DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Applicant's amendments filed on 07/07/2026 has been received and entered. Currently Claims 1-3, 5-7, and 9 are pending.
Response to Arguments
Applicant’s arguments have been considered but are moot in view of the new ground(s) of rejection.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2 and 5-6 are rejected under 35 U.S.C. 103 as being unpatentable over Kim US 2019/0044943, in view of Edwards et al. US 2021/0150014 (hereinafter Edwards), and Mohamad Abdul et al. US 2018/0337914 (hereinafter Mohamad Abdul).
As per claim 1, Kim teaches an authentication relay server that relays between an authentication server providing a user authentication function and a predetermined system used by a user, the authentication relay server comprising: a processor, configured to: receive a first authentication request from the system (Kim paragraph [0063], [0092], [0106], [0112], client sends authentication request to proxy server. Proxy server sends authentication result data to client);
in response to the first authentication request being a request related to a constraint, perform a constraint authentication processing different from an authentication processing performed in the authentication server for the first authentication request to create a second authentication request based on the first authentication request, wherein the constraint related to the first authentication request comprises a login to the authentication server by the system used by the user (Kim paragraph [0073], [0095]-[0102], [0112], proxy server performs authentication of client request. Proxy server sends an authentication request to service server.); and
transmit the second authentication request to the authentication server and receive a second response of the authentication processing performed in the authentication server from the authentication server (Kim paragraph [0073], [0092], [0102], [0106], [0112], proxy server sends an authentication request to service server. Service server sends authentication result back to proxy server);
in response to the second response being a response related to the constraint, perform the constraint authentication processing for the second response to create a first response based on the second response (Kim paragraph [0106], [0112], proxy server performs processing based on the received authentication result and generates an authentication result data based on the received authentication result); and
transmit the first response as an authentication result to the system (Kim paragraph [0092], [0106], [0112], Proxy server sends authentication result data to client).
Kim does not explicitly disclose in response to a message, issue an authentication code authenticating login for authentication relay server, transmit a response comprising the authentication code to user via a means of contact different from first response, and perform a processing of another first authentication request comprising the authentication code from system by verifying whether the authentication code included in another first authentication request from the system is identical to the issued authentication code.
Edwards teaches in response to a message, issue an authentication code authenticating login for authentication relay server, transmit a response comprising the authentication code to user via a means of contact different from first response, and perform a processing of another first authentication request comprising the authentication code from system by verifying whether the authentication code included in another first authentication request from the system is identical to the issued authentication code (Edwards paragraph [0047]-[0050], intermediate server receives message and generates and sends OTP to user. User sends OTP back to intermediate server. Intermediate server verifies the received OTP and notifies service server that authentication was successful).
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Kim of having an authentication proxy server performing authentication processes with the teachings of Edwards to include generating and verifying an OTP in order to provide multifactor authentication of the user by the proxy server.
Kim in view of Edwards does not explicitly disclose wherein second response comprises a first token indicating that authentication by authentication server has succeeded;
in response to authentication code included in another first authentication request from system being verified, transmit first response comprising the first token included in the second response as an authentication result to the system to complete login to authentication server.
Mohamad Abdul teaches wherein second response comprises a first token indicating that authentication by authentication server has succeeded (Mohamad Abdul paragraph [0174], after successful authentication provide response with the authentication token);
in response to authentication code included in another first authentication request from system being verified, transmit first response comprising the first token included in the second response as an authentication result to the system to complete login to authentication server (Mohamad Abdul Fig. 11, paragraph [0174], exchange az code for token and transmit response including the authentication token) (It is obvious to one of ordinary skill in the art that the azcode is verified).
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Kim in view of Edwards of having an authentication proxy server performing authentication and OTP verification with the teachings of Mohamad Abdul to include issuing a token and providing the token in response to verification of a code because the results would have been predictable and resulted in issuing an authentication token when authentication succeeds and providing the authentication token to the user in response to successful OTP verification.
As per claim 2, Kim in view of Edwards and Mohamad Abdul teaches the authentication relay server according to claim 1, wherein the processor is further configured to perform display associated with at least the first authentication request on the system (Kim paragraph [0092], [0094], [0106], [0112], proxy server sends authentication result to client. Client displays authentication result).
As per claim 5, the claim claims a non-transitory computer readable storage medium essentially corresponding to the server claim 1 above, and is rejected, at least for the same reasons.
As per claim 6, Kim in view of Edwards and Mohamad Abdul teaches the authentication relay server according to claim 1, wherein the constraint authentication processing is not provided in the authentication server (Kim paragraph [0073], [0095]-[0102], [0112], proxy server performs authentication of client request. Proxy server sends an authentication request to service server. Service server performs authentication of the received request and sends back authentication result to proxy server.)(In other words, proxy server performs authentication processing that the service server does not perform).
Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over Kim in view of Edwards and Mohamad Abdul, and further in view of Ferguson et al. US 2008/0126478 (hereinafter Ferguson).
As per claim 3, Kim in view of Edwards and Mohamad Abdul teaches the authentication relay server according to claim 1.
Kim in view of Edwards and Mohamad Abdul does not explicitly disclose wherein constraint related to first authentication request further comprises to change a password used for second authentication request, and
processor confirms whether a password to be changed to in the first authentication request is different from a password used for authentication in authentication server in the past.
Ferguson teaches wherein constraint related to first authentication request further comprises to change a password used for second authentication request (Ferguson paragraph [0174], password change request), and
processor confirms whether a password to be changed to in the first authentication request is different from a password used for authentication in authentication server in the past (Ferguson paragraph [0178], perform similarity check between the new password and the current password to determine if the two are sufficiently different).
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Kim in view of Edwards and Mohamad Abdul of having an authentication proxy server performing authentication processes with the teachings of Ferguson to include updating a password and checking the new password against the current password in order to allow the user to update their password and to provide similarity checking of the new password by the proxy server.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Kim in view of Edwards and Mohamad Abdul, and further in view of Tharoor et al. US 2021/0004793 (hereinafter Tharoor).
As per claim 7, Kim in view of Edwards and Mohamad Abdul teaches the authentication relay server according to claim 1, wherein the means of contact different from the first response comprises an email or a short message service (SMS) (Kim paragraph [0092], [0106], [0112]; Edwards paragraph [0048], send OTP via text message or email).
Kim in view of Edwards and Mohamad Abdul does not explicitly disclose an email or a short message service (SMS) pre-registered for the user.
Tharoor teaches an email or a short message service (SMS) pre-registered for the user (Tharoor paragraph [0034], send OTP via a registered SMS or registered email).
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Kim in view of Edwards and Mohamad Abdul of having an authentication proxy server performing authentication processes including sending an OTP via SMS or email with the teachings of Tharoor to include sending an OTP via a registered SMS or email because the results would have been predictable and resulted in the proxy server sending the OTP via a registered SMS or email.
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Kim in view of Edwards and Mohamad Abdul, and further in view of Vellozo Luz et al. US 2013/0340071 (hereinafter Vellozo Lu).
As per claim 9, Kim in view of Edwards and Mohamad Abdul teaches the authentication relay server according to claim 1, wherein the processor is further configured to: the authentication code included in the another first authentication request from the system not being identical to the issued authentication code(Edwards paragraph [0050], OTP does not match the previously generated OTP).
Kim in view of Edwards and Mohamad Abdul does not explicitly disclose in response to authentication code not being identical to issued authentication code, transmit first response comprising error information as another authentication result to system.
Vellozo Luz teaches in response to authentication code not being identical to issued authentication code, transmit first response comprising error information as another authentication result to system (Vellozo Luz paragraph [0030], if the OTP does not match send error message).
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Kim in view of Edwards and Mohamad Abdul of having an authentication proxy server performing authentication processes including OTP verification with the teachings of Vellozo Luz to include sending an error message to a client when OTP verification fails in order to indicate to the client that OTP verification failed.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HENRY TSANG whose telephone number is (571)270-7959. The examiner can normally be reached M-F 9am - 5pm EST.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at (571) 272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HENRY TSANG/ Primary Examiner, Art Unit 2495