Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed Action
Claims 1-3, 7-9, 11-15, and 19-21 are amended
Claim 10 is cancelled
Claims 1-9, and 11-21 are pending
Priority
This application claims priority to foreign application FRANCE 2006715 filed on 06/26/2020. All priority documents have been received. Therefore, the effective filing date of this application is 06/26/2020.
Response to Arguments
Applicant’s arguments filed on 03/11/2026 have been fully considered
With respect to the amendment of independent claim 1 of “eavesdropping and analyzing messages transmitted by radio waves …”. TODD teaches this limitation as can be seen in the following citation ([TODD, para. 0006] “The communication network 16 that is described herein, generally refers to the Internet, but could be any network which allows for terminals to be connected through any other suitable wired or wireless means for the exchange of data.”) ([TODD, para. 0082] “The network security device of the invention has at least one communication device port 2, which communicates with communication device(s) 12. … For example, the port could be an Ethernet port, or a serial, parallel or USB port, or an 802.11 or Bluetooth wireless connection, an infrared transceiver, or any other appropriate connection”). As can be seen from these citations of TODD the network security device is intercepting and analyzing data objects transmitted wirelessly by a communication device. A wireless transmission is a transmission of radio waves. Therefore, TODD teaches this newly amended limitation.
With respect to the arguments of “first cleartext sensitive data” for independent claim 1. Examiner is relying on a new reference NEUMANN to better teach this limitation. Furthermore, Examiner is no longer relying on PATHURI to teach the limitations of claim 1.
With respect to the arguments of claim 8. Examiner was relying on para. 0126 of TODD of deleting the sensitive information to teach “a modification of the value of said sensitive data”. However, the rejection is now being changed due to the amendments.
Additional arguments are moot in view of new grounds of rejection necessitated by the claim amendments.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
Claims 1, 11, and 12 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claim 1 is amended to recite of the limitation “a device of a network gateway type holding first cleartext sensitive data, said first cleartext sensitive data allowing a terminal of a first network managed by the device to connect to said device”. In Applicant’s remarks filed on 03/11/2026 Applicant has mentioned support for this amendment is found in para. 0020 and 0087 of the U.S. publication. Para. 0020 of the spec. recites ([spec., para. 0020] “The detection device provided does not need to decipher the analyzed messages. If the first terminal communicates the sensitive datum to the other terminal in an encrypted manner, the detection device provided does not detect the cleartext sensitive datum in the analyzed messages and does not then detect any security breach.”) and further in para. 0087 ([spec., para. 0087] “During this step E300, the device BX analyzes the contents of the messages sent to the new terminal in order to be able to detect a potential cleartext (without encryption or cipher) transmission of the password MDP.”) These citations do not provide adequate written description to describe a network gateway type holding first cleartext sensitive data. These paragraphs mention only of detecting for potential cleartext sensitive datum in messages that are transmitted. Furthermore, para. 0081 of the spec states ([spec., para. 0081] “The gateway BX holds the password MDP. This password MDP is a sensitive datum in the sense of the present invention. The gateway BX stores identifiers of the terminals PC and T known by the latter, for example their MAC addresses. These terminals PC and T form first terminals in the sense of the invention”). As can be seen in this citation, the gateway BX holds the password MDP which is the sensitive data. However, the paragraph does not describe that the password is stored in cleartext format in the gateway. Therefore, claims 1, 11, and 12 fail to comply with the written description requirement.
Claims 2-9 and 13-21 depend on claims 1 and 12. Therefore, claims 2-9 and 13-21 also inherit the rejection.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claim 1-9, and 11-21 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 11, and 12 recite the limitation "after detecting a presence of said first cleartext sensitive data …". It is unclear what is “after” referring to in this claim limitation. The claim limitation recites of detecting a presence of first cleartext sensitive data in at least one of the analyzed messages. However, the limitation does not recite what happens “after”. Furthermore, the following limitation recites of “upon receiving a request …” also does not clarify what happens after. For the purpose of examination Examiner is interpreting this limitation as “detecting a presence …” without the term “after”. Furthermore, the following limitation of “upon receiving a request …” is unclear in regards to when the request is being received. It is unclear if the request is received after or before the detecting. For the purpose of examination Examiner is interpreting this limitation to recite “and after detecting the presence of said first cleartext sensitive data receiving a request to …”. Appropriate correction is required.
Claims 2-9 and 13-21 depend on claims 1 and 12. Therefore, claims 2-9 and 13-21 also inherit the rejection.
Claim 1 recites the limitation "the cleartext sensitive data". There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination Examiner is interpreting this limitation as “the first cleartext sensitive data”. Appropriate correction is required.
Claims 2-9 depend on claim 1. Therefore, claims 2-9 also inherit the rejection.
Claims 1, 11, and 12 recite the limitation " said analyzed message". There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination Examiner is interpreting this limitation as “said analyzed messages”. Appropriate correction is required.
Claims 2-9 and 13-21 depend on claims 1 and 12. Therefore, claims 2-9 and 13-21 also inherit the rejection.
Claims 8 and 20 recite the limitation " said at least one countermeasure". There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination Examiner is interpreting this limitation as “said countermeasure”. Appropriate correction is required.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-3, 7-9, 11-15, and 19-21 are rejected under 35 U.S.C. 103 as being unpatentable over TODD (US-20070261112-A1) in view of NEUMANN (US-20180285558-A1), and further in view of BABU (US-20210136586-A1), hereinafter TODD-NEUMANN-BABU.
Regarding claim 1, TODD teaches “A method implemented by a device … said method comprising: ([TODD, abstract] “A network security device which acts as an “airlock” for traffic between a communications device and a network. Data is screened using rules based analysis by the security device to counter various threats, including viruses, phishing, attempts to “hijack” communications, communications with known malicious addresses or unknown addresses, and transmission of sensitive information.”) ([TODD, para. 0257] “security devices are placed at carefully selected gateways between subnetworks and key points of interest.”) eavesdropping and analyzing messages transmitted by radio waves from at least a first terminal of the first network to a second terminal through a second network not managed by the device, the first terminal being known to the device; and ([TODD, para. 0009] “The term “data object” 14 is used to refer to any stream of data that originates from a communication device 12 and is destined for a destination address at a server 18 or other communication device 12.”) ([TODD, para. 0068] “A communication device 12 is used to generate a data object 14, which is transmitted from the communication device 12 through network 16 to an external computing device, for example server 18. In this explanation, the data objects 14 are described as being destined for web servers, and server 18 is understood to be such a server.”) ([TODD, para. 0083] “the network security device may be inserted seamlessly and invisibly into a communication path between the communication device 12 and the network 16”) ([TODD, para. 0069] “The data object 14 upon transmission from the communication device 12, is transmitted directly to a network security device 1. The network security device 1 is used to analyze and filter data objects 14 that are sent to or from a communication device 12.”) ([TODD, para. 0257] “multiple security devices must be employed, each with carefully crafted rulesets, across the network.”) ([TODD, para. 0266, fig. 14] “Each network security device 151 a-151 c uses a separate, isolated connection 154 to central command network security device 153 to communicate log information, attack details, notable traffic, or any other security-related information. Updates can also be sent to and from the central command Network security device 153, as well as any other information which may need to be passed between various Network security devices 151 a-151 c on the local network.”) ([TODD, para. 0006] “The communication network 16 that is described herein, generally refers to the Internet, but could be any network which allows for terminals to be connected through any other suitable wired or wireless means for the exchange of data.”) ([TODD, para. 0082] “The network security device of the invention has at least one communication device port 2, which communicates with communication device(s) 12. … For example, the port could be an Ethernet port, or a serial, parallel or USB port, or an 802.11 or Bluetooth wireless connection, an infrared transceiver, or any other appropriate connection”) after detecting a presence of said … sensitive data in at least one of the analyzed messages transmitted to said second terminal … ([TODD, para. 0089] “When the network security device 1 has determined that a data object may not be suitable for transmission, the data object 14 is not transmitted to the destination address and the user is notified that the data has not been transmitted.”) ([TODD, para. 0110] “certain URLs may be blocked by the network security device, and certain patterns of information may be classified as potentially sensitive information and hence be restricted from being transmitted from the communication device. Specifically, one example of a pattern of information that may be predefined as part of the rule system would be any stream of numbers that resemble the convention used to record credit card numbers. If such a pattern of numbers is detected by the rules system, then a data object 14 containing such an object may not be transmitted to the intended destination address.”) ([TODD, para. 0009] “The term “data object” 14 is used to refer to any stream of data that originates from a communication device 12 and is destined for a destination address at a server 18 or other communication device 12.”)
However, TODD does not teach “… a device of a network gateway type holding said first cleartext sensitive data, said first cleartext sensitive data allowing a terminal of a first network managed by the device to connect to said device … upon receiving a request to connect to the device from a third terminal over the first network, the third terminal being not known to the device and the request comprising the … sensitive data that has been detected in said analyzed message implementing a countermeasure that results in the device refusing the request received from the third terminal”.
In analogous teaching NEUMANN teaches “… a device of a network gateway type holding said first cleartext sensitive data, said first cleartext sensitive data allowing a terminal of a first network managed by the device to connect to said device …” ([NEUMANN, para. 0005] “Constant passwords are an advantage from a usability point of view. Since the passwords do not change, they can be printed on a sticker on the gateway and users may still factory reset the gateway as this does not change the password. The user can then easily read the network password to connect a device to the gateway's WiFi network and the administrator password to manage the gateway.”) ([NEUMANN, para. 0045, figure 1] “In a variant, a specially arranged memory takes the place of the password display. The memory is connected to the gateway via a one-way connection, so that the gateway can write the password in the memory (possibly as a text file), but not read the memory from it. This are several ways of achieving this. For example, the memory may have two interfaces, a first interface arranged only to receive data (i.e., the password) from the gateway and a second interface arranged to output the data to another device, such as a computer.”) ([NEUMANN, para. 0011] “That the network password is for connecting to a network managed by device.”) ([NEUMANN, para. 0018] “the present principles are directed to a method for generating a network password for connecting to a network. A hardware processor of a device managing the network generates a network password from at least one non-static parameter, processes the network password to obtain a network password verification value, stores the network password verification value in a memory, transfers the network password through a one-way connection to a storage unit of the device for retrieval by the user”). [Examiner’s note: NEUMANN teaches of a gateway holding first cleartext sensitive data, as can be seen in para. 0045 the gateway writes the password in the memory as a text file.]
Thus, given the teaching of NEUMANN, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of cleartext sensitive data by NEUMANN into the teaching of a method for detecting a security breach by TODD. One of ordinary skill in the art would have been motivated to do so because NEUMANN recognizes the need to improve password reset and storage in devices ([NEUMANN, para. 0006] “use of constant passwords results in drawbacks when it comes to security.”) ([NEUMANN, para. 0047] “It will be appreciated that the present principles can provide a solution that provides a secure password reset mechanism in user devices.”)
However, TODD-NEUMANN does not teach “upon receiving a request to connect to the device from a third terminal over the first network, the third terminal being not known to the device and the request comprising the … sensitive data that has been detected in said analyzed message implementing a countermeasure that results in the device refusing the request received from the third terminal.”.
In analogous teaching BABU teaches “upon receiving a request to connect to the device from a third terminal over the first network, the third terminal being not known to the device and the request comprising the … sensitive data that has been detected in said analyzed message implementing a countermeasure that results in the device refusing the request received from the third terminal.” ([BABU, para. 0030] “These wireless signals 150 may contain secure information, such as an encryption key, that allows the intruder 140 to take over control of the secure device 130. The sniffer 120 is configured to detect an intruder 140 (through a method 300, discussed further below) and alert the master controller 110.”) ([BABU, para. 0031] “Referring now to FIG. 2, with continued reference to FIG. 1. FIG. 2 shows a flow chart of a method 200 of operating a wireless communication system”)([BABU, para. 0032] “Starting at block 204, the master controller 110 issues (i.e., transmits) a NONCE-GET to the secure device 130. At block 206, the secure device issues a NONCE-REPORT, which is unintentionally sent to an intruder 140 as well at block 206 a. At block 208, the master controller 110 and the secure device 130 exchange a key so that they can operate over a secure connection. … The key exchange is unintentional sent to the intruder 140 at block 208 a.”) ([BABU, para. 0037] “secure device 130 issues a NONCE-REPORT to the master controller 110 at block 320 as well as the intruder 140 at block 312 a. At block 322, the sniffer 120 determines that at least one of the NONCE-GET and the NONCE-REPORT is unintended … So now when the intruder attacks the secure device 130 with the old NONCE-REPORT and key at block 314 a, the secure device 130 will ignore the attack. Subsequently, the master controller will restore the secure device 130 state if it was changed by the intruder 140 at block 328.”).
Thus, given the teaching of BABU, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of receiving a connection request from an attacker and implementing a countermeasure by BABU into the teaching of a method for detecting a security breach by TODD-NEUMANN. One of ordinary skill in the art would have been motivated to do so because BABU recognizes the need for improved security in networks ([BABU, para. 0002] “Commonly, there are many different wireless protocols for home automation and security, one such example is Z-Wave protocol. … Protection against the above method and brute force methods is greatly desired.”) ([BABU, para. 0003] “a method of operating a secure wireless network between a master controller and a secure device is provided.”)
Regarding claim 11, this claim recites of a non-transitory computer readable medium storing instruction which once executed by a processor performs the steps of method claim 1. Therefore, claim 11 is rejected in a similar manner as in the rejection of claim 1.
Regarding claim 12, this claim recites of device for detecting a security breach by performing the steps of method claim 1. Therefore, claim 12 is rejected in a similar manner as in the rejection of claim 1.
Regarding claims 2 and 13, TODD-NEUMANN-BABU teaches all limitations of claims 1 and 12. TODD further teaches “wherein the eavesdropping comprises: monitoring destinations of the messages transmitted by said first terminal known to the device; ([TODD, para. 0069] “The network security device 1, which will be described in further detail below, determines whether a data object 14 may be transmitted to its intended destination address based on a set of rules”) said analyzing being implemented only for the messages that are transmitted to at least one destination terminal not known to the device. ([TODD, para. 0035] “Data is screened using rules based analysis by the security device to counter various threats, including viruses, phishing, attempts to “hijack” communications, communications with known malicious addresses or unknown addresses”) ([TODD, para. 0142] “If at step 205, it is determined that the destination address is not included in the allowable list of URLs, but is not explicitly disallowed, method proceeds to step 207. … If a decryption key is present, then 208 the unencrypted data processing method of FIG. 18 may be initiated. In order to initiate the unencrypted data processing method upon the data object 14, the data object is first decrypted, and the method is then executed upon the data object 14, as explained above in connection with FIG. 18.”)
Regarding claims 3 and 15, TODD-NEUMANN-BABU teaches all limitations of claims 1 and 12. TODD further teaches “in which said analyzing is implemented for a first duration starting from detection of a first message transmitted by the first terminal to the second terminal.” ([TODD, para. 0142] “the method is initiated (step 200) upon the determination that an encrypted data object 14 has been received by the security device 1. The processing of the buffered encrypted data object results in the extraction of the respective headers associated with the data object 14.”) ([TODD, para. 0126] “As data objects 14 are transmitted from the communication device 12 to the security device 1 through TCP/IP, packets from various layers of the TCP/IP protocol are analyzed. In an embodiment, the network device 1 is able to analyze data objects 14 that are transmitted at the network, transport and link layers of the TCP/IP protocol. … step 190: the security device 1 receives an unencrypted data object 14 step 191: the unencrypted data object that has been buffered is processed by extracting the data sections of the respective packets that are found in the buffered data”).
Regarding claims 7 and 19, TODD-NEUMANN-BABU teaches all limitations of claims 1 and 12. TODD further teaches “furthermore comprising, upon detecting the presence of said first … sensitive data, notifying a user of said device of the detected security breach and of an identifier of said second terminal.” ([TODD, para. 0089] “When the network security device 1 has determined that a data object may not be suitable for transmission, the data object 14 is not transmitted to the destination address and the user is notified that the data has not been transmitted. … Upon the user receiving notification of the data object 14 not having been transmitted, the user has the option of activating a tamper lock 11 that then allows for the data object to be transmitted to its destination address 20”) ([TODD, para. 0192] “notifying the user of a poisoned DNS, and automatically blacklisting and logging the malicious IP returned in the original reply”).
NEUMANN teaches of “… first cleartext sensitive data …” as seen in the rejection of claim 1. The same rejection and motivation apply.
Regarding claims 8 and 20, TODD-NEUMANN-BABU teaches all limitations of claims 1 and 20. TODD further teaches “wherein said at least one countermeasure is chosen from amongst: a modification of the value of said … sensitive data; an unpairing of terminals which have connected to said device for a second duration following said detection; a blocking from connection with said device of any terminal for a third duration following said detection; a maintaining of connection only for a terminal which has connected in the first place to said device following said detection; or a maintaining of connection only for a terminal which has connected to said device for a fourth duration following said detection and which has a Media Access Control (MAC) address identical to a MAC address of said second terminal.” ([TODD, para. 0126] “Upon the user being informed that the transmission has been restricted, the user has the option of overriding the decision made by the security device 1, and allowing the data object 14 to be transmitted even though it contains sensitive information. The user in an exemplary embodiment is able to override the decision by deleting the sensitive information”) ([TODD, para. 0109] “the rules flag the data object as objectionable, the transmission of the data object is blocked, and the network security device 1 will then take other actions, such as sending a message back to the communication device 12”). [Examiner’s note: Examiner is relying on deleting the sensitive information as taught in para. 0126 of TODD to teach modification of the value of said … sensitive data.]
NEUMANN teaches of “modification of … first cleartext sensitive data …” ([NEUMANN, para. 0030] “In step S20, generation of a new password is triggered. This is preferably done by the user pressing the factory reset button or another button on the gateway.”) ([NEUMANN, para. 0045] “a specially arranged memory takes the place of the password display. The memory is connected to the gateway via a one-way connection, so that the gateway can write the password in the memory (possibly as a text file), but not read the memory from it.”).
The same motivation to modify TODD with NEUMANN as in the rejection of claim 1 applies.
Regarding claims 9 and 21, TODD-NEUMANN-BABU teaches all limitations of claim 2. TODD further teaches “furthermore comprising, in absence of said detection, storing an identifier of the at least one destination terminal not known to the device in a memory comprising identifiers of terminals known by said device.” ([TODD, para. 0115] “the user can input the institutions he wishes to deal with, and the network security device automatically builds a “whitelist” of authorized, legitimate Internet servers where the user's financial information can safely be sent. It is crucial that the sensitive information database, the whitelist, and other related settings are continually updated and refreshed by the administrator of the device; the network security device can only guarantee the utmost safety of information that has been entered into it”) ([TODD, para. 0078] “The update from the secure server 19 could take place after specific URLs have been classified as allowed on the secure server 19, which would then update the database on the network security device 1. The URL database may contain a list of allowed URLs (“white list”), and disallowed URLs (“black list”).”) ([TODD, para. 0105] “This example will describe the operation of the network security device in terms of data flowing through the network security device 1 from the communication device 12 to a server 18 on the network 16”).
Regarding claim 14, TODD-NEUMANN-BABU teaches all limitations of claim 12. TODD further teaches “wherein the device is comprised in network termination equipment, an extender of coverage of a wireless communications network, a server for first cleartext sensitive data, or user equipment.” ([TODD, para. 0067] “the network security device of the invention has the ability to pass, drop, reject, mangle, or otherwise manipulate any packet passing through it, all in a completely transparent manner.”) ([TODD, para. 0058] “The network security device of the invention shares some attributes with a network bridge, in that it operates at the second-lowest level of the OSI network model (Layer 2, the link layer) and does not require an IP address to communicate on the network.”)
Claims 4, 6, 16, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over TODD-NEUMANN-BABU in view of PATHURI (US-20160112870-A1).
Regarding claims 4 and 16, TODD-NEUMANN-BABU teaches all limitations of claims 1 and 12. However, TODD-NEUMANN-BABU does not teach “furthermore comprising determining at least one characteristic of said other terminal from amongst: a manufacturer; a unique identifier UUID of a service used by said second terminal; or a prefix of a name of said second terminal; said analyzing being conditioned by a said characteristic of said second terminal”
In analogous teaching PATHURI teaches “furthermore comprising determining at least one characteristic of said other terminal from amongst: a manufacturer; a unique identifier UUID of a service used by said second terminal; or a prefix of a name of said second terminal; said analyzing being conditioned by a said characteristic of said second terminal” ([PATHURI, para. 0088] “The SDU UniqueId value may depend on the type of access device that is used and the type of values that may be accessed and/or generated by the type of access device. … the SDU UniqueId value may include a value that is unique to the access device itself, such as a serial number, UUID, or the like. In this example, the access device may retrieve the unique value from storage within the access device.”) ([PATHURI, para. 0089] “The access device may place the signature in a data packet and may transmit the data packet to the cloud network server with a communication signal. … The server then verifies whether the signatures match. Upon determining that the signatures match, the server authenticates the access device and allows it to communicate with one or more of the network devices associated with logical network”).
Thus, given the teaching of PATHURI, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of determining at least one characteristic of said other terminal by PATHURI into the teaching of a method for detecting a security breach by TODD-NEUMANN-BABU. One of ordinary skill in the art would have been motivated to do so because PATHURI recognizes the need to improve connectivity of network devices ([PATHURI, para. 0002] “Attaching wireless devices which do not include a user interface for entry of characters can be more complex, though security tokens can simplify this procedure. Further techniques for simplifying the connection of wireless devices to secured networks are needed”) ([PATHURI, para. 0004] “Storing the security credentials and transmitting them to a new device advantageously simplifies the connection of the new device to the secured network, as additional user input is not required in order for the new device to connect to the network”).
Regarding claims 6 and 18, TODD-NEUMANN-BABU teaches all limitations of claims 2 and 12. However, TODD-NEUMANN-BABU does not teach “in which said detecting comprises detecting a characteristic of said at least one not-known destination terminal from amongst a Media Access Control (MAC) address, a frequency change algorithm and a strength of transmission by said at least one not-known destination terminal”
In analogous teaching PATHURI teaches “in which said detecting comprises detecting a characteristic of said at least one not-known destination terminal from amongst a Media Access Control (MAC) address, a frequency change algorithm and a strength of transmission by said at least one not-known destination terminal.” ([PATHURI, para. 0057] “The network device may transmit the credentials to a server of a wide area network, such as a cloud network server. In some embodiments, the network device may also send to the server information relating to the network device (e.g., MAC address, serial number, or the like) and/or information relating to the access device (e.g., MAC address, serial number, application unique identifier, or the like).”) ([PATHURI, para. 0092] “For example, the status of a network device may refer to the network device's proximity to another network device and/or its ability to communicate with another network device because of the relative signal strength between the two network devices.”) ([PATHURI, para. 0009] “a variety of network credentials types and configurations are useful with the methods and devices described herein. For example, in embodiments, the network credentials comprise one or more of … a wireless transmission frequency”).
The same motivation to modify TODD-NEUMANN-BABU with PATHURI as in the rejection of claim 4 applies.
Claims 5 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over TODD-NEUMANN-BABU in view of POLO (US-20160165649-A1).
Regarding claims 5 and 17, TODD-NEUMANN-BABU teaches all limitations of claims 2 and 12. However, TODD-NEUMANN-BABU does not teach “in which said monitoring comprises eavesdropping on channels of an “advertising” type according to the Bluetooth standard.”
In analogous teaching POLO teaches “in which said monitoring comprises eavesdropping on channels of an “advertising” type according to the Bluetooth standard.” ([POLO, para. 0018] “The connections 118, 122 may be, for example, BLE connections, Bluetooth connections, or any other wireless connections. In order to establish the connections 118, 122, the wireless devices 102, 110, 114 may transmit connection request packets over a first channel, such as an advertising channel and/or an overhead channel, to initiate the connections 118, 122 on one or more second channels, such as data channels. The connection request packets may include control information for initiating the connections 118, 122 on the second channels, such as timing information, hopping pattern information, etc. Thus, an eavesdropping device that is able to intercept the connection request packets on the advertising channel, and access the control information contained therein, may be able to follow the wireless devices 102, 110, 114 to the connections 118, 122 on the data channels.”).
Thus, given the teaching of POLO, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of Bluetooth advertising channel by POLO into the teaching of a method for detecting a security breach by TODD-NEUMANN-BABU. One of ordinary skill in the art would have been motivated to do so because POLO recognizes the need to secure Bluetooth connectivity ([POLO, para. 0003] “communication between the two wireless devices may be followed by an eavesdropper from the BLE connection establishment. For example, an eavesdropper may discover the connection when the connection is initiated”) ([POLO, para. 0002] “present description relates generally to secure connection establishment including Bluetooth Low Energy (BLE) secure connection establishment”)
Pertinent Art
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure.
JORDAN (US-20040083393-A1): This prior art teaches of method and system for dynamically changing password-keys in a secured wireless communication system includes initiating a password key change, generating a new password key, embedding the new password key and a password key indicator in a first message, encrypting the first message using an old password key, storing the new password key, sending the formatted encrypted first message over a wireless communication system, receiving a subsequent second message, and decrypting the subsequent second message using the new password key.
SHEHORY (US-10333950-B2): This prior art teaches of defending against malicious electronic messages by analyzing electronic messages sent via a computer network to identify predefined risk elements found within the electronic messages, detecting attempts to perform computer-mediated actions that are associated with the electronic messages, identifying a potential security risk associated with the electronic messages and the computer-mediated actions, and performing a predefined preventive security action responsive to identifying the potential security risk.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFAQ ALI whose telephone number is (571)272-1571. The examiner can normally be reached Mon - Fri 7:30am - 5:30pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.A./
04/02/2026
/AFAQ ALI/Examiner, Art Unit 2434
/NOURA ZOUBAIR/Primary Examiner, Art Unit 2434