejected under the same rationale.
Response to Arguments
Arguments
It is argued that: Claim 1 is not anticipated by Rajput for at least the reason that Rajput does not disclose: sending to an AMF an authentication request message for initiating a
primary authentication procedure for the UE, wherein the authentication request message includes a subscription permanent identifier (SUPI) associated with the UE,
as required by claim 1.
The Office contends that the above feature is disclosed in paragraph 10 of Rajput. (See Office Action at page 3). Applicant respectfully disagrees.
Paragraph 10 of Rajupt discloses a "method for mitigating location tracking and DoS
attacks that utilize an AMF location service." As described in paragraph 10, the method includes "receiving, at a network function (NF), an authentication response message from a home public land mobile network (HPLMN) of a user equipment (UE)" and further includes "extracting, by the NF and from the authentication response message, a subscription identifier and an indicator of an authentication result for the UE." As noted in paragraph 10, the method further includes "storing, by the NF and in an AMF location service validation database, the subscription identifier and the indicator of the authentication result for the UE" as well as "receiving, by the NF, an AMF location service message" and "using, by the NF, at least one of a subscription identifier extracted from the AMF location service message and contents of the AMF location service validation database, to classify the AMF location service message as a location tracking or DoS attack." Lastly, paragraph 10 discloses that the method "further includes, in response to classifying the AMF location service message as a location tracking attack, preventing the location tracking or DoS attack."
Applicant recognizes that paragraph 10 discloses an authentication message comprising a subscription identifier, but the similarities end here. Claim 1 expressly requires the SUPI (subscription identifier) is included in "an authentication request message," whereas Rajput discloses that the subscription identifier is included in "an authentication response message." Moreover, claim 1 also expressly requires that the SUPI (subscription identifier) is included a message "for initiating a primary authentication procedure for the UE," and the authentication response message disclosed in Rajupt is not "for initiating a primary authentication procedure for the UE," as required by claim 1.
In short, Rajput does not anticipate and Applicant requests respectfully that the rejection be withdrawn.
Examiner’s response
In response to applicant's argument, Examiner respectfully submits that claimed limitation is to be given their broadest reasonable interpretation during prosecution, and the scope of a claim cannot be narrowed by reading disclosed limitations into the claim. See In re Morris, 127 F.3d 1048, 1054, 44 USPQ2D 1023, 1027 (Fed. Cir. 1997); In re Zletz, 893 F.2d 319, 321, 13 USPQ2D 1320, 1322 (Fed. Cir. 1989); In re Prater, 415 F.2d 1393, 1404, 162 USPQ 541,550 (CCPA 1969). In addition, the law of anticipation does not require that a reference "teach" what an appellant's disclosure teaches. Assuming that reference is properly "prior art,'" it is only necessary that the claims "read on" something disclosed in the reference, i.e., all limitations of the claim are found in the reference, or "fully met" by it. Kalman v. Kimberly-Clark Corp., 713 F.2d 760, 772, 218 USPQ 781,789 (Fed. Cir. 1983). In this case, Rajput fairly discloses the claimed limitation of claim 1, 9, 16, and 22.
As to claim 1, Rajput teaches a method performed by a Unified Data Management (UDM), comprising (Rajput Pa. [0036]) [a UDM function 104 that manages user data]: registering a user equipment (UE in the UDM after receiving a registration message from an Access and Mobility Management Function (AMF) (Rajput Pa. [0082]) can be implemented at any network function (NF) that processes or forwards AMF location service messages, including a visited SEPP of the UE and the AMF at which the UE is registered]; after registering the UE, sending to the AMF an authentication request message for initiating a primary authentication procedure for the UE (Rajput Pa. [0052]) [performed by a visited SEPP in obtaining and storing UE subscription identification information and authentication result information from the Nausf authentication procedure. Referring to FIG. 5, when a UE registers with an AMF, the AMF sends an Nausf_UEAuthentication_Authenticate request message to the home network of the UE, as indicated by line 1 of the message flow diagram. The Nausf_UEAuthentication_Authenticate request message includes the subscription concealed identifier (SUCI) and an identifier for the serving network in which the UE is currently located. In line 2 of the message flow diagram, V-SE PP 126B forwards the in a Nausf_UEAuthentication_Authenticate request message], (Rajput Pa. [0010]) [A method for mitigating location tracking and DoS attacks that utilize an AMF location service includes receiving, at a network function (NF), an authentication response message from a home public land mobile network (HPLMN) of a user equipment (UE)], wherein the authentication request message includes a subscription permanent identifier (SUPI) associated with the UE (Rajput Pa. [0010]) [he method further includes extracting, by the NF and from the authentication response message, a subscription identifier and an indicator of an authentication result for the UE]; and receiving a response message from the AMF based on the authentication request message (Rajput Pa. [0013]) [receiving an authentication response message includes receiving an Nausf_UEAuthentication message containing an authentication result parameter and a subscription permanent identifier (SUPI)], wherein the response message indicates an authentication status of the UE (Rajput Pa. [0055]) [responds to the Nudm_UEAuthentication request message by sending an Nudm_UEAuthentication response message containing an authentication result parameter and the SUPI of the UE. The value of the authentication result parameter indicates whether the authentication of the UE was successful or not.]
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EVANS DESROSIERS whose telephone number is (571)270-5438. The examiner can normally be reached Monday -Friday 8:00 am - 5:30 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EVANS DESROSIERS/Primary Examiner, Art Unit 2491