DETAILED ACTION
This Office Action is in response to the application 18/339,251 filed on 06/22/2023.
Claims 1-20 have been examined and are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Action is made Non-FINAL.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 06/22/2023 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements have been considered by the examiner.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically discloses as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, 8-9, 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over Lal et al. (“Lal,” US 20240356907, filed April 20, 2023).
Regarding claim 1, Lal discloses A computer-implemented method comprising:
generating a temporary access code to access a resource (Lal FIG. 3, [0046], [0074]. Laptop 120 can request to access content by sending the EPC to content service 110, and the request is authorized if the EPC is valid. In the example, suppose Alice's laptop 120 is the EMD [Ephemeral Master Device] and has received the current EPC [Ephemeral Personal Credential]. A QR code is sent to Alice's laptop 120 (or another device in the domain which has a valid EPC). The QR code can be temporary and/or dynamic (e.g., repeatedly changing periodically or at randomly determined intervals). Furthermore, George's laptop 122 is in such proximity to laptop 120 that laptop 122 can capture a live QR code before the QR code expires and/or is replaced with another QR code. George's laptop 122 sends the valid captured QR code 322 to content service 110. Upon verification of the QR code, content service 110 sends the current EPC to George's laptop 122.);
wherein a user device is authorized to access the resource and [is in a current session actively accessing the resource on the local network] (Lal FIG. 3, [0046], [0074]. Laptop 120 can request to access content by sending the EPC to content service 110, and the request is authorized if the EPC is valid. In the example, suppose Alice's laptop 120 is the EMD [Ephemeral Master Device] and has received the current EPC [Ephemeral Personal Credential].);
receiving, from the client device, a scanned temporary access code; and responsive to determining the scanned temporary access code matches the temporary access code to access the resource, granting the client device access to the resource (Lal FIG. 3, [0046], [0074]. Laptop 120 can request to access content by sending the EPC to content service 110, and the request is authorized if the EPC is valid. In the example, suppose Alice's laptop 120 is the EMD [Ephemeral Master Device] and has received the current EPC [Ephemeral Personal Credential]. A QR code is sent to Alice's laptop 120 (or another device in the domain which has a valid EPC). The QR code can be temporary and/or dynamic (e.g., repeatedly changing periodically or at randomly determined intervals). Furthermore, George's laptop 122 is in such proximity to laptop 120 that laptop 122 can capture a live QR code before the QR code expires and/or is replaced with another QR code. George's laptop 122 sends the valid captured QR code 322 to content service 110. Upon verification of the QR code, content service 110 sends the current EPC to George's laptop 122.).
The current embodiment of Lal does not explicitly disclose: determining a client device is connected to a local network, wherein a user device is authorized to access the resource and is in a current session actively accessing the resource on the local network.
However, in another embodiment, Lal discloses a method, comprising the step of:
determining a client device is connected to a local network, wherein a user device is authorized to access the resource and is in a current session actively accessing the resource on the local network (Lal [0061], [0082]. EPC synchronization between devices in a domain is authorized when the devices are within a particular range (hereinafter referred to as within range or within proximity) of each other. The particular range may be a preconfigured distance, such as a distance set by the licensing terms of content service 110 for the subscription account. The distance can be measured from a particular device in the domain. For example, a device is within range if it is within a certain distance from the EMD, another device in the domain which has an EPC, the most recently used device in the domain (e.g., most recent device to log in with the account credentials and/or access content with a valid EPC, etc.). In another embodiment, the distance may be any suitable distance which allows for synchronization of data between devices using wireless short range communication technology, such as near-field communication (NFC), Bluetooth, local Wi-Fi, ultra wideband (UWB). At step 524, content service 506 authorizes the content request for client device # 1 502 once the EPC is recognized. If a device had previously accessed content (e.g., initiated a session), content service 506 can memorize (e.g., store) the session authorized. When the device logs out of the account and makes a subsequent successful request for content access, authorizing the content request can include authorizing access to resume the session.)
Therefore, it would have been obvious to one of ordinary skill in the art at the time of the invention was made to combine the embodiments of Lal to include the steps of: determining a client device is connected to a local network, wherein a user device is authorized to access the resource and is in a current session actively accessing the resource on the local network. One would have been motivated to provide users with a means for sharing content with devices connected to a given location/area and within a given wi-fi or NFC connection. (See Lal [0074].)
Regarding claim 2, Lal disclose the method of claim 1. Lal further discloses displaying, in a user interface on the user device, the temporary access code to access the resource, wherein the temporary access code displayed in the user interface of the user device is scannable by the client device (Lao [0074]. George's laptop 122 is within range of Alice's laptop 120 because George's laptop 122 can capture an image of the QR code 320 directly from the screen of Alice laptop 120. Furthermore, George's laptop 122 is in such proximity to laptop 120 that laptop 122 can capture a live QR code before the QR code expires and/or is replaced with another QR code.).
Regarding claim 8, claim 8 is directed to a computer program product corresponding to the method of claim 1. Claim 8 is similar to claim 1 and is therefore rejected under similar rationale.
Regarding claim 9, claim 9 is directed to a computer program product corresponding to the method of claim 2. Claim 9 is similar to claim 2 and is therefore rejected under similar rationale.
Regarding claim 15, claim 15 is directed to a system corresponding to the method of claim 1. Claim 15 is similar to claim 1 and is therefore rejected under similar rationale.
Regarding claim 16, claim 16 is directed to a system corresponding to the method of claim 2. Claim 16 is similar to claim 2 and is therefore rejected under similar rationale.
Claims 3-4, 10-11, 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Lal et al. (“Lal,” US 20240356907, filed April 20, 2023) in view of Fraser et al. (“Fraser,” US 9760399, patented Sept. 12, 2017).
Regarding claim 3, Lal discloses the method of claim 1. Lal further discloses wherein granting the client device the access to the resource (Lal FIG. 3, [0046]. Laptop 120 can request to access content by sending the EPC to content service 110, and the request is authorized if the EPC is valid.) further comprises.
Lal does not explicitly disclose: opening, in a user interface on the client device, a browser window with the access to the resource.
However, in an analogous art, Fraser discloses a method, comprising the step of: opening, in a user interface on the client device, a browser window with the access to the resource (Fraser col. 18: 1-3. [T]he device can provide quick access to a movie application to provide easy access to movie information, or can alternatively prime a browser window to launch a website that the user frequents to order movies or other media.).
Therefore, it would have been obvious to one of ordinary skill in the art at the time of the invention was made to combine the teachings of Fraser and Lal to include the steps of: opening, in a user interface on the client device, a browser window with the access to the resource. One would have been motivated to provide users with a means for providing content via a new or refreshed browser interface. (See Fraser col. 18: 1-3.)
Regarding claim 4, Lal and Fraser disclose the method of claim 3. Fraser further discloses:
subsequent to granting the client device the access to the resource, determining whether the client device is connected to the local network (Fraser col. 4: 54-58; col. 19: 3-6, 20-27. Thus, a state of the device can be determined in some embodiments to assess an extent to which termination can be utilized on the device at a given time, as the amount of available resources can change due to factors such as the number and types of applications running, the types of connections (e.g., LAN or Wi-Fi) being utilized. [T]he orientation of the device and/or the way in which the user is holding the device can be used to determine which applications to select for pre-warming and/or termination. Other information can be used as well, such as whether the device is [] connected to a wireless data network, and the like.); and
responsive to determining the client device is no longer connected to the local network, terminating the access to the resource (Fraser col. 4: 30-36, 53-59. As used herein, a “termination” action will be used broadly to refer to any action that causes an application or service to operate at less than a typical or conventional level, such as by fully terminating a service, throttling the service, deleting data cached for the service, slowing the execution of the service, and the like. Thus, a state of the device can be determined in some embodiments to assess an extent to which termination can be utilized on the device at a given time, as the amount of available resources can change due to factors such as the number and types of applications running, the types of connections (e.g., LAN or Wi-Fi) being utilized.).
Therefore, it would have been obvious to one of ordinary skill in the art at the time of the invention was made to combine the teachings of Fraser and Lal to include the steps of: subsequent to granting the client device the access to the resource, determining whether the client device is connected to the local network; and responsive to determining the client device is no longer connected to the local network, terminating the access to the resource. One would have been motivated to provide users with a means for allocating the availability of a resource (e.g., content, service) according to network availability and connectivity. (See Fraser col. 4: 30-36.)
Regarding claim 10, claim 10 is directed to a computer program product corresponding to the method of claim 3. Claim 10 is similar to claim 3 and is therefore rejected under similar rationale.
Regarding claim 11, claim 11 is directed to a computer program product corresponding to the method of claim 4. Claim 11 is similar to claim 4 and is therefore rejected under similar rationale.
Regarding claim 17, claim 17 is directed to a system corresponding to the method of claim 3. Claim 17 is similar to claim 3 and is therefore rejected under similar rationale.
Regarding claim 18, claim 18 is directed to a system corresponding to the method of claim 4. Claim 18 is similar to claim 4 and is therefore rejected under similar rationale.
Claims 5, 12 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Lal et al. (“Lal,” US 20240356907, filed April 20, 2023) in view of Fraser et al. (“Fraser,” US 9760399, patented Sept. 12, 2017) and Ellington (“Ellington,” US 20250150438, filed Jan. 27, 2023).
Regarding claim 5, Lal and Fraser disclose the method of claim 4. Lal and Fraser do not explicitly disclose: wherein terminating the access to the resource further comprises: closing, in the user interface on the client device, the browser window with the access to the resource.
However, in an analogous art, Ellington discloses a method, comprising the steps of:
wherein terminating the access to the resource further comprises: closing, in the user interface on the client device, the browser window with the access to the resource (Ellington [0143]. In some embodiments, the secure session is configured to operate at a dedicated browser, and the first remedial action is an OS-level remedial action. In some embodiments, the second application is at one of a tab of the dedicated browser, a different browser, and/or a desktop application, and the second remedial action is an application-level remedial action (e.g., shutting down and/or closing the tab of the browser).).
Therefore, it would have been obvious to one of ordinary skill in the art at the time of the invention was made to combine the teachings of Ellington, Fraser and Lal to include the steps of: closing, in the user interface on the client device, the browser window with the access to the resource. One would have been motivated to provide users with a means for shutting down an application and its browser interface as a result of terminating user access. (Ellington [0143].)
Regarding claim 12, claim 12 is directed to a computer program product corresponding to the method of claim 5. Claim 12 is similar to claim 5 and is therefore rejected under similar rationale.
Regarding claim 19, claim 19 is directed to a system corresponding to the method of claim 5. Claim 19 is similar to claim 5 and is therefore rejected under similar rationale.
Claims 6, 13 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Lal et al. (“Lal,” US 20240356907, filed April 20, 2023) in view of Fraser et al. (“Fraser,” US 9760399, patented Sept. 12, 2017) and Goldfarb et al. (“Goldfarb,” US 20170366547, published Dec. 21, 2017).
Regarding claim 6, Lal and Fraser disclose the method of claim 3. Lal and Fraser do not explicitly disclose: subsequent to granting the client device the access to the resource, determining a time expired for the generated temporary access code; and responsive to determining the time has expired for the generated temporary access code, terminating the access to the resource.
However, in an analogous art, Goldfarb discloses a method, comprising the step of: subsequent to granting the client device the access to the resource, determining a time expired for the generated temporary access code; and responsive to determining the time has expired for the generated temporary access code, terminating the access to the resource (Goldfarb [0076], [0091]. In some embodiments, de-authentication may occur because an access token times out. In some embodiments, access tokens may be associated with a value that indicates when they expire, and the third-party server may cease honoring the access token upon that time lapsing. Alternatively, upon successfully authenticating, some embodiments may proceed to execute the native application, as indicated by block 112. Some embodiments may then monitor for a de-authentication command, as indicated by block 114, and continue to execute the native application until such a de-authentication command is received or a user closes the native application. In some embodiments, access credentials may be associated with an expiration time, and some embodiments may check the operating native application against the expiration time and terminate the native application.).
Therefore, it would have been obvious to one of ordinary skill in the art at the time of the invention was made to combine the teachings of Goldfarb, Fraser and Lal to include the steps of: subsequent to granting the client device the access to the resource, determining a time expired for the generated temporary access code; and responsive to determining the time has expired for the generated temporary access code, terminating the access to the resource. One would have been motivated to provide users with a means for restricting access to a resource subject to expiration policy of the access credential. (See Goldfarb [0091].)
Regarding claim 13, claim 13 is directed to a computer program product corresponding to the method of claim 6. Claim 13 is similar to claim 6 and is therefore rejected under similar rationale.
Regarding claim 20, claim 20 is directed to a system corresponding to the method of claim 6. Claim 20 is similar to claim 6 and is therefore rejected under similar rationale.
Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Lal et al. (“Lal,” US 20240356907, filed April 20, 2023) in view of Fraser et al. (“Fraser,” US 9760399, patented Sept. 12, 2017), Goldfarb et al. (“Goldfarb,” US 20170366547, published Dec. 21, 2017) and Chang et al. (“Chang,” US 20180337918, published Nov. 22, 2018).
Regarding claim 7, Lal, Fraser and Goldfarb disclose the method of claim 6. Lal, Fraser and Goldfarb do not explicitly disclose: wherein terminating the access to the resource further comprises: displaying, in the user interface on the client device, an overlay over the browser window with the access to the resource; and providing a notification requesting the client device scan a new temporary access code to continue accessing the resource.
However, in an analogous art, Chang discloses a method, comprising the step of: wherein terminating the access to the resource further comprises: displaying, in the user interface on the client device, an overlay over the browser window with the access to the resource; and providing a notification requesting the client device [scan a new temporary access code] to continue accessing the resource (Chang [0194], [0387]-[0388]. In some embodiments, user interface 5002 is an interface of a browser application. FIGS. 12T-12U, for example, illustrate interactions between the user and the participant that occurred after a previously-verified credential of the user had expired. The user's credential to access the user's account with ABC Airlines had expired at the time the user submitted the request illustrated in message bubble 6125. FIG. 12U illustrates displaying a response from the participant requesting the user to sign into the user's account with ABC Airlines and displaying credential verification affordance 6010 in message bubbles 6126 and 6127, respectively. In some embodiments, device 100 detects (1342), via the one or more input devices, one or more user inputs to re-authenticate the user account. Continuing with the foregoing example, the user may perform a tap gesture with contact over credential verification affordance 6010 of FIG. 12U to re-authenticate the user account.).
Therefore, it would have been obvious to one of ordinary skill in the art at the time of the invention was made to combine the teachings of Chang, Goldfarb, Fraser and Lal to include the steps of: wherein terminating the access to the resource further comprises: displaying, in the user interface on the client device, an overlay over the browser window with the access to the resource; and providing a notification requesting the client device [scan a new temporary access code] to continue accessing the resource. One would have been motivated to provide users with a means for re-authenticating with updated access credentials upon expiration of current access credentials. (See Chang [0388].)
Regarding claim 14, claim 14 is directed to a computer program product corresponding to the method of claim 7. Claim 14 is similar to claim 7 and is therefore rejected under similar rationale.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDWARD LONG whose telephone number is (571)272-8961. The examiner can normally be reached on Monday to Friday, 9 AM - 6 PM EST (Alternate Fridays).
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached on (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only.
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EDWARD LONG/
Examiner, Art Unit 2439
/LUU T PHAM/ Supervisory Patent Examiner, Art Unit 2439