DETAILED ACTION
This communication is in response to the applicant’s amendment filed on June 12, 2026. Claims 1-20 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed on 06/12/2026 have been fully considered but are moot in view of the new ground(s) of rejection.
Allowable Subject Matter
Claims 5 and 16 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The bold portion was not found upon searching: “generating the constructed credential key when a third time difference between the third time and the first time is less than a second pre-determined time threshold different than the first pre-determined time threshold”.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 6-7, 10, 11, 12, 17, 18 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over US PGPUB No. 20200301793 A1 to Tomlinson et al (hereinafter Tomlinson) in view of US PG-PUB No. 20140208112 A1 to McDonald et al. (hereinafter McDonald).
As per claim 1, Tomlinson teaches a computer-implemented method for credential key distribution for access control (Tomlinson, par 0002, “systems and methods by which such a quorum-based principle is realised for data processing in a computing environment, such as encryption, authentication, data retrieval, access control, etc.”) comprising:
receiving, by a reader device from a provisioning device, a full credential key for unlocking a security device (Tomlinson, par 0052-0055, Fig. 1, quorum system 5 includes key generator module 22 that generates or retrieves secret key 19, and an authentication module 13 for “verifying the recovered secret key 19 and authorising access…”, par 0052, the secured computing environment may facilitate “secured access…via an electronic lock of a physical building, lab, vault, safe deposit box, critical infrastructure system, etc.”, par 179, “…the quorum verification device may be incorporated as a processing module or element of…a device controlling access to a secured asset, such as an electronic lock that is unlocked in response to receiving the correct reconstructed passcode.” The Examiner notes that where the verification/access-controlling device performs authentication by verifying the recovered secret key, the full credential key must necessarily be available at that device for verification purposes, and thus transmission of the full key from the generating entity to the verification device is implied.);
receiving, by the reader device from a first electronic device, a first sub-credential key generated based at least in part on the full credential key (Tomlinson, par 0004, “… generating, by a server, a plurality of quorum portions from original data, wherein the original data is a secret key for encrypting or decrypting data within a secured computing environment”, par 0053-0054, 0072, quorum system 5 receives quorum keys 17 from respective computing devices 3 of available participants, where each quorum key is generated from the secret key 19; par 179, verification device receives quorum portions from participant devices including “authentication token[s],” “security dongle[s],” and computing devices with “wireless data communication interface[s]”);
receiving, by the reader device from a second electronic device, a second sub-credential key generated based at least in part on the full credential key (Tomlinson, par 0053-0054, 0072-0074, Fig. 6A-6B: quorum data processing module 15 receives quorum keys 17 from multiple respective computing devices 3-1 to 3-N of different participants; e.g., quorum keys received from participants 1, 2, and 4 as shown in FIG. 6A, par 0123, “… a quorum data verification module 55 that receives a plurality of quorum portions 33 from a quorum of authorised participants…”);
generating, by the reader device, a constructed credential key based at least in part on the first sub-credential key and the second sub-credential key (Tomlinson, par 0071-0074, and FIG. 5, quorum data processing module 15 recovers/reconstructs the original secret key 19 from the received quorum keys 17 using majority voting at each digit position; see also par 0104-0113: second embodiment reconstructs secret key from received quorum code portions using equation solving);
generating, by the reader device, a determination that the constructed credential key corresponds to the full credential key based at least in part on a comparison between the constructed credential key with the full credential key (Tomlinson, par 0055, authentication module 13 “…for verifying the recovered secret key 19 and authorising access to another data processing module or entity”, par 0116-0119, quorum data processing module “determines the reconstructed secrets that contain the predefined redundant data, thus deemed to be correct, and also determines the reconstructed secrets that do not contain the predefined redundant data, thus deemed to be erroneous or corrupted”, par 0135-0136, verification module “compares the reconstructed hash digests…with the hash digests of the corresponding purported partial key…to identify discrepancies.” The Examiner finds that the authentication module’s verification of the recovered secret key constitutes generating a determination that the constructed key corresponds to the full key based at least in part on a comparison, since verification inherently requires comparison against a known reference);
unlocking, by the reader device, the security device with the constructed credential key based at least in part on the determination that the constructed credential key corresponds to the full credential key (Tomlinson, par 0052,“ As another example, the secured computing environment may facilitate controlled access to the original secure data file, by reconstructing the original secret data based on quorum data received from a quorum of authorised personnel. As yet another example, the secured computing environment may facilitate secured access by a quorum of authenticated personnel to a product or service (e.g. a bank account, a secure web site), and/or a facility (e.g. via an electronic lock of a physical building, lab, vault, safe deposit box, critical infrastructure system, etc.)”, par 0179, “ As yet another example, the quorum verification device may be configured with an interface for receiving user input of the respective quorum key or code portions, and to output the reconstructed data temporarily on a display, or to communicate the reconstructed data to a further data processing device for example to complete decryption of data using the reconstructed secret key, or to a device controlling access to a secured asset, such as an electronic lock that is unlocked in response to receiving the correct reconstructed passcode.” Examiner Note – The quorum verification device may allow access to the secured asset upon doing the determination that the correct key has been reconstructed. The act of unlocking the device implies that the positive determination has been made by the reader device.);
Tomlinson does not explicitly teach that the full credential key is received by the reader device (i.e., the access-controlling verification device) from a separate provisioning device in a distinct transmission step prior to receiving the sub-credential keys from the participant devices. While Tomlinson’s quorum system 5 generates the secret key and performs verification, Tomlinson does not expressly disclose the architecture in which a provisioning device transmits the full key to a physically separate reader device that controls access to the security device; however, in an analogous art in access control, McDonald teaches a system in which a base computer 502 (provisioning device) is used to define a master key 504 and divided shares of the master key 508, and the base computer transmits key material to separate devices for subsequent use in authentication (McDonald, par 0041, FIG. 5: “a base computer 502 may be used to define a master key 504, an encrypted account credential 506, and the divided shares of the master key 508. The base computer 502 may then transmit the encrypted account credential 522 and the first share 524 of the master key to a first device 520. The base computer 502 may also transmit the second share 534 of the master key to a second device 530.”). McDonald further teaches that the device performing reconstruction receives key material from the provisioning entity for use in the authentication/access process (McDonald, par 0041-0042);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the quorum-based access control system of Tomlinson such that the full credential key is transmitted from the quorum system (acting as a provisioning device) to a separate reader device that controls access to the security device, as suggested by McDonald’s architecture of a base computer distributing key material to separate purpose-specific devices. One of ordinary skill in the art would have been motivated to make this modification because: (1) separating the key generation/provisioning function from the access control/verification function is a well-known architectural design principle that improves system modularity and security by isolating functions across distinct devices (see McDonald, par 0041); (2) Tomlinson itself suggests that the verification device “may be incorporated as a processing module or element of…a device controlling access to a secured asset” (par 0179), indicating that the verification/access-controlling device can be separate from the quorum generation system; and (3) providing the full key to the reader device enables straightforward local comparison-based verification without requiring the reader device to rely on indirect verification methods (such as redundancy-based or hash-based checks), thereby simplifying the verification process and improving reliability.
As per claim 6, Tomlinson-McDonald teaches the computer-implemented method of claim 1, further comprising determining, by the reader device, a first distance between the first electronic device and the reader device, and a second distance between the second electronic device and the reader device, wherein generating the constructed credential key includes generating the constructed credential key when the first distance and the second distance are each less than a pre-determined distance threshold (Tomlinson, par 0178, “The quorum participants have to be at, or within, a predefined geographical location, or at the same location as the other participants, in order for the original data to be reconstructed.”, McDonald, par 0027, credential communication between devices requires each device to be “located within a pre-defined physical proximity range” of the receiving device; It would have been obvious to one of ordinary skill in the art to implement Tomlinson’s spatial requirement for quorum reconstruction (par 0178) as a per-device distance threshold measured at the reader device, as suggested by McDonald’s concept of a “pre-defined physical proximity range” (par 0027), in order to ensure all authorized parties are physically present when the security device is unlocked).
As per claim 7, Tomlinson-McDonald teaches the computer-implemented method of claim 1, further comprising receiving, by the reader device from a third electronic device, a third sub-credential key, wherein generating the constructed credential key includes generating the constructed credential key without the third sub-credential key (Tomlinson, par 0053-0054, 0072 and Fig 6A: quorum data processing module 15 receives quorum keys 17 from respective computing devices 3, including from participants 1, 2, and 4 — i.e., three separate devices; par 0047, “the number of quorum participants required to form a quorum can be predetermined and can be less than the total number of quorum participants”; i.e., the reader device may receive sub-credential keys from three participant devices but reconstruct the secret key using only a minimum threshold number of those keys).
As per claim 10, Tomlinson-McDonald teaches the computer-implemented method of claim 1, wherein generating the constructed credential key includes generating the constructed credential key through a process associated with a cryptographic algorithm (Tomlinson, par 0012 “The quorum portions can be generated based on a cryptographic encoding of the original data together with hash digests of partial encryption keys distributed between quorum participants, wherein the cryptographic encoding is based on combinations of said partial encryption keys.”, Tomlinson, par 0055 “ The quorum system 5 can also include a cryptography module 11 for encrypting data based on the secret key 19 and for decrypting data based on the recovered secret key 19”).
As per claim 11, Tomlinson-McDonald teaches the computer-implemented method of claim 1, wherein determining that the constructed credential key corresponds to the full credential key includes determining that the constructed credential key matches the full credential key. (Tomlinson, par 0052, “As another example, the secured computing environment may facilitate controlled access to the original secure data file, by reconstructing the original secret data based on quorum data received from a quorum of authorised personnel.” Examiner Note – The reference teaches that access is given by reconstructing the original secret data based on the quorum keys. This matches the limitation wherein the constructed credential key matches the full credential key.).
Claim 12 recites substantially the same limitation as claim 1, in which the computer-implemented method generates and distributes sub-credentials based on a full credential that is used to unlock a security device, in the form of one of more non-transitory computer readable media, therefore it is rejected under the same rationale.
Claim 17 recites substantially the same limitation as claim 6, in which the computer-implemented method generates the constructed credential key when the distances are within the pre-determined threshold, in the form of one of more non-transitory computer readable media, therefore it is rejected under the same rationale.
Claim 18 recites substantially the same limitation as claim 1, in which the computer-implemented method generates and distributes sub-credentials based on a full credential that is used to unlock a security device, in the form of a system, therefore it is rejected under the same rationale.
Claim 20 recites substantially the same limitation as claim 6, in which the computer-implemented method generates the constructed credential key when the distances are within the pre-determined threshold, in the form of a system, therefore it is rejected under the same rationale.
Claims 2, 8, 13, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Tomlinson in view of McDonald as applied to claim 1 above, and further in view of US 20220024408 A1 to Narumi (hereinafter Narumi).
As per claim 2, Tomlinson-McDonald teaches the computer-implemented method of claim 1. Tomlinson- McDonald does not explicitly teach receiving the first sub-credential key includes receiving the first sub-credential key at a first time and receiving the second sub-credential key includes receiving the second sub- credential key at a second time after the first time; and generating the constructed credential key includes generating the constructed credential key when a first time difference between the second time and the first time is less than a first pre-determined time threshold; However, in a analogous art of authentication that receive key information from multiple user terminals, Narumi disclosed receiving the first sub-credential key includes receiving the first sub-credential key at a first time and receiving the second sub-credential key includes receiving the second sub-credential key at a second time after the first time (Narumi, par 0028-0029: portable terminal 8a transmits main-key information Dk1 through near-range wireless communication (BLE) to authentication device 11, and authentication device 11 receives and authenticates the main-key information Dk1; par 0039, subsequently, portable terminal 8b transmits sub-key information Dk2 through BLE communication to authentication device 11, and authentication device 11 receives and authenticates the sub-key information Dk2. The authentication device 11 thus receives key credentials from two different user terminals at two different times, with the second key necessarily received after the first.);
Narumi further teaches that the sub-key information Dk2 includes temporal validity constraints, specifically “information such as the valid period of the sub-key information Dk2” (par 0020) and “date and time for use (reserved date and time)” encoded within the sub-key (par 0038). Thus, the authentication device must receive and authenticate the sub-key within a defined temporal window;
Tomlinson additionally teaches imposing temporal constraints on credential presentation for quorum-based access, specifically that “quorum participants have to input their data at predefined times or dates in order for the original data to be reconstructed” (Tomlinson, par 0178) and that quorum portions include metadata with “an expiry date and/or time for the associated quorum portion” (Tomlinson, par 0164);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the quorum-based access system of Tomlinson-McDonald, which receives multiple sub-credential keys from multiple devices, to implement time-bounded sequential key receipt as taught by Narumi and to further implement a time-difference threshold between consecutive key receipts based on Tomlinson’s temporal constraint teachings. One of ordinary skill in the art would have been motivated to make this modification because: (1) Narumi demonstrates that receiving key credentials from multiple user terminals at an authentication device inherently occurs sequentially (par 0028-0039), establishing the baseline architecture for time-separated credential receipt; (2) Narumi’s teaching of “valid period” for sub-keys (par 0020) establishes the principle of imposing temporal constraints on credential validity at the authentication device; (3) Tomlinson’s teaching that participants “have to input their data at predefined times” (par 0178) with expiry metadata (par 0164) confirms that temporal gating on credential presentation is essential for security in multi-party access systems.
As per claim 8, Tomlinson-McDonald teaches the computer-implemented method of claim 1, Tomlinson-McDonald does not explicitly teach wherein receiving the first sub-credential key and the second sub-credential key includes receiving the first sub-credential key and the second sub-credential key through at least one of a near-field communication protocol, a Bluetooth® low energy protocol, or an ultra-wideband protocol. However, Narumi receiving the first sub-credential key and the second sub-credential key includes receiving the first sub-credential key and the second sub-credential key through at least one of a near-field communication protocol, a Bluetooth® low energy protocol, or an ultra-wideband protocol (Narumi, par 0039, “The sub-key information Dk2 is transmitted through, for example, Bluetooth Low Energy (BLE) communication. When the authentication device 11 receives the sub-key information Dk2, the authentication device 11 authenticates the sub-key information Dk2.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the invention of Tomlinson to further incorporate receiving the sub-credential keys through a communication, low energy, or ultra-wideband protocol as taught by Narumi, in order to allow for communication (Narumi, par 0039).
Claim 13 recites substantially the same limitation as claim 2, in which the computer-implemented method generates a constructed credential based on comparing time thresholds, in the form of one of more non-transitory computer readable media, therefore it is rejected under the same rationale.
Claim 19 recites substantially the same limitation as claim 2, in which the computer-implemented method generates a constructed credential based on comparing time thresholds, in the form of a system, therefore it is rejected under the same rationale.
Claims 3, 4, 14, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Tomlinson in view of McDonald and Narumi as applied to claim 2 above, and in further view of US 20190020646 A1 to Magyar et al (hereinafter Magyar).
As per claim 3, Tomlinson-McDonald-Narumi teaches the computer-implemented method of claim 2, Tomlinson-McDonald-Narumi does not teach but in related art in access security, Magyar teaches: receiving, by the reader device from a third electronic device, a third sub-credential key at a third time after the second time, wherein generating the constructed credential key includes generating the constructed credential key based at least in part on the third sub-credential key (Magyar, par 0025, “As shown, the master password 124 is rendered as multiple password parts, all of which are required to decrypt the password vault 110 but none of which is capable of decrypting the password vault 110 individually. Three password parts, K1, K2, and K3, are specifically shown. For proper operation, the master password 124 should be rendered with a minimum of two password parts, and any number of passwords parts greater than one is permitted.”, Magyar, par 0026, “In the illustrated example, all three key parts K1, K2, and K3 are required to decrypt the password vault 110.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Tomlinson-McDonald-Narumi to require three sub-credential keys from three respective devices as taught by Magyar (¶[0025]-[0026]), because increasing the number of required key portions in a multi-party access control system is a well-known security measure that reduces the risk of unauthorized access by requiring additional authorized participants to be present.
As per claim 4, Tomlinson-McDonald-Narumi-Magyar teaches the computer-implemented method of claim 3, wherein generating the constructed credential key includes generating the constructed credential key when a second time difference between the third time and the second time is less than the first pre-determined time threshold (Narumi, par 0028-0039, sequential key credential receipt at an authentication device, par 0020, 0038, temporal validity constraints (“valid period”)on credential presentation (“date and time for use”); Tomlinson, par 0178, “quorum participants have to input their data at predefined times or dates in order for the original data to be reconstructed”, i.e., temporal constraints apply to ALL quorum participants’ inputs, and par 0164, “expiry date and/or time for the associated quorum portion”, i.e., EACH quorum portion includes its own temporal validity metadata); It would have been obvious to one of ordinary skill in the art to apply the same time-difference threshold between consecutive credential receipts (as established in claim 2 between the first and second receipts) equally to the time difference between the second and third receipts. One of ordinary skill would have been motivated because: (1) Tomlinson’s temporal constraint in ¶[0178] applies to “quorum participants” (plural) — indicating ALL participants must satisfy temporal requirements, not just the second one; (2) Tomlinson’s per-portion expiry metadata (¶[0164]) demonstrates that each portion is subject to its own temporal validity, supporting uniform temporal treatment; (3) applying a consistent time-difference threshold to each consecutive pair of credential presentations serves the same security purpose (preventing relay attacks and ensuring temporal co-presence of all authorized users) regardless of which pair is being measured.
Claim 14 recites substantially the same limitation as claim 3, in which the computer-implemented method generates the full key based at least in part on the third sub key, in the form of one of more non-transitory computer readable media, therefore it is rejected under the same rationale.
Claim 15 recites substantially the same limitation as claim 4, in which the computer-implemented method validates the time threshold between two keys, in the form of one or more non-transitory computer-readable media, therefore it is rejected under the same rationale.
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Tomlinson in view of McDonald and Narumi as applied to claim 8 above, and further in view of US 20250379727 A1 to Kim et al (hereinafter Kim).
As per claim 9, Tomlinson-Narumi teaches the computer-implemented method of claim 8, Tomlinson-Narumi does not teach wherein receiving the first sub-credential key and the second sub-credential key includes receiving the first sub-credential key and the second sub-credential key through an Aliro™ protocol. In an analogous art in the endeavor, Kim teaches receiving the first sub-credential key and the second sub-credential key includes receiving the first sub-credential key and the second sub-credential key through an Aliro™ protocol (Kim, par 0062, “The communication unit 110 provides an interface for communicating with other servers or devices (for example, terminals or reader devices) in the network. For example, the communication unit 110 may transmit and receive signals with other servers or devices in the network. …. The communication unit 110 enables the Aliro network to communicate with other devices via at least one interface.”);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the invention of Tomlinson-Narumi to incorporate receiving the sub-credential keys through an IoT communications protocol as taught by Kim, in order to enable the user or user device to access a reader device quickly and conveniently (Kim, par 0055).
Conclusion
The prior art is made of record and not relied upon is considered pertinent to applicant’s disclosure:
Wong (US 20060271783 A1) discloses a multiparty authorization system for sensitive database operations in which key-shares are received from multiple approving parties, a key is constructed from those shares, and authorization is granted when the constructed key matches a stored copy of the original key (par 0051). The system also teaches imposing temporal deadlines within which each approval must be received (par 0037).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Linglan Edwards whose telephone number is (571)270-5440. The examiner can normally be reached 8:30am - 5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
LINGLAN EDWARDS
Supervisory Patent Examiner
Art Unit 2408
/LINGLAN EDWARDS/ Supervisory Patent Examiner, Art Unit 2408