DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Objections
Examiner notes that the claims have been reviewed for compliance with 35 U.S.C. §101 (as set forth in MPEP 2106) and determined to be statutory.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 12 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 12 is directed to user equipment that includes a processor such that the processor transmits a token to the processor over a network. In other words, the processor of the user equipment transmits a token to itself over a network, which renders the claims indefinite because it is generally unclear how the user equipment processor transmits a token to itself. It appears as though functions steps performed by other elements of the system (i.e., Authorization server 304 or resource server 306 of Figure 3) are attributed to the user equipment (e.g., client 302 of Figure 3) in claim 12. For the purposes of examination, the functional steps of claim 12 will be addressed using prior art below since it is generally unclear from the claims which device is intended to perform each functional step from claim 12. However, it is clear that the claimed user equipment does not perform each of the functional steps from claim 12. Specifically, Applicant’s specification makes it clear that the client 402 sends the token to the resource server 408 in step 408 of Figure 4 ([0065]). The resource server 408 forwards this token to the authorization server 404 in step 410 of Figure 4 ([0066]). Therefore, resource server 408 and authorization server 404 each receive the token from the client/UE. The authorization server 404 decodes the token in step 412 of Figure 4 ([0067]). The authorization server 404 does not correspond to the user equipment as required by the claim. The authorization server 404 validates the token and sends success/failure responses to the resource server 406 based on that validation in steps 412 and 414 of Figure 4 ([0067]-[0068]). The resource server 408 sends a service response to the client 402 in step 418 ([0070]). Therefore, it is clear that all the functional steps performed in claim 12 are not performed by a single entity such as the user equipment as required by the claims.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 5, 7, 11-13 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Lebron, U.S. Publication No. 2013/0318348.
Referring to claim 1, Lebron discloses transaction processing that includes a server 102 (Figure 1) that includes a processor and memory ([0052] & [0056]-[0057]), which meets the limitation of a system comprising a processor, and a memory operatively coupled with the processor, wherein said memory stores instructions which, when executed by the processor cause the processor to. Server 102 receives an encrypted transaction token from client 101 ([0044]: client 101 reads on the claimed computing device; token transmission reads on the claimed NF request), which meets the limitation of receive a token from one or more users via a computing device, wherein the token is based on a network function (NF) request generated by the one or more users. Server 102 decrypts the received encrypted transaction token and verifies the transaction token using digital signature verification ([0045]), which meets the limitation of decode the token received from the one or more users and determine if the decoded token is valid. If the token is verified, server 102 sends the decrypted transaction token to a service provider 104 ([0045]), which meets the limitation of in response to a positive determination, send the decoded token to a resource server within a predetermined period. The service provider 104 sends a response to server 102 ([0046]: response reads on the claimed token validation request), which meets the limitation receive a token validation request from the resource server within the predetermined time. Server 102 invokes an authorization result page component that is provided to the client 101 ([0047]-[0048]) indicating the granting of access to resources ([0018]), which meets the limitation of generate one or more requested services for the one or more users via the resource server within the predetermined period.
Referring to claim 5, Lebron discloses that the server 102 sends the decrypted transaction token to a service provider 104 along with additional information such as information related to the transaction ([0045]: additional information reads on the claimed network function instance identification), which meets the limitation of wherein the processor is to send a network function instance identification (NFinstanceID) along with the decoded token to the resource server.
Referring to claim 7, Lebron discloses transaction processing that includes a server 102 (Figure 1) that includes a processor and memory ([0052] & [0056]-[0057]), which meets the limitation of a processor. Server 102 receives an encrypted transaction token from client 101 ([0044]: client 101 reads on the claimed computing device; token transmission reads on the claimed NF request), which meets the limitation of receiving, by a processor associated with a system, a token from one or more users via a computing device, wherein the token is based on a network function (NF) request generated by the one or more users. Server 102 decrypts the received encrypted transaction token and verifies the transaction token using digital signature verification ([0045]), which meets the limitation of decoding, by the processor, the token received from the one or more users and determine if the decoded token is valid. If the token is verified, server 102 sends the decrypted transaction token to a service provider 104 ([0045]), which meets the limitation of in response to a positive determination, sending, by the processor, the decoded token to a resource server within a predetermined period. The service provider 104 sends a response to server 102 ([0046]: response reads on the claimed token validation request), which meets the limitation receiving, by the processor, a token validation request from the resource server within the predetermined time. Server 102 invokes an authorization result page component that is provided to the client 101 ([0047]-[0048]) indicating the granting of access to resources ([0018]), which meets the limitation of generating, by the processor, one or more requested services for the one or more users via the resource server within the predetermined period.
Referring to claim 11, Lebron discloses that the server 102 sends the decrypted transaction token to a service provider 104 along with additional information such as information related to the transaction ([0045]: additional information reads on the claimed network function instance identification), which meets the limitation of sending, by the processor, a network function instance identification (NFinstanceID) along with the decoded token to the resource server.
Referring to claim 12, Lebron discloses transaction processing that includes a server 102 (Figure 1) that includes a processor and memory ([0052] & [0056]-[0057]), which meets the limitation of a user equipment comprising one or more processors communicatively coupled to a processor associated with a system, wherein the one or more processors are coupled with a memory, and wherein said memory stores instructions which when executed by the one or more processors cause the one or more processors to. Server 102 receives an encrypted transaction token from client 101 ([0044]: client 101 reads on the claimed computing device; token transmission reads on the claimed NF request), which meets the limitation of transmit a token to the processor via a network, wherein the token is based on a network function (NF) request generated by the one or more users, wherein the processor is configured to receive the token from the UE. Server 102 decrypts the received encrypted transaction token and verifies the transaction token using digital signature verification ([0045]), which meets the limitation of decode the token and determine if the decoded token is valid. If the token is verified, server 102 sends the decrypted transaction token to a service provider 104 ([0045]), which meets the limitation of in response to a positive determination, send the decoded token to a resource server within a predetermined period. The service provider 104 sends a response to server 102 ([0046]: response reads on the claimed token validation request), which meets the limitation receive a token validation request from the resource server within the predetermined time. Server 102 invokes an authorization result page component that is provided to the client 101 ([0047]-[0048]) indicating the granting of access to resources ([0018]), which meets the limitation of generate one or more requested services for the UE via the resource server within the predetermined period.
Referring to claim 13, Lebron discloses transaction processing that includes a server 102 (Figure 1) that includes a processor and memory ([0052] & [0056]-[0057]), which meets the limitation of a processor. Server 102 receives an encrypted transaction token from client 101 ([0044]: client 101 reads on the claimed computing device; token transmission reads on the claimed NF request), which meets the limitation of receive a token from one or more users via a computing device, wherein the token is based on a network function (NF) request generated by the one or more users. Server 102 decrypts the received encrypted transaction token and verifies the transaction token using digital signature verification ([0045]), which meets the limitation of decode the token received from the one or more users and determine if the decoded token is valid. If the token is verified, server 102 sends the decrypted transaction token to a service provider 104 ([0045]), which meets the limitation of in response to a positive determination, send the decoded token to a resource server within a predetermined period. The service provider 104 sends a response to server 102 ([0046]: response reads on the claimed token validation request), which meets the limitation receive a token validation request from the resource server within the predetermined time. Server 102 invokes an authorization result page component that is provided to the client 101 ([0047]-[0048]) indicating the granting of access to resources ([0018]), which meets the limitation of generate one or more requested services for the one or more users via the resource server within the predetermined period.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 2, 8 are rejected under 35 U.S.C. 103 as being unpatentable over Lebron, U.S. Publication No. 2013/0318348, in view of Mansour, U.S. Publication No. 2012/0216265. Referring to claim 2, Lebron discloses that if the token verification fails, server 102 notifies the client 101 ([0045]), which meets the limitation of wherein the processor is to, in response to a negative determination, send a failure response to the [resource server].
Lebron does not disclose that the server 102 notifies the service provider 104. Mansour discloses that responsive to an authentication failure, an authenticator may notify the user and the service provider ([0046]), which meets the limitation of wherein the processor is to, in response to a negative determination, send a failure response to the resource server. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the server 102 to have notified the server provider 104 if the token verification fails because Mansour discloses that notifications to service providers represent one of a finite number of possible forms of notifications that can be implemented by those having ordinary skill in the art with a reasonable expectation of success in response authentication failures (Mansour: [0046]).
Referring to claim 8, Lebron discloses that if the token verification fails, server 102 notifies the client 101 ([0045]), which meets the limitation of sending, by the processor, a failure response to the [resource server] in response to a negative determination.
Lebron does not disclose that the server 102 notifies the service provider 104. Mansour discloses that responsive to an authentication failure, an authenticator may notify the user and the service provider ([0046]), which meets the limitation of sending, by the processor, a failure response to the resource server in response to a negative determination. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the server 102 to have notified the server provider 104 if the token verification fails because Mansour discloses that notifications to service providers represent one of a finite number of possible forms of notifications that can be implemented by those having ordinary skill in the art with a reasonable expectation of success in response authentication failures (Mansour: [0046]).
Claims 3, 9 are rejected under 35 U.S.C. 103 as being unpatentable over Lebron, U.S. Publication No. 2013/0318348, in view of Watanabe, U.S. Publication No. 2002/0069361.
Referring to claim 3, Lebron discloses that a security token includes the time that the security token will expire ([0028]). However, Lebron does not disclose that the transaction token includes an expiration time. Watanabe discloses a service provider receiving a certificate from an IDA ([0641]) wherein the certificate includes an expiration date ([0641]) and the service provider checks the expiration date prior to starting a transaction such that if the expiration date has been reached, the service provider sends a request to the IDA ([0651]: service provider sends a request to the device that sent the certificate; as it pertains to Lebron, service provider 104 receives the token from server 102; Examiner notes that the name of the response represents non-functional descriptive material that does not receive patentable weight. See MPEP 2111.04-2111.05), which meets the limitation of wherein the processor is to receive a forbidden error response from the resource server upon an expiry of the predetermined period. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the transaction token of Lebron to have included an expiration in order to limit the amount of time that token is valid as suggested by Watanabe ([0176]).
Referring to claim 9, Lebron discloses that a security token includes the time that the security token will expire ([0028]). However, Lebron does not disclose that the transaction token includes an expiration time. Watanabe discloses a service provider receiving a certificate from an IDA ([0641]) wherein the certificate includes an expiration date ([0641]) and the service provider checks the expiration date prior to starting a transaction such that if the expiration date has been reached, the service provider sends a request to the IDA ([0651]: service provider sends a request to the device that sent the certificate; as it pertains to Lebron, service provider 104 receives the token from server 102; Examiner notes that the name of the response represents non-functional descriptive material that does not receive patentable weight. See MPEP 2111.04-2111.05), which meets the limitation of receiving, by the processor, a forbidden error response from the resource server upon an expiry of the predetermined period. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the transaction token of Lebron to have included an expiration in order to limit the amount of time that token is valid as suggested by Watanabe ([0176]).
Claims 4, 10 are rejected under 35 U.S.C. 103 as being unpatentable over Lebron, U.S. Publication No. 2013/0318348, in view of Watanabe, U.S. Publication No. 2002/0069361, and further in view of Kuperman, U.S. Publication No. 2018/0278624. Referring to claim 4, Lebron, as modified by Watanabe, does not disclose that a new request is received from the user based on the received response from the service provider.
Kuperman discloses a user presenting a new request that includes a new token in response to receiving a challenge ([0095]), which meets the limitation of wherein the processor is to receive an access request to the resource server from the one or more users based on the forbidden error response. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the users of Lebron to have sent new requests in response to the notification from the service provider in order to provide the user with an additional attempt to authenticate as suggested by Kuperman ([0095]).
Referring to claim 10, Lebron, as modified by Watanabe, does not disclose that a new request is received from the user based on the received response from the service provider.
Kuperman discloses a user presenting a new request that includes a new token in response to receiving a challenge ([0095]), which meets the limitation of receiving, by the processor, an access request to the resource server from the one or more users based on the forbidden error response. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the users of Lebron to have sent new requests in response to the notification from the service provider in order to provide the user with an additional attempt to authenticate as suggested by Kuperman ([0095]).
Claims 6 are rejected under 35 U.S.C. 103 as being unpatentable over Lebron, U.S. Publication No. 2013/0318348, in view of Hind, U.S. Patent No. 6,980,660.
Referring to claim 6, Lebron discloses that the transaction token is encrypted using the public key of server 102 such that the encrypted transaction token can only be decrypted using the private key of server 102 which is also used to digital sign message data ([0040]), which meets the limitation of wherein [the processor] is to generate a key based on the token received from the one or more users and use the key for decoding the token and processing the token validation request. However, Lebron does not specify that server 102 generates the private key.
Hind discloses devices generating their own public/private key pairs (Col. 9, lines 63-65), which meets the limitation of wherein the processor is to generate a key based on the token received from the one or more users and use the key for decoding the token. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for server 102 to have generated its’ own private key in order to protect the private key by ensuring that the private key is never transmitted as suggested by Hind (Col. 9, lines 63-67).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Mahoney, U.S. Publication No. 2023/0396438, discloses the utilization of access tokens to provide services from a service provider.
Duchastel, U.S. Publication No. 2022/0006800, discloses that utilization of tokens to provide access to remote resources.
Kruse, U.S. Patent No. 10,243,945, discloses that utilization of identity certificates to provide access to resources.
Yabe, U.S. Publication No. 2018/0278603, discloses the utilization of access tokens to provide services from a service provider.
Herter, U.S. Publication No. 2014/0282880, utilization of tokens to provide resources from a service provider.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BENJAMIN E LANIER whose telephone number is (571)272-3805. The examiner can normally be reached M-Th: 5:30-4:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at 5712705143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BENJAMIN E LANIER/ Primary Examiner, Art Unit 2437