DETAILED ACTION
1. Claims 1-20 are pending in this examination.
Notice of Pre-AIA or AIA Status
2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
3. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
4.1. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
4.2. Claims 1-2, 4-7, 9-10, 12-15, 17-18, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over US Patent Application No. 20210218768 to Keohane et al (“Keohane”) in view of US Patent Application No. 20230065220 to Rodriguez Bravo et al (“Rodriguez Bravo”).
As per claim 1, Keohane discloses a computer-implemented method for generating a password criteria combination in response to a required password change, the computer-implemented method comprising ([0004], the computer processor acquires a new password for access to the targeted item, wherein the new password is based on a more complex set of password generation rules than a current password):
generating, by the computer, password criteria for the new password, the password criteria being different than a previous password criteria ([0036], the new password by dynamically generating the new password and applying a longer character length and a more complex set of password generations rules than that of the current password.)
receiving, at the computer, a submitted new password ([0035] In some embodiments of the present invention, password change program 200
acquires the new password from a set of pre-defined passwords, selecting a next password in the set of passwords subsequent to the current password);
determining, by the computer, when the submitted new password meets each of the password criteria for the new password ([0038] In step 260, password change program 200 replaces the current password with a new password that includes a longer character string and in some embodiments of the present invention, may meet additional and more complex rules. In some embodiments the new
password is from a set of sequentially more complex passwords pre-determined by the user and sequentially applied by password change program 200. In other embodiments, password change program 200 dynamically generates the new password to include a longer character string that the previous
password and may meet additional and more complex rules, [0025]).
Keohane does not explicitly disclose however in the same field of endeavor, Rodriguez Bravo discloses detecting, by a computer, a request for a new password for a program; allowing, by the computer, access to the program ([0023], a user, via user interface 122, invokes workflow 200 upon indicating an intent to change a default password, [0036]-[0037]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Keohane with the teaching of Rodriguez Bravo by including the feature of access, in order for Keohane’s system to prevent unauthorized access to a bank account in the same manner that a company utilizes strong passwords to stop illegal/unlawful access to proprietary data. A random password policy for a specific user associated with an entity is generated based on a global password requirement. A new password created by the specific user based on the generated random password policy is identified. That the new password complies with a set of requirements specified by the generated random password policy is confirmed. (Rodriguez Bravo, abstract).
As per claim 2, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein more than half of user accounts for the program have different password criteria (Rodriguez Bravo, [0023] FIG. 2A is a flowchart of workflow 200 depicting a method for creating unique password
policies on an individual basis.). The motivation regarding the obviousness of claim 1 is also applied to claim 2.
As per claim 4, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein the at least one of the password criteria options is a limitation on any letters, numbers, asterisk, words, special characters, symbols, accent marks, punctuation marks, grammar, or phrases used in the changed password (Keohane, [0035], the number and requirements for uppercase and lowercase letters, numbers, and special characters).
As per claim 5, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein the password criteria is not identical to a previous password criteria (Keohane, [0004], the new password is based on a more complex set of password generation rules than a current password, [0038]).
As per claim 6, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein generating the password criteria further comprises: selecting one or more password requirements at random from a list of password criteria (Rodriguez Bravo, [0030] In an embodiment, muddle program
138 identifies a password (step 214). In other words, muddle program 138
identifies a new (or updated) password associated with the user (subsequent to the user creating a password based on the generated random password policy
received from muddle program 138). The motivation regarding the obviousness of claim 1 is also applied to claim 6.
As per claim 7, the combination of Keohane and Rodriguez Bravo discloses the computer-implemented method of claim 1, wherein determining the request for a new password is based at least in part on, determining a predetermined number of unsuccessful log ins exceeds a predetermined threshold (Keohane, [0011], unsuccessful access or login attempts exceeds an attempt threshold).
Claims 9, and 17 are rejected for similar reasons as stated above, and claim 1.
Claims 10, and 18 are rejected for similar reasons as stated above, and claim 2.
Claim 12 rejected for similar reasons as stated above, and claim 4.
Claims 13, and 19 are rejected for similar reasons as stated above, and claim 5.
Claim 14 rejected for similar reasons as stated above, and claim 6.
Claim 17 rejected for similar reasons as stated above, and claim 7.
4.3. Claims 3, 8, 11, 16 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Keohane and Rodriguez Bravo as applied to claim above, and in view of US Patent Application No. 20220407849 to Endler et al (“Endler ”).
As per claim 3, the combination of Keohane and Rodriguez Bravo discloses the invention as described above. Keohane and Rodriguez Bravo do not explicitly disclose however, In the same field of endeavor, Endler discloses the computer-implemented method of claim 1, wherein detecting the request for a new password is based at least in part on, a predetermined amount of time passed since a previous password was created (Endler, [0126]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Keohane with the teaching of Rodriguez Bravo/ Endler by including the feature of amount of time, in order for Keohane’s system to efficiently and proactively retrieve exposed or stolen passwords, to block access to a user account associated with a compromised password, to reject use of passwords that have found to have been exposed or compromised, and to notify a user to change a password that has been found to have been exposed or compromised. Provided is a process, including: obtaining a first password to a private computer network; determining, with a credential-monitoring application within the private computer network, whether the first password satisfies one or more criteria by: comparing the first password to a set of compromised credentials within a database within the private computer network; and determining whether the first password matches one or more passwords within the database; and in response to the determination that the first password satisfies the one or more criteria from among the plurality of criteria, causing a use of the first password to access the private computer network to be rejected and causing a first user associated with the first password to be notified to change the first password (Endler, abstract).
As per claim 8, the combination of Keohane, Rodriguez Bravo and Endler discloses the computer-implemented method of claim 1, wherein generating the password criteria, further comprises categorizing the criteria in one or more types of password criteria and further generating the plurality of password criteria based, at least in part, on selecting at least two criteria from two different types of password criteria (Endler, [0155], in response to the determination that the first password satisfies two or more criteria from among the plurality of criteria). The motivation regarding the obviousness of claim 1 is also applied to claim 8.
Claims 11, and 20 are rejected for similar reasons as stated above, and claim 3.
Claim 16 is rejected for similar reasons as stated above, and claim 8.
5.1. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure as the prior art discloses many of the claim features (See PTO-form 892).
5.2. a). US Patent Application No. 20040250141 to Casco-Arias et al., discloses a method of controlling password changes in a system having a plurality of data processing systems having separate password registries. Contents of passwords in the password registries of the data processing systems are controlled using password content policies that are centrally shared between the plurality of data processing systems.
b). US Patent No. 8769607 issued to Jerdonek et al., discloses systems, methods and articles of manufacture for evaluating a password policy are disclosed. The password evaluation system receives password policy data regarding a password policy, including a password constraint. The system analyzes the password policy data to determine a usability index and a password strength index for the password policy, and also determines a usability index and password strength index for a plurality of modified password policies having password constraints different from the password policy. The system then provides a graphical representation of the usability index and the password strength for the password policy and the modified password policies, thereby allowing a password designer to optimize the tradeoffs between usability and security of a password policy.
Conclusion
6. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARUNUR RASHID whose telephone number is (571)270-7195. The examiner can normally be reached 9 AM to 5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
HARUNUR . RASHID
Primary Examiner
Art Unit 2497
/HARUNUR RASHID/Primary Examiner, Art Unit 2497