DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1-19 and 21 have been considered but are moot based on new grounds of rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-19 and 21 are rejected under 35 U.S.C. 103 as being unpatentable over Maass, patent number: US 11 246 032 in view of Kermes, Publication number: US 2019/0228144 in further view of Gelbard, patent number: US 8 751 808.
As per claim 1, Maass teaches a method of device authentication comprising:
Communicating to an API of one or more servers, credentials corresponding to a unique identifier of a second device included in the first request and a second request for a signed certificate (communication to server API via proxy server, col. 27, line 66 – col. 28, line 23, communicating user specific public key col. 4, lines 29-53, requesting a signed certificate col. 28, line 57- col. 29, line 2);
receiving, by the second device from the one or more servers via the API, a response to the second request including the signed certificate (receiving a generated digital certificate, x509, in response to a CSR, col. 29, lines 2 - 26);
establishing, by the second device, using the signed certificate, a virtual tunnel to communicate with a remote resource (establishing direct communication using received certificate, col. 29, lines 48-67); and
updating, by the second device using the remote resource, one or more provisioned resources of the second device (updating firmware, col. 3, lines 2 – 14, col. 5, lines 51 – col. 6, line 5).
Maass does not teach communicating by a second device to one or more servers prior to an expiration time corresponding to a first request from a first device.
In an analogous art, Kermes teaches communicating by a second device to one or more servers prior to an expiration time corresponding to a first request from a first device (validity time of a ticket, [0043][0045], user device 205 communicating with server 215 using ticket 235-b corresponding to initial login request 220-a, [0028-0029] Fig. 2, initial user verification via a proxy server [0025])
Therefore, it would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to modify Maass’ updating system to include a validity time as described in Kermes’ user authentication system for the advantage of reducing replay attacks.
The combination of Maas and Kermes does not teach communicating, by a second device, to one or more servers, prior to a time corresponding to a first request originating from a first device, credentials corresponding to a unique identifier of the second device included in the first request by the first device.
In an analogous art, Gelbard communicating, by a second device, to one or more servers, prior to a time corresponding to a first request originating from a first device, credentials corresponding to a unique identifier of the second device included in the first request by the first device (sending trusted device information to a server ahead of a connection request, col. 2, lines 66 – col. 3, line 10, col. 3, line 54-60, col. 5, line 64 – col. 6, line 7, Fig. 2).
Therefore, it would have been obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the combination of Maass and Kermes to include trusted device information as described in Gelbard’s connection system for the advantage of ensuring system safety.
As per claim 2, the combination teaches wherein:
the first device establishes a shared secret with the one or more servers prior to the first request;
the shared secret expires at a second expiration time; and
a communications channel for the first request is established using the shared secret (Kermes: validity time, [0045], proxy specific secret, [0026]).
As per claim 3, the combination teaches wherein the provisioned resources comprise a plurality of shared secrets and application installations (Kermes: proxy specific secret [0026], Maass: updating, col. 3, lines 2 – 14, col. 5, lines 51 – col. 6, line 5).
As per claim 4, the combination teaches wherein the communications between the second device and the one or more servers for the API are provided over a public network (Kermes: internet, [0015][0051]).
As per claim 5, the combination teaches wherein communicating the second request comprises communicating, by the second device, the second request to the API automatically responsive to an execution of a startup sequence of the second device, the startup sequence comprising a suboperation to prevent an execution of the startup sequence upon a completion of the startup sequence (Maass: sequence of operations, col. 24, line 55 – col. 25, line 2).
As per claim 6, the combination teaches further comprising:
verifying, by the second device, responsive to a second execution of the startup sequence, a state of a plurality of sequential suboperations of the startup sequence to update the one or more provisioned resources; and
resuming, by the second device, responsive to detecting an uncompleted suboperation of the plurality of sequential suboperations, the sequential suboperations to update the one or more provisioned resources (Maass: not repeating operations, col. 24, line 55 – col. 25, line 2, col, 27, line 66 – col. 28, line 23).
As per claim 7, the combination teaches further comprising:
retrieving, by the second device, a first portion of the credentials from a non-volatile hardware-embedded unique identifier of an application specific hardware device local to the second device; and
retrieving, by the second device via a network interface from the first device, a second portion of the credentials comprising the unique identifier included in the first request (Maass: stored in TPM, col. 4, lines 29-53, Kermes: authorization via proxy, [0027] ).
As per claim 8, the combination teaches wherein the API determines a status of the signed certificate and reverts the updates to the one or more provisioned resources based on the status (Maass: deprovision, col. 5, lines 24 – 41, col. 26, lines 31-57).
As per claim 9, Kermes teaches a server, comprising:
one or more processors configured to:
receive, from a first device, a first request comprising a unique identifier, the first request corresponding to an expiration time (validity time of a ticket, [0043][0045], initial user verification via a proxy server [0025]);
receive from a second device, prior to the expiration time, a credential corresponding to the unique identifier (user device 205 communicating with server 215 using ticket 235-b corresponding to initial login request 220-a, [0028-0029] Fig. 2) and
Kermes does not teach a second request for a signed certificate; and
issue, responsive to receipt of the credential, the signed certificate.
In an analogous art, Maass teaches a second request for a signed certificate (requesting a signed certificate col. 28, line 57- col. 29, line 2); and
issue, responsive to receipt of the credential, the signed certificate (communicating user specific public key col. 4, lines 29-53, receiving a generated digital certificate, x509, in response to a CSR, col. 29, lines 2 - 26).
Therefore, it would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to modify Kermes to include a signed certificate as described in Maass’ provisioning system for the advantage of identity verification.
The combination of Maass and Kermes does not teach a first request originated by a first device and comprising a unique identifier of a second device.
In an analogous art, Gelbard teaches a first request originated by a first device and comprising a unique identifier of a second device (sending trusted device information to a server ahead of a connection request, col. 2, lines 66 – col. 3, line 10, col. 3, line 54-60, col. 5, line 64 – col. 6, line 7, Fig. 2).
Therefore, it would have been obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the combination of Maass and Kermes to include trusted device information as described in Gelbard’s connection system for the advantage of ensuring system safety.
As per claim 10, the combination teaches wherein the one or more processors are further configured to:
establish, over a public network, a virtual tunnel to communicate with the second device; and
update, using the virtual tunnel, one or more provisioned resources of the second device (Maass: updating, updating, col. 3, lines 2 – 14, col. 5, lines 51 – col. 6, line 5, Kermes: internet, [0015] Fig. 2, 220b).
As per claim 11, the combination teaches wherein the one or more processors are further configured to:
close, prior to the expiration time, a window for the second request defined according to the first request, responsive to a receipt of the credential; and
log any subsequent requests to sign a certificate (Kermes: expiration, [0045], storing interactions, [0016][0018]).
As per claim 12, the combination teaches wherein the credential comprises a credential of an application-specific hardware device (Maass: TPM, col. 4, lines 29 - 53).
As per claim 13, the combination teaches wherein the one or more processors are further configured to:
establish a secure connection, using a shared secret between the first device and the server prior to receipt of the first request (Kermes: proxy specific secret, [0026]).
As per claim 14, the combination teaches wherein the one or more processors are further configured to:
receive, from the second device in a deployed configuration, a third request to renew a certificate; and
provide, to the second device, a second signed certificate responsive to the third request (Maass: CSR, col. 4, 54 – col. 5, lines 23).
As per claim 15, the combination teaches wherein the signed certificate is a mutual transport layer security certificate established between the server and the second device (Maass: mTLS, col 5, line 51 – col. 6, line 5).
As per claim 16, the combination teaches wherein the one or more processors are further configured to:
revoke, prior to a predefined expiration time, the signed certificate of the second device (Maass: deprovisioning, col. 5, lines 24 – 41, col. 26, lines 31-57).
As per claim 17, the combination teaches wherein the one or more processors are further configured to:
determine an authorization status of the second device responsive to:
a match between a first and second portion of the credential; and
a revocation status of the credential; and
issue the signed certificate responsive to the authorization status (Maass: CSR, col. 4, 54 – col. 5, lines 23, Kermes: time [0043][0045]).
As per claim 18, the combination teaches wherein the server comprises:
a device commissioning server configured to communicate with the second device;
a certificate issuance server configured to generate the signed certificate; and
a data repository configured to maintain a record of communication between the device commissioning server and the second device (Kermes: tracking, [0016][0018], Maass: deprovisioning col. 5, lines 24 – 41, col. 26, lines 31-57, certificate server col. 22, line 65 – col. 23, line 15).
As per claim 19, Maass teaches a system comprising:
a first server (Provisioning service 1404, Fig. 14, col. 22, line 65 – col. 23, line 15) comprising one or more first processors configured to:
receive a request from a second device (requesting a signed certificate col. 28, line 57- col. 29, line 2);
forward a signed certificate to the second device, the signed certificate received from a second server responsive to a communication of the request to the second server (Digital certificates, x509, from certificate authority 1406 to device 1402, col. 29, lines 3 - 26); and
establish a virtual tunnel to communicate with the second device, (Digital certificates, x509, from certificate authority 1406 to device 1402 based on a request, col. 29, lines 3 – 26, establishing direct communication using received certificate, col. 29, lines 48-67).
Maass does not teach receive, prior to an expiration of a temporal window between for the first server and a first device, a request from a second device.
In an analogous art, Kermes teaches receive, prior to an expiration of a temporal window between for the first server and a first device, a request from a second device(validity time of a ticket, [0043][0045], user device 205 communicating with server 215 using ticket 235-b corresponding to initial login request 220-a, [0028-0029] Fig. 2, initial user verification via a proxy server [0025])
Therefore, it would have been obvious to one of ordinary skill in the art, prior to the effective filing date of the claimed invention to modify Maass’ updating system to include a validity time as described in Kermes’ user authentication system for the advantage of reducing replay attacks.
The combination of Maass and Kermes does not teach a first request originating from a first device and including a unique identifier of a second device prior to a second request from a second device.
In an analogous art, Gelbard teaches a first request originating from a first device and including a unique identifier of a second device prior to a second request from a second device (sending trusted device information to a server ahead of a connection request, col. 2, lines 66 – col. 3, line 10, col. 3, line 54-60, col. 5, line 64 – col. 6, line 7, Fig. 2).
Therefore, it would have been obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify the combination of Maass and Kermes to include trusted device information as described in Gelbard’s connection system for the advantage of ensuring system safety.
As per claim 21, the combination teaches wherein the second server, comprising one or more second processors configured to generate the signed certificate, responsive to receipt of the communication from the first server (Maass: from certificate authority 1406 to device 1402 based on a request, col. 29, lines 3 – 26)
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to OLUGBENGA O IDOWU whose telephone number is (571)270-1450. The examiner can normally be reached Monday-Friday 8am - 5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached at 5712723804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/OLUGBENGA O IDOWU/Primary Examiner, Art Unit 2494