DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This Office Action is in response to the Amendment filed on 3/16/2026.
In instant Amendment, claims 1, 13, 14 and 20 have been amended; claims 3-6 and 16-19 have been canceled; claims 1, 14 and 20 are independent claims. Claims 1, 2, 7-15 and 20 have been examined and are pending. This Action is made Final.
Response to Arguments
Applicant’s arguments, filed 3/16/2026, with respect to the 35 U.S.C. 101 rejection have been fully considered and are persuasive. The 35 U.S.C. 101 of claim(s) 1-20 have been withdrawn.
Applicant's arguments, filed 3/16/2026, with respect to the 35 U.S.C. 102 rejection have been fully considered but they are not persuasive.
Applicant Argues: Thus, Applicant's claims, as amended, recite that a first device fingerprint is generated based on network traffic associated with a first wireless connection provided by an access point "located in a public location that is not a home or an office, and wherein the connected device accesses each first wireless network using a public user authentication controlled by a network service provider managing the access point located in the public location." A second device fingerprint is generated based on network traffic associated with a second wireless connection provided by an access point "located in a home or an office, and wherein the connected device accesses each second wireless network using a private user authentication controlled by a user managing the access point located in the home or the office."
Nowhere does Spencer teach or suggest the generation of device fingerprints from access points in both a "public location that is not a home or an office" and "a home or an office," as now recited in Applicant's claim 1. Rather, Spencer discloses the use of public hotspots to allow devices to access private networks. The use of a public hotspot to access a private network fails to teach or suggest the generation of device fingerprints from access points in both a "public location that is not a home or an office" and "a home or an office."
For at least the foregoing reasons, Applicant submits that claim 1 is patentably distinct from the cited art. Claims 14 and 20 contain limitations substantially similar to those discussed herein with regard to claim 1 and should thus be allowable for at least the same reasons.
Examiner’s Response: The examiner respectfully disagrees. The examiner respectfully notes that Spencer discloses “generation of device fingerprints from access points in both a "public location that is not a home or an office" and "a home or an office",” as amended by applicant. Spencer discloses in ¶[0034] - In general, the system 10 may be used to identify different remote devices 102 via the network access module 112, and in some embodiments, authenticate and authorize access thereto to network and/or Web-based services accessible via the service access module 106. The authentication and authorization would be predicated on Spencer’s fingerprinting as disclosed in ¶[0006] - In accordance with one embodiment of the invention, there is provided a method for recognizing a wireless device across multiple hotspot locations, the method comprising: detecting at one of the multiple hotspot locations a wireless transmission sent by the wireless device; extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input. Spencer discloses an access point in a public location that is not a home or office, in ¶[0034] - ... when such remote devices are operated at a public access hotspot supported by the system 10 and further a home or an office in ¶[0040] - A user could thus connect to a home access system (e.g. a home media server, networked computer, etc.) to access images, music, videos, files, and the like that are stored on remote devices located in the user's home, business, office, etc. This construction is affirmed by Spencer n ¶ [0046] - As introduced above, in accordance with some embodiments of the invention, the system 10 may be configured to manage public and/or private network access for a plurality of remote devices 102, optionally of a plurality of remote device types, configurations and/or functionality, and that, within a variety of venues if necessary. Thus, as shown above, Spencer does in fact disclose generation of device fingerprints from access points in both a "public location that is not a home or an office" and "a home or an office".” Therefore, this argument is not persuasive.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1, 2, 7-15 and 20 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Spencer et al. (US 2013/0167196 A1).
Regarding Claim 1;
Spencer discloses a computer-implemented method comprising:
obtaining one or more first device fingerprints from one or more first wireless connections of a connected device in one or more first wireless networks ([0006] - In accordance with one embodiment of the invention, there is provided a method for recognizing a wireless device across multiple hotspot locations, the method comprising: detecting at one of the multiple hotspot locations a wireless transmission sent by the wireless device; extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input and [0036] and [0072]), wherein each first wireless network is provided by an access point located in a public location that is not a home or an office ([0034] In some embodiments, the system 10 allows browser-based, browser-challenged, and/or browserless remote devices to access these services, or a selection thereof, when such remote devices are operated at a public access hotspot supported by the system 10 and [0046] - As introduced above, in accordance with some embodiments of the invention, the system 10 may be configured to manage public and/or private network access for a plurality of remote devices 102, optionally of a plurality of remote device types, configurations and/or functionality, and that, within a variety of venues if necessary and [0111])), and wherein the connected device accesses each first wireless network using a public user authentication controlled by a network service provider managing the access point located in the public location ([0034] - In general, the system 10 may be used to identify different remote devices 102 via the network access module 112, and in some embodiments, authenticate and authorize access thereto to network and/or Web-based services accessible via the service access module 106. In some embodiments, the system 10 allows browser-based, browser-challenged, and/or browserless remote devices to access these services, or a selection thereof, when such remote devices are operated at a public access hotspot supported by the system 10 and [0046] - As introduced above, in accordance with some embodiments of the invention, the system 10 may be configured to manage public and/or private network access for a plurality of remote devices 102, optionally of a plurality of remote device types, configurations and/or functionality, and that, within a variety of venues if necessary and [0111]),
obtaining one or more second device fingerprints generated based on network traffic associated with one or more second wireless connections of the connected device in one or more second wireless networks ([0006] - In accordance with one embodiment of the invention, there is provided a method for recognizing a wireless device across multiple hotspot locations, extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input; cross-referencing said extracted device identifier with a network accessible database of stored device profiles, each of said device profiles having a respective stored device identifier associated therewith and [0036] - Similarly, in some embodiments, remote device information or data resides or is stored on the remote device and is compared to a remote device profile stored in a knowledge base operatively coupled to the service access module and [0072] and [0189] Similarly, the extracted device identifier can be cross-referenced with stored device profiles such that repeat visitors can be recognized upon subsequent visits to the same or related locations, or again at unrelated locations for the purpose of expanding the device profile database across multiple operators (device profile sharing rules between entities may be set in place to protect user privacy and the like, as will be readily appreciated by the person of ordinary skill in the art), wherein each second wireless network is provided by an access point at a home or an office ([0034] - In some embodiments, the system 10 allows browser-based, browser-challenged, and/or browserless remote devices to access these services, or a selection thereof, when such remote devices are operated at a public access hotspot supported by the system 10 and [0040] - The system 10 generally provides one or more remote devices 102 access to one or more services 114 via network 104. For example, the system 10 could be used to provide access to digital home services, such as access to digital TV or other forms of home content to access applications such as, but not limited to, Slingbox, Orb, Location Free TV (LFTV), and/or home security features provided by various online home security service providers. A user could thus connect to a home access system (e.g. a home media server, networked computer, etc.) to access images, music, videos, files, and the like that are stored on remote devices located in the user's home, business, office, etc. and [0111]), and wherein the connected device accesses each second wireless network using a private user authentication controlled by a user managing the access point at the home or the office ([0034] - In general, the system 10 may be used to identify different remote devices 102 via the network access module 112, and in some embodiments, authenticate and authorize access thereto to network and/or Web-based services accessible via the service access module 106 and [0040] - The system 10 generally provides one or more remote devices 102 access to one or more services 114 via network 104. For example, the system 10 could be used to provide access to digital home services, such as access to digital TV or other forms of home content to access applications such as, but not limited to, Slingbox, Orb, Location Free TV (LFTV), and/or home security features provided by various online home security service providers. A user could thus connect to a home access system (e.g. a home media server, networked computer, etc.) to access images, music, videos, files, and the like that are stored on remote devices located in the user's home, business, office, etc. and [0046] - As introduced above, in accordance with some embodiments of the invention, the system 10 may be configured to manage public and/or private network access for a plurality of remote devices 102, optionally of a plurality of remote device types, configurations and/or functionality, and that, within a variety of venues if necessary and [0111]);
and
in response to finding a match between the one or more first device fingerprints and the one or more second device fingerprints ([0006] and [0036] - Similarly, in some embodiments, remote device information or data resides or is stored on the remote device and is compared to a remote device profile stored in a knowledge base operatively coupled to the service access module. Remote device information can be indicative of inherent characteristics of the remote device, such as a MAC address, or can be other information stored on the remote device for identification thereof and [0189] - Similarly, the extracted device identifier can be cross-referenced with stored device profiles such that repeat visitors can be recognized upon subsequent visits to the same or related locations, or again at unrelated locations for the purpose of expanding the device profile database across multiple operators (device profile sharing rules between entities may be set in place to protect user privacy and the like, as will be readily appreciated by the person of ordinary skill in the art). Combination of the device ID, location ID, and timestamp thus provide an indication that a particular device 1302 was present at a particular location at a particular time) entitling an enhanced service to the connected device ([0038]-[0039] - In one embodiment, authorization constraints can be associated with a service profile and used to directly or indirectly limit or disable specified applications, or to limit or disable network access functionality related to said specified applications. Authorization whitelists can also be used, as an alternative to or in conjunction with authorization constraints, to positively define access to services or to provide minimum service level guarantees and [0042]), wherein entitling the enhanced service to the connected device further comprises: in response to determining that the connected device has an ongoing wireless connection that comprises of the one or more first wireless connections or one of the one or more second wireless connections, ([0006] and [0036] - Similarly, in some embodiments, remote device information or data resides or is stored on the remote device and is compared to a remote device profile stored in a knowledge base operatively coupled to the service access module. Remote device information can be indicative of inherent characteristics of the remote device, such as a MAC address, or can be other information stored on the remote device for identification thereof and [0189] - Similarly, the extracted device identifier can be cross-referenced with stored device profiles such that repeat visitors can be recognized upon subsequent visits to the same or related locations, or again at unrelated locations for the purpose of expanding the device profile database across multiple operators (device profile sharing rules between entities may be set in place to protect user privacy and the like, as will be readily appreciated by the person of ordinary skill in the art). Combination of the device ID, location ID, and timestamp thus provide an indication that a particular device 1302 was present at a particular location at a particular time), enabling the enhanced service to the ongoing wireless connection ([0038]-[0039] - In one embodiment, authorization constraints can be associated with a service profile and used to directly or indirectly limit or disable specified applications, or to limit or disable network access functionality related to said specified applications. Authorization whitelists can also be used, as an alternative to or in conjunction with authorization constraints, to positively define access to services or to provide minimum service level guarantees and [0042]).
Regarding Claim 2;
Spencer discloses the method of claim 1.
Spencer further discloses wherein the one or more first wireless networks comprise wireless non-cellular internet access networks of a first type ([0046] - As introduced above, in accordance with some embodiments of the invention, the system 10 may be configured to manage public and/or private network access for a plurality of remote devices 102, optionally of a plurality of remote device types, configurations and/or functionality, and that, within a variety of venues if necessary and [0188] – part of the IEEE 802.11 standard), and the one or more second wireless networks comprise wireless non-cellular internet access networks of a second type ([0046] - As introduced above, in accordance with some embodiments of the invention, the system 10 may be configured to manage public and/or private network access for a plurality of remote devices 102, optionally of a plurality of remote device types, configurations and/or functionality, and that, within a variety of venues if necessary and [0188] – part of the IEEE 802.11 standard), and
Regarding Claim 7;
Spencer discloses the method of claim 1.
Spencer further discloses wherein the method further comprises, prior to obtaining the one or more first device fingerprints from the one or more first wireless connections of the connected device in the one or more first wireless networks: intercepting a first data communication of the connected device via the one or more first wireless networks at one or more first packet inspection points ([0006] - In accordance with one embodiment of the invention, there is provided a method for recognizing a wireless device across multiple hotspot locations, extracting a unique device identifier of the detected device from said wireless transmission and [0111] - ...may intercept the request to access the network 104...and [0194] - For example, while device identification and recognition may be implemented via packet capture of probe requests, as noted above, other packet captures and/or logging/tracking techniques may also or alternatively be used in conjunction therewith to automatically access a greater representation of user activity. )
Regarding Claim 8;
Spencer discloses the method of claim 1.
Spencer further discloses wherein the method further comprises, prior to obtaining the one or more second device fingerprints from the one or more second wireless connections of the connected device in the one or more second wireless networks: intercepting a second data communication of the connected device via the one or more second wireless networks at one or more second packet inspection points ([0006] - In accordance with one embodiment of the invention, there is provided a method for recognizing a wireless device across multiple hotspot locations, extracting a unique device identifier of the detected device from said wireless transmission and [0036] and [0111] - ...may intercept the request to access the network 104...and [0189] and [0194] - For example, while device identification and recognition may be implemented via packet capture of probe requests, as noted above, other packet captures and/or logging/tracking techniques may also or alternatively be used in conjunction therewith to automatically access a greater representation of user activity. )
Regarding Claim 9;
Spencer discloses the method of claim 1.
Spencer further discloses wherein a similar function generates both the one or more first device fingerprints and the one or more second device fingerprints so that they are comparable to each other ([0006] - extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input and [0111] - . Such remote device information, for example forming part of the remote device profile, may include, but is not limited to, the Media Access Control (MAC) address of the remote device 102, traffic type (e.g. communication port, data type, communication protocol, traffic headers, etc.), browser type (e.g. full browser, microbrowser, browser origin and/or configuration, etc.), and/or some other unique identifier (e.g. remote device configuration, serial number, signature related to a remote device clock or crystal oscillator, etc.)).
Regarding Claim 10;
Spencer discloses the method of claim 9.
Spencer further discloses wherein the similar function generates the one or more first device fingerprints based at least partly on one or more first host media access control protocol addresses transmitted by the connected device on the one or more first wireless connections ([0006] - extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input and [0111] - . Such remote device information, for example forming part of the remote device profile, may include, but is not limited to, the Media Access Control (MAC) address of the remote device 102, traffic type (e.g. communication port, data type, communication protocol, traffic headers, etc.), browser type (e.g. full browser, microbrowser, browser origin and/or configuration, etc.), and/or some other unique identifier (e.g. remote device configuration, serial number, signature related to a remote device clock or crystal oscillator, etc.)), and generates the one or more second device fingerprints based at least partly on one or more second host media access control protocol addresses transmitted by the connected device on the one or more second wireless connections ([0006] - extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input and [0036] and [0111] - . Such remote device information, for example forming part of the remote device profile, may include, but is not limited to, the Media Access Control (MAC) address of the remote device 102, traffic type (e.g. communication port, data type, communication protocol, traffic headers, etc.), browser type (e.g. full browser, microbrowser, browser origin and/or configuration, etc.), and/or some other unique identifier (e.g. remote device configuration, serial number, signature related to a remote device clock or crystal oscillator, etc.) and [0189]).
Regarding Claim 11;
Spencer discloses the method of claim 1.
Spencer further discloses wherein the enhanced service comprises an upgraded data transfer for an ongoing or future one or more first wireless connections of the connected device in the one or more first wireless networks ([0038]-[0039] and [0042] - data transmission or reception capabilities at a specified bandwidth), and/or an upgraded data transfer for an ongoing or future one or more second wireless connections of the connected device in the one or more second wireless networks ([0036] and [0038]-[0039] and [0042] - data transmission or reception capabilities at a specified bandwidth [0189]).
Regarding Claim 12;
Spencer discloses the method of claim 1.
Spencer further discloses wherein the enhanced service comprises a cybersecurity surveillance for an ongoing or future one or more first wireless connections of the connected device in the one or more first wireless networks ([0036] and [0038]-[0040] - For example, the system 10 could be used to provide access to digital home services, such as access to digital TV or other forms of home content to access applications such as, but not limited to, Slingbox, Orb, Location Free TV (LFTV), and/or home security features provided by various online home security service providers), and/or a cybersecurity surveillance for an ongoing or future one or more second wireless connections of the connected device in the one or more second wireless networks ([0036] and [0038]-[0040] - For example, the system 10 could be used to provide access to digital home services, such as access to digital TV or other forms of home content to access applications such as, but not limited to, Slingbox, Orb, Location Free TV (LFTV), and/or home security features provided by various online home security service providers and [0189]).
Regarding Claim 13;
Spencer discloses the method of claim 1.
Spencer further discloses wherein obtaining the one or more second device fingerprints from the one or more second wireless connections of the connected device in the one or more second wireless networks further comprises: obtaining the second device fingerprint from a present second wireless connection of the connected device in the second wireless network ([0006] - In accordance with one embodiment of the invention, there is provided a method for recognizing a wireless device across multiple hotspot locations, extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input; cross-referencing said extracted device identifier with a network accessible database of stored device profiles, each of said device profiles having a respective stored device identifier associated therewith and [0036] - Similarly, in some embodiments, remote device information or data resides or is stored on the remote device and is compared to a remote device profile stored in a knowledge base operatively coupled to the service access module and [0072] and [0189] Similarly, the extracted device identifier can be cross-referenced with stored device profiles such that repeat visitors can be recognized upon subsequent visits to the same or related locations, or again at unrelated locations for the purpose of expanding the device profile database across multiple operators (device profile sharing rules between entities may be set in place to protect user privacy and the like, as will be readily appreciated by the person of ordinary skill in the art); wherein obtaining the one or more first device fingerprints from the one or more first wireless connections of the connected device in the one or more first wireless networks further comprises ([0006] - In accordance with one embodiment of the invention, there is provided a method for recognizing a wireless device across multiple hotspot locations, the method comprising: detecting at one of the multiple hotspot locations a wireless transmission sent by the wireless device; extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input and [0036] and [0072]); retrieving the one or more first device fingerprints from a data storage configured to store the one or more first device fingerprints obtained from past one or more first wireless connections of the connected device in the one or more first wireless networks ([0006] - In accordance with one embodiment of the invention, there is provided a method for recognizing a wireless device across multiple hotspot locations, extracting a unique device identifier of the detected device from said wireless transmission, said unique device identifier automatically embedded within said wireless transmission by the detected device without user input; cross-referencing said extracted device identifier with a network accessible database of stored device profiles, each of said device profiles having a respective stored device identifier associated therewith and [0036] - Similarly, in some embodiments, remote device information or data resides or is stored on the remote device and is compared to a remote device profile stored in a knowledge base operatively coupled to the service access module and [0072] and [0189] Similarly, the extracted device identifier can be cross-referenced with stored device profiles such that repeat visitors can be recognized upon subsequent visits to the same or related locations, or again at unrelated locations for the purpose of expanding the device profile database across multiple operators (device profile sharing rules between entities may be set in place to protect user privacy and the like, as will be readily appreciated by the person of ordinary skill in the art).
Regarding Claim(s) 14 and 15; claim(s) 14 and 15 is/are directed to a/an apparatus associated with the method claimed in claim(s) 1 and 2. Claim(s) 14 and 15 is/are similar in scope to claim(s) 1 and 2 and is/are therefore rejected under similar rationale.
Regarding Claim(s) 20; claim(s) 20 is/are directed to a/an medium associated with the method claimed in claim(s) 1. Claim(s) 20 is/are similar in scope to claim(s) 1, and is/are therefore rejected under similar rationale.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KARI L SCHMIDT whose telephone number is (571)270-1385. The examiner can normally be reached Monday-Friday 10am - 6pm (MDT).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KARI L SCHMIDT/Primary Examiner, Art Unit 2439