DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The amendment filed 06/01/2026 has been entered. Claims 1, 3-5, 10 and 13-20 have been amended. No Claims have been newly added. No Claims has been/remains canceled. Claims 1-20 remain pending in the application.
Applicant amendments to the Specification have overcome the objections previously set forth in the Non-Final Office Action mailed on 03/25/2026. The objection has been withdrawn in view of the amended Specification.
Applicant amendments to the Claims have overcome the objections previously set forth in the Non-Final Office Action mailed on 03/25/2026. The objection has been withdrawn in view of the amended Claims.
Response to Arguments
Regarding Applicant’s arguments, on page 9-12 of the remark filed on 06/01/2026, on the newly amended limitations of independent Claims 1: “generating, by the authenticator device, a one-time passcode (OTP) by applying a function to the data including a token received from the client device; receiving, by the authenticator device that generated the OTP based on the token received from the client device, the OTP from the client device over an unsecure channel that is unencrypted for exchanging unencrypted data; and”, arguments are not persuasive.
Applicant argues on Pages 9-10 that the cited references fail to teach generating, by the authenticator device, a one-time passcode (OTP) by applying a function to the data including a token received from the client device; receiving, by the authenticator device that generated the OTP based on the token received from the client device, the OTP from the client device over an unsecure channel that is unencrypted for exchanging unencrypted data. Applicant’s interpretation of the reference has been noted; however, examiner respectfully disagrees. Jibrin teaches on Par. (0004) a one-way function is applied to the token message and data and on Par. (0006) describing a one-way function is used with the OTP generator and is outputted. Jibrin teaches on Par. (0107 and 0112-0113) a one-way function is applied and the device receives the token message and data that is associated with the one-way function. Akamine then teaches on Par. (0067) a transmitting and receiving of a one-time password to a terminal device based on a password received. Akamine on Par. (0075) teaches packets or data transmitted that is not encrypted. Therefore, the rejection is maintained.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 9, 18 and 20, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) further in view of Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”)
In regards to Claim 1, Jibrin teaches a method comprising: establishing a secure channel between an authenticator device and a client device; (Figure 1A labels 104,110, 106; secure channel between authenticator device (server 106) and client device (client device 104)), (Par. (0071, 0107); establishing connection between client device and server and communication between server and client))
generating, by the authenticator device, a one-time passcode (OTP) by applying a function to data including a token received from the client device; (Par. (0009-0010); authenticator device (server) receives token from the client device (receives token OTP string of individual/user file) and generates a OTP), (Par. (0110); authenticator device (server) receives OTP string and token then generate OTP)), (Par. (0101-0108 and 1010); authenticator device (server) receives token OTP string of client then generates OTP)), (Par. (0006, 0107 and 0112-0113); one-way function applied to token message and data then received from device))
storing the OTP in a memory of the authenticator device; (Par. (0113); authenticator device (server) storing OTPs)), (Figure 1A labels 106, 130 and 114; memory of authenticator device (memory of server corresponding to OTP generator))
transmitting the OTP to the client device over the secure channel; (Par. (0107); transmitting OTP to client device via a secure connection))
receiving, by the authenticator device that generated the OTP based on the token received from the client device, the OTP from the client device (Par. (0110); authenticator device (server) receives OTP string and token that generated OTP))
enabling access to a secure resource in response to determining that the OTP received from the client device matches the OTP stored in the memory of the authenticator device. (Par. (0030 and 0033); enabling access (authorized benefits for period of time) in response to determining that the OTP received from the client device matches the OTP stored (comparing one-time passcode sent from client device (individual) to one-time passcode generated by the authenticator device (server)) (Par. (0073); in response to determining that the OTP received from the client device matches the OTP stored in the memory of the authenticator device (comparing the token OTP received to the server OTP), (Par. (0076); authenticator device (server) compares OTP received from user to OTP stored in server)), (Par. (0034, 0079, 0084, 0096); enabling access to a secure resource (access to digital systems corresponding to one-time passcode and after comparing OTP releasing/receiving benefits))
Jibrin does not explicitly teach over an unsecure channel that is unencrypted for exchanging unencrypted data; and
Wherein Akamine teaches over an unsecure channel; and (Par. (0067); client device (portable terminal) receives OTP over unsecure channel (receives one-time password over BLE) communications), (Par. (0018-0020); client device (portable terminal of user corresponds to portable computer)), (Par. (0075); data is transmitted that is unencrypted)) (Examiner Note: In the instant application the specification on Par. (0027) defines unsecure channel to be a BLE channel. Therefore it will be broadly and reasonably interpreted as such))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin to incorporate the teaching of Akamine to utilize the above feature because of the analogous concept of authentication based on one-time passwords between client and servers, with the motivation of authenticating a device based on the unsecure or BLE connection to grant access in a limited time and state and notify devices a particular presence. (Akamine Par. (0052))
In regards to Claim 9, the combination of Jibrin and Akamine teach the method of claim 1, Jibrin further teaches the method of claim 1, further comprising: associating an expiration time with the OTP that is stored in the memory; and (Par. (0058); expiration time of OTP), (Par. (0113); that is stored in the memory (authenticator device (server) storing OTPs)), (Figure 1A labels 106, 130 and 114; that is stored in the memory (memory of server corresponding to OTP generator))
invalidating or removing the OTP after the expiration time. (Par. (0113); invalidating the OTP after the expiration time (OTP no longer valid after time window elapses))
In regards to Claims 18 and 20, claims 18 and 20 recites similar limitation to independent claim 1 and the teachings of Jibrin and Akamine address all the limitations discussed in independent claim 1 and are thereby rejected under the same grounds.
Claim(s) 2, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Mumma et al. (U.S Pub. No. 20200045038, hereinafter referred to as “Mumma”)
In regards to Claim 2, the combination of Jibrin and Akamine do not explicitly teach verifying that the token received from the client device is valid, wherein the OTP is generated in response to determining that the token is valid.
Wherein Mumma teaches verifying that the token received from the client device is valid, (Par. (0013-0015); user receives token and verifies token)
wherein the OTP is generated in response to determining that the token is valid. (Par. (0013-0015); generating the OTP based on received and verified token))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Mumma to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of creating a two-step verification to regulate access to applications based on the OTP and a physical token in conjunction to make things easier for users and less frustration for immediate access. (Mumma Par. (0003-0004))
Claim(s) 3 is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Radu et al. (U.S Pub. No. 20200250669, hereinafter referred to as “Radu”)
In regards to Claim 3, the combination of Jibrin and Akamine teach the method of claim 1, Jibrin further teaches the method of claim 1, further comprising: determining, by the authenticator device, whether one or more valid OTPs are stored in the memory; and (Par. (0058); determining, by the authenticator device, whether one or more valid OTPs (server determines expiration time of OTP), (Par. (0113); whether one or more valid OTPs are stored in the memory (authenticator device (server) storing OTPs)), (Par. (0113); determining, by the authenticator device, whether one or more valid OTPs (OTP no longer valid after time window elapses by server))
Jibrin and Akamine do not explicitly teach in response to determining that one or more valid OTPs are stored in the memory of the authenticator device, initiating scanning the unsecure channel for an OTP message.
Wherein Radu teaches in response to determining that one or more valid OTPs are stored in the memory of the authenticator device, (Par. (0024 and 0035); verifier comparing OTP and verifier with OTP authentication), (Par. (0045-0046); determining that one or more valid OTPs are stored in the memory of the authenticator device (authenticator device (verifier) splits OTP into portions i.e “witness value OTP” and send OTP to second component of verifier; the OTP is then compared to be equal to OTP stored)), (Par. (0036); valid OTPs are stored in the memory of the authenticator device (verifier with components))
initiating scanning the unsecure channel for an OTP message. (Par. (0045-0047); scanning an unsecure channel (determining and verifying untrusted channel) for an OTP message (verifier transmits authentication message confirming untrusted channel associated with OTP))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Radu to utilize the above feature because of the analogous concept of one-time passwords being communicated in untrusted channels, with the motivation of utilizing one-time passwords transmitted to verifier servers to create a face to face interaction with financial institutions and implementing multi-factor authentication to confirm identities and establish a trusted exchange and channel between consumer and verifier on mobile devices. (Radu Par. (0021-0024))
Claim(s) 4, 17 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Ishida et al. (U.S Pub. No. 20100017860, hereinafter referred to as “Ishida”)
In regards to Claim 4, the combination of Jibrin and Akamine do not explicitly teach in response to determining that the token received from the client device is invalid, generating a dummy OTP that cannot be used to access the secure resource and transmitting the dummy OTP to the client device.
Wherein Ishida teaches in response to determining that the token received from the client device is invalid, (Par. (0076-0078); after a time period has elapsed for the OTP)
generating a dummy OTP that cannot be used to access the secure resource and transmitting the dummy OTP to the client device. (Par. (0076-0078); generating dummy password when time is elapsed), (Par. (0091); transmitting the dummy password to client))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Ishida to utilize the above feature because of the analogous concept of token communication through secure channels, with the motivation of enhancing user authentication by identifying leaks and illegal uses of device to prevent risks by using one-time passwords. (Ishida Par. (0009-0013))
In regards to Claim 17, the combination of Jibrin and Akamine teach the method of claim 1, Jibrin further teaches the method of claim 1, wherein the OTP is generated prior to the client device receiving a request to access the secure resource, further comprising: (Par. (0075-0076); first and second OTP generators produce OTPs before server receives request)), (Par. (0030 and 0033); access the secure resource (authorized benefits for period of time))
Jibrin and Akamine do not explicitly teach generating, by the authenticator device, a random token at the same time as the OTP; associating the random token with the OTP in the memory of the authenticator device; and transmitting the random token to the client device over the secure channel.
Wherein Ishida teaches generating, by the authenticator device, a random token at the same time as the OTP (Par. (0055-0057, 0063); fixed password and random password generated at startup))
associating the random token with the OTP in the memory of the authenticator device; and (Par. (0055-0057, 0063); fixed password and random password processed together))
transmitting the random token to the client device over the secure channel. (Par. (0076-0078); random password transmitted to client))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Ishida to utilize the above feature because of the analogous concept of token communication through secure channels, with the motivation of enhancing user authentication by identifying leaks and illegal uses of device to prevent risks by using one-time passwords. (Ishida Par. (0009-0013))
In regards to Claim 19, the combination of Jibrin and Akamine do not explicitly teach in response to determining that the token received from the client device is invalid, generating a dummy OTP in a predefined format that enables the client device to determine that access has not been granted, and transmitting the dummy OTP to the client device.
Wherein Ishida teaches in response to determining that the token received from the client device is invalid, (Par. (0076-0078); after a time period has elapsed for the OTP)
generating a dummy OTP in a predefined format that enables the client device to determine that access has not been granted, and transmitting the dummy OTP to the client device. (Par. (0076-0078); generating dummy password when time is elapsed), (Par. (0091); transmitting the dummy password to client)), (Par. (0078); a dummy OTP in a predefined format (dummy OTP with fixed format of time))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Ishida to utilize the above feature because of the analogous concept of token communication through secure channels, with the motivation of enhancing user authentication by identifying leaks and illegal uses of device to prevent risks by using one-time passwords. (Ishida Par. (0009-0013))
Claim(s) 5, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Liao et al. (U.S Pub. No. 20160219012, hereinafter referred to as “Liao”)
In regards to Claim 5, the combination of Jibrin and Akamine teach the method of claim 1, Jibrin further teaches the method of claim 1, wherein the secure channel is established based on the client device being within a first threshold proximity to the authenticator device, and (Par. (0011, 0113); the secure channel is established( location of token and device to determine vitality verification)), (Par. (0064-0066, 0175); the secure channel is established based on a first threshold proximity (device with GPS location is satisfied to determine verification corresponding to coordinates to validated communication))
Jibrin and Akamine do not explicitly teach wherein the OTP is received from the client device over the unsecure channel based on the client device being within a second threshold proximity to the authenticator device, the second threshold proximity being closer than the first threshold proximity.
Wherein Liao teaches wherein the OTP is received from the client device over the unsecure channel based on the client device being within a second threshold proximity to the authenticator device, the second threshold proximity being closer than the first threshold proximity. (Par. (0071); OTP is received from the client device over the unsecure channel (token broadcasted over Bluetooth channel) based on the client device being within a second threshold proximity to the authenticator device (second device is within threshold range with first device and proximity platform 109)), (Figure 2 label 109 and 201; authenticator device (proximity platform 109) with authentication module) (Figure 6 labels 807 and 605; user 605 is closer proximity than user 80
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Liao to utilize the above feature because of the analogous concept of verifying identity using trusted and untrusted channels of communications, with the motivation of using proximity and geographical locations to assists users in tracing and identifying rightful parties for communication. (Liao Par. (0001))
Claim(s) 6, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Suwald et al. (U.S Pub. No. 20200167539, hereinafter referred to as “Suwald”)
In regards to Claim 6, the combination of Jibrin and Akamine teach the method of claim 1, Jibrin further teaches the method of claim 1,wherein the secure channel comprises a first protocol, and (Par. (0071, 0107); the secure channel (establishing connection between client device and server and communication between server and client)), (Par. (0138 and 0146); first protocol (SMS protocol and other protocols corresponding to device and WAN, LAN between client and server))
Jibrin and Akamine do not explicitly teach wherein the unsecure channel comprises a second protocol.
Wherein Suwald teaches wherein the unsecure channel comprises a second protocol. (Par. (0035); unsecure channel (BLE) with second protocol (second communication channel LAN))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Suwald to utilize the above feature because of the analogous concept of token verification of mobile devices on secure and unsecure channels, with the motivation of using token verification based on various protocols on untrusted channels to use location and proximity to identify a first party based on access points on various area networks to authorize transaction more effectively based on secrets and location and indication factors. (Suwald Par. (0009-0011 and 0035))
Claim(s) 7, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Schock et al. (U.S Pub. No. 20200351619, hereinafter referred to as “Schock”)
In regards to Claim 7, the combination of Jibrin and Akamine do not explicitly teach wherein the secure channel is established automatically in response to detecting a signal from the client device and verification of one or more access conditions.
Wherein Schock teaches wherein the secure channel is established automatically in response to detecting a signal from the client device and verification of one or more access conditions. (Par. (0081-0082); secure channel is established automatically (when user 1 arrives at specified location automatically broadcasting signal for wireless connection)) (Par. (0006-0007); detecting a signal from client electronic device based on verification of one or more access conditions (detecting proximity to physical location) then establishing communication channel), (Par. (0014-0015 and 0023); verification of one or more access conditions (determining client electronic device is in proximity by comparing distances))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Schock to utilize the above feature because of the analogous concept of authentication of mobile devices using passwords and shared secret on established secure channel, with the motivation of regulating access based on verifying identities and permitting authorized entities based on location to be permitted entry. By using an alert or signal as access condition the system matches identities and determine authenticity from fraudulent users. (Schock Par. (0003-0008))
Claim(s) 8, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Lourembam et al. (U.S Pub. No. 20220030419, hereinafter referred to as “Lourembam”)
In regards to Claim 8, the combination of Jibrin and Akamine do not explicitly teach wherein the OTP is transmitted by the client device over the unsecure channel in response to receiving a user request by the client device to access the secure resource, further comprising: transmitting a message to client device indicating that the access to the secure resource has been enabled.
Wherein Lourembam teaches wherein the OTP is transmitted by the client device over the unsecure channel in response to receiving a user request by the client device to access the secure resource, further comprising: (Par. (0033, 0056, 0113); wherein the OTP is transmitted by the client device over the unsecure channel (OTP exchange between two wireless devices over unsecure channel (BLE)), (Par. (0054 and 0056); in response to receiving a user request by the client device to access the secure resource (wireless device allowing request then exchange of OTP))
transmitting a message to client device indicating that the access to the secure resource has been enabled. (Par. (0036 and 0077); transmitting a notification message when access is granted))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Lourembam to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of determined based on unsecure channels a successful of device pairing and to prevent attackers or access to victim device on unsecure channel by using one-time passwords to create consent and protect data of user. By transmitting alerts and notifications the user can be aware of successful authentication and allow the system to determine rightful permissions and access when connecting. (Lourembam Par. (0001-0002 and 0007-0009))
Claim(s) 10, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”), Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) and Patni et al. (U.S Pub. No. 20190213585, hereinafter referred to as “Patni”) further in view of Pearse et al. (U.S Pub. No. 20250219839, hereinafter referred to as “Pearse”)
In regards to Claim 10, the combination of Jibrin and Akamine do not explicitly teach wherein the OTP is received from the client device after the expiration time, further comprising: preventing the access to the secure resource; and transmitting a message to client device indicating that the access to the secure resource has been prevented.
Wherein Patni teaches wherein the OTP is received from the client device after the expiration time, further comprising: (Par. (0011); user receives OTP after it expires within a predetermined time limit and forced user to regenerate request))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Patni to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of preventing unauthorized access to users conducting transactions online to determined based on the OTP and location and time the rightful and authorized users. (Patni Par. (0003-0005 and 0011))
Jibrin, Akamine and Patni do not explicitly teach preventing the access to the secure resource; and transmitting a message to client device indicating that the access to the secure resource has been prevented.
Wherein Pearse teaches preventing the access to the secure resource; and (Par. (0014-0015); user access attempt failure corresponding to expiration and OTP), (Par. (0025, 0032); message with OTP and indication of failure for access attempt), (Par. (0028-0029); access the secure resource (access attempt corresponding to online service))
transmitting a message to client device indicating that the access to the secure resource has been prevented.(Par. (0014-0015, 0025); transmitted message when expiration occurs and user access attempt fails corresponding to OTP)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin, Akamine and Patni to incorporate the teaching of Pearse to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of preventing malicious attackers on mobile devices with SMS communication by using expiration time to mitigate attackers intercepting OTP codes and improving overall security for authentication with new users and deny access for online transaction attempts. (Pearse Par. (0003-0004 and 0032))
Claim(s) 11, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”) and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Chitkara et al. (U.S Pub. No. 20220174061, hereinafter referred to as “Chitkara”)
In regards to Claim 11, the combination of Jibrin and Akamine do not explicitly teach receiving, by the authenticator device, an idle token from the client device; and in response to receiving the idle token, extending the expiration time associated with the OTP.
Wherein Chitkara teaches receiving, by the authenticator device, an idle token from the client device; and (Par. (0075-0076); authenticator device (authentication server) receives an idle token (receives replacement password) from device)), (Par. (0054); idle token (replacement password that is temporary))
in response to receiving the idle token, extending the expiration time associated with the OTP. (Par. (0076-0077); in response to receiving idle token (in response to receiving replacement password) extending the expiration time associated with the OTP (extending a rollover period that expires to gain more time with the OTP (password))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Chitkara to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of implementing security practices with new passwords based on timing mechanism and rotating passwords to securely protect the integrity between administrators and users and regulate proper access. (Chitkara Par. (0002-0003 and 0007-0009))
Claim(s) 12, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”), Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) and Chitkara et al. (U.S Pub. No. 20220174061, hereinafter referred to as “Chitkara”) further in view of Sylwan et al. (U.S Pub. No. 20240265760, hereinafter referred to as “Sylwan”)
In regards to Claim 12, the combination of Jibrin, Akamine and Chitkara do not explicitly teach wherein the idle token is received over the unsecure channel.
Wherein Sylwan teaches wherein the idle token is received over the unsecure channel. (Par. (0053-0055); received idle token (receiving temporary passcode) over unsecure channel (temporary passcode received corresponding to BLE connection))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin, Akamine and Chitkara to incorporate the teaching of Sylwan to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of implementing idle or temporary passcodes based on time to eliminate security risks and allow multi entities to receive passcode and regulate access based on determining validity periods. (Sylwan Par. (0032))
Claim(s) 13, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”), and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Girdhar et al. (U.S Pub. No. 20190306153, hereinafter referred to as “Girdhar”)
In regards to Claim 13, the combination of Jibrin and Akamine teach the method of claim 1, Akamine further teaches invalidating the OTP after receiving the OTP from the client device over the unsecure channel, (Par. (0072-0073); receiving one-time password from device that transmits packet with one-time password and when the packet does not include one-time password ending the process over unsecure channel (BLE communication))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin to incorporate the teaching of Akamine to utilize the above feature because of the analogous concept of authentication based on one-time passwords between client and servers, with the motivation of authenticating a device based on the unsecure or BLE connection to grant access in a limited time and state and notify devices a particular presence. (Akamine Par. (0052))
Jibrin and Akamine do not explicitly teach wherein the access to the secure resource is prevented in response to receiving an invalid OTP.
Wherein Girdhar teaches wherein the access to the secure resource is prevented in response to receiving an invalid OTP. (Par. (0062); preventing access to the secure resource (access denied to secure resource) in response to determining that the OTP has been invalidated (OTP is received and falls outside of authentication window))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Girdhar to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of enhancing OTP authentication on business and financial institutions with secure resources by having synchronized windows to protect against brute force attacks. (Girdhar Par. (0006-0008))
Claim(s) 14, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”), Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) and Girdhar et al. (U.S Pub. No. 20190306153, hereinafter referred to as “Girdhar”) further in view of Gadewar et al. (U.S Pub. No. 20220198408, hereinafter referred to as “Gadewar”)
In regards to Claim 14, the combination of Jibrin and Akamine teach the method of claim 1, Jibrin further teaches the method of claim 13, further comprising: determining that the OTP has been invalidated; and (Par. (0113); invalidating the OTP after the expiration time (OTP no longer valid after time window elapses))
Jibrin and Akamine do not explicitly teach after invaliding the OTP, receiving the OTP from the same or another client device; preventing the access to the secure resource in response to determining that the OTP has been invalidated.
Wherein Girdhar teaches preventing the access to the secure resource in response to determining that the OTP has been invalidated. (Par. (0062); preventing access to the secure resource (access denied to secure resource) in response to determining that the OTP has been invalidated (OTP is received and falls outside of authentication window))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Girdhar to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of enhancing OTP authentication on business and financial institutions with secure resources by having synchronized windows to protect against brute force attacks. (Girdhar Par. (0006-0008))
Jibrin, Akamine and Girdhar do not explicitly teach after invaliding the OTP, receiving the OTP from the same or another client device;
Wherein Gadewar teaches after invaliding the OTP, receiving the OTP from the same or another client device; (Par. (0026); same client device (card device as computing device)), (Par. (0061); after invaliding the OTP (one-time password fails in authentication by matching) receiving the OTP from the same client device (card device is provided by the server the one-time password))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin, Akamine and Girdhar to incorporate the teaching of Gadewar to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of implementing a transmission of failed one-time passwords to enhance authentication system and create indication to users of success or failure and regulate access for merchant, consumers and providers. (Gadewar Par. (0061-0062))
Claim(s) 15-16, is/are rejected under 35 U.S.C. 103 as being unpatentable over Jibrin et al. (U.S Pub. No. 20220263653, hereinafter referred to as “Jibrin”), and Akamine et al. (U.S Pub. No. 20160286053, hereinafter referred to as “Akamine”) further in view of Kanoria et al. (U.S Pub. No. 20190188940, hereinafter referred to as “Kanoria”)
In regards to Claim 15, the combination of Jibrin and Akamine teach the method of claim 1, Jibrin further teaches the method of claim 1, wherein the authenticator device comprises a server, ((Par. (0009-0010); authenticator device (server) receives token from the client device (receives token OTP string of individual/user file) and generates a OTP)
Jibrin and Akamine do not explicitly teach wherein the server transmits an instruction to a physical access control device to enable the access to the secure resource.
Wherein Kanoria teaches wherein the server transmits an instruction to a physical access control device to enable the access to the secure resource. (Par. (0025-0029); the server transmits an instruction to a physical access control device (TTLS application server communicates onetime password to a computing device) Par. (0029); wherein the authenticator device (TTLS application server) to enable access to the secure resource (onetime password to unlock vehicle through permissions)), (Par. (0046); a physical access control device to enable access to the secure resource (computing device 104 receives onetime password to unlock vehicle)), (Examiner Note: In the instant application on Par. (0037-0038) the specification describes physical access control device to enable access to the secure resource to be unlocking a door or vehicle ignition system, therefore it will be broadly and reasonably interpreted as such.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Kanoria to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of implementing physical access control devices to unlock smart technologies such as door or vehicles to authorize appropriate users based on permissions as well as prevent theft, robbery and tampering. (Kanoria Par. (0002 and 0018-0019))
In regards to Claim 16, the combination of Jibrin and Akamine do not explicitly teach wherein the authenticator device comprises a physical access control device to enable the access to the secure resource.
Wherein Kanoria teaches wherein the authenticator device comprises a physical access control device to enable the access to the secure resource. (Par. (0018); authentication device (TTLS application server with authorized routes, unique codes and permissions)), (Par. (0044); wherein the authenticator device comprises a physical access control device (computing device 104 coupled to TTLS application server)), (Par. (0029); wherein the authenticator device (TTLS application server) to enable access to the secure resource (onetime password to unlock vehicle through permissions)), (Par. (0046); a physical access control device to enable access to the secure resource (computing device 104 receives onetime password to unlock vehicle)), (Examiner Note: In the instant application on Par. (0037-0038) the specification describes physical access control device to enable access to the secure resource to be unlocking a door or vehicle ignition system, therefore it will be broadly and reasonably interpreted as such.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Jibrin and Akamine to incorporate the teaching of Kanoria to utilize the above feature because of the analogous concept of authentication based on one-time passwords, with the motivation of implementing physical access control devices to unlock smart technologies such as door or vehicles to authorize appropriate users based on permissions as well as prevent theft, robbery and tampering. (Kanoria Par. (0002 and 0018-0019))
Relevant Prior Art
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Jordan; Benjamin Marcus (U.S Pub. No. 20260065272) “SYSTEM, APPARATUS AND METHOD”. Considered this reference because it addressed the storing of one-time passwords on a secure channel.
Lee; Yiu (U.S Pub. No. 20230069337) “METHODS AND SYSTEMS FOR COMMUNICATION SESSION MANAGEMENT”. Considered this application because it relates temporary or idle tokens and authentication with OTP codes.
Hoyer; Philip (U.S Pub. No. 20210383624) “SYSTEMS, METHODS, AND DEVICES FOR ACCESS CONTROL”. Considered this application because it addressed one-time password authentication on unsecure or BLE channels by comparing and denying access to resources.
Conclusion
Applicant's amendment to the dependent claims necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HASSAN A HUSSEIN whose telephone number is (571)272-3554. The examiner can normally be reached on 7:30am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-y.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/H.A.H./ Examiner, Art Unit 2497
/ELENI A SHIFERAW/ Supervisory Patent Examiner, Art Unit 2497