DETAILED ACTION
This communication responsive to the Application No. 18/881,878 filed on 07/10/2026. Claims 1-11 are pending and are directed towards MESSAGE PRESENTATION SYSTEM, PRESENTATION APPARATUS, AND MESSAGE PRESENTATION METHOD.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to arguments
Applicant’s arguments with respect to amended claims 1, 10 and 11 have been fully considered and are moot because the new ground of rejection does not rely on the combination of references applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
A new reference Martinian et al. (US 20060123241 A1) has been introduced to disclose a template derived from an enrollment biometric with a ciphertext and attaches a presentation biometric with the code to recreate the same key which succeeds only when both the biometrics are similar for the decoder to correct the difference and using that key to decrypt the text and recover the original data.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 1, 10 and 11 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding amended claim 1, 10 and 11, recites- “biometric information is sufficiently close to the registration biometric information”. Here, the metric sufficiently close is indefinite and does not render how close the biometric information is to the registration information. Hence, the claims 1, 10 and 11 are being rejected under 35 U.S.C 112(b).
Additionally, claims 2-9 are rejected for being dependent on any one of the independent claims.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
-The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-11 are rejected under 35 U.S.C. 103 as being unpatentable over Lewison et al. (US 20200153824 A1), hereinafter referred to as Lewison in view of Li et al. (US 20150095654 A1), hereinafter referred to as Li in further view of Martinian et al. (US 20060123241 A1), hereinafter referred to as Martinian
As per claim 1, Lewison discloses a message presentation system comprising: a presentation apparatus, wherein the presentation apparatus
stores a template generated based on registration biometric information for a user, (The issuer generates a helper datum and a biometric key from the biometric sample obtained prior to issuance and derives a biometric template from the biometric sample obtained prior to issuance and it assigns the helper datum and biometric key and the biometric template, Lewison, para [0092]- [0095]. Here, the stored material is the biometric template and the helper datum generated from the pre-issuance biometric sample. Additionally, Li discloses stored material being the enrollment-derived helper data which is stored in NVM 150).
an encrypted message in which a message including one or more message elements are encrypted, and (The rich certificate includes a typed hash tree containing a plurality of attributes of the subject and verification data and the presentation copy can omit selected portions. The typed hash tree has an attribute subtree for each attribute, Lewison, para [0099]. Here, the message is analogous to the rich-certificate content inside the typed hash tree and the message elements are the attributes/subtrees items in that tree. Additionally, Li discloses using the biometric derived key to decrypt protected content such as documents. This combination provides the structured message from Lewison and the storing in a protected form and decrypting it with the biometrically recovered key is supplied by Li)
an issuance proof generated based on a user's public key corresponding to the template, the message, and an issuer's secret key corresponding to an issuance entity of the message, (The procurement app sends the public key component to the issuer ad the issuer constructs the typed-hash tree content and then computes the signature 440 on the public key, the metadata and the root label of the typed hash-tree. The rich certificate includes a signature computed on data including the public key and the root label, Lewison, para [0089] and [0099]. The insurance proof is interpreted as the issuer’s signature 440. The user’s public key is analogous to the public key sent by the procurement application and included in the rich certificate. The message is interpreted to be the typed hash tree content represented by the signed root label. The issuing server/certification authority is the issuance entity and its signing key is the issuer secret key)
acquires presentation biometric information for the user, (If a biometric sample is used as a verification factor it must be presented directly to the verifier. The presentation application arranges for biometric apps to submit one or more biometric samples to the verifier, Lewison, para [0006]. The presentation biometric information is analogous presentation-time biometric sample/input obtained from the user and also acquiring/submitting biometric samples for verification during presentation is disclosed)
generates a presentation proof based on the presentation part, the issuance proof, and the user's secret key, and (The presentation-state copy is created by pruning and that pruning occurs without invalidating a signature computed by the issuing server. The verifier checks the presentation-state copy, including a proof of knowledge of the private key. The presentation application proves knowledge of the private key associated with the public key present in the presentation state copy, Lewison, para [0011] and [0014]. The presentation part is analogous to the selectively pruned presentation-state copy and the issuance proof is analogous the issuance signature that survives pruning and the user’s secret key is similar to the private key side secret whose knowledge is proven)
outputs the partial message and the presentation proof (The verifier receives the presentation state copy and the application proves knowledge of the private key associated with the public key in that copy during presentation process, the rich credential is presented to the verifier, Lewison, para [0046] and [0090]. The presentation state copy and the proof of knowledge of the private key generated during presentation protocol are delivered as part of the presentation flow).
However, Lewison does not explicitly disclose the limitations:
generates a user's secret key corresponding to the user's public key based on the template and the presentation biometric information,
restores the message by decrypting the encrypted message using the user's secret key,
generates a partial message from the message based on a presentation part that is information for identifying a part presented in the message,
Li discloses:
generates a user's secret key corresponding to the user's public key based on the template and the presentation biometric information, (In fuzzy extractor recovery, helper data is computed from biometric data at a first time period and later the key k is then extracted from recovered biometric data using the helper data. The later biometric inputs are used with the helper data to determine component keys and then determine the cryptographic key k with later biometric data and stored helper data, the secret key k can be unlocked and output, Li, para [0021] and [0073]. Here, Li discloses the mechanism to recover or unlock key k from stored enrollment-derived helper data plus later biometric input. So, the users secret key corresponding to the user’s public key is the credentials private key side secret, implemented or recovered using the biometric key generation/recovery flow. Lewison discloses the public/private key pair used by the credential)
restores the message by decrypting the encrypted message using the user's secret key, (The biometric-derived key may be used to decrypt user secrets such as passwords or documents at unlock time with later biometric data and helper data the secret key k can be unlocked and output, Li, para [0002] and [0021])
generates a partial message from the message based on a presentation part that is information for identifying a part presented in the message, (The presentation application agrees on which attributes and factors are to be shown then creates a presentation- state copy containing the agreed upon attributes but omitting other attributes and other verification data before presentation, the application transitions the stored certificate to presentation state by pruning subtrees for attributes not to be disclosed and verification factors not to be presented, Li, para [0011]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Lewison with Li by multifactor privacy-enhanced remote identification using a rich credential (Lewison) with cryptographic key generation based on multiple biometrics (Li). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Lewison with Li in order to effectively maintain safety of a system when data leak occurs (See Li, para [0011]).
However, Lewison in view of Li does not explicitly disclose the limitations:
in response to determining that the presentation biometric information is sufficiently close to the registration biometric information used to generate the template;
wherein the user's secret key has a fixed value corresponding to the template;
Martinian discloses:
in response to determining that the presentation biometric information is sufficiently close to the registration biometric information used to generate the template; (Because of error correcting properties of syndrome codes, even if the second biometric parameters P' differs slightly from the first biometric parameters P, a suitably designed syndrome decoder can successfully produce the third biometric parameters P'' that are exactly the same as the first biometric parameters used as the encryption key P 502, Martinian, para [0076]. If syndrome decoding fails, the user is denied access. If syndrome decoding succeeds, then the original biometric parameters are used to verify the authenticity of the user, Martinian, para [0058]. Here, the syndrome decoder 570 has finite error correction capability which is a metric that defines how close it is. The decode is successful when P’ is slightly different from P)
wherein the user's secret key has a fixed value corresponding to the template; (A suitably designed syndrome decoder can successfully produce the third biometric parameters P'' that are exactly the same as the first biometric parameters used as the encryption key P 502, Martinian, para [0076]. Each stored syndrome code can be decoded to yield the original biometric parameters, and to authenticate a user or decrypt data that was encrypted with the biometric data, Martinian, para [0041]. The decoded value E'' 371 is an estimate of the original biometric parameter E 301 used to produce the syndrome code S 331, Martinian, para [0070]. Here, the regenerated key is the same value as the key each time the decode is successful. The presentation biometric functions as decoder side information and doesn’t enter the key’s value)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Lewison and Li with Martinian by multifactor privacy-enhanced remote identification using a rich credential (Lewison) and cryptographic key generation based on multiple biometrics (Li) with biometric user authentication and data encryption (Martinian). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Lewison and Li with Martinian in order to generate identical user secret key from presentation biometrics (See Martinian, para [0070])
As per claim 2, Lewison, Li and disclose the message presentation system according to claim 1, further comprising:
Furthermore, Lewison discloses:
a verification apparatus, wherein (Verifier 150, Lewison, para [0039])
the verification apparatus transmits a presentation challenge to the presentation apparatus, and (At 1710 the verifier generates a random nonce and sends it to the prover over the TLS connection. Then the process continues at 1720. At 1720 the prover generates its own random nonce and computes a signature on the two nonces and the identifier found in the TLS server certificate of the verifier, using the private key associated with the public key held by the verifier. Then the process continues at 1730, Lewison, para [0124]- [0125]. Here, the verifiers nonce is analogous to the presentation challenge and this is sent at the start of the proof-of-knowledge protocol. That is a challenge generated by the verification apparatus and transmitted to the presentation apparatus before the presentation proof is computed).
the presentation apparatus generates the presentation proof based on the presentation challenge, the presentation part, the issuance proof, and the generated secret key (Attributes to be disclosed and the presentation state are mentioned. The verifier specifies the subset to be presented and the presentation application prunes the certificate accordingly while keeping the issuer signature valid, Lewison, para [0030]. The system proves knowledge and computes a signature. The presentation application and verifier execute a protocol in which the presentation application proves knowledge of the credential private key and the prover computes a signature using the verifier nonce, Lewison, para [0090]. The presentation challenge is analogous to the verifier nonce and the presentation part aligns with the negotiated subset of attributes/factors and the resulting presentation-state copy. The issuance proof is similar to the issuer signature that remains valid after pruning and Li discloses the generated secret key which is the private key side secret as recovered/unlocked using the biometric key recovery flow. The resulting presentation proof is the nonce-based signature).
As per claim 3, Lewison, Li and discloses the message presentation system according to claim 1, further comprising:
Furthermore, Lewison discloses:
a verification apparatus, wherein (Verifier 150, Lewison, para [0039])
the verification apparatus stores an issuer's public key corresponding to the issuer's secret key and the presentation part, (The certificate chain is empty if the CA that operates the issuer 110 is a root CA, whose public keys, one of which is identified by the issuer key ID 436, are well known, Lewison, para [0100]. It is computed by the issuer 110 using a private key pertaining to a digital signature cryptosystem such as DSA, ECDSA or RSA identified by the signature cryptosystem ID, and verified by the verifier 150 using the associated public key, which the verifier identifies by means of the issuer key ID 436, Lewison, para [0054]. At 1635 the verifier creates an identification event record where it stores the presentation-state copy of the rich certificate and the CA certificate chain that it received at 1620, together with a security code for the record, by which the record can be located, Lewison, para [0114]).
the presentation apparatus transmits the presentation proof to the verification apparatus, and (At 1730 the prover sends the signature and its random nonce to the verifier, Lewison, para [0126]. The transmission of the presentation proof is the prover’s transmission of the signature and nonce to the verifier in the challenge response proof protocol).
the verification apparatus verifies the presentation proof using the issuer's public key, the presentation part, and the partial message (Verified by the verifier. At 1740 the verifier attempts to verify the signature, Lewison, para [0127]).
As per claim 4, Lewison, Li and discloses the message presentation system according to claim 1, wherein
Furthermore, Lewison discloses:
the presentation apparatus verifies whether the template is falsified based on a generation algorithm of the template and stops a process of generating the presentation proof when the verification fails (Every node in a typed hash tree has a type and a label and a root label. Internal node labels are computed by a specified hash/encoding rule and unauthorized modification changes the root label, the root label acts an omission tolerant checksum, Lewison, para [0055]. The presentation application checks whether the stored typed hash tree includes the required attribute and verification factor subtrees before continuing).
As per claim 5, Lewison, Li and discloses the message presentation system according to the message presentation system according to wherein the presentation apparatus
Furthermore, Lewison discloses:
is connected to an input device, and (The computing equipment comprises a primary computing device 142 such as a desktop or laptop computer, and an ancillary computing device 144 such as a smart phone, both connected to the network 160. The ancillary computing device is equipped with one or more sensors such as a camera 146 and one or more biometric presentation applications 148 capable of obtaining data from the sensors, such as a live video application capable of obtaining live video from the camera and transmitting it over the Internet, Lewison, para [0040])
acquires the presentation biometric information when input of an agreement for outputting the presentation part is received via the input device (A credential presentation application 180 runs on the primary computing device at credential presentation time and interacts with the subject and the verifier in order to present the rich credential to the verifier, proving knowledge of a private key, proving that the subject knows a password, and arranging for one or more biometric presentation applications running on the ancillary device, such as the live video application, to submit one or more biometric samples to the verifier as biometric verification factors in a manner that facilitates presentation attack detection by the verifier, such as a live video of the subject's face reading prompted text, which the verifier verifies against biometric verification data included in the credential such as a facial image of the subject, Lewison, para [0041]).
As per claim 6, Lewison, Li and discloses the message presentation system according to claim 5, wherein
Furthermore, Lewison discloses:
the presentation apparatus generates data for outputting a display screen through which the input of the agreement is received, and (The biometric presentation application receives subject input and a QR code displayed by the credential presentation application on a display of the primary computing device, Lewison, para [0115]. The presentation apparatus generates user facing UI/output on the primary device display as part of the QR-code and this UI is used for user interaction during presentation. This gives a display or UI path and user interaction)
the display screen includes information indicating a message element of the presentation part (The rich certificate comprising a typed hash tree containing a plurality of attributes of the subject and verification data. At 1510 the verifier specifies the attributes to be disclosed and the verification factors to be presented, and the credential presentation application prunes the tree accordingly, Lewison, para [0009], [0104]. The message element of the presentation part corresponds to the selected attributes/verification-data elements that remain in the presentation state copy after pruning).
As per claim 7, Lewison, Li and discloses the message presentation system according to claim 1, further comprising: a log output apparatus, wherein
the log output apparatus (An identification event record, Lewison, para [0114])
stores an encrypted log in which a log related to presentation of the presentation part presented by the presentation apparatus is encrypted with the user's public key or the user's secret key, and the template, (An identification event record where it stores the presentation-state copy, Lewison, para [0114]. The system uses a helper datum and template node associated with biometric processing, Lewison, para [0120]. A biometric cryptosystem key can be used to decrypt user secrets such as passwords or documents, Lewison, para [0109])
acquires log output biometric information for the user, (A second time period, Lewison, para [0021]. The log output biometric information is analogous to the later acquired biometric inputs used to unlock the key).
Furthermore, Li discloses:
generates the user's secret key based on the template and the log output biometric information, (Setup logic outputs helper data based on biometric data and key material and the helper data is stored in NVM, Li, para [0037]. At the second time period the key is recovered using later biometric input and the helper data. The secret key can be unlocked and output and the schemes are used to transform and unlock the key, Li, para [0021]. The verifier regenerates a biometric key from a biometric sample and the helper datum node label and also matches biometric samples against a template node label)
decrypts the encrypted log using the user's secret key, and (The unlocked key can decrypt user secrets such as passwords or documents, Li, para [0002])
outputs the decrypted log (Unlocked and output, Li, para [0021]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Lewison with Li by multifactor privacy-enhanced remote identification using a rich credential (Lewison) with cryptographic key generation based on multiple biometrics (Li). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Lewison with Li in order to effectively maintain safety of a system when data leak occurs (See Li, para [0011])
As per claim 8, Lewison, Li and discloses the message presentation system according to claim 1, further comprising:
Furthermore, Lewison discloses:
a verification apparatus configured to store a verifier's secret key, wherein (The verifier has authenticated itself during the TLS handshake, TLS server certificate and proving knowledge of the private key associated with the certificate, Lewison, para [0123])
the presentation apparatus stores a verifier's public key corresponding to the verifier's secret key, and (Identifier found in the TLS server certificate of the verifier and public key held by the verifier. Public key to be used for verifying in the certificate-chain discussion, Lewison, para [0125])
outputs the partial message that is encrypted with the verifier's public key to the verification apparatus (Presented to the verifier, Lewison, para [0108]- [0109]).
As per claim 9, Lewison, Li and discloses the message presentation system according to claim 1, further comprising:
Furthermore, Li discloses:
a DB, wherein the issuance proof is generated based on the user's public key, a message for issuance process including the message, and the issuer's secret key, (Storing the helper data h.sub.i in a non-volatile memory 150, Li, para [0087])
the DB stores an encrypted message for issuance process generated by dividing the message for issuance process into a plurality of parts and encrypting the parts, and (Divide the key k into plurality of component keys and helper data h may be stored in NVM 150. Dividing the cryptographic key into n component keys and produce the corresponding helper data h_i. Decrypt user secrets such as passwords or documents, Li, para [0084])
selects a part of the encrypted message for issuance process as the encrypted message and transmits the selected part to the presentation apparatus (Send the rich certificate to the credential procurement application. Verifier specifies the attributes to be disclosed and the application checks for the required subtrees, Li, para [0123], claim 7).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Lewison with Li by multifactor privacy-enhanced remote identification using a rich credential (Lewison) with cryptographic key generation based on multiple biometrics (Li). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Lewison with Li in order to effectively maintain safety of a system when data leak occurs (See Li, para [0011]).
As per claim 10, Lewison discloses a presentation apparatus that presents a message, the presentation apparatus comprising:
a processor; and (Processor, Lewison, para [0042])
a memory, wherein the memory stores a template generated based on registration biometric information for a user, an encrypted message in which a message including one or more message elements are encrypted, and an issuance proof generated based on a user's public key corresponding to the template, the message, and an issuer's secret key corresponding to an issuance entity of the message, (The issuer generates a helper datum and a biometric key from the biometric sample obtained prior to issuance and derives a biometric template from the biometric sample obtained prior to issuance and it assigns the helper datum and biometric key and the biometric template, Lewison, para [0092]- [0095]. Here, the stored material is the biometric template and the helper datum generated from the pre-issuance biometric sample. Additionally, Li discloses stored material being the enrollment-derived helper data which is stored in NVM 150).
the processor acquires presentation biometric information for the user, (If a biometric sample is used as a verification factor it must be presented directly to the verifier. The presentation application arranges for biometric apps to submit one or more biometric samples to the verifier, Lewison, para [0006]. The presentation biometric information is analogous presentation-time biometric sample/input obtained from the user and also acquiring/submitting biometric samples for verification during presentation is disclosed)
generat[[es]]ing a presentation proof based on the presentation part, the issuance proof, and the user's secret key, and (The presentation-state copy is created by pruning and that pruning occurs without invalidating a signature computed by the issuing server. The verifier checks the presentation-state copy, including a proof of knowledge of the private key. The presentation application proves knowledge of the private key associated with the public key present in the presentation state copy, Lewison, para [0011] and [0014]. The presentation part is analogous to the selectively pruned presentation-state copy and the issuance proof is analogous the issuance signature that survives pruning and the user’s secret key is similar to the private key side secret whose knowledge is proven)
output[[s]]ing the partial message and the presentation proof (The verifier receives the presentation state copy and the application proves knowledge of the private key associated with the public key in that copy during presentation process, the rich credential is presented to the verifier, Lewison, para [0046] and [0090]. The presentation state copy and the proof of knowledge of the private key generated during presentation protocol are delivered as part of the presentation flow).
However, Lewison does not explicitly disclose the limitations:
generat[[es]]ing a user's secret key corresponding to the user's public key based on the template and the presentation biometric information,
restores the message by decrypting the encrypted message using the user's secret key,
generat[[es]]ing a partial message from the message based on a presentation part that is information for identifying a part presented in the message,
Li discloses:
generat[[es]]ing a user's secret key corresponding to the user's public key based on the template and the presentation biometric information, (In fuzzy extractor recovery, helper data is computed from biometric data at a first time period and later the key k is then extracted from recovered biometric data using the helper data. The later biometric inputs are used with the helper data to determine component keys and then determine the cryptographic key k with later biometric data and stored helper data, the secret key k can be unlocked and output, Li, para [0021] and [0073]. Here, Li discloses the mechanism to recover or unlock key k from stored enrollment-derived helper data plus later biometric input. So, the users secret key corresponding to the user’s public key is the credentials private key side secret, implemented or recovered using the biometric key generation/recovery flow. Lewison discloses the public/private key pair used by the credential)
restores the message by decrypting the encrypted message using the user's secret key, (The biometric-derived key may be used to decrypt user secrets such as passwords or documents at unlock time with later biometric data and helper data the secret key k can be unlocked and output, Li, para [0002] and [0021])
generat[[es]]ing a partial message from the message based on a presentation part that is information for identifying a part presented in the message, (The presentation application agrees on which attributes and factors are to be shown then creates a presentation- state copy containing the agreed upon attributes but omitting other attributes and other verification data before presentation, the application transitions the stored certificate to presentation state by pruning subtrees for attributes not to be disclosed and verification factors not to be presented, Li, para [0011])
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Lewison with Li by multifactor privacy-enhanced remote identification using a rich credential (Lewison) with cryptographic key generation based on multiple biometrics (Li). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Lewison with Li in order to effectively maintain safety of a system when data leak occurs (See Li, para [0011])
However, Lewison in view of Li does not explicitly disclose the limitations:
and in response to determining that the presentation biometric information is sufficiently close to the registration biometric information used to generate the template;
wherein the user's secret key has a fixed value corresponding to the template;
Martinian discloses:
and in response to determining that the presentation biometric information is sufficiently close to the registration biometric information used to generate the template; (Because of error correcting properties of syndrome codes, even if the second biometric parameters P' differs slightly from the first biometric parameters P, a suitably designed syndrome decoder can successfully produce the third biometric parameters P'' that are exactly the same as the first biometric parameters used as the encryption key P 502, Martinian, para [0076]. If syndrome decoding fails, the user is denied access. If syndrome decoding succeeds, then the original biometric parameters are used to verify the authenticity of the user, Martinian, para [0058]. Here, the syndrome decoder 570 has finite error correction capability which is a metric that defines how close it is. The decode is successful when P’ is slightly different from P)
wherein the user's secret key has a fixed value corresponding to the template; (A suitably designed syndrome decoder can successfully produce the third biometric parameters P'' that are exactly the same as the first biometric parameters used as the encryption key P 502, Martinian, para [0076]. Each stored syndrome code can be decoded to yield the original biometric parameters, and to authenticate a user or decrypt data that was encrypted with the biometric data, Martinian, para [0041]. The decoded value E'' 371 is an estimate of the original biometric parameter E 301 used to produce the syndrome code S 331, Martinian, para [0070]. Here, the regenerated key is the same value as the key each time the decode is successful. The presentation biometric functions as decoder side information and doesn’t enter the key’s value)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Lewison and Li with Martinian by multifactor privacy-enhanced remote identification using a rich credential (Lewison) and cryptographic key generation based on multiple biometrics (Li) with biometric user authentication and data encryption (Martinian). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Lewison and Li with Martinian in order to generate identical user secret key from presentation biometrics (See Martinian, para [0070])
As per claim 11, Lewison discloses a message presentation method by a message presentation system, wherein the message presentation system includes a presentation apparatus,
the presentation apparatus stores a template generated based on registration biometric information for a user, (The issuer generates a helper datum and a biometric key from the biometric sample obtained prior to issuance and derives a biometric template from the biometric sample obtained prior to issuance and it assigns the helper datum and biometric key and the biometric template, Lewison, para [0092]- [0095]. Here, the stored material is the biometric template and the helper datum generated from the pre-issuance biometric sample. Additionally, Li discloses stored material being the enrollment-derived helper data which is stored in NVM 150).
an encrypted message in which a message including one or more message elements are encrypted, and (The rich certificate includes a typed hash tree containing a plurality of attributes of the subject and verification data and the presentation copy can omit selected portions. The typed hash tree has an attribute subtree for each attribute, Lewison, para [0099]. Here, the message is analogous to the rich-certificate content inside the typed hash tree and the message elements are the attributes/subtrees items in that tree. Additionally, Li discloses using the biometric derived key to decrypt protected content such as documents. This combination provides the structured message from Lewison and the storing in a protected form and decrypting it with the biometrically recovered key is supplied by Li)
an issuance proof generated based on a user's public key corresponding to the template, the message, and an issuer's secret key corresponding to an issuance entity of the message, (The procurement app sends the public key component to the issuer ad the issuer constructs the typed-hash tree content and then computes the signature 440 on the public key, the metadata and the root label of the typed hash-tree. The rich certificate includes a signature computed on data including the public key and the root label, Lewison, para [0089] and [0099]. The insurance proof is interpreted as the issuer’s signature 440. The user’s public key is analogous to the public key sent by the procurement application and included in the rich certificate. The message is interpreted to be the typed hash tree content represented by the signed root label. The issuing server/certification authority is the issuance entity and its signing key is the issuer secret key)
the message presentation method includes acquiring presentation biometric information for the user by the presentation apparatus, (If a biometric sample is used as a verification factor it must be presented directly to the verifier. The presentation application arranges for biometric apps to submit one or more biometric samples to the verifier, Lewison, para [0006]. The presentation biometric information is analogous presentation-time biometric sample/input obtained from the user and also acquiring/submitting biometric samples for verification during presentation is disclosed)
generat[[es]]ing a presentation proof based on the presentation part, the issuance proof, and the user's secret key by the presentation apparatus, and (The presentation-state copy is created by pruning and that pruning occurs without invalidating a signature computed by the issuing server. The verifier checks the presentation-state copy, including a proof of knowledge of the private key. The presentation application proves knowledge of the private key associated with the public key present in the presentation state copy, Lewison, para [0011] and [0014]. The presentation part is analogous to the selectively pruned presentation-state copy and the issuance proof is analogous the issuance signature that survives pruning and the user’s secret key is similar to the private key side secret whose knowledge is proven)
output[[s]]ing the partial message and the presentation proof by the presentation apparatus (The verifier receives the presentation state copy and the application proves knowledge of the private key associated with the public key in that copy during presentation process, the rich credential is presented to the verifier, Lewison, para [0046] and [0090]. The presentation state copy and the proof of knowledge of the private key generated during presentation protocol are delivered as part of the presentation flow).
However, Lewison does not explicitly disclose the limitations:
generating a user's secret key corresponding to the user's public key based on the template and the presentation biometric information by the presentation apparatus,
restoring the message by decrypting the encrypted message using the user's secret key by the presentation apparatus,
generates a partial message from the message based on a presentation part that is information for identifying a part presented in the message by the presentation apparatus,
Li discloses:
generating a user's secret key corresponding to the user's public key based on the template and the presentation biometric information by the presentation apparatus, (In fuzzy extractor recovery, helper data is computed from biometric data at a first time period and later the key k is then extracted from recovered biometric data using the helper data. The later biometric inputs are used with the helper data to determine component keys and then determine the cryptographic key k with later biometric data and stored helper data, the secret key k can be unlocked and output, Li, para [0021] and [0073]. Here, Li discloses the mechanism to recover or unlock key k from stored enrollment-derived helper data plus later biometric input. So the users secret key corresponding to the user’s public key is the credentials private key side secret, implemented or recovered using the biometric key generation/recovery flow. Lewison discloses the public/private key pair used by the credential)
restoring the message by decrypting the encrypted message using the user's secret key by the presentation apparatus, (The biometric-derived key may be used to decrypt user secrets such as passwords or documents at unlock time with later biometric data and helper data the secret key k can be unlocked and output, Li, para [0002 and [0021])
generat[[es]]ing a partial message from the message based on a presentation part that is information for identifying a part presented in the message by the presentation apparatus, (The presentation application agrees on which attributes and factors are to be shown then creates a presentation- state copy containing the agreed upon attributes but omitting other attributes and other verification data before presentation, the application transitions the stored certificate to presentation state by pruning subtrees for attributes not to be disclosed and verification factors not to be presented, Li, para [0011]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Lewison with Li by multifactor privacy-enhanced remote identification using a rich credential (Lewison) with cryptographic key generation based on multiple biometrics (Li). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Lewison with Li in order to effectively maintain safety of a system when data leak occurs (See Li, para [0011])
However, Lewison in view of Li does not explicitly disclose the limitations:
in response to determining that the presentation biometric information is sufficiently close to the registration biometric information used to generate the template;
wherein the user's secret key has a fixed value corresponding to the template,
Martinian discloses:
in response to determining that the presentation biometric information is sufficiently close to the registration biometric information used to generate the template; (Because of error correcting properties of syndrome codes, even if the second biometric parameters P' differs slightly from the first biometric parameters P, a suitably designed syndrome decoder can successfully produce the third biometric parameters P'' that are exactly the same as the first biometric parameters used as the encryption key P 502, Martinian, para [0076]. If syndrome decoding fails, the user is denied access. If syndrome decoding succeeds, then the original biometric parameters are used to verify the authenticity of the user, Martinian, para [0058]. Here, the syndrome decoder 570 has finite error correction capability which is a metric that defines how close it is. The decode is successful when P’ is slightly different from P)
wherein the user's secret key has a fixed value corresponding to the template, (A suitably designed syndrome decoder can successfully produce the third biometric parameters P'' that are exactly the same as the first biometric parameters used as the encryption key P 502, Martinian, para [0076]. Each stored syndrome code can be decoded to yield the original biometric parameters, and to authenticate a user or decrypt data that was encrypted with the biometric data, Martinian, para [0041]. The decoded value E'' 371 is an estimate of the original biometric parameter E 301 used to produce the syndrome code S 331, Martinian, para [0070]. Here, the regenerated key is the same value as the key each time the decode is successful. The presentation biometric functions as decoder side information and doesn’t enter the key’s value)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Lewison and Li with Martinian by multifactor privacy-enhanced remote identification using a rich credential (Lewison) and cryptographic key generation based on multiple biometrics (Li) with biometric user authentication and data encryption (Martinian). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Lewison and Li with Martinian in order to generate identical user secret key from presentation biometrics (See Martinian, para [0070])
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the
examiner should be directed to RAGHAVENDER CHOLLETI whose telephone number is (703) 756-1065. The examiner can normally be reached Monday - Thursday 8AM-5PM EST & Friday variable.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s
supervisor, RUPAL DHARIA can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be
obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Respectfully Submitted
/RAGHAVENDER NMN CHOLLETI/Examiner, Art Unit 2492
/RUPAL DHARIA/Supervisory Patent Examiner, Art Unit 2492