CTNF 18/108,920 CTNF 80923 DETAILED ACTION Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013 , is being examined under the first inventor to file provisions of the AIA. The instant application having application No. 18/108,920 of OROZCO CERVANTES et al. for “AUTHENTICATION WITH INFRARED LIGHT FOR DIGITAL KEYS” filed February 13, 2023 has been examined. Drawings Drawings Figures 1-3 submitted on February 13, 2023 are in compliance with the provisions of 37 CFR 1.121(d). Information Disclosure Statement The information disclosure statement (IDS) submitted on February 13, 2023 is being considered by the examiner. Claim Rejections - 35 USC § 102/103 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claim Rejections - 35 USC § 102 07-07-aia AIA 07-07 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – 07-08-aia AIA (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. 07-15 AIA Claim s 1-20 are rejected under 35 U.S.C. 102( a)(1 ) as being anticipated by the Prior Art of JOHANSSON et al. (U.S. Publication No. 2019/0312858 A1) hereafter “Johansson” . As to claim 1 , Johansson discloses a computer-implemented method for controlling access to a system ( authentication object may be stored in memory of a computer system, shown in Figures 1 - 3 , 9 and described in Paragraphs 0018 , 0035 , 0038 0042 - 0044 , 0058 and 0089 , meet the claimed limitations [i.e. a computer-implemented method for controlling access to a system ], See also Figures 4 - 8 and 10 ) based on multi-factor authentication using infrared light ( two factor authentication process, described in Paragraph 0025 , meet the claimed limitations [i.e. based on multi-factor authentication using infrared light ], see also Paragraphs 0024 and 0040 ), the computer-implemented method comprising: receiving a request for system authentication via a username and password ( the interface 218 includes a username field 220 and a password field 222 which, in this example, are graphical user interface elements that enable a user to enter (e.g., via a virtual or physical keyboard) alphanumeric input corresponding to respectively a username and password, shown in Figure 2 and described in Paragraph 0040 , meet the claimed limitations [i.e. the computer-implemented method comprising: receiving a request for system authentication via a username and password ], see also Figure 5 and described in Paragraph 0064 ); detecting infrared light communication capability on a second device ( short-range communication channel may be established using various technologies, such as induction wireless, infrared wireless (such as technologies operating according to specifications and protocols provided by the Infrared Data Association, or IrDA) or ultra wideband formats, described in Paragraph 0064 , meet the claimed limitations [i.e. detecting infrared light communication capability on a second device ] ); receiving a digital key transmitted via infrared light from the second device ( upon successful verification of the authentication object, provide cryptographically verifiable proof of successful authentication to the user device for use in proving successful authentication with the service provider 304. For example, the proof may be encrypted using a public key of a public/private key pair for which the service provider 304 has access to the private key, described in Paragraph 0049 , meet the claimed limitations [i.e. receiving a digital key transmitted via infrared light from the second device ] ); validating the received digital key; and granting system access based on the validation ( the proof may be digitally signed by the identity provider 306 using a private key of the identity provider such that the service provider 304 can verify the digital signature using a corresponding public key, described in Paragraph 0049 , meet the claimed limitations [i.e. validating the received digital key; and granting system access based on the validation ] ). As to claim 2 , the disclosure of Johansson as set forth above in claim 1, further Johansson discloses the method further comprising: identifying the digital key based on a light pattern emitted by the infrared light; and authenticating access based on the light pattern ( the authentication object 400 including or excluding the attestation and/or certificate may be digitally signed and/or encrypted using a key accessible to the authentication object manager, described in Paragraph 0061 and the authentication object manager executed by the mobile device 812 may cause an infrared LED included in the mobile device 812 to display infrared light in a particular pattern during drag and drop operations, described in Paragraph 0087 , meet the claimed limitations [i.e. identifying the digital key based on a light pattern emitted by the infrared light; and authenticating access based on the light pattern ], see also Paragraphs 0049 and 0059 - 0060 ). As to claim 3 , the disclosure of Johansson as set forth above in claim 1, further Johansson discloses the method further comprising: transmitting a dynamic token using infrared light ( the second device including the plurality of cameras may capture a one-time password (OTP) obtained from a one-time password token and the captured OTP may be included in the authentication object , described in Paragraph 0025 and The application server 1008 may provide static, dynamic or a combination of static and dynamic data in response to the received instructions. Dynamic data, such as data used in web logs (blogs), shopping applications, news services and other such applications may be generated by server-side structured languages as described herein or may be provided by a content management system (“CMS”) operating on, or under the control of, the application server. In one example, a user, through a device operated by the user, might submit a search request for a certain type of item. In this case, the data store might access the user information to verify the identity of the user, described in Paragraph 0100 , meet the claimed limitations [i.e. transmitting a dynamic token using infrared light ], see also Paragraphs 0049 and 0059 - 0060 ). As to claim 4 , the disclosure of Johansson as set forth above in claim 1, further Johansson discloses wherein the received infrared light is near infrared (NIR) light ( light-based data transfer (e.g., infrared data transfer), described in Paragraph 0064 ), and wherein the received infrared light is interpreted as binary data and transformed into a security token ( the authentication object manager executed by the mobile device 812 may cause an infrared LED included in the mobile device 812 to display infrared light in a particular pattern during drag and drop operations. The cameras 832 may then capture the pattern of infrared light and include information corresponding to the captured pattern in the authentication object, described in Paragraph 0087 ), secret key ( The attestation may be digitally signed and/or encrypted by the TPM, utilizing a key securely stored within the TPM and inaccessible to the authentication object manager . A certificate usable to verify this signature may be provided with the authentication object 400 in connection with an attestation. Other portions of the authentication object 400 including or excluding the attestation and/or certificate may be digitally signed and/or encrypted using a key accessible to the authentication object manager. Other variations are also considered as being within the scope of the present disclosure, described in Paragraph 0061 ), or password ( password-authenticated key agreement techniques, the pallier cryptosystem, the RSA encryption algorithm (PKCS#1), the Cramer-Shoup cryptosystem, the YAK authenticated key agreement protocol, described in Paragraph 0096 , meet the claimed limitations [i.e. wherein the received infrared light is near infrared (NIR) light, and wherein the received infrared light is interpreted as binary data and transformed into a security token, secret key, or password ] ). As to claim 5 , the disclosure of Johansson as set forth above in claim 4, further Johansson discloses the method further comprising: validating the security token, as key, or password against a previously stored role or username ( the authentication object may be stored in memory of a computer system providing the graphical user interface and accessed from memory to be provided for authentication, described in Paragraph 0018 and The attestation may be digitally signed and/or encrypted by the TPM, utilizing a key securely stored within the TPM and inaccessible to the authentication object manager . A certificate usable to verify this signature may be provided with the authentication object 400 in connection with an attestation. Other portions of the authentication object 400 including or excluding the attestation and/or certificate may be digitally signed and/or encrypted using a key accessible to the authentication object manager. Other variations are also considered as being within the scope of the present disclosure, described in Paragraphs 0061 and 0063 , meet the claimed limitations [i.e. validating the security token, as key, or password against a previously stored role or username ] ). As to claim 6 , the disclosure of Johansson as set forth above in claim 4, further Johansson discloses wherein the received infrared light is interpreted as binary data and transformed into a security token ( the authentication object manager executed by the mobile device 812 may cause an infrared LED included in the mobile device 812 to display infrared light in a particular pattern during drag and drop operations. The cameras 832 may then capture the pattern of infrared light and include information corresponding to the captured pattern in the authentication object, described in Paragraph 0087 ), secret key ( The attestation may be digitally signed and/or encrypted by the TPM, utilizing a key securely stored within the TPM and inaccessible to the authentication object manager . A certificate usable to verify this signature may be provided with the authentication object 400 in connection with an attestation. Other portions of the authentication object 400 including or excluding the attestation and/or certificate may be digitally signed and/or encrypted using a key accessible to the authentication object manager. Other variations are also considered as being within the scope of the present disclosure, described in Paragraph 0061 ), or password using encryption ( password-authenticated key agreement techniques, the pallier cryptosystem, the RSA encryption algorithm (PKCS#1), the Cramer-Shoup cryptosystem, the YAK authenticated key agreement protocol, described in Paragraph 0096 ), encoding ( an authentication object may encode a solution to a test (puzzle) configured to be easier for human users to solve than for automated agents. The test may be, for example, a completely automated public Turing test to tell computers and humans apart (CAPTCHA) test. In some embodiments, a user is able to interact with a user interface to input a solution to a test and perform a drag and drop operation of a proposed solution to the test to submit the proposed solution. The proposed solution may be encoded in an authentication object with additional information, described in Paragraph 0061 ), or plain text ( access control services in cooperation with the data store and is able to generate content including, but not limited to, text, graphics, audio, video and/or, described in Paragraph 0099 , meet the claimed limitations [i.e. wherein the received infrared light is interpreted as binary data and transformed into a security token, secret key, or password using encryption, encoding, or plain text ] ). As to claim 7 , the disclosure of Johansson as set forth above in claim 1, further Johansson discloses the method further comprising: prompting multi-factor authentication ( two factor authentication process, described in Paragraph 0025 [i.e. prompting multi-factor authentication ], see also Figure 7 and Paragraphs 0024 , 0040 and 0080 - 0083 ); transmitting infrared light communication ( The short-range communication channel may be established using various technologies, such as induction wireless, infrared wireless (such as technologies operating according to specifications and protocols provided by the Infrared Data Association, or IrDA), described in Paragraph 0064 and a computer-readable storage media reader, a communications device (e.g., a modem, a network card (wireless or wired), an infrared communication device, etc.), described in Paragraph 0107 ); reading the infrared light communication (light-based data transfer (e.g., infrared data transfer), an acoustic-based data transfer (e.g., sound wave-embedded data), or magnetic field-based transfer (e.g., reading data from a magnetic stripe) may be used for inter-device communication , described in Paragraph 0064 ), which is invisible to an unaided eye ( the mobile device may be a smartphone or tablet computing device, although the techniques described in connection with FIG. 8 are not limited to such devices. Furthermore, the mobile device 812 may include one or more cameras 832, the cameras 832 may include a flash or other light emitting device such as a light emitting diode (LED). The cameras 832 may be configured to capture information during the execution of one or more operations utilizing the authentication object manager executed by the mobile device 812, described in Paragraph 0083 ); and granting access permissions based on the read infrared light communication ( step 716 shown in Figure 7 and described in Paragraphs 0082 - 0083 ). As to claim 8 , Johansson discloses a computer program product ( the authentication object may be stored in memory of a computer system providing the graphical user interface and accessed from memory to be provided for authentication, shown in Figures 1 - 3 , 9 and described in Paragraphs 0018 , 0035 , 0038 0042 - 0044 , 0058 and 0089 , meet the claimed limitations [i.e. a computer program product ], See also Figures 4 - 8 and 10 ), comprising a non-transitory tangible storage device having program code embodied therewith ( the authentication object may be stored in memory of a computer system providing the graphical user interface and accessed from memory to be provided for authentication, described in Paragraphs 0018 , 0058 and 0089 , meet the claimed limitations [i.e. a non-transitory tangible storage device having program code embodied therewith ] ), the program code executable by a processor of a computer to perform a method ( shown in Figure 7 and described in Paragraphs 0080 and 0093 , meet the claimed limitations [i.e. the program code executable by a processor of a computer to perform a method ] ), the method comprising: receiving a request for system authentication via a username and password ( the interface 218 includes a username field 220 and a password field 222 which, in this example, are graphical user interface elements that enable a user to enter (e.g., via a virtual or physical keyboard) alphanumeric input corresponding to respectively a username and password, shown in Figure 2 and described in Paragraph 0040 , meet the claimed limitations [i.e. the method comprising: receiving a request for system authentication via a username and password ], see also Figure 5 and described in Paragraph 0064 ); detecting infrared light communication capability on a second device ( short-range communication channel may be established using various technologies, such as induction wireless, infrared wireless (such as technologies operating according to specifications and protocols provided by the Infrared Data Association, or IrDA) or ultra wideband formats, described in Paragraph 0064 , meet the claimed limitations [i.e. detecting infrared light communication capability on a second device ] ); receiving a digital key transmitted via infrared light from the second device ( upon successful verification of the authentication object, provide cryptographically verifiable proof of successful authentication to the user device for use in proving successful authentication with the service provider 304. For example, the proof may be encrypted using a public key of a public/private key pair for which the service provider 304 has access to the private key, described in Paragraph 0049 , meet the claimed limitations [i.e. receiving a digital key transmitted via infrared light from the second device ] ); validating the received digital key; and granting system access based on the validation ( the proof may be digitally signed by the identity provider 306 using a private key of the identity provider such that the service provider 304 can verify the digital signature using a corresponding public key, described in Paragraph 0049 , meet the claimed limitations [i.e. validating the received digital key; and granting system access based on the validation ] ). As to claim 9 , the claim recites a computer program product that parallels the computer-implemented method of claim 2. Therefore, the analysis discussed above with respect to claim 2 also applies to claim 9. Accordingly, claim 9 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 2. As to claim 10 , the claim recites a computer program product that parallels the computer-implemented method of claim 3. Therefore, the analysis discussed above with respect to claim 3 also applies to claim 10. Accordingly, claim 10 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 3. As to claim 11 , the claim recites a computer program product that parallels the computer-implemented method of claim 4. Therefore, the analysis discussed above with respect to claim 4 also applies to claim 11. Accordingly, claim 11 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 4. As to claim 12 , the claim recites a computer program product that parallels the computer-implemented method of claim 5. Therefore, the analysis discussed above with respect to claim 5 also applies to claim 12. Accordingly, claim 12 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 5. As to claim 13 , the claim recites a computer program product that parallels the computer-implemented method of claim 6. Therefore, the analysis discussed above with respect to claim 6 also applies to claim 13. Accordingly, claim 13 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 6. As to claim 14 , the claim recites a computer program product that parallels the computer-implemented method of claim 7. Therefore, the analysis discussed above with respect to claim 7 also applies to claim 14. Accordingly, claim 14 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 7. As to claim 15 , Johansson discloses a computer system ( a computer system providing the graphical user interface, shown in Figures 1 - 3 , 9 and described in Paragraphs 0018 , 0035 , 0038 0042 - 0044 , 0058 and 0089 , meet the claimed limitations [i.e. a computer system ], See also Figures 4 - 8 and 10 ), comprising: one or more computer devices ( the authentication object may be stored in memory of a computer system providing the graphical user interface and accessed from memory to be provided for authentication, shown in Figures 1 , 3 , 9 , 10 and described in Paragraphs 0018 , 0035 , 0038 0042 - 0044 , 0058 and 0089 , meet the claimed limitations [i.e. comprising: one or more computer devices ], See also Figures 2 and 4 - 8 ) each having one or more processors ( shown in Figure 7 and described in Paragraphs 0080 and 0093 , meet the claimed limitations [i.e. the program code executable by a processor of a computer to perform a method ] ) and one or more tangible storage devices ( the authentication object may be stored in memory of a computer system providing the graphical user interface and accessed from memory to be provided for authentication, described in Paragraphs 0018 , 0058 and 0089 , meet the claimed limitations [i.e. one or more tangible storage devices ] ); and a program embodied on at least one of the one or more storage devices ( the authentication object may be stored in memory of a computer system providing the graphical user interface and accessed from memory to be provided for authentication, described in Paragraphs 0018 , 0058 and 0089 , meet the claimed limitations [i.e. a program embodied on at least one of the one or more storage devices ] ), the program having a plurality of program instructions for execution by the one or more processors ( shown in Figure 7 and described in Paragraphs 0080 and 0093 , meet the claimed limitations [i.e. the program having a plurality of program instructions for execution by the one or more processors ] ), the program instructions comprising instructions for: receiving a request for system authentication via a username and password ( the interface 218 includes a username field 220 and a password field 222 which, in this example, are graphical user interface elements that enable a user to enter (e.g., via a virtual or physical keyboard) alphanumeric input corresponding to respectively a username and password, shown in Figure 2 and described in Paragraph 0040 , meet the claimed limitations [i.e. the program instructions comprising instructions for: receiving a request for system authentication via a username and password ], see also Figure 5 and described in Paragraph 0064 ); detecting infrared light communication capability on a second device ( short-range communication channel may be established using various technologies, such as induction wireless, infrared wireless (such as technologies operating according to specifications and protocols provided by the Infrared Data Association, or IrDA) or ultra wideband formats, described in Paragraph 0064 , meet the claimed limitations [i.e. detecting infrared light communication capability on a second device ] ); receiving a digital key transmitted via infrared light from the second device ( upon successful verification of the authentication object, provide cryptographically verifiable proof of successful authentication to the user device for use in proving successful authentication with the service provider 304. For example, the proof may be encrypted using a public key of a public/private key pair for which the service provider 304 has access to the private key, described in Paragraph 0049 , meet the claimed limitations [i.e. receiving a digital key transmitted via infrared light from the second device ] ); validating the received digital key; and granting system access based on the validation ( the proof may be digitally signed by the identity provider 306 using a private key of the identity provider such that the service provider 304 can verify the digital signature using a corresponding public key, described in Paragraph 0049 , meet the claimed limitations [i.e. validating the received digital key; and granting system access based on the validation ] ). As to claim 16 , the claim recites a computer program product that parallels the computer system of claim 2. Therefore, the analysis discussed above with respect to claim 2 also applies to claim 16. Accordingly, claim 16 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 2. As to claim 17 , the claim recites a computer program product that parallels the computer system of claim 3. Therefore, the analysis discussed above with respect to claim 3 also applies to claim 17. Accordingly, claim 17 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 3. As to claim 18 , the claim recites a computer program product that parallels the computer system of claim 4. Therefore, the analysis discussed above with respect to claim 4 also applies to claim 18. Accordingly, claim 18 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 4. As to claim 19 , the claim recites a computer program product that parallels the computer system of claim 5. Therefore, the analysis discussed above with respect to claim 5 also applies to claim 19. Accordingly, claim 19 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 5. As to claim 20 , the claim recites a computer program product that parallels the computer system of claim 6. Therefore, the analysis discussed above with respect to claim 6 also applies to claim 20. Accordingly, claim 20 is rejected by the prior art of Johansson under the same rationale as set forth above with respect to claim 6 . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following cited arts are further to show the state of related art . U.S. Publication No. 2013/0298208 A1 of AYED , discloses a method and apparatus for mobile security using a short wireless device. The method and device increases mobile device security and data security and reduces false alerts. U.S. Patent No. 9,386,003 B2 to KUMAR , discloses systems and methods directed towards a highly secure and intelligent, end to end provisioning, authentication, and transaction system which creates and/or consolidates user data for a unified profile for the user (e.g., a person, place, organization, object, etc.) to allow for the safe, secure, and verifiable exchange of information. WIPO Publication No. WO 2016/174154 A1 of WAGNER et al , discloses a method and a system for authenticating a user by means of a merely temporarily used, it strange and quasi publicly accessible terminal in a via a network, in particular via the Internet, reachable server, the user access to a personalized online service For example, access to social media is possible. Correspondence Any inquiry concerning this communication or earlier communications from the examiner should be directed to SISAY YACOB whose telephone number is (571)272-8562. The examiner can normally be reached Monday - Friday 10:30-07:00 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, BRIAN A ZIMMERMAN can be reached at (571) 272-3059. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SISAY YACOB/ May 12, 2026 Primary Examiner, Art Unit 2686 Application/Control Number: 18/108,920 Page 2 Art Unit: 2686 Application/Control Number: 18/108,920 Page 3 Art Unit: 2686 Application/Control Number: 18/108,920 Page 4 Art Unit: 2686