Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
DETAILED ACTION
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 11/22/2023 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim(s) 1, 9 and 10 are rejected under 35 U.S.C. 102(a)(1)/(a)(2) as being anticipated by US 20140230020 A1 to Mogaki
Claim 1
Mogaki teaches an information processing system [e.g. Mogaki; Fig. 1-2, Para. 0057-0062 – Mogaki discloses a server cooperative system including external service system (hereinafter “ESS”) 103 (client), access management service system (hereinafter “AMSS”) 104 (authentication server) and form service system (hereinafter “FSS”) 105 (service). ] comprising:
one or more processors [e.g. Mogaki; Fig. 2 CPU 203, Para. 0061-0066] configured to:
receive a request for issuance of an access token to be used when a service is used; [e.g. Mogaki; Para. 0090-0093, 0101, 0102 – Mogaki discloses AMSS 104 receives an access token request as an issuance request (e.g. request for issuance of an access token), the access token being required for ESS 103 to use FSS 105 (e.g. access token to be used when a service is used). ]
provide an instruction for issuance of the access token and a refresh token to be used to, when a validity period of the access token has expired, refresh the access token; [e.g. Mogaki; Para. 0043, 0044, 0101, 0105-0107 – Mogaki discloses ESS 103 transmits an access token request as an issuance request (e.g. instructions for issuance), in response to which AMSS 104 generates access token information (e.g. access token) and update authorization information identified as a refresh token where the refresh token is information used to issue a new access token without renewed user authorization after the access token validity period expires. ]
acquire the access token and the refresh token issued in response to the instruction; [e.g. Mogaki; Para. 0105-0109 – Mogaki discloses AMSS 104 returns the generated access token and refresh token to ESS 103 and token manager 305 stores the received access token in access token ID 602 and the received refresh token in refresh token ID 603 (e.g. acquire access and refresh token in response to the request). ]
refresh the access token, using the refresh token, based on a predetermined refresh condition; [e.g. Mogaki; Para. 0122-0128, 0133-0137 – Mogaki discloses AMSS 104 determining access token in invalid because its valid date and time has elapsed (e.g. predetermined refresh condition) ESS 103 passes refresh token in a refresh processing request, AMSS 104 validates the refresh token and generates and returns a new access token and refresh token (e.g. refreshes the access token using the refresh token) ] and
discard the refresh token, based on a predetermined condition on discarding. [e.g. Mogaki; Para. 0134, 0139-0141, 0144-0147, 0150 – Mogaki discloses AMSS 104 determines that a refresh token is invalid when its valid period has expired or when the token was invalidated after prior refresh processing (e.g. predetermined condition on discarding) and in response to the refresh token invalid response and invalidation processing ESS 103 deletes the refresh token ID 603 and client authorization information containing the invalidated refresh token from authorization information management table 600 (e.g. discards refresh token)]
Regarding claims 9 and 10 they are method and manufacture claims essentially corresponding to the above recitations, and they are rejected, at least, for the same reasons.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2 and 3 are rejected under 35 U.S.C. 103 as being unpatentable over US 20140230020 A1 to Mogaki in view of US 20230162226 to Lieginger et al. (hereinafter “Lieginger”)
Claim 2:
While Mogaki teaches the information processing system according to claim 1, and teaches issuance and storage of access and refresh tokens where the access token refreshed using the refresh token and deleting (e.g. discarding) a refresh token under a predetermined invalidity condition in order to prevent illicit refresh processing and continued unauthorized use of the corresponding service (see Para. 0150-0152, 0159 of Mogaki) Mogaki fails to teach using a period of service inactivity as the condition for discarding the refresh token.
However, Lieginger teaches: “wherein the predetermined condition on discarding includes lapse of a certain period of time without the service being used by a user of the service” [e.g. Lieginger; Para. 0134-0136, 0143-0146 – Lieginger discloses authentication service issuing a refresh token usable to obtain new session and access tokens, tokens authenticating certain service endpoints are limited a predetermined inactivity period and may remain valid while the user is actively using the application and when an endpoints determines that the inactivity timeout has expired the refresh and/or all tokens are revoked.]
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to use Lieginger service inactivity determination as the conditional or additional trigger for Mogaki’s refresh token deletion in order to prevent a retained refresh token from restoring authenticated service access after a user has been inactive for that service for a period of time further enhancing the prevention of illicit refresh processing and continued unauthorized use of corresponding services of Mogaki.
Claim 3:
Mogaki as modified by Lieginger teaches the information processing system according to claim 2, wherein the certain period of time is set according to a type of the service to be used. [e.g. Lieginger; Para. 0131-0136,– Lieginger discloses the system applying different security protocols according to the type and sensitivity of the service data and distinguishing between ordinary L0/L1 API services where the refresh token may remain valid for years and L2 API services where the tokens are limited to no more than a predetermined period of inactivity.]
Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over US 20140230020 A1 to Mogaki in view of US 20230162226 to Lieginger et al. (hereinafter “Lieginger”) and further in view of US 9876859 to Plummer et al. (hereinafter “Plummer”)
Claim 4:
While Mogaki and Lieginger teaches the information processing system according to claim2, and teaches discarding the refresh token after a predetermined period without service use the combination do not teach measuring that period as elapsed time from the last date and time at which the service was used
However, Plummer teaches: “wherein the certain period of time is an elapsed time since a last date and time at which the service is used by the user of the service” [e.g. Plummer; Col 5 Ln 7-34, Col 5 Ln 55 – Col 6 Ln 65, Col 7 Ln 8 – Col 8 Ln 55 – Plummer discloses a client storing a timestamp identifying the last detected user activity on the service session (e.g. last date and time at which the service was used) and the server determines whether the difference between a later request time and the last user active time exceeds the predetermined timeout (e.g. elapsed time since the last service used).]
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to determine Lieginger inactivity period using Plummer’s last user active timestamp in order prevent clients from remaining in a vulnerable state as disclosed Col 4 Ln 66-67 of Plummer.
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over US 20140230020 A1 to Mogaki in view of US 9876859 to Plummer et al. (hereinafter “Plummer”)
While Mogaki teaches the information processing system according to claim 1, and teaches storing and deleting refresh token information under predetermined conditions, Mogaki does not teach periodically determining, based on the use status of the service, whether a service inactivity condition for discarding the refresh token is satisfied.
However, Plummer teaches: “wherein the one or more processors are configured to determine, every predetermined period of time, the condition on discarding, based on a use status of the service by the user of the service” [e.g. Plummer; Col 3 Ln 8-29, Col 4 Ln 1 - Col 6 Ln 65, Col 13 Ln 56 – Col 14 Ln 32 – Plummer discloses a recurring session timer cause the server to periodically determine whether the authenticated service session remains active (e.g. every predetermined period of time) the determination being based on timestamps identifying the user actual activity in the service session as opposed to automatically generated refresh request (e.g. use status of the service) and the server terminates the authenticated session when the measured inactivity exceeds the timeout (e.g. determining whether the service inactivity condition is satisfied).]
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to use Plummer’s periodic actual user activity determination in Mogaki refresh token management inactivity period in order prevent clients from remaining in a vulnerable state as disclosed Col 4 Ln 66-67 of Plummer.
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over US 20140230020 A1 to Mogaki in view of US 9876859 to Plummer et al. (hereinafter “Plummer”) and further in view of US 10051019 to Jasso et al. (hereinafter “Jasso”)
While Mogaki and Plummer teaches the information processing system according to claim 5, and teaches periodically determining whether actual service inactivity satisfies the refresh token discard condition the combination do not teach determining that the discard condition is not satisfied when either one of two associated services is used.
However, Jasso teaches: “wherein the one or more processors are configured to, in a case where the user of the service uses at least one of a first service and a second service that is associated with the first service, determine that the condition on discarding is not satisfied” [e.g. Jasso; Col 2 Ln 51 – Col 4 Ln 54– Jasso discloses client applications providing access to different services such as deposit, transfer, financial management (e.g. first and second services) and that the application sessions are associated through a common portal and single-sign on arrangement (e.g. associated services) in which activity in any one application causes each associated session to remain active despite inactivity in the other application (e.g. use of either associated service causes the shared inactivity condition remain not satisfied.).]
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to apply Jasso’s collective activity determination to the service use determination from the combination of Mogaki and Plummer and in order to provide a user with a more consistent experience across service as disclosed Col 7 Ln 40-41 of Jasso ensure continued authorized use of service.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over US 20140230020 A1 to Mogaki in view of US 9876859 to Plummer et al. (hereinafter “Plummer”) and further in view of US 20030126441 to Laux et al. (hereinafter “Laux”)
While Mogaki and Plummer teaches the information processing system according to claim 5, and teaches periodically determining whether actual service inactivity satisfies the refresh token discard condition as well as associating multiple user sessions with a common SSO session and determining that the common inactivity condition is not satisfied when at least one associated user session remains active (See Para. 0119-0022 and 0040-0055 of Plummer) the combination do not teach the associated service provides access to a plurality of services based on the same access token.
However, Laux teaches: “a plurality of services that are able to be used using a same access token” [e.g. Laux; Abstract, Para. 0014-0019, 0031-0033, 0044, 0049-0052, 0064-0068 – Laux related services 226, 228 and 230 are associated with a common session and security token and that client 202 uses the same security token to access each of the related services.]
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to apply Laux use of a same access token for providing access across a plurality of services to the combination of Mogaki and Plummer in order to eliminated multiple log-ins for multiple uses of a plurality of services thereby increasing speed, efficiency and reducing time and effort as disclosed in the abstract of Laux.
Thus the combination would enable
wherein the one or more processors are configured to, in a case where the user of the service uses at least one of a plurality of services that are able to be used using a same access token, determine that the condition on discarding is not satisfied. [e.g. Laux; Abstract, Para. 0014-0019, 0031-0033, 0044, 0049-0052, 0064-0068 – Laux related services 226, 228 and 230 are associated with a common session and security token and that client 202 uses the same security token to access each of the related services; Plummer 0019-0022, 0040-0055 – Plummer discloses activity in at least one user session associated with the common SSO session causes all associated sessions to remain active (e.g. use of at least one of the plurality of services causes the common discard condition to not be satisfied.)]
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over US 20140230020 A1 to Mogaki in view of US 9876859 to Plummer et al. (hereinafter “Plummer”) and further in view of US 20200358856 to Guerra et al. (hereinafter “Guerra”)
While Mogaki and Plummer teaches the information processing system according to claim 5, and teaches periodically determining whether actual service inactivity satisfies the refresh token discard condition the combination do not teach overriding the inactivity determination for a first apparatus based on service use at a specifically related second apparatus.
However, Guerra teaches: “wherein the one or more processors are configured to, even in a case where it is determined that the condition on discarding is satisfied for a first information processing apparatus among a plurality of information processing apparatuses that are in a specific relationship, when a service is used on a second information processing apparatus among the plurality of information processing apparatuses that are in the specific relationship, determine that the condition on discarding is not satisfied” [e.g. Guerra; Para. 0014-0021 – Guerra discloses that the same user is authenticated in to a protected web application on a primary computing device and a communicatively linked protected mobile application on a secondary mobile computing device (e.g. first and second information processing apparatuses in a specific relationship) and that a timeout condition may arise for the primary device session (e.g. condition satisfied for the first apparatus) and may be overridden and renewed and not terminated when user interaction on the secondary device shows that the linked mobile session remains active (e.g. service use on the second apparatus cause the inactivity condition for the first apparatus to be determined not satisfied)]
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to apply Guerra’s cross device activity determination as the service use determination in the combination of Mogaki and Plummer in order to improve the user experience of maintaining a protected session (see Guerra Para. 0005) without the need to reauthenticate prematurely.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER C HARRIS whose telephone number is (571)270-7841. The examiner can normally be reached Monday through Friday between 8:00 AM to 4:00 PM CST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached on (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHRISTOPHER C HARRIS/Primary Examiner, Art Unit 2432