Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This office action is in response to the application filed on or reply to the remarks of 4/29/2024. The instant application has claims 1-5, 7-15 pending. The system and method for using authentication protocols at different nodes for authenticating an device. There a total of 20 claims.
Response to Arguments
The applicant’s argument relating to integrated into a practical application is not persuasive. There are several court cases that illustrate a practical concept is still deemed abstract idea and ineligible by Fed. Circuit Court. The examples include device profiles for imaging device, playing bingo, or guarantee online transaction, data analysis on documents. See Digitech Image Tech's v. Electronics For Imaging, 758 F.3d 1344 (Fed. Cir. 2014); Planet Bingo, LLC v. VKGS, LLC, 576 Fed. Appx. 1005 (Fed. Cir. 2014) ; Buysafe, Inc. v. Google, Inc., 765 F.3d 1350 (Fed. Cir. 2014); Content Extraction and Transmission. v. Wells Fargo Bank, 776 F.3d 1343 (Fed. Cir. 2014).
Applicant’s arguments with respect to claim(s) 1-5, 7-15 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Examiner’s Notes
The applicant is advised that an similar product from Vodafone(parent company of assignee) was available on the market as of October 21, 2021, The product named Digital Asset Management(DAB), the extent to which it covers the current claims cannot be ascertained as the product specifications is not available online. However, the applicant is advised about this to potential bar under 35 USC § 102(a)(1) for use and sale. It is left to the applicant to find out if there is an overlap with the claims. See Attached NPL showing the products details & citation of statute with underline for emphasis.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Information Disclosure Statement
The information disclosure statement filed 4/29/2024 fails to comply with 37 CFR 1.98(a)(2), which requires a legible copy of each cited foreign patent document; each non-patent literature publication or that portion which caused it to be listed; and all other information or that portion which caused it to be listed. It has been placed in the application file, but the information referred to therein has not been considered.
The information disclosure statement filed 4/29/2024 fails to comply with 37 CFR 1.98(a)(3)(i) because it does not include a concise explanation of the relevance, as it is presently understood by the individual designated in 37 CFR 1.56(c) most knowledgeable about the content of the information, of each reference listed that is not in the English language. It has been placed in the application file, but the information referred to therein has not been considered.
-- The Chinese Patent CN 10868364 is cited but no concise explanation is provided.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-5, 7-15 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The claims recites an “authentication request including data indicating one or more steps of authentication method”, but the specifications fails to describe what that means. That is, does the data include the how to use the authentication methods with what to use as parameters, e.g. symmetric encryption using session key or public key to be used for authentication. The specifications does not adequately provide details about what the data includes and there are no examples given either. And furthermore, the claim recites protocols that might not be possible to perform by the node. For example, the node might be an simple IoT device with limited computational and memory resources than how would it perform complex protocols like TLS.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-5, 7-15 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The steps can be performed by an human on an generic computer. The claim recites authenticating an device based on credentials being verified by different nodes using authentication protocol. The steps can be performed by an human with different persons sitting at different nodes, i..e. device presents an SIM identifier and the representative checks whether the SIM identifier is registered and check other parties as well.
The limitation of “receiving, at a plurality of nodes of a distributed ledger, from the device an authentication request, the authentication request including data indicating one or more steps of an authentication method”, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting “by a processor,” nothing in the claim element precludes the step from practically being performed in the mind. For example, but for the “by a processor” language, “receiving, at a plurality of nodes of a distributed ledger, from the device an authentication request, the authentication request including data indicating one or more steps of an authentication method” in the context of this claim encompasses the user manually making an request via device to include credentials like SIM identifier or identifier information. Similarly, the limitation of “plurality of nodes use an authentication protocol defined by the described one or more steps of the authentication method, of a plurality of authentication protocols useable by the plurality of nodes, to follow the one or more steps of the authentication method”, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation done in the mind but for the recitation of generic computer components the 2019 Revised Patent Subject Matter Eligibility Guidance (“2019 PEG”) Federal Register January 7, 2019. For example, but for the “by a processor” language, “plurality of nodes use an authentication protocol defined by the described one or more steps of the authentication method, of a plurality of authentication protocols useable by the plurality of nodes, to follow the one or more steps of the authentication method” in the context of this claim encompasses the user thinking that confirming upon receiving the identifier is registered from other parties/members that the user’s device is authentic. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” & “Certain methods of organizing human activity” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. In particular, the claim only recites one additional element – using a processor to perform both the “receiving, at a plurality of nodes of a distributed ledger, from the device an authentication request, the authentication request including data indicating one or more steps of an authentication method” and “plurality of nodes use an authentication protocol defined by the described one or more steps of the authentication method, of a plurality of authentication protocols useable by the plurality of nodes, to follow the one or more steps of the authentication method “steps. The processor in both steps is recited at a high-level of generality (i.e., as a generic processor performing a generic computer function of receiving an request and checking the credentials with other parties) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a processor to perform receiving an request and checking the credentials with other parties steps amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is not patent eligible.
Furthermore, the examiner points out that using an blockchain for carrying out this operation is still ineligible under 35 USC 101, as illustrated by several Fed circuit and PTAB cases. For example, trading platforms using digital assets was deemed ineligible see Coinbase Inc v. Securities and Exchange Commission, No. 23-3202 (3d Cir. 2025). Another Fed Circuit court case where using blockchain for supply-chain of gemstones was deemed ineligible see RADY v. BOSTON CONSULTING GROUP, INC. , No. 22-2218 (Fed. Cir. 2024). An PTAB case where the use of blockchain for managing commercial payment transactions, processing payments and recording in ledger was deemed ineligible see Ex parte McCann, No. 2021-003397 (P.T.A.B. March 7, 2022).
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-5, 7-15 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-36 of U.S. Patent No. 8776183(based on common assignee Dabco’s parent company Vodafone) in view of US Patent 11601426 to Fan. Both the instant application and ‘183 patent describes an group of nodes connected to an hub being authenticated using authentication protocols. The claims of ‘183 patent describes the authentication using IP address(claim 6), public-private key pair(claim 14), and certificate(claim 15). Thus, the plurality of authentication protocols for connecting to an plurality of nodes is taught, the missing feature is the distributed ledger, which is remedied by Fan. It would have been obvious to add distributed ledger to the invention in order to have an immutable record of transactions as taught by Fan see Col 3 LN 20-39. Additionally, the grouping of devices using keys as authentication is evidenced by drawings Fig. 3 & Fig. 4 of ‘183 patent, similar to device and partner systems being group and authenticated see Fig. 2 of instant application .
US App # 18705836
US Patent # 8776183
Comments
1. A method for authenticating a device, the method comprising the steps of: receiving, at a plurality of nodes of a distributed ledger, from the device an authentication request, the authentication request including data indicating describing one or more steps of an authentication method; and authenticating the device across a plurality of nodes of the distributed ledger, wherein plurality of nodes use an authentication protocol defined by the described one or more steps of the authentication method, of a plurality of authentication protocols useable by the plurality of nodes, to follow the one or more steps of the authentication method.
1. A system including: plurality of devices; an administration entity for allowing selected devices to be associated together as a group by providing each device with security data and identification data, the security data of each device being interpretable by each other device within the group, particular modes of communication only being allowed between devices within the group having such security data, and the identification data identifying each device within the group for the purpose of delivering data to that device but not necessarily being recognisable by other devices not in said group; and a plurality of hubs, each having an external identifier recognisable by others of said hubs for routing communications between respective ones of the hubs via a communication medium, wherein a first of said hubs is operable to communicate data, originating from one device within said group and destined for another device within said group, via said communication medium to a second of said hubs by means of the external identifier of the second of said hubs, the second of said hubs being operable to route the data to said another device within said group using the identification data of said another device; wherein at least one of the devices comprises a mobile telecommunications terminal and is operable to communicate with an associated one of the hubs via a mobile telecommunications network; wherein the associated one of the hubs includes means for authenticating the mobile terminal; and wherein the authenticating means is operable to authenticate the mobile terminal using data relating to the subscription of the mobile terminal with the mobile telecommunications network.
6. The system of claim 1, wherein the external identifier is a unique public IP address or telephone number.
14. The system of claim 1, wherein the hubs are operable to generate a public-private key pair.
15. The system of claim 14, wherein the device associated with the hub is operable to generate a certificate using the public key of the hub and the device's key.
16. The system of claim 15, wherein the hub is operable to authenticate itself with the administration entity using said certificate.
The features of instant application is taught by
183 patent as evidenced by claim 1 + claim 6 + claim 14 + claim 15 yielding the current claims. It would have been obvious at the time of filing to include distributed ledger to have an immutable records of the transactions as taught by Fan see Col 3 Ln 20-39.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-5, 7-15 is/are rejected under 35 U.S.C. 103 as being unpatentable over US Patent 11601426 to Fan in view of EP 3474209 to Van de Ruit1.
Regarding claim 1, 9, Fan discloses A method for authenticating a device, the method comprising the steps of: receiving, at a plurality of nodes of a distributed ledger, from the device an authentication request, the authentication request including data indicating one or more steps of an authentication method(Fig. 1 item 11 & Col 2 LN 18-40, the authentication method for device); and authenticating the device across a plurality of nodes of the distributed ledger, wherein each of the plurality of nodes follows the one or more steps of the authentication method indicated by the data received from the device (Col 8 Ln 26-40, the second device receives that authentication request & Fig. 4 & Col 13 Ln 15-37).
Fan does not disclose plurality of nodes use an authentication protocol defined by the described one or more steps of the authentication method, of a plurality of authentication protocols useable by the plurality of nodes, to follow the one or more steps of the authentication method.
In the same field of endeavor as the claimed invention, Van de Ruit discloses plurality of nodes use an authentication protocol defined by the described one or more steps of the authentication method, of a plurality of authentication protocols useable by the plurality of nodes, to follow the one or more steps of the authentication method(Par. 0028, consensus proof & Par. 0031 & Par. 0010-011 & Par. 0097, the high security and low security with public keys or kernel application representing plurality of authentication protocols)
It would have been obvious to one of ordinary skill in the art before the effective filing date of claimed invention to modify Fan invention to incorporate plurality of nodes use an authentication protocol defined by the described one or more steps of the authentication method, of a plurality of authentication protocols useable by the plurality of nodes, to follow the one or more steps of the authentication method for the advantage of provide for different levels of security for different applications and as taught in Van de Ruit see Par. 0097-0099.
Regarding claim 2. Fan discloses the method of claim 1, wherein the request further includes credentials and the step of authenticating the device across the plurality of nodes of the distributed ledger further includes authenticating the credentials(Col 6 Ln 31-60, the identifiers used for authentication) .
Regarding claim 3. Fan discloses the method according to claim 1, wherein authentication of the device is unsuccessful unless more than one node of the plurality of nodes authenticate the device according to the one or more steps indicated by the data received from the device(Col 9 Ln 7-53, the parties record the successful authentication).
Regarding claim 4. Fan discloses the method according to claim 1, wherein authentication of the device is unsuccessful unless a majority of the plurality of nodes involved in the authentication authenticate the device(Fig. 4 & Fig. 7).
Regarding claim 5. Fan discloses the method according to claim 1, wherein the data indicating one or more steps of an authentication method are included in a header of the request(Col 6 Ln 28-40).
Regarding claim 7. Fan discloses the method of claim 1,wherein the plurality of authentication protocols include: symmetric encryption; asymmetric encryption; public key infrastructure, PKI;SIM Trust; IoT SAFE; TLS; DTLS; and Generic Bootstrapping Architecture, GBA(Col 9 Ln 17-53, the public key is used).
Regarding claim 8. Fan discloses the method according to claim 1 further comprising the step of the device selecting the authentication method from a plurality of authentication methods available to the device before generating the request including data indicating the one or more steps of the selected authentication method(Col 10 Ln 33-55).
Regarding claim 10. Fan discloses the authentication system of claim 9, wherein a further device of the one or more devices is configured to generate a further authentication request indicating further one or more steps of a second authentication method different to the one or more steps of the authentication method(Col 10 Ln 33-55)..
Regarding claim 11. The authentication system of claim 9, wherein authentication of the device is unsuccessful unless more than one node of the plurality of nodes authenticate the device according to the one or more steps indicated by the data received from the device(Fig. 4 & Fig. 7). .
Regarding claim 12. Fan discloses the authentication system according Claim 9, wherein each of the one or more devices is further configured to select the authentication method from a plurality of authentication methods available to the device before generating the request including data indicating the one or more steps of the selected authentication method(Col 10 Ln 33-55).
Regarding claim 13. Fan discloses the authentication system according to claim 9,where each of the one or more devices is further configured to receive data defining a new authentication method for use in further authentication requests(Col 10 Ln 33-55).
Regarding claim 14. Fan discloses the authentication system of claim 13, wherein the original and/or new authentication method has an expiry time(Col 12 LN 1-7, time interval).
Regarding claim 15. Fan discloses the authentication system according to claim 9,wherein the one or more devices further comprises a UICC or SIM configured to secure the request(Col 1 LN 54-60, SIM is used).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Venkat Perungavoor whose telephone number is (571)272-7213. The examiner can normally be reached 9-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached at 571-272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VENKAT PERUNGAVOOR/Primary Examiner, Art Unit 2492 Email: venkatanarayan.perungavoor@uspto.gov
1 Already in file as of 4/20/2026.