DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The preliminary amendment of 11/12/24 was received and considered. Claims 1-20 are presented for examination.
Double Patenting
Claims 1-20 of this application are patentably distinct from the claims of Application No. 17/328,759 and 17/155,091.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-8, 10-17 and 19-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter.
As per claims 1, 10, and 19:
Step 1: Statutory Categories: Claim 1 is a system (machine). Claim 10 is a computer-implemented method (process). Claim 19 is a non-transitory computer-readable medium (manufacture).
Step 2A, Prong 1: Judicial Exception? The claims are directed towards receiving rules governing authentication from an organization, receiving an authentication query regarding a message, determining a response based on the identifier and the rules, and transmitting the response. These limitations are directed towards a mental process (evaluating an identifier against a set of rules to determine an outcome) and/or a method of organizing human activity (managing organizational rules and verifying identity/authorization). The claims effectively describe the concept of a gatekeeper checking credentials against a policy before allowing access or verifying origin.
Step 2A, Prong 2: The independent claims merely use generic computer components, i.e. “one or more processors”, “a third party-server”, “a message recipient device” as a tool to execute the rule-based authentication. There is no recitation of how the network’s efficiency is improved or how a novel hardware architecture is utilized. The claims simply automate the abstract idea of rule-checking using standard network communication. Therefore, the abstract idea is not integrated in a practical application.
Step 2B: Significantly More:
The recited hardware elements (servers, processors and recipient devices) are invoked at a high level of generality to perform their basic, routine, and conventional functions, i.e. receiving data, processing data and transmitting data. Standard network communication and data routing do not prove the requisite “inventive concept” to transform the abstract idea into a patent-eligible invention.
As per claims 2-5, 11-14 and 20:
These claims add steps for determining a “likely role”, transmitting “recommendations” for “policy modification”, generating a “guided workflow” and searching “open-source intelligence”. This limitations introduce further abstract concepts, specifically methods of organizing human activity (managing policies, guiding user workflows) and metal processes (evaluating open-source intelligence to determine a role). The do not offer a technical solution to a technical problem.
As per claims 6-7 and 15-16:
These claims add that authentication is done through a “DNS record” or by using a “public key” to authenticated a “digital signature”. While these are technical network elements, they are highly conventional. Merely applying well-known cryptographic techniques (public keys/digital signatures) or using standard network directories (DNS) for their intended purposes does not amount to “significantly more”.
As per claims 8 and 17:
These claims recite that the query includes “contextual metadata” and the rules specific “contextual conditions”. This merely broadens the scope of the data being analyzed by the abstract rule engine. Gathering an analyzing additional data points is does not amount to “significantly more”.
Claim Objections
Claims 9 and 18 objected to because of the following informalities: “metada” is misspelled and assumed to be “metadata”. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 2, 11, 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding claims 2, 11, 20, the phrase "likely role" renders the claims indefinite because the claims include elements not actually disclosed (those encompassed by "or the like"), thereby rendering the scope of the claims unascertainable. See MPEP § 2173.05(d).
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by US 10,897,485 to Goldstein.
The applied reference has a common Assignee with the instant application. Based upon the earlier effectively filed date of the reference, it constitutes prior art under 35 U.S.C. 102(a)(2). This rejection under 35 U.S.C. 102(a)(2) might be overcome by: (1) a showing under 37 CFR 1.130(a) that the subject matter disclosed in the reference was obtained directly or indirectly from the inventor or a joint inventor of this application and is thus not prior art in accordance with 35 U.S.C. 102(b)(2)(A); (2) a showing under 37 CFR 1.130(b) of a prior public disclosure under 35 U.S.C. 102(b)(2)(B) if the same invention is not being claimed; or (3) a statement pursuant to 35 U.S.C. 102(b)(2)(C) establishing that, not later than the effective filing date of the claimed invention, the subject matter disclosed in the reference and the claimed invention were either owned by the same person or subject to an obligation of assignment to the same person or subject to a joint research agreement.
Regarding claim 1, Goldstein teaches a system comprising:
one or more processors (processor 402); and one or more computer-readable media configured to store code comprising instructions (main memory 404 and instructions 424), wherein the instructions, when executed by the one or more processors, cause the one or more processors to:
receive, by a third-party server from an organization (Fig. 1, receiving email system/third party system 120), one or more rules governing authentication of messages transmitted from a named entity that is associated with the organization (col. 4, line 59: the domain owner system 110 includes a rule creator 111 that generates validation rules to allow receiving email systems, such as receiving email system 120, to verify the authenticity of emails that indicate the domain of the domain owner system 110 as the sender of the email.), the third-party server designated by the organization for managing part a namespace of the organization, the named entity identifiable by an identifier under the namespace (col. 9, line 22: the DNS record containing the targeted SPF domain specification may be hidden behind one or more DNS CNAME or NS records referring to other domains, and not managed by the targeted DNS SPF resolver);
receive, by the third-party server, an authentication query from a message recipient device that attempts to authenticate a message transmitted from a transmitter device purportedly associated with the identifier of the named entity (Fig. 3, 315: query DNS for email domain validation record);
determine, by the third-party server and based on the identifier and the one or more rules specified by the organization, a response to the authentication query (340: extract identifying information from query); and
transmit the response to the message recipient device (360: transmit target validation record), the response including information that allows the message recipient device to authenticate the message (330: authenticate email).
Regarding claim 2, Goldstein teaches the system of claim 1, wherein the instructions, when executed, further cause the one or more processors to: determine a likely role of the named entity (col. 7, line 44: . The authorization evaluator 135 accesses the deliverer/IP store 131 to determine the identity of the delivering email system 115 associated with the identifying information.); transmit a recommendation to the organization for a potential policy modification based on the likely role of the named entity; and implement the potential policy modification (col. 7, line 48: the authorization evaluator accesses the authorized deliverers list 132 to determine whether that delivering email system is an authorized delivery agent for the domain indicated in the identifying information of the DNS query.).
Regarding claim 3, Goldstein teaches the system of claim 2, wherein the instructions, when executed, further cause the one or more processors to generate a guided workflow that comprises one or more questions or suggested actions for the organization to characterize the named entity (Figs. 2 and 3: interaction diagrams. Step 345: identify delivering organization based on identifying information).
Regarding claim 4, Goldstein teaches the system of claim 2, wherein the likely role of the named entity is determined based on a recursive process (Figs. 2 and 3: interaction diagrams.).
Regarding claim 5, Goldstein teaches the system of claim 2, wherein the likely role of the named entity is determined based on one or more searches of open-source intelligence sources (col. 12, line 9: the inbound stream of DNS queries received by the authorizing DNS server 130 can be used as a source of EHLO names and IP addresses that require investigation. For a complete database all (EHLO Name, IP Address) combinations originating from legitimate email should map to a known delivering organization. Any inbound data that cannot be mapped to a known delivering organization may generally indicate a) missing legitimate values in the database).
Regarding claim 6, Goldstein teaches the system of claim 1, wherein the named entity is authenticated by the message recipient device through a DNS record associated with the named entity (Fig. 3, 325: query DNS).
Regarding claim 7, Goldstein teaches the system of claim 1, wherein the information that allows the message recipient to authenticate the message includes a public key of the named entity, the public key capable of authenticating a digital signature signed by the named entity (Example Key Delegation System. Fig. 3: 345: identifying information).
Regarding claim 8, Goldstein teaches the system of claim 1, wherein the authentication query from the message recipient includes contextual metadata of the transmitter device and the one or more rules specified by the organization specify contextual conditions for authenticating the message (fig. 3, 320: generate target domain based on email connection attributes).
Regarding claim 9, Goldstein teaches the system of claim 1, wherein the instruction to determine the response to the authentication query comprises instructions to: retrieve an authentication credential of the named entity from a domain name system (DNS) address specified in the identifier of the named entity (Step 325: query DNS); use the authentication credential to verify attested metadata of the named entity that is included in the message (340: extract identifying information); and determine, responsive to a successful verification, that the message is authenticated (350: determine if authorized), wherein the response comprises an indication that the third-party server has determined that the message is authenticated (330: validate email).
As per claims 10-18 and 19-20, this is a method and medium version of the claimed system discussed above in claims 1-9 wherein all claimed limitations have also been addressed and/or cited as set forth above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AUBREY H WYSZYNSKI whose telephone number is (571)272-8155. The examiner can normally be reached M-F 9-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/AUBREY H WYSZYNSKI/Primary Examiner, Art Unit 2434