Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This action is in response to the amendment and remarks filed 3/02/2026. Claims 1-20 are pending. Claims 1 (a non-transitory CRM), 11 (a method), and 20 (a machine) are independent.
Response to Arguments
Applicant’s remarks directed to the 112(a) rejection of claims 1-20 are persuasive. The rejection is withdrawn.
Applicant's arguments filed 3/02/2026 have been fully considered but they are not persuasive.
On pages 11-12 of the remarks Applicant states “Cha relies on his server sending tests to his client/UE”.
This argument is irrelevant.
MPEP § 2111.03.I: “The transitional term “comprising”, which is synonymous with “including,” “containing,” or “characterized by,” is inclusive or open-ended and does not exclude additional, unrecited elements or method steps.”
This means that so long as the UE of Cha performs communication analogous to the claimed “test” it does not matter if the server additionally performs tests.
In Cha Figure 8, Messages 804, 808, and 814 are tests. Although only messages 808 and 814 are messages that comply with a type of authentication. Therefore, Cha discloses the claimed concept of tests.
Examiner notes that the messages that Applicant references as server tests are commonly termed authentication challenges, see Cha ¶ 114. In the context of authentication, server-based challenges are expected. Further, the portion of Applicant’s specification noted in the amendment, ¶¶ 90, 91, 98, and 42 do not detail any server message that would exclude the relevance of the messages of Cha.
In summary, Applicant’s claims do not exclude the server messages of Cha (Figure 8, steps 806, 810) and Applicant’s specification would not support a negative limitation to exclude the steps of Cha.
On page 12 of the remarks Applicant states: “Modifying Cha to associate a set of policy files with each application on BYODs instead of sending tests from a server to a client to challenge the client would require substantial reconstruction and redesign as well as change the basic principle with regards to how Cha is constructed to operate (see MPEP 2143.01(VI))”. This argument is not persuasive.
In response to applicant's argument that “substantial reconstruction and redesign as well as change the basic principle with regards to how Cha is constructed to operate”, the test for obviousness is not whether the features of a secondary reference may be bodily incorporated into the structure of the primary reference; nor is it that the claimed invention must be expressly suggested in any one or all of the references. Rather, the test is what the combined teachings of the references would have suggested to those of ordinary skill in the art. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981).
In more detail, Cha is directed to automated negotiation and selection of authentication protocols (Cha title) and Barton is directed to policy-based application management (Barton title) which includes cloud services and numerous authentication mechanisms.
The principle of operation of Cha is negotiation in authentication. The principle of operation of Barton is performing authentication in a cloud environment. They are directly related in that both are concerned with authentication and neither “principle of operation” would be impacted by the other.
For at least the above reasons, Applicants remarks are not persuasive.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 4-9, 11, and 14-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Grossbart, “What you need to know about OAuth2 and logging in with Facebook” (published 2017).
As to claims 1, 11, and 20, Grossbart discloses:
A non-transitory processor-readable medium including instructions executable by one or more processors, and when executed operable for: (“I use Spotify on my iPad” Grossbart p. 6)
transmitting tests from a client device to server-side software located on a server device, wherein the tests include a first requesting message that complies with the first type of authentication and a second requesting message that complies with the second type of authentication;” (see Grossbart page 8 showing a username/password login and a different OAuth-Facebook login. Each login type being the respective first/second login types.)
receiving results of the tests from the server-side software; (the successful logins using either username/password or Facebook in Grossbart page 8)
selecting, based on the results of the tests, an authentication sub-flow from a plurality of authentication sub-flows enabling a client-side program on the client device to operate on cloud-based data associated with server-side software; (“I can use my Facebook account to log in. When I tap that button, Spotify sends me over to facebook.com, and I log in there.” Grossbart p. 9)
facilitating client authentication for the client-side program to operate on the cloud-based data using the selected authentication sub-flow; and (“Spotify sends me over to facebook.com, and I log in there.” Grossbart p. 9. Spotify is a distributed multi-server service and is therefore cloud based.)
operating on the cloud-based data from the client-side program using the client- authentication. (“As an example, I use Spotify on my iPad.” Grossbart p. 6).
Grossbart discloses (page 8) that you can login to Spotify using either a username/password or Facebook federated OAuth login. Grossbart does not disclose using both logins and then using at least one of the logins a second time; e.g. the combined performance of “transmitting tests” and “facilitating client authentication for the client-side program”
However, a person of ordinary skill in the art before the effective filing date of the claimed invention would have practiced the invention by logging into Spotify multiple times using both username/password and Facebook when preferred, and then subsequently logging into Spotify again. As is normally done with services that require logins, users would login multiple times whenever desired. Thus, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to perform the various logins discussed in Grossbart multiple times as needed, thereby practicing the claimed invention.
As to claims 4 and 14, Grossbart further discloses:
wherein the tests are messages and the transmitting tests from a client device to server-side software further includes: transmitting the messages from the client device to the server-side software. (Grossbart pp. 6-8).
As to claims 5 and 15, Grossbart further discloses:
wherein the test results are responses and the receiving of the results of the tests from the server- side software further includes: receiving the responses of the messages from the server-side software. (Grossbart pp. 6-8).
As to claims 6 and 16, Grossbart further discloses:
wherein each of the plurality of authentication sub-flows are associated with a different type of authentication. (see Grossbart Figure on p. 8, Facebook or username/password)
As to claims 8 and 18, Grossbart further discloses:
determining a type of authentication used by the server-side software based on the results from the tests. (see Grossbart Figure on p. 8, Facebook or username/password)
As to claims 9 and 19, Grossbart further discloses:
(“I can use my Facebook account to log in. When I tap that button, Spotify sends me over to facebook.com, and I log in there.” Grossbart p. 9)
providing authenticated credentials; and (“Opening a new browser window for the OAuth2 provider is a crucial step. That’s what allows providers to show their own log-in forms and to ask each user for whatever login information they need.” Grossbart p. 13)
collecting authentication evidence based on the selected authentication sub-flow. (“The important part is that, when the provider is done, they will redirectback to you and give you a token.” Grossbart p. 14)
Claim(s) 1-6, 8-16, and 18-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cha US 2013/0174241 (filed 2012), in view of Barton et al., US 2014/0033271 (filed 2013).
As to claims 1, 11, and 20, Cha discloses a non-transitory processor-readable medium including:
transmitting tests from a client device to server-side software located on a server device; (see Cha figure 8, messages, 808)
receiving results of the tests from the server-side software, located on a server device (see Cha Fig. 8, messages 810), wherein the tests include
a first requesting message that complies with the first type of authentication and (see Cha Fig. 8, messages 808)
(also: “In an example embodiment in which the UE may not be capable of implementing the requested authentication protocols, the UE may “fail gracefully”… If the UE successfully authenticates the server with the AUTN and determines that the SQN” Cha ¶ 124, another authentication type.)
selecting, based on results of the tests, an authentication sub-flow from a plurality of authentication sub-flows enabling a client-side program on the client device (see Cha Fig. 8, messages 812/814. “Successful negotiations (e.g., arriving at an acceptable authentication protocol) between the UE and the MNO/OP may be achieved with an intelligent browser. FIG. 8… the server may send another 401 with a different WWW-Authenticate header which may comprise a challenge for the authentication protocol that matches the UE's and RP's requested authentication protocol (812).” Cha ¶ 122)
…
facilitating client authentication for the client-side program to (“the server may send another 401 with a different WWW-Authenticate header which may comprise a challenge for the authentication protocol that matches the UE's and RP's requested authentication protocol (812).” Cha ¶ 122)
Cha, although disclosing additional authentication attempts in ¶ 124, does not explicitly disclose:
a second requesting message that complies with the second type of authentication;
Cha does not disclose a cloud, as claimed:
a second requesting message that complies with the second type of authentication;
to operate on cloud-based data associated with server-side software;
…
operate on the cloud-based data using the selected authentication sub-flow; and
operating on the cloud-based data from the client-side program using the client-authentication.
Barton discloses:
a second requesting message that complies with the second type of authentication;
(“the client device 2505 and resources 2520 may use different authentication and/or communication protocols. The proxy device 2510 may translate between these different protocols. Additionally or alternatively, the proxy device 2510 may provide additional benefits, as will be described in the examples below.” Barton ¶ 396. “the proxy device 2510 may request that the client device 2505 sign or decrypt an authentication message using the client certificate (or a private key included therein), or return a list of available security certificates or a selection by the user of a particular security certificate.” Barton ¶ 397. “the client device 2505 and proxy device 2510 may exchange one or more authentication messages. They may exchange HTTP status codes, such as HTTP 401 codes for requesting authentication, and/or challenge-response messages.” Barton ¶ 406)
to operate on cloud-based data associated with server-side software; (“As seen in FIG. 2, client computers 211-214 may communicate with a cloud management server 210 to access the computing resources (e.g., host servers 203, storage resources 204, and network resources 205) of the cloud system.” Barton ¶ 67)
…
operate on the cloud-based data using the selected authentication sub-flow; and
operating on the cloud-based data from the client-side program using the client-authentication. (“A variety of authentication techniques may be employed in the procedure above. For example, in some arrangements, a set of tickets (or tokens) is loaded into the mobile device during initial authentication” Barton ¶ 313. Also Barton ¶¶ 323 and 402. “Assuming the mobile device is running on a foreign network and the enterprise administrator has permitted VPN access for this application for this user, then the specialized network software initiates a secure connection to the corporate gateway device” Barton ¶ 324.)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Cha with Barton by incorporating the additional authentication types in the negotiation tests of Cha Figure 8 and utilizing said negotiation in mobile devices authenticating to a cloud environment of Barton. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Cha with Barton in order to allow control over managed corporate software and its access to sensitive internal information in a cloud, thereby securing corporate information from unintended exposure.
As to claims 2 and 12, Cha in view of Barton discloses the CRM/method/machine of claims 1, 11, and 20 and further discloses:
further including instructions executable by the one or more processors and when executed operable for:
transmitting
receiving
selecting, based on the
Cha in view of Barton, as combined in claim 1, does not disclose:
second [authentication]
second results
second cloud-based
Barton further discloses:
second [authentication]
second results
(“it should be understood that over time, such tickets may expire. If such tickets expire prior to use, operations that required tickets instead now require that the user re-authenticate.” Barton ¶ 314, see also ¶¶ 315 and 324)
second cloud-based (“one or more policy files may define the circumstances under which one or more applications operating under the control of or in accordance with those policy files can and cannot use an SSO service to bypass an authentication or security challenge.” Barton ¶ 395)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Cha with Barton by utilizing the authentication negotiation of Cha in mobile devices authenticating to a cloud environment of Barton. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Cha with Barton in order to allow control over managed corporate software and its access to sensitive internal information in a cloud, thereby securing corporate information from unintended exposure.
As to claim 3 and 13, Cha in view of Barton discloses the CRM/method/machine of claims 2 and 12 and further discloses:
facilitating second client authentication for the second client-side program to operate on the second cloud-based data using the selected second authentication sub-flow; and (“the server may send another 401 with a different WWW-Authenticate header which may comprise a challenge for the authentication protocol that matches the UE's and RP's requested authentication protocol (812).” Cha ¶ 122)
operating on the second cloud-based data from the second client-side program using the second client authentication. (“A variety of authentication techniques may be employed in the procedure above. For example, in some arrangements, a set of tickets (or tokens) is loaded into the mobile device during initial authentication” Barton ¶ 313. Also Barton ¶ 323. “Assuming the mobile device is running on a foreign network and the enterprise administrator has permitted VPN access for this application for this user, then the specialized network software initiates a secure connection to the corporate gateway device” Barton ¶ 324).
As to claims 4 and 14, Cha in view of Barton discloses the CRM/method/machine of claims 1, 11, and 20 and further discloses:
wherein the tests are messages and the transmitting tests from a client device to server-side software further includes:
transmitting the messages from the client device to the server-side software. (see Cha figure 8, messages 804, 808, 814).
As to claim 5 and 15, Cha in view of Barton discloses the CRM/method/machine of claims 4 and 14 and further discloses:
wherein the test results are responses and the receiving of the results of the tests from the server-side software further includes: receiving the responses of the messages from the server-side software. (see Cha Fig. 8, messages 806, 810)
As to claims 6 and 16, Cha in view of Barton discloses the CRM/method/machine of claims 1, 11, and 20 and further discloses:
wherein each of the plurality of authentication sub-flows are associated with a different type of authentication. (“the server may send another 401 with a different WWW-Authenticate header which may comprise a challenge for the authentication protocol that matches the UE's and RP's requested authentication protocol (812).” Cha ¶ 122)
As to claims 8 and 18, Cha in view of Barton discloses the CRM/method/machine of claims 1, 11, and 20 and further discloses:
further including instructions executable by the one or more processors and when executed operable for: determining a type of authentication used by the server-side software based on the results from the tests. (“the server may send another 401 with a different WWW-Authenticate header which may comprise a challenge for the authentication protocol that matches the UE's and RP's requested authentication protocol (812).” Cha ¶ 122)
As to claims 9 and 19, Cha in view of Barton discloses the CRM/method/machine of claims 1, 11, and 20 and further discloses:
further including instructions executable by the one or more processors and when executed operable for:
providing authenticated credentials; and collecting authentication evidence based on the selected authentication sub-flow. (see Cha figure 8, messages 812, 814. “A variety of authentication techniques may be employed in the procedure above. For example, in some arrangements, a set of tickets (or tokens) is loaded into the mobile device during initial authentication” Barton ¶ 313. Also Barton ¶ 323. “Assuming the mobile device is running on a foreign network and the enterprise administrator has permitted VPN access for this application for this user, then the specialized network software initiates a secure connection to the corporate gateway device” Barton ¶ 324).
As to claims 10, Cha in view of Barton discloses the CRM/method/machine of claims 1, 11, and 20 and further discloses:
further including instructions executable by the one or more processors and when executed operable for:
transmitting the tests from the client device to the server-side software on a second server device; (see Cha figure 8, messages 804, 808, 814)
receiving ; (see Cha Fig. 8, messages 806, 810)
selecting, based on client device to operate on ; (“the server may send another 401 with a different WWW-Authenticate header which may comprise a challenge for the authentication protocol that matches the UE's and RP's requested authentication protocol (812).” Cha ¶ 122)
facilitating
operating on the
Cha in view of Barton, as combined in claim 1, does not disclose:
a copy of the server-side software
a second server device
second results of the tests … on a second server device … on a second server device
second cloud-based data
second client-authentication
Barton further discloses:
a copy of the server-side software (“The proxy device 2510 may comprise one or more of a server (e.g., servers 201, 206, 1701, 410), computing device, access gateway 360, gateway server 406, or any other device. The proxy device 2510 may facilitate communications between the client device 2510 and enterprise resources or other networks. For example, a user of the client device 2505 may wish to access enterprise resources that require authentication, and the proxy device 2510 may mediate access.” Barton ¶ 402. See also Barton ¶ 73)
a second server device (Barton ¶ 402. See also Barton ¶ 73)
second results of the tests (“it should be understood that over time, such tickets may expire. If such tickets expire prior to use, operations that required tickets instead now require that the user re-authenticate.” Barton ¶ 314, see also ¶¶ 315 and 324) … on a second server device … on a second server device (“The proxy device 2510 may comprise one or more of a server (e.g., servers 201, 206, 1701, 410), computing device, access gateway 360, gateway server 406, or any other device. The proxy device 2510 may facilitate communications between the client device 2510 and enterprise resources or other networks. For example, a user of the client device 2505 may wish to access enterprise resources that require authentication, and the proxy device 2510 may mediate access.” Barton ¶ 402. See also Barton ¶ 73)
second cloud-based data (“one or more policy files may define the circumstances under which one or more applications operating under the control of or in accordance with those policy files can and cannot use an SSO service to bypass an authentication or security challenge.” Barton ¶ 395)
second client-authentication (“it should be understood that over time, such tickets may expire. If such tickets expire prior to use, operations that required tickets instead now require that the user re-authenticate.” Barton ¶ 314, see also ¶¶ 315 and 324)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Cha with Barton by utilizing the authentication negotiation of Cha in mobile devices authenticating to a cloud environment of Barton. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Cha with Barton in order to allow control over managed corporate software and its access to sensitive internal information in a cloud, thereby securing corporate information from unintended exposure.
Claim(s) 7 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cha US 2013/0174241 (filed 2012), in view of Barton et al., US 2014/0033271 (filed 2013), and Vepa et al., US 2017/0329957 (published 2017-11).
As to claims 7 and 17, Cha in view of Barton discloses the CRM/method/machine of claims 1, 11, and 20 and further discloses:
wherein the types of types of authentication include
Cha in view of Barton does not disclose:
include JSON Web Token (JWT), basic access authentication (BASIC)
Vepa discloses:
include JSON Web Token (JWT) (“receiving standard identity tokens that are JavaScript Object Notation (“JSON”) Web Tokens (“JWTs”) conveying the user's authenticated identity.” Vepa ¶ 100), basic access authentication (BASIC) (“Cloud Gate 702 also acts as an HTTP Basic Auth authenticator, validating HTTP Basic Auth credentials against IDCS.” Vepa ¶ 143)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have modified Cha in view of Barton with Vepa by incorporating and supporting JSON web tokens and HTTP Basic. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Cha in view of Barton with Vepa in order to expand the supported authentication methods and thereby support a wide variety of software products and services.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892, particularly:
Boss et al., US 2006/0168509, discloses a method to map favorite values for electronic form filling.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL W CHAO whose telephone number is (571)272-5165. The examiner can normally be reached M, W-F 8-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached at (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MICHAEL W CHAO/ Primary Examiner, Art Unit 2492