DETAILED ACTION
Claims 1-20 are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Sliwka et al. (US Patent Application No. 20210082044 ) (Hereinafter Sliwka) in view of Mars et al. (US Patent Application No. 20240129708) (Hereinafter Mars) in further view of Jakobsson et al. (US Patent Application No. 20220407702) (Hereinafter Jakobsson).
As per claim 1, Sliwka discloses a method for verifying user identity, the method comprising:
associating a biometric identifier of a user with:
a token (para 74, token); and
a cryptographic key, wherein the cryptographic key is associated with a set of access rights to the token (para 79, he digital signature may be used to verify the validity of the token, para 92, managing the ownership rights of the generated tokens);
verifying whether the identity/token [biometric] data matches the token [biometric] identifier (para 130, The token verification request may include a token to be verified or a token identifier ); and
obtaining access to at least part of the cryptographic key (para 121); and
accessing the token, wherein access is performed (para 121, 130, the verification system 306 use the received public key and the private key used to encode the digital signature to determine whether the received public key is the public key used to sign the token. For example, in embodiments, the verification system 306 may attempt to decrypt the digital signature using the private key and the received public key. If the private key and the received public key enable decryption of the digital signature to obtain the value used to generate the token):
using the cryptographic key (para 121, 130, the verification system 306 use the received public key and the private key used to encode the digital signature to determine whether the received public key is the public key used to sign the token. For example, in embodiments, the verification system 306 may attempt to decrypt the digital signature using the private key and the received public key. If the private key and the received public key enable decryption of the digital signature to obtain the value used to generate the token), and
according to the set of access rights (para 121).
Sliwka does not explicitly disclose obtaining, from a sensor, biometric data, wherein the biometric data corresponds to the user; when the biometric data matches the biometric identifier beyond a pre-determined threshold.
However, Mars discloses obtaining, from a sensor (para 122, phone sensors are used to fingerprint), biometric data, wherein the biometric data corresponds to the user (para 63, can be generated on a device, such as a lock, using other factors, such as biometrics fingerprint, voice recognition, face recognition or retina scanner part of the device, geo-location, expiration time, and so on.);
when the biometric data matches the biometric identifier beyond a pre-determined threshold (para 12, A reader with a camera uses a camera image to match the face that the first party has in its account as a second factor. Learning algorithms can be utilized to better match the face).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Sliwka and Mars. The motivation would have been to build the network that provide endpoint security solutions (both hardware and software based).
Sliwka in view of Mars does not explicitly disclose a set of access rights to the token, wherein association between the biometric identifier and the set of access rights to the token is expressed in a digital certificate corresponding to the cryptographic key. However, Jakobsson discloses a set of access rights to the token (para 198, Tokens in accordance with numerous embodiments of the invention may carry encrypted key material, where only environments with sufficient support for DRM functionality would be capable of receiving keys that can be used to decrypt such encrypted key material and obtain the key material, where such key material is used to decrypt encrypted data contained in or associated with the token. Tokens associated with secure processing environments may be referred to as DRM tokens. ), wherein association between the biometric identifier (Para 193, user device representing a first user may generate a digital signature on a message, using the first private key, after verifying that a user's biometric credentials match the first identifier or an identifier linked to the first identifier. This first token only includes data, as described above) and the set of access rights to the token is expressed in a digital certificate corresponding to the cryptographic key (para 200, a car rental company may obtain a license to certify its own cars (e.g., in the form of a trusted token or a certificate token), where this license may be expressed as a token including a certificate of the car rental company's public key, as well as one or more rules identifying what types of documents (including tokens) the car rental company certification authority may accept or issue).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Sliwka and Mars with Jakobsson. The motivation would have been to use tokens includes a biometric verification, evaluating the tokens to determine whether to authorize a user based on the biometric verification and a communication with a digital rights management.
The Examiner notes that this motivation applies to all dependent and/or otherwise subsequently addressed claims.
As per claim 2, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Sliwka discloses wherein the token is a non-fungible token (NFT) (para 121, the tokens are non-fungible tokens).
As per claim 3, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Sliwka discloses wherein: the NFT is associated with media content; and
the NFT is stored in a digital wallet owned by the user(para 113, a digital wallet of the user., para 118, Item-related data may include, but is not limited to, item identifiers, expiration dates of items, conditions or restrictions placed on the items, item descriptions, media content).
As per claim 4, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Sliwka discloses wherein an access right of the set of access rights is selected from the group consisting of viewing the media content associated with the token, editing the media content associated with the token, copying the token, transferring the token, deleting digital assets associated with the token, assigning at least one access right to another entity, and revoking the association between the biometric identifier and the set of access rights (para 92, managing the ownership rights of the generated tokens.).
As per claim 5, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Mars discloses wherein the sensor is: a camera (para 112, A reader with a camera uses a camera image); and
additionally configured to: detect when the user views the media content associated with the token (para 63, tokens can be generated on a device, such as a lock, using other factors, such as biometrics fingerprint, voice recognition, face); and
identify aspects of the media content that the user focuses on (para 98, video).
As per claim 6, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Sliwka discloses, further comprising at least one of: curating additional content in the digital wallet according to the aspects (para 113, the token may be deposited in a digital wallet of the user); and
sending a creator of the token a royalty when the user views the media content associated with the token (para 132, he transaction system 106 may include a digital wallet system 408, an express trading system 410, a payment integration system).
As per claim 7, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Sliwka discloses wherein the set of access rights is determined based on a policy associated with the token (para 92, managing the ownership rights of the generated tokens.).
As per claim 8, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Sliwka discloses wherein the policy is associated with a smart contract (para 8, he authentication smart contract instance).
As per claim 9, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Sliwka discloses wherein the association between the biometric identifier and the set of access rights is further comprises at least one of: pre-determined duration based on a policy associated with the token; or
revocability, where the association is revocable by a party with an access right (para 88, tokens may be perishable, in that they lose all value at a predetermined time or upon the occurrence of a predetermined event.).
As per claim 10, claim is rejected for the same reasons and motivation as claim 1, above. In addition, Sliwka discloses wherein access to a remaining part of the cryptographic key is obtained using a digital signature (para 121, the token generation system 302 may embed or otherwise encode the public key used to digitally sign the token in the token).
As per claims 11-20, claims are rejected for the same reasons and motivations as claims 1-10, above.
Response to Arguments
Applicant’s arguments with respect to amended claim(s) have been considered but are moot because the new ground of rejection, see the rejection above.
Conclusion
Please see the attached PTO-892 for the prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMAD A SIDDIQI whose telephone number is (571)272-3976. The examiner can normally be reached Monday-Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl G Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MOHAMMAD A SIDDIQI/Primary Examiner, Art Unit 2493