Prosecution Insights
Last updated: October 02, 2026
Application No. 19/136,273

METHODS AND DEVICES FOR SHORT FRAME PROTECTION IN A WIRELESS COMMUNICATION NETWORK

Non-Final OA §103
Filed
Jun 05, 2025
Priority
Nov 01, 2023 — AU 2023903512 +1 more
Examiner
ALMAGHAYREH, KHALID M
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
Morse Micro Pty Ltd.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
217 granted / 259 resolved
+25.8% vs TC avg
Strong +24% interview lift
Without
With
+24.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
15 currently pending
Career history
276
Total Applications
across all art units

Statute-Specific Performance

§101
5.9%
-34.1% vs TC avg
§103
50.4%
+10.4% vs TC avg
§102
17.6%
-22.4% vs TC avg
§112
21.8%
-18.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 259 resolved cases

Office Action

§103
DETAILED ACTION This communication is responsive to Application No. 19/136,273 filed on June 05, 2025. Claims 1-20 are pending and are directed towards METHODS AND DEVICES FOR SHORT FRAME PROTECTION IN A WIRELESS COMMUNICATION NETWORK. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/05/2025 was Acknowledge. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Specification The use of the term “WI-FI, BLUETOOTH”, which is a trade name or a mark used in commerce, has been noted in this application. The term should be accompanied by the generic terminology; furthermore the term should be capitalized wherever it appears or, where appropriate, include a proper symbol indicating use in commerce such as ™, SM , or ® following the term. Although the use of trade names and marks used in commerce (i.e., trademarks, service marks, certification marks, and collective marks) are permissible in patent applications, the proprietary nature of the marks should be respected and every effort made to prevent their use in any manner which might adversely affect their validity as commercial marks. Allowable Subject Matter Claims 6 and 19-20 objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1-5 and 7-18 are rejected under 35 U.S.C. 103 as being unpatentable over Kneckt et al. US 2023/0319688 A1 (hereinafter “Kneckt”) in view of Ouzieli et al. US 2021/0195497 A1 (hereinafter “Ouzieli”) As per claims 1 and 10, Kneckt teaches a short frame protection method for a short frame transmitted in a wireless communication network, the method comprising: determining a target transmission time for transmitting the short frame (The PE STA can determine a target PE beacon transmission time (TPBTT) comprising a random time offset from a TBTT, where the TPBTT does not change a timing synchronization function (TSF) timer corresponding to a PE AP transmitting the PE beacon frame. The TPBTT can occur during a PE beacon randomization window duration that is based on a percentage of the TBTT. Kneckt, para [0009]); and computing an integrity value for protection of the short frame, wherein the integrity value is generated using an authentication algorithm (MME 925 is a hash check sum that may be used to detect integrity of the discovery beacon. If the MME calculated from the PE beacon frame content matches with the MME transmitted in the PE beacon frame, then the receiver knows that non-encrypted parts of the PE beacon frame has not been changed by an attacker... Provides out-of-band information for PE BSSs Management MIC element (MME) 925 Integrity check sum of the discovery beacon frame content. Kneckt, para [0065]), wherein the protection of the short frame is based on including, within a transmission of the short frame, at least a portion of the integrity value computed by a transmitter of the short frame (PE discovery beacon frame of example 930 can include MAC header 935, country/TX power envelope 940, PE RNR 950, multiple PE BSSID elements 960, and MME 970. Country/TX power envelope 940 and MME 970 may correspond to country/TX power envelope 915 and MME 925 of FIG. 9A. Kneckt, para [0067]). Kneckt does not explicitly teach wherein the integrity value is generated based on the target transmission time. However, Ouzieli teaches wherein the integrity value is generated based on the target transmission time (The timestamp may be included partially in the MIC calculation. For example, the first X number of bits (e.g., over 16 μseconds) of the timestamp field may be set to 0 (e.g., masked out). Because beacon frames may be transmitted at fixed intervals, such as every 100 time units (e.g., where each time unit is 1024 μseconds), even if one beacon transmission becomes delayed, the following beacon's planned transmission time may remain on the fixed 100 time unit interval of the originally planned transmission time (e.g., not the actual transmission time). Thus, the MIC may be determined in advance (i.e., prior to insertion of the timestamp field into the beacon frame) and compared to the actual timestamp received. For beacons transmitted at the correct planned time, the timestamp's lowest X bits (μseconds) may be 0. Unless a beacon is delayed by more than Y μseconds, the timestamp may not change. In such a manner, the partial timestamp may be included in the MIC calculations. Ouzieli, para [0061]) (The transmitting AP may use CMAC and GMAC cipher suites and the IGK to calculate the MIC over the group-addressed management frame. The AP may add the MIC to a group-addressed management frame body. The AP may use a management MIC IE (MMIE) for beacon frame protection A receiving STA may calculate the expected MIC on the received group-addressed management frame and may compare the result to the MIC field within the MMIE. The STA may not calculate the expected MIC using the MIC field within the MMIE. When the expected MIC matches the MIC field within the MMIE, the frame is valid. When the expected MIC differs from the MIC field within the MMIE, the STA may ignore the beacon as having been manipulated by a MIM attack. Ouzieli, para [0066]). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to modify the teaching of Kneckt in view of Ouzieli. One would be motivated to do so, to enhance the security of the system by using transmission time in calculating the integrity check code. As per claim 2, Kneckt and Ouzieli teach the short frame protection method of claim 1, wherein the short frame is a management frame, a control frame, or a data frame transmitted in the wireless communication network (Example 320 can include but is not limited to type 322 and subtype 324. Example values of type 322 and subtype 324 are shown in example 350 of FIG. 3C. Type 322 is used to detect whether the frame is a data, control, or management frame. Subtype 324 defines more fine grained content of the MPDU. Kneckt, para [0041]). As per claims 3 and 12, Kneckt and Ouzieli teach the short frame protection method of claims 1 and 10, wherein: the short frame is a beacon frame (privacy enhanced (PE) beacon frames. Kneckt, para [0004]); and the target transmission time is a Target Beacon Transmission Time (TBTT) associated with transmitting the beacon frame, or a Target Short Beacon Transmission Time (TSBTT) associated with transmitting the beacon frame (neighbor AP info 852 includes target beacon transmission time (TBTT) info header 860 as well as TBTT info 870. TBTT info 870 field includes BSS parameters 880 and MLD parameters 890. Kneckt, para [0061])( The PE STA can determine a target PE beacon transmission time (TPBTT) comprising a random time offset from a TBTT, where the TPBTT does not change a timing synchronization function (TSF) timer corresponding to a PE AP transmitting the PE beacon frame. The TPBTT can occur during a PE beacon randomization window duration that is based on a percentage of the TBTT. Kneckt, para [0009]). As per claims 4 and 11, Kneckt and Ouzieli teach the short frame protection method of claims 1 and 10, further comprising: generating a protected short frame based on inserting the computed integrity value within the short frame, or appending the computed integrity value to the short frame (a discovery beacon, according to some embodiments of the disclosure. Example 900 can include MAC header 910, country/transmission power envelope 915, reduced neighbor report (RNR) 920, and Management Message Integrity Check (MIC) Element (MME) 925. Kneckt, para [0065]); and transmitting the protected short frame to one or more stations in the wireless communication network (An AP (e.g., AP 110 or a PE AP) can send a discovery beacon to advertise PE BSSs. As described above, in some embodiments, MAC header 910 can include an extension type (e.g., 11) and a subtype (e.g., 0011) that enables a PE STA to identify the discovery beacon (e.g., using random ID and checksum ID). Kneckt, para [0065]). As per claim 5, Kneckt and Ouzieli teach the short frame protection method of claim 4, further comprising truncating the computed integrity value to thereby obtain a truncated integrity value for inserting within or appending to the short frame, wherein the protected short frame transmitted on the wireless communication network is protected based on the truncated integrity value (the calculated checksum value can be determined using a Hash Message Authentication Code (HMAC)-SHA and Address Resolution Key (ARK) functions shown below: Determined Checksum ID = Truncate-64(HMAC-SHA-256(ARK, “AP MLD ID”, Random ID)), where AP MLD ID is a 128 bit identifier of PE AP MLD 610, random ID is a 64 bit random ID 2 of PE AP 612, and determined Checksum value is a 64 bit Checksum ID 2 of PE AP 612. Kneckt, para [0049-0053]). As per claims 7 and 13, Kneckt and Ouzieli teach the short frame protection method of claims 1 and 10, wherein the integrity value is a Message Integrity Code (MIC) or a message authentication code (Example 900 can include MAC header 910, country/transmission power envelope 915, reduced neighbor report (RNR) 920, and Management Message Integrity Check (MIC) Element (MME) 925. Kneckt, para [0065]). As per claim 8, Kneckt and Ouzieli teach the short frame protection method of claim 1. Kneckt does not explicitly teach wherein the authentication algorithm is based on a Broadcast/multicast Integrity Protocol (BIP) for protecting an integrity for group addressed frames. However, Ouzieli teaches wherein the authentication algorithm is based on a Broadcast/multicast Integrity Protocol (BIP) for protecting an integrity for group addressed frames (While a robust security network element (RSNE) may be included in messages between the AP and STA during authentication and association, for example, beacon frame protection against forgery may not be prevented after association. While a broadcast/multicast integrity protocol (BIP) may provide protection for group-addressed management frames. Ouzieli, para [0021]). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to modify the teaching of Kneckt in view of Ouzieli. One would be motivated to do so, to enhance the security of the system by using integrity protocol for group addressed frame protection. As per claim 9, Kneckt and Ouzieli teach the short frame protection method of claim 1, wherein the target transmission time for transmitting the short frame is independently determined by a transmitter and a receiver of the short frame (Some embodiments include determining target PE beacon transmission times (TPBTTs) 1140a-1140d based on beacon intervals (e.g., beacon intervals 1145a-1145d) plus a corresponding random time offset 1155 for SN X (e.g., corresponding random time offsets 1155a-1155d). Kneckt, para [0075])(PE STA 170 can calculate a Target PE Beacon Transmission Time (TPBTT) for the beacon. Kneckt, para [0081]). As per claim 14, Kneckt teaches a short frame protection method in a wireless communication network, the method comprising: receiving, by a first network device, a short frame transmitted by a second network device, wherein the received short frame includes information indicative of an integrity value calculated by the second network device (a PE station (STA) that can receive a PE beacon frame with a media access control (MAC) header that includes a first random identifier (ID) and a first checksum ID. The PE STA can determine that the first random ID and the first checksum ID satisfy configured PE beacon parameters, and process the PE beacon frame responsive to the determination. Kneckt, para [0005]). determining, by the first network device, a target transmission time associated with the received short frame (The PE STA can determine a target PE beacon transmission time (TPBTT) comprising a random time offset from a TBTT, where the TPBTT does not change a timing synchronization function (TSF) timer corresponding to a PE AP transmitting the PE beacon frame. The TPBTT can occur during a PE beacon randomization window duration that is based on a percentage of the TBTT. Kneckt, para [0009]; computing, by the first network device, an expected integrity value for the received short frame (PE STA 620 can use the received random ID (e.g., random ID 2 from PE AP 612) and AP MLD ID 605 to calculate a checksum ID. PE STA 620 can compare the calculated checksum value with checksum ID 2 received in the PE beacon frame. Kneckt, para [0048]).; and verifying, by the first network device, the received short frame, based on comparing the expected integrity value and the integrity value indicated in the received short frame (PE STA 620 can use the received random ID (e.g., random ID 2 from PE AP 612) and AP MLD ID 605 to calculate a checksum ID. PE STA 620 can compare the calculated checksum value with checksum ID 2 received in the PE beacon frame. If the calculated checksum value substantially matches checksum ID2, PE STA 620 can verify the identity of PE AP 612. In other words, PE STA 620 determines that PE AP 612 affiliated with AP MLD 610 has been discovered. In some embodiments the checksum used in the comparison is a previously stored value. Kneckt, para [0048]). Kneckt does not explicitly teach an integrity value calculated by the second network device based on a target transmission time associated with the short frame (The timestamp may be included partially in the MIC calculation. For example, the first X number of bits (e.g., over 16 μseconds) of the timestamp field may be set to 0 (e.g., masked out). Because beacon frames may be transmitted at fixed intervals, such as every 100 time units (e.g., where each time unit is 1024 μseconds), even if one beacon transmission becomes delayed, the following beacon's planned transmission time may remain on the fixed 100 time unit interval of the originally planned transmission time (e.g., not the actual transmission time). Thus, the MIC may be determined in advance (i.e., prior to insertion of the timestamp field into the beacon frame) and compared to the actual timestamp received. For beacons transmitted at the correct planned time, the timestamp's lowest X bits (μseconds) may be 0. Unless a beacon is delayed by more than Y μseconds, the timestamp may not change. In such a manner, the partial timestamp may be included in the MIC calculations. Ouzieli, para [0061]); wherein the expected integrity value is based on the target transmission time determined by the first network device (The transmitting AP may use CMAC and GMAC cipher suites and the IGK to calculate the MIC over the group-addressed management frame. The AP may add the MIC to a group-addressed management frame body. The AP may use a management MIC IE (MMIE) for beacon frame protection A receiving STA may calculate the expected MIC on the received group-addressed management frame and may compare the result to the MIC field within the MMIE. The STA may not calculate the expected MIC using the MIC field within the MMIE. When the expected MIC matches the MIC field within the MMIE, the frame is valid. When the expected MIC differs from the MIC field within the MMIE, the STA may ignore the beacon as having been manipulated by a MIM attack. Ouzieli, para [0066]). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to modify the teaching of Kneckt in view of Ouzieli. One would be motivated to do so, to enhance the security of the system by using transmission time in calculating the integrity check code.; As per claim 15, Kneckt and Ouzieli teach the short frame protection method of claim 14, wherein the first network device comprises a station (STA) included in the wireless communication network, and wherein the second network device comprises an Access Point (AP) included in the wireless communication network (access point 110, Station 120 and network 150, Kneckt, Fig. 1 and related paragraphs). As per claim 16, Kneckt and Ouzieli teach the short frame protection method of claim 14, wherein: the received short frame is a protected beacon frame (privacy enhanced (PE) beacon frames. Kneckt, para [0004]); and the target transmission time is a Target Beacon Transmission Time (TBTT) or a Target Short Beacon Transmission Time (TSBTT) associated with transmission of the protected beacon frame by the second network device (neighbor AP info 852 includes target beacon transmission time (TBTT) info header 860 as well as TBTT info 870. TBTT info 870 field includes BSS parameters 880 and MLD parameters 890. Kneckt, para [0061])( The PE STA can determine a target PE beacon transmission time (TPBTT) comprising a random time offset from a TBTT, where the TPBTT does not change a timing synchronization function (TSF) timer corresponding to a PE AP transmitting the PE beacon frame. The TPBTT can occur during a PE beacon randomization window duration that is based on a percentage of the TBTT. Kneckt, para [0009]).. As per claim 17, Kneckt and Ouzieli teach the short frame protection method of claim 14, wherein at least a portion of the integrity value calculated by the second network device is included within or appended to the received short frame received by the first network device (a discovery beacon, according to some embodiments of the disclosure. Example 900 can include MAC header 910, country/transmission power envelope 915, reduced neighbor report (RNR) 920, and Management Message Integrity Check (MIC) Element (MME) 925. Kneckt, para [0065]); (An AP (e.g., AP 110 or a PE AP) can send a discovery beacon to advertise PE BSSs. As described above, in some embodiments, MAC header 910 can include an extension type (e.g., 11) and a subtype (e.g., 0011) that enables a PE STA to identify the discovery beacon (e.g., using random ID and checksum ID). Kneckt, para [0065]). As per claim 18, Kneckt and Ouzieli teach the short frame protection method of claim 14, wherein the received short frame includes a truncated integrity value calculated by the second network device (the calculated checksum value can be determined using a Hash Message Authentication Code (HMAC)-SHA and Address Resolution Key (ARK) functions shown below: Determined Checksum ID = Truncate-64(HMAC-SHA-256(ARK, “AP MLD ID”, Random ID)), where AP MLD ID is a 128 bit identifier of PE AP MLD 610, random ID is a 64 bit random ID 2 of PE AP 612, and determined Checksum value is a 64 bit Checksum ID 2 of PE AP 612. Kneckt, para [0049-0053]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. A. Cariou et al US 2021/0185607 A1 directed to multi-link parameters and capability indication. B. Wang et al. WO 2016045036 A1 directed to data communication method and relevant device. C. Kim et al. US 2008/159535 A1 directed to method for protecting broadcast frame, terminal authenticating broadcast frame and access point broadcasting frame. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KHALID M ALMAGHAYREH whose telephone number is (571)272-0179. The examiner can normally be reached Monday - Thursday 8AM-5PM EST & Friday variable. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, RUPAL DHARIA can be reached at (571)272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. Respectfully submitted /KHALID M ALMAGHAYREH/Primary Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Jun 05, 2025
Application Filed
Sep 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750392
AUTOMATIC GENERATION OF VULNERABILITY METRICS USING MACHINE LEARNING
2y 0m to grant Granted Sep 29, 2026
Patent 12730872
AUTHENTICATION DEVICE, AUTHENTICATION SYSTEM, AND AUTHENTICATION METHOD
1y 7m to grant Granted Sep 08, 2026
Patent 12706904
AUTHENTICATED MESSAGING SESSION WITH CONTACTLESS CARD AUTHENTICATION
1y 8m to grant Granted Aug 11, 2026
Patent 12694152
INFORMATION PROCESSING SYSTEM, INFORMATION PROCESSING METHOD, AND NON-TRANSITORY COMPUTER READABLE STORAGE MEDIUM
1y 9m to grant Granted Jul 28, 2026
Patent 12688438
DYNAMICALLY MONITORING VARIATIONS IN PROCESS EXPLAINABILITY WITHIN A DISTRIBUTED COMPUTING ENVIRONMENT
3y 1m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+24.0%)
2y 7m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 259 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month