DETAILED ACTION
This communication responsive to the Application No. 18/923,161 filed on 04/27/2026. Claims 1-6,8,11-16 and 18 are pending and are directed towards METHOD FOR AUTHENTICATING ELECTRONIC DEVICE, AND ELECTRONIC DEVICE THEREFOR
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to arguments
Claim Rejections - 35 USC 101
Applicants’ amendments to claims 1-20 which were rejected under 35 U.S.C. 101 are fully considered and are persuasive. Hence, the rejection under 35 U.S.C 101 has been withdrawn.
Claim Rejections - 35 USC 103
Applicant’s arguments with respect to claim(s) 1-6, 10-16, and 20, 7-9 and 17-19 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Applicants’ amendment resulted in a change of scope of the claims and necessitated new grounds of rejection. The claim now requires a user login to a second server based on identifying that user authentication.
A new reference Choi et al. (US 20170245145 A1), hereinafter referred to as Choi discloses an electronic device that broadcasts a short-range search signal to discover nearby external electronic devices, collects their authentication related information from those that respond and ranks them into a priority order to build a candidate list. It then selects the top priority device from that list and sends it an authentication request, receiving back a determination of authentication success or failure. Upon success, the device grants connection authority corresponding to the account i.e., gates access based on that authentication outcome.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-6,11-16 are rejected under 35 U.S.C. 103 as being unpatentable over Johnston et al. (US 20110072507 A1), hereinafter referred to as Johnston, in view of Choi et al. (US 20170245145 A1), hereinafter referred to as Choi
As per claim 1, Johnston discloses an electronic device comprising:
a communication circuit; (Computer-based system or network 10, Johnston, para [0014])
memory; (Memory devices, Johnston, para [0018])
a user interface module; and (Graphical user interface (GUI), Johnston, para [0027])
at least one processor operatively connected to the communication circuit, the memory and the user interface module, wherein the memory stores instructions that, when executed by the at least one processor individually or collectively, cause the electronic device to: (Client device motherboard, Johnston, para [0027])
identify a plurality of neighboring electronic devices that are capable of performing user authentication in response to a user authentication request; (The user selects the login button and client scans for available authentication devices, Johnston, Fig 3 S104 and S116)
provide, via the user interface module, a list of the plurality of neighboring electronic devices comprising arranged according to the priority order (Client displays list of authentication devices within the GUI, Johnston, Fig 3, S120).
However, Johnston does not explicitly disclose the limitations:
produce a priority order of the plurality of neighboring electronic devices, based on a security level of the plurality of neighboring electronic devices;
transmit a request to an authentication server for performing user authentication using an electronic device selected from the list
identify, via the authentication server, whether the user authentication using the selected electronic device is successfully performed; and
perform a user login to a second server based on identifying that the user authentication using the selected electronic device is successfully performed.
Choi discloses:
produce a priority order of the plurality of neighboring electronic devices, based on a security level of the plurality of neighboring electronic devices; (The processor 120 can determine the order of priority of the external electronic devices, based on at least one of identification information of each of the external electronic devices registered as authentication devices, sensor type information, account information, information representing a master device or not, the latest connection time information, use frequency information, or a combination thereof, Choi, para [0056]. Here, the neighboring electronic devices is analogous to the external electronic devices and master device designation functions as a trust or security tier attribute distinguishing devices, supporting a priority order determination. Master device status is a trust or authority designation among devices analogous to security level that drives the priority ordering)
transmit a request to an authentication server for performing user authentication using an electronic device selected from the list (Receive a request for authentication, to select at least one external electronic device among the one or more external electronic devices for the authentication, to transmit a request for authentication to the at least one external electronic device, using at least one identification information corresponding to the at least one external electronic device among the one or more identification information, and to perform the authentication, based at least on authentication information received from the at least one external electronic device, Choi, para [0008]. Select an external electronic device to request for authentication, among external electronic devices registered as authentication devices, Choi, para [0051]. Here, authentication server is interpreted functionally as a networked computing device that coordinates and determines authentication which is being done by device 1101 as it can be characterized as an authentication server as it performs the authentication side control functions)
identify, via the authentication server, whether the user authentication using the selected electronic device is successfully performed; and (Determine authentication success or non-success based on the authentication information and the random data that are included in the biometric authentication response signal, Choi, para [0059]).
perform a user login to a second server based on identifying that the user authentication using the selected electronic device is successfully performed. (The latest connection time information can be information representing a time point of connecting to a corresponding account based on authentication information received from a corresponding external electronic device, Choi, para [0054]. The 2nd external electronic device 1001-2 can compare the acquired biometric data and previously stored biometric data and perform authentication. In a case where the acquired biometric data and previously stored biometric data are the same as each other, the 2nd external electronic device 1001-2 can determine that authentication succeeds, Choi, para [0197]- [0198]. Here, Choi describes establishing successful authentication followed by account connection).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston and Choi by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi in order to efficiently grant account connection authority (See Choi, para [0059]).
As per claim 2, Johnston and Choi disclose the electronic device of claim 1, wherein
Furthermore, Johnston discloses:
the list of the plurality of neighboring electronic devices is produced based on authentication- related information of the lurality of neighboring electronic devices. (A list of available authentication devices 74 that are found to be present and a list of the various identities stored thereon or the corresponding data entry needed, e.g., fingerprint data, is then presented inside the GUI on the client device display 46, as indicated at 120 and 124. In various embodiments, a username and password may additionally be required to access the list of identities on one or more of the authentication devices 74 found to be present, Johnston, para [0029])
As per claim 3, Johnston and Choi disclose the electronic device of claim 2, wherein
Furthermore, Johnston discloses:
the authentication-related information comprises at least one of device identification information, location information, a security level, or an authentication method in association with the lurality of neighboring electronic devices. (The location of the client device 14, what kind of network the device 14 is connected to, how frequently the client device 14 is inspected and maintained, how many different users are allowed access to the client device 14, who is allowed access to the client device 14 as well as what credentials are required to allow access to the remote server 18, Johnston, para [0049]).
As per claim 4, Johnston and Choi disclose the electronic device of claim 2, wherein the instructions, when executed by the at least one processor individually or collectively, cause the electronic device to:
Furthermore, Choi discloses:
search for the plurality of neighboring electronic devices over a short- range communication network; and (The processor 120 can broadcast a search request signal for searching external electronic devices whose communication coupling is available, using a short-range communication protocol, Choi, para [0044])
obtain the authentication-related information from the plurality of searched neighboring electronic devices. (By receiving a response signal to the search request signal, the processor 120 can search the external electronic device. The biometric authentication information registration response signal can include authentication information (e.g., public key) of the external electronic device and external electronic device related information thereof, Choi, para [0045])
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston and Choi by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi in order to efficiently grant account connection authority (See Choi, para [0059])
As per claim 5, Johnston and Choi disclose the electronic device of claim 4, wherein the instructions,
Furthermore, Choi discloses:
when executed by the at least one processor individually or collectively, cause the electronic device to obtain, from the authentication server, at least one of the authentication-related information or the list of the plurality of neighboring electronic devices (The processor 120 can generate a candidate external electronic device list to request for authentication, based on a list representing external electronic devices whose short-range communication coupling is available and a list representing external electronic devices registered as authentication devices. Choi, para [0051]. Here, the registered list data aligns with the data obtained in association with the authentication serving devices)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston and Choi by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi in order to efficiently grant account connection authority (See Choi, para [0059])
As per claim 6, Johnston and Choi disclose the electronic device of claim 5, wherein the instructions, when executed by the at least one processor individually or collectively, cause the electronic device to:
Furthermore, Choi discloses:
transmit a multi-cast message for searching for the lurality of neighboring electronic devices, to obtain the authentication-related information from the at least one plurality of neighboring electronic devices that responds to the multi-cast message; and (The processor 120 can broadcast a search request signal for searching external electronic devices whose communication coupling is available, using a short-range communication protocol, and determine external electronic devices having transmitted response signals responsive to the search request signal, as the external electronic devices whose short-range communication coupling is available i.e., that responded, Choi, para [0051]. Broadcast is a type of multicast message like a single outgoing message addressed to multiple nearby devices simultaneously. The devices having transmitted response signals are the devices that responded to that message directly).
request the authentication server to perform user authentication using the selected electronic device (The processor 120 can select an external electronic device whose priority order is set highest among external electronic devices registered as authentication devices, and transmit a short-range communication coupling request signal to the selected external electronic device. Transmit a biometric authentication request signal to the selected external electronic device, Choi, para [0057]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston and Choi by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi in order to efficiently grant account connection authority (See Choi, para [0059])
As per claim 11, Johnston disclose a method of an electronic device, the method comprising:
identifying at least one neighboring electronic device capable of performing user authentication in order to perform user authentication for the electronic device; (The user selects the login button and client scans for available authentication devices, Johnston, Fig 3 S104 and S116)
providing a list of the plurality of neighboring electronic devices arranged according to the priority order (Client displays list of authentication devices within the GUI, Johnston, Fig 3, S120).
However, Johnston does not explicitly disclose:
transmitting a request to an authentication server for performing user authentication using an electronic device selected from the list
producing a priority order of a plurality of neighboring electronic devices, based on a security level of the plurality of neighboring electronic devices;
identifying, via the authentication server, whether the user authentication using the selected electronic device is successfully performed; and
perform a user login to a second server based on identifying that the user authentication using the selected electronic device is successfully performed.
Choi discloses:
transmitting a request to an authentication server for performing user authentication using an electronic device selected from the list (Receive a request for authentication, to select at least one external electronic device among the one or more external electronic devices for the authentication, to transmit a request for authentication to the at least one external electronic device, using at least one identification information corresponding to the at least one external electronic device among the one or more identification information, and to perform the authentication, based at least on authentication information received from the at least one external electronic device, Choi, para [0008]. Select an external electronic device to request for authentication, among external electronic devices registered as authentication devices, Choi, para [0051]. Here, authentication server is interpreted functionally as a networked computing device that coordinates and determines authentication which is being done by device 1101 as it can be characterized as an authentication server as it performs the authentication side control functions)
producing a priority order of a plurality of neighboring electronic devices, based on a security level of the plurality of neighboring electronic devices; (The processor 120 can determine the order of priority of the external electronic devices, based on at least one of identification information of each of the external electronic devices registered as authentication devices, sensor type information, account information, information representing a master device or not, the latest connection time information, use frequency information, or a combination thereof, Choi, para [0056]. Here, the neighboring electronic devices is analogous to the external electronic devices and master device designation functions as a trust or security tier attribute distinguishing devices, supporting a priority order determination. Master device status is a trust or authority designation among devices analogous to security level that drives the priority ordering)
identifying, via the authentication server, whether the user authentication using the selected electronic device is successfully performed; and (Determine authentication success or non-success based on the authentication information and the random data that are included in the biometric authentication response signal, Choi, para [0059]).
perform a user login to a second server based on identifying that the user authentication using the selected electronic device is successfully performed. (The latest connection time information can be information representing a time point of connecting to a corresponding account based on authentication information received from a corresponding external electronic device, Choi, para [0054]. The 2nd external electronic device 1001-2 can compare the acquired biometric data and previously stored biometric data and perform authentication. In a case where the acquired biometric data and previously stored biometric data are the same as each other, the 2nd external electronic device 1001-2 can determine that authentication succeeds, Choi, para [0197]- [0198]. Here, Choi describes establishing successful authentication followed by account connection).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston and Choi by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi in order to efficiently grant account connection authority (See Choi, para [0059])
As per claim 12, Johnston and Choi disclose the method of claim 11, wherein
Furthermore, Johnston discloses:
the list of the plurality of neighboring electronic device devices is produced based on authentication- related information of the lurality of neighboring electronic devices. (A list of available authentication devices 74 that are found to be present and a list of the various identities stored thereon or the corresponding data entry needed, e.g., fingerprint data, is then presented inside the GUI on the client device display 46, as indicated at 120 and 124. In various embodiments, a username and password may additionally be required to access the list of identities on one or more of the authentication devices 74 found to be present, Johnston, para [0029]).
As per claim 13, Johnston and Choi disclose the method of claim 12, wherein
Furthermore, Johnston discloses:
the authentication-related information comprises at least one of device identification information, location information, a security level, or an authentication method in associated association with the lurality of neighboring electronic devices. (The location of the client device 14, what kind of network the device 14 is connected to, how frequently the client device 14 is inspected and maintained, how many different users are allowed access to the client device 14, who is allowed access to the client device 14 as well as what credentials are required to allow access to the remote server 18, Johnston, para [0049]).
As per claim 14, Johnston and Choi disclose the method of claim 12, wherein the identifying of the at least one plurality of neighboring electronic devices capable of performing user authentication comprises:
Furthermore, Choi discloses:
searching for the lurality of neighboring electronic devices over a short-range communication network; and (The processor 120 can broadcast a search request signal for searching external electronic devices whose communication coupling is available, using a short-range communication protocol, Choi, para [0044])
obtaining the authentication-related information from the lurality of searched neighboring electronic devices. (By receiving a response signal to the search request signal, the processor 120 can search the external electronic device. The biometric authentication information registration response signal can include authentication information (e.g., public key) of the external electronic device and external electronic device related information thereof, Choi, para [0045])
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston and Choi by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi in order to efficiently grant account connection authority (See Choi, para [0059])
As per claim 15, Johnston and Choi disclose the method of claim 14, wherein at least one of the
Furthermore, Choi discloses:
authentication-related information or the list of the lurality of neighboring electronic devices (The processor 120 can generate a candidate external electronic device list to request for authentication, based on a list representing external electronic devices whose short-range communication coupling is available and a list representing external electronic devices registered as authentication devices. Choi, para [0051]. Here, the registered list data aligns with the data obtained in association with the authentication serving devices)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston and Choi by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi in order to efficiently grant account connection authority (See Choi, para [0059])
As per claim 16, Johnston and Choi disclose the method of claim 15, further comprising:
Furthermore, Choi discloses:
transmitting a multi-cast message for searching for the plurality of neighboring electronic devices, to obtain the authentication-related information from the plurality of at least one neighboring electronic devices that responds to the multi-cast message, and (The processor 120 can broadcast a search request signal for searching external electronic devices whose communication coupling is available, using a short-range communication protocol, and determine external electronic devices having transmitted response signals responsive to the search request signal, as the external electronic devices whose short-range communication coupling is available i.e., that responded, Choi, para [0051]. Broadcast is a type of multicast message like a single outgoing message addressed to multiple nearby devices simultaneously. The devices having transmitted response signals are the devices that responded to that message directly).
requesting the authentication server to perform user authentication using the selected electronic device (The processor 120 can select an external electronic device whose priority order is set highest among external electronic devices registered as authentication devices, and transmit a short-range communication coupling request signal to the selected external electronic device. Transmit a biometric authentication request signal to the selected external electronic device, Choi, para [0057]).
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston and Choi by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi in order to efficiently grant account connection authority (See Choi, para [0059])
Claims 8, 18 are rejected under 35 U.S.C. 103 as being unpatentable over Johnston et al. (US 20110072507 A1), hereinafter referred to as Johnston, in view of Choi et al. (US 20170245145 A1), hereinafter referred to as Choi in further view of Decharms et al. (US 20140368601 A1), hereinafter referred to as Decharms.
As per claim 8, Johnston and disclose the electronic device of claim 1, wherein the instructions,
However, Johnston in view of Choi does not explicitly disclose the limitations:
when executed by the at least one processor individually or collectively, cause the electronic device to provide the list arranged in colors distinguished according to the priority order
Decharms discloses:
when executed by the at least one processor individually or collectively, cause the electronic device to provide the list arranged in colors distinguished according to the priority order (The safety level may be presented as a color. An icon may be presented showing a color- coded representation of the first user's safety level, Decharms, para [0197]. The list is prioritized by level and provides entries with distinct colors corresponding to that level is analogous to the list being arranged in colors distinguished based on the priority order)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston, Choi with Decharms by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi) with mobile security technology (Decharms). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi with Decharms in order to efficiently prioritize list of users using color coding (See Decharms, para [0059])
As per claim 18, Johnston and Choi disclose the method of claim 11, wherein
However, Johnston in view of Choi does not explicitly disclose the limitation:
the providing the list of the plurality of neighboring electronic devices comprises providing the list arranged in colors distinguished according to the priority order
Decharms discloses:
the providing the list of the plurality of neighboring electronic devices comprises providing the list arranged in colors distinguished according to the priority order (The safety level may be presented as a color. An icon may be presented showing a color- coded representation of the first user's safety level, Decharms, para [0197]. The list is prioritized by level and provides entries with distinct colors corresponding to that level is analogous to the list being arranged in colors distinguished based on the priority order)
A person of ordinary skill in the art before the effective filing date of the claimed invention would have combined Johnston, Choi with Decharms by multi-identity access control tunnel relay object (Johnston) and authenticating based on biometric data (Choi) with mobile security technology (Decharms). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to combine Johnston and Choi with Decharms in order to efficiently prioritize list of users using color coding (See Decharms, para [0059])
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RAGHAVENDER CHOLLETI whose telephone number is (703) 756-1065. The examiner can normally be reached M-F 9am-5pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, RUPAL DHARIA can be reached on (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/palents/cocx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Respectfully submitted,
/RAGHAVENDER NMN CHOLLETI/
Examiner, Art Unit 2492
/MICHAEL W CHAO/Primary Examiner, Art Unit 2492