Prosecution Insights
Last updated: October 01, 2026
Application No. 18/274,498

DEVICE IDENTITY AUTHENTICATION METHOD AND APPARATUS, ELECTRONIC DEVICE, AND COMPUTER-READABLE MEDIUM

Final Rejection §103
Filed
Jul 27, 2023
Priority
Oct 28, 2021 — nonprovisional of PCTCN2021126978
Examiner
KIM, TAE K
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
BOE Technology Group Co., Ltd.
OA Round
4 (Final)
75%
Grant Probability
Favorable
5-6
OA Rounds
4m
Est. Remaining
80%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
501 granted / 671 resolved
+16.7% vs TC avg
Moderate +5% lift
Without
With
+5.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 6m
Avg Prosecution
14 currently pending
Career history
698
Total Applications
across all art units

Statute-Specific Performance

§101
12.3%
-27.7% vs TC avg
§103
41.3%
+1.3% vs TC avg
§102
25.8%
-14.2% vs TC avg
§112
15.1%
-24.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 671 resolved cases

Office Action

§103
DETAILED ACTION This Action is in consideration of the Applicant’s response on April 29, 2026. Claims 10 and 11 are amended by the Applicant. Claim 26 is canceled and Claim 27 is added. Claims 1 – 8, 10 – 18, 23, 25, and 27, where Claims 1 and 12 are in independent form, are presented for examination. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on April 29, 2026 was filed before the mailing date of the current action. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Response to Arguments Applicant’s arguments filed on April 29, 2026 have been fully considered but they are not persuasive. Applicant argued: a) Regarding Claims 1 and 12, Adams does not disclose or suggest of counting of messages received within a threshold period. The Office respectfully disagrees with Applicant’s assertions. 1. With regards to a), the Applicant’s argument that there is a count of messages during “credit mode” is not specifically stated in the claim. The Office reminds the Applicant that the pending claims must be "given the broadest reasonable interpretation consistent with the specification" [In re Prater, 162 USPQ 541 (CCPA 1969)] and "consistent with the interpretation that those skilled in the art would reach" [In re Cortright, 49 USPQ2d 1464 (Fed. Cir. 1999)]. Additionally, although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPTQ2d 1057 (Fed. Cir. 1993). The claim recites the monitoring a number of effective communications that occur in the credit mode between two devices. Nothing in the claims indicates a counter being used or of any number greater than one. The Applicant’s specification even indicates that the threshold is typically one [Para. 0126-127]. Adams discloses that if a heartbeat response is not received within the heartbeat response lost timeout period (monitoring a number of effective communications between two devices with a threshold of one), the secure connection ends (credit mode ends when number of effective communications is less than one) [Fig. 2, Para. 0015, 0026-27]. There are no claims limitations that are distinguishable from the process described in Adams. Claim Rejections - 35 USC § 103 The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action. Claim(s) 1 – 8, 10, 12 – 18, 23, and 25 are rejected under 35 U.S.C. 103 being unpatentable over PGPub. 2015/0046710 (hereinafter “Clish”), in view of PGPub. 2007/0297609 (hereinafter “Adams”). 2. Regarding Claims 1 and 23, Clish discloses of an electronic device [Fig. 3; Para. 0032] comprising: one or more processors [Fig. 3; Para. 0032]; a storage device on which one or more programs are stored (Claim 26), when the one or more programs are executed by the one or more processors, such that the one or more processors implement a device identity authentication method [Fig. 3; Para. 0032, 0057]; one or more I/O interfaces connected between the processor and the memory, configured to implement information exchange between the processor and the memory [Fig. 3; Para. 0032, 0057]; the device identity authentication method is applied to a terminal device [Fig. 2, item 106B and Fig. 5] and comprises: generating, by the terminal device, a first identity authentication message in response to an identity authentication instruction [Fig. 2, item 204, Fig. 5; Para. 0026, 0034; module 106B]; wherein the identity authentication instruction is an instruction initiated by a second device to authenticate an identity of the terminal device [Fig. 2, item 202; Para. 0024, 0034]; sending the first identity authentication message to the second device, for the second device to authenticate the identity of the terminal device based on the first identity authentication message [Fig. 2, items 204 and Fig. 5; Para. 0026-27, 0034], to obtain a first identity authentication result [Para. 0027-28, 0034]; receiving, by the terminal device, a second identity authentication message [Fig. 2, items 206 and Fig. 5; Para. 0029, 0034]; wherein the second identity authentication message is a message sent by the second device when the first identity authentication result is passed; authenticating an identity of the second device based on the second identity authentication message, to obtain a second identity authentication result [Fig. 2, item 208 and Fig. 5; Para. 0030, 0034]; when the second identity authentication result is passed, entering, by the terminal device a credit mode [Para. 0054; secure communications between devices after authentication], wherein in the credit mode, the terminal device and the second device communicate with each other and are capable of securely transmitting data to each other [Para. 0054; secure communications between devices after authentication], Clish, however, does not specifically disclose that the credit mode ends when the terminal device and the second device are disconnected from each other or of cyclically monitoring, within a preset time period, a number of effective communications that occur in the credit mode between the terminal device and the second device and exiting from the credit mode when the number of effective communications is less than a preset threshold. Adams discloses a system and method of establishing a secure connection between devices [Abstract]. Adams further discloses that after the terminal device enters credit mode (secure channel) [Fig. 2; Para. 0026], if a heartbeat response is not received within the heartbeat response lost timeout period, the secure channel is dropped (cyclically monitoring, within a preset time period, a number of effective communications that occur in the credit mode between the terminal device and the second device and exiting from the credit mode when the number of effective communications is less than a preset threshold) and the encryption keys can be cleared from the devices (the credit mode ends when the terminal device and the second device are disconnected from each other) [Fig. 2; Para. 0015, 0027]. It would have been obvious to one skilled in the art before the effective filing date of the current invention to incorporate the teachings of Adams with Clish since both systems perform device authentication utilizing security keys. The combination would enable the Clish system to provide additional security by providing the heartbeat in the secure channel to prevent attackers from keeping the connection alive [Adams; Para. 0016-17]. 3. Regarding Claim 2, Clish, in view of Adams, discloses the limitations of Claim 1. Clish further discloses that the first identity authentication message comprises a first random number, an identifier of the terminal device, and first signature data [Fig. 2, item 204; Para. 0026]; wherein the first random number is generated by the terminal device [Para. 0026], and the first signature data is obtained by signing the first random number using a private key of the terminal device and through a pre agreed signature algorithm [Para. 0026]. 4. Regarding Claim 3, Clish, in view of Adams, discloses the limitations of Claim 2. Clish further discloses that generating a first identity authentication message in response to an identity authentication instruction comprising: generating, by the terminal device, the first random number in response to the identity authentication instruction [Fig. 2, item 204; Para. 0026]; signing the first random number using the private key of the terminal device and through a pre agreed signature algorithm, to obtain the first signature data [Fig. 2, item 204; Para. 0026]; obtaining the first identity authentication message based on the first random number, the identifier of the terminal device, and the first signature data [Fig. 2, item 204; Para. 0026]. 5. Regarding Claim 4, Clish, in view of Adams, discloses the limitations of Claim 2. Clish further discloses that the second identity authentication message comprises second signature data obtained by signing the first random number using a private key of the second device and through the signature algorithm [Fig. 2, item 206; Para. 0029]. 6. Regarding Claim 5, Clish, in view of Adams, discloses the limitations of Claim 4. Clish further discloses that the authenticating an identity of the second device based on the second identity authentication message to obtain a second identity authentication result comprising: authenticating the second signature data using a public key of the second device and through an authentication algorithm to obtain the second identity authentication result [Para. 0030]. 7. Regarding Claim 6, Clish, in view of Adams, discloses the limitations of Claim 2. Clish further discloses that the signature algorithm comprises either an ECDSA algorithm [Para. 0025, 0027] or an RSA algorithm. 8. Regarding Claim 7, Clish, in view of Adams, discloses the limitations of Claim 1. Clish further discloses that after obtaining the second identity authentication result, the method further comprises: when the second identity authentication result is authentication passed, returning a second identity authentication result to the second device [Fig. 2, item 208; Para. 0030]. 9. Regarding Claim 8, Clish, in view of Adams, discloses the limitations of Claim 1. Clish further discloses that after obtaining the second identity authentication result, the method further comprises: when the second identity authentication result is authentication failed, generating, recording, or sending an alarm message [Fig. 2, item 208; Para. 0030]. 10. Regarding Claim 10, Clish, in view of Adams, discloses the limitations of Claim 8. Adams further discloses that after the terminal device entering a credit mode [Fig. 2], the method further comprises: monitoring a connection status between the terminal device and the second device; when the connection status is disconnected, exiting from the credit mode directly [Fig. 2; Para. 0027-28]. 11. Regarding Claims 12 and 25, Clish discloses of an electronic device [Fig. 3; Para. 0032] comprising: one or more processors [Fig. 3; Para. 0032]; a memory on which one or more programs are stored, wherein the one or more programs are executed by the one or more processors [Fig. 3; Para. 0032], such that the one or more processors implement the device identity authentication method applied to an upper computer [Fig. 2, item 106A and Fig. 4], comprising: sending, by the upper computer, an identity authentication instruction to a first device [Fig. 2, item 202 and Fig. 4; Para. 0024]; receiving a first identity authentication message returned by the first device [Fig. 2, item 204 and Fig. 4; Para. 0026, 0033]; wherein the first identity authentication message is information generated by the first device in response to the identity authentication instruction [Fig. 2, item 202, 204 and Fig. 4; Para. 0024-26, 0033]; authenticating an identity of the first device based on the first identity authentication message, to obtain a first identity authentication result [Fig. 2, item 204 and Fig. 4; Para. 0027-28, 0033]; when the first identity authentication result is passed, sending a second identity authentication message to the first device for the first device to authenticate an identity of the upper computer based on the second identity authentication message [Fig. 2, item 206 and Fig. 4; Para. 0029-30, 0033], to obtain the second identity authentication result [Fig. 2, item 208 and Fig. 4; Para. 0029-30, 0033]; receiving a message of entering a credit mode sent by the first device; wherein the first device enters the credit mode when the second identity authentication result is authentication passed [Para. 0054; secure communications between devices after authentication]; in the credit mode, the first device and the upper computer communicate with each other and are capable of securely transmitting data to each other [Para. 0054; secure communications between devices after authentication]; one or more I/O interfaces connected between the processors and the memory, configured to implement information exchange between the processors and the memory [Fig. 3, items 302, 304; Para. 0032]. Clish, however, does not specifically disclose of receiving a message of exiting from the credit mode sent by the first device; wherein the first device sends the message of exiting from the credit mode when a number of effective communications within a preset time period is lower than a preset threshold. Clish, however, does not specifically disclose that the credit mode ends when the first device and the upper computer are disconnected from each other or receiving a message of exiting from the credit mode sent by the first device; wherein the first device sends the message of exiting from the credit mode when a number of effective communications that occur in the credit mode between the upper computer and the first device within a preset time period is lower than a preset threshold. Adams discloses a system and method of establishing a secure connection between devices [Abstract]. Adams further discloses that after the terminal device enters credit mode (secure channel) [Fig. 2; Para. 0026], if a heartbeat response is not received within the heartbeat response lost timeout period, the secure channel is dropped (first device sends the message of exiting from the credit mode when a number of effective communications that occur in the credit mode between the upper computer and the first device within a preset time period is lower than a preset threshold) and the encryption keys can be cleared from the devices (the credit mode ends when the first device and the upper computer are disconnected from each other) [Fig. 2; Para. 0015, 0027]. It would have been obvious to one skilled in the art before the effective filing date of the current invention to incorporate the teachings of Adams with Clish since both systems perform device authentication utilizing security keys. The combination would enable the Clish system to provide additional security by providing the heartbeat in the secure channel to prevent attackers from keeping the connection alive [Adams; Para. 0016-17]. 12. Regarding Claim 13, Clish, in view of Adams, discloses the limitations of Claim 12. Clish further discloses that the first identity authentication message comprises a first random number, an identifier of the first device, and first signature data [Fig. 2, item 204; Para. 0026]; wherein the first random number is generated by the terminal device [Para. 0026], and the first signature data is obtained by signing the first random number using a private key of the terminal device and through a pre agreed signature algorithm [Para. 0026]. 13. Regarding Claim 14, Clish, in view of Adams, discloses the limitations of Claim 13. Clish further discloses that authenticating an identity of the first device based on the first identity authentication message to obtain a first identity authentication result comprising: obtaining a public key of the first device based on the identifier of the first device [Fig. 2; Para. 0026-28]; wherein the private key of the first device and the public key of the first device are identity keys of the first device [Fig. 2; Para. 0026-28]; authenticating the first signature data using the public key of the first device and through the signature algorithm, to obtain the first identity authentication result [Fig. 2; Para. 0026-28]. 14. Regarding Claim 15, Clish, in view of Adams, discloses the limitations of Claim 13. Clish further discloses that the second identity authentication message comprises second signature data obtained by signing the first random number using a private key of the upper computer and through a predetermined signature algorithm [Fig. 2, item 206; Para. 0029]. 15. Regarding Claim 16, Clish, in view of Adams, discloses the limitations of Claim 13. Clish further discloses that the signature algorithm comprises either an ECDSA algorithm [Para. 0025, 0027] or an RSA algorithm. 16. Regarding Claim 17, Clish, in view of Adams, discloses the limitations of Claim 12. Clish further discloses that the first device is authenticated based on the first identity authentication message [Fig. 2, items 204; Para. 0026-28], and after obtaining the first identity authentication result, the method further comprises: when the first identity authentication result is failed, terminating the identity authentication process [Fig. 2; Para. 0028]. 17. Regarding Claim 18, Clish, in view of Adams, discloses the limitations of Claim 12. Clish further discloses that after sending a second identity authentication message to the first device [Fig. 2, items 206; Para. 0029], the method further comprises: receiving the second identity authentication result returned by the first device [Fig. 2, items 208; Para. 0030]. Claim 11 is rejected under 35 U.S.C. 103 being unpatentable over PGPub. Clish, in view of Adams, in further view of PGPub. 2014/0196142 (hereinafter “Louboutin”). 18. Regarding Claim 11, Clish, in view of Adams, discloses the limitations of Claim 10. Neither Clish or Adams discloses that the terminal device and the second device are connected through a cable or that when the connection state is disconnected, exiting from the credit mode directly comprises: exiting from the credit mode directly when the cable is disconnected from the terminal device and/or the second device Louboutin further discloses that the terminal device and the second device are connected through a cable [Para. 0024]; when the connection state is disconnected [Fig. 4; Para. 0075-77], exiting from the credit mode directly comprises: exiting from the credit mode directly when the cable is disconnected from the terminal device and/or the second device [Fig. 4; Para. 0075-77]. While Adams discloses a wireless connection, since the heartbeat signals are transmitted in the secure channel, the heartbeat would have been measured through the cable. It would have been obvious to one skilled in the art before the effective filing date of the current invention to incorporate the teachings of Louboutin with Clish and Adams since the systems enable secure communications between devices. The motivation to do so is to provide additional methods of connecting device for system flexibility (obvious to one skilled in the art). Claim 27 is rejected under 35 U.S.C. 103 being unpatentable over PGPub. Clish, in view of Adams, in further view of PGPub. 2022/0217537 (hereinafter “Dawes”). 19. Regarding Claim 27, Clish, in view of Adams, discloses the limitations of Claim 1. Neither Clish or Adams, however, discloses that the preset threshold is greater than one. Dawes discloses a system and method for establishing a secure channel between devices [Abstract; Fig. 11]. Dawes further discloses that there can be a plurality of heartbeat/keepalive signals attempted within an established retry interval being monitored, such as 5 [Para. 0654]. It would have been obvious to one skilled in the art before the effective filing date to incorporate the teachings of Dawes with Clish and Adams since both systems are directed to maintaining communications between devices. The combination would enable the Adams heartbeat detection to incorporate retry attempts prior to disconnecting the secure connection. The motivation to do so is to provide a more user-friendly timeout detection for a secure channel (obvious to one skilled in the art). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Contacts Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAE K KIM whose telephone number is (571)270-1979. The examiner can normally be reached M-F 9:30-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached at 5712727642. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TAE K KIM/Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Show 3 earlier events
Oct 16, 2025
Final Rejection mailed — §103
Dec 08, 2025
Applicant Interview (Telephonic)
Dec 08, 2025
Examiner Interview Summary
Dec 24, 2025
Request for Continued Examination
Jan 18, 2026
Response after Non-Final Action
Jan 28, 2026
Non-Final Rejection mailed — §103
Apr 24, 2026
Response Filed
Aug 25, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739258
Computer Network Security
3y 11m to grant Granted Sep 15, 2026
Patent 12719906
SYSTEMS AND METHODS FOR AUTOMATED CYBER SECURITY AND CONTROL MONITORING
5y 1m to grant Granted Aug 25, 2026
Patent 12717883
IMAGING APPARATUS, INFORMATION PROCESSING METHOD, AND PROGRAM
3y 12m to grant Granted Aug 25, 2026
Patent 12695607
INTEGRATED CIRCUIT PROTECTION USING STACKED DIES
3y 8m to grant Granted Jul 28, 2026
Patent 12689503
METHOD FOR DETERMINING A QUANTUM COMMUNICATION SETUP, QUANTUM COMMUNICATION SETUP, COMPUTER PROGRAM, AND DATA PROCESSING SYSTEM
3y 11m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
75%
Grant Probability
80%
With Interview (+5.1%)
3y 6m (~4m remaining)
Median Time to Grant
High
PTA Risk
Based on 671 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month