DETAILED ACTION
Claims 11 and 23 are canceled.
Claims 25 and 26 are new.
Claims 1-10, 12-22, and 24-26 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 05/11/2026 has been entered.
Response to Arguments
Applicant's arguments filed 05/11/2026 have been fully considered but they are not persuasive.
Regarding applicant’s argument, from pages 3-9, that the prior art of record does not teach all the limitations of the newly amended claims, Examiner agrees, however, this argument is moot in view of new grounds of rejection.
Regarding applicant arguments, from pages 9-11, that claims 3 and 15 are allowable because the prior art of record does not teach all the limitations of the newly amended independent claims and therefore cannot teach the limitations of dependent claims 3 and 15, this argument is moot. As stated earlier, the newly amended claim limitations are rejected under new grounds of rejection, therefore, dependent claims 3 and 15 remain rejected.
Regarding applicant arguments, from pages 11-13, that claims 4 and 16 are allowable because the prior art of record does not teach all the limitations of the newly amended independent claims and therefore cannot teach the limitations of dependent claims 4 and 16, this argument is moot. As stated earlier, the newly amended claim limitations are rejected under new grounds of rejection, therefore, dependent claims 4 and 16 remain rejected.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claim(s) 1-3, 5-10, 12-15, 17-22 and 24-26 is/are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent Pub. No. 20130145426 A1 to Wright et al. (Wright) in view of U.S. Patent Pub. No. 20210256111 A1 to Ilincic et al. (Ilincic).
Regarding claim 1, Wright teaches a collaborative security management system, comprising: a processing device in communication with a plurality of user devices (Wright [0065], e.g., More particularly, a service provider system 102 is coupled to communicate bidirectionally through a communications network, or cloud, 104, with a user system 106 and a designated recipient system 108); and a memory device in communication with the processing device (Wright [0105], e.g., any other computer-readable storage medium, wherein, when the computer program code is loaded into and executed by a computer), the memory device storing instructions (Wright [0105], e.g., any other computer-readable storage medium, wherein, when the computer program code is loaded into and executed by a computer) that when executed by the processing device result in: storing a plurality of data structures in the memory device (Wright [0062], e.g., The user's legacy may contain legal documents), each of the data structures including secured information (Wright [0062], e.g., legal documents relating to wills, trusts, estates, taxes, insurance, location of assets, accounts and pass codes); establishing at least one safe associated with one or more of the data structures (Wright [0059], e.g., The contents of the legacy may be organized, as noted above, into an arrangement that includes one or more vaults……… Each vault may contain one or more lock-boxes, and each lock-box may contain a portion of, or all of, the collection of information); defining, by an owner of the at least one safe, contents of the secured information (Wright [0057], e.g., The legacy is a collection of information that a user wishes to share with, or distribute to, one or more designated recipients, typically at a future time, where the user controls the contents of the collection, and the times and rules under which the collection, or portions of the collection, may be accessed by, or delivered to, the one or more designated recipients) and one or more security rules for the at least one safe (Wright [0059], e.g., each vault being accessible by its owner, i.e., the user, and further accessible by designated recipients in accordance with rules of access specified by the user), each of the security rules governing for one or more of the user devices: an access privilege for granting or for denying access to at least one of the safe and the one or more data structures associated therewith by the one or more of the user devices via an interface (Wright [0059], e.g., further accessible by designated recipients in accordance with rules of access specified by the user……… The rules of access may be the same or different for each designated recipient; Fig. 10, e.g., add shared users); and an operations privilege for enabling or for disabling performance of operations upon the at least one safe and the one or more data structures associated therewith initiated by the one or more of the user devices from the interface (Wright [0057], e.g., The legacy may include autobiography and/or contributed biography, each accessible for editing exclusively by the user. Contributed biography refers to materials obtained, provided, or submitted for inclusion in the legacy by sources other than the user; Fig. 10, e.g., add contributors); and controlling, by application of the security rules, at least one of access to and operations performed upon the at least one safe and the one or more data structures associated therewith by the one or more of the user devices (Wright [0057], e.g., The legacy may include autobiography and/or contributed biography, each accessible for editing exclusively by the user, [0059], e.g., further accessible by designated recipients in accordance with rules of access specified by the user; Fig. 10, e.g., add contributors, add shared users); [wherein when the operations privilege enables an operation of at least one of executing an application, accessing a document, or following a link to access an account presented on the interface and when identifying information is selectively defined within the secured information, the processing device further automatically providing a portion of the secured information to execute an identified application, to access an identified document, or to follow an identified link to access the account].
Wright does not explicitly teach, but Ilincic teaches wherein when the operations privilege enables an operation of at least one of executing an application, accessing a document, or following a link to access an account presented on the interface and when identifying information is selectively defined within the secured information (Ilincic [0048], e.g., The password manager application can decode the QR code to get the session ID and send the login request for a website and the session ID to a backend server. The backend server can determine that the website is on the whitelist, find the login credentials and send encrypted login credentials to the browser extension. The browser extension can decrypt the login credentials and automatically perform the secure login for the user; [0037]-[0038], e.g., The user can scan the QR code, which can open the password manager application 114 and require the user to authenticate into the password manager application 114. The password manager application 114 can determine if the user has login credentials available for that website and, if so, give the user a button to log into the website. Once the user clicks the button, the password manager application 114 can encrypt the data and send it to the server 106, which can route the encrypted data to the browser extension 108, where it can be decrypted. Once decrypted, the username and password can be populated into the fields by the browser extension 108. The user can click login and then be able to proceed to the website authenticated), the processing device further automatically providing a portion of the secured information to execute an identified application, to access an identified document, or to follow an identified link to access the account (Ilincic [0048], e.g., The backend server can determine that the website is on the whitelist, find the login credentials and send encrypted login credentials to the browser extension. The browser extension can decrypt the login credentials and automatically perform the secure login for the user; [0038], e.g., Once the user clicks the button, the password manager application 114 can encrypt the data and send it to the server 106, which can route the encrypted data to the browser extension 108, where it can be decrypted. Once decrypted, the username and password can be populated into the fields by the browser extension 108).
Wright teaches using username and password credentials to access a service provider system which host the vaults and lockboxes. A password is a string of characters (letters, numbers, and other symbols) used to authenticate an identity or to verify access authorization. A person of ordinary skill in the art would know that longer passwords correlate with stronger passwords and passwords should not be reused. These guidelines would result in multiple lengthy passwords, for each unique application that requires credentials. Thus, it may be difficult for users to keep track of all these passwords. Ilincic teaches of a method that would autofill credentials for logins. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Wright with the teachings of Ilincic with reasonable expectation of success. One of ordinary skill in the art would have been motivated to make the modification for the benefit of saving time, increasing security, and reducing password theft (Ilincic [0036], e.g., For example, a user uses the password manager application 114 on a phone to automatically login to a website and authenticates with a PIN and biometrics. In order to not have to type in the login credentials, which could be intercepted by keyloggers, the user uses the password manager application 114 in sync with the server 106 and browser extension 108. The user can advantageously have more secure passwords since the user does not have to remember them or type them in manually).
Regarding claim 2, most of the limitations of this claim have been noted in the rejection of claim 1. Wright further teaches wherein the contents of the secured information includes at least one of login credentials, cryptographic keys, documents, data strings, or the identifying information to identify a name or an address of a resource within a network accessible by the collaborative security system including the identified application, the identified document, or the identified link (Wright [0062], e.g., The user's legacy may contain legal documents relating to wills, trusts, estates, taxes, insurance, location of assets, accounts and pass codes, physical safe deposit boxes, health directives, burial instructions, and so on).
Regarding claim 3, most of the limitations of this claim have been noted in the rejection of claim 3. Wright does not explicitly teach, but Ilincic teaches wherein at least a portion of the secured information is encrypted prior to storing in the memory device (Ilincic [0079], e.g., For example, the password manager application 114 can encrypt data locally and send it to the server 106 for storage).
The motivation to combine is the same as that of claim 1.
Regarding claim 5, most of the limitations of this claim have been noted in the rejection of claim 1. Wright further teaches wherein one of the plurality of user devices initiates the establishing of the safe (Wright [0063], e.g., A user may establish one or more vaults for content to be shared).
Regarding claim 6, most of the limitations of this claim have been noted in the rejection of claim 5. Wright further teaches wherein the one of the plurality of user devices initiates the defining of the one or more security rules for the safe (Wright [0059], e.g., each vault being accessible by its owner, i.e., the user, and further accessible by designated recipients in accordance with rules of access specified by the user).
Regarding claim 7, most of the limitations of this claim have been noted in the rejection of claim 1. Wright further teaches wherein an administrator of the security management system initiates the establishing of the safe (Wright [0063], e.g., A user may establish one or more vaults for content to be shared; Note that user = administrator).
Regarding claim 8, most of the limitations of this claim have been noted in the rejection of claim 7. Wright further teaches wherein the administrator initiates the defining of the one or more security rules for the safe (Wright [0059], e.g., each vault being accessible by its owner, i.e., the user, and further accessible by designated recipients in accordance with rules of access specified by the user).
Regarding claim 9, most of the limitations of this claim have been noted in the rejection of claim 1. Wright further teaches wherein the access privilege includes at least one of read-only access or read-and-write access to the at least one safe and the one or more data structures associated therewith (Wright [0059], e.g., each vault being accessible by its owner, i.e., the user, and further accessible by designated recipients in accordance with rules of access specified by the user, [0057], e.g., The legacy may include autobiography and/or contributed biography, each accessible for editing exclusively by the user).
Regarding claim 10, most of the limitations of this claim have been noted in the rejection of claim 1. Wright further teaches wherein the operations privilege includes operations of at least one of adding, modifying, deleting, copying, or sharing between one or more of the plurality of user devices and the at least one safe and the one or more data structures associated therewith (Wright [0057], e.g., The legacy may include autobiography and/or contributed biography, each accessible for editing exclusively by the user, Fig. 10, e.g., add contributor).
Regarding claim 12, most of the limitations of this claim have been noted in the rejection of claim 1. Wright does not explicitly teach, but Ilincic teaches verifying the one or more of the user devices performing the operation is compatible to operate effectively with the at least one of application to be executed, document to be accessed, or account to be accessed prior to initiating performance of the operation (Ilincic [0037]-[0038], e.g., The user can scan the QR code, which can open the password manager application 114 and require the user to authenticate into the password manager application 114. Once the user is authenticated, the password manager application 114 can contact the server 106 with the unique identifier that was read from the QR code and learn from it the website where the login is needed, what the IP is and any additional metadata for the login session that may be required. The password manager application 114 can determine if the user has login credentials available for that website and, if so, give the user a button to log into the website. Once the user clicks the button, the password manager application 114 can encrypt the data and send it to the server 106, which can route the encrypted data to the browser extension 108, where it can be decrypted. Once decrypted, the username and password can be populated into the fields by the browser extension 108. The user can click login and then be able to proceed to the website authenticated).
The motivation to combine is the same as that of claim 1.
Regarding claim 13, the claim recites a method of the system of claim 1, and is similarly analyzed.
Regarding claim 14, the claim recites a method of the system of claim 2, and is similarly analyzed.
Regarding claim 15, the claim recites a method of the system of claim 3, and is similarly analyzed.
Regarding claim 17, the claim recites a method of the system of claim 5, and is similarly analyzed.
Regarding claim 18, the claim recites a method of the system of claim 6, and is similarly analyzed.
Regarding claim 19, the claim recites a method of the system of claim 7, and is similarly analyzed.
Regarding claim 20, the claim recites a method of the system of claim 8, and is similarly analyzed.
Regarding claim 21, the claim recites a method of the system of claim 9, and is similarly analyzed.
Regarding claim 22, the claim recites a method of the system of claim 10, and is similarly analyzed.
Regarding claim 24, the claim recites a method of the system of claim 12, and is similarly analyzed.
Regarding claim 25, most of the limitations of this claim have been noted in the rejection of claim 1. Wright does not explicitly teach, but Ilincic further teaches wherein when the defined contents of the secured information includes login credentials and the identifying information to identify a name or an address of a resource within a network accessible by the collaborative security system and when the operations privilege enables the executing, accessing, or following operations (Ilincic [0048], e.g., The password manager application can decode the QR code to get the session ID and send the login request for a website and the session ID to a backend server. The backend server can determine that the website is on the whitelist, find the login credentials and send encrypted login credentials to the browser extension. The browser extension can decrypt the login credentials and automatically perform the secure login for the user; [0037]-[0038], e.g., The user can scan the QR code, which can open the password manager application 114 and require the user to authenticate into the password manager application 114. The password manager application 114 can determine if the user has login credentials available for that website and, if so, give the user a button to log into the website. Once the user clicks the button, the password manager application 114 can encrypt the data and send it to the server 106, which can route the encrypted data to the browser extension 108, where it can be decrypted. Once decrypted, the username and password can be populated into the fields by the browser extension 108. The user can click login and then be able to proceed to the website authenticated), the processing device further automatically provides the login credentials and the identifying information to execute the identified application, to access the identified document, or to follow the identified link to access the account (Ilincic [0048], e.g., The backend server can determine that the website is on the whitelist, find the login credentials and send encrypted login credentials to the browser extension. The browser extension can decrypt the login credentials and automatically perform the secure login for the user; [0038], e.g., Once the user clicks the button, the password manager application 114 can encrypt the data and send it to the server 106, which can route the encrypted data to the browser extension 108, where it can be decrypted. Once decrypted, the username and password can be populated into the fields by the browser extension 108).
The motivation to combine is the same as that of claim 1.
Regarding claim 26, the claim recites a method of the system of claim 25, and is similarly analyzed.
Claim(s) 4 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wright in view of Ilincic, and in further view of “Is LastPass Password Manager worth using? “, 2021 (hereinafter, gHacks).
Regarding claim 4, most of the limitations of this claim have been noted in the rejection of claim 3. Wright and Ilincic do not explicitly teach, but gHacks teaches wherein when the one or more user devices access the safe and the one or more data structures associated therewith, the encrypted secured information remains encrypted when presented on the interface until selected for decrypting and viewing on the interface (gHacks, Figure below shows a hidden password, which can be unhidden by clicking the eye icon).
PNG
media_image1.png
605
821
media_image1.png
Greyscale
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to have modified the combined teachings of Wright and Ilincic with the teachings of gHacks with reasonable expectation of success. One of ordinary skill in the art would have been motivated to make the modification for the benefit preventing shouldering surfing attacks or prevent leaking the password to the surrounding area.
Regarding claim 16, the claim recites a method of the system of claim 4, and is similarly analyzed.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Patent Pub No. 20240020376 A1 to Li discloses a password manager for safely autofilling user login credentials. User interface elements are parsed to determine if password input fields are present. When password input fields are detected, a user is authenticated to ensure that the user is authorized to access the password manager. When the authentication is successful, the password manager autofills the login password input field with login data.
Contact Information
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LAWRENCE TRUONG whose telephone number is (571)272-6973. The examiner can normally be reached Monday - Friday, 8:00 am - 4 pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/LAWRENCE TRUONG/Examiner, Art Unit 2434
/NOURA ZOUBAIR/Primary Examiner, Art Unit 2434