DETAILED ACTION
This Office action is in response to a non-provisional utility patent application filed by Applicant on 11/27/2023.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement PTO-1449
The Information Disclosure Statement submitted by applicant on 11/27/2023 has been considered. The submission is in compliance with the provisions of 37 CFR § 1.97. Form PTO-1449 signed and attached hereto.
Double Patenting
No conflicting application or issued patent was identified that would require a rejection under double patenting.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1–9 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 8, and 9, recite, “that are installed in an information processing apparatus”, which is unclear. It is not apparent what is being modified. The recited language is written in the plural (“that are”), which means either the recited “authentication keys” or the recited “applications” are installed. However, it is not clear which of these elements (or both) “are installed in an information processing apparatus”.
Claims 1, 8, and 9, recite, “each of the authentication keys being used when a corresponding one of the applications uses a service and being associated with the application using the authentication key”, which is unclear. The Examiner cannot determine which keys are being used, nor what they are being used for.
Further, the Examiner cannot determine what the recited “and being associated with the application using the authentication key” means. There is an antecedent basis issue here because it cannot be determined which authentication key is being referred to. Also, what is being associated with the application using the authentication key? The language suggests that each of the authentication keys is associated with the application using “the authentication key”, which cannot be determined.
Claims 1, 8, and 9, recite, “in response to presence of an authentication key”. Which conflicts with a previously instantiated “an authentication key” and therefore, is indefinite.
Claims 1, 8, and 9, recite, “in response to presence of an authentication key of the authentication keys”, which is unclear. It cannot be determined which “authentication keys” are being referred to.
Dependent claims 2–7 inherit the indefiniteness of the independent claims and are also rejected.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 8 and 9 rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims classify and group authentication keys with respect to associated applications, determining whether a key is associated with an application that has been uninstalled, removing the key.
The limitations of classifying and grouping of authentication keys with respect to associated applications, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the generic computer components. That is, other than reciting “a processor configured to”, nothing in the claim elements preclude the steps from practically being performed in the mind. For example, but for the “a processor configured to” language, “in referring to pieces of key management information each including an authentication key and an application, the authentication key being included in authentication keys that are used for authentication by applications including the application that are installed in an information processing apparatus, each of the authentication keys being used when a corresponding one of the applications uses a service and being associated with the application using the authentication key” amounts to a person defining, organizing and grouping authentication keys according to their associations with applications. Further, the “in response to presence of an authentication key of the authentication keys that is no longer associated with any one of the applications because an application of the applications that is associated with the authentication key is uninstalled from the information processing apparatus, delete the authentication key” amounts to a person comparing the list of keys and their associations with applications and recognizing that certain applications are no longer installed and deleting the associated authentication keys from the record. All of these steps cover performance that can be accomplished by the mind and would fall within the “Mental Process” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of “processor” amounts to applying the exception using a generic computer component, which cannot provide an inventive concept. The claim is not patent eligible.
Claim 4 is also rejected under 35 U.S.C. 101 because it defines setting an expiration date on the authentication keys and tracking whether the authentication keys have exceeded this time period before deleting the keys. This limitation can be described as part of the mental step (checking dates) using conventional computer functions (deleting expired keys). Therefore, the dependent claim is also directed to an abstract idea and is not patent eligible.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 8, 9 rejected under 35 U.S.C. 102(a)(1) as being anticipated by Delaney (US 11,349,646 B1, issued May 31, 2022.
Regarding claims 1, 8 and 9, Delaney discloses: an information processing system comprising: a processor configured to: in referring to pieces of key management information each including an authentication key and an application (secure communications application and associated keys. Delaney 4:40–64.), the authentication key being included in authentication keys that are used for authentication by applications including the application that are installed in an information processing apparatus (keys are stored in groups in files for use in facilitating the secure communications application. Delaney 4:40–64.), each of the authentication keys being used when a corresponding one of the applications uses a service and being associated with the application using the authentication key (specific keys are used by specific user devices to achieve cryptographically secure communication by the secure communications application. Delaney 4:40–5:29.), in response to presence of an authentication key of the authentication keys that is no longer associated with any one of the applications because an application of the applications that is associated with the authentication key is uninstalled from the information processing apparatus, delete the authentication key (removing applications from devices and directing each user device to remove all user private keys and content stored on each of the user devices. Delaney 6:58–7:8.).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim 4 rejected under 35 U.S.C. 103 as being unpatentable over Delaney in view of Oberheide (US 2015/0074408 A1, published Mar. 12, 2015).
Regarding claim 4, Delaney discloses the limitations of claim 1. Delaney does not disclose: wherein a registration date information element is associated with the authentication key in each piece of key management information, the registration date information element being included in registration date information elements that each indicate a date when a corresponding one of the authentication keys is registered with the piece of key management information, and wherein the processor is configured to: refer to the registration date information elements; and delete, from the authentication keys, an authentication key with a predetermined time elapsed since the authentication key is registered.
However, Oberheide does disclose: wherein a registration date information element is associated with the authentication key in each piece of key management information, the registration date information element being included in registration date information elements that each indicate a date when a corresponding one of the authentication keys is registered with the piece of key management information, and wherein the processor is configured to: refer to the registration date information elements; and delete, from the authentication keys, an authentication key with a predetermined time elapsed since the authentication key is registered (storing authentication keys with an expiration condition and when the expiration condition is satisfied, removing the authentication key. Oberheide ¶ 35.).
Therefore, it would have been prima facie obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the authentication key management system that deletes authentication keys when it is determined that the associated application is no longer installed on the device of Delaney with deleting authentication keys based upon predetermined expiration registration information having elapsed based upon the teachings of Oberheide. The motivation being to restrict the storage of non-usable encryption keys that might make an application vulnerable.
Allowable Subject Matter
Claims 2–3 and 5–7 are rejected as being indefinite under 35 U.S.C. 112(b) based upon the intervening independent claims. If the independent claims were to overcome the indefiniteness rejection (and depending on how Applicant amends the independent claims), claims 2–3 would likely be objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VANCE M LITTLE whose telephone number is (571) 270-0408. The examiner can normally be reached on Monday - Friday 9:30am - 5:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung (Jay) Kim can be reached on (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VANCE M LITTLE/Primary Examiner, Art Unit 2493