DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
The instant application is a 371 National Stage application of PCT/EP2022/068163 filed 30 June 2022. The priority claim complies with all applicable rules and regulations. Therefore, the effective filing date of the claims is 30 June 2022.
Response to Arguments
Applicant's arguments filed 04 August 2026 and stating on page 8 that “[i]t would not be obvious to modify Soman to include such features”, and stating on page 9 that “none of the references, taken alone or in combination, teach or suggest ‘sending to the second communication device a request for accessing the service, the second communication device being a sign-in server, wherein the request comprises credentials of the user,’ and ‘in response to sending the request, receiving inference biometric data of the user from the second communication device,’ as recited in amended independent claim 1” have been fully considered but they are not persuasive.
Soman discloses a system that includes a user device, Virtual Desktop Interface (VDI) server, and a management server. The user device sends a virtual session initiation request to the VDI server and the VDI server authenticates the data in the request. The VDI server then sends user details to the management server which sends the trained ML model to the user device. The user device initiates the video feed and verifies the user’s face using the received ML model.
Graf (newly cited) discloses an authentication system that includes an authentication server, a content server, and a secure computing device. The authentication server receives user computing device authentication requests. The content server provides access to content and provides access to websites. The content server may perform the functions of the authentication server—sign-in server.
Singh discloses an authentication system that includes a vehicle computing system and a mobile computing device. The vehicle computing system may be an example of computing system 410. Computing system 410 includes one or more image capture devices 414 (Fig. 4, el. 410, 414; Para. 87). Communication channels 449 may interconnect each of the components 412, 414, 430, 442, 444, 446, and/or 448 for inter-component communications (physically, communicatively, and/or operatively), wherein communication channels 449 may include a system bus, a network connection, one or more inter-process communication data structures, or any other components for communicating data (also referred to as information) (Fig. 4, el. 449; Para. 88). One or more communication units 446 of computing system 410 may communicate with external devices by transmitting and/or receiving data, where computing system 410 may use one or more of communication units 446 to transmit and/or receive radio signals on a radio network such as a cellular radio network, where communication units 446 may include short wave radios (e.g., NFC, BLUETOOTH (including BLE)), GPS, 3G, 4G, 5G, and WIFI radios found in mobile devices as well as Universal Serial Bus (USB) controllers and the like (Fig. 4, el. 446; Para. 90).
Singh further discloses a mobile computing device (e.g., mobile computing device 170, wearable device 107) may establish a connection with vehicle computing system 100 of the vehicle illustrated in FIG. 1, and after establishing the connection, the mobile computing device 170 may receive, from vehicle computing system 100, first feature data associated with at least one image of a face of user 150 of the vehicle, wherein the at least one image of the face of user 150 of the vehicle is captured by an image capture device (e.g., camera 104/111) connected to at least a portion of the vehicle (Fig. 1, el. 104, 111, 150, 170; Para. 48).
Singh also discloses camera 104 may function as input devices for vehicle computing system 100 (Para. 26). Control unit 106 may be operably coupled to camera 104 and display 102 to control, configure, and/or communicate information with the components (Para. 32).
Singh further discloses Vehicle computing system 100 may then access the authentication data for the user, user account information to log the user into the infotainment head unit—sign-in server (Para. 49).
Graf’s combination authentication/content server is used to modify Soman’s separate VDI server and management server. Singh’s integrated vehicle computing system that includes a camera connected via a system bus is used to modify Soman in view of Graf to include a camera external to the mobile device and integrated with the server. The stated motivation for this combination is provided as: “providing for better integration of a camera trusted by the second communication device with the facial recognition system of the mobile device, thereby providing better ease-of-use for the user.”
Applicant further states “such a combination would merely provide use of a ‘trusted camera’ in communication with the first communication device” on page 9. Singh’s trusted camera is part of the computer system where the camera may be connected to the other computing elements via a system bus. The camera does not transmit images directly to the mobile device. The images are sent to the mobile device via the network interface of the computing system.
A proper motivation to combine the references has been provided. Therefore, the combination of the references is valid.
See the 35 USC 103 section below for a more detailed analysis of the rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1, 6, 14, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Soman et al. (US 2022/0232004 A1) in view of Graf et al. (US 2019/0332787 A1) and further in view of Singh et al. (US 2021/0229673 A1).
Regarding claim 1, Soman teaches a method for supporting authentication of a user to a service provided by a second communication device, e.g., VDI server 430 (Fig. 4, el. 430), the method being performed by a first communication device, e.g., user device 410 (Fig. 4, el. 410), the method comprising:
- sending to the second communication device a request for accessing the service,…,wherein the request comprises credentials of the user, e.g., at stage 308, the user device can send a virtual session initiation request to a VDI server, wherein the user can send a virtual session initiation request by inputting login information into the VDI client, such as information identifying the virtual session and login credentials (Fig. 3, el. 308; Para. 48);
at stage 310, the VDI server can authenticate the user device, wherein this can include receiving user credentials and checking them with an authentication service (Fig. 3, el. 310; Para. 49);
- in response to sending the request, receiving inference biometric data of the user…, e.g., at stage 312, the VDI server can send details about the user to the management server, where the details can include information identifying the user and indicate that the user is requesting access to a virtual session, as an example, and this information can be used by the management server to retrieve an ML model trained to identify the user and send it to the user device (Fig. 3, el. 312; Para. 50);
at stage 314, the management server can send the trained ML model to the user device (Fig. 3, el. 314; Para. 51);
at stage 316, the user device can initiate a video stream, wherein the user device can include or be connected to a live camera device (Fig. 3, el. 316; Para. 52);
at stage 318, the user device can verify the user's face in the video stream (Fig, 3, el. 318; Para. 53);
- determining whether the user can be authenticated using a machine learning, ML, model trained for classifying biometric data of the user and the received inference biometric data as input, e.g., at stage 318, the user device can verify the user's face in the video stream, wherein this can include applying the ML model to the video stream to identify the user's face (Fig. 3, el. 318; Para. 53);
at stage 314, the management server can send the trained ML model to the user device (Fig. 3, el. 314; Para. 51); and
- in response thereto, sending to the second communication device a message indicative of a confirmation or a rejection of the authentication of the user, e.g., at stage 320, the user device can notify the VDI server whether the user's face could be verified (Fig. 3, el. 320; Para. 55).
Soman does not clearly teach the second communication device being a sign-in server; and
- in response to sending the request, receiving inference biometric data of the user from the second communication device.
Graf teaches - sending to the second communication device, e.g., authentication server 40, content server 50 (Figs. 1, 6, el. 40, 50);
where the authentication server 40 may be configured to request and/or receive one or more user computing device authentication requests, store a plurality of user profiles, store information/data corresponding to a plurality of user accounts, provide secure access to one or more websites, and/or the like (Para. 45);
the content server 50 is a computing device configured to provide application functionality, provide access to content, store and provide one or more websites and/or website information/data of a website, and/or a combination thereof such that functionality and/or content may be provided in the secure environment of the secure Internet browser via the secure computing device 200 (Para. 46),
a request for accessing the service, the second communication device being a sign-in server, e.g., at least one of the one or more content servers 50 may also perform one or more functions described as being performed by the authentication server 40 herein (Para. 46), wherein the request comprises credentials of the user, e.g., at operation/step 636, the secure Internet browser 240 may send an authentication request to an authentication server 40, where the authentication request comprises one or more authentication credentials (Fig. 6, el. 636; Para. 85).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman to include the second communication device being a sign-in server, using the known method of sending an authentication request to an authentication server, where a content server may perform the functions of the authentication server, as taught by Graf, in combination with the facial recognition system of Soman, for the purpose of reducing the amount of required infrastructure, thereby reducing costs.
Soman in view of Graf does not clearly teach - in response to sending the request, receiving inference biometric data of the user from the second communication device.
Singh teaches …the second communication device, e.g., vehicle computing system 100 (Fig. 1, el. 100);
computing system 410 may be a more detailed example of vehicle computing system 100 (Fig. 4, el. 410; Para. 86);
vehicle computing system 100 may be referred to as an infotainment head unit (IHU) (Para. 34),
being a sign-in server…, e.g., IHU system 100 receives (565) this data indicative of a match as representing authentication of the registered user, and proceeds to log in the registered user (e.g., user 150 of the vehicle) (Fig. 5, el. 565; Para. 137);
- in response to sending the request, receiving inference biometric data of the user from the second communication device, e.g., a mobile computing device (e.g., mobile computing device 170, wearable device 107) may establish a connection with vehicle computing system 100 of the vehicle illustrated in FIG. 1, and after establishing the connection, the mobile computing device 170 may receive, from vehicle computing system 100, first feature data associated with at least one image of a face of user 150 of the vehicle, wherein the at least one image of the face of user 150 of the vehicle is captured by an image capture device (e.g., camera 104/111) connected to at least a portion of the vehicle (Fig. 1, el. 104, 111, 150, 170; Para. 48);
computing system 410 includes one or more image capture devices 414 (Fig. 4, el. 410, 414; Para. 87);
image capture devices 414 may include one or more cameras, such as digital cameras, still cameras, motion picture cameras, and the like (Para. 89);
communication channels 449 may interconnect each of the components 412, 414, 430, 442, 444, 446, and/or 448 for inter-component communications (physically, communicatively, and/or operatively), wherein communication channels 449 may include a system bus, a network connection, one or more inter-process communication data structures, or any other components for communicating data (also referred to as information) (Fig. 4, el. 449; Para. 88);
one or more communication units 446 of computing system 410 may communicate with external devices by transmitting and/or receiving data, where computing system 410 may use one or more of communication units 446 to transmit and/or receive radio signals on a radio network such as a cellular radio network, where communication units 446 may include short wave radios (e.g., NFC, BLUETOOTH (including BLE)), GPS, 3G, 4G, 5G, and WIFI radios found in mobile devices as well as Universal Serial Bus (USB) controllers and the like (Fig. 4, el. 446; Para. 90);
- determining whether the user can be authenticated using…the received inference biometric data as input, e.g., the mobile computing device may determine, based on a comparison between the first feature data and second feature data associated with at least one image of a face of a previously enrolled user of the mobile computing device, a match between the user of the vehicle and the previously enrolled user, and the mobile computing device authenticates, based on the match, user 150 of the vehicle (Para. 48); and
- in response thereto, sending to the second communication device a message indicative of a confirmation or a rejection of the authentication of the user, e.g., the mobile computing device the sends, to vehicle computing system 100, authentication data for user 150 of the vehicle, where the authentication data is indicative of the match (Para. 48).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman in view of Graf to include receiving inference biometric data of the user from the second communication device, using the known method of capturing a facial image using an in-vehicle camera and sending feature data of the facial image to the mobile device, as taught by Singh, in combination with the facial recognition system of Soman in view of Graf, for the purpose of providing for better integration of a camera trusted by the second communication device with the facial recognition system of the mobile device, thereby providing better ease-of-use for the user.
Regarding claim 6, Soman in view of Graf in view of Singh teaches the method according to claim 1, further comprising: - receiving a message indicative of a successful verification of the credentials of the user from the second communication device, e.g., at stage 310, the VDI server can authenticate the user device, wherein this can include receiving user credentials and checking them with an authentication service (Soman-Fig. 3, el. 310; Para. 49);
at stage 322, the VDI can initiate the virtual session with the user device, and where the user's face cannot be verified above a threshold level, the VDI can instead deny the virtual session request (Soman-Fig. 3, el. 322; Para. 55);
the VDI client 414 can communicate with a VDI server 430 to provide a virtual session on the user device 410 (Soman-Fig. 4, el. 414; Para. 63).
Regarding claim 14, the claim is analyzed with respect to claim 1. Soman in view of Graf in view of Singh further teaches a first communication device, e.g., user device 410 (Soman-Fig. 4, el. 410), for supporting authentication of a user to a service provided by a second communication device, e.g., VDI server 430 (Soman-Fig. 4, el. 430), the first communication device comprising a processor and a memory, the memory having stored thereon instructions executable by the processor, wherein the instructions, when executed by the processor, e.g., a non-transitory, computer-readable medium having instructions that, when executed by a processor associated with a computing device, cause the processor to perform the stages described (Soman-Para. 11; Claim 8); the user device 410 can be one or more processor-based devices (Soman-Para. 62), cause the first communication device to: perform the steps.
Regarding claim 19, the claim is analyzed with respect to claim 6.
Claims 2 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Soman in view of Graf in view of Singh and further in view of Figueredo de Santana et al. (US 2020/0272717 A1).
Regarding claim 2, Soman in view of Graf in view of Singh teaches the method according to claim 1.
Soman in view of Graf in view of Singh does not clearly teach - obtaining training biometric data of the user from a sensor adapted to capture training biometric data of the user; and
- training the ML model using the obtained training biometric data.
Figueredo de Santana teaches - obtaining training biometric data of the user from a sensor, e.g., the user device 202 may include one or more image capturing components, such as first device camera 204a and second device camera 204b (Fig. 2, el. 202, 204a, 205b; Para. 35), adapted to capture training biometric data of the user, e.g., the first device camera 204a and the second device camera 204b may be provided to capture an image data 208 of the user 206 associated with an authentication challenge (Fig. 2, el. 208; Para. 35);
the access control program 110a, 110b may prompt the user 206 (e.g., via user interface text box) to capture and upload a real-time face image of the user 206 via the front-facing camera (e.g., first device camera 204a) or the rear-facing camera (e.g., second device camera 204b) of the user device 202, and the access control program 110a, 110b may store the captured real-time face image of the user 206 in the device database 210 (Fig. 2, el. 210; Para. 53);
the access control program 110a, 110b may provide a deep learning module for training one or more facial recognition algorithms (e.g., facial recognition model), and in order to train the facial recognition model, the access control program 110a, 110b may access image data stored in a device database 210 (Para. 37); and
- training the ML model using the obtained training biometric data, e.g., the access control program 110a, 110b may provide a deep learning module for training one or more facial recognition algorithms (e.g., facial recognition model), and in order to train the facial recognition model, the access control program 110a, 110b may access image data stored in a device database 210 (Para. 37).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman in view of Graf in view of Singh to include obtaining training biometric data of the user from a sensor adapted to capture training biometric data of the user; and training the ML model using the obtained training biometric data, using the known method of training the facial recognition model using a deep learning module and image data accessed from the device database, as taught by Figueredo de Santana, in combination with the facial recognition system of Soman in view of Graf in view of Singh, for the purpose of increasing the accuracy of the facial recognition method by enabling the system to automatically learn and extract features from the image data.
Regarding claim 15, the claim is analyzed with respect to claim 2.
Claims 3, 4, 16, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Soman in view of Graf in view of Singh and further in view of Barboi (US 2020/0050749 A1).
Regarding claim 3, Soman in view of Graf in view of Singh teaches the method according to claim 1.
Soman in view of Graf in view of Singh does not clearly teach - obtaining a communication session identifier via an out-of-band communication channel from the second communication device; and
- sending a message comprising the communication session identifier to the second communication device.
Barboi teaches - obtaining a communication session identifier via an out-of-band communication channel from the second communication device, e.g., security server 103 (Fig. 1, el. 103);
in operation 406, process 400 may further generate a unique session identifier for the user, wherein the unique session identifier may be a variety of different types of identifiers that the client computing device can receive and relay back to the security server 103, wherein examples include barcodes 302, QR codes 304, images or icons 306, text strings 308, graphical patterns 310, colors 312, and more (Fig. 4, el. 406; Para. 72);
in operation 407, the unique session identifier may be provided to the user, wherein the unique session identifier may be sent from the security server 103 to the client computing device 101 that transmitted the request identified in operation 401 (Fig. 4, el. 407; Para. 74);
in operation 409, the user may return the unique session identifier that they received to the security server 103, wherein if the unique session identifier is a QR code, the user may optically scan the received QR code (e.g., using a camera), and send back to the security server a copy of the QR code, a decoded version of its contents, or an encrypted version of its contents (Fig. 4, el. 409; Para. 76); and
- sending a message comprising the communication session identifier to the second communication device, e.g., in operation 409, the user may return the unique session identifier that they received to the security server 103, wherein if the unique session identifier is a QR code, the user may optically scan the received QR code (e.g., using a camera), and send back to the security server a copy of the QR code, a decoded version of its contents, or an encrypted version of its contents (Fig. 4, el. 409; Para. 76).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman in view of Graf in view of Singh to include obtaining a communication session identifier via an out-of-band communication channel from the second communication device; and sending a message comprising the communication session identifier to the second communication device, using the known method of sending, by a security server, a QR code including a session ID to a user device, capturing and decoding the QR code using the user device’s camera, and sending the session ID back to the security server, as taught by Barboi, in combination with the facial recognition system of Soman in view of Graf in view of Singh, for the purpose of securely, flexibly, and quickly authenticating users seeking access to network-restricted resources (Barboi-Para. 4).
Regarding claim 4, Soman in view of Graf in view of Singh in view of Barboi teaches the method according to claim 3, wherein the obtaining a communication session identifier comprises using a camera to capture an encoded visual representation of the communication session identifier, e.g., in operation 409, the user may return the unique session identifier that they received to the security server 103, wherein if the unique session identifier is a QR code, the user may optically scan the received QR code (e.g., using a camera), and send back to the security server a copy of the QR code, a decoded version of its contents, or an encrypted version of its contents (Barboi-Fig. 4, el. 409; Para. 76).
Regarding claim 16, the claim is analyzed with respect to claim 3.
Regarding claim 17, the claim is analyzed with respect to claim 4.
Claims 5 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Soman in view of Graf in view of Singh and further in view of Aggarwal et al. (US 2025/0126030 A1).
Regarding claim 5, Soman in view of Graf in view of Singh teaches the method according to claim 1.
Soman further teaches - sending a message comprising a user identifier identifying the user…to the second communication device, e.g., the user can send a virtual session initiation request by inputting login information into the VDI client, such as information identifying the virtual session and login credentials (Para. 48).
Soman in view of Graf in view of Singh does not clearly teach - sending a message comprising a user identifier identifying the user and a model identifier identifying the ML model to the second communication device.
Aggarwal teaches sending a message comprising a user identifier identifying the user and a model identifier identifying the ML model to the second communication device, e.g., in step 11, the UE may send a request to the AF for model uploading service to access the model identified by the model ID and/or model version ID, where the UE may send the UE ID, the model ID, the model version ID and/or the access key., where the UE may send a mobile subscriber identification number (MSIN) (Fig. 4b, el. 11; Para. 198).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman in view of Graf in view of Singh to include sending a message comprising a user identifier identifying the user and a model identifier identifying the ML model to the second communication device, using the known method of sending, by the UE, a MSIN, UE ID, the model ID, and the access key to the AF, as taught by Aggarwal, in combination with the facial recognition system of Soman in view of Graf in view of Singh, for the purpose of providing an extra verification for the machine learning model and user. Another benefit would be to allow the second device to log the model that is used by the user device.
Regarding claim 18, the claim is analyzed with respect to claim 5.
Claims 7-9 are rejected under 35 U.S.C. 103 as being unpatentable over Soman in view of Graf and further in view of Ives-Halperin et al. (US 2016/0080943 A1).
Regarding claim 7, Soman teaches a method for supporting authentication of a user to a service provided by a second communication device, e.g., VDI server 430 (Fig. 4, el. 430), the method being performed by the second communication device, the method comprising:
- receiving, from a first communication device, e.g., user device 410 (Fig. 4, el. 410), a request for accessing the service,…, wherein the request comprises credentials of the user, e.g., at stage 308, the user device can send a virtual session initiation request to a VDI server, wherein the user can send a virtual session initiation request by inputting login information into the VDI client, such as information identifying the virtual session and login credentials (Fig. 3, el. 308; Para. 48);
at stage 310, the VDI server can authenticate the user device, wherein this can include receiving user credentials and checking them with an authentication service (Fig. 3, el. 310; Para. 49);
- …inference biometric data of the user from a sensor, e.g., video camera 420 (Fig. 4, el. 420), adapted to capture biometric data from the user, in response to a successful verification of the credentials of the user, e.g., at stage 310, the VDI server can authenticate the user device, wherein this can include receiving user credentials and checking them with an authentication service (Soman-Fig. 3, el. 310; Para. 49);
at stage 316, the user device can initiate a video stream, wherein the user device can include or be connected to a live camera device (Fig. 3, el. 316; Para. 52);
at stage 318, the user device can verify the user's face in the video stream (Fig, 3, el. 318; Para. 53);
the VDI client 414 can communicate with the video camera to initialize a live video stream of the area in front of the user device 410, and the VDI client 414 can apply the ML model 446 to verify the user upon login and to monitor the video stream for any unauthorized objects or persons (Fig. 4, el. 446; Para. 67);
- …the inference biometric data to the first communication device, e.g., at stage 316, the user device can initiate a video stream, wherein the user device can include or be connected to a live camera device (Fig. 3, el. 316; Para. 52);
at stage 318, the user device can verify the user's face in the video stream (Fig, 3, el. 318; Para. 53);
the VDI client 414 can communicate with the video camera to initialize a live video stream of the area in front of the user device 410, and the VDI client 414 can apply the ML model 446 to verify the user upon login and to monitor the video stream for any unauthorized objects or persons (Fig. 4, el. 446; Para. 67);
- receiving from the first communication device a message indicative of a confirmation or a rejection of the authentication of the user, e.g., at stage 320, the user device can notify the VDI server whether the user's face could be verified (Fig. 3, el. 320; Para. 55).
Soman does not clearly teach the second communication device being a sign-in server;
- in response to receiving the request, obtaining inference biometric data of the user from a sensor adapted to capture biometric data from the user, in response to a successful verification of the credentials of the user; and
- sending the inference biometric data to the first communication device.
Graf teaches - receiving, from a first communication device, a request for accessing the service, the second communication device, e.g., authentication server 40, content server 50 (Figs. 1, 6, el. 40, 50);
where the authentication server 40 may be configured to request and/or receive one or more user computing device authentication requests, store a plurality of user profiles, store information/data corresponding to a plurality of user accounts, provide secure access to one or more websites, and/or the like (Para. 45);
the content server 50 is a computing device configured to provide application functionality, provide access to content, store and provide one or more websites and/or website information/data of a website, and/or a combination thereof such that functionality and/or content may be provided in the secure environment of the secure Internet browser via the secure computing device 200 (Para. 46),
being a sign-in server, e.g., at least one of the one or more content servers 50 may also perform one or more functions described as being performed by the authentication server 40 herein (Para. 46),
wherein the request comprises credentials of the user, e.g., at operation/step 636, the secure Internet browser 240 may send an authentication request to an authentication server 40, where the authentication request comprises one or more authentication credentials (Fig. 6, el. 636; Para. 85).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman to include the second communication device being a sign-in server, using the known method of sending an authentication request to an authentication server, where a content server may perform the functions of the authentication server, as taught by Graf, in combination with the facial recognition system of Soman, for the purpose of reducing the amount of required infrastructure, thereby reducing costs.
Soman in view of Graf does not clearly teach - in response to receiving the request, obtaining inference biometric data of the user from a sensor adapted to capture biometric data from the user, in response to a successful verification of the credentials of the user; and
- sending the inference biometric data to the first communication device
Ives-Halperin teaches - in response to receiving the request, obtaining inference biometric data of the user from a sensor, e.g., camera 1527/1606 (Fig. 15A, el. 1527; Fig. 16, el. 1606), adapted to capture biometric data from the user, in response to a successful verification of the credentials of the user, e.g., at block 1915a, the user device transmits a BLE signal including a device identifier, and at block 1915b, the device identifier is received by the client device as part of the transmitted BLE signal, wherein the device identifier may be an access-enabling code specifying access rights for a user associated with the user device, and the client device may optionally facilitate verification of the access-enabling code to determine whether the user associated with the user device has a valid access right—successful verification of the credentials of the user-- (Fig. 19, el. 1915a, 1915b; Para. 343);
at block 1920 the client device obtains one or more biometric credentials from the user, such as using one or more biometric capture devices—obtaining inference biometric data of the user-- (Fig. 19, el. 1920; Para. 344);
client device 1501 may further include or be in data communication with one or more biometric capture devices, wherein client device 1501 is in communication with a camera 1527, which may be used to obtain a facial image of authorized user 1514, and it will be appreciated that other biometric capture devices can be incorporated into, attached to, or otherwise in communication with client device 1501, such as fingerprint or palm print scanners, iris scanners, retinal scanners, microphones, such as for voice recognition, and the like (Fig. 15, el. 1501; Para. 311);
camera 1606, which is included in or otherwise in data communication with client device 1610, wherein camera 1606 may provide images of users, such as in the form of a video feed to client device 1610 (Fig. 16, el. 1610; Para. 318); and
- sending the inference biometric data to the first communication device, e.g., at block 1925a, the client device transmits a BLE signal to send the biometric credential over the BLE communication channel (Fig. 19, el. 1925a; Para. 345).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman in view of Graf to include obtaining inference biometric data of the user from a sensor adapted to capture biometric data from the user, in response to a successful verification of the credentials of the user; and sending the inference biometric data to the first communication device, using the known method of receiving an access-enabling code, verifying the code, capturing biometric data of the user, and sending the biometric data to the user device, as taught by Ives-Halperin, in combination with the facial recognition system of Soman in view of Graf, for the purpose of providing for better integration of a camera trusted by the client device with the facial recognition system of the user device, thereby providing better ease-of-use for the user and increased security for the system.
Regarding claim 8, Soman in view of Graf in view of Ives-Halperin teaches the method according to claim 7, further comprising:- in response to receiving the message indicative of the confirmation of the authentication of the user, granting the user access to the service, e.g., at stage 320, the user device can notify the VDI server whether the user's face could be verified, and at stage 322, the VDI can initiate the virtual session with the user device, wherein in one example where the user's face cannot be verified above a threshold level, the VDI can instead deny the virtual session request (Soman-Fig. 3, el. 320, 322; Para. 55).
Regarding claim 9, Soman in view of Graf in view of Ives-Halperin teaches the method according to claim 7, further comprising: - sending a message indicative of a successful verification of the credentials of the user to the first communication device, e.g., at stage 320, the user device can notify the VDI server whether the user's face could be verified, and at stage 322, the VDI can initiate the virtual session with the user device, wherein in one example where the user's face cannot be verified above a threshold level, the VDI can instead deny the virtual session request (Soman-Fig. 3, el. 320, 322; Para. 55);
the VDI client 414 can communicate with a VDI server 430 to provide a virtual session on the user device 410 (Soman-Fig. 4, el. 414; Para. 63).
Claims 10 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Soman in view of Graf in view of Ives-Halperin and further in view of Barboi.
Regarding claim 10, Soman in view of Graf in view of Ives-Halperin teaches the method according to claim 7.
Soman in view of Graf in view of Ives-Halperin does not clearly teach - sending to the first communication device, a communication session identifier via an out-of-band communication channel; and
- receiving a message comprising the communication session identifier from the first communication device.
Barboi teaches - sending to the first communication device, e.g., client computing device 101 (Fig. 1, el. 101), a communication session identifier via an out-of-band communication channel, e.g., in operation 406, process 400 may further generate a unique session identifier for the user, wherein the unique session identifier may be a variety of different types of identifiers that the client computing device can receive and relay back to the security server 103, wherein examples include barcodes 302, QR codes 304, images or icons 306, text strings 308, graphical patterns 310, colors 312, and more (Fig. 4, el. 406; Para. 72);
in operation 407, the unique session identifier may be provided to the user, wherein the unique session identifier may be sent from the security server 103 to the client computing device 101 that transmitted the request identified in operation 401 (Fig. 4, el. 407; Para. 74);
in operation 409, the user may return the unique session identifier that they received to the security server 103, wherein if the unique session identifier is a QR code, the user may optically scan the received QR code (e.g., using a camera), and send back to the security server a copy of the QR code, a decoded version of its contents, or an encrypted version of its contents (Fig. 4, el. 409; Para. 76); and
- receiving a message comprising the communication session identifier from the first communication device, e.g., in operation 409, the user may return the unique session identifier that they received to the security server 103, wherein if the unique session identifier is a QR code, the user may optically scan the received QR code (e.g., using a camera), and send back to the security server a copy of the QR code, a decoded version of its contents, or an encrypted version of its contents (Fig. 4, el. 409; Para. 76).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman in view of Graf in view of Ives-Halperin to include sending to the first communication device, a communication session identifier via an out-of-band communication channel; and receiving a message comprising the communication session identifier from the first communication device, using the known method of sending, by a security server, a QR code including a session ID to a user device, capturing and decoding the QR code using the user device’s camera, and sending the session ID back to the security server, as taught by Barboi, in combination with the facial recognition system of Soman in view of Graf in view of Ives-Halperin, for the purpose of securely, flexibly, and quickly authenticating users seeking access to network-restricted resources (Barboi-Para. 4).
Regarding claim 11, Soman in view of Graf in view of Ives-Halperin in view of Barboi teaches the method according to claim 10, wherein the sending a communication session identifier comprises displaying an encoded visual representation of the communication session identifier, e.g., in operation 409, the user may return the unique session identifier that they received to the security server 103, wherein if the unique session identifier is a QR code, the user may optically scan the received QR code (e.g., using a camera), and send back to the security server a copy of the QR code, a decoded version of its contents, or an encrypted version of its contents (Barboi-Fig. 4, el. 409; Para. 76).
Claims 12 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Soman in view of Graf in view of Ives-Halperin and further in view of Aggarwal.
Regarding claim 12, Soman in view of Graf in view of Ives-Halperin teaches method according to claim 7.
Soman further teaches - receiving, from the first communication device, a message comprising a user identifier identifying the user…, e.g., the user can send a virtual session initiation request by inputting login information into the VDI client, such as information identifying the virtual session and login credentials (Para. 48),
…a machine learning, ML, model trained for classifying biometric data of the user, e.g., at stage 318, the user device can verify the user's face in the video stream, wherein this can include applying the ML model to the video stream to identify the user's face (Fig. 3, el. 318; Para. 53);
at stage 314, the management server can send the trained ML model to the user device (Fig. 3, el. 314; Para. 51).
Soman in view of Graf in view of Ives-Halperin does not clearly teach - receiving, from the first communication device, a message comprising a user identifier identifying the user and a model identifier identifying a machine learning, ML, model trained for classifying biometric data of the user;
- verifying the user identifier and the model identifier.
Aggarwal teaches - receiving, from the first communication device, a message comprising a user identifier identifying the user and a model identifier identifying a machine learning, ML, model…, e.g., in step 11, the UE may send a request to the AF for model uploading service to access the model identified by the model ID and/or model version ID, where the UE may send the UE ID, the model ID, the model version ID and/or the access key., where the UE may send a mobile subscriber identification number (MSIN) (Fig. 4b, el. 11; Para. 198); and
- verifying the user identifier and the model identifier, e.g., in step 12, the AF for model uploading service may send a request to the DMRF to verify the access key and UE ID, as well as the model ID and/or the model version ID (Fig. 4b, el. 12; Para. 199);
in step 14, the DMRF may send an indication to the AF for model uploading service that the verification has been successful or that the verification has been unsuccessful (Fig. 4b, el. 14; Para. 205).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman in view of Graf in view of Ives-Halperin to include receiving, from the first communication device, a message comprising a user identifier identifying the user and a model identifier identifying a machine learning, ML, model trained for classifying biometric data of the user; and verifying the user identifier and the model identifier, using the known method of sending, by the UE, a MSIN, UE ID, the model ID, and the access key to the AF and verifying the identifiers, as taught by Aggarwal, in combination with the facial recognition system of Soman in view of Graf in view of Ives-Halperin, for the purpose of providing an extra verification for the machine learning model and user. Another benefit would be to allow the second device to log the model that is used by the user device.
Regarding claim 13, Soman in view of Graf in view of Ives-Halperin in view of Aggarwal teaches the method according to claim 12.
Soman in view of Graf in view of Ives-Halperin further teaches wherein the obtaining inference biometric data of the user comprises obtaining the inference biometric data of the user in response to a successful verification of the user identifier…, e.g., at block 1915a, the user device transmits a BLE signal including a device identifier, and at block 1915b, the device identifier is received by the client device as part of the transmitted BLE signal, wherein the device identifier may be an access-enabling code specifying access rights for a user associated with the user device, and the client device may optionally facilitate verification of the access-enabling code to determine whether the user associated with the user device has a valid access right—successful verification of the credentials of the user-- (Ives-Halperin-Fig. 19, el. 1915a, 1915b; Para. 343);
at block 1920 the client device obtains one or more biometric credentials from the user, such as using one or more biometric capture devices—obtaining inference biometric data of the user-- (Ives-Halperin-Fig. 19, el. 1920; Para. 344);
Soman in view of Graf in view of Ives-Halperin does not clearly teach wherein the obtaining inference biometric data of the user comprises obtaining the inference biometric data of the user in response to a successful verification of the user identifier and the model identifier.
Aggarwal teaches …in response to a successful verification of the user identifier and the model identifier, e.g., in step 12, the AF for model uploading service may send a request to the DMRF to verify the access key and UE ID, as well as the model ID and/or the model version ID (Fig. 4b, el. 12; Para. 199);
in step 14, the DMRF may send an indication to the AF for model uploading service that the verification has been successful or that the verification has been unsuccessful (Fig. 4b, el. 14; Para. 205).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Soman in view of Graf in view of Ives-Halperin to include wherein the obtaining inference biometric data of the user comprises obtaining the inference biometric data of the user in response to a successful verification of the user identifier and the model identifier, using the known method of sending, by the UE, a MSIN, UE ID, the model ID, and the access key to the AF and verifying the identifiers, as taught by Aggarwal, in combination with the facial recognition system of Soman in view of Graf in view of Ives-Halperin, for the purpose of providing an extra verification for the machine learning model and user. Another benefit would be to allow the second device to log the model that is used by the user device.
Relevant Prior Art
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Deng (US 2015/0244557 A1)—Deng discloses sending the sign-in information to a sign-in server (Abstract).
Salter et al. (US 2022/0029987 A1)—Salter discloses at verification time the bartender, Bob, sends a photo of the current customer (supposedly Alice, the individual) to them. Alice is able to process the photo or features thereof using the credential to prove in zero knowledge that her credential contains an attribute (>21 years old) such that without divulging the underlying value, such as Alice's birthdate or actual age (Para. 121).
Arora et al. (US 2020/0186352 A1)—Arora discloses step S420 involves access terminal 404 transmitting the first biometric instance to the plurality of candidate user mobile devices 408. Step S422 involves each candidate user mobile device 408 generating a match determination (or “biometric match determination”) based on a comparison of the first biometric instance with a second biometric instance stored on the candidate user mobile device. Step S424 involves each candidate user mobile device 408 transmitting their biometric match determination back to access terminal 404 (Fig. 4; Para. 100).
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JEREMY DUFFIELD whose telephone number is (571)270-1643. The examiner can normally be reached Monday - Friday, 7:00 AM - 3:00 PM (ET).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at (571) 272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
17 September 2026
/Jeremy S Duffield/Primary Examiner, Art Unit 2498