Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
The instant application having Application No. 18/607,626 is presented for examination by the examiner. Claims 1, 8-9, 12, 18 are amended, claims 1-20 have been examined.
Response to Arguments
Applicant' s arguments filed 05/08/2025, with respect to the rejection(s) of claim(s) 1, 12 and 18 under 35 U.S.C. 103 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim 12 is rejected under 35 U.S.C. § 103 as being unpatentable over Basile (US 2020/0382297 A1) in view of Brown (US 2014/0223186 A1).
Regarding Claim 12
Basile discloses:
A first device comprising: a processor configured to execute a method comprising:
transmitting a registration request to a communication component for generating a first registration for a first device having a mobile device number (Basile ¶¶0016–0017 teach creating a first registration for a first device associated with a phone number by having the device register its public key 104 with IDS server 120, which stores the public key in association with a user account tied to the phone number for message routing.);
receiving a notify message from the communication component, wherein the notify message comprises an indication of a second registration of a second device having the same mobile device number and comprising a second device public key of the second device (Basile ¶0015-0016 discloses multiple user devices "100A-N" registered to the same user account associated with a phone number, thereby teaching a second device tied to the same mobile device number, and ¶0016-0017 teaches that when a given device is added, it registers its own public key 104 with IDS server 120, thus creating a second registration comprising a second device public key. Basile ¶0017, ¶¶0037–0038, claim 12: teaches transmitting to the first device information identifying the second device's registration and its corresponding public key by having the IDS server provide devices associated with the same user account with the public keys of registered devices in response to a contact information request. This provision of the second device's public key to the first device informs the first device of the second device's registration.);
Basile teaches a multi-device messaging system in which multiple devices are registered under the same user account and public keys for those devices are distributed to inform devices of one another's registration. However, Basile does not expressly teach, after receiving the notify message of the second registration and the second device public key, determining whether the second device is being spoofed by determining whether a received second device public key within a secure communication invite received from the second device via the communication component matches the second device public key within the notify message.
Brown teaches storing a public key associated with a given identity following a successful signature verification operation, for reuse in later verifications of that same identity (Brown ¶0097: "when a given public key is used in successfully verifying the digital signature on a certificate, a copy of that public key is cached, or otherwise stored in a memory store... the public key may be stored with the certificate data associated with the certificate, or in a separate memory store... adapted to store public keys employed in successful signature verifications."). Brown further teaches that, upon a subsequent attempt to verify the digital signature for that same identity, the public key that would otherwise be used to re-perform verification is instead compared against the previously stored public key to determine whether they match (Brown ¶0099: "comparing a stored public key for the certificate issuer previously used to successfully verify the digital signature on the subject certificate... with the public key that is about to be used to verify the digital signature, and then determining if there is a match... if a match were determined, this would suggest that the digital signature on the subject certificate has previously been successfully verified."). Brown additionally teaches that a mismatch between an expected public key and a subsequently received public key for a purported sender is indicative that the communication did not originate from that sender (Brown ¶0061: "If the digests of the received message do not match, this suggests that either the message content was changed during transport and/or the message did not originate from the sender whose public key was used for verification."), i.e., that comparison of a stored public key against a subsequently received public key for the same purported identity serves to detect a possible impersonation of that identity.
It would have been obvious to one of ordinary skill in the art at the time of the invention to modify Basile's multi-device registration and notification framework to incorporate Brown's technique of storing a public key received for a given identity and, upon a subsequent communication purporting to originate from that same identity, comparing the subsequently received public key against the stored public key to confirm a match, in order to authenticate the secure communication invite received from the second device against the second device public key already known from the notify message. A person of ordinary skill would have been motivated to make this combination because Brown expressly teaches that a mismatch between a stored/expected public key and a subsequently presented public key for the same identity is evidence that the subsequent communication did not originate from the identity it claims to represent, and applying this known key comparison technique within Basile's registered multi-device messaging framework would predictably yield the result of detecting whether a secure communication invite from the previously registered second device is legitimate or is instead an attempted impersonation of that device. The combination merely applies Brown's known stored key comparison technique within Basile's registration/notify/invite framework, yielding the predictable result of authenticating a secure communication invite against previously established key material for the second device.
Claims 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Basile (US 20200382297 A1), in view of Brown (US 2014/0223186 A1) as applied to claim 12 above, and in further view of THIRUMALAI (US 11,012,428 B1).
Regarding Claim 13
Basile and Brown combined teach registering devices with public keys tied to user accounts, notifying and authenticating devices within a trusted group using exchanged credentials. However, Basile and Brown do not expressly teach transmitting an encrypted message comprising a first device private key encrypted using the second device public key to the second device for use in performing end-to-end encrypted communication between the second device and a sender device. Thirumalai teaches that, for each new message, a sending client device signs the message using a sender message signing private key and performs authenticated encryption before transmitting the encrypted message, such that recipient devices decrypt and verify the message using corresponding cryptographic keys (Col. 19, ll. 42 – Col. 20, l. 4). Thirumalai further teaches that group key material is wrapped using device-specific encryption keys and that each member device uses its associated private key to decrypt the group blob key necessary to access encrypted communications (Col. 16, ll. 18–24). Thirumalai thus teaches facilitating end-to-end encrypted communication in which secure messaging operations depend upon the use of a device private key. It would have been obvious to one of ordinary skill in the art at the time of the invention to modify the Basile, Brown, and Nicholson system to facilitate end-to-end encrypted communication between the sender device and the first and second devices using the first device private key, as taught by Thirumalai, in order to provide authenticated message signing, confidentiality, and integrity protection within the multi-device communication framework. The combination merely applies Thirumalai’s well-known end-to-end encryption and private key signing techniques within the established device registration and invite-routing architecture of Basile and Brown yielding the predictable result of secure, authenticated communications between the registered devices.
Claims 14 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Basile (US 20200382297 A1), in view of Brown (US 2014/0223186 A1) as applied to claim 12 above, and in further view of Sànchez (US 2022/0224728A1).
Regarding Claim 14
Basile and Brown combined teach registering devices with public keys tied to user accounts, notifying and authenticating devices within a trusted group using exchanged credentials. However, Basile and Brown do not expressly teach wherein the method further comprises: transmitting a publish request to a presence server for generating a presence indicator for the first device; and utilizing the presence indicator as an indication to the second device that the first device supports end-to-end encryption. Sànchez discloses an event subscription element system/method that includes: encryption (Sánchez Paragraphs 74: Messaging app 156 may generate and send a registration message … which includes a device identifier and a public key associated with the application.” This process serves to identify the device with a unique key as part of its registration); Sánchez Paragraphs 66: The message delivery server…encrypts the message using a public key identified based on a recipient identifier…this ensures secure delivery…only the recipient device with the corresponding private key can decrypt the message).
Given the teaching of Sánchez, a person having ordinary skill in the art before the effective filing date of the claimed invention would have recognized the desirability of modifying the teaching of Basile and Brown by incorporating a method for using a public key in a presence indicator to signify a device’s capability for end-to-end encryption. Sánchez describes a method in which a messaging app generates a registration message containing a unique device identifier and a public key associated with the application, which effectively identifies the device and associates it with a specific public key. Sánchez also explains that the message delivery server encrypts messages using a public key identified based on a recipient identifier, ensuring that only the recipient device, which has the corresponding private key, can decrypt the message. This process supports end-to-end encryption by signaling that a device can decrypt incoming encrypted messages when it holds the appropriate private key corresponding to its registered public key. It would have been obvious to extend Sánchez’s approach by utilizing the presence indicator, which includes the public key, as a signal to another device (the second device) that the first device supports end-to-end encryption (Sánchez Paragraphs 66).
Regarding Claim 17
Basile and Brown combined teach registering devices with public keys tied to user accounts, notifying and authenticating devices within a trusted group using exchanged credentials. Basile and Brown do not disclose the following limitation wherein the method further comprises: transmitting a subscribe request to the communication component to register for receiving notify messages of devices with the mobile device number registering with the communication component. However, in an analogous art, Sànchez discloses a subscribe request element system/method that includes: (Sànchez Paragraph 91: A client device may utilize SIP SUBSCRIBE to request from a remote node (e.g., wireless carrier system 160) a current state and/or state updates. When such a request is received, the remote node may send a SIP NOTIFY message, e.g., in response to determination that the change in current state has occurred based on the receipt of a message that includes the notification from delivery application 108 … Sànchez Paragraph 55: In some implementations, the registration message also includes a telephone number associated with the client device that implements method 200 (e.g., client device 120). Once the client device is registered, a message delivery server (e.g., server 104 that executes delivery application 108) may deliver messages to the client device via a network access layer.).
Given the teaching of Sánchez, a person having ordinary skill in the art before the effective filing date of the claimed invention would have recognized the desirability of modifying the teaching of Basile and Brown by incorporating a method for using a subscribe request to register for receiving notify messages based on the state of a device associated with a particular identifier, such as a mobile device number. Sánchez describes a method in which a client device uses SIP SUBSCRIBE to request updates from a remote node, such as a wireless carrier system, to receive notifications regarding the device’s state. Sánchez explains that when a subscription request is received, the remote node may respond with a SIP NOTIFY message if a change in state has occurred. Additionally, Sánchez describes a registration message that includes a telephone number associated with the client device. Upon successful registration, a message delivery server may send messages to the client device, establishing a communication link associated with the device’s telephone number. It would have been obvious to apply Sánchez’s approach to implement a method where a device transmits a subscribe request to a communication component to register for receiving notify messages, specifically using the mobile device number as a means to register with the communication component (Sànchez Paragraph 55).
Claims 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Basile (US 20200382297 A1), in view of Brown (US 2014/0223186 A1) as applied to claim 12 above, Lackey (US 9,635,003 B1)
Regarding Claim 15
Basile and Brown combined teach registering devices with public keys tied to user accounts, notifying and authenticating devices within a trusted group using exchanged credentials. Basile and Brown do not disclose the following limitation in response to determining that the second device public key within a secure communication invite does not match the second device public key within the notify message, refraining from creating and transmitting an encrypted message. However, in an analogous art, Lackey discloses a mismatch key system/method that includes: (Lackey Column 5, Line 64: At step 158, Alice determines whether the recovered public key, B* matches the delivered public key, B. If the recovered public key, B*, matches the received public key, B, the received public key, B, is considered valid and Alice will proceed to use her computed session key kA as Bob's session key k to perform the intended cryptographic task. For example, in the event an encrypted message was received from Bob, Alice will decrypt the encrypted message, EnckM (M) to recover the message M. If however, the recovered public key, B*, does not match the received public key, B, the public key B received from Bob is considered invalid and Alice is informed that the communication is invalid. It is important to note that if Alice does not want to reveal information about her private key, she will not communicate to Bob that the session keys do not match. Alice may, however, communicate to Bob that the cryptographic task failed, e.g. the message failed to decrypt correctly. It is noted that regardless of whether the invalid public key provided by Bob would satisfy k=aB allowing Alice to perform the cryptographic task, if the public key is invalid (i.e. it was not created using the key agreement protocol), Alice will respond by notifying Bob that the cryptographic task failed. By providing the same response in each instance, Alice does not provide any information as to the characteristics of her private key, a. Alice therefore eliminates the vulnerability of the prior art method described above.).
Given the teaching of Lackey, a person having ordinary skill in the art before the effective filing date of the claimed invention would have recognized the desirability of modifying the teaching of Basile and Brown by incorporating a method for verifying that a public key received during a communication initiation matches an expected public key before proceeding with cryptographic operations. Lackey describes a method where a device (Alice) verifies the validity of a received public key, comparing it to an expected public key, to ensure the authenticity of the communication. Lackey explains the process of verifying public key consistency to ensure that the communication validity aligns with the claimed limitation's step of determining whether the second device’s public key matches an expected value to authenticate the communication. It would have been obvious to modify Lackey’s approach to not only notify the user of an invalid public key but also to refrain from transmitting an encrypted message when the received public key does not match the expected public key. Lackey’s approach to verifying the public key before proceeding with any cryptographic task meets the claimed invention’s requirement of refraining from creating and transmitting an encrypted message upon detecting a mismatch, ensuring secure communication by preventing unauthorized access.
Claims 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Basile (US 20200382297 A1), in view of Brown (US 2014/0223186 A1) as applied to claim 12 above, and in further view of Asveren2 (US 9,800,589 B1).
Regarding Claim 16
Basile and Brown teach that when a second device is registered (A1) with the same identity as first device (A), they system generates a new public key for A1 notifies the first device of the second device registration and key via a validation message and enables a secure peer-to-peer communication by exchanging public keys through a signet-based protocol that establish a trusted relationship between both devices. However, they do not disclose the following limitation wherein the method further comprises: in response to determining that the second device is being spoofed, triggering an alert of a spoofing attack of the second device.
However, in an analogous art, Asveren2 discloses a spoofing detection system/method that includes (Asveren2 Column 32, Line 55- Column 33, Line 2: teaches that when a spoofing check is performed the SBC monitors for a reply. If no reply is received, the system concludes that no legitimate device exists at that address, which indicates a spoofing attempt. In such cases, the SBC may trigger an alarm, blacklist the source, or drop future requests.).
Given the teachings of Asveren2, a person of ordinary skill in the art would have found it obvious to modify the teachings of Basile and Brown to secure communication system to determine whether a device is spoofed based on its response (or lack thereof) to a test message. Asveren2 teaches that if no reply is received, the SBC can trigger an alarm indicating a spoofing attempt (Asveren2 Column 32, Line 55- Column 33, Line 2).
Allowable Subject Matter
Claims 1–11 and 18–20 are allowed.
Claim 1 (and claim 18): Basile (US 20200382297 A1) discloses registering multiple devices to the same mobile device number and distributing each device's public key so a sender may encrypt separately to each device using its own key. Agarwal (US 20110225426 A1) discloses exchanging SIP invite/response messages with self-signed certificate fingerprints to establish a trusted session. Nicholson (US 20140162619 A1) discloses a network device transmitting a private key to a communication device, but that key is a symmetric shared secret used in hash challenge response authentication, not an asymmetric key encrypted using the recipient's public key. No reference of record discloses routing a message comprising a first device private key, encrypted using a second device public key, from the first device to the second device, wherein the first device private key is usable by the second device to decrypt a communication encrypted by a sender device using the first device public key, as recited in claim 1 and similarly in claim 18.
An updated search was conducted and the closest prior art identified is Kirsch (US 2015/0088754 A1), which discloses an existing authorized device providing a private encryption key to a newly authorized device, encrypted using the new device's public key. However, Kirsch's transferred key is a shared user level encryption key onto which all of a user's devices converge, rather than an existing device's own distinct private key tied to its own registration. Kirsch's devices retain separate device-specific key pairs used only to secure the transfer itself. Kirsch therefore does not disclose the first device's own registered private key being transmitted to the second device for use in decrypting communications encrypted using that same first device public key.
Claims 2–11 and 19–20 are allowable by virtue of their dependency on allowable claims 1 and 18, respectively.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAAD A ABDULLAH whose telephone number is (571) 272-1531. The examiner can normally be reached on Monday - Friday, 8:30am - 5:00pm, EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SAAD AHMAD ABDULLAH/ Examiner, Art Unit 2431
/LYNN D FEILD/ Supervisory Patent Examiner, Art Unit 2431