Prosecution Insights
Last updated: October 01, 2026
Application No. 19/204,036

COMMUNICATION METHOD AND APPARATUS

Non-Final OA §101§103§112
Filed
May 09, 2025
Priority
Nov 11, 2022 — continuation of PCTCN2022131518
Examiner
FARAMARZI, GITA
Art Unit
Tech Center
Assignee
Huawei Technologies Co., Ltd.
OA Round
1 (Non-Final)
51%
Grant Probability
Moderate
1-2
OA Rounds
2y 2m
Est. Remaining
70%
With Interview

Examiner Intelligence

Grants 51% of resolved cases
51%
Career Allowance Rate
41 granted / 80 resolved
-8.7% vs TC avg
Strong +19% interview lift
Without
With
+18.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
22 currently pending
Career history
122
Total Applications
across all art units

Statute-Specific Performance

§101
8.3%
-31.7% vs TC avg
§103
57.4%
+17.4% vs TC avg
§102
4.9%
-35.1% vs TC avg
§112
28.4%
-11.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 80 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims The following is a Non-Final Office Action in response to applicant’s filing on May 09, 2025. Claims 1-16 were canceled. Claims 17-36 are pending, of which claims 17, 24 and 30 are in independent form. Preliminary Amendment The preliminary amendment filed on 10/03/2025, canceling claims 1-16 and adding new claims 17-36, has been entered. Information Disclosure Statement The information disclosure statement (IDS) submitted on June 30, 2025, is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Specification The specification is objected to because the parenthetical in paragraph [0065] is empty, “The 5G mobile communication system may be non-standalone (NSA) or standalone ( )”. Appropriate correction is required. Claim Objections Claim 32 is objected to because of the following informalities: The term “wherein the receiving the second information” in claim 32 needs to be changed to “wherein receiving the second information”. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 30-36 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 30 is rejected as being indefinite. Claim 30 recites “An apparatus comprising: at least one processor; and at least one memory with instructions stored thereon, wherein the instructions, when executed by the at least one processor, enable the apparatus to:… a first security module is a security module serving the first node; and send the security policy to a second security module, wherein the security policy is configured to be used for secure communication between the first node and the second node, wherein the second security module is a security module serving the second node”. Claim 30 does not state whether the claimed apparatus is the first security module, comprises the first security module, is served by it, acts on its behalf or bears no relationship to it at all. One of ordinary skill in the art would not be apprised of the metes and bounds of claim 30, because it cannot be determined whether the first security module is a required element of the claimed apparatus or merely a feature of the environment in which the apparatus operates. Accordingly, the claim is indefinite. The same reasons apply to dependent claims 31-36 by virtue of dependency to their independent claim 30. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 17-36 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Analysis Step 1 (Statutory Categories) — 2019 PEG pq. 53 Claims 17-36 are directed to the statutory categories of invention. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 17 recites the following types of subject matter that are judicial exceptions: Abstract idea— mental processes: “…generating a security policy based on first information and second information,”. Recites evaluating two sets of information and reaching a policy decision based on the evaluated information. The information consists of: a trustworthiness requirement statement of a first node or a network global trustworthiness policy of the first node, and a trustworthiness requirement statement of a second node or a network global trustworthiness policy of the second node. For example, a person could review the respective trustworthiness requirements, compare them, and select a policy satisfying the applicable requirements. Such operations can be performed in the human mind or by using pen and paper. Accordingly, claim 17 is directed to an abstract idea. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 The claim recites additional elements “first and second security modules”, are recited at a high level of generality and are used as generic computer components to perform the abstract idea. The step “sending the security policy to a second security module” merely communicates the result of the abstract evaluation. The claim does not specify a technical procedure for delivering the policy. The sending step therefore constitutes insignificant post-solution activity. Merely transmitting the result of an abstract evaluation does not integrate the evaluation into a practical application. Further, the limitation “configured to be used for secure communication” identifies only the intended use of the generated policy. Accordingly, the claim does not recite any particular improvement to the operation of a computer or communication network. Therefore, claim 17 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 the additional elements, individually or in combination do not amount to significantly more than the abstract idea. Applying the method to a first security module merely invokes a generic computer as a tool for performing the abstract evaluation. Having respective security modules merely assigns the generic components to the parties whose information is evaluated. , sending a policy is a conventional data transmission function, stating that the policy is configured for secure communication is an intended use limitation that does not impose a technical operation. The steps are well-understood, routine and conventional activities in the field of a secure communication. The claim fails to recite an inventive concept sufficient to transform the abstract idea into a patent-eligible subject matter. Therefore, there is no specific technological improvement. Accordingly, under Step 2B of the PEG, the claim 17 is not patent eligible. Step 2A, Prong 1: Claim 18 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: Since claim 18 depends from claim 17, the abstract idea identified in claim 17 is incorporated into claim 18. Claim 18 further recites “receiving the second information from the second security module”. These limitations do not fall within Step 2A, Prong One because it does not recite a mental process. It merely identifies the additional data gathering activity. Claim 18 nevertheless recites the abstract idea through its dependency to claim 17. Therefore, claim 18 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2A, Prong 2: Claim 18 does not integrate the abstract idea into a practical application. The additional limitation “receiving the second information from the second security module”. This limitation does not integrate the exception into a practical application. The limitation does not specify a particular communication protocol and it constitutes insignificant data gathering activity. Therefore, claim 18 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B: Claim 18 does not include an inventive concept. Claim 18 does not recite an inventive concept sufficient to amount to significantly more than the judicial exception. The additional elements including “receiving the second information from the second security module” does not amount to significantly more than the judicial exception. The receiving step does not provide an inventive concept. Thus, under Step 2B of the PEG, the claim 18 is not patent eligible. Step 2A, Prong 1: Claim 19 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: Since claim 19 depends from claim 18, the abstract idea identified in claim 18 is incorporated into claim 19. Claim 18 further recites “receiving the second information … receiving a first request message from the second security module…. the first request message comprises the second information”. These limitations do not fall within Step 2A, Prong One because it does not recite a mental process. It merely identifies the additional data gathering activity. Claim 19 nevertheless recites the abstract idea through its dependency to claim 18. Therefore, claim 19 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2A, Prong 2: Claim 19 does not integrate the abstract idea into a practical application. The additional limitation “receiving the second information … receiving a first request message from the second security module…. the first request message comprises the second information”. This limitation does not integrate the exception into a practical application. The limitation does not specify a particular communication protocol and it constitutes insignificant data gathering activity. The statement that the message id “configured to request” security negotiation describes the message’s intended function but does not require a particular technical implementation of the negotiation. Therefore, claim 19 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B: Claim 19 does not include an inventive concept. Claim 19 does not recite an inventive concept sufficient to amount to significantly more than the judicial exception. The additional elements including “receiving a request, including information in the message, and identifying the message as a request” are well-understood, routine and conventional communication functions and do not amount to significantly more than the judicial exception. The receiving step does not provide an inventive concept. Thus, under Step 2B of the PEG, the claim 19 is not patent eligible. Step 2A, Prong 1: Claim 20 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: Since claim 20 depends from claim 17, the abstract idea identified in claim 20 is incorporated into claim 17. Claim 20 further recites “sending a second request message to the second security module, wherein the second request message is configured to request the second security module to perform security negotiation”. The limitation does not recite how security negotiation is technically performed. They merely require transmitting a message having a particular prepose. These limitation does not fall within Step 2A, Prong One because it does not recite a mental process. It merely transmitting a message having a particular purpose. Claim 20 nevertheless recites the abstract idea through its dependency to claim 17. Therefore, claim 20 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2A, Prong 2: Claim 20 does not integrate the abstract idea into a practical application. The additional limitation “sending a … request message …” merely initiates the exchange of information used in the abstract policy evaluation. Claim 20 does not specify a particular communication protocol or message structure. The language “configured to request the second security module to perform security negotiation” does not require the second security module to perform a particular technical negotiation procedure. Thus, the limitation does not integrate the exception into a practical application. Therefore, claim 20 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B: Claim 20 does not include an inventive concept. Claim 20 does not recite an inventive concept sufficient to amount to significantly more than the judicial exception. The additional elements including “sending a … request message …” is a generic transmission of a request message to another network component is well-understood, routine and conventional communication function and does not amount to significantly more than the judicial exception. The receiving step does not provide an inventive concept. Thus, under Step 2B of the PEG, the claim 20 is not patent eligible. Step 2A, Prong 1: Claim 21 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: Since claim 21 depends from claim 17, the abstract idea identified in claim 20 is incorporated into claim 17. Claim 21 further recites “the first information further comprises a trustworthiness configuration obtained from a management end; and the second information further comprises a trustworthiness configuration obtained from the management end.”. The limitation involves reviewing two sets of trustworthiness information and determining a policy based on the respective requirements or configurations. A person could review the stated trustworthiness requirements and policies through evaluation. Such operations can be performed in the human mind or by using pen and paper. Accordingly, claim 21 is directed to an abstract idea. Step 2A, Prong 2: Claim 21 does not integrate the abstract idea into a practical application. The additional limitation identifying the “management end” as a source of trustworthiness configurations merely limits where the information was generated. Claim 21 does not specify a particular communication protocol or message structure and it constitutes insignificant data-gathering activity and does not meaningfully limit how the abstract idea is performed. Therefore, claim 21 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B: Claim 21 does not include an inventive concept. Claim 21 does not recite an inventive concept sufficient to amount to significantly more than the judicial exception. The additional elements including “obtaining information, management end” are well-understood, routine and conventional communication function and does not amount to significantly more than the judicial exception. The additional limitations do not provide an inventive concept. Thus, under Step 2B of the PEG, the claim 21 is not patent eligible. Step 2A, Prong 1: Claim 22 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: Since claim 22 depends from claim 17, the abstract idea identified in claim 22 is incorporated into claim 17. Claim 22 further recites “the first security module is deployed within a user equipment (UE)”. This limitation is an additional element rather than part of identified mental process. However, merely locating the generic security module within a UE. The limitation nevertheless recites the abstract idea through its dependency to claim 17. Therefore, claim 22 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2A, Prong 2: Claim 22 does not integrate the abstract idea into a practical application. The additional limitation “security module deployed… within a user equipment ” merely locating the security module within a UE does not require a particular UE architecture. Thus, the limitation does not integrate the exception into a practical application. Therefore, claim 22 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B: Claim 22 does not include an inventive concept. Claim 22 does not recite an inventive concept sufficient to amount to significantly more than the judicial exception. The additional elements including “security module deployed… within a user equipment” is well-understood, routine and conventional implementation and does not amount to significantly more than the judicial exception. The deploying a security module step does not provide an inventive concept. Thus, under Step 2B of the PEG, the claim 22 is not patent eligible. Step 2A, Prong 1: Claim 23 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes: Since claim 22 depends from claim 17, the abstract idea identified in claim 22 is incorporated into claim 17. Claim 22 further recites “the first security module is deployed external to a user equipment (UE)”. This limitation is an additional element rather than part of identified mental process. However, merely locating the generic security module within a UE. The limitation nevertheless recites the abstract idea through its dependency to claim 17. Therefore, claim 23 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2A, Prong 2: Claim 23 does not integrate the abstract idea into a practical application. The additional limitation “the first security module is deployed external to a user equipment (UE)” merely locating the security module outside of a UE does not require a particular UE architecture. Thus, the limitation does not integrate the exception into a practical application. Therefore, claim 23 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B: Claim 23 does not include an inventive concept. Claim 23 does not recite an inventive concept sufficient to amount to significantly more than the judicial exception. The additional elements including “security module deployed… external to a user equipment” is well-understood, routine and conventional implementation and does not amount to significantly more than the judicial exception. The deploying a security module step does not provide an inventive concept. Thus, under Step 2B of the PEG, the claim 23 is not patent eligible. Claim 24 recites “A method applied to a second security module… determining second information” is an evaluation performed in the human mind and falls within the mental process grouping. Therefore, claim 24 recites the same abstract idea of claim 17. The recited limitations of claim 24 are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 25 is dependent on claim 24 and includes all the limitations of claim 24. Therefore, claim 25 recites the same abstract idea of claim 24. Claim 25 recites additional limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 26 is dependent on claim 25 and includes all the limitations of claim 25. Therefore, claim 26 recites the same abstract idea of claim 25. Claim 26 recites additional limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 27 is dependent on claim 25 and includes all the limitations of claim 25. Therefore, claim 27 recites the same abstract idea of claim 25. Claim 27 recites additional limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 28 is dependent on claim 24 and includes all the limitations of claim 24. Therefore, claim 28 recites the same abstract idea of claim 24. Claim 28 recites additional limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 29 is dependent on claim 24 and includes all the limitations of claim 24. Therefore, claim 29 recites the same abstract idea of claim 24. Claim 29 recites additional limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 30 includes all the limitations of claim 17. Therefore, claim 30 recites the same abstract idea of claim 17. Claim 30 recites the additional limitation “an apparatus …one processor; … one memory with instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 31 is dependent on claim 30 and includes all the limitations of claim 30. Therefore, claim 31 recites the same abstract idea of claim 30. Claim 31 recites additional limitations “an apparatus …one processor; … one memory with instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 32 is dependent on claim 31 and includes all the limitations of claim 31. Therefore, claim 32 recites the same abstract idea of claim 31. Claim 32 recites additional limitations “an apparatus …one processor; … one memory with instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 33 is dependent on claim 30 and includes all the limitations of claim 30. Therefore, claim 33 recites the same abstract idea of claim 30. Claim 33 recites additional limitations “an apparatus …one processor; … one memory with instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 34 is dependent on claim 30 and includes all the limitations of claim 30. Therefore, claim 34 recites the same abstract idea of claim 30. Claim 34 recites additional limitations “an apparatus …one processor; … one memory with instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 35 is dependent on claim 30 and includes all the limitations of claim 30. Therefore, claim 35 recites the same abstract idea of claim 30. Claim 35 recites additional limitations “an apparatus …one processor; … one memory with instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 36 is dependent on claim 30 and includes all the limitations of claim 30. Therefore, claim 36 recites the same abstract idea of claim 30. Claim 36 recites additional limitations “an apparatus …one processor; … one memory with instructions”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claims 17-36 are therefore rejected under 35 USC § 101. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 17-36 are rejected under 35 U.S.C. 103 as being unpatentable over Guo et al. (WO 2021/201857 A1), hereinafter Guo in view of FRANK (US 2015/0358354 A1), hereinafter FRANK. Regarding claim 17, Guo discloses a method applied to a first security module (Guo, Para. 0120, Example 8 is an apparatus configured to be employed in a User Equipment (UE), comprising: one or more processors configured to: process a Direct Communication Request from a peer UE, wherein the Direct Communication Request indicates security capabilities for the peer UE and a signaling security policy for the peer U), the method comprising: generating a security policy based on first information and second information (Guo, Para. 0085, the combination of security policies for UP Integrity Protection can result in the activation of integrity protection according to one or more of the following cases) and (Guo, Para. 0086, the resulting activation can be the same as the UP integrity protection activation, but based on the corresponding security policies for UP confidentiality protection instead of those for UP integrity protection), wherein the first information comprises a trustworthiness requirement statement of a first node or a network global trustworthiness policy of the first node (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, for NR PC5 Unicast, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF) and (Guo, Para. 0081), the second information comprises a trustworthiness requirement statement of a second node or a network global trustworthiness policy of the second node (Guo, Para. 0088, UE_1 502i can send a Direct Communication Request (DCR) to UE_2 5022. This message can comprise Nonce_1 (for session key KNRP-sess generation), UE_1 502i security capabilities (the list of algorithms that UE_1 502i will accept for this connection), the signaling security policy for UE_1 502i) and (Guo, Para. 0105, a Direct Communication Request (DCR) can be received at a receiving UE (e.g., UE_2 5022) from a peer UE (e.g., UE_1 502i), wherein the DCR can indicate security capabilities of the peer UE and a signaling integrity protection security policy of the peer UE), sending the security policy to a second security module (Guo, Para. 0091, UE_2 5022 can send a Direct Security Mode Command message to UE_1 502i. This message can comprise the n (wherein n is an integer, e.g., which can be predetermined (e.g., 8, etc.) or chosen by UE_2 5022) MSB of KNRP ID and optionally Key_Est_lnfo if a fresh KNRP is to be generated (see clause 5.3.3.1 .3). UE_2 5022 can include Nonce_2 to allow a session key to be calculated and the Chosen algs (“Chosen algorithms”) parameter to indicate which security algorithms the UEs will use to protect the data in the message), wherein the security policy is configured to be used for secure communication between the first node and the second node (Guo, Para. 0091, the Chosen algs can depend on the signaling security policy of UE_2 5022, for example, they can only indicate the use of the NULL integrity algorithm if the signaling security policy of UE_2 5022 has integrity as OFF or PREFERRED. UE_2 5022 can also include its security capabilities and signalling security policy in the information for UE_1 502i, so that UE_1 502i can make decision based on the security policy and security capability of UE_2 5022. UE_2 5022 can also return the UE_1 502i security capabilities and signaling security policy to provide protection against bidding down attacks) and (Guo, Para. 0109, in response to the peer UE accepting the connection, a direct security mode complete message can be received based on the new security context (e.g., based at least in part on the chosen algorithms)), Guo does not explicitly disclose the first security module is a security module serving the first node; and the second security module is a security module serving the second node. However, Frank teaches the first security module is a security module serving the first node (Frank, Para. 0055, a key management server (e.g., an HSM) 702 is configured to manage multiple remote stateless modules in mobile (client) devices 704, 706, 708 and 710); and the second security module is a security module serving the second node (Frank, Para. 0055, client device 704 includes a stateless hardware security Module (“SHSM”) 722). Guo and Frank are considered to be analogous to the claim invention because they are in the same field of generating, communicating and enforcing security policies between security components to protect communications between network devices. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Guo to incorporate the teachings of Frank to include the first security module is a security module serving the first node (Frank, Para. 0055); and the second security module is a security module serving the second node (Frank, Para. 0055). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Regarding claim 18, the combination of Guo in view of Frank teaches the method according to claim 17, further comprising: receiving the second information from the second security module (Guo, Para. 0105, a Direct Communication Request (DCR) can be received at a receiving UE (e.g., UE_2 5022) from a peer UE (e.g., UE_1 502i), wherein the DCR can indicate security capabilities of the peer UE and a signaling integrity protection security policy of the peer UE). Regarding claim 19, the combination of Guo in view of Frank teaches the method according to claim 18, wherein receiving the second information from the second security module comprises: receiving a first request message from the second security module (Guo, Para. 105, At 810, a Direct Communication Request (DCR) can be received at a receiving UE (e.g., UE_2 5022) from a peer UE (e.g., UE_1 502i), wherein the DCR can indicate security capabilities of the peer UE and a signaling integrity protection security policy of the peer UE), wherein the first request message is configured to request the first security module to perform security negotiation, and the first request message comprises the second information (Guo, Para. 104, FIG. 8, illustrated is a flow diagram of an example method employable at a receiving UE that facilitates V2X security policy negotiation between peer UEs, according to various embodiments discussed herein) and (Guo, Para. 105). Regarding claim 20, the combination of Guo in view of Frank teaches the method according to claim 17, further comprising: sending a second request message to the second security module (Guo, Para. 108, At 840, a direct security mode command can be transmitted, indicating the initiating (peer) UE’s security capabilities and signaling security policy), wherein the second request message is configured to request the second security module to perform security negotiation (Guo, Para. 0099, a direct security mode command can be received, indicating the initiating UE’s security capabilities and signaling security policy, the peer UE’s security capabilities and signaling security policy, and the chosen algorithms for security (e.g., which can be null)) and (Guo, Para. 0100, a determination can be made whether to accept or reject the connection based on the initiating UE’s security policy for signaling integrity protection, the chosen algorithms, and the peer UE’s security capabilities and signaling security policy) and (Guo, Para. 0101). Regarding claim 21, the combination of Guo in view of Frank teaches the method according to claim 17, wherein: the first information further comprises a trustworthiness configuration obtained from a management end (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF)); and the second information further comprises a trustworthiness configuration obtained from the management end (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF)) and (Guo, Para. 0088). Regarding claim 22, the combination of Guo in view of Frank teaches the method of claim 17, wherein the first security module is deployed within a user equipment (UE) (Frank, Para. 0060, the hardware security module 800, the mobile device includes and processor and memory for communication with the security module and for executing different functions. The stateless module (e.g., SHSM) may provide key protection and management (e.g., enforcing proper usage of keys) required for multiple levels of key material). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Guo to incorporate the teachings of Frank to include the method of claim 17, wherein the first security module is deployed within a user equipment (UE) (Frank, Para. 0060). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Regarding claim 23, the combination of Guo in view of Frank teaches the method of claim 17, wherein the first security module is deployed external to a user equipment (UE) (Frank, Para. 0055, a key management server (e.g., an HSM) 702 is configured to manage multiple remote stateless modules in mobile (client) devices 704, 706, 708 and 710. For example, client device 704 includes a stateless hardware security Module (“SHSM”) 722) and (Frank, Para. 0059, the stateless module provides a secure usage environment that may be remotely separated from, yet cryptographically secured to, the HSM). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Guo to incorporate the teachings of Frank to include wherein the first security module is deployed external to a user equipment (UE) (Frank, Para. 0055) and (Frank, Para. 0059). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Regarding claim 24, Guo discloses a method applied to a second security module (Guo, Para. 0105), the method comprising: determining second information (Guo, Para. 0076, UE_2 5022 can make a decision on whether to accept the connection based on the security capability and security policy of UE_1 502i and the security policy of UE_2 5022), wherein the second information is configured to be used by a first security module to generate a security policy based on first information (Guo, Para. 0085, the combination of security policies for UP Integrity Protection can result in the activation of integrity protection according to one or more of the following cases) and (Guo, Para. 0086, the resulting activation can be the same as the UP integrity protection activation, but based on the corresponding security policies for UP confidentiality protection instead of those for UP integrity protection), the first information comprises a trustworthiness requirement statement of a first node or a network global trustworthiness policy of the first node (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, for NR PC5 Unicast, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF) and (Guo, Para. 0081), the second information comprises a trustworthiness requirement statement of a second node or a network global trustworthiness policy of the second node (Guo, Para. 0088, UE_1 502i can send a Direct Communication Request (DCR) to UE_2 5022. This message can comprise Nonce_1 (for session key KNRP-sess generation), UE_1 502i security capabilities (the list of algorithms that UE_1 502i will accept for this connection), the signaling security policy for UE_1 502i) and (Guo, Para. 0105, a Direct Communication Request (DCR) can be received at a receiving UE (e.g., UE_2 5022) from a peer UE (e.g., UE_1 502i), wherein the DCR can indicate security capabilities of the peer UE and a signaling integrity protection security policy of the peer UE), and receiving the security policy from the first security module (Guo, Para. 0094, then UE_1 502i is ready to send and receive signalling and user plane traffic with the new security context. UE_1 502i can send an integrity protected and confidentiality protected (with the chosen algorithm, which can be the null algorithm) Direct Security Mode Complete message to UE_2 5022. UE_1 502i can form the KNRP-sess ID from the most significant bits it sent at 610 and least significant bits it received at 630), wherein the security policy is configured to be used for secure communication between the first node and the second node (Guo, Para. 0091, the Chosen algs can depend on the signaling security policy of UE_2 5022, for example, they can only indicate the use of the NULL integrity algorithm if the signaling security policy of UE_2 5022 has integrity as OFF or PREFERRED. UE_2 5022 can also include its security capabilities and signalling security policy in the information for UE_1 502i, so that UE_1 502i can make decision based on the security policy and security capability of UE_2 5022. UE_2 5022 can also return the UE_1 502i security capabilities and signaling security policy to provide protection against bidding down attacks) and (Guo, Para. 0109, in response to the peer UE accepting the connection, a direct security mode complete message can be received based on the new security context (e.g., based at least in part on the chosen algorithms)). Guo does not explicitly disclose the first security module is a security module serving the first node, and the second security module is a security module serving the second node; However, Frank teaches the first security module is a security module serving the first node (Frank, Para. 0055, a key management server (e.g., an HSM) 702 is configured to manage multiple remote stateless modules in mobile (client) devices 704, 706, 708 and 710); and the second security module is a security module serving the second node (Frank, Para. 0055, client device 704 includes a stateless hardware security Module (“SHSM”) 722). Guo and Frank are considered to be analogous to the claim invention because they are in the same field of generating, communicating and enforcing security policies between security components to protect communications between network devices. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Guo to incorporate the teachings of Frank to include the first security module is a security module serving the first node (Frank, Para. 0055); and the second security module is a security module serving the second node (Frank, Para. 0055). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Regarding claim 25, the combination of Guo in view of Frank teaches the method according to claim 24, further comprising: sending the second information to the first security module (Guo, Para. 0108, a direct security mode command can be transmitted, indicating the initiating (peer) UE’s security capabilities and signaling security policy, the receiving UE’s security capabilities and signaling security policy, and the chosen algorithms for security (e.g., which can be null)). Regarding claim 26, the combination of Guo in view of Frank teaches the method according to claim 25, wherein sending the second information to the first security module comprises: sending a first request message to the first security module (Guo, Para. 0108, a direct security mode command can be transmitted, indicating the initiating (peer) UE’s security capabilities and signaling security policy, the receiving UE’s security capabilities and signaling security policy, and the chosen algorithms for security (e.g., which can be null), wherein the first request message is configured to request the first security module to perform security negotiation (Guo, Para. 0092 and Table 2, upon receiving the Direct Security Mode Command, UE_1 502i can decide on whether to reject the connection or not based on its local policy and the security policy and security capability of UE_2 5022), and the first request message comprises the second information (Guo, Para. 0091, UE_2 5022 can also include its security capabilities and signalling security policy in the information for UE_1 502i, so that UE_1 502i can make decision based on the security policy and security capability of UE_2 5022). Regarding claim 27, the combination of Guo in view of Frank teaches the method according to claim 25, wherein the second security module is configured to store the security policy (Frank, Para. 0056, for a high security requirement, the HSM may provide all of the services for secure key management such as generating and destroying keys 714, establishing and enforcing a new key policy 716, using keys 718, providing key backup and secure key storage 720 and communicating with peers). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Guo to incorporate the teachings of Frank to include wherein the second security module is configured to store the security policy (Frank, Para. 0056). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Regarding claim 28, the combination of Guo in view of Frank teaches the method according to claim 24, further comprising: receiving a second request message from the first security module (Guo, Para. 0105, a Direct Communication Request (DCR) can be received at a receiving UE (e.g., UE_2 5022) from a peer UE (e.g., UE_1 502i)), wherein the second request message is configured to request the second security module to perform security negotiation (Guo, Para. 0099, a direct security mode command can be received, indicating the initiating UE’s security capabilities and signaling security policy, the peer UE’s security capabilities and signaling security policy, and the chosen algorithms for security (e.g., which can be null)) and (Guo, Para. 0100, a determination can be made whether to accept or reject the connection based on the initiating UE’s security policy for signaling integrity protection, the chosen algorithms, and the peer UE’s security capabilities and signaling security policy) and (Guo, Para. 0101). Regarding claim 29, the combination of Guo in view of Frank teaches the method according to claim 24, wherein: the first information further comprises a trustworthiness configuration obtained from a management end (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF)); and the second information further comprises a trustworthiness configuration obtained from the management end (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF)) and (Guo, Para. 0088). Regarding claim 30, Guo discloses an apparatus comprising: at least one processor(Guo, Para. 0064); and at least one memory with instructions stored thereon (Guo, Para. 0064), wherein the instructions, when executed by the at least one processor, enable the apparatus to (Guo, Para. 0104) and (Guo, Para. 0111): generate a security policy based on first information and second information (Guo, Para. 0085, the combination of security policies for UP Integrity Protection can result in the activation of integrity protection according to one or more of the following cases) and (Guo, Para. 0086, the resulting activation can be the same as the UP integrity protection activation, but based on the corresponding security policies for UP confidentiality protection instead of those for UP integrity protection), wherein the first information comprises a trustworthiness requirement statement of a first node or a network global trustworthiness policy of the first node (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, for NR PC5 Unicast, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF) and (Guo, Para. 0081), the second information comprises a trustworthiness requirement statement of a second node or a network global trustworthiness policy of the second node (Guo, Para. 0088, UE_1 502i can send a Direct Communication Request (DCR) to UE_2 5022. This message can comprise Nonce_1 (for session key KNRP-sess generation), UE_1 502i security capabilities (the list of algorithms that UE_1 502i will accept for this connection), the signaling security policy for UE_1 502i) and (Guo, Para. 0105, a Direct Communication Request (DCR) can be received at a receiving UE (e.g., UE_2 5022) from a peer UE (e.g., UE_1 502i), wherein the DCR can indicate security capabilities of the peer UE and a signaling integrity protection security policy of the peer UE), send the security policy to a second security module (Guo, Para. 0091, UE_2 5022 can send a Direct Security Mode Command message to UE_1 502i. This message can comprise the n (wherein n is an integer, e.g., which can be predetermined (e.g., 8, etc.) or chosen by UE_2 5022) MSB of KNRP ID and optionally Key_Est_lnfo if a fresh KNRP is to be generated (see clause 5.3.3.1 .3). UE_2 5022 can include Nonce_2 to allow a session key to be calculated and the Chosen algs (“Chosen algorithms”) parameter to indicate which security algorithms the UEs will use to protect the data in the message), wherein the security policy is configured to be used for secure communication between the first node and the second node (Guo, Para. 0091, the Chosen algs can depend on the signaling security policy of UE_2 5022, for example, they can only indicate the use of the NULL integrity algorithm if the signaling security policy of UE_2 5022 has integrity as OFF or PREFERRED. UE_2 5022 can also include its security capabilities and signalling security policy in the information for UE_1 502i, so that UE_1 502i can make decision based on the security policy and security capability of UE_2 5022. UE_2 5022 can also return the UE_1 502i security capabilities and signaling security policy to provide protection against bidding down attacks) and (Guo, Para. 0109, in response to the peer UE accepting the connection, a direct security mode complete message can be received based on the new security context (e.g., based at least in part on the chosen algorithms)), Guo does not explicitly disclose a first security module is a security module serving the first node; and wherein the second security module is a security module serving the second node. However, Frank teaches the first security module is a security module serving the first node (Frank, Para. 0055, a key management server (e.g., an HSM) 702 is configured to manage multiple remote stateless modules in mobile (client) devices 704, 706, 708 and 710); and the second security module is a security module serving the second node (Frank, Para. 0055, client device 704 includes a stateless hardware security Module (“SHSM”) 722). Guo and Frank are considered to be analogous to the claim invention because they are in the same field of generating, communicating and enforcing security policies between security components to protect communications between network devices. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Guo to incorporate the teachings of Frank to include the first security module is a security module serving the first node (Frank, Para. 0055); and the second security module is a security module serving the second node (Frank, Para. 0055). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Regarding claim 31, the combination of Guo in view of Frank teaches the apparatus according to claim 30, wherein the instructions, when executed by the at least one processor, further enable the apparatus to: receive the second information from the second security module (Guo, Para. 0105, a Direct Communication Request (DCR) can be received at a receiving UE (e.g., UE_2 5022) from a peer UE (e.g., UE_1 502i), wherein the DCR can indicate security capabilities of the peer UE and a signaling integrity protection security policy of the peer UE). Regarding claim 32, the combination of Guo in view of Frank teaches the apparatus according to claim 31, wherein the receiving the second information from the second security module comprises: receiving a first request message from the second security module (Guo, Para. 105, At 810, a Direct Communication Request (DCR) can be received at a receiving UE (e.g., UE_2 5022) from a peer UE (e.g., UE_1 502i), wherein the DCR can indicate security capabilities of the peer UE and a signaling integrity protection security policy of the peer UE), wherein the first request message is configured to request the first security module to perform security negotiation, and the first request message comprises the second information (Guo, Para. 104, FIG. 8, illustrated is a flow diagram of an example method employable at a receiving UE that facilitates V2X security policy negotiation between peer UEs, according to various embodiments discussed herein) and (Guo, Para. 105). Regarding claim 33, the combination of Guo in view of Frank teaches the apparatus according to claim 30, wherein the instructions, when executed by the at least one processor, further enable the apparatus to: send a second request message to the second security module (Guo, Para. 108, At 840, a direct security mode command can be transmitted, indicating the initiating (peer) UE’s security capabilities and signaling security policy), wherein the second request message is configured to request the second security module to perform security negotiation (Guo, Para. 0099, a direct security mode command can be received, indicating the initiating UE’s security capabilities and signaling security policy, the peer UE’s security capabilities and signaling security policy, and the chosen algorithms for security (e.g., which can be null)) and (Guo, Para. 0100, a determination can be made whether to accept or reject the connection based on the initiating UE’s security policy for signaling integrity protection, the chosen algorithms, and the peer UE’s security capabilities and signaling security policy) and (Guo, Para. 0101). Regarding claim 34, the combination of Guo in view of Frank teaches the apparatus according to claim 30, wherein: the first information further comprises a trustworthiness configuration obtained from a management end (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF)); and the second information further comprises a trustworthiness configuration obtained from the management end (Guo, Para. 0079, the PCF can also provision the UP (User Plane) security policy per V2X application, during service authorization and information provisioning procedure as defined in TS 23.287) and (Guo, Para. 0080, the UE can be provisioned with the following security policy: The list of V2X services, e.g. PSIDs or ITS-AIDs of the V2X applications, with Geographical Area(s) and their security policy which indicates the following: (1 ) Signalling integrity protection (REQUIRED/PREFERRED/OFF); (2) Signalling confidentiality protection (REQUIRED/PREFERRED/OFF); (3) User plane integrity protection (REQUIRED/PREFERRED/OFF); and/or (4) User plane confidentiality protection (REQUIRED/PREFERRED/OFF)) and (Guo, Para. 0088). Regarding claim 35, the combination of Guo in view of Frank teaches the apparatus according to claim 30, wherein the apparatus is comprised within a user equipment (UE) (Frank, Para. 0060, the hardware security module 800, the mobile device includes and processor and memory for communication with the security module and for executing different functions. The stateless module (e.g., SHSM) may provide key protection and management (e.g., enforcing proper usage of keys) required for multiple levels of key material). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Guo to incorporate the teachings of Frank to include the method of claim 17, wherein the first security module is deployed within a user equipment (UE) (Frank, Para. 0060). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Regarding claim 36, the combination of Guo in view of Frank teaches the apparatus according to claim 30, wherein the first security module is external to a user equipment (UE) (Frank, Para. 0055, a key management server (e.g., an HSM) 702 is configured to manage multiple remote stateless modules in mobile (client) devices 704, 706, 708 and 710. For example, client device 704 includes a stateless hardware security Module (“SHSM”) 722) and (Frank, Para. 0059, the stateless module provides a secure usage environment that may be remotely separated from, yet cryptographically secured to, the HSM). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Guo to incorporate the teachings of Frank to include wherein the first security module is deployed external to a user equipment (UE) (Frank, Para. 0055) and (Frank, Para. 0059). Doing so would aid to assign and enforce different security requirements (e.g., data integrity, data confidentiality, and/or non repudiation) to the data being processed/accessed, the function being invoked, the user and/or the location of the device. In one embodiment, the availability of functions of a mobile device change, depending on authentication of the user and/or location of the device (Frank, Para. 0030). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Guccione et al. (US 2014/0179271 A1) teaches methods and instrumentalities that enable one or more domains on one or more devices to be owned or controlled by one or more different local or remote owners, while providing a level of system-wide management of those domains. Each domain may have a different owner, and each owner may specify policies for operation of its domain and for operation of its domain in relation to the platform on which the domain resides, and other domains. A system-wide domain manager may be resident on one of the domains. The system-wide domain manager may enforce the policies of the domain on which it is resident, and it may coordinate the enforcement of the other domains by their respective policies in relation to the domain in which the system-wide domain manager resides. Additionally, the system-wide domain manager may coordinate interaction among the other domains in accordance with their respective policies. A domain application may be resident on one of the domains. The domain application may be ported to the platform based on a relationship between at least one domain owner and at least one other domain owner of the one or more domains. Atighetchi et al. (US 2021/0306227 A1) teaches techniques for metadata-based information provenance are disclosed. A node in a data provisioning layer receives encrypted payload data to be delivered to a recipient. The node generates provenance metadata that describes at least one action taken by the node with respect to the encrypted payload data. The node transmits the encrypted payload data and the provenance metadata via the data provisioning layer toward the recipient. Satish et al. (US 8,239,915 B1) teaches techniques for implementing dynamic endpoint management. In accordance with one embodiment, whenever an endpoint joins a managed network for the first time, or rejoins that network, a local security module submits a list of applications (e.g., all or incremental) to a security server. The server validates the list and sends back a rule set (e.g., allow/block rules and/or required application security settings) for those applications. If the server has no information for a given application, it may further subscribe to content from a content provider or service. When the server is queried regarding an unknown application, the server sends a query to the service provider to obtain a trust rating for that unknown application. The trust rating can then be used to generate a rule set for the unknown application. Functionality can be shifted from server to client, and vice-versa if so desired. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GITA FARAMARZI whose telephone number is (571)272-0248. The examiner can normally be reached Monday- Friday 9:00 am- 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GITA FARAMARZI/Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

May 09, 2025
Application Filed
Oct 09, 2025
Response after Non-Final Action
Aug 26, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12627633
SYSTEM AND METHOD FOR APPLICATION TRAFFIC AND RUNTIME BEHAVIOR LEARNING AND ENFORCEMENT
5y 9m to grant Granted May 12, 2026
Patent 12339997
ENTITY FOCUSED NATURAL LANGUAGE GENERATION
2y 1m to grant Granted Jun 24, 2025
Patent 12316648
Data value classifier
5y 10m to grant Granted May 27, 2025
Patent 12301564
VIRTUAL SESSION ACCESS MANAGEMENT
4y 3m to grant Granted May 13, 2025
Patent 12256022
BLOCKCHAIN TRANSACTION COMPRISING RUNNABLE CODE FOR HASH-BASED VERIFICATION
3y 3m to grant Granted Mar 18, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
51%
Grant Probability
70%
With Interview (+18.9%)
3y 7m (~2y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 80 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month