CTNF 18/487,358 CTNF 85279 Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. This action is in response to the claims filed 10/16/023. Claims 1-20 are pending. Claims 1 (a machine), 8 (a non-transitory CRM), and 15 (a method) are independent. Claim Rejections - 35 USC § 112 07-30-01 AIA The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. 07-31-01 Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA), first paragraph , as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Independent claims 1, 8, and 15 require: (1) an “authentication match score”, (2) an “enrollment match score”. Where a match score is defined in Applicant’s ¶ 66: “As used herein, the term "match score" may refer to a degree of match between one or more credentials.” Applicant’s specification does not provide a description on how to determine a degree of match between credentials. In the field of biometrics, individual samples vary vastly and the field of biometric authentication is directed to finding identical attributes of biometrics that allow consistent matching between an original enrollment template and a later submitted authentication sample. Finding differences between biometric samples is not well studied because each sample is massively different. Consider a fingerprint where different portions of the finger, rotations, and sampling accuracy each contribute to a unique sample of the user’s finger. Or in the case of voice, different ambient sound, distance, health, and mood each contribute to the uniqueness of the various samples. Applicant’s specification hypothesizes: “the system may determine that the enrollment match score between different voice samples varies by 3% based on comparing the different samples received from the user during the enrollment phase and may set the predetermined threshold as 3%.” Applicant’s specification ¶ 73. However, 3% is unrealistically optimistic for user input consistency of biometric samples and would not be attainable for calculating an “authentication match score”. Applicant’s specification provides no description for calculating the “match scores” and such a calculation is non-trivial in the case of variable biometric samples of users. A person of skill in the art would not have understood the inventor to be in possession of the invention requiring calculation of “match scores” between biometric samples based on the written description as filed. Note that independent claims 1, 8, and 15 do not require biometric credentials and; therefore, require even more description on how a “match score” might be computed for any time of credential. Dependent claims 2-7, 9-14, and 16-20 are rejected due to their dependency on a rejected independent base claim. 07-30-02 AIA The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 07-34-01 Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA), second paragraph , as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. For the purposes of examination, the “authentication match score” is interpreted to be a derivative of the “at least one credential” and the “enrollment match score” is interpreted to be a prior sample of the credential, i.e. a template. In more detail: Independent claims 1, 8, and 15 require (1) an “authentication match score”, (2) an “enrollment match score” and (3) “comparing the authentication match score of the at least one credential with the enrollment match score”. It is unclear what the match scores require and unclear how the scores are utilized to determine the authenticity of a user. In ¶ 66 of Applicant’s specification, a match score is a difference between two samples. Whereas in ¶ 74, a match score is compared to determine a difference. Comparing percentages has no relation to whether the input biometric matches a prior biometric. It is unclear why the claim performs three matching actions when a normal biometric authentication performs a single comparison between a ‘sample’ and an enrolled ‘template’. Dependent claims 2-7, 9-14, and 16-20 are rejected due to their dependency on a rejected independent base claim. Claims 5, 12, and 19 require: “determine that the quantum key distribution secret verification is not successful based on determining that the new common base matches the enrollment common base.” This appears to be a typographical error as a match should indicate a successful verification, as stated in claim 4. Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim (s) 1, 7, 8, 14, and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Sands et al., US 2004/0148526 (published 2004) . As to claims 1, 8, and 15 Sands discloses a machine comprising: A system for securely authenticating users using quantum key distribution protocol, the system comprising: (non-limiting intended use) at least one network communication interface; at least one non-transitory storage device; and at least one processing device coupled to the at least one non-transitory storage device and the at least one network communication interface, wherein the at least one processing device is configured to: (Sands ¶ 90) receive an authentication request comprising at least one credential from a user, via a user device; (“The system displays an indication of the biometrics required and overall progress to the user as the hardware acquires the biometric. This is usually done one biometric at a time, but may be more: some scanners can acquire several prints at once, or both eyes at once for example. This step includes loading device drivers specific to the various scanners, and communicating with the scanning hardware” Sands ¶ 75) in response to receiving the authentication request, calculate an authentication match score for the at least one credential; (“to gather a ‘sample set’ of biometrics.” Sands ¶ 75) retrieve an authentication token associated with the user stored on an external physical device connected to the user device; (“In step 410, the authentication policy retrieves the user's template biometric profile from a persistent storage medium such as a database, file, or smartcard.” Sands ¶ 69) retrieve an enrollment match score associated with the authentication token of the user, wherein the enrollment match score is generated and scored during an enrollment phase of the user; (“The enrollment manager 200 is responsible for collecting and storing information for each valid user of the network into the storage media 205.” Sands ¶ 50. “This storage 205, may be a centralized database or distributed, as in the case where each user carries a portable storage media, such as a smart card, containing one or more biometric profiles. In either case it must be accessible by the server.” Sands ¶ 49) validate the at least one credential by comparing the authentication match score of the at least one credential with the enrollment match score associated with the user; and (“In step 435, the authentication policy engine compares the sample set of biometrics with the biometric profile on record through the use of one or more matching algorithms.” Sands ¶ 76. See also Sands ¶ 96) determine if the validation is successful based on comparing the authentication match score of the at least one credential with the enrollment match score. (“The matching engine returns to the authentication policy engine a confidence figure indicating the likelihood that the biometric measurements acquired came from the same person that provided the biometric profile stored in the database.” Sands ¶ 64. See also Sands ¶ 96) Sands does not explicitly disclose that the biometric sample (step 430 of Figure 4) can be performed prior to obtainment of the enrollment templates (step 410 of Figure 4). However, as the biometric templates are unused until the comparison is performed in step 435, it would have been obvious to obtain them after obtaining the sample (step 430). It would have improved the system of Sands for a number of reasons including securing other unnecessary enrollment templates from exposure during transmission (Sands ¶ 69) as well as conserving bandwidth by avoiding transmittal of unnecessary data prior to any comparison; for example if the user’s location indicates that no authentication can be performed (Sands ¶ 37) As to claims 7 and 14, Sands discloses the machine/CRM of claims 1 and 8 and further discloses: wherein the at least one credential comprises biometric credentials. (“The system displays an indication of the biometrics required and overall progress to the user as the hardware acquires the biometric. This is usually done one biometric at a time, but may be more: some scanners can acquire several prints at once, or both eyes at once for example. This step includes loading device drivers specific to the various scanners, and communicating with the scanning hardware” Sands ¶ 75) Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim (s) 2-6, 9-13, and 16-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Sands et al., US 2004/0148526 (published 2004), in view of Liao et al. “Cancelable remote quantum fingerprint templates protection scheme” (published 2017) . As to claims 2, 9, and 16 Sands discloses the machine/CRM/method of claims 1, 8, and 15 and further discloses: wherein the at least one processing device is configured to: determine that the validation is not successful (see biometric retries in Sands ¶¶ 78 and 79) based on determining that the authentication match score is over a predetermined threshold associated with the enrollment match score; and (see thresholds of Sands ¶ 96) Sands does not disclose an authentication failure when a “match score is over a predetermined threshold”. However, whether the determination is made based on greater than or less than a threshold the underlying intent and calculation is identical. For example, the threshold of 90-100% in Sands ¶ 96 is equivalent to saying 0-10% mismatch percentage. Thus, it would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention that the threshold comparison could have similarly determined a failure based on a threshold being exceeded. Sands does not disclose: perform a quantum key distribution secret verification based on an enrollment common base stored on a quantum computing platform during the enrollment phase via a quantum communication network. Liao discloses: (“we detail the proposed novel cancelable remote quantum fingerprint templates protection scheme, which can theoretically guarantee the security and privacy of the fingerprint identification system.” Liao § 1 “3) The final step of the verification stage is to match the query code and record’s encrypted key. Assume that BE represents the encrypted key, BQ represents the query code, and BT represents the template…. where ‘1’ indicates a perfect match. We propose another metric s(UE,UQ) here to avoid the situation that once an encrypted key stored in the server database is compromised, an adversary may try to login in using this encrypted key, which makes the value of s(UE,UQ) be ‘1’. That is to say, if the value of s(UE,UQ) is larger than a certain threshold tscore (0 < tscore < 1), this verification can be considered as a failure.” Liao § 3.2). perform a quantum key distribution secret verification (Liao Figure 4. “This protocol has a profound impact on the discrete-variable quantum key distribution (DVQKD) area.” Liao § 1) based on an enrollment common base stored on a quantum computing platform (“At the enrollment stage, a decision sequence and a measurement basis sequence are produced by the client and the server respectively for each registrant.” Liao § 3.1) during the enrollment phase via a quantum communication network. (Liao Figure 2) A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Sands with Liao by performing the biometric template and sample communications, including the retry authentications, using the quantum transmission of Liao. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Sands with Liao in order to defend against attacks on biometric identification systems by making it harder to obtain retrieve the biometric information from transmissions, Liao § 1. As to claims 3, 10, and 17 Sands in view of Liao discloses the machine/CRM/method of claims 2, 9, and 16 and further discloses: wherein the at least one processing device is configured to perform the quantum key distribution secret verification based on: generating a new common base for the at least one credential received with the authentication request; (“After measurement, all these quantum bits are collapsed into the eigenstates of their corresponding measurement operators. Applying Pauli-X gate[28] to these collapsed quantum bits, subsequently, the quantum bits X|qb ⟩ i are translated into a classical binary bit string according to the interconversion rule. By these two steps, an encrypted and specific binary bit string for the current record has been produced. This binary bit string is called the query code.” Liao § 3.2) communicating with the quantum computing platform about the enrollment common base stored on the quantum computing platform; and (“The enrollment manager 200 is responsible for collecting and storing information for each valid user of the network into the storage media 205.” Sands ¶ 50. “This storage 205, may be a centralized database or distributed, as in the case where each user carries a portable storage media, such as a smart card, containing one or more biometric profiles. In either case it must be accessible by the server.” Sands ¶ 49) comparing the new common base with the enrollment common base based on communicating with the quantum computing platform over the quantum communication network. (“3) The final step of the verification stage is to match the query code and record’s encrypted key. Assume that BE represents the encrypted key, BQ represents the query code, and BT represents the template…. where ‘1’ indicates a perfect match. We propose another metric s(UE,UQ) here to avoid the situation that once an encrypted key stored in the server database is compromised, an adversary may try to login in using this encrypted key, which makes the value of s(UE,UQ) be ‘1’. That is to say, if the value of s(UE,UQ) is larger than a certain threshold tscore (0 < tscore < 1), this verification can be considered as a failure.” Liao § 3.2). As to claims 4, 11, and 18 Sands in view of Liao discloses the machine/CRM/method of claims 3, 10, and 17 and further discloses: determine that the new common base matches the enrollment common base based on comparing the new common base with the enrollment common base; (“3) The final step of the verification stage is to match the query code and record’s encrypted key. Assume that BE represents the encrypted key, BQ represents the query code, and BT represents the template.” Liao § 3.2). determine that the quantum key distribution secret verification is successful based on determining that the new common base matches the enrollment common base; and (“where ‘1’ indicates a perfect match.” Liao § 3.2). authenticate the user based on determining that the quantum key distribution secret verification is successful. (“In step 445, authentication is granted after a successful match.” Sands ¶ 81. “The matching engine returns to the authentication policy engine a confidence figure indicating the likelihood that the biometric measurements acquired came from the same person that provided the biometric profile stored in the database.” Sands ¶ 64. See also Sands ¶ 96). As to claims 5, 12, and 19, Sands in view of Liao discloses the machine/CRM/method of claims 3, 10, and 17 and further discloses: wherein the at least one processing device is configured to: determine that the new common base does not match the enrollment common base based on comparing the new common base with the enrollment common base; (“3) The final step of the verification stage is to match the query code and record’s encrypted key. Assume that BE represents the encrypted key, BQ represents the query code, and BT represents the template.” Liao § 3.2). determine that the quantum key distribution secret verification is not successful based on determining that the new common base matches the enrollment common base; and (“3) The final step of the verification stage is to match the query code and record’s encrypted key. Assume that BE represents the encrypted key, BQ represents the query code, and BT represents the template…. where ‘1’ indicates a perfect match. We propose another metric s(UE,UQ) here to avoid the situation that once an encrypted key stored in the server database is compromised, an adversary may try to login in using this encrypted key, which makes the value of s(UE,UQ) be ‘1’. That is to say, if the value of s(UE,UQ) is larger than a certain threshold tscore (0 < tscore < 1), this verification can be considered as a failure.” Liao § 3.2). deny authentication of the user based on determining that the quantum key distribution secret verification is successful. (“In step 455, user authentication is not granted, the authentication system now returns a token implying ‘the user does not appear to be who they claim’.” Sands ¶ 83. See also Sands ¶ 96. “2. The sample does not match the template profile, or for other reasons, access should not be granted. If the maximum number of user retries has been reached, for example, access is not allowed.” Sands ¶ 78). As to claims 6, 13, 20 Sands in view of Liao discloses the machine/CRM/method of claims 2, 9, and 16 and further discloses: receive an enrollment request from the user at a previous instance; (enrollment precedes comparison with the enrollment) perform enrollment of the user, wherein the enrollment of the user during the enrollment phase comprises: (“The enrollment manager 200 may collect user identification information (USER ID) from a new user, such as the user's name or a derivative of the user's name. The enrollment manager 200 also collects from the user one or more biometric profiles.” Sands ¶ 50) receiving one or more enrollment credentials from the user device of the user; (“for each biometric or biometric device that the user is entitled to use, biometric data may be generated and stored for the user in the enrollment database as part of the biometric profile.” Sands ¶ 53) extracting one or more features from the one or more enrollment credentials; (“for each biometric or biometric device that the user is entitled to use, biometric data may be generated and stored for the user in the enrollment database as part of the biometric profile.” Sands ¶ 53) generating the enrollment match score from the one or more features extracted from the one or more enrollment credentials; (“for each biometric or biometric device that the user is entitled to use, biometric data may be generated and stored for the user in the enrollment database as part of the biometric profile.” Sands ¶ 53) generating the authentication token and associate the authentication token with the enrollment match score of the user; (“FIG. 3 shows an illustrative view of a database entry for a user. The entry includes the user's USER ID, and an entry for each biometric device type that the user has been measured on up to N biometric devices.” Sands ¶ 53) storing the authentication token and the enrollment match score in the external physical device; (“This storage 205, may be a centralized database or distributed, as in the case where each user carries a portable storage media, such as a smart card, containing one or more biometric profiles.” Sands ¶ 49) generating the enrollment common base based on the enrollment match score of the user; and (see Liao Figure 2, “Owing to the property of EPR entanglement, which is discussed in Section 2, once a particle of EPR has been measured, another particle state can be confirmed. In this case, |qa ⟩ has been measured, thus the state of |qb ⟩ can be known without additional measurement.” Liao § 3.1) transmitting the enrollment common base to the quantum computing platform via the quantum communication network. (“Then, the server recovers the classical bit string according to the decision sequence produced in step 1), and saves it in database.” Liao § 3.1) . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892, particularly: Al-Saggaf, US 11,483,310, discloses a post-quantum biometric template protection system using a smart-card. Cerf et al., US 2004/0109564, discloses quantum key distribution relying on continuously phase and amplitude-modulated coherent light. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL W CHAO whose telephone number is (571)272-5165. The examiner can normally be reached M, W-F 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached at (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent- center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MICHAEL W CHAO/ Primary Examiner, Art Unit 2492 Application/Control Number: 18/487,358 Page 2 Art Unit: 2492 Application/Control Number: 18/487,358 Page 3 Art Unit: 2492 Application/Control Number: 18/487,358 Page 4 Art Unit: 2492 Application/Control Number: 18/487,358 Page 5 Art Unit: 2492 Application/Control Number: 18/487,358 Page 6 Art Unit: 2492 Application/Control Number: 18/487,358 Page 7 Art Unit: 2492 Application/Control Number: 18/487,358 Page 8 Art Unit: 2492 Application/Control Number: 18/487,358 Page 9 Art Unit: 2492 Application/Control Number: 18/487,358 Page 10 Art Unit: 2492 Application/Control Number: 18/487,358 Page 11 Art Unit: 2492 Application/Control Number: 18/487,358 Page 12 Art Unit: 2492 Application/Control Number: 18/487,358 Page 13 Art Unit: 2492 Application/Control Number: 18/487,358 Page 14 Art Unit: 2492 Application/Control Number: 18/487,358 Page 15 Art Unit: 2492