DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
The amendment filed 4/21/2026 has been entered. Claims 1, 8, 15 are currently amended. Claims 1-20 are pending in the application.
Response to Amendment
The objection to claims 1, 8, 15 due to informalities has been withdrawn in light of applicant’s amendment to the claims.
Response to Arguments
Applicant’s arguments, see pages 8-10 of the Remarks filed 4/21/2026 with respect to claims rejected under 35 USC 103 over prior arts of record has been fully considered.
Examiner acknowledges that applicant amended independent claims 1, 8, 15 respectively by including limitation underlined reciting “one or more compliance indicators generated by the authentication agent based on performing one or more compliance checks on the user device, the one or more compliance indicators being associated with one or more compliance requirements for accessing the service”, and “sending, by the service client, the access certificate to the host server for validation using a public key of the access control server”. Upon review, examiner asserts applicant’s argument regarding Ekberg’s tag on compliance indicators and “sending, by the service client, the access certificate to the host server for validation using a public key of the access control server” is persuasive. However, upon further review, examiner asserts Avetisov teaches those limitation(s). Therefore, a updated claim rejections under 35 USC 103 with previously identified prior arts are presented below.
Applicant is encouraged to further include innovative features into the independent claims to advance the case.
Examiner Notes
Examiner cites particular paragraphs, columns and line numbers in the references as applied to the claims below for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the applicant fully consider the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 5, 7-8, 12, 14-15, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Ekberg et al (US20100325427A1, hereinafter, “Ekberg”), in view of Avetisov et al (US20220255931A1, hereinafter, “Avetisov”).
Regarding claim 1, similarly claim 8, claim 15, Ekberg teaches:
A method/A system/A non-transitory computer-readable medium (Ekberg, discloses method and apparatus for authenticating a mobile device to access to service using a tag specific to the mobile device to an authentication platform which generates a public-key certificate using the tag, see [Abstract]) comprising:
receiving, by an authentication agent of a user device (Fig. 1, Authentication Module 109 (i.e., authentication agent of a user device)), a request of a service client of the user device (Fig. 1 User equipment 101 or Mobile device of Fig. 5) for authentication data to access a service provided by a host server (Fig. 1 Application Server 107 (i.e., host server). And refer to Fig. 5 at 501, [0053] In step 501, the authentication platform 103 receives a request from the UE 101 to access a service or application);
requesting, by the authentication agent, an access certificate from an access control server (Fig. 1 or Fig. 2, Authentication Platform 103 (i.e., access control server)), a request for the access certificate comprising [one or more compliance indicators generated by the authentication agent based on performing one or more compliance checks on the user device, the one or more compliance indicators being associated with one or more compliance requirements for accessing the service] ([Abstract] A mobile device initiates transmission of a request to an authentication platform for generating a public-key certificate to access a service. And [0002] The method further comprises initiating transmission of a tag specific to the mobile device to the authentication platform. The tag is used by the authentication platform to generate the public-key certificate (i.e., access certificate). And [0026] As used herein, the term "tag" refers to an identifier or set of identifiers that is unique to the mobile device. In other words, the tag is associated with only one mobile device, and no two mobile devices share the same tag. It is contemplated that the tag may be bound to the mobile device by hardware, software, or a combination thereof);
receiving, by the authentication agent, the access certificate from the access control server ([0059] The process 700 assumes that the authentication module 109 has already requested and received the public-key certificate as described with respect to FIG. 6), the access certificate comprising: an indication that the user device complies with the one or more compliance requirements (see [0026] shown above for using service tag or tag as an indication that the user device complies with the one or more compliance requirements), and [a digital signature of the access control server]; (See Avetisov below for teachings of limitations in brackets above)
providing, to the service client, the access certificate ([0059] The process 700 assumes that the authentication module 109 has already requested and received the public-key certificate as described with respect to FIG. 6) that is to be sent to the host server for validation using a public key of the access control server ([0027] As used herein, the term "public-key certificate" refers to a user's public key signed by a trusted source (e.g., a certification authority (CA)) to verify the authenticity of the public key… public-key cryptography uses a private key to encrypt messages and a public key to decrypt the message... In this way, only the user with the private key can encrypt messages that can then be decrypted using the corresponding public key. And [0060] Once the public-key signature is validated per the process as described with respect to FIG. 5, the authentication module 109 receives a license file from the authentication platform 103 granting access to the service or application (step 707)).
While Ekberg teaches the main concept of the claimed invention shown above, using public-key certificate as access certificate for validation of access request of user equipment (or mobile device) to service, but does not specifically teach the access certificate with digital signature of access control server and following, in the same field of endeavor Avetisov teaches:
one or more compliance indicators generated by the authentication agent based on performing one or more compliance checks on the user device, the one or more compliance indicators being associated with one or more compliance requirements for accessing the service (Avetisov, discloses a process for mobile-initiated authentications to web services, see [Abstract]. e.g., Fig. 1, Auth Server 155 (i.e., access control server). E.g., [0130] the authentication application 120 may receive policy information governing access to a relying device 140 (or web-service like a server providing online resources 147 or services 175A or other assets). Policy information may include one or more rules by which an access request must comply (i.e., one or more compliance checks) for authentication. And [0146] an authentication server 155 may verify access requests received from a mobile device 101, such as by verifying whether the access request complies with a policy, and which may include verification of representations of credentials stored by the user device, or other data, like certificates, such as by signature verification, where data is signed by a private key, or signature key, maintained within a TEE 103 of the mobile device 101 of the user);
a digital signature of the access control server; sending, by the service client, the access certificate to the host server for validation using a public key of the access control server (e.g., [0233] For example, the authentication server 155 may issue a user session by passing (i.e., sending) a user certificate to the relying device 140… the authentication server 155 may sign the user certificate, such as in response to verifying the information received from the mobile device. The signature of the authentication server 155 may convey the verification of the issuance of the user session, such as to a service 175. Thus, for example, presentation of the certificate to the service 175 may convey the provenance (i.e., host server for validation), like a chain of tile, of the certificate and the entities which handled it, e.g., by nested signatures, and which the service 175 may verify based on public keys or signatures keys maintained for the respective entities).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Avetisov in the authentication of mobile device of Ekberg by signing the user certificate. This would have been obvious because the person having ordinary skill in the art would have been motivated to convey the verification of the issuance of the user session to the requested service (Avetisov, [Abstract], [0233]).
Regarding claim 5, similarly claim 12, claim 19, Ekberg-Avetisov combination teaches the method of claim 1, the system of claim 8, the non-transitory computer-readable medium of claim 15,
Ekberg further teaches: wherein the access certificate further comprises a public key of the user device and an indication of one or more memberships of the user device in one or more resource groups of the host server ([0027] Therefore, a recipient of a message that can be decrypted by the public key has assurance that the message came from a sender possessing the private key. To transform a public key into a public-key certificate, a trusted source (e.g., the CA) can verify the identity of the user possessing the private to bind that particular user to the private/public key combination. By certifying the public key, the CA also gives confidence to others who trust the CA that the public-key certificate is bound to the a particular user or mobile device, thereby enabling the public-key certificate to, for instance, authenticate a mobile device to access a restricted service or application).
Regarding claim 7, similarly claim 14, Ekberg-Avetisov combination teaches the method of claim 1, the system of claim 8,
Avetisov further teaches: wherein the one or more compliance requirements are associated with a configuration communication between the access control server and the host server ([0148] The authentication application 120 may be configured to generate, based on the policy, an access request which the mobile device 101 transmits to a server or service in a mobile initiated authentication process for authentication. The server or service may verify credential information provided by the mobile device 101 and verify compliance with a policy, and issue a session to a relying device 140 if the user is deemed authenticated based on the verification). Same motivation as presented in claim 1, 8 would apply.
Claims 2, 9, 16 are rejected under 35 U.S.C. 103 as being unpatentable over Ekberg-Avetisov as applied above to claim 1, 8, 15 respectively, further in view of Calero et al (US20120278873A1, hereinafter, “Calero”).
Regarding claim 2, similarly claim 9, claim 16, Ekberg-Avetisov combination teaches the method of claim 1, the system of claim 8, the non-transitory computer-readable medium of claim 15,
The combination of Ekberg-Avetisov does not specifically teach, in the same field of endeavor Calero teaches:
wherein the authentication agent of the user device is a modular authentication agent, and wherein the modular authentication agent is interchangeable with a second authentication agent not in communication with the access control server (Calero, discloses for resource operation based on usage, sharing, and recommendations with modular authentication. And [0071] Services can be made available to users independent of the authentication service or identity provider, which own the identities of those users. In other words, a user can be associated with multiple authentication mechanisms and can be authenticated with any available mechanism at any location with any device all based on a combination of the device capabilities and the end user preferences).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Calero in the authentication of mobile device of Ekberg-Avetisov by using modular authentication. This would have been obvious because the person having ordinary skill in the art would have been motivated to allow user being associated with multiple authentication mechanisms and being authenticated with any available mechanism at any location (Calero, [Abstract], [0071]).
Claims 3, 10, 17 are rejected under 35 U.S.C. 103 as being unpatentable over Ekberg-Avetisov as applied above to claim 1, 8, 15 respectively, further in view of Wilson et al (US20230388787A1, hereinafter, “Wilson”).
Regarding claim 3, similarly claim 10, claim 17, Ekberg-Avetisov combination teaches the method of claim 1, the system of claim 8, the non-transitory computer-readable medium of claim 15,
The combination of Ekberg-Avetisov does not specifically teach, in the same field of endeavor Wilson teaches:
wherein the service client communicates with the host server using a Secure Shell (SSH) protocol, and wherein the authentication agent of the user device communicates with the service client using a SSH Agent protocol (Wilson, discloses methods and systems of key management to securely grant access to components of a cloud-based data processing system, see [Abstract]. And [0020] the secure shell (SSH) protocol used by an authorized user is augmented using a plugin or the like that consults a key vault used to store private keys. If the authenticated user wishes to connect to a secured service from an SSH session, for example, the user supplies the public key for the appropriate service being accessed, and the SSH plugin (i.e., SSH Agent protocol) is able to consult the user's profile to verify that proper access is allowed).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Wilson in the authentication of mobile device of Ekberg-Avetisov by implementing access to cloud-based service using SSH protocol using SSH plugin for authorized user. This would have been obvious because the person having ordinary skill in the art would have been motivated to securely grant access to components of a cloud-based data processing system (Wilson, [Abstract]).
Claims 4, 11, 18 are rejected under 35 U.S.C. 103 as being unpatentable over Ekberg-Avetisov as applied above to claim 1, 8, 15 respectively, further in view of Xu et al (US20170223012A1, hereinafter, “Xu”).
Regarding claim 4, similarly claim 11, claim 18, Ekberg-Avetisov combination teaches the method of claim 1, the system of claim 8, the non-transitory computer-readable medium of claim 15,
The combination of Ekberg-Avetisov does not specifically teach, in the same field of endeavor Xu teaches:
wherein the access certificate is a limited-duration access certificate, the method further comprising: requesting using a second request, prior to an expiration time of the limited-duration access certificate, a second limited-duration access certificate from the access control server, the second request comprising one or more continued compliance indicators (Xu, discloses system and method for determining whether a client device complies with compliance rules while authenticating a user account, see [Abstract]. And [0029] A management component 179 executed on the client device 112 can send a certificate to the key distribution service 166 to authenticate the client device 112. The key distribution service 166 can verify the certificate is valid and issue a ticket to the management component 179. To verify the certificate is valid, the key distribution service 166 can determine that the certificate is signed by the certificate authority 115. The key distribution service 166 can also ensure data within the certificate is valid. As an example, the key distribution service 166 can determine whether the certificate has expired based on a time range specified in the certificate).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Xu in the authentication of mobile device of Ekberg-Avetisov for verifying the certificate being expired based on time range specified in the certificate. This would have been obvious because the person having ordinary skill in the art would have been motivated to determine whether a client device complies with compliance rules to control client devices to access company resources (Xu, [Abstract], [0002]).
Claims 6, 13, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Ekberg-Avetisov as applied above to claim 1, 8, 15 respectively, further in view of Turner et al (US20220070002A1, hereinafter, “Turner”).
Regarding claim 6, similarly claim 13, claim 20, Ekberg-Avetisov combination teaches the method of claim 1, the system of claim 8, the non-transitory computer-readable medium of claim 15,
The combination of Ekberg-Avetisov does not specifically teach, in the same field of endeavor Turner teaches:
further comprising: using a second access certificate to connect to a virtual private network (VPN) associated with the host server prior to the service client sending the access certificate to the host server for validation (Turner, discloses system and method for implementing an multi-service simple certificate enrollment protocol (SCEP) based authentication system, see [Abstract]. And [0046] at step 306, the authentication service 133 can receive a request from a client application 143 to access a restricted or access-controlled resource. For example, the authentication service 133 could receive a request … a request from a virtual private network (VPN) client to access a VPN network... The access request can include access credentials, such as a copy of a token signing certificate 159, an authentication token 163, and a signature for the authentication token 163).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Turner in the authentication of mobile device of Ekberg-Avetisov for implementing an multi-service simple certificate enrollment protocol. This would have been obvious because the person having ordinary skill in the art would have been motivated to authenticate user to access service after validation by authentication server (Turner, [Abstract]).
Citation of References
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action:
Khait et al (US20160344736A1) discloses method and proxy device for securing an access to a cloud-based application.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL M LEE whose telephone number is (571)272-1975. The examiner can normally be reached on M-F: 8:30AM - 5:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on (571) 272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MICHAEL M LEE/Primary Examiner, Art Unit 2436