Prosecution Insights
Last updated: October 02, 2026
Application No. 19/199,111

METHODS AND APPARATUS FOR PERFORMING ACCESS AND/OR FORWARDING CONTROL IN WIRELESS NETWORKS SUCH AS WLANS

Non-Final OA §101§102§DOUBLEPATENT
Filed
May 05, 2025
Priority
Aug 16, 2017 — continuation of 11/051,169 +1 more
Examiner
DESROSIERS, EVANS
Art Unit
Tech Center
Assignee
Juniper Networks Inc.
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
866 granted / 1046 resolved
+22.8% vs TC avg
Strong +23% interview lift
Without
With
+23.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 12m
Avg Prosecution
20 currently pending
Career history
1072
Total Applications
across all art units

Statute-Specific Performance

§101
11.2%
-28.8% vs TC avg
§103
52.5%
+12.5% vs TC avg
§102
14.5%
-25.5% vs TC avg
§112
8.1%
-31.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1046 resolved cases

Office Action

§101 §102 §DOUBLEPATENT
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed Action This communication is in response to the application filed on 5/05/2025 in which Claims 1-9 are presented for examination. Drawings The applicant’s drawings submitted on 5/05/2025 are acceptable for examination purposes. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 21, 28 and 35 are rejected under 35 U.S.C. 101 because the claimed invention are directed to non-statutory subject matter. As to claim 21, 28 and 35, claims 21, 28 and 35 appear to be directed to an abstract idea rather than a practical application of the idea. The claim does not result in a physical transformation, nor does it appear to provide a useful, concrete and tangible result. The claimed step of "A network device comprising: memory; and one or more processors in communication with the memory, the one or more processors configured to: obtain a message from a source device…" Thus, what results from the claimed method is merely a data encryption/decryption. The encryption/decryption data is not claimed as applied in a practical application, which provides a tangible, i.e., real world result. encryption/decryption is not produced a tangible result, because it does not use the result of the connect in a practical application nor make the result available for use in such a form as to enable any usefulness of having performed the step of encrypting/decrypting to be realized. Instead, it appears to remain a mere abstraction. Therefore, claims 21, 28 and 35 are not statutory and it is rejected under 35 U. S. C. 101. Double Patenting The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). Claims 21-40 are provisionally rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over claims 1-20 of US patent No. 12342167. This is a provisional double patenting rejection since the conflicting claims have not yet been patented. Claims 21-40 recite similar limitations as claims 1-20 of US No. 12342167 as follows: Instant application US Application No. 12342167 Claim 21. A network device comprising: memory; and one or more processors in communication with the memory, the one or more processors configured to: obtain a message from a source device; decrypt the message based on a key associated with communication between the network device and the source device; determine that a destination device is associated with the key used to decrypt the message; and based on determining that the destination device is associated with the key, forward the message to the destination device. Claims 28, 35. Claim 1. A method comprising: determining, by a wireless access point and based on a message received from a first wireless terminal connected to the wireless access point, that the message is addressed to a second wireless terminal; determining, by the wireless access point, a key used to secure communications between the wireless access point and the first wireless terminal; determining, by the wireless access point, whether the second wireless terminal is associated with the key used to secure communications between the wireless access point and the first wireless terminal based on whether the second wireless terminal is connected to the wireless access point; and based on determining that the second wireless terminal is associated with the key used to secure communications between the wireless access point and the first wireless terminal, forwarding, by the wireless access point, the message to the second wireless terminal. Claims 11, 20. The table above shows that, although the corresponding claims are directed to different statutory categories, the US patent No.12342167 implemented on a computer would render the claims in the instant application obvious. It is clearly obvious that the (US No. 12342167) substantially discloses the subject matter of claim 1 of the instant Application. The Applicant merely broadens the scope of the instant application by deleting a few elements from the (US No 12342167). This is an obviousness-type double patenting rejection. The claims 22-27, 29-34 and 36-40 included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 21-40 is/are rejected under 35 U.S.C. 102(a)(1) and (a)(2) as being anticipated by Radpour U.S. Patent No. 20130103939 A 1 (hereinafter " Radpour"). As to claim 21, Radpour teaches a network device comprising: memory; and one or more processors in communication with the memory, the one or more processors configured to (Radpour Pa. [0082]) [according to one or more embodiments. As shown, CS 1510 can include a memory medium 3210 coupled to a processor 3110, and computer system 1510 can include a network interface 331]: obtain a message from a source device (Radpour Pa. [0019]) [The network provider can receive first encrypted data that includes an encryption key via an otherwise unsecured wireless communication from a mobile device utilizing the wireless network, where the encryption key is subsequently utilizable for secure wireless communications between the mobile device and the at least one wireless access point]; decrypt the message based on a key associated with communication between the network device and the source device (Radpour Pa. [0120]) [the first encrypted data that includes the encryption key can be decrypted to obtain the encryption key. For example, access server 1710 can decrypt the first encrypted data that includes the encryption key, the first data can be encrypted via a public encryption key, and access server 1710 can decrypt the first encrypted data via a private encryption key, associated with and/or paired with the public encryption key, to obtain the encryption key]; determine that a destination device is associated with the key used to decrypt the message; and based on determining that the destination device is associated with the key, forward the message to the destination device (Radpour Pa. [0080]) [ MD 1110 can construct a PTK based on the encryption key that was previously provided to or obtained by access server 1710. In one or more embodiments, the encryption key can be or include a PMK. As illustrated, MD 1110 can provide a MD nonce and a first message integrity code (MIC) to AP 1210. In one or more embodiments, a MIC can be or include a message authentication code that can be utilized to validate and/or verify an authenticity of a message. For instance, the MIC can be produced from a hash function (e.g., a cryptographic hash function) of the message and one or more of a shared secret and other data (e.g., a nonce, a timestamp, etc.).] As to claim 22, Radpour teaches wherein the network device comprises a wireless access point (Radpour Pa. [0004]) [wireless access point] As to claim 23, Radpour teaches wherein to determine that the destination device is associated with the key used to decrypt the message, the one or more processors are configured to determine whether the destination device is attached to the network device (Radpour Pa. [0043]) [of verifying an identity (e.g., an identity of a device, an identity of a user of a device, etc.). For example, one or more of a username, a password, a telephone identification (e.g., an IMSI, a MSISDN, a portion of a MSISDN, etc.), and a medium access control (MAC) address, among others, can be used to verify and/or authenticate an identity of a device, an identity of a user of a device,] (Radpour Pa. [0063]) [with and/or pair with the public encryption key. In one or more embodiments, the information of the authentication request and/or the encryption key encrypted based on the public encryption key can be decrypted utilizing the private encryption key that is associated with and/or pair with the public encryption key.], As to claim 24, Radpour teaches wherein to determine whether the destination device is attached to the network device (Radpour Fig. 1), the one or more processors are configured to determine that the network device has access to a key associated with communication between the network device and the destination device (Radpour Pa. [0022]) [access of the public network can be permitted, and the at least one wireless access point and the mobile device can communicate in a secure fashion based on the encryption key. For example, each of the at least one wireless access point and the mobile device can determine a pairwise transient key based on the encryption key (e.g., a pairwise master key). In one instance, the mobile can encrypt second data via the pairwise transient key] As to claim 25, Radpour teaches wherein to determine that the destination device is associated with the key used to decrypt the message, the one or more processors are configured to (Radpour Pa. [0120]) [the first encrypted data that includes the encryption key can be decrypted to obtain the encryption key. For example, access server 1710 can decrypt the first encrypted data that includes the encryption key, the first data can be encrypted via a public encryption key, and access server 1710 can decrypt the first encrypted data via a private encryption key, associated with and/or paired with the public encryption key, to obtain the encryption key]: receive, from a management node configured to manage key information for a plurality of network devices including the network device (Radpour Pa. [0019]) [he network provider can receive first encrypted data that includes an encryption key via an otherwise unsecured wireless communication from a mobile device utilizing the wireless network, where the encryption key is subsequently utilizable for secure wireless communications between the mobile device and the at least one wireless access point. T]; and determine that the destination device is associated with the key used to decrypt the message based on a key association record provided by the management node (Radpour Pa. [0022]) [access of the public network can be permitted, and the at least one wireless access point and the mobile device can communicate in a secure fashion based on the encryption key. For example, each of the at least one wireless access point and the mobile device can determine a pairwise transient key based on the encryption key (e.g., a pairwise master key). In one instance, the mobile can encrypt second data via the pairwise transient key] As to claim 26, Radpour teaches wherein to forward the message to the destination device, the one or more processors are configured to: encrypt the message with the key (Radpour Pa. [0019]) [The network provider can receive first encrypted data that includes an encryption key via an otherwise unsecured wireless communication from a mobile device utilizing the wireless network, where the encryption key is subsequently utilizable for secure wireless communications between the mobile device and the at least one wireless access point.] As to claim 27, Radpour teaches wherein the one or more processors are further configured to: prior to decrypting the message based on the key associated with communication between the network device and the source device, send a nonce to the source device; and determine that a response, generated by the source device and based on the nonce, matches an expected value for the key (Radpour Pa. [0120]) [the first encrypted data that includes the encryption key can be decrypted to obtain the encryption key. For example, access server 1710 can decrypt the first encrypted data that includes the encryption key, the first data can be encrypted via a public encryption key, and access server 1710 can decrypt the first encrypted data via a private encryption key, associated with and/or paired with the public encryption key, to obtain the encryption key] As to claims 28-34 claims 28-34 recite the claimed that respectively contain similar limitations as claims 21-27; therefore, they are rejected under the same rationale. As to claims 35 and 36-40 claims 35 and 36-40 recite the claimed that respectively contain similar limitations as claims 21 and 23-27; therefore, they are rejected under the same rationale. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. These include. US 20100115278 A1 – Shen et al. operating an access point (AP) configured to support multiple pre-shared keys at a given time to authenticate its associated client devices. Each client device associated with the AP is provisioned with a key. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to EVANS DESROSIERS whose telephone number is (571)270-5438. The examiner can normally be reached Monday -Friday 8:00 am - 5:30 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /EVANS DESROSIERS/Primary Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

May 05, 2025
Application Filed
Oct 22, 2025
Response after Non-Final Action
Aug 11, 2026
Non-Final Rejection mailed — §101, §102, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744685
METHOD FOR COMPUTER-IMPLEMENTED SERVICE PROVISION IN A BLOCKCHAIN, CORRESPONDING BLOCKCHAIN NETWORK NODE AND COMPUTER PROGRAM
2y 6m to grant Granted Sep 22, 2026
Patent 12719698
METHOD AND SYSTEM FOR BLOCKCHAIN-BASED COOPERATIVE SOCIETY TRANSACTIONS
1y 11m to grant Granted Aug 25, 2026
Patent 12699794
SYSTEMS AND METHODS OF FACILITATING CONTROLLING ACCESS TO DATA
1y 12m to grant Granted Aug 04, 2026
Patent 12682086
ELECTRONIC ACCESS CONTROL SYSTEM
2y 1m to grant Granted Jul 14, 2026
Patent 12683993
SYSTEM AND METHOD FOR PROVIDING FLEET CYBER-SECURITY
2y 0m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+23.1%)
2y 12m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1046 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month