DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This is in response to the correspondence filed on 10/25/23. Claims 1-20 are still pending and have been considered below.
Claim Objections
Claims 10 and 17 are objected to because of the following informalities: the instant claims should be amended to recite, “the at least one verifier”. Appropriate correction is required.
Claim 20 is objected to because of the following informalities: line 12 of the instant claim should be amended to recite, “communicate between [[a]]the plurality of”. Appropriate correction is required.
Claim 20 is objected to because of the following informalities: line 13 of the instant claim should be amended to recite, “wherein the at least one verifier is selected”. Appropriate correction is required.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-5 and 8-10 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Badhwar et al. (2021/0194883).
Claim 1: Badhwar et al. discloses a method for multi-application registration and verification, the method comprising:
identifying a gateway application programming interface (API) on a client device, wherein the gateway API is configured to communicate with a plurality of auxiliary APIs associated with the client device(clients can connect to an enterprise scale service provider which allows for a single sign on connection to all web applications in the group) [page 2, paragraph 0021];
registering the client device via the gateway API(registered users) [pages 2-3, paragraph 0025];
verifying registration of the client device(registration status) [page 6, paragraph 0071];
creating at least one verifier configured to communicate between the plurality of auxiliary APIs associated with the client device(initiate step-up authentication security request) [page 5, paragraph 0058]; and
accessing the plurality of auxiliary APIs associated with the client device via the at least one verifier(determine if user has satisfied security requests) [page 3, paragraphs 0034-0035 | page 5, paragraphs 0059-0060].
Claim 2: Badhwar et al. discloses the method of claim 1, wherein the auxiliary APIs associated with the client device comprise a social media platform [page 9, paragraph 0120].
Claim 3: Badhwar et al. discloses the method of claim 1, wherein verifying registration comprises: identifying at least one verifier associated with a phone number associated with the client device; and transmitting a one-time password code to the client device(sending OTP to user via SMS or phone call) [page 5, paragraph 0058 | page 8, paragraph 0109].
Claim 4: Badhwar et al. discloses the method of claim 3, wherein the one-time password (OTP) code comprises a short message service message (SMS) [page 8, paragraph 0109].
Claim 5: Badhwar et al. discloses the method of claim 1, further comprising determining a preexisting verifier for the client device [page 8, paragraphs 0107-0109].
Claim 8: Badhwar et al. discloses the method of claim 1, wherein the at least one verifier comprises a plurality of verifiers, each verifier configured to communicate with a different API(different actions would have different step-up authentication methods depending on the determined risk) [pages 4-5, paragraphs 0053-0055 & 0058 & 0060].
Claim 9: Badhwar et al. discloses the method of claim 1, wherein the at least one verifier comprises a primary verifier and a secondary verifier, wherein the primary verifier is configured to communicate with a first social media platform and the secondary verifier is configured to communicate with a second social media platform(different actions on different sites having different risk assessments and require different authenticators) [pages 4-5, paragraphs 0053-0055 & 0058 & 0060 | page 9, paragraph 0120].
Claim 10: Badhwar et al. discloses the method of claim 1, wherein the verifier is associated with a specific user account [page 8, paragraph 0108].
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 6, 7, 11-17 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Badhwar et al. (2021/0194883) in view of Chauhan et al. (2021/0126910).
Claim 6: Badhwar et al. discloses the method of claim 5, and further suggests determining that the preexisting verifier has exceeded a time-based registration expiration value [page 8, paragraphs 0107-0109], but does not explicitly disclose further comprising determining that the preexisting verifier has exceeded a registration threshold.
However, Chauhan et al. discloses a similar invention [page 1, paragraphs 0010-0012] and further discloses further comprising determining that the preexisting verifier has exceeded a registration threshold(check whether or not token is expired) [page 8, paragraph 0077].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify the disclosure of Badhwar et al. with the additional features of Chauhan et al., in order to rendering the verifier unusable/expired if one stores it for too long and attempts to use it later, as suggested by Chauhan et al. [page 6, paragraph 0055].
Claim 7: Badhwar et al. and Chauhan et al. disclose the method of claim 6, and Chauhan et al. further discloses wherein the registration threshold is at least 30 days(the set expiration period can reasonably encompass any desired value) [page 7, paragraph 0071] [Badhwar et al.: page 8, paragraphs 0107-0109].
Claim 11: Badhwar et al. discloses a system configured for multi-application registration and verification, the system comprising:
one or more hardware processors configured by machine-readable instructions to:
identify a gateway application programming interface (API) on a client device, wherein the gateway API is configured to communicate with a plurality of auxiliary APIs associated with the client device [page 2, paragraph 0021];
register the client device via the gateway API [pages 2-3, paragraph 0025];
verify registration of the client device [page 6, paragraph 0071];
determine a preexisting verifier for the client device [page 5, paragraph 0058];
determining that the preexisting verifier has exceeded a time-based registration expiration value [page 8, paragraphs 0107-0109]; and
create at least one verifier configured to communicate between a plurality of auxiliary APIs [page 5, paragraph 0058];
but does not explicitly disclose determine that the preexisting verifier has exceeded a registration threshold.
However, Chauhan et al. discloses a similar invention [page 1, paragraphs 0010-0012] and further discloses determine that the preexisting verifier has exceeded a registration threshold [page 8, paragraph 0077].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify the disclosure of Badhwar et al. with the additional features of Chauhan et al., in order to rendering the verifier unusable/expired if one stores it for too long and attempts to use it later, as suggested by Chauhan et al. [page 6, paragraph 0055].
Claim 12: Badhwar et al. and Chauhan et al. disclose the system of claim 11, and Badhwar et al. further discloses wherein verifying registration comprises comparing a received OTP code to a stored OTP code associated with the client device [page 5, paragraph 0058 | page 8, paragraph 0109].
Claim 13: Badhwar et al. and Chauhan et al. disclose the system of claim 11, and Badhwar et al. further discloses wherein verifying registration comprises verifying a digital signature associated with the client device [page 8, paragraphs 0105-0106].
Claim 14: Badhwar et al. and Chauhan et al. disclose the system of claim 11, and Badhwar et al. further discloses wherein the at least one verifier is selected based on a geographic location of the client device [page 4, paragraphs 0050-0051 | page 6, paragraph 0079].
Claim 15: Badhwar et al. and Chauhan et al. disclose the system of claim 11, and Badhwar et al. further discloses wherein the at least one verifier is selected based on a language setting of the client device [page 4, paragraphs 0050-0051 | page 6, paragraph 0070].
Claim 16: Badhwar et al. and Chauhan et al. disclose the system of claim 11, and Badhwar et al. further discloses wherein verifying registration further comprises verifying a user's identity via biometric authentication [page 8, paragraphs 0108-0111].
Claim 17: Badhwar et al. and Chauhan et al. disclose the system of claim 11, and Badhwar et al. further discloses wherein the verifier is communicated with a third-party authentication service [page 4, paragraph 0046].
Claim 19: Badhwar et al. and Chauhan et al. disclose the system of claim 11, and Badhwar et al. further discloses wherein the at least one verifier is selected based on a user's preference for a specific auxiliary API, wherein the auxiliary API comprises a social media platform [page 9, paragraph 0120].
Claim(s) 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Badhwar et al. (2021/0194883) in view of Chauhan et al. (2021/0126910) and further in view of Subramanian et al. (2018/0075231).
Claim 18: Badhwar et al. and Chauhan et al. disclose the system of claim 11, but neither explicitly disclose wherein the at least one verifier is selected based on a user's consent for multi-app auto-confirmation.
However, Subramanian et al. discloses a similar invention [page 1, paragraph 0004] and further discloses wherein the at least one verifier is selected based on a user's consent for multi-app auto-confirmation(login preferences for SSO microservice) [page 25, paragraphs 0370-0372].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further modify the disclosures of Badhwar et al. and Chauhan et al. with the additional features of Subramanian et al., in order to provide secure access to cloud-based and/or remotely located applications regardless of the device type and/or user type accessing the applications, as suggested by Subramanian et al. [page 1, paragraph 0003].
Allowable Subject Matter
Claim 20 is allowed over the prior art of record.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Moore (2023/0129466).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDWARD ZEE whose telephone number is (571)270-1686. The examiner can normally be reached Monday-Friday 9AM-5PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EDWARD ZEE/Primary Examiner, Art Unit 2435