Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The present office action is responsive to communication received 4/27/2026.
Claims 1-20 are pending.
Claims 1-20 have been amended.
Response to Arguments
Applicant's arguments filed 4/27/2026 have been fully considered but they are not persuasive. The applicant argues Zimmerman fails to disclose the claim limitation “wherein the at least one processor is configured to emulate a network adapter to the host device”. The examiner respectfully disagrees and believes Zimmerman [0041] discloses a processor emulating a Wi-Fi adapter. The Wi-Fi adapter is interpreted to be the network adapter.
The applicant argues Ellington fails to disclose the claim limitation “wherein the authentication data is received from a web application instantiated at a browser of the host device”. The examiner respectfully disagrees and believes that Ellington [0105] discloses receiving authentication data from an application instantiated on a dedicated browser. Ellington states the received authentication data is from an application which can be one instantiated at the browser as stated in [0105][0107].
Claim interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
This application includes one or more claim limitations that use the word “means” or “step” but are nonetheless not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph because the claim limitation(s) recite(s) sufficient structure, materials, or acts to entirely perform the recited function. Such claim limitation(s) is/are: “means for storing data”, “means for coupling with the host device via a first communication channel”, “means for coupling with the host device via the second channel”, “means for receiving authentication data”, and “means for verifying the authentication data” in claim 20.
Because this/these claim limitation(s) is/are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are not being interpreted to cover only the corresponding structure, material, or acts described in the specification as performing the claimed function, and equivalents thereof.
If applicant intends to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to remove the structure, materials, or acts that performs the claimed function; or (2) present a sufficient showing that the claim limitation(s) does/do not recite sufficient structure, materials, or acts to perform the claimed function.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3-10, 12, 14-18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over by Zimmerman et al. (US 20220086928) in view of Ellington et al. (US 20250150438).
Regarding claim 1,
Zimmerman teaches A data storage device comprising:
a storage medium with at least a secured partition that stores user data;
[an example of a data storage device 1 including a communication interface 3, storage medium 19, and at least one processor 7. (Zimmerman et al., paragraph 39)]
a communication interface enabling communication with a host device;
[an example of a data storage device 1 including a communication interface 3, storage medium 19, and at least one processor 7. (Zimmerman et al., paragraph 39)]
And at least one processor operable to:
[an example of a data storage device 1 including a communication interface 3, storage medium 19, and at least one processor 7. (Zimmerman et al., paragraph 39)]
communicatively couple with the host device using, a first communication channel, wherein the at least one processor emulates a network adapter to the host device,
[the at least one processor 7 emulating a Wi-Fi adapter sends 103, via the communication interface 3, (Zimmerman et al., paragraph 41)]
And wherein the first communication channel is enabled by an Ethernet over Universal Serial Bus (USB) protocol driver;[a USB (universal serial bus) bridge to enumerate with the host device 5. (Zimmerman et al., paragraph 48)]
communicatively couple with the host device using, a second communication channel,
wherein the second communication channel enables communication between the storage medium and the host device,
[emulates a Wi-Fi adapter 9 to the host device 5. Preferably, the at least one processor 7 emulates a generic Wi-Fi adapter 9 that is supported by the operating system of the host device 5. That is, emulating a standard PnP Wi-Fi adapter. The advantage is that such an emulated device can communicate with the operating system without additional drivers, software or special settings. In one example, the emulated Wi-Fi adapter 9 is seen as a USB device by the host device 5. (Zimmerman et al., paragraph 74)]
and wherein the second communication channel is enabled by a USB mass storage driver;
[That is, the communication interface 3 can function as a USB hub. One peripheral device is as a mass data storage device, whereby the host uses the storage medium 19 to store, read, and write, user content data. (Zimmerman et al., paragraph 49)]
receive, using the first communication channel, authentication data from the host device, wherein the authentication data is received from a [web application] instantiated at a browser of the host device;[the authentication data 61 is then sent 309 from the host device 5, via the communication interface 3, to be received 107 by the at least one processor 7 as illustrated in FIG. 10. (Zimmerman et al., paragraph 82)]
verify that the received authentication data corresponds to a record in an authentication data set;
[The at least one processor 7 then verifies 109 that the received authentication data 61 corresponds to a record 63 in an authentication data set 65. (Zimmerman et al., paragraph 83)]
And in response to verifying the received authentication data, selectively enable access between the host device and the secured partition using the second communication channel.
[device authorizes 111 additional function(s) 67 of the data storage device 1. In this example, the additional function(s) includes selectively enabling access 113 to at least part of the storage medium 19 (that is authorized for the corresponding authentication data) (Zimmerman et al., paragraph 85)]
Zimmerman fails to explicitly disclose a web application, however in an analogous art Ellington discloses a web application.
[receiving authentication data from an application (e.g., a dedicated browser) running on the client device, and determine, using the authentication data from the application running on the client device, the authentication status of the user. (Ellington et al., paragraph 105, 107)]
Zimmerman and Ellington are considered to be analogous to the claimed invention because they are in the same field of authentication data. Therefore, it would have been obvious to one of ordinary skill in the art before the instant application effective filing date of the claimed invention to have modified the teachings of Zimmerman to incorporate the teachings of Ellington et al. to include a web application, in order to determine the authentication status of the user. (Ellington et al., paragraph 105)]
Regarding claim 12,
Zimmerman teaches a method comprising:
[Disclosed herein is a method for a data storage device to communicate with a host device, the method comprises communicatively coupling with a host device, (Zimmerman et al., paragraph 20)]
The claim recites substantially the same content as claim 1 and is rejected with the rationales set forth for claim 1.
Regarding claim 20,
Zimmerman teaches a data storage device comprising:
[Disclosed herein is a method for a data storage device to communicate with a host device, the method comprises communicatively coupling with a host device, (Zimmerman et al., paragraph 20)]
The claim recites substantially the same content as claim 1 and is rejected with the rationales set forth for claim 1.
Regarding claims 3 and 14,
Zimmerman in view of Ellington discloses the data storage device of claim 1, wherein the storage medium stores the web application, and wherein the at least one processor is further operable to:
[Additional functions can include enrolling user(s) and their authentication data 61 and storing related information into the authentication data set 65. (Zimmerman et al., paragraph 91)]
send to the host device, using the first communication channel, at least one of the web application and a representation of the web application.
[sending, via the host device to a remote server, a representation of the received authentication data; (Zimmerman et al., paragraph 8)]
Regarding claims 4,
Zimmerman in view of Ellington discloses the data storage device of claim 3, wherein the at least one processor is further operable to emulate a server, wherein the server is operable to host the web application.
[emulating a Wi-Fi adapter sends 103, via the communication interface 3, a notification 11 of a new Wi-Fi network 13 that is available to the host device 5. The new Wi-Fi network 13 is emulated by the data storage device (Zimmerman et al., paragraph 41)]
Regarding claim 5 and 15,
Zimmerman in view of Ellington discloses the data storage device of claim 1 and the method of claim 12,
wherein the storage medium further comprises an unsecured partition operable to store the web application, and wherein the data storage device is operable send the web application from the unsecured partition to the host device using the second communication channel.
[the authentication data set 65 is be stored local on the data storage device 1, (Zimmerman et al., paragraph 84)]
Regarding claim 6,
Zimmerman in view of Ellington discloses A data storage device of claim 5,
wherein the web application stored in the unsecured partition is at least one of read-only and write protected.
[the host device 5 is in data communication to read and/or write data the storage medium 19 in accordance with access control limitations, if any. (Zimmerman et al., paragraph 43)]
Regarding claims 7 and 16,
Zimmerman in view of Ellington discloses the data storage device of claim 1 and the method of claim 12, wherein the communication interface includes a USB bridge, and wherein the first communication channel and the second communication channel are respective logical pipes through a USB cable between the host device and the data storage device.
[The communication interface 3 is configured to enable communication between the data storage device 1 and a host device 5. The communication interface may include a wire-based data port, which is provided in FIG. 1 by a USB (universal serial bus) bridge, for transmission of data between the host device 5 and the data storage device 1. The data storage device 1 is configured to facilitate examples of the methods 100, 300 illustrated in FIG. 2. (Zimmerman et al., paragraph 39)]
Regarding claims 8
Zimmerman in view of Ellington discloses the data storage device of claim 7, further comprising:
a first endpoint set to send and receive data transferred through the first communication channel;
[the authentication data 61 is then sent 309 from the host device 5, via the communication interface 3, to be received 107 by the at least one processor 7 as illustrated in FIG. 10. (Zimmerman et al., paragraph 82)]
and a second endpoint set to send and receive data transferred through the second communication channel.
[access between the storage medium and the host device is via the communication interface. In some particular examples, the communication interface is a universal serial bus (USB) interface. (Zimmerman et al., paragraph 19)]
Regarding claims 9 and 17,
Zimmerman in view of Ellington discloses the data storage device of claim 1 and the method of claim 12, further comprising:
a cryptography engine, wherein in response to selective access between the host device and the secured partition, the cryptography engine is operable:
encrypt user data to generate encrypted data; send the encrypted data to be stored in the secured partition; and decrypt encrypted data stored in the secured partition to generate the user data,
[storage medium 19 comprises a cryptography engine 22 in the form of a dedicated and/or programmable integrated circuit that encrypts data to be stored on storage medium 19 and decrypts data to be read from storage medium 19. (Zimmerman et al., paragraph 70)]
wherein the communication interface is operable to receive and send the user data between the data storage device and the host device, using the second communication channel.
[access between the storage medium and the host device is via the communication interface. In some particular examples, the communication interface is a universal serial bus (USB) interface. (Zimmerman et al., paragraph 19)]
Regarding claims 10 and 18,
Zimmerman in view of Ellington discloses the data storage device of claim 1 and the method of claim 12,
wherein the web application comprises at least one or more of:
Hypertext Markup Language (HTML);
Cascading Style Sheets; And JavaScript.
[the captive portal 17 can also collect data about the host device 5, network(s) used by the host device 5, and other information on connected network devices. In some examples, this includes JavaScript running inside the HTML (hyptertext markup language) of the captive portal 17 page to collect such data, and then sending this data to the remote server 69 via the host device 5. (Zimmerman et al., paragraph 93)]
Claims 2, 11, 13, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over by Zimmerman et al. (US 20220086928) in view of Ellington et al. (US 20250150438) and in further view of Yoo et al. (US 20250202989).
Regarding claims 2 and 13,
Zimmerman in view of Ellington discloses the data storage device of claim 1 and the method of claim 12, but fails to explicitly disclose wherein the Ethernet over USB protocol driver is a Communication Device Class Network Control Model (CDC-NCM).
However in an analogous art Yoo discloses wherein the Ethernet over USB protocol driver is a Communication Device Class Network Control Model (CDC-NCM).
[the wireless modem device 110 may use a standard protocol according to communications device class (CDC) designated in USB implementers forum (USB-IF) to support USB to serial or USB to Ethernet. CDC may include subclasses such as, but not limited to, abstract control model (ACM), Ethernet networking control model (ECM), Ethernet emulation model (EEM), network control model (NCM), (Yoo et al., paragraph 34)]
Zimmerman, Ellington, and Yoo are considered to be analogous to the claimed invention because they are in the same field of authentication. Therefore, it would have been obvious to one of ordinary skill in the art before the instant application effective filing date of the claimed invention to have modified the teachings of Zimmerman and Ellington to incorporate the teachings of Yoo et al. to include wherein the Ethernet over USB protocol driver is a Communication Device Class Network Control Model (CDC-NCM), in order to support USB to serial or USB to ethernet. (Yoo et al., paragraph 34)]
Regarding claims 11 and 19,
Zimmerman in view of Ellington discloses the data storage device of claim 1 and the method of claim 12, but fails to explicitly disclose wherein the communication interface is operable to transmit and receive data, using the first communication channel, in accordance with at least one of Transmission Control Protocol (TCP) and User Datagram Protocol (UJDP).
However in an analogous art Yoo discloses wherein the communication interface is operable to transmit and receive data, using the first communication channel, in accordance with at least one of Transmission Control Protocol (TCP) and User Datagram Protocol (UJDP). [the electronic device 100 (e.g., the TCP/IP module 610) may transmit an RS message to the router 125 through the wireless modem device 110. (Yoo et al., paragraph 98)]
Zimmerman, Ellington, and Yoo are considered to be analogous to the claimed invention because they are in the same field of authentication. Therefore, it would have been obvious to one of ordinary skill in the art before the instant application effective filing date of the claimed invention to have modified the teachings of Zimmerman and Ellington to incorporate the teachings of Yoo et al. to include wherein the communication interface is operable to transmit and receive data, using the first communication channel, in accordance with at least one of Transmission Control Protocol (TCP) and User Datagram Protocol (UJDP), in order to support USB to serial or USB to ethernet. (Yoo et al., paragraph 34)]
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Nuggehalli et al. (US 20070247660) discloses authentication data being transmitted to a Web application using any mechanism for transferring data from a Web browser to a web application. The web application receives and provides the authentication data to locked print process 120.
Brandt et al. (US 5892905) discloses the user inputing data via the web browser, which is communicated to the web server application. Web server application then authenticates the web browser, and passes appropriate input data to an application gateway, including data to uniquely identify the web browser. The application gateway then uses authentication data received from the browser to determine whether the user of the browser is authorized to access the software application.
Applicant’s amendment necessitated the new ground(s) of rejection presented in this Office action. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL ELAHIAN whose telephone number is (703) 756-1284. The examiner can normally be reached on Monday – Friday from 7:30am to 5pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at telephone number 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/D.E./DANIEL ELAHIAN, Examiner, Art Unit 2407
/Catherine Thiaw/Supervisory Patent Examiner, Art Unit 2407 7/20/2026