DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office action is in response to the application filed on 07/07/2026.
Claims 1-5 are currently pending in this application.
Election/Restrictions
Applicant’s election without traverse of 1-5 in the reply filed on 07/07/2026 is acknowledged. Claims 6-20 are withdrawn from consideration.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over Grajek et al. US 20180124039 in view of in view of Bhardwaj et al. US 20230281687 hereinafter referred to as Bhardwaj.
As per claim 1, Grajek teaches a system comprising: a processor; and a non-transitory computer-readable medium having stored thereon instructions that are executable by the processor to cause the system to perform operations comprising (Grajek [0030], [0032], [0164-0165]: "hardware processors and memory and I/O devices. The hardware processor(s) may execute program instructions that are stored in memory and/or other data storage such as a hard drive or solid state disk… one or more hardware processors, memory and storage devices that may store programmatic instructions executable by the hardware processors to carry out methods described herein"):
receiving, from a first application on a first user device, a first session request for an online interaction with an online service (Grajek [0005], [0024], [0036], [0046-0047]: "receive, over a network, a request for authentication of a user computing device associated with a user, the request resulting from a redirection operation sent to the user computing device… a user may initially browse to an enterprise's web resource, app resource, or other network resource… the user may point his web browser to an enterprise's web-based portal to access a web-based email system on an enterprise's web server… accomplished via the user being instructed to register their device via a browser based system… via a mobile application, for example, on an iPhone");
authenticating a user account for the first session request using one or more authentication factors (Grajek [FIG. 2], [0024], [0053-0057]: "first-time process… may attempt to access an application from a mobile device. The webserver accessed may redirect the browser to the authentication system for device registration and/or an additional factor of authentication… a first factor of authentication of the user computing device may be from a user ID and/or password… one-time password may be sent from the authentication system to a user cellphone… one-time password may then be sent from the user computing device over the web to the authentication system… This verification may constitute an additional factor of authentication");
establishing, in response to authenticating the first session request, a first active session for the user account on the first user device (Grajek [0062-0064]: after the user provides the request credentials the authentication system verifies them and establishes an authenticated session, see e.g., "Once the fingerprint has been created and the user has been authenticated, the user may then be redirected to the original target resource, for example, web server 103a… an indication of authentication, such as an authentication token… a cookie, or other data structure, stored by the user computing device's browser that indicates that that user was authenticated using an additional factor");
associating the active session with the user account and the first user device using the identified first application and the identified first device type (Grajek [0070-0071], [0117]: token and device fingerprint are associated with the user ID, see e.g., "user ID could be stored in an authentication token stored by the browser or be associated with an authentication token… an authentication token's unique number may be stored in the authentication system as associated with the current user ID… SQL database implemented within the authentication system may store in a table a user ID, and an associate with that user ID, in a table row, a key to or the name of the user device along with any hash and characteristic data… determine what user devices are associated with the user ID, and use those listed devices and associated devices");
receiving, from a second application on a second user device, a second session request for the online interaction with the online service (Grajek [FIG. 1], [FIG. 4], [0028-0029], [0070], [0078-0081], [0100]: "In the future, when the user and his/her user device attempt to access the same enterprise web server (or a different enterprise web/app server), the web server may then again redirect the user's device… fingerprint created on the fly for each device may be compared to past stored fingerprints on a per user basis… on subsequent authentications… map the user ID of a user to the fingerprint of one of his stored devices, and compare that with the current device that is accessing the authentication system 102… the user may attempt to access the network service or the web service on web server 103a from a desktop or a mobile device represented by user computing device 110… Multiple devices may be associated with a single user");
determining a confidence score that the second user device identified from the second session request matches the user account based on the first user device associated with the user account (Grajek [0007], [0093], [0141], [Clm. 25]: "determine a device certainty score based on a comparison of the first plurality of characteristic values of the user computing device to the second plurality of characteristic values… a comparison may be made of the characteristics collected by the user computing device to previous characteristics collected by the user computing device or any computing device that is associated with the user ID sent to the authentication system 102… the user ID has an association with all of its registered device's characteristics that were collected to calculate each registered device's fingerprint hash. The authentication system may compare the current characteristics, on a one-to-one basis, to those of the registered devices and calculated a “device certainty score.” For example, it may compare the user-agent parameter for the registered device, to the user-agent parameter of the current device, and so on… generating a score representing a degree of match between the set of device attribute values of the authenticating user device and the set of device attribute values of a first of the one or more registered user devices");
authenticating the user account for the second session request based on the confidence score satisfying a confidence threshold associated with the online interaction (Grajek [0007], [0093-0094], [0142]: "when a determination is made that the device certainty score is above a threshold update score: update the second plurality of characteristic values in data storage to include the first plurality of characteristic values, and transmit an authentication token to the user computing device, the authentication token indicating that the user computing device was authenticated by a fingerprinting mechanism… If there is a match of characteristics compared on a one-to-one basis for each characteristic, or if it meets a configurable threshold of matches of the characteristics (such as a percentage match) then authentication may be considered successful as well… the fingerprint of the user computing device 110 that is currently associated with the user ID may be updated to reflect the new device fingerprint because there was not a complete 100% match but the match of the characteristics did meet the threshold for updating… if the match score was 90% then if a match between the current device characteristics and a registered device's characteristics meets or exceeds 90%, then no new fingerprint may be computed, no new fingerprint is updated, and the authentication is considered a success");
and establishing, in response to authenticating the second session request, a second active session for the user account on the second user device (Grajek [0081]: "fingerprint is then compared with other fingerprints of other devices that are associated with the user ID in the data store that previously authenticated… authentication system may then return an authentication token that provides single sign-on to the user device for access to the network service which may be a cloud, web, or mobile resource… authentication token may be accepted by other network services in lieu of requiring an additional factor of authentication").
Grajek does not explicitly disclose identifying the first user device from the first session request based at least on the first application and a first device type of the first user device and identifying the second user device from the second session request based at least on the second application and a second device type of the second user device.
Bhardwaj teaches identifying the user device from the session request based at least on the application and a device type of the user device (Bhardwaj [FIG. 2C], [0037], [0061-0062]: request includes device attributes from application and user device data, see e.g., "creating a device fingerprint 250 including a plurality of device attributes 251, 252, 253, 254, and 255… the security service 220 may extract user-device details from a request message 260 submitted by the user device 210… request message 260 may include a HTTP request (POST, GET, PUT, etc.), an API call… request message 260 includes various attributes 261, 262, 263, and 264 which can be extracted and used for device fingerprinting").
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Grajek of a device fingerprint based authentication system with the teachings of Bhardwaj to include identifying the user device from the session request based at least on the application and a device type of a user device in order to improve security tracking and device based authentication accuracy by effectively tracking requests originating from difference devices belonging to a user.
As per claim 5, Grajek in view of Bhardwaj teaches the system of claim 1, wherein the confidence threshold corresponds to a desired security associated with the online interaction using the online service (Grajek [0038], [0047], [0093], [0142], [053]: "if it meets a configurable threshold of matches of the characteristics (such as a percentage match) then authentication may be considered successful… A match score may be a configurable setting that tells the authentication system what is the lowest level of device certainty score… administrators may also set preferences on a per authentication realm basis. These preferences may also establish the distinct requirements for individual applications, such as a web application, or individual requirements for a certain authentication realm").
Claims 2-4 are rejected under 35 U.S.C. 103 as being unpatentable over Grajek in view Bhardwaj, and further in view of Kong et al. US 20220224679 hereinafter referred to as Kong.
As per claim 2, Grajek in view of Bhardwaj teaches the system of claim 1, wherein associating the active session with the user account and the first user device further comprises storing a user account identifier for the user account, and a first user device identifier for the first user device based on the identified first application and the identified first device type (Grajek [0070-0071], [0117]: token and device fingerprint are associated with the user ID, see e.g., "user ID could be stored in an authentication token stored by the browser or be associated with an authentication token… an authentication token's unique number may be stored in the authentication system as associated with the current user ID… SQL database implemented within the authentication system may store in a table a user ID, and an associate with that user ID, in a table row, a key to or the name of the user device along with any hash and characteristic data… determine what user devices are associated with the user ID, and use those listed devices and associated devices").
Grajek in view of Bhardwaj does not explicitly disclose storing a session identifier for the active session.
Kong teaches storing a session identifier for the active session (Kong [0064]: "session record will include the grant token and information that can be used to distinguish that grant token's session from other sessions that are associated with the user agent, such as an identifier for the user account, a user agent identifier, time of creation, time of last access, and/or other data").
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Grajek in view of Bhardwaj of storing user account identifier and a device identifier with the teachings of Kong to include storing a session identifier for the active session in order to enhance session tracking management by distinguishing a specific user session from other concurrent sessions associated with the same user account and device.
As per claim 3, Grajek in view of Bhardwaj teaches the system of claim 1, wherein the instructions further cause the system to perform operations comprising: identifying one or more user devices associated with the user account (Grajek [0114-0117]: authentication system maintains, per user account, list of devices registered to that account, see e.g., "authentication system 102 presents the option for administrators of authentication system 102, enterprise administrators, and/or the users themselves to see which devices have been registered in association with the user… the user or admin can see what devices have been registered and when the last update of the fingerprint has been made… authentication system to easily query either an SQL database or LDAP to determine what user devices are associated with the user ID").
Grajek in view of Bhardwaj does not explicitly disclose detecting the one or more active sessions based on the identified one or more user devices and providing a notification of the one or more active sessions.
Kong teaches detecting the one or more active sessions based on the identified one or more user devices (Kong [0064], [0066]: "Grant tokens can be stored on the server side and enable a user agent to have multiple sessions active at any point in time… any of the endpoints may create and store a session record for each grant token… identifier for the user account, a user agent identifier… session manager may be a web page or other interface that displays all active grant tokens across a set of user agents… may display additional information for each grant token such as device information, login time, or other details to help the user distinguish the grant tokens from each other") and providing a notification of the one or more active sessions (Kong [0066]: "browsing the session manager, the user may be alerted that he or she neglected to log out of a session on a particular device… his or her account is being used on an unrecognized device").
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Grajek in view of Bhardwaj of identifying one or more users associated with the user account with the teachings of Kong to include a session manager interface to view and manage the devices tied to a user account in order to prevent unauthorized access by allowing the user to track and perform actions on active sessions.
As per claim 4, Grajek in view of Bhardwaj and Kong teaches the system of claim 3, wherein the instructions further cause the system to perform operations comprising: receiving, from the user device, a selection of the one or more active sessions (Kong [0066-0067]: "session manager also may generate and output an account manager user interface that identifies accounts that are associated with the user agent, and that enables the user to select the connect to, or log out of, any of various accounts to create a new session or join an active session for each account");
and deactivating the selected one or more active sessions (Kong [0066-0067]: "session manager may enable the user to terminate a session by providing a user interface that will receive a termination command, in response to which the system will delete the grant token corresponding to that session… enables the user to select the connect to, or log out of").
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CAROLINE HOANG-ANH NGUYEN whose telephone number is (571)272-8309. The examiner can normally be reached Monday-Thursday 7am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at (571) 272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/C.H.N./Examiner, Art Unit 2495
/HENRY TSANG/Primary Examiner, Art Unit 2495