Prosecution Insights
Last updated: August 16, 2026
Application No. 19/121,302

First Node, Second Node, Third Node, Fourth Node and Methods Performed Thereby for Handling Registration of the Second Node

Non-Final OA §102§103
Filed
Apr 15, 2025
Priority
Nov 03, 2022 — EU 22383058.9 +1 more
Examiner
PARK, SANGSEOK
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Telefonaktiebolaget LM Ericsson
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
215 granted / 255 resolved
+26.3% vs TC avg
Strong +16% interview lift
Without
With
+15.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 3m
Avg Prosecution
22 currently pending
Career history
269
Total Applications
across all art units

Statute-Specific Performance

§101
5.7%
-34.3% vs TC avg
§103
63.5%
+23.5% vs TC avg
§102
16.8%
-23.2% vs TC avg
§112
7.8%
-32.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 255 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 04/15/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claim(s) 63, 66, 68 and 72 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Vetter et al., US-10356087-B1 (hereinafter “Vetter ‘087”). Per claim 63 (independent): Vetter ‘087 discloses: A computer-implemented method performed by a second node configured to operate in a communications system (FIG. 1, [Col. 6], ll.61 – [Col. 7], ll.48, an architecture including an enterprise environment 100 with such a credential provisioning server 110 ... The enterprise environment 100 may include a directory service server 140 that manages user accounts within the enterprise environment 100 and controls access to resources within the enterprise environment 100 ... the mobile device 170 (a second node) may access the enterprise environment 100 through a publicly available network 160 like the Internet – configured to operate in a communications system), the method comprising: obtaining information enabling identification of the second node in the communications system; subsequently sending a first request to a first node operating in the communications system, wherein the first request indicates the obtained information; and (FIG. 4, [Col. 11], ll. 19-29, when the request (a first request) from the credential provisioning module 174 (of the mobile device 170, i.e., the second node) is received by the credential provisioning server 110 (a first node) via the credential provisioning service 112 (after obtaining information enabling identification of the second node in the communication system), the user identifier (information enabling identification of the second node) may be obtained from the request (401) (that is, the first request is subsequently sent to the first node) and used to determine if there is a corresponding entry 118 for the user in the data store of the credential provisioning server 110 (403). If there is no entry an error message may be returned (405). If there is an entry 118 in the data store for the user, the OTP password received in the request may be compared against the OTP password stored in the data store in the entry 118 for the user (407)); responsive to the first request, receiving from the first node a second response indicating registration of the second node at a fourth node operating as a Public Key Infrastructure (PKI) registration authority for the communications system, wherein registration of the second node facilitates acceptance of a subsequent request from the second node for processing of a certificate (FIG. 4, [Col. 12], ll.19-61, (responsive to the first request; refer to step 403 in FIG. 4 ) If it is determined that the credential should be generated at the credential provisioning server 110 (the first node), the credential provisioning service 112 may access the user's enterprise account information ... the credential provisioning service 112 can then create a certificate signing request (CSR; a second response indicating registration of the second node at a fourth node to be sent from the first node) using the generated key pair (Public Key Infrastructure (PKI)) and the user's enterprise account information (e.g., the user's common name or email address) (421) ... The credential provisioning service 112 provided by the credential provisioning server 110 can then send the CSR to a certificate authority (423; a fourth node operating as a Public Key Infrastructure (PKI) registration authority for the communications system) (receiving from the first node the second response at the fourth node); [Col. 13], ll. 1-20, This P12 file (including the signed certificate returned from the CA) may be returned to the credential provisioning module 174 on the mobile device (431) – after registration of the second node at the CA ... The credential provisioning module 174 on the mobile device 170 may decrypt the file using the stored password associated with the initial credential request ... and stored the credentials (facilitate acceptance of a subsequent request from the second node for processing of a certificate); [Col. 7], ll. 40-48, At least because the client application 172 is capable of establishing a mutual secure connection (e.g., a communication link or path) with a server of the enterprise). Per claim 66 (dependent on claim 63): Vetter ‘087 discloses the elements detailed in the rejection of claim 63 above, incorporated herein by reference. Vetter ‘087 discloses: The method according to claim 63, further comprising storing the obtained information in a memory of the second node (FIG. 4, [Col. 11], ll. 19-29, when the request from the credential provisioning module 174 (the second node storing the obtained information in a memory) is received by the credential provisioning server 110 via the credential provisioning service 112, the user identifier (the obtained information) may be obtained from the request (401) and used to determine if there is a corresponding entry 118 for the user in the data store of the credential provisioning server 110 (403)). Per claim 68 (dependent on claim 63): Vetter ‘087 discloses the elements detailed in the rejection of claim 63 above, incorporated herein by reference. Vetter ‘087 discloses: The method according to claim 63, wherein at least one of the following applies: the second node has a capability for automatically requesting certificates for a service-based interface of the second node; the communications system is a Fifth Generation (5G) system; the first node implements a Network Repository Function (NRF); the second node implements one of the following network functions: Authentication Server Function (AUSF), Unified Data Management (UDM), and Unified Data Repository (UDR); the third node is an Operations Support System (OSS) node; the fourth node is a Registration Authority (RA) node; the first request is an NF PKI Register Request; the subsequent request for processing of the certificate is a certificate signing request (CSR); the information is obtained via an encrypted interface, the second request comprises the obtained information; the second response comprises the following: a one-time password (OTP) issued by the fourth node, and an identifier of the fourth node; and the identifier of the fourth node is a uniform resource identifier (URI) associated with the fourth node (FIG. 1, [Col. 6], ll.61 – [Col. 7], ll.48, the mobile device 170 may access the enterprise environment 100 through a publicly available network 160 like the Internet ... embodiments disclosed here may provide increased security when the client application 172 is accessing resources (e.g., services provided by directory service server 140, certificate authority servers 150, 155 (the fourth node is a Registration Authority (RA) node), application servers 190, 195, etc.) of the enterprise). Per claim 72 (independent): Vetter ‘087 discloses: A computer-implemented method performed by a fourth node configured to operate as a Public Key Infrastructure (PKI) registration authority for a communications system (FIG. 1, [Col. 6], ll.61 – [Col. 7], ll.48, the mobile device 170 may access the enterprise environment 100 through a publicly available network 160 like the Internet ... embodiments disclosed here may provide increased security when the client application 172 is accessing resources ( e.g., services provided by directory service server 140, certificate authority servers 150, 155 (a fourth node configured to operate as a Public Key Infrastructure (PKI) registration authority for a communications system), application servers 190, 195, etc.) of the enterprise), and the method comprising: receiving, from a first node operating in the communications system, a second request to register a second node in the communications network, wherein the second request includes information enabling identification of the second node in the communications system (FIG. 4, [Col. 12], ll.19-61, the credential provisioning service 112 (of the credential provisioning server 110, i.e., a first node) can then create a certificate signing request (CSR; a second request to register a second node, i.e., the mobile device 170 of FIG. 1, in the communication network) using the generated key pair and the user's enterprise account information (e.g., the user's common name or email address; includes information enabling identification of the second node) (421) ... The credential provisioning service 112 provided by the credential provisioning server 110 can then send the CSR to a certificate authority (423) (receiving, from a first node operating in the communications system, a second request to register a second node in the communications network)); and responsive to the second request, sending to the first node a first response indicating registration of the second node at the fourth node, wherein registration of the second node facilitates acceptance of a subsequent request from the second node for processing of a certificate (FIG. 4, [Col. 12], ll.19 - [Col. 13], ll. 20, The credential provisioning service 112 (the first node) provided by the credential provisioning server 110 can then send the CSR (the second request) to a certificate authority (423; the fourth node) ... (responsive to the second request) When the signed certificate is returned to the credential provisioning service 112 (425) (sending to the first node a first response indicating registration of the second node at the fourth node), a file may be created with the signed certificate and the key pair created ...This P12 file (including the signed certificate returned from the CA) may be returned to the credential provisioning module 174 on the mobile device (431) – after registration of the second node at the CA ... The credential provisioning module 174 on the mobile device 170 may decrypt the file using the stored password associated with the initial credential request ... and stored the credentials (facilitate acceptance of a subsequent request from the second node for processing of a certificate); [Col. 7], ll. 40-48, At least because the client application 172 is capable of establishing a mutual secure connection (e.g., a communication link or path) with a server of the enterprise). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 56-57 and 60-62 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vetter ‘087 in view of Ronda et al., US-20140020073-A1 (hereinafter “Ronda ‘073”). Per claim 56 (independent): Vetter ‘087 discloses: A computer-implemented method performed by a first node configured to operate in a communications system (FIG. 1, [Col. 6], ll.61 – [Col. 7], ll.48, an architecture including an enterprise environment 100 with such a credential provisioning server 110 (a first node) ... The enterprise environment 100 may include a directory service server 140 that manages user accounts within the enterprise environment 100 and controls access to resources within the enterprise environment 100 ... the mobile device 170 may access the enterprise environment 100 through a publicly available network 160 like the Internet – the credential provisioning server 110 configured to operate in a communication system), the method comprising: obtaining information enabling identification of a second node expected to operate in the communication system; subsequently receiving from the second node a first request indicating the obtained information (FIG. 4, [Col. 11], ll. 19-29, when the request from the credential provisioning module 174 (of the mobile device 170, i.e., a second node) is received by the credential provisioning server 110 via the credential provisioning service 112, the user identifier may be obtained from the request (401) (obtaining information enabling identification of a second node expected to operate in the communication system) and used to determine if there is a corresponding entry 118 for the user in the data store of the credential provisioning server 110 (403). If there is no entry an error message may be returned (405). If there is an entry 118 in the data store for the user, the OTP password received in the request (subsequently receiving from the second node a first request indicating the obtained information) may be compared against the OTP password stored in the data store in the entry 118 for the user (407)); based on the obtained information and the first request, determining whether the second node is a node which is expected to operate in the communication system (FIG. 4, [Col. 11], ll.19 – [Col. 12], ll.61, If there is an entry 118 in the data store for the user, the OTP password received in the request may be compared against the OTP password stored in the data store in the entry 118 for the user (407) (based on the obtained information – refer to step 401 and 403 in FIG. 4 – and the first request) ... If the mobile device 170 (or OS, OS type, etc.), that is, the second node, is not on the blacklist (or is on the whitelist), the credential parameters may be determined (417) – determining whether the second node is a node which is expected to operate in the communication system); and based on a result of the determination, selectively sending a second request to a fourth node operating as a Public Key Infrastructure (PKI) registration authority for the communications system, wherein the second request is for registration of the second node to facilitate acceptance of a subsequent request from the second node for processing of a certificate (FIG. 4, [Col. 12], ll.19-61, If it is determined that the credential should be generated at the credential provisioning server 110 (e.g., the mobile device 170 is not on the black list, that is, based on a result of the determination), the credential provisioning service 112 may access the user's enterprise account information (for selectively sending) ... the credential provisioning service 112 can then create a certificate signing request (CSR; a second request) using the generated key pair (Public Key Infrastructure (PKI)) and the user's enterprise account information (e.g., the user's common name or email address) (421) ... The credential provisioning service 112 provided by the credential provisioning server 110 can then send the CSR to a certificate authority (423; a fourth node operating as a Public Key Infrastructure (PKI) registration authority) (sending the second request to the fourth node operating as a Public Key Infrastructure (PKI) registration authority for the communications system); [Col. 13], ll. 1-20, This P12 file (including the signed certificate returned from the CA) may be returned to the credential provisioning module 174 on the mobile device (431) – after registration of the second node at the CA ... The credential provisioning module 174 on the mobile device 170 (the second node) may decrypt the file using the stored password associated with the initial credential request ... and stored the credentials (facilitate acceptance of a subsequent request from the second node for processing of a certificate); [Col. 7], ll. 40-48, At least because the client application 172 is capable of establishing a mutual secure connection (e.g., a communication link or path) with a server of the enterprise). Vetter ‘087 does not disclose but Ronda ‘073 discloses: wherein the information is obtained from a third node operating in the communications system (FIG. 1A, [0046], Once client agent 14 provides first factor credentials to either provider server 16 (a third node) or identity provider 18, an identity identifier (such as a username; the information) can be sent to authentication server 22. Authentication server 22 may use the identity identifier to identify an associated client device (which is associated with the identity identifier in a database, for example); FIG. 2, [0087], Provider server 16 (the third node) may also send an identity identifier, associated with the login request, to authentication server 22 (the information is obtained from the third node operating in the communications system); [0094], after receiving an identity identifier, authentication server 22 may locate one or more corresponding client device records that are associated with the identity identifier, as well as provider server 16.); It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Vetter ‘087 with the receiving of an identity identifier from a provider server at an authentication server in order to identify an associated client device as taught by Ronda ‘073 because existing provider servers can be easily adapted to support two-factor authentication by leveraging authentication server [0045]. Additionally, Ronda ‘073 is analogous to the claimed invention because it teaches the user 12 may employ the client agent 14 executing on a computing device 13 in order to authenticate with provider server 16 and take advantage of the services offered [0045]. Per claim 57 (dependent on claim 56): Vetter ‘087 in view of Ronda ‘073 discloses the elements detailed in the rejection of claim 56 above, incorporated herein by reference. Vetter ‘087 discloses: The method according to claim 56, wherein selectively sending the second request based on a result of the determination comprises one or more of the following: sending the second request when the result of the determination is positive; and when the result of the determination is negative, refraining from sending the second request and sending an alarm (FIG. 4, [Col. 12], ll.8-61, If the mobile device 170 (or OS, OS type, etc.) is not on the blacklist (or is on the whitelist), the credential parameters may be determined (417) (based on a result of the determination; in this case, positive) ... If it is determined that the credential should be generated at the credential provisioning server 110, the credential provisioning service 112 may access the user's enterprise account information (for selectively sending) ... the credential provisioning service 112 can then create a certificate signing request (CSR; the second request) using the generated key pair and the user's enterprise account information (e.g., the user's common name or email address) (421) ... The credential provisioning service 112 provided by the credential provisioning server 110 can then send the CSR to a certificate authority (423) (sending the second request when the result of the determination is positive)). Per claim 60 (dependent on claim 56): Vetter ‘087 in view of Ronda ‘073 discloses the elements detailed in the rejection of claim 56 above, incorporated herein by reference. Vetter ‘087 discloses: The method according to claim 56, further comprising: storing the obtained information in a memory of the first node (FIG. 4, [Col. 11], ll. 19-29, when the request from the credential provisioning module 174 is received by the credential provisioning server 110 (the first node) via the credential provisioning service 112, the user identifier (the obtained information) may be obtained from the request (401) – then, storing the obtained information in a memory of the first node – and used to determine if there is a corresponding entry 118 for the user in the data store of the credential provisioning server 110 (403)), responsive to the second request, receiving from the fourth node a first response indicating a registration of the second node at the fourth node, and responsive to the first response, sending to the second node a second response indicating the registration of the second node at the fourth node (FIG. 4, [Col. 12], ll.19 - [Col. 13], ll. 20, The credential provisioning service 112 provided by the credential provisioning server 110 can then send the CSR (the second request) to a certificate authority (423; the fourth node) ... (responsive to the second request) When the signed certificate is returned to the credential provisioning service 112 (425) (receiving from the fourth node a first response indicating a registration of the second node at the fourth node), a file may be created with the signed certificate and the key pair created ...( responsive to the first response) This P12 file (including the signed certificate returned from the CA, that is, a second response) may be returned to the credential provisioning module 174 on the mobile device (431; the second node) (sending to the second node a second response indicating the registration of the second node at the fourth node) ... The credential provisioning module 174 on the mobile device 170 may decrypt the file using the stored password associated with the initial credential request ... and stored the credentials). Per claim 61 (dependent on claim 56): Vetter ‘087 in view of Ronda ‘073 discloses the elements detailed in the rejection of claim 56 above, incorporated herein by reference. Vetter ‘087 discloses: The method according to claim 56, further comprising: prior to sending of the second request, obtaining from the third node a fourth indication indicating the fourth node, and storing the obtained fourth indication in a memory of the first node (FIG. 4, [Col 11], ll.19-49, When the credential provisioning service 112 (the first node) receives the user's enterprise credentials from credential provisioning module 174 it can verify these credentials using the enterprise's directory service server 140 (the third node) to determine if they are correct (411) – prior to sending of the second request, an additional authentication result (the fourth indication indicating the fourth node) obtained from the directory service server 140 is to be stored in a memory of the credential provision service 112; [Col. 12], ll.19-61, the credential provisioning service 112 can then create a certificate signing request (CSR; the second request) using the generated key pair and the user's enterprise account information (e.g., the user's common name or email address) (421) ... The credential provisioning service 112 provided by the credential provisioning server 110 can then send the CSR to a certificate authority (423; the fourth node) (sending the second request to the fourth node)). Per claim 62 (dependent on claim 56): Vetter ‘087 in view of Ronda ‘073 discloses the elements detailed in the rejection of claim 56 above, incorporated herein by reference. The limitations of the claim(s) correspond(s) to features of claim 68 and the claim(s) is/are rejected for the reasons detailed with respect to claim 68. Claim(s) 58-59 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vetter ‘087 in view of Ronda ‘073 and Schumann, III et al., US-20230246819-A1 (hereinafter “Schumann ‘819”). Per claim 58 (dependent on claim 56): Vetter ‘087 in view of Ronda ‘073 discloses the elements detailed in the rejection of claim 56 above, incorporated herein by reference. Vetter ‘087 discloses: The method according to claim 56, wherein the obtained information comprises one or more of the following: a first indication that identifies the second node (FIG. 4, [Col. 11], ll. 19-29, when the request from the credential provisioning module 174 (of the mobile device 170, i.e., the second node) is received by the credential provisioning server 110 via the credential provisioning service 112, the user identifier may be obtained from the request (401) and used to determine if there is a corresponding entry 118 for the user in the data store of the credential provisioning server 110 (403); [Col. 10], ll. 44-50, the credential provisioning module 174 application may send a request for credentials to the credential provisioning service 112 provided by the credential provisioning server 110, where the request includes an identifier for the user (identifies the second node), the OTP for the user, the device type, and the OS type and version running on the device 170). Vetter ‘087 in view of Ronda ‘073 does not disclose but Schumann ‘819 discloses: a second indication of a key assigned to the second node ([0007], a source client device (the second node) sends a packet including information about the user and/or machine-specific information (referred to herein as "identity context information") and PKI information as metadata of the packet to a router configured to perform session-based routing ... The PKI information may include a public key – a key assigned to the second node). It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to have modified Vetter ‘087 in view of Ronda ‘073 with the sending of a packet including identity context information and PKI information including a public key as metadata to perform session-based routing as taught by Schumann ‘819 because the network device can securely enforce session policies based on verified identity information within the network by validating metadata using a public key associated with an authenticated user or device [0039]. Additionally, Schumann ‘819 is analogous to the claimed invention because it teaches providing public key infrastructure (PKI) based session authentication [0006]. Per claim 59 (dependent on claim 58): Vetter ‘087 in view of Ronda ‘073 and Schumann ‘819 discloses the elements detailed in the rejection of claim 58 above, incorporated herein by reference. Vetter ‘087 discloses: The method according to claim 58, wherein the obtained information further comprises a third indication of a type of the second node (FIG. 4, [Col. 11], ll. 19-29, when the request from the credential provisioning module 174 (of the mobile device 170, i.e., the second node) is received by the credential provisioning server 110 via the credential provisioning service 112, the user identifier may be obtained from the request (401) and used to determine if there is a corresponding entry 118 for the user in the data store of the credential provisioning server 110 (403); [Col. 10], ll. 44-50, the credential provisioning module 174 application may send a request for credentials to the credential provisioning service 112 provided by the credential provisioning server 110, where the request includes an identifier for the user, the OTP for the user, the device type (a type of the second node), and the OS type and version running on the device 170). Claim(s) 64-65 and 73-74 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vetter ‘087 in view of Schumann ‘819. Per claim 64 (dependent on claim 63): Vetter ‘087 discloses the elements detailed in the rejection of claim 63 above, incorporated herein by reference. The limitations of the claim(s) correspond(s) to features of claim 58 and the claim(s) is/are rejected for the reasons detailed with respect to claim 58. Per claim 65 (dependent on claim 64): Vetter ‘087 in view of Schumann ‘819 discloses the elements detailed in the rejection of claim 64 above, incorporated herein by reference. The limitations of the claim(s) correspond(s) to features of claim 59 and the claim(s) is/are rejected for the reasons detailed with respect to claim 59. Per claim 73 (dependent on claim 72): Vetter ‘087 discloses the elements detailed in the rejection of claim 72 above, incorporated herein by reference. The limitations of the claim(s) correspond(s) to features of claim 58 and the claim(s) is/are rejected for the reasons detailed with respect to claim 58. Per claim 74 (dependent on claim 73): Vetter ‘087 in view of Schumann ‘819 discloses the elements detailed in the rejection of claim 73 above, incorporated herein by reference. The limitations of the claim(s) correspond(s) to features of claim 59 and the claim(s) is/are rejected for the reasons detailed with respect to claim 59. Allowable Subject Matter Claim(s) 69-71 is/are allowed. The following is a statement of reasons for the indication of allowable subject matter: Regarding claim 69, the prior art of record (Vetter ‘087 in view of Ronda ‘073) does not disclose: “... performed by a third node configured to operate in a communications system, the method comprising: ... sending to the first node a fourth indication of a fourth node operating as a Public Key Infrastructure (PKI) registration authority for the communications system, wherein the information and the fourth indication facilitate registration of the second node at the fourth node” in the recited context. Vetter ‘087 teaches that the first node, the second node, and the fourth node. However, it is unclear what element, if any, corresponds to the claimed “third node.” Furthermore, although Vetter ‘087 disclose that the fourth node transmits certain indication information to the first node, such indication cannot reasonably be interpreted as “facilitating registration of the second node.” Rather, the indication merely signifies that the registration process has already been completed at the fourth node. Accordingly, the indication is provided after registration and does not facilitate acceptance of a subsequent registration-related request as recited in the claim. Ronda ‘073 can be relied upon for teaching the “third node.” However, Ronda ‘073 fails to disclose or suggest the fourth node, particularly a node “operating as a Public Key Infrastructure (PKI) registration authority.” Therefore, the combination of Vetter ‘087 in view of Ronda ‘073 fails to teach or suggest the above claimed limitations. Dependent claims 70-71 are allowed in view of their respective dependence from claims. Claim(s) 67 and 75 is/are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: Regarding claims 67 and 75, the claims further require that the fourth node issue a one-time password (OTP) and subsequently process a certificate based on an OTP received from other nodes. However, Vetter ‘087 in view of Ronda ‘073 fails to teach or suggest this critical concept. In particular, the cited references do not disclose the fourth node generating an OTP for certificate processing, nor do they teach the claimed communications involving the second node and the third node in connection with the generation, transmission, and use of a certificate. Therefore, Vetter ‘087 in view of Ronda ‘073 fails to teach or render obvious the limitations of claims 67 and 75. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Law, US-20210051012-A1 – upon successful user authentication, the client device signs an authentication indicator with a device-specific private key and transmits the signed indicator to an SRT platform. The signed indicator allows the platform to verify that the authentication was performed by an authorized device. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SANGSEOK PARK whose telephone number is (571)272-4332. The examiner can normally be reached Monday-Friday 7:30-5:30 and Alternate Fridays 9:00 am-5:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, PHILIP CHEA can be reached at (571)272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SANGSEOK PARK/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Apr 15, 2025
Application Filed
Jun 26, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12701141
ENABLING COMMUNICATIONS BETWEEN APPLICATIONS IN A MOBILE OPERATING SYSTEM
2y 0m to grant Granted Aug 04, 2026
Patent 12675602
BIOMETRIC DATA ACCESS
1y 8m to grant Granted Jul 07, 2026
Patent 12664321
ELECTRONIC SYSTEM OF PUF-BASED ROOT KEY ENTANGLEMENT WITH MULTIPLE DIGITAL INPUT SEQUENCES AND ROOT KEY EXTRACTOR
2y 0m to grant Granted Jun 23, 2026
Patent 12640920
CRYPTOGRAPHIC KEY CONFIGURATION USING PHYSICAL UNCLONABLE FUNCTION
2y 2m to grant Granted May 26, 2026
Patent 12639453
MEMORY SYSTEM AND METHOD OF OPERATING THE SAME
1y 12m to grant Granted May 26, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+15.7%)
2y 3m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 255 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month