DETAILED ACTION
This communication responsive to the Application No. 18/862,997 filed on 11/05/2024. Claims 17-34 are pending and are directed towards UPDATING DIGITAL CERTIFICATES OF AN ELEVATOR SYSTEM WITH A MOBILE TERMINAL
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 17-34 are rejected under 35 U.S.C. 103 as being unpatentable over Zhang et al. (US 20190276273 A1), hereinafter referred to as Zhang, in view of Mandava et al. (US 20200127854 A1) hereinafter referred to as Mandava.
As per claim 17, Zhang discloses a method for automatically updating a digital certificate of an elevator system, wherein the digital certificate is used for authenticating a communication established within or with the elevator system, the method comprising steps of:
connect a mobile terminal to the elevator system to enable the mobile terminal to check a time validity of the digital certificate of the elevator system; and (Receiving a sent authorized digital certificate and a sent elevator service request command, wherein the elevator service request command is generated by a personal mobile terminal, and the authorized digital certificate is acquired from a digital certificate management device by the personal mobile terminal; and verifying the authorized digital certificate in an offline mode to implement authentication of the elevator service request command, Zhang, para [0005]. Here, the authorized digital certificate obtained from a digital certificate management device is a standard digital certificate which includes a validity period, the verification step inherently involves checking whether the certificate is valid, which normally includes checking whether it is within its validity interval).
However, Zhang does not explicitly disclose the limitation:
generate a human-perceptible signal indicating a check result when the time validity of the digital certificate is expired or will expire by a predefined time limit
Mandava discloses:
generate a human-perceptible signal indicating a check result when the time validity of the digital certificate is expired or will expire by a predefined time limit (A notification to a user of the digital certificate alerting the user of the expiration time, Mandava, para [0005]. The check result is that the certificate’s validity period is near the end or expired and sending a notification based on the determined expiration time constitutes generating a human-perceptible signal indicating that result).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005]).
As per claim 18, Zhang and Mandava disclose the method according to Claim 17 wherein
Furthermore, Zhang discloses:
the elevator system includes a local network and a device connected with the local network, the device including the digital certificate, and wherein the device is identified in the check result (An authentication method for an elevator service request implemented in an elevator system where an authentication system receives a certificate and service request command from a personal mobile terminal and verifies the certificate, Zhang, para [0005]. The authentication system and relevant elevator controller are devices connected within the elevator system’s internal network. This interpreted as local network and a device connected with the local network inside the elevator system).
As per claim 19, Zhang and Mandava disclose the method according to Claim 17 wherein
Furthermore, Zhang discloses:
the mobile terminal includes the digital certificate and the mobile terminal is identified in the check result (Generated by a personal mobile terminal, and the authorized digital certificate is acquired from a digital certificate management device by the personal mobile terminal. At step S540, a response result of an elevator system to the elevator service request command is returned to the personal mobile terminal., Zhang, Abstract, para [0094]. Thus, the mobile terminal itself stores/holds the authorized digital certificate and sends it along with the elevator service request which is analogous to the mobile terminal includes the digital certificate).
As per claim 20, Zhang and Mandava disclose the method according to Claim 17 wherein
the elevator system includes a local network and a device connected with the local network, wherein the device includes the digital certificate or a different digital certificate and the mobile terminal includes the digital certificate or the different digital certificate, and (The personal mobile terminal acquires and holds an authorized digital certificate from a management device. The elevator’s authentication system uses its own trust certificate for offline verification, Zhang, para [0005]. This corresponds to having both the elevator-side device including digital certificate and the mobile terminal including a digital certificate).
Furthermore, Mandava discloses:
wherein the check result identifies the device and/or the mobile terminal when the time validity of the included one of the digital certificate and the different digital signal is expired or will expire by the predefined time limit (The system determines an expiration time of time digital certificate and when appropriate, sends a notification to a user of the digital certificate alerting the user of the expiration time, Mandava, para [0032], [0065]. Combinedly this discloses that, when the elevator system determines that either its own certificate or the mobile terminal’s certificate is near or past expiration, it can generate a human-perceptible signal/notification that inherently identifies whether the problem is with the elevator-side device or the mobile terminal).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 21, Zhang and Mandava disclose the method according to Claim 17 including
Furthermore, Mandava discloses:
request to update the digital certificate when the human-perceptible signal is generated (A renewal process for digital certificate 325 using instrumentation program code 335. In some embodiments, the renewal process may be initiated if the detected expiration date is within a threshold amount of time from a current date, Mandava, para [0066]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005]).
As per claim 22, Zhang and Mandava disclose the method according to Claim 17 including, when the time validity of the digital certificate is expired or will expire by the predefined time limit, performing steps of:
Furthermore, Mandava discloses:
generate a new digital certificate; (Initiating a renewal of the digital certificate, Mandava, para [0005]. This means causing the system to obtain a new certificate instance with a fresh validity period often a new key pair to replace the old one. This renewal process is equivalent to a new digital certificate).
send the new digital certificate with a signature request to a public key infrastructure (PKI) to authenticate the new digital certificate; (Digital certificates may be issued by a trusted third party not directly associated with the client or server computer systems, Mandava, para [0003]. Here, the digital certificates may be issued by a certificate authority (CA))
sign the new digital certificate with a private key at the PKI; (A public encryption key, an indicator of a type of encryption, and an encrypted value indicating a validity of the certificate, Mandava, para [0071]. Here, when a CA issues a digital certificate, it signs the certificate with the CA’s key so that other entities can verify it with the public key)
obtain the signed new digital certificate from the PKI; and (The information is sent using communication application module 220, or a different communication method is used, Mandava, para [0071]. Renewal involves interaction with a CA which then issues the renewed certificate back to the system)
distribute the signed new digital certificate and update the digital certificate with the signed new digital certificate (This extracted information is sent by instrumentation program code 235 to monitoring computer system 130. FIGS. 3A and 3B depict how instrumentation program code interacts with previously installed program code when a computer system receives (FIG. 3A) or sends (FIG. 3B) a digital certificate, Mandava, para [0044], [0071]. Here, the certificates are associated with particular applications or services and the system manages them so those applications continue to use valid certificates).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 23, Zhang and Mandava disclose the method according to claim 22 wherein
Furthermore, Zhang discloses:
the mobile terminal, the elevator system and/or a device of the elevator system receives the signed new digital certificate and verifies the signed new digital certificate with a public key (Personal mobile terminal acquires an authorized digital certificate from a digital certificate management device, Zhang, para [0005]. The elevator-side system interacts with a certificate management device and perform offline authentication based on authorized digital certificate).
As per claim 24, Zhang and Mandava disclose a mobile terminal
Furthermore, Zhang discloses:
for accessing and/or controlling an elevator system, the elevator system including a digital certificate for authenticating a communication established within or with the elevator system, (Receiving a sent authorized digital certificate and a sent elevator service request command, wherein the elevator service request command is generated by a personal mobile terminal, and the authorized digital certificate is acquired from a digital certificate management device by the personal mobile terminal; and verifying the authorized digital certificate in an offline mode to implement authentication of the elevator service request command, Zhang, para [0005]. Here, the authorized digital certificate obtained from a digital certificate management device is a standard digital certificate which includes a validity period, the verification step inherently involves checking whether the certificate is valid, which normally includes checking whether it is within its validity interval).
Furthermore, Mandava discloses:
wherein when the mobile terminal is connected with the elevator system the mobile terminal is adapted to check a time validity of the digital certificate and generate a human-perceptible signal indicating a check result when the time validity of the digital certificate is expired or will expire by a predefined time limit (A notification to a user of the digital certificate alerting the user of the expiration time, Mandava, para [0005]. The check result is that the certificate’s validity period is near the end or expired and sending a notification based on the determined expiration time constitutes generating a human-perceptible signal indicating that result).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 25, Zhang and Mandava disclose the mobile terminal according to Claim 24 wherein
the elevator system includes a local network and a device connected with the local network, the device and the mobile terminal including the digital certificate or a different digital certificate, and (The personal mobile terminal acquires and holds an authorized digital certificate from a management device. The elevator’s authentication system uses its own trust certificate for offline verification, Zhang, para [0005]. This corresponds to having both the elevator-side device including digital certificate and the mobile terminal including a digital certificate).
Furthermore, Mandava disclose:
wherein the mobile terminal is adapted to identify the device and/or the mobile terminal when the digital certificate and/or the different digital certificate is expired or will expire by the predefined time limit (The system determines an expiration time of time digital certificate and when appropriate, sends a notification to a user of the digital certificate alerting the user of the expiration time, Mandava, para [0032], [0065]. Combinedly this discloses that, when the elevator system determines that either its own certificate or the mobile terminal’s certificate is near or past expiration, it can generate a human-perceptible signal/notification that inherently identifies whether the problem is with the elevator-side device or the mobile terminal).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 26, Zhang and Mandava disclose the mobile terminal according to Claim 24 wherein
Furthermore, Mandava discloses:
the mobile terminal requests to update the digital certificate when generating the human-perceptible signal (A renewal process for digital certificate 325 using instrumentation program code 335. In some embodiments, the renewal process may be initiated if the detected expiration date is within a threshold amount of time from a current date, Mandava, para [0066]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 27, Zhang and Mandava disclose the mobile terminal according Claim 24 wherein, when the time validity of the digital certificate is expired or will expire by the predefined time limit, the mobile terminal:
Furthermore, Mandava discloses:
generates a new digital certificate; (Initiating a renewal of the digital certificate, Mandava, para [0005]. This means causing the system to obtain a new certificate instance with a fresh validity period often a new key pair to replace the old one. This renewal process is equivalent to a new digital certificate).
sends the new digital certificate with a signature request to a public key infrastructure (PKI) for authenticating the new digital certificate; (Digital certificates may be issued by a trusted third party not directly associated with the client or server computer systems, Mandava, para [0003]. Here, the digital certificates may be issued by a certificate authority (CA))
obtains a signed new digital certificate from the PKI; and (The information is sent using communication application module 220, or a different communication method is used, Mandava, para [0071]. Renewal involves interaction with a CA which then issues the renewed certificate back to the system)
distributes the signed new digital certificate to the elevator system and updates the digital certificate with the signed new digital certificate (This extracted information is sent by instrumentation program code 235 to monitoring computer system 130. FIGS. 3A and 3B depict how instrumentation program code interacts with previously installed program code when a computer system receives (FIG. 3A) or sends (FIG. 3B) a digital certificate, Mandava, para [0044], [0071]. Here, the certificates are associated with particular applications or services and the system manages them so those applications continue to use valid certificates).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 28, Zhang and Mandava disclose the mobile terminal according to Claim 27 wherein
Furthermore, Zhang discloses:
the mobile terminal verifies the signed new digital certificate with a public key saved in the mobile terminal (Personal mobile terminal acquires an authorized digital certificate from a digital certificate management device, Zhang, para [0005]. The elevator-side system interact with a certificate management device and perform offline authentication based on authorized digital certificate).
As per claim 29, Zhang discloses an elevator system including a digital certificate for authenticating a communication established within or with the elevator system, wherein a mobile terminal connected to the elevator system checks a time validity of the digital certificate, and (Receiving a sent authorized digital certificate and a sent elevator service request command, wherein the elevator service request command is generated by a personal mobile terminal, and the authorized digital certificate is acquired from a digital certificate management device by the personal mobile terminal; and verifying the authorized digital certificate in an offline mode to implement authentication of the elevator service request command, Zhang, para [0005]. Here, the authorized digital certificate obtained from a digital certificate management device is a standard digital certificate which includes a validity period, the verification step inherently involves checking whether the certificate is valid, which normally includes checking whether it is within its validity interval).
However, Zhang does not explicitly disclose the limitation:
the elevator system generates a human-perceptible signal indicating a check result when the time validity of the digital certificate is expired or will expire by a predefined time limit
Mandava discloses:
the elevator system generates a human-perceptible signal indicating a check result when the time validity of the digital certificate is expired or will expire by a predefined time limit (A notification to a user of the digital certificate alerting the user of the expiration time, Mandava, para [0005]. The check result is that the certificate’s validity period is near the end or expired and sending a notification based on the determined expiration time constitutes generating a human-perceptible signal indicating that result).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 30, Zhang and Mandava disclose the elevator system according to Claim 29 wherein the elevator system includes a local network and a device connected with the local network, the device and the mobile terminal including the digital certificate or a different digital certificate, and (The personal mobile terminal acquires and holds an authorized digital certificate from a management device. The elevator’s authentication system uses its own trust certificate for offline verification, Zhang, para [0005]. This corresponds to having both the elevator-side device including digital certificate and the mobile terminal including a digital certificate).
Furthermore, Mandava discloses:
wherein the mobile terminal is adapted to access and/or control the elevator system (The system determines an expiration time of time digital certificate and when appropriate, sends a notification to a user of the digital certificate alerting the user of the expiration time, Mandava, para [0032], [0065]. Combinedly this discloses that, when the elevator system determines that either its own certificate or the mobile terminal’s certificate is near or past expiration, it can generate a human-perceptible signal/notification that inherently identifies whether the problem is with the elevator-side device or the mobile terminal).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 31, Zhang and Mandava disclose the elevator system according to Claim 29 wherein
Furthermore, Mandava discloses:
the elevator system requests to update the digital certificate when generating the human-perceptible signal (A renewal process for digital certificate 325 using instrumentation program code 335. In some embodiments, the renewal process may be initiated if the detected expiration date is within a threshold amount of time from a current date, Mandava, para [0066]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 32, Zhang and Mandava disclose the elevator system according to Claim 29 including a controller that:
Furthermore, Mandava discloses:
generates a new digital certificate and a signature request; (Initiating a renewal of the digital certificate, Mandava, para [0005]. This means causing the system to obtain a new certificate instance with a fresh validity period often a new key pair to replace the old one. This renewal process is equivalent to a new digital certificate).
sends the new digital certificate with the signature request to a public key infrastructure (PKI) for authenticating the new digital certificate; (Digital certificates may be issued by a trusted third party not directly associated with the client or server computer systems, Mandava, para [0003]. Here, the digital certificates may be issued by a certificate authority (CA))
obtains a signed new digital certificate from the PKI; and (The information is sent using communication application module 220, or a different communication method is used, Mandava, para [0071]. Renewal involves interaction with a CA which then issues the renewed certificate back to the system)
distributes the signed new digital certificate to the elevator system and/or the mobile terminal to update the digital certificate with the signed new digital certificate (This extracted information is sent by instrumentation program code 235 to monitoring computer system 130. FIGS. 3A and 3B depict how instrumentation program code interacts with previously installed program code when a computer system receives (FIG. 3A) or sends (FIG. 3B) a digital certificate, Mandava, para [0044], [0071]. Here, the certificates are associated with particular applications or services and the system manages them so those applications continue to use valid certificates).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005])
As per claim 33, Zhang and Mandava disclose the elevator system according to Claim 32 wherein
Furthermore, Zhang discloses:
the elevator system verifies the signed new digital certificate with a public key that is saved in the elevator system (Personal mobile terminal acquires an authorized digital certificate from a digital certificate management device, Zhang, para [0005]. The elevator-side system interacts with a certificate management device and perform offline authentication based on authorized digital certificate).
As per claim 34, Zhang and Mandava disclose a computer program comprising computer-readable instructions,
Furthermore, Mandava discloses:
the computer program stored on a non-transitory computer-readable medium, the instructions when executed by a processor cause an elevator system and a mobile terminal to carry out the steps of the method according to Claim 17 (A processing unit may also be configured to execute program instructions from any suitable form of non-transitory computer-readable media to perform specified operations, Mandava, para [0077]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Zhang with Mandava by elevator service request and offline authentication of the elevator service request (Zhang) and tracking digital certificate using instrumentation (Mandava). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Zhang and Mandava in order to ensure safe access of a mobile device to an elevator (See Mandava, para [0005]).
Conclusion
Any inquiry concerning this communication or earlier communications from the
examiner should be directed to RAGHAVENDER CHOLLETI whose telephone number is (703) 756-1065. The examiner can normally be reached Monday - Thursday 8AM-5PM EST & Friday variable.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s
supervisor, RUPAL DHARIA can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be
obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service
Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Respectfully Submitted
/RAGHAVENDER NMN CHOLLETI/Examiner, Art Unit 2492
/RUPAL DHARIA/Supervisory Patent Examiner, Art Unit 2492