DETAILED ACTION
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 30 April 2026 has been entered.
By the above submission, no claims have been amended, added, or canceled. Claims 1-32 are currently pending in the present application.
Response to Arguments
Applicant's arguments filed 30 April 2026 have been fully considered but they are not persuasive.
Regarding the objection to Figures 14-17 as requiring a prior art label, Applicant states that various paragraphs of the specification describe functionality performed at the illustrated units (pages 10-11 of the present response, citing paragraphs 0469-0503, 0505-0537, 0542-0575, and 0580-0611). However, Applicant provides no explanation of how such functionality is shown in the figures or any details of what such functionality may include. Although Applicant asserts that the requested information is provided in the cited paragraphs, Applicant has not explained what, specifically, in the over one hundred cited paragraphs, is considered to show specific functionality that does not constitute prior art implemented by generic elements such as receiving units, sending units, processing units, memories, processors, communication interfaces, and input modules.
Regarding the rejection of Claims 1-32 under 35 U.S.C. 101 as directed to abstract ideas without significantly more, and with particular reference to independent Claim 1, Applicant argues with respect to Step 2A that Claim 1 describes structure of a first node receiving a message from a second node and describes the basis of the generation of the PSK as well as the structure of the message (page 13 of the present response) and asserts that none of the structure and associated functions are directed to a mathematical function (page 13 of the present response). However, despite Applicant's assertions, the generation of the key and the generation of the authentication information based on parameters clearly constitute mathematical calculations, which are one of the groupings of abstract ideas set forth in MPEP § 2106.04(a)(2). Although Applicant argues that there is no step of generating a key (page 11 of the present response), Claim 1 explicitly recites “a PSK generated based on a second parameter… and a third parameter” in lines 6-7, as well as “the first identity authentication information is generated based on the first PSK and the first parameter or based on the first PSK and the first association request message” in lines 10-11.
Although Applicant argues that claim elements describe messaging and the structure of the messaging, operations performed to generate messages, and uses for the messaging, and argues that these are grounded in a hardware environment reciting non-generic structure (page 13 of the present response), the recitation of the first and second nodes are at a high level of generality and constitute nothing more than mere instructions to implement the abstract ideas on a computer, as per MPEP § 2106.05(f), or a recitation of a field of use or technological environment for the abstract idea as per MPEP § 2106.05(h). The claims clearly recite abstract ideas (the mathematical calculations noted above) that are not integrated into a practical application. Although Applicant argues that the specification defines the claimed node as an electronic device with a data receiving and sending capability (page 11 of the present response, citing paragraphs 0228 and 0229 of the present specification), this is, in fact, a generic description of an electronic device at a high level. Although Applicant notes that the specification provides specific embodiments of a node in a vehicle cockpit domain (page 11 of the present response), limitations from the specification are not read into the claims. Further, at most, a vehicle cockpit would be a field of use or technological environment for the abstract idea.
Applicant further argues with respect to Step 2B that the claims recite an inventive concept which is significantly more than the abstract ideas, asserting that the generation of keys based on particular parameters and alleges that this describes a technical methodology for dynamic, identity-linked key derivation that improves security because it is tied to parameters exchanged between specific nodes (page 13 of the present response). However, the independent claims do not specify what the various parameters may encompass, and therefore, there is no "identity-linked key derivation" from the specific parameters; rather, the key is only generated from arbitrary/abstract parameters which could be any numbers. This is still an abstract mathematical function and not significantly more. Although Applicant argues that a four parameter authentication request constitutes a specific improvement (page 13 of the present response), Applicant has not clearly explained the nexus between the specific claim elements and the alleged improvement, nor has Applicant clearly explained the substance of the alleged improvement.
Further, although Applicant argues that the remaining independent claims recite structure similar to Claim 1 (pages 13-14 of the present response), it is noted that Claims 19 and 28 are directed to distinct methods and apparatus that do not recite the same steps or structures. Although Applicant alleges that Claims 19 and 28 recite features that meet the standard for patent eligible subject matter (page 12 of the present response), Applicant does not provide any explanation of what these features in the other claims might be.
Regarding the rejection of Claims 1-32 under 35 U.S.C. 112(b) as indefinite, and with respect to independent Claims 1, 10, 19, and 28, Applicant argues that it is clear from the specification that the pre-shared key is obtained by being generated as taught in the specification (page 13 of the present response, citing paragraph 0261 of the specification). However, the use of the distinct terms "obtaining" and "generated" in the claims suggests that the obtaining is distinct from the generation of the key. It is not clear from where the key is actually obtained. Although Applicant indicates agreement that the generation of the PSK is different from obtaining the PSK, Applicant also argues that the specification discloses generation of the PSK and obtaining the PSK by a first node (page 14 of the present response, citing paragraphs 0266-0285). However, the claim still does not clearly recite from where the first node actually obtains the first PSK. Although the first PSK is generated, the claim does not recite where the first PSK is generated or how or from where the first node would obtain it after the generation of the key.
Also regarding the independent claims and other dependent claims, Applicant argues that there is support for algorithms in other paragraphs (pages 14 and 15 of the present response, citing Figure 1 and paragraphs 0230-0246). However, although there are general descriptions in these paragraphs of key generation algorithms, none of these are explicitly described in reference to a pre-shared key as claimed.
Regarding Claims 2, 11, 20, and 29, Applicant argues that the steps are performed by a first node (page 14 of the present response), but this does not apply to Claims 20 and 29. Applicant attempts to clarify that the steps for Claims 20 and 29 are performed by the second node (page 15 of the present response) but does not otherwise clearly address the limitations at issue. It is not clear whether the preamble of the independent claims applies to all steps of the dependent claims.
Further, Applicant argues that the verification is performed earlier (page 14 of the present response), but this does not clearly address the noted issues of whether the verification is a step of the method. Although Applicant argues that the verification need only be earlier than the sending step and successful (page 15 of the present response), this does not address whether the verification is itself a step of the method, i.e. whether the method includes the step of verifying or not.
Applicant also argues that there is support for the second identity authentication information (pages 14-15 of the present response), but it is noted that there is not clear antecedent basis for the more detailed limitation of second identity information that is based on the first PSK and fourth parameter. Although Applicant asserts that the claim specifies that the second identity authentication information is based on the first PSK and the fourth parameter (page 15 of the present response), it is noted that the claim does not provide this as a further limitation on the second identity authentication information, for example as a wherein clause such as “wherein the second identity authentication information is based on the first PSK and the fourth parameter” or similar.
Therefore, for the reasons detailed above, the Examiner maintains the rejections as set forth in the final Office action.
Drawings
The objection to Figures 14-17 as requiring a prior art label is NOT withdrawn for the reasons detailed above.
Figures 14-17 should be designated by a legend such as --Prior Art-- because only that which is old is illustrated. See MPEP § 608.02(g). Corrected drawings in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. The replacement sheet(s) should be labeled “Replacement Sheet” in the page header (as per 37 CFR 1.84(c)) so as not to obstruct any portion of the drawing figures. If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Claim Rejections - 35 USC § 101
The rejection of Claims 1-32 under 35 U.S.C. 101 as directed to abstract ideas without significantly more is NOT withdrawn for the reasons detailed above.
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-32 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract ideas without significantly more.
Claim 1 recites a method that includes receiving a first association request message, obtaining a first pre-shared key generated based on parameters, and sending a first authentication request message that includes first identity authentication information generated based on the PSK and parameters. The steps of generating the key and authentication information based on parameters are mathematical calculations. These constitute mathematical concepts, which are one of the groupings of abstract ideas set forth in MPEP § 2106.04(a)(2). Abstract ideas are judicial exceptions as per MPEP § 2106.04(I). See also Alice Corporation Pty. Ltd. v. CLS Bank, International, et al, 573 U.S. 208, 110 USPQ2d 1976 (2014).
This judicial exception is not integrated into a practical application because the claim does not recite a clear use or substantial further action for the generated information. The step of sending the message is insignificant post-solution activity, i.e. necessary output of the mathematical operations, as per MPEP § 2106.05(g). There is nothing that would result in a particular transformation, as per MPEP § 2106.05(c), nor does the claim require the use of the abstract ideas in conjunction with a particular machine or article of manufacture, as per MPEP § 2106.05(b). At most, the recitations of the nodes (e.g. that the method is performed by the first node) constitute nothing more than mere instructions to implement the abstract idea on a computer, as per MPEP § 2106.05(f), or a recitation of a field or use or technological environment for the abstract idea as per MPEP § 2106.05(h). The step of receiving a message constitutes data gathering, which is also insignificant extra-solution activity as per MPEP § 2106.05(g). Obtaining the pre-shared key appears to constitute either abstract mathematical calculations, as noted above, or mere data gathering. There are no additional elements that apply or use the abstract ideas in a meaningful way beyond merely linking the use of the judicial exceptions to a particular technological environment. Therefore, the claim is not directed to a practical application of the abstract ideas.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exceptions for similar reasons as detailed above with respect to the question of a practical application of the judicial exception. The steps of receiving and sending the message constitute receiving or sending data over a network, and obtaining the pre-shared key constitutes either receiving data over a network or retrieving data from memory, which have been recognized by the courts as well-understood, routine, and conventional functions. See MPEP § 2106.05(d)(II), citing Symantec, TLI, OIP Techs., buySAFE, and Versata. Therefore, the claim as a whole, whether the steps are considered individually or as an ordered combination, is not directed to significantly more than the abstract idea.
Similarly, Claim 19 recites a method that includes sending a first association request message, receiving a first authentication request message, and obtaining a second pre-shared key generated based on parameters. The step of generating the key based on parameters is a mathematical calculation. This constitutes a mathematical concept, which is one of the groupings of abstract ideas set forth in MPEP § 2106.04(a)(2). Abstract ideas are judicial exceptions as per MPEP § 2106.04(I). See also Alice Corporation Pty. Ltd. v. CLS Bank, International, et al, 573 U.S. 208, 110 USPQ2d 1976 (2014).
This judicial exception is not integrated into a practical application because the claim does not recite a clear use or substantial further action for the generated information. Although the claim recites that the obtained second PSK is used to verify the identity of the first node, this merely recites an intended use because the claim does not positively include an active step of verification (and it is further noted that verification, by itself, may constitute an abstract idea of a mental process if only generically recited). There is nothing that would result in a particular transformation, as per MPEP § 2106.05(c), nor does the claim require the use of the abstract ideas in conjunction with a particular machine or article of manufacture, as per MPEP § 2106.05(b). At most, the recitations of the nodes (e.g. that the method is performed by the second node) constitute nothing more than mere instructions to implement the abstract idea on a computer, as per MPEP § 2106.05(f), or a recitation of a field or use or technological environment for the abstract idea as per MPEP § 2106.05(h). The step of sending the message merely constitutes insignificant extra-solution activity, as per MPEP § 2106.05(g). The step of receiving a message constitutes data gathering, which is also insignificant extra-solution activity as per MPEP § 2106.05(g). Obtaining the pre-shared key appears to constitute either abstract mathematical calculations, as noted above, or mere data gathering. There are no additional elements that apply or use the abstract ideas in a meaningful way beyond merely linking the use of the judicial exceptions to a particular technological environment. Therefore, the claim is not directed to a practical application of the abstract ideas.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exceptions for similar reasons as detailed above with respect to the question of a practical application of the judicial exception. The steps of sending and receiving the messages constitute sending or receiving data over a network, and obtaining the pre-shared key constitutes either receiving data over a network or retrieving data from memory, which have been recognized by the courts as well-understood, routine, and conventional functions. See MPEP § 2106.05(d)(II), citing Symantec, TLI, OIP Techs., buySAFE, and Versata. Therefore, the claim as a whole, whether the steps are considered individually or as an ordered combination, is not directed to significantly more than the abstract idea.
Dependent Claims 2-9 and 20-27 only recite further detail of the abstract steps/functions of mathematical calculations by reciting additional calculations to compute or further details of the inputs to the functions. Therefore, the dependent claims do not provide a practical application or significantly more than the abstract ideas.
Claims 10-18 and 28-32 are directed to apparatus having functionality corresponding to the methods of Claims 1-9 and 19-23, respectively, and therefore, Claims 10-18 and 28-32 recite abstract ideas for similar reasons as detailed above with respect to Claims 1 and 19. The recitations of the processor and storage medium are at a generic level and constitute nothing more than mere instructions to implement the abstract ideas on a computer. See MPEP § 2106.05(f). Therefore, the apparatus claims are also not directed to significantly more than the abstract ideas.
Based upon consideration of all of the relevant factors with respect to the claims as an ordered combination and as a whole, Claims 1-32 are determined to be directed to abstract ideas without a practical application and without significantly more, as detailed above. Therefore, based on the above analysis, the claimed inventions are not directed to patent eligible subject matter.
Claim Rejections - 35 USC § 112
The rejection of Claims 1-32 under 35 U.S.C. 112(b) as indefinite is NOT withdrawn for the reasons detailed above, and because not all issues have been addressed, as detailed below.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-32 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 recites “obtaining a first pre-shared key” in line 5. However, it is not clear from where this key is obtained. The claim further recites that “the first PSK is a PSK generated based on a second parameter from the second node and a third parameter from the first node” in lines 6-7. However, the claim and specification do not clearly define an algorithm to be used to generate such a PSK. Similarly, the claim also recites “the first identity authentication information is generated based on the first PSK and the first parameter or based on the first PSK and the first association request message” in lines 9-11. Again, the claim and specification do not clearly define an algorithm to be used to generate such identity authentication information. The above ambiguities render the claim indefinite.
Claim 2 recites “receiving a first authentication response message from the second node” in line 3. It is not clear where this message is received. The claim further recites “an earlier successful verification performed at the second node on the second identity authentication information that is based on the first PSK and the fourth parameter” in lines 6-7. It is not clear when the verification of the second identity authentication information is performed, which amounts to a gap in the claim, or if the verification is a step of the claimed method. Further, there is not clear antecedent basis for “the second identity authentication information that is based on the first PSK and the fourth parameter”.
Claim 4 recites “generating the first PSK based on the first parameter and the fourth parameter” in lines 3-4. However, the claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 6 recites “generating the first PSK is further based on a first password” in lines 2-5. However, the claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 7 recites “generating the first PSK is further based on a first password and the first key agreement algorithm parameter” in lines 3-6. The claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 8 recites “generating the first PSK is further based on a first password and an intermediate key” in lines 3-6. The claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 10 recites “obtaining a first pre-shared key” in line 9. However, it is not clear from where this key is obtained. The claim further recites that “the first PSK is a PSK generated based on a second parameter from the second node and a third parameter from the first node” in lines 10-11. However, the claim and specification do not clearly define an algorithm to be used to generate such a PSK. Similarly, the claim also recites “the first identity authentication information is generated based on the first PSK and the first parameter or based on the first PSK and the first association request message” in lines 14-16. Again, the claim and specification do not clearly define an algorithm to be used to generate such identity authentication information. The above ambiguities render the claim indefinite.
Claim 11 recites “an earlier successful verification performed at the second node on the second identity authentication information that is based on the first PSK and the fourth parameter” in lines 6-8. It is not clear when the verification of the second identity authentication information is performed, which amounts to a gap in the claim, and further, the verification is not clearly a function of the claimed first node. Further, there is not clear antecedent basis for “the second identity authentication information that is based on the first PSK and the fourth parameter”.
Claim 13 recites “generating the first PSK based on the first parameter and the fourth parameter” in lines 3-4. the claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 15 recites “generating the first PSK is further based on a first password” in lines 2-5. However, the claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 16 recites “generating the first PSK is further based on a first password and the first key agreement algorithm parameter” in lines 3-6. The claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 17 recites “generating the first PSK is further based on a first password and an intermediate key” in lines 3-6. The claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 19 recites “obtaining a second pre-shared key” in line 7. However, it is not clear from where this key is obtained. The claim further recites that “the second PSK is a PSK generated based on a second parameter from a second node and a third parameter from the first node” in lines 8-9. However, the claims and specification do not clearly define an algorithm to be used to generate such a PSK. The above ambiguities render the claim indefinite.
Claim 20 recites “an earlier successful verification performed at the second node and on the first identity authentication information that is based on the second PSK and the first parameter” in lines 4-6. It is not clear when the verification of the second identity authentication information is performed, which amounts to a gap in the claim, or if the verification is a step of the claimed method. Further, there is not clear antecedent basis for “the second identity authentication information that is based on the first PSK and the first parameter”. The claim further recites “the second identity authentication information is generated based on the second PSK and the fourth parameter” in lines 8-9. The claims and specification do not clearly define an algorithm to be used to generate such identity authentication information.
Claim 22 recites “generating the second PSK based on the first parameter and the fourth parameter” in lines 3-4. However, the claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 24 recites “generating the second PSK is further based on a first password” in lines 2-5. However, the claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 25 recites “generating the second PSK is further based on a first password and the second key agreement algorithm parameter” in lines 3-6. The claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 26 recites “generating second PSK is further based on a first password and an intermediate key” in lines 3-6. The claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claim 28 recites “obtaining a second pre-shared key” in line 11. However, it is not clear from where this key is obtained. The claim further recites that “the second PSK is a PSK generated based on a second parameter from a second node and a third parameter from the first node” in lines 12-13. However, the claims and specification do not clearly define an algorithm to be used to generate such a PSK. The above ambiguities render the claim indefinite.
Claim 29 recites “an earlier successful verification performed at the second node and on the first identity authentication information that is based on the second PSK and the first parameter” in lines 4-6. It is not clear when the verification of the second identity authentication information is performed, which amounts to a gap in the claim. Further, there is not clear antecedent basis for “the second identity authentication information that is based on the first PSK and the first parameter”. The claim further recites “the second identity authentication information is generated based on the second PSK and the fourth parameter” in lines 8-9. The claims and specification do not clearly define an algorithm to be used to generate such identity authentication information.
Claim 31 recites “generating the second PSK based on the first parameter and the fourth parameter” in lines 3-4. However, the claims and specification do not clearly define an algorithm to be used to generate such a PSK.
Claims not explicitly referred to above are rejected due to their dependence on a rejected base claim.
Examiner’s Note
Because the claims are rendered indefinite due to the numerous issues as detailed above in reference to the rejections under 35 U.S.C. 112(b) and are also directed to non-eligible subject matter as detailed in the rejections under 35 U.S.C. 101, it has not been possible to fully construe pending Claims 1-32 in order to analyze the claims for novelty under 35 U.S.C. 102 and non-obviousness under 35 U.S.C. 103. As per MPEP § 2173.06 II, if there is uncertainty as to the proper interpretation of the limitations of the claim, it would not be proper to reject such a claim on the basis of prior art. See also In re Steele, 305 F.2d 859, 134 USPQ 292 (CCPA 1962). A search has been performed to the extent possible, and references that appear to be relevant are cited on the attached form PTOL-892.
Conclusion
All claims are identical to or patentably indistinct from, or have unity of invention with claims in the application prior to the entry of the submission under 37 CFR 1.114 (that is, restriction (including a lack of unity of invention) would not be proper) and all claims could have been finally rejected on the grounds and art of record in the next Office action if they had been entered in the application prior to entry under 37 CFR 1.114. Accordingly, THIS ACTION IS MADE FINAL even though it is a first action after the filing of a request for continued examination and the submission under 37 CFR 1.114. See MPEP § 706.07(b). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Zachary A Davis whose telephone number is (571)272-3870. The examiner can normally be reached Monday-Friday, 9:00am-5:30pm, Eastern Time.
Examiner interviews are available via telephone and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal D Dharia can be reached at (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Zachary A. Davis/Primary Examiner, Art Unit 2492