Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This Office Action is in response to the communication and claim amendment
filed on 06/05/2026; Claims 1, 9, and 17 have been amended; Claims 1, 9, and 17 are independent claims. Claims 1-20 have been examined and are pending. This Action is made FINAL.
Response to Arguments
Applicants’ arguments in the instant Amendment, filed on 06/05/2026, with respect to claims 1-20 have been fully considered but are not persuasive.
A. Applicant argues that Ulewicz and West do not disclose or suggest "wherein the server authenticates the computing device in a later authentication process based on a comparison of the corresponding hash of the plurality of hashes and (f1) the one or more hashes previously generated by the computing device for the set of authenticated regions and (f2) previously registered by the computing device with the server as hashed authentication regions." (Remarks, pp. 8–12).
The Examiner respectfully disagrees.
Ulewicz teaches the server-side comparison against previously stored region hashes (par. 0084, "storing or updating the encrypted geospatial index at a data store according to the geofence identifier, at 704"; par. 0097, "determining whether the encrypted device location identifier is included in the encrypted geospatial index, at 908"), where what is stored is the hashed form of the regions (par. 0078; par. 0035).
West teaches the recited actor and temporal relationships: registration performed by the same device (par. 0016, "the registration is being performed via the mobile device"; par. 0013; par. 0017), and later authentication of that same device against that registration (par. 0025, "when the user subsequently attempts to access a secure network resource that requires authentication"; par. 0032, "perform authentication on the user and the mobile device based on a previous registration").
The combination of Ulewicz and West as a whole teaches the argued limitations.
B. Applicant argues that Ulewicz is directed to privacy-preserving geofence determination and does not disclose "the presently claimed authentication framework," even accepting that Ulewicz involves "some form of comparison." (Remarks, p. 10).
The Examiner respectfully disagrees.
Ulewicz was not relied upon for the authentication framework. As stated in the rejection, West supplies the authentication context (par. 0023, "automatic authentication performed on behalf of the user and the mobile device with respect to the secure network resource when the mobile device is within the predefined range of the registered geographical location"; par. 0035, "establishes an authenticated session"). One cannot show nonobviousness by attacking references individually where the rejection is based on a combination. In re Keller, 642 F.2d 413, 426 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 1097 (Fed. Cir. 1986); MPEP 2145(IV).
C. Applicant argues the distinction is "substantive, not semantic" because the claims are directed to a "device-authentication workflow" rather than geofence determination, citing specification paragraphs 0011, 0012, and 0033. (Remarks, p. 10).
The Examiner respectfully disagrees.
The terms "authentication framework," "device-authentication workflow," and "privacy-preserving hash architecture" appear nowhere in claim 1. Claim 1 recites a comparison of hashes and an indication of the result. Limitations from the specification are not read into the claims. In re Van Geuns, 988 F.2d 1181, 1184 (Fed. Cir. 1993); MPEP 2111.01(II). Applicant's arguments are therefore not commensurate in scope with the claims as recited.
D. Applicant argues that West does not cure Ulewicz because West does not disclose "the claimed privacy-preserving hash architecture," and that "at most, WEST is directed to using location as a factor in authentication." (Remarks, pp. 10–11).
The Examiner respectfully disagrees.
West was not relied upon for the hash architecture; Ulewicz supplies the keyed hashing, the region quantization, and the server's inability to recover location (par. 0047, "The geofence service 130 may be configured to be unaware of the current location of the end user devices 120 by not being provided the cryptographic keys or the secret keys 118, 128"). West is relied upon solely for the recited single-device registration and later authentication. This is again an individual attack on the references. In re Keller, supra.
Further, Applicant does not dispute the articulated reason to combine, the reasonable expectation of success, or that the references are analogous art. Ulewicz's end user device 120 already possesses the same hash function and may hold the same secret key as client 110 (par. 0043, "the secret key 128 may be the same as the secret key 118"; par. 0089), such that the modification requires no new capability.
For the reasons above, the combination of Ulewicz and West as a whole teaches each limitation argued. Applicant's arguments directed to the additional references (Remarks, p. 12) are predicated solely on the alleged deficiencies of Ulewicz and are not persuasive for the same reasons.
The rejections are maintained.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3-4, 9, 11-12, 16-17, and 19 are under 35 U.S.C. 103 as being unpatentable over Ulewicz (“Ulewicz,” US 2023/0069458, published on Mar. 2, 2023), in view of West (“West,” US 2014/0031011, publishes on Jan. 30, 2014).
Regarding claim 1, Ulewicz a method for obscured location verification, the method comprising:
(a) generating, by a computing device, one or more hashes for a set of authenticated regions (Ulewics: par. 0078: "generating an encrypted geospatial index of the one or more locations based on applying a hash function to the one or more numerical representations"; par. 0030)), wherein the one or more hashes are generated using a key associated with the computing device (Ulewics: par. 0043, The secret key 128 may be private to the client 120 such that the secret key 128 is known only by the client 120 or entities granted access by the client 120, such the end user devices 120 [] the secret key 128 may be the same as the secret key 118 to maintain consistency between the format, encoding, or encryption of the encrypted geospatial index 119 and the encrypted device location identifier 129; par. 0089, the secret key used by the user device is the same as the secret key used by the client device such that the same secret key is shared by the user device and the client device; par. 0078, generating an encrypted geospatial index of the one or more locations based on applying a hash function to the one or more numerical representations of the one or more locations according to a secret key, at 606), and wherein the one or more hashes are provided to a server as part of a region registration process (Ulewicz: par. 0028, The client 110 may establish one or more geofence locations 112"; par. 0035, The client 110 may send a request to establish a geofence with the geofence service 130 [] the client 110 may send the encrypted geofence locations in addition to the encrypted geospatial index 119 as part of the request to establish the geofence; par. 0019, The geofence service may receive the encrypted identifiers and store the encrypted identifiers to a data store or a database for the geofence of the client; par. 0082, par. 0084, storing or updating the encrypted geospatial index at a data store according to the geofence identifier; par. 0019,.. The geofence service may then determine whether another device is located within the geofence based on querying the database.);
(b) obtaining, by the computing device, location information associated with the computing device ((Ulewicz: fig. 8, step 802 "Determine a current location of a user device according to a location sensor of the user device"; par. 0087, determining a current location of a user device according to a location sensor of the user device, at 802. The location sensor may correspond to the location sensor 122 of FIG. 1, according to some embodiments. The location sensor may include GPS hardware configured to determine the current location);
(c) generating, by the computing device, a hash of region data (Ulewicz: fig. 8, step 806, "Generate one or more hashed representations of the current location based on applying a hash function to the one or more numerical representations of the current location according to a secret key"; par. 0089) for each of a plurality of regions associated with the location information (Ulewicz : fig. 8, step 804, "Determine one or more numerical representations of the current location of the user device, individual ones of the one or more numerical representations have different levels of precision of location tracking"; par. 0088, determining one or more numerical representations of the current location of the user device, individual ones of the one or more numerical representations have different levels of precision of location tracking, at 804. The one or more numerical representations may correspond to the cells 402 of FIG. 4, according to some embodiments. The user device may be configured to perform conversion operations to transform the current location to one or more cells according to a geospatial indexing algorithm , according to some embodiments. The cells may be expressed as numerical values of varying levels of precision, such as zoom levels per cell.) using the key to produce a plurality of hashes (Ulewicz: fig. 8, step 806, "Generate one or more hashed representations of the current location based on applying a hash function to the one or more numerical representations of the current location according to a secret key"; par. 0043, par. 0089, …The hash function may output hash values for the numerical representations that are one-directional in nature, such that the hash values cannot be converted back to the numerical representations of the geofence locations, according to some embodiments. For example, the hash values may be encoded to obfuscate or encrypt the information that would otherwise identify the geofence locations to the geofence service.);
(d) sending, by the computing device, the plurality of hashes to the server (Ulewicz; fig. 8, step 812, "Send the one or more hashed representations [ ... ] to a geofence service"; par. 0092, sending the one or more hashed representations and the encrypted the encrypted device location identifier and the encrypted representation of the current location to a geofence service to allow the geofence service to determine whether the user device is within a geofence, at 812. In some embodiments, the user device may send the encrypted device location identifier and the encrypted representation of the current location to the geofence service via a network connection; See also par. 0088: "determining one or more numerical representations of the current location of the user device, individual ones of the one or more numerical representations have different levels of precision of location tracking"; par. 0089: "generating an encrypted device location identifier for the current location based on applying a hash function to the one or more numerical representations of the current location according to a secret key” par. 0042: "the hashed representation of the current location may include a plurality of hash values that represent a hierarchical structure...different levels of precision"; par. 0059: "The cells 402 may represent different resolutions of cells corresponding to different degrees of precision in identifying the current location"); and
(e) receiving, by the computing device (Ulewicz; fig 9. Step 910, "Send a notification to an event bus"; par 64 "The event bus service 520 may be configured to receive indications of events [ ... ] to interface with other services and external clients such as [ ... ] user devices"), authentication information from the server (Ulewicz; fig. step 910, "a notification [ ... ] indicating that the current location of the user device is within the one or more locations of the geofence", par. 0098; par. 0093, fig. 9, Illustrates[ ... ] a method 900 [ ... ] The method 900 may be performed by a geofence service " ), authentication information from the server indicative of whether one or more of the plurality of regions is authenticated based upon a corresponding hash from the plurality of hashes (Ulewicz:par. 0098, Fig. 9 step 910: "sending a notification to an event bus indicating that the current location of the user device is within the one or more locations of the geofence"; par. 0099: "sending a notification to the event bus indicating that the current location of the user device is not within the one or more locations of the geofence"; par. 0064: "The event bus service 520 may be configured to receive indications of events from the various services throughout the provider network 500 to interface with other services and external clients such as clients 550 and user devices 552"; par. 0050: "the geofence service 130 may indicate to an event bus 160 whether the end user device 120 is located within the geofence locations 112...The event bus 160 may be configured to send an indication as to whether the end user device 120 is located within the geofence locations 112 to the client 110"; par. 0023: "based on a determination that the user device is located in the location of the plurality of locations, provide an indication that the user device is located in the location of the plurality of locations".),
(f) wherein the server authenticates the computing device [[in a later authentication process ]] based on a comparison of the corresponding hash of the plurality of hashes and (f1) the one or more hashes [[previously]] generated [[by the computing device]] for the set of authenticated regions (Ulewicz: par. 0023: "The geofence service may receive an encrypted geospatial index for a specified geofence comprising a geofence location hash value generated based on application of a hash function to respective ones of a plurality of locations for the specified geofence...determine whether the user device is located in a location of the plurality of locations based on a query of the encrypted geospatial index according to the encrypted device location identifier"; par. 0031, "the hashed representation of the geofence locations 112 may include a plurality of hash values that represent a hierarchical structure"; Par. 0078: "generating an encrypted geospatial index of the one or more locations based on applying a hash function to the one or more numerical representations"; par. 0046: "the geofence logic 132 may determine whether the end user device 120 is currently located within one or more of the geofence locations 112 based on querying the geofence database 142 according to the encrypted device location identifier"; par. 0047: "The geofence logic 132 may be configured to determine whether there is a match or an inclusion of the encrypted device location identifier 129 within the encrypted geospatial index 146"; par. 0048: "the geofence logic 132 may implement a query of the encrypted geospatial index 146 according to the encrypted device location identifier 129...determine whether hash values of the encrypted device location identifier 129 are included within the encrypted geospatial index 146"; par. 0049: "If the encrypted geospatial index 146 for the specified geofence includes at least a portion of the encrypted device location identifier...then the geofence logic 132 may determine that the end user device 120 is within one or more of the geofence locations 112"; pars. 0096-0097, Fig. 9 steps 906-908: "querying the encrypted geospatial index according to the encrypted device location identifier...determining whether the encrypted device location identifier is included in the encrypted geospatial index; See also, par. 0019, The geofence service may receive the encrypted identifiers and store the encrypted identifiers to a data store or a database for the geofence of the client; par. 0084, storing or updating the encrypted geospatial index at a data store according to the geofence identifier.) [[ and (f2) previously registered by the computing device with the server as hashed authentication regions.]]
Ulewicz teaches “(a) generating, by a computing device, one or more hashes for a set of authenticated regions, … the one or more hashes are provided to a server as part of a region registration process;” (i.e. registration process) is performed by client 110, while “(b) obtaining, by the computing device, location information associated with the computing device;” “( c) generating, by the computing device, a hash of region data for each of a plurality of regions ..;” ;”(d) sending, by the computing device, the plurality of hashes to the server;” and “(e ) receiving, by the computing device, authentication information from the server … corresponding hash from the plurality of hashes,” .(i.e. subsequent location-based authentication process with server) is performed by the end user device 120.
Ulewicz does not explicitly teach that a single computing device both generates and registers the hashes for the set of authenticated regions with the server and thereafter, in a later authentication process, is authenticated by that same server based on a comparison against those previously registered hashes.
However, in an analogous art, West teaches the concept that a single computing device both generates and registers geographic location information with a server and thereafter, in a later authentication process, is authenticated by that same server based on its current location as compared against that previous registration (West: par. 0012, “at 110, The location-based authentication manager "registers a mobile device for location-based authentication services."; par. 0013, at 111 "the location-based authentication manager interacts with a user via an application that processes on the mobile device. So, the mobile device being registered with the location-based authentication manager is used to interact with the location-based authentication manager for registration."; par. 0015. As part of registration, the location-based authentication manager "associates or links together: a geographical location for the mobile device, an identifier for the mobile device, an identity for the user, and an authentication policy."; pars. 0015-0018; par. 0021, “the location-based authentication manager defines the authentication policy as actions to take when the mobile device is within a predefined range of the registered geographical location for the mobile device [...]”; par. 0022, As used herein, 'geofence' refers to a known or registered geographical location around or within proximity to geographical coordinates; par. 0025, "the location-based authentication manager enforces the registered authentication policy when the user subsequently attempts to access a secure network resource that requires authentication. This is done on behalf of the user and the mobile device and is based on the geographical location of the mobile device when the attempt is made by the user to access the secure network resource."; par. 0026, "the location-based authentication manager automatically provides registered credentials to the secure network resource on behalf of the user in order to automatically authenticate the user for access to the secure network resource based on dynamic evaluation of the authentication policy and a dynamically resolved current geographical location of the mobile device."; Abstract, "A user pre-registers a mobile device and a geographical location with a location-based authentication service. When the user attempts to access a target resource from the mobile device, a current location for the mobile device is resolved and communicated to the location-based authentication service.").
More specifically, West teaches the temporal and actor relationships recited in limitations:
(i) "in a later authentication process" (West: par. 0025, "the location-based authentication manager enforces the registered authentication policy when the user subsequently attempts to access a secure network resource that requires authentication. This is done on behalf of the user and the mobile device and is based on the geographical location of the mobile device when the attempt is made by the user to access the secure network resource"; par. 0032, "The location-based authentication manager uses the current geographical location of the mobile device to perform authentication on the user and the mobile device based on a previous registration having a registered authentication policy"; par. 0035, "the location authenticator establishes an authenticated session between the secure network resource and the user, via the mobile device.")
(ii) "the one or more hashes previously generated by the computing device for the set of authenticated regions" (West: par. 0016, "the location-based authentication manager automatically acquires the geographical location of the mobile device from an existing geographical location detected for the mobile device during registration. In other words, the registration is being performed via the mobile device and an interface option permits the geographical location to register to be automatically detected based on the current and existing geographical location of the mobile device"; par. 0017, "the mobile device may be used to perform the registration." In combination with Ulewicz, the generating recited in (f1) is Ulewicz's generating step (Ulewicz: par. 0078, "generating an encrypted geospatial index of the one or more locations based on applying a hash function to the one or more numerical representations of the one or more locations according to a secret key, at 606"), performed by Ulewicz's end user device 120 rather than client 110 in view of West).
(iii) "previously registered by the computing device with the server as hashed authentication regions" (West: par. 0013, "the mobile device being registered with the location-based authentication manager is used to interact with the location-based authentication manager for registration"; par. 0016 (quoted above); par. 0017, "the mobile device may be used to perform the registration"; par. 0032, "based on a previous registration"; par. 0034, "the location authenticator also sends a mobile device identifier to the location-based authentication manager for the location-based authentication manager to look-up and locates a previous registration associated with that mobile device"; par. 0041, the manager is "configured to pre-register the mobile device and the user along with one or more pre-defined geographical locations (geofences) for the mobile device." In combination with Ulewicz, what is registered and stored is the hashed form of the regions (Ulewicz: par. 0035, "The client 110 may send a request to establish a geofence with the geofence service 130 via the network 150... The request to establish the geofence may include the encrypted geospatial index 119"; par. 0084, "storing or updating the encrypted geospatial index at a data store according to the geofence identifier, at 704"), i.e., hashed authentication regions).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of West to have modified the method and system of Ulewicz such that the end user device — rather than a separate client device — performs the registration of authenticated regions (generating hashes for geofence locations and providing them to the server), as taught by West. One of ordinary skill would have been motivated to make this modification for at least the following reasons:
(1) Ulewicz already equips the end user device 120 with all the cryptographic tools necessary to perform registration — specifically, the same hash function and the same secret key used by Client 110. Thus, the end user device is already technically capable of performing the registration step.
(2) West demonstrates that having a single device perform both registration and subsequent location-based authentication is a known design pattern in the art (West: pars. 0012-0015, 0025-0026), confirming that consolidating these functions onto a single device was a recognized approach.
(3) Consolidating the registration and authentication functions onto a single device would simplify system architecture by eliminating the need for a separate client system to perform registration, thereby reducing deployment complexity and allowing individual users to manage their own authenticated regions directly from their mobile device.
There would have been a reasonable expectation of success because Ulewicz's end user device 120 already possesses all the necessary components — the hash function, the secret key, and the geospatial indexing capability — to execute the registration process in addition to the authentication process. The modification merely involves having the same device execute both processes, which West confirms is a functional and effective architecture.
Regarding claim 3, the combination of Ulewicz and West teaches the method of claim 1. The combination of Ulewicz and West further discloses wherein the key is a device-specific key associated with the computing device location (Ulewciz: par. 0089, based on applying a hash function to the one or more numerical representations of the current location according to a secret key; par. 0092, the user device may send the encrypted device location identifier and the encrypted representation of the current location to the geofence service via a network connection; par. 0043, the secret key 128 may be private to the client 120; par. 0078).
Regarding claim 4, the combination of Ulewicz and West teaches the method of claim 1. The combination of Ulewicz and West further discloses, wherein the region data for each of the plurality of regions comprises a region size of each of the associated regions (Ulewicz: par. 0052, the geofence 210 is a different size and shape from the geofence 212. The different size and shape may be different levels of precision of geofenced locations in order to focus in on particular locations; par. 0088, the one or more numerical representations may correspond to the cells 402 of FIG. 4, according to some embodiments. The user device may be configured to perform conversion operations to transform the current location to one or more cells according to a geospatial indexing algorithm …; fig. 4, par. 0059 The cells 402 may be generated from a geometric representation of the current location; par. 0052).
Regarding claim 9, claim 9 is directed to an apparatus for obscured location verification, the apparatus comprising a computer processor (Ulewicz: pars. 0106,0107), a computer memory (Ulewicz: pars. 0106,0107), operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to associated with the method claimed in claim 1; claim 9 is similar in scope to claim 1, and is therefore rejected under similar rationale.
Regarding claim 11, claim 11 is similar in scope to claim 3, and is therefore rejected under similar rationale.
Regarding claim 12, claim 12 is similar in scope to claim 4, and is therefore rejected under similar rationale.
Regarding claim 16, the combination of Ulewicz and West teaches the method of claim 9. The combination of Ulewicz and West further discloses, wherein the server is configured to authenticate the computing device based upon a comparison of the corresponding hash for each of the plurality of regions to one or more hashes associated with a set of authenticated regions (Ulewicz: par. 0023, The geofence service may further receive an encrypted device location identifier comprising a hash value generated based on application of the hash function to a representation of a current location of a user device in accordance with the secret key; determine whether the user device is located in a location of the plurality of locations based on a query of the encrypted geospatial index according to the encrypted device location identifier. The geofence service may further based on a determination that the user device is located in the location of the plurality of locations, provide an indication that the user device is located in the location of the plurality of locations; par. 0093, determining whether a user device is in a geofence location based on an encrypted device location identifier..; pars. 0096-0097, querying the encrypted geospatial index according to the encrypted device location identifier, at 906..; fig. 9, (908) ; par. 0088-0089, individual ones of the one or more numerical representations have different levels of precision of location …The hash function may output hash values; par. 0019, The geofence service may receive the encrypted identifiers and store the encrypted identifiers to a data store or a database for the geofence of the client; par. 0084, storing or updating the encrypted geospatial index at a data store according to the geofence identifier).
Regarding claim 17, claim 17 is directed to a computer program product for obscured location verification, the computer program product disposed upon a computer readable storage device, the computer program product comprising computer program instructions that, when executed, cause a computer to associated with the method claimed in claim 17; claim 17 is similar in scope to claim 1, and is therefore rejected under similar rationale.
Regarding claim 19, claim 19 is similar in scope to claim 3, and is therefore rejected under similar rationale.
Claims 2, 10, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Ulewicz (“Ulewicz,” US 2023/0069458, published on Mar. 2, 2023), in view of West (“West,” US 2014/0031011, publishes on Jan. 30, 2014), further in view of Arunkumar et al. (“Arunkumar,” US 9,473,511, published on Oct. 18, 2016).
Regarding claim 2, the combination of Ulewicz and West teaches the method of claim 1. The combination of Ulewicz and West further teaches generating, by the computing device, a hash of region data for each of a plurality of regions associated with the location information using a key associated with the computing device to produce a plurality of hashes. Ulewicz and West do not explicitly teach “wherein the key comprises a passphrase received from a user of the computing device, and wherein the hash region of data for each of the plurality of regions is generated using passphrase.”
However, in an analogous art, Arunkumar teaches wherein the key comprises a -9passphrase received from a user of the computing device (Arunkumar: Col. 3, lines 33-49, policy program 120 receives a username and password provided by a client device ( e.g., client device 104) or some other authentication method 35 known by one skilled in the art, which verifies that the specific identification is the actual user or machine that is trying to access the secure connection. …).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Arunkumar with the method and system of Ulewicz and West to include “wherein the key comprises a passphrase received from a user of the computing device, and wherein the hash region of data for each of the plurality of regions is generated using passphrase.” One would have been motivated to recognize that using a user-supplied passphrase as the key for hashing region data is a known design choice to enhance user control security, and would substitute it for the static or device-based in Ulewicz without the need for inventive ingenuity.”
Regarding claim 10, claim 10 is similar in scope to claim 2, and is therefore rejected under similar rationale.
Regarding claim 18, claim 18 is similar in scope to claim 2, and is therefore rejected under similar rationale.
Claims 5, 13, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Ulewicz (“Ulewicz,” US 2023/0069458, published on Mar. 2, 2023), in view of West (“West,” US 2014/0031011, publishes on Jan. 30, 2014), further in view of Rajadurai et al. (“Rajadurai,” US 2022/0116774, published on Apr. 14, 2022)
Regarding claim 5, the combination of Ulewicz and West teaches the method of claim 1. The combination of Ulewicz and West further teaches a method for obscured location verification using encrypted device location identifiers and hash geospatial indexes (Ulewicz: fig. 9, pars. 0093-0099). The combination of Ulewicz and West further teaches teaches sending authentication information via a notification system (Ulewicz: par. 0098, sending a notification to an event bus indicating that the current location of the user device is within the one or more locations of the geofence based on results of the query, where the notification includes the one or more encrypted representation, at 910). Ulewicz and West do not explicitly disclose establishing a session between the device and a server based on the authentication information.
However, in an analogous art, Rajadurai discloses establishing a session between the device and a serv er based on the authentication information (Rajadurai: par. 0041, provisioning required credentials and establish a secure session/connection between the UE and the server for accessing edge computing services, based on a successful authentication and authorization of the UE and the server).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Rajadurai with the method and system of Ulewicz and West to include establishing a session between the device and a server based on the authentication information. One would have been motivated to provide the method enables performing mutual authentication between the UE and the server using the PSK so as to establish a secure connection for the edge computing service (Rajadurai: pars. 0018, 0042).
Regarding claim 13, claim 13 is similar in scope to claim 5, and is therefore rejected under similar rationale.
Regarding claim 20, claim 20 is similar in scope to claim 5, and is therefore rejected under similar rationale.
Claims 6-7 and 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over Ulewicz (“Ulewicz,” US 2023/0069458, published on Mar. 2, 2023), in view of West (“West,” US 2014/0031011, publishes on Jan. 30, 2014), further in view of Delucas et al. (“Delucas,” US 2019/0164081, published on May 30, 2019).
Regarding claim 6, the combination of Ulewicz and West teaches the method of claim 1. Ulewicz and West do not explicitly teach, further comprising receiving an indication from the server of valid region sizes for the plurality of regions.
However, in an analogous art, Delucas further discloses comprising receiving an indication from the server of valid region sizes for the plurality of regions (Ulewicz: par. 0049, "manager system 110 can generate one or more additional candidate geofences having sizes based on the size of the specified nominally sized geofence, e.g. having one or more sizes incrementally larger and/or incrementally smaller. In one aspect, a purpose and function of the candidate geofences generated at predicting block 1107 can be to visualize performance of candidate geofences of different sizes."; par. 0066, manager system 110 can send geofence information to computer devices of user computer devices 130A-130Z for receipt by computer devices of user computer devices 130A-130Z at block 1304.").
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Delucas with the method and system of Ulewicz and West to include “receiving an indication from the server of valid region sizes for the plurality of regions.” One would have been motivated to provide the machine learning processes are performed for increased accuracy and for reduction of reliance on rules based criteria and thus reduced computational overhead. The potential network loading events are intelligently reduced by intelligent management of notifications to users. The distribution of geofence breach detection logic to user computer devices for local on-device breach detection improves computer network performance, e.g., in terms of bandwidth and power conservation, speed and reliability (Delucas; par 0072).
Regarding claim 7, the combination of Ulewicz, West, and Delucas teaches the method of claim 6. The combination of Ulewicz, West, and Delucas further discloses comprising receiving a selection of a region sizes from among the valid regions sizes for each of the plurality of regions from a user of the computing device (Delucas: par. [0052] discloses: "geofence configurator administrator user interface 600 can be configured so that a user can use pointer 620 to point and click onto the depicted perimeter, e.g. perimeter 602 or 603 and then drag inward or outward to change the size of the depicted perimeter representing a geofence. The user can point and click onto a perimeter and then drag inward to make the perimeter, e.g. perimeter 602 or 603 smaller, or can point, click, and drag outward to make the perimeter, e.g. perimeter 602 or 603, larger."; par. 0049: "manager system 110 can generate one or more additional candidate geofences having sizes based on the size of the specified nominally sized geofence, e.g. having one or more sizes incrementally larger and/or incrementally smaller"; par. 0052, "In another aspect, geofence configurator administrator user interface 600 can be provided so that the user can enter a target number of breaches in area 614 or 616...In response to the user entering the specified target value, manager system 110 can automatically generate iteratively a number of candidate geofences having different perimeters and can automatically predict performance of each candidate geofence until a candidate geofence yielding the target number of breaches is determined."; par. 0050 "there is shown perimeter 602 representing the area of a first candidate geofence and perimeter 603 representing an area of a second candidate geofence...a user can view depictions of anticipated predicted numbers of breaches for the various depicted geofences of different size").
Regarding claim 14, claim 14 is similar in scope to claim 6, and is therefore rejected under similar rationale.
Regarding claim 15, claim 15 is similar in scope to claim 7, and is therefore rejected under similar rationale.
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Ulewicz (“Ulewicz,” US 2023/0069458, published on Mar. 2, 2023), in view of West (“West,” US 2014/0031011, publishes on Jan. 30, 2014), further in view of Patel et al. (“Patel,” 9,973,891, published May 15, 2018).
Regarding claim 8, the combination of Ulewicz and West teaches the method of claim 1. The combination of Ulewicz and West further disclose generating, by the computing device, the one or more hashes based on one or more region size limits (Ulewicz: fig. 8, step 806, "Generate one or more hashed representations of the current location based on applying a hash function to the one or more numerical representations of the current location according to a secret key"; par. 0089, par. 0052, the geofence 210 is a different size and shape from the geofence 212. The different size and shape may be different levels of precision of geofenced locations in order to focus in on particular locations; par. 0088, the one or more numerical representations may correspond to the cells 402 of FIG. 4, according to some embodiments), wherein the set of authenticated regions are selected based on one or more region size limits (Ulewics: par. 0052, the geofence 210 is a different size and shape from the geofence 212. The different size and shape may be different levels of precision of geofenced locations in order to focus in on particular locations; par. 0088, the one or more numerical representations may correspond to the cells 402 of FIG. 4, according to some embodiments.).
Ulewicz and West do not explicitly disclose receiving, from the server, information regarding one or more region size limits
However, in an analogous art, Patel discloses receiving, from the server, information regarding one or more region size limits (Patel: Col. 16, lines 22-23, The location management server 204 sends updated geofences definitions to the group member 202B (step 514); Col. 16, lines 30-33. Updating the geofence definition may include transmitting a new location of the geofence anchor or reference point, or transmitting a new shape/size of the encapsulated region; See also claim 32).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Patel with the method and system of Ulewicz and West to include receiving, from the server, information regarding one or more region size limits. One would have been motivated to do so because having the server provide size information without require device-side configuration. Patel recognizes this benefit, teaching that the server dynamically updates geofence definitions including shape/size to the device during runtime (Patel: Col. 16, lines 22-23, Col. 16, lines 30-33), thereby allowing the system to adapt region parameters as operational, condition change.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CANH LE whose telephone number is (571)270-1380. The examiner can normally be reached on Monday to Friday 6:00AM to 3:30PM other Friday off.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham, can be reached at telephone number 571-270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated- interview-request-air-form.
/Canh Le/
Examiner, Art Unit 2439
July 29th, 2026
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439