DETAILED ACTION
1. This action is responsive to communication filed on 13 March 2026, with acknowledgement of an original application filed on 07 November 2024.
2. Claims 1-20 are currently pending. Claims 1, 11, and 16 are in independent forms. Claims 1-3, 11-13, and 16 has been amended.
Response to Amendment
3. Applicant’s arguments filed 27 April 2026 have been fully considered however they are moot due to new grounds of rejection below initiated by applicant’s amendment.
Claim Rejections - 35 USC § 103
4. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
5. Claims 1-5 and 10-20 are rejected under 35 U.S.C. 103 as being unpatentable over Queralt et al. US Patent Application Publication No. 2018/0097640 (hereinafter Queralt) in view of Lundy et al. US Patent No. 8,896,416 (hereinafter Lundy) in further view of Pancholi et al. US Patent Application Publication No. 2018/0342018 (hereinafter Pancholi).
Regarding claim 1, Queralt discloses a backend device (Fig. 1, FIDO user device 100), comprising:
“a processing system including a processor” (Fig. 2, FIDO authenticator registration process 200); and
a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations (see Queralt par. 0076-0077, a manager sends and invitation 202 to a user. A registration request 204 is then sent to a relying party app 206, which is then transmitted to a FIDO UAF server/registration portal 214 such that, a FIDO x.509 authenticator is downloaded 208 to the user device), the operations comprising:
“enabling, using the validation request data, the end user device to communicate with the user validation system, wherein validation of the individual involves the user validation system triggering an authentication system to provide access information to the end user device for utilization by a mobile device of the individual, (see pars. 0088-0090, the FIDO UAF authentication process 600 is described. The various steps for authentication are depicted including where a User 602 opens 604 a Relying Party Mobile app 606. The Mobile App 606 triggers a UAF authentication request 608, which is sent to FIDO Server 610. A general authorization request 612 is generated and the UAF authentication request is returned 614 to the relying party mobile app 606. The Relying Party Mobile app 606 then sends the UAF authentication request along with the application identification and the TLS bindings 616 to the FIDO Client 618. The FIDO Client 618 seeks to retrieve the Facet identification list identified by the application identification 620, which request is sent to the Relying Party Mobile app 606. The Relying Party Mobile app 606 then returns the Facet identification list 622 to the FIDO Client 618. The FIDO Client 618 then selects an authenticator based on policy 624, which triggers an authentication 626 to the Authenticator Specific Module 628. The Authenticator Specific Module 628 then triggers an authentication including a Key Handle (KH) access token 630 with the Authenticator 632. This triggers a user verification 634, such that when the User 602 identifies themselves, a certificate verification and validation request 636 is sent to PKI Process 638. The PKI Process 638 would then send a user verification 640 back to the Authenticator 632 );
Queralt does not explicitly discloses the authentication system authenticating the individual and the mobile device after the mobile device utilizes the access information, the authentication system providing, to the user validation system, identification information associated with the individual based on the authenticating.
However, in analogues art, Lundy discloses the authentication system authenticating the individual and the mobile device after the mobile device utilizes the access information, the authentication system providing, to the user validation system, identification information associated with the individual based on the authenticating (see Lundy col. 8, lines 3- 65, a flow diagram illustrates overall method 200 for identifying a user by authenticating a mobile device associated with that user, in accordance with an embodiment. Initially, as indicated at block 210, a request to access a secured portion of a website is received from a user. In one embodiment, access information (e.g., login name, password, security message), which is included in the request for access, is submitted by the user at computing device 160 and/or mobile device 110. Incident to receiving the request, the user profile may be searched for security credentials that correspond to the requesting user. The security credentials may then be compared against the access information received in the request according a procedure for validating the set of security credentials. the communications network authorizes the mobile device by using a network-authentication procedure. An illustrative network-authentication procedure extracts the device identifier embedded within, or appended to, a communication from the user's mobile device).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Lundy into the system of Queralt to include a mobile device in proximity to the user while attempting to acquire access at the user interface, the server may authenticate the mobile device and utilize the authentication as user validation (see Lundy col. 3, lines 28-31).
Queralt in view of Lundy does not explicitly discloses obtaining validation request data from a user validation system in response to a validation request from an end user device for an individual, wherein the validation request comprises a validation criterion directed to personally identifiable information (PII) associated with the individual comprising an image of the user and at least one datum of information that comprises textual data, numerical data, or a combination thereof; obtaining the validation result from the user validation system and causing the validation result to be presented to or by the end user device, wherein the validation result comprises an indicator whether the validation criterion is satisfied; wherein a presentation of the validation result excludes the datum of the PII; wherein the validation of the individual involves use of the at least one datum of the P11.
However, in analogues art, Pancholi discloses obtaining validation request data from a user validation system in response to a validation request from an end user device for an individual, wherein the validation request comprises a validation criterion directed to personally identifiable information (PII) associated with the individual comprising an image of the user and at least one datum of information that comprises textual data, numerical data, or a combination thereof (see Pancholi pars. 0010-0011, receive image data from a user, identify personally identifiable information based, at least in part, on the received image data, cause first analysis of the personally identifiable information, and present one or more user interfaces based, at least in part, on the first analysis. In some embodiments, the one or more processors are further configured to: receive additional data from the user via the one or more user interfaces, concurrently with presenting the one or more user interfaces, cause second analysis of at least a portion of the additional data and/or the personally identifiable information, and determine a result for insurance application based, at least in part, on the second analysis. the one or more processors are further configured to validate the identified personally identifiable information. In some embodiments, the one or more processors are further configured to verify the user's identity based, at least in part, on the personally identifiable information); obtaining the validation result from the user validation system and causing the validation result to be presented to or by the end user device, wherein the validation result comprises an indicator whether the validation criterion is satisfied (see Pancholi par. 0004, the method includes presenting a first set of user interfaces for an application for insurance, receiving image data from a user in response to the user's interaction with the first set of user interfaces, identifying personally identifiable information based, at least in part, on the received image data, and transmitting the personally identifiable information to the at least one remote computing device, wherein the personally identifiable information is analyzed based, at least in part, on communication between the remote computing device and one or more third-party computing resources); and wherein a presentation of the validation result excludes the datum of the PII (see Pancholi par. 0005, the first set of user interfaces are predefined independent of the personally identifiable information of the user. In some embodiments, the image data includes at least one of an image of an identification card, an image of a payment card, or an image of the user's face.); wherein the validation of the individual involves use of the at least one datum of the P11 (see Pancholi par. 0014, a user can use a smart phone to complete an insurance application without manually inputting a significant amount of data. The smart phone can capture image data and can automatically complete one or more steps based on the image data. In further embodiments, a system comprises a server computer, mobile phone, or other computing device programmed to receive image data associated with a user, identify personally identifiable information based on the received image data, analyze the personally identifiable information, and/or underwrite insurance based on the personally identifiable information).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Pancholi into the system of Queralt and Lundy to receive image data from a user in response to the user's interaction with the first set of user interfaces, identifying personally identifiable information based, at least in part, on the received image data (see Pancholi par. 0004).
Regarding claim 2, Queralt in view of Lundy in further view of Pancholi discloses the backend device of claim 1,
Pancholi further discloses wherein the indicator whether the validation criterion is satisfied has a first mode of presentation if the validation criterion is satisfied and a second mode of presentation if the validation criterion is not satisfies (see Pancholi par. 0011, the system corresponds to a mobile phone or a server computer. In some embodiments, the one or more processors are further configured to validate the identified personally identifiable information. In some embodiments, the one or more processors are further configured to verify the user's identity based, at least in part, on the personally identifiable information. In some embodiments, the one or more processors are further configured to evaluate fraud risks based on the personally identifiable information. In some embodiments, the one or more processors are further configured to automatically underwrite an insurance policy for the user based, at least in part, on data associated with the user).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Pancholi into the system of Queralt and Lundy to receive image data from a user in response to the user's interaction with the first set of user interfaces, identifying personally identifiable information based, at least in part, on the received image data (see Pancholi par. 0004).
Regarding claim 3, Queralt in view of Lundy in further view of Pancholi discloses the backend device of claim 1,
Pancholi further discloses wherein the validation results further comprises an image of the individual (see Pancholi par. 0004, the method includes presenting a first set of user interfaces for an application for insurance, receiving image data from a user in response to the user's interaction with the first set of user interfaces, identifying personally identifiable information based, at least in part, on the received image data,).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Pancholi into the system of Queralt and Lundy to receive image data from a user in response to the user's interaction with the first set of user interfaces, identifying personally identifiable information based, at least in part, on the received image data (see Pancholi par. 0004).
Regarding claim 4, Queralt in view of Lundy in further view of Pancholi discloses the backend device of claim 1,
Queralt further discloses wherein the end user device is equipped with a validation request app or has access to a web page for obtaining the validation request and for presenting the validation result (see Queralt par. 0080, The authentication request is transmitted to the user device 310 via the relying party application 304. The app 301 sends a certificate validation request 312 to an OCSP server 314 and receives back the validation. The validation or signed assertion 316 is then transmitted to the FIDO enabled relying party application 304. The FIDO enabled relying party application 304 then verifies the result 318 with the FIDO server, and once verified, allows the app 301 to access 320 the FIDO enabled relying party application 304).
Regarding claim 5, Queralt in view of Lundy in further view of Pancholi discloses the backend device of claim 1,
Queralt further discloses wherein the validation request data comprises a request code or request ID (see Queralt par. 0082, The mobile app 406 requests the user 402 for a PIN 408 and for the user name and PIN to be submitted 410. The mobile app 406 then verifies the login 412 and triggers a UAF Registration request 414 to a FIDO server 416, which returns the UAF registration request 418 to the relying party mobile app 406).
Regarding claim 10, Queralt in view of Lundy in further view of Pancholi discloses the backend device of claim 1,
Lundy further discloses wherein the user validation system comprises a trusted source or database and stores personal information relating to a plurality of individuals that includes the individual (see Lundy col. 7, lines 31-39, the profiles database 130 stores information associated with a subscriber of the services of the communications network and is searchable for such information. In one embodiment, a subscriber profile is generated where information is associated with, or mapped to, a subscriber that utilizes communications network 170 to authenticate user mobile devices. In this embodiment, the associated information may include, for example, indicia of the subscriber, device identifiers associated with user mobile devices, dial-in numbers (discussed above), or any other data that relates to a subscriber or a customer thereof).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Lundy into the system of Queralt to include a mobile device in proximity to the user while attempting to acquire access at the user interface, the server may authenticate the mobile device and utilize the authentication as user validation (see Lundy col. 3, lines 28-31).
Regarding claim 11, Queralt discloses a non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor of a backend device, facilitate performance of operations, the operations comprising:
“obtaining validation request data from a user validation system in response to a validation request from an end user device for an individual” (see Queralt pars. 0091-0092, the Authenticator 632 then unlocks the user authentication and computes the authentication result 642 and sends signed data 644 to the Authenticator Specific Module 628, which in turn, sends the signed data 646 to the FIDO Client 618. The FIDO Client 618 sends a UAF authentication response including the signed data 648 to the Relying Party Mobile App 606. The Relying Party Mobile App 606 sends the UAF authentication response 650 to the FIDO Server 610, which verifies 652 the UAF authentication response. The verification result is then sent 654 to the Relying Party Mobile App 606, which in turn, provides the login information 656 to the User 602);
“wherein the authenticating the individual comprises the authentication system performing a multi-factor authentication” (see Queralt par. 0010, Mobile devices have brought a rapid convergence of multi-factor authentication, native functionality (i.e. apps), and web browsing. One of the most important recent advances is the phone-as-second-factor);
“enabling, using the validation request data, the end user device to communicate with the user validation system, wherein validation of the individual involves the user validation system triggering an authentication system to provide access information to the end user device for utilization by a mobile device of the individual, (see pars. 0088-0090, the FIDO UAF authentication process 600 is described. The various steps for authentication are depicted including where a User 602 opens 604 a Relying Party Mobile app 606. The Mobile App 606 triggers a UAF authentication request 608, which is sent to FIDO Server 610. A general authorization request 612 is generated and the UAF authentication request is returned 614 to the relying party mobile app 606. The Relying Party Mobile app 606 then sends the UAF authentication request along with the application identification and the TLS bindings 616 to the FIDO Client 618. The FIDO Client 618 seeks to retrieve the Facet identification list identified by the application identification 620, which request is sent to the Relying Party Mobile app 606. The Relying Party Mobile app 606 then returns the Facet identification list 622 to the FIDO Client 618. The FIDO Client 618 then selects an authenticator based on policy 624, which triggers an authentication 626 to the Authenticator Specific Module 628. The Authenticator Specific Module 628 then triggers an authentication including a Key Handle (KH) access token 630 with the Authenticator 632. This triggers a user verification 634, such that when the User 602 identifies themselves, a certificate verification and validation request 636 is sent to PKI Process 638. The PKI Process 638 would then send a user verification 640 back to the Authenticator 632 );
Queralt does not explicitly discloses the authentication system authenticating the individual and the mobile device after the mobile device utilizes the access information, the authentication system providing, to the user validation system, identification information associated with the individual based on the authenticating.
However, in analogues art, Lundy discloses the authentication system authenticating the individual and the mobile device after the mobile device utilizes the access information, the authentication system providing, to the user validation system, identification information associated with the individual based on the authenticating (see Lundy col. 8, lines 3- 65, a flow diagram illustrates overall method 200 for identifying a user by authenticating a mobile device associated with that user, in accordance with an embodiment. Initially, as indicated at block 210, a request to access a secured portion of a website is received from a user. In one embodiment, access information (e.g., login name, password, security message), which is included in the request for access, is submitted by the user at computing device 160 and/or mobile device 110. Incident to receiving the request, the user profile may be searched for security credentials that correspond to the requesting user. The security credentials may then be compared against the access information received in the request according a procedure for validating the set of security credentials. the communications network authorizes the mobile device by using a network-authentication procedure. An illustrative network-authentication procedure extracts the device identifier embedded within, or appended to, a communication from the user's mobile device).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Lundy into the system of Queralt to include a mobile device in proximity to the user while attempting to acquire access at the user interface, the server may authenticate the mobile device and utilize the authentication as user validation (see Lundy col. 3, lines 28-31).
Queralt in view of Lundy does not explicitly discloses obtaining the validation result from the user validation system.
However, in analogues art, Pancholi discloses obtaining the validation result from the user validation system (see Pancholi par. 0010, receive image data from a user, identify personally identifiable information based, at least in part, on the received image data, cause first analysis of the personally identifiable information, and present one or more user interfaces based, at least in part, on the first analysis. In some embodiments, the one or more processors are further configured to: receive additional data from the user via the one or more user interfaces, concurrently with presenting the one or more user interfaces, cause second analysis of at least a portion of the additional data and/or the personally identifiable information, and determine a result for insurance application based, at least in part, on the second analysis).
Regarding claim 12, Queralt in view of Lundy in further view of Pancholi discloses the non-transitory machine-readable medium of claim 11,
Queralt further discloses wherein the multi-factor authentication comprises receiving at least one of: a personal identification number (PIN); a login password; a username; biometric data such as a fingerprint; device data such as a subscriber identify module, serial number, International Mobile Equipment Identity (IMEI), or device location; or a combination thereof (see Queralt par. 0010, the cell phone is the “something you have”. The overt physical factor is activated by Personal Identification Number (PIN) or password (the something you know), or increasingly, an integrated biometric).
Regarding claim 13, Queralt in view of Lundy in further view of Pancholi discloses the non-transitory machine-readable medium of claim 11,
Pancholi further discloses wherein the validation result comprises an image of the individual (see Pancholi par. 0004, the method includes presenting a first set of user interfaces for an application for insurance, receiving image data from a user in response to the user's interaction with the first set of user interfaces, identifying personally identifiable information based, at least in part, on the received image data,).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Pancholi into the system of Queralt and Lundy to receive image data from a user in response to the user's interaction with the first set of user interfaces, identifying personally identifiable information based, at least in part, on the received image data (see Pancholi par. 0004).
Regarding claim 14, Queralt in view of Lundy in further view of Pancholi discloses the non-transitory machine-readable medium of claim 11,
Lundy further discloses wherein the operations further comprise receiving a session ID or authorization code (see Lundy col. 6, line 65- col. 7, line 38, security application 125 initiates a request to validate the set of security credentials, incident to receiving a request for access from a user. In still another step, access of the digitally secured information is granted. In one embodiment, access is granted if communications-network server 140 determines the device identifiers embedded in a mobile-device communication are authentic and the set of security credentials is satisfied by the received access information. Accordingly, the user is granted rights to view and/or manipulate information previously shielded by subscriber server 120. Alternatively, security application 125 may withhold from the user, rights to access at least a portion of the digitally secured information if any one of the set of security credentials is left unsatisfied, subscriber server 120. These steps of the procedure for validating the set of security credentials may be also be performed at any other component operably coupled to communications network 170).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Lundy into the system of Queralt to include a mobile device in proximity to the user while attempting to acquire access at the user interface, the server may authenticate the mobile device and utilize the authentication as user validation (see Lundy col. 3, lines 28-31).
Regarding claims 15 and 19, Queralt in view of Lundy in further view of Pancholi discloses the non-transitory machine-readable medium of claim 11, the method of claim 16,
Queralt further discloses wherein the causing the validation result to be provided to the end user device involves use of a Hypertext Transfer Protocol Secure (HTTPS) POST (see Queralt par. 0017, The recent publication of NIST SP 800-63-3 DIGITAL IDENTITY GUIDELINES outlined notable changes in the identity proofing and authentication of users, such as employees, contractors, private individuals, and commercial entities, working with government IT systems over open networks. See, https://pages.nist.gov/800-63-3/sp800-63-3.html. Two significant changes outlined in the document are (1) the separation of identity assurance from authenticator assurance, and (2) the recognition of technologies like FIDO U2F and UAF within the highest level—Authenticator Assurance Level 3 (AAL3)).
Regarding claim 16, Queralt discloses a method, comprising:
“obtaining. by a backend device, validation request data from a user validation system in response to a validation request from an end user device for an individual” (see Queralt pars. 0091-0092, the Authenticator 632 then unlocks the user authentication and computes the authentication result 642 and sends signed data 644 to the Authenticator Specific Module 628, which in turn, sends the signed data 646 to the FIDO Client 618. The FIDO Client 618 sends a UAF authentication response including the signed data 648 to the Relying Party Mobile App 606. The Relying Party Mobile App 606 sends the UAF authentication response 650 to the FIDO Server 610, which verifies 652 the UAF authentication response. The verification result is then sent 654 to the Relying Party Mobile App 606, which in turn, provides the login information 656 to the User 602);
“obtaining, by the backend device, the validation result from the user validation system and causing the validation result to be presented to or by the end user device,” (see Queralt pars. 0091-0092, the Authenticator 632 then unlocks the user authentication and computes the authentication result 642 and sends signed data 644 to the Authenticator Specific Module 628, which in turn, sends the signed data 646 to the FIDO Client 618. The FIDO Client 618 sends a UAF authentication response including the signed data 648 to the Relying Party Mobile App 606. The Relying Party Mobile App 606 sends the UAF authentication response 650 to the FIDO Server 610, which verifies 652 the UAF authentication response. The verification result is then sent 654 to the Relying Party Mobile App 606, which in turn, provides the login information 656 to the User 602);
“enabling, by the backend device using the validation request data, the end user device to communicate with the user validation system, wherein validation of the individual involves the user validation system triggering an authentication system to provide access information to the end user device for utilization by a mobile device of the individual, (see pars. 0088-0090, the FIDO UAF authentication process 600 is described. The various steps for authentication are depicted including where a User 602 opens 604 a Relying Party Mobile app 606. The Mobile App 606 triggers a UAF authentication request 608, which is sent to FIDO Server 610. A general authorization request 612 is generated and the UAF authentication request is returned 614 to the relying party mobile app 606. The Relying Party Mobile app 606 then sends the UAF authentication request along with the application identification and the TLS bindings 616 to the FIDO Client 618. The FIDO Client 618 seeks to retrieve the Facet identification list identified by the application identification 620, which request is sent to the Relying Party Mobile app 606. The Relying Party Mobile app 606 then returns the Facet identification list 622 to the FIDO Client 618. The FIDO Client 618 then selects an authenticator based on policy 624, which triggers an authentication 626 to the Authenticator Specific Module 628. The Authenticator Specific Module 628 then triggers an authentication including a Key Handle (KH) access token 630 with the Authenticator 632. This triggers a user verification 634, such that when the User 602 identifies themselves, a certificate verification and validation request 636 is sent to PKI Process 638. The PKI Process 638 would then send a user verification 640 back to the Authenticator 632 );
Queralt does not explicitly discloses the authentication system authenticating the individual and the mobile device after the mobile device utilizes the access information, the authentication system providing, to the user validation system, identification information associated with the individual based on the authenticating.
However, in analogues art, Lundy discloses the authentication system authenticating the individual and the mobile device after the mobile device utilizes the access information, the authentication system providing, to the user validation system, identification information associated with the individual based on the authenticating (see Lundy col. 8, lines 3- 65, a flow diagram illustrates overall method 200 for identifying a user by authenticating a mobile device associated with that user, in accordance with an embodiment. Initially, as indicated at block 210, a request to access a secured portion of a website is received from a user. In one embodiment, access information (e.g., login name, password, security message), which is included in the request for access, is submitted by the user at computing device 160 and/or mobile device 110. Incident to receiving the request, the user profile may be searched for security credentials that correspond to the requesting user. The security credentials may then be compared against the access information received in the request according a procedure for validating the set of security credentials. the communications network authorizes the mobile device by using a network-authentication procedure. An illustrative network-authentication procedure extracts the device identifier embedded within, or appended to, a communication from the user's mobile device).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Lundy into the system of Queralt to include a mobile device in proximity to the user while attempting to acquire access at the user interface, the server may authenticate the mobile device and utilize the authentication as user validation (see Lundy col. 3, lines 28-31).
Queralt in view of Lundy does not explicitly discloses wherein the user validation system comprises a database of a public entity; and wherein the backend device is operated by a third-party service provider distinct from the public entity.
However, in analogues art, Pancholi discloses wherein the user validation system comprises a database of a public entity (see Pancholi par. 0026, The server computer 104 can maintain a database 120 that stores records for a number of consumers. In one embodiment of the system, each consumer is identified by a unique identifier, such as their policy number, e-mail address, mobile phone number. The server computer 104 can include one or more modules 108, including a Validation Module, Automated Underwriting Review Module, Underwriting Acceptance Module, and so forth); and wherein the backend device is operated by a third-party service provider distinct from the public entity (see Pancholi pars. 0029-0030, the computer server(s) processes applicant data by communicating with third-party resource(s) (e.g., background check services, risk analysis services, other evaluation or analytical services related to applicant DNA, medical history, prescription records, etc.) while the mobile device keeps interacting with the applicant to receive additional input that may in turn be fed to the server side. This process enables on-the-fly generation and/or updating of reactive and/or reflexive user interfaces (e.g., screen displays) tailored to particular applicants).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Pancholi into the system of Queralt and Lundy to include an application Module can also include a database that manages stored/archived information that is generated during the application process, including Applicant data, as well as artificial intelligence (AI) for controlling the plurality of processes required to complete the application process. (see Pancholi par. 0036).
Regarding claim 17, Queralt in view of Lundy in further view of Pancholi the method of claim 16,
Pancholi further discloses wherein the validation of the individual involves use of personally identifiable information (PII) associated with the individual (see Pancholi par. 0010, receive image data from a user, identify personally identifiable information based, at least in part, on the received image data, cause first analysis of the personally identifiable information, and present one or more user interfaces based, at least in part, on the first analysis).
Regarding claim 18, Queralt in view of Lundy in further view of Pancholi disclose the method of claim 16,
Lundy further discloses wherein progress information associated with the validation of the individual is presented during one or more of the authenticating of the individual and the mobile device, the providing of the identification information, and the determination of the validation result (see Lundy col. 6, lines 45-59, Each of subscriber server 120, profiles database 130, communications-network server 140, network gateway 150, and computing device 160 shown in FIG. 1 may take the form of various types of computing devices. By way of example only, components 120, 130, 140, 150, and 160 may be a personal computing device, handheld device, consumer electronic device, and the like. Additionally, computing device 160 is configured to present a user interface 165 and even to receive input at an input component 166 in one embodiment. User interface 165 may be presented on any presentation component (not shown) that may be capable of presenting information to a user. In an exemplary embodiment, user interface 165 presents a prompt for the user to provide an input (e.g., message, personal identifier, password, etc.) into an input-entry area).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Lundy into the system of Queralt to include a mobile device in proximity to the user while attempting to acquire access at the user interface, the server may authenticate the mobile device and utilize the authentication as user validation (see Lundy col. 3, lines 28-31).
Regarding claim 20, Queralt in view of Lundy in further view of Pancholi disclose the method of claim 16,
Lundy further discloses wherein the end user device is associated with an account registered with the backend device or the user validation system, and wherein the account permits submission of validation requests to the backend device or the user validation system for validation of individuals (see Lundy col. 4, lines 46-58, a secured portion of a website resides on a subscriber server, where the subscriber server determines whether to grant a user access upon receiving a request for access. In another embodiment, the secured portion of the website includes any information related to a user, user accounts with the subscriber, or data that the user desires to be protected. By way of example, the secured portion of a website is a user's bank account information, as more fully discussed below with reference to FIGS. 7 and 8. Digitally secured information refers to any protected information (e.g., user accounts, addresses, or other data). In an exemplary embodiment, the digitally secured information resides on a subscriber server).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Lundy into the system of Queralt to include a mobile device in proximity to the user while attempting to acquire access at the user interface, the server may authenticate the mobile device and utilize the authentication as user validation (see Lundy col. 3, lines 28-31).
6. Claims 6-8 are rejected under 35 U.S.C. 103 as being unpatentable over Queralt et al. US Patent Application Publication No. 2018/0097640 (hereinafter Queralt) in view of Lundy et al. US Patent No. 8,896,416 (hereinafter Lundy) in further view of Pancholi et al. US Patent Application Publication No. 2018/0342018 (hereinafter Pancholi) in further view of Marquardt US Patent Application Publication No. 2017/0118648 (hereinafter Marquardt).
Regarding claim 6, Queralt in view of Lundy discloses the device of claim 1,
Queralt in view of Lundy does not explicitly discloses the backend device of claim 1, wherein the authentication system comprises an authentication management system and a provider-based authentication system, wherein the provider-based authentication system corresponds to a particular network carrier, and wherein the provider-based authentication system is configured to provide mobile or user identity verification via authentication of subscriber accounts or subscriber identity modules (SIMs).
However, in analogues art, Marquardt discloses wherein the authentication system comprises an authentication management system and a provider-based authentication system, wherein the provider-based authentication system corresponds to a particular network carrier, and wherein the provider-based authentication system is configured to provide mobile or user identity verification via authentication of subscriber accounts or subscriber identity modules (SIMs) (see Marquardt par. 0013, Removable SIM technology has set the standard for the development of mobile telephony subscriber identity management techniques over the past 25 years. SIM cards allow mobile network operators to authenticate a subscriber using a secure token that is stored in an integrated circuit (IC) on a small and inexpensive card that can be easily distributed to subscribers. SIM cards also provide subscribers with a means for preserving their identity and other personal information across devices or while upgrading handset technology. SIM cards additionally allow device manufacturers to market a single device to different markets around the world by providing a mechanism for abstracting subscriber and carrier information from the device itself).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Marquardt into the system of Queralt and Lundy to include a subscriber identity module (SIM) card to facilitate communication with a communication network via a subscription for the designated voice or data subscription of the wireless device (see Marquardt par. 0003).
Regarding claim 7, Queralt in view of Lundy in further view of Marquardt discloses the device of claim 6,
Marquardt further discloses wherein the authentication management system is associated with a plurality of provider-based authentication systems corresponding to different network carriers (see Marquardt par. 0021, benefits include transferability of SIM cards between different mobile devices and the ability to use different mobile network accounts with a single device. Accordingly, wireless communication network carriers and mobile device manufacturers have continued to utilize legacy SIM formats).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Marquardt into the system of Queralt, Lundy, and Pancholi to include a subscriber identity module (SIM) card to facilitate communication with a communication network via a subscription for the designated voice or data subscription of the wireless device (see Marquardt par. 0003).
Regarding claim 8, Queralt in view of Lundy in further view of Marquardt discloses the device of claim 6,
Queralt further discloses wherein the device is provided or operated by a third-party entity different from entities that provide or operate the provider-based authentication system and the user validation system (see Queralt pars. 0003-0007, There has been a host of other approaches to user authentication including the use of imaging software to visually identify if the person opening the computer, or the use of biometrics to identify a person (e.g., finger print, eye scan, etc.). When there is a need for strongly vetted credentials, Public Key Infrastructure (PKI) has been effectively used When there is a need for strongly vetted credentials, Public Key Infrastructure (PKI) has been effectively used. Digital “identities” issued by trusted third parties that identify users and machines. They may be securely stored in wallets or in directories.).
7. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Queralt et al. US Patent Application Publication No. 2018/0097640 (hereinafter Queralt) in view of Lundy et al. US Patent No. 8,896,416 (hereinafter Lundy) in further view of Pancholi et al. US Patent Application Publication No. 2018/0342018 (hereinafter Pancholi) in further view of Grigg et al US Patent Application Publication No. 2016/0173478 (hereinafter Grigg).
Regarding claim 9, Queralt in view of Lundy discloses the device of claim 1,
Queralt in view of Lundy does not explicitly discloses wherein the access information comprises a quick response (QR) code, and wherein the mobile device utilizes the access information by scanning the QR code.
However, in analogues art, Grigg discloses wherein the access information comprises a quick response (QR) code, and wherein the mobile device utilizes the access information by scanning the QR code (see Grigg par. 0052, the user may provide a request to access the framework application in response to scanning visual indicia (e.g. barcode, Quick Response (QR) code, hologram, and the like) associated with the framework application).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Grigg into the system of Queralt, Lundy, and Pancholi for a user to provide a request to access the non-framework application in response to scanning visual indicia (e.g. barcode, Quick Response (QR) code, hologram, and the like) associated with the non-framework application. (see Grigg par. 0069).
Conclusion
8. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMUEL AMBAYE whose telephone number is (571)270-7635. The examiner can normally be reached M-F 9:00 AM - 6:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached at (571) 272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SAMUEL AMBAYE/Examiner, Art Unit 2433
/JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433