DETAILED ACTION
This action is in response to Arguments/Amendments filed 6/12/2026. Claims 1, 2, 4,5 and 7-23 are pending with claims 2, 5, 8 and 9 having been amended and claims 3 and 6 cancelled and claims 21-23 newly added.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 4/14/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
Applicant's arguments filed 6/12/2026 have been fully considered.
A) Applicant's arguments with respect to Niinuma not disclose or contemplate “generating a list of items detected in the first image using the Multi-Model Model” have been fully considered but they are not persuasive.
In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., "list of items" comprises "people, objects, buildings, locations, landmarks") are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993).
B) Applicant's arguments with respect to Niinuma not disclose or contemplate “generating a context-specific challenge based on the list of items detected in the first image” have been fully considered but they are not persuasive.
Regarding B) Niinuma teaches “generating a context-specific challenge based on the list of items detected in the first image” in figure 4A and paragraphs 0080-0091 i.e. In step 156, the first authentication unit 18 calculates a final similarity from both the similarity between the color histogram of the searched-for face area and the reference color histogram of the face area as well as the similarity between the color histogram of the searched-for body area and the reference color histogram of the body area. If the similarity between the color histogram of the face area and the corresponding reference color histogram is denoted Sface and the similarity the color histogram of the body area and the corresponding reference color histogram is denoted Sbody, then the final similarity denoted Sfinal is calculated according to equation (1) below. Sfinal=w.times.Sface+(1-w).times.Sbody (1) where w is a weighting factor for the similarity Sface between the color histogram of the face area and the corresponding reference color histogram; the value of w is at least 0 and at most 1. In step 158, the first authentication unit 18 stores the position and size of the face area of the user, which has been extracted from the newly obtained image, as well as the color histograms of the face area and body area in the first storage unit 30 as the color histogram information 28. This completes the color histogram authentication processing. Upon completion of the above color histogram authentication processing, the sequence proceeds to step 98 in the continuous authentication processing in FIG. 4A. In step 98, the determination unit 22 determines whether to continue the color histogram authentication. Specifically, the determination unit 22 determines whether the color histogram similarity obtained in the color histogram authentication processing by the first authentication unit 18 is greater than or equal to a threshold. In this embodiment, the final similarity Sfinal is used as the similarity, for example. If the color histogram similarity is greater than or equal to the threshold, the determination in step 98 becomes affirmative. The sequence then proceeds to step 100, where the determination unit 22 sets the color histogram authentication mode as the operation mode in continuous authentication. The sequence then returns to step 92. As a result, while the final color histogram similarity obtained in the color histogram authentication processing is greater than or equal to the threshold, processing from step 92 to step 100 is repeated. Accordingly, continuous authentication is carried out for subsequent images through color histogram authentication.
This clearly teaches the claim limitation of a context-specific challenge based on the list of items since the different color of the items such as the face and body are compare during the color histogram authentication processing of the continuous authentication process.
C) Applicant's arguments with respect to Niinuma not disclose or contemplate “sending the Context-Specific challenge to the user device with a request for the user to complete the context-specific challenge” have been fully considered but they are not persuasive.
Regarding C) Niinuma teaches “sending the Context-Specific challenge to the user device with a request for the user to complete the context-specific challenge” in figure 4A and paragraphs 0080-0091 i.e. Upon completion of the above color histogram authentication processing, the sequence proceeds to step 98 in the continuous authentication processing in FIG. 4A. In step 98, the determination unit 22 determines whether to continue the color histogram authentication. Specifically, the determination unit 22 determines whether the color histogram similarity obtained in the color histogram authentication processing by the first authentication unit 18 is greater than or equal to a threshold. In this embodiment, the final similarity Sfinal is used as the similarity, for example. If the color histogram similarity is greater than or equal to the threshold, the determination in step 98 becomes affirmative. The sequence then proceeds to step 100, where the determination unit 22 sets the color histogram authentication mode as the operation mode in continuous authentication. The sequence then returns to step 92. As a result, while the final color histogram similarity obtained in the color histogram authentication processing is greater than or equal to the threshold, processing from step 92 to step 100 is repeated. Accordingly, continuous authentication is carried out for subsequent images through color histogram authentication.
This clearly teaches the claim limitation of sending the context-Specific challenge to the user device with a request for the user to complete the context-specific challenge such as the face and body are compare during the color histogram authentication processing of the continuous authentication process.
D) In response to applicant’s argument that there is no teaching, suggestion, or motivation to combine the references, the examiner recognizes that obviousness may be established by combining or modifying the teachings of the prior art to produce the claimed invention where there is some teaching, suggestion, or motivation to do so found either in the references themselves or in the knowledge generally available to one of ordinary skill in the art. See In re Fine, 837 F.2d 1071, 5 USPQ2d 1596 (Fed. Cir. 1988), In re Jones, 958 F.2d 347, 21 USPQ2d 1941 (Fed. Cir. 1992), and KSR International Co. v. Teleflex, Inc., 550 U.S. 398, 82 USPQ2d 1385 (2007). In this case, It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy in view of Niinuma to have uses Niinuma color histogram continuous authentication technology that uses color histograms of an image on which a user is pictured, has the advantage that robust continuous authentication is possible for changes in the orientation of the user in comparison with face authentication and other methods in which key strokes or the like is used (see Niinuma paragraph 0005).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3, 5, 7-10, 12-16 and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Sambamurthy et al (US 2014/0283016) in view of Niinuma et al (US 2013/0147972).
With respect to claim 1 Sambamurthy teaches an automated computer-implemented process executed by an authentication server for real-time authentication of a user, the process comprising:
receiving an authentication request; receiving user data about the user from a user device (See Sambamurthy figure 2 step 204 and paragraph 0044 i.e. This means that after the user logs in 204 and is granted access 206);
comparing the user data with a user profile database to authenticate the user data (See Sambamurthy paragraph 0053 i.e. In one embodiment, the biometric identity of the user is tied with the centrally available authentication system that uses a username and password, or any other additional data, such as physical location information, time and date, etc. The authentication utilizes multiple pieces of information to establish a physical presence of the user, which is integrated with the trusted display and computer);
receiving a first image from the user device (See Sambamurthy paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors);
providing as input to a multi-modal model the first image and instructions for evaluating the first image (see Sambamurthy paragraph 0153 i.e. In one embodiment, continuous authentication of the user is performed based on images taken of the user while interacting with the computer device and paragraph 0155 i.e. From operation 1522, the method flows to operation 1524 where periodic images are receiving from an image capture device coupled to the second computing device. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images);
receiving a second image from the user in response to the context-specific challenge (see Sambamurthy paragraph 0155 i.e. From operation 1522, the method flows to operation 1524 where periodic images are receiving from an image capture device coupled to the second computing device. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images);
verifying the second image with the multi-modal model (see Sambamurthy paragraph 0155 i.e. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images); and
outputting for display to the user device an authentication confirmation (see Sambamurthy paragraph 0045 i.e. i.e. If any of the continuous monitoring operations fails 210, then computer access is terminated 202, and the user must login (e.g., be authenticated again), before access is granted again).
While Sambamurthy teaches continuous monitoring with biometric authentication
Sambamurthy does not disclose generating a list of items detected in the first image using the multi-modal model; generating a context-specific challenge for the user, the context-specific challenge is based on the list of items detected in the first image; and sending the context-specific challenge to the user device with a request for the user to complete the context-specific challenge.
Niinuma teaches generating a list of items detected in the first image using the multi-modal model (see Niinuma figure 5 steps 132, 136, 138 and 140 and paragraphs 0072-0074 i.e. In step 138, the first authentication unit 18 creates a color histogram of the face area of the user and a color histogram of the body area, the face area and body area having been set in step 136. When, for example, the obtaining unit 16 obtains image data that represents the colors of each pixel in an image with a combination of three colors, red, green, and blue (RGB), each color histogram created as described above represents a frequency of each of the three colors, RGB for each three-color combination, as illustrated in FIG. 6A. It is also possible to use a color space other than the RGB color space. In step 140, the first authentication unit 18 stores the color histograms, which have been created in step 138, of the face area and body area in the first storage unit 30 as the reference color histograms. These reference color histograms are part of the color histogram information 28. In step 142, the first authentication unit 18 stores information that represents the position and size of the face area of the user, which has been set in step 136, in the first storage unit 30 as part of the color histogram information 28. Thus, information as illustrated in FIG. 6A is stored in the first storage unit 30 as the color histogram information 28. In step 144, the determination unit 22 sets a color histogram authentication mode as the operation mode in continuous authentication); generating a context-specific challenge for the user, the context-specific challenge is based on the list of items detected in the first image; and sending the context-specific challenge to the user device with a request for the user to complete the context-specific challenge (see Niinuma paragraphs 0080-0091 i.e. If the color histogram similarity is greater than or equal to the threshold, the determination in step 98 becomes affirmative. The sequence then proceeds to step 100, where the determination unit 22 sets the color histogram authentication mode as the operation mode in continuous authentication. The sequence then returns to step 92. As a result, while the final color histogram similarity obtained in the color histogram authentication processing is greater than or equal to the threshold, processing from step 92 to step 100 is repeated. Accordingly, continuous authentication is carried out for subsequent images through color histogram authentication).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy in view of Niinuma to have uses Niinuma color histogram continuous authentication technology that uses color histograms of an image on which a user is pictured, has the advantage that robust continuous authentication is possible for changes in the orientation of the user in comparison with face authentication and other methods in which key strokes or the like is used (see Niinuma paragraph 0005).
With respect to claim 2 Sambamurthy in view of Niinuma teach the process of claim 1, wherein the user data includes a biometric data of the user or location data of the user (See Sambamurthy paragraph 0050 i.e. In one embodiment, continuous monitoring requires biometric input in order to assure that the user is the user that has been granted access. Embodiments presented herein may use a variety of biometric signals, such as face recognition, fingerprint recognition, iris recognition, keyboard input trends, skin pattern recognition (e.g., using a bracelet), etc. In one embodiment, more than one biometric measure may be used to perform continuous authentication and paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors. In one embodiment, additional inputs from other external sensors are utilized, such as pressure sensors, weight sensors, surveillance cameras in close proximity to the secured monitor in front of the user, IP addresses, MAC addresses, physical location data, etc., to improve system accuracy).
With respect to claim 5 Sambamurthy in view of Niinuma teach the process of claim 1, wherein the context-specific challenge for the user is at least one of: generated at random intervals or generated at intervals. And a duration between intervals in based upon a trust score of the user (see Sambamurthy paragraph 0044 i.e. This means that after the user logs in 204 and is granted access 206, a new operation 208 is added to the secure access process. In operation 208, a check is made periodically, or continuously, to verify that the user is still accessing the computer resources and that the user is the user that was granted access).
With respect to claim 7 Sambamurthy in view of Niinuma teach the process of claim 1, wherein verifying the second image includes at least one of: verifying metadata of the second image; or verifying that a geographic location of the second image matches a location of the user (See Sambamurthy paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors. In one embodiment, additional inputs from other external sensors are utilized, such as pressure sensors, weight sensors, surveillance cameras in close proximity to the secured monitor in front of the user, IP addresses, MAC addresses, physical location data, etc., to improve system accuracy).
With respect to claim 8 Sambamurthy teaches a computer system that provides real-time authentication of a user, the computer system including one or more processors, one or more data-storage devices, and machine-readable instructions stored in the one or more data-storage devices that when executed using the one or more processors controls the computer system to perform operations comprising: receiving an authentication request; receiving user data about the user from a user device (See Sambamurthy figure 2 step 204 and paragraph 0044 i.e. This means that after the user logs in 204 and is granted access 206);
comparing the user data with a user profile database to authenticate the user data (See Sambamurthy paragraph 0053 i.e. In one embodiment, the biometric identity of the user is tied with the centrally available authentication system that uses a username and password, or any other additional data, such as physical location information, time and date, etc. The authentication utilizes multiple pieces of information to establish a physical presence of the user, which is integrated with the trusted display and computer);
receiving a first image from the user device (See Sambamurthy paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors);
providing as input to a multi-modal model the first image and instructions for evaluating the first image (see Sambamurthy paragraph 0153 i.e. In one embodiment, continuous authentication of the user is performed based on images taken of the user while interacting with the computer device and paragraph 0155 i.e. From operation 1522, the method flows to operation 1524 where periodic images are receiving from an image capture device coupled to the second computing device. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images);
receiving a second image from the user in response to the context-specific challenge (see Sambamurthy paragraph 0155 i.e. From operation 1522, the method flows to operation 1524 where periodic images are receiving from an image capture device coupled to the second computing device. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images);
verifying the second image with the multi-modal model (see Sambamurthy paragraph 0155 i.e. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images); and
outputting for display to the user device an authentication confirmation (see Sambamurthy paragraph 0045 i.e. i.e. If any of the continuous monitoring operations fails 210, then computer access is terminated 202, and the user must login (e.g., be authenticated again), before access is granted again).
While Sambamurthy teaches continuous monitoring with biometric authentication
Sambamurthy does not disclose generating a list of items detected in the first image using the multi-modal model; generating a context-specific challenge for the user, the context-specific challenge is based on the list of items detected in the first image; and sending the context-specific challenge to the user device with a request for the user to complete the context-specific challenge.
Niinuma teaches generating a list of items detected in the first image using the multi-modal model (see Niinuma figure 5 steps 132, 136, 138 and 140 and paragraphs 0072-0074 i.e. In step 138, the first authentication unit 18 creates a color histogram of the face area of the user and a color histogram of the body area, the face area and body area having been set in step 136. When, for example, the obtaining unit 16 obtains image data that represents the colors of each pixel in an image with a combination of three colors, red, green, and blue (RGB), each color histogram created as described above represents a frequency of each of the three colors, RGB for each three-color combination, as illustrated in FIG. 6A. It is also possible to use a color space other than the RGB color space. In step 140, the first authentication unit 18 stores the color histograms, which have been created in step 138, of the face area and body area in the first storage unit 30 as the reference color histograms. These reference color histograms are part of the color histogram information 28. In step 142, the first authentication unit 18 stores information that represents the position and size of the face area of the user, which has been set in step 136, in the first storage unit 30 as part of the color histogram information 28. Thus, information as illustrated in FIG. 6A is stored in the first storage unit 30 as the color histogram information 28. In step 144, the determination unit 22 sets a color histogram authentication mode as the operation mode in continuous authentication); generating a context-specific challenge for the user, the context-specific challenge is based on the list of items detected in the first image (see); and sending the context-specific challenge to the user device with a request for the user to complete the context-specific challenge (see Niinuma paragraphs 0080-0091 i.e. If the color histogram similarity is greater than or equal to the threshold, the determination in step 98 becomes affirmative. The sequence then proceeds to step 100, where the determination unit 22 sets the color histogram authentication mode as the operation mode in continuous authentication. The sequence then returns to step 92. As a result, while the final color histogram similarity obtained in the color histogram authentication processing is greater than or equal to the threshold, processing from step 92 to step 100 is repeated. Accordingly, continuous authentication is carried out for subsequent images through color histogram authentication).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy in view of Niinuma to have uses Niinuma color histogram continuous authentication technology that uses color histograms of an image on which a user is pictured, has the advantage that robust continuous authentication is possible for changes in the orientation of the user in comparison with face authentication and other methods in which key strokes or the like is used (see Niinuma paragraph 0005).
With respect to claim 9 Sambamurthy in view of Niinuma teach the computer system of claim 8, wherein the user data includes at least one of a biometric data of the user or location data of the user (See Sambamurthy paragraph 0050 i.e. In one embodiment, continuous monitoring requires biometric input in order to assure that the user is the user that has been granted access. Embodiments presented herein may use a variety of biometric signals, such as face recognition, fingerprint recognition, iris recognition, keyboard input trends, skin pattern recognition (e.g., using a bracelet), etc. In one embodiment, more than one biometric measure may be used to perform continuous authentication and paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors. In one embodiment, additional inputs from other external sensors are utilized, such as pressure sensors, weight sensors, surveillance cameras in close proximity to the secured monitor in front of the user, IP addresses, MAC addresses, physical location data, etc., to improve system accuracy).
With respect to claim 12 Sambamurthy in view of Niinuma teach the computer system of claim 8, wherein the context-specific challenge for the user is generated at random intervals (see Sambamurthy paragraph 0044 i.e. This means that after the user logs in 204 and is granted access 206, a new operation 208 is added to the secure access process. In operation 208, a check is made periodically, or continuously, to verify that the user is still accessing the computer resources and that the user is the user that was granted access).
With respect to claim 13 Sambamurthy in view of Niinuma teach the computer system of claim 8, wherein verifying the second image includes verifying metadata of the second image (See Sambamurthy paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors. In one embodiment, additional inputs from other external sensors are utilized, such as pressure sensors, weight sensors, surveillance cameras in close proximity to the secured monitor in front of the user, IP addresses, MAC addresses, physical location data, etc., to improve system accuracy).
With respect to claim 14 Sambamurthy in view of Niinuma teach the computer system of claim 13, wherein verifying the second image includes verifying that a geographic location of the second image matches a location of the user (See Sambamurthy paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors. In one embodiment, additional inputs from other external sensors are utilized, such as pressure sensors, weight sensors, surveillance cameras in close proximity to the secured monitor in front of the user, IP addresses, MAC addresses, physical location data, etc., to improve system accuracy).
With respect to claim 15 Sambamurthy teaches a non-transitory computer-readable medium encoded with machine-readable instructions that when executed using one or more processors of a computer system control the one or more processors to execute operations comprising: receiving an authentication request; receiving user data about the user from a user device (See Sambamurthy figure 2 step 204 and paragraph 0044 i.e. This means that after the user logs in 204 and is granted access 206);
comparing the user data with a user profile database to authenticate the user data (See Sambamurthy paragraph 0053 i.e. In one embodiment, the biometric identity of the user is tied with the centrally available authentication system that uses a username and password, or any other additional data, such as physical location information, time and date, etc. The authentication utilizes multiple pieces of information to establish a physical presence of the user, which is integrated with the trusted display and computer);
receiving a first image from the user device (See Sambamurthy paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors);
providing as input to a multi-modal model the first image and instructions for evaluating the first image (see Sambamurthy paragraph 0153 i.e. In one embodiment, continuous authentication of the user is performed based on images taken of the user while interacting with the computer device and paragraph 0155 i.e. From operation 1522, the method flows to operation 1524 where periodic images are receiving from an image capture device coupled to the second computing device. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images);
receiving a second image from the user in response to the context-specific challenge (see Sambamurthy paragraph 0155 i.e. From operation 1522, the method flows to operation 1524 where periodic images are receiving from an image capture device coupled to the second computing device. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images);
verifying the second image with the multi-modal model (see Sambamurthy paragraph 0155 i.e. From operation 1524, the method flows to operation 1526, where periodic authentication operations are performed to validate an identification of the user based on the periodic images); and
outputting for display to the user device an authentication confirmation (see Sambamurthy paragraph 0045 i.e. i.e. If any of the continuous monitoring operations fails 210, then computer access is terminated 202, and the user must login (e.g., be authenticated again), before access is granted again).
While Sambamurthy teaches continuous monitoring with biometric authentication
Sambamurthy does not disclose generating a list of items detected in the first image using the multi-modal model; generating a context-specific challenge for the user, the context-specific challenge is based on the list of items detected in the first image; and sending the context-specific challenge to the user device with a request for the user to complete the context-specific challenge.
Niinuma teaches generating a list of items detected in the first image using the multi-modal model (see Niinuma figure 5 steps 132, 136, 138 and 140 and paragraphs 0072-0074 i.e. In step 138, the first authentication unit 18 creates a color histogram of the face area of the user and a color histogram of the body area, the face area and body area having been set in step 136. When, for example, the obtaining unit 16 obtains image data that represents the colors of each pixel in an image with a combination of three colors, red, green, and blue (RGB), each color histogram created as described above represents a frequency of each of the three colors, RGB for each three-color combination, as illustrated in FIG. 6A. It is also possible to use a color space other than the RGB color space. In step 140, the first authentication unit 18 stores the color histograms, which have been created in step 138, of the face area and body area in the first storage unit 30 as the reference color histograms. These reference color histograms are part of the color histogram information 28. In step 142, the first authentication unit 18 stores information that represents the position and size of the face area of the user, which has been set in step 136, in the first storage unit 30 as part of the color histogram information 28. Thus, information as illustrated in FIG. 6A is stored in the first storage unit 30 as the color histogram information 28. In step 144, the determination unit 22 sets a color histogram authentication mode as the operation mode in continuous authentication); generating a context-specific challenge for the user, the context-specific challenge is based on the list of items detected in the first image (see); and sending the context-specific challenge to the user device with a request for the user to complete the context-specific challenge (see Niinuma paragraphs 0080-0091 i.e. If the color histogram similarity is greater than or equal to the threshold, the determination in step 98 becomes affirmative. The sequence then proceeds to step 100, where the determination unit 22 sets the color histogram authentication mode as the operation mode in continuous authentication. The sequence then returns to step 92. As a result, while the final color histogram similarity obtained in the color histogram authentication processing is greater than or equal to the threshold, processing from step 92 to step 100 is repeated. Accordingly, continuous authentication is carried out for subsequent images through color histogram authentication).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy in view of Niinuma to have uses Niinuma color histogram continuous authentication technology that uses color histograms of an image on which a user is pictured, has the advantage that robust continuous authentication is possible for changes in the orientation of the user in comparison with face authentication and other methods in which key strokes or the like is used (see Niinuma paragraph 0005).
With respect to claim 16 Sambamurthy in view of Niinuma teach the non-transitory computer-readable medium of claim 15, wherein the user data includes at least one of a biometric data of the user or a location data of the user (See Sambamurthy paragraph 0050 i.e. In one embodiment, continuous monitoring requires biometric input in order to assure that the user is the user that has been granted access. Embodiments presented herein may use a variety of biometric signals, such as face recognition, fingerprint recognition, iris recognition, keyboard input trends, skin pattern recognition (e.g., using a bracelet), etc. In one embodiment, more than one biometric measure may be used to perform continuous authentication and paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors. In one embodiment, additional inputs from other external sensors are utilized, such as pressure sensors, weight sensors, surveillance cameras in close proximity to the secured monitor in front of the user, IP addresses, MAC addresses, physical location data, etc., to improve system accuracy).
With respect to claim 18 Sambamurthy in view of Niinuma teach the non-transitory computer-readable medium of claim 15, wherein the context-specific challenge for the user is generated at random intervals (see Sambamurthy paragraph 0044 i.e. This means that after the user logs in 204 and is granted access 206, a new operation 208 is added to the secure access process. In operation 208, a check is made periodically, or continuously, to verify that the user is still accessing the computer resources and that the user is the user that was granted access).
With respect to claim 19 Sambamurthy in view of Niinuma teach the non-transitory computer-readable medium of claim 15, wherein verifying the second image includes verifying metadata of the second image (See Sambamurthy paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors. In one embodiment, additional inputs from other external sensors are utilized, such as pressure sensors, weight sensors, surveillance cameras in close proximity to the secured monitor in front of the user, IP addresses, MAC addresses, physical location data, etc., to improve system accuracy).
With respect to claim 20 Sambamurthy in view of Niinuma teach the non-transitory computer-readable medium of claim 19, wherein verifying the second image includes verifying that a geographic location of the second image matches a location of the user (See Sambamurthy paragraph 0054 i.e. In one embodiment, the user is continuously authenticated throughout the session, based on physical presence and using data signals from multiple sensors integrated with the display such as cameras, microphones, speakers, IR detectors, thermometers, proximity sensors. In one embodiment, additional inputs from other external sensors are utilized, such as pressure sensors, weight sensors, surveillance cameras in close proximity to the secured monitor in front of the user, IP addresses, MAC addresses, physical location data, etc., to improve system accuracy).
Claims 4, 11 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Sambamurthy et al (US 2014/0283016) in view of Niinuma et al (US 2013/0147972) in further view of Douglas et al (US 2025/0141867).
With respect to claim 4 Sambamurthy in view of Niinuma teach the process of claim 1, but do not disclose wherein generating the context-specific challenge for the user includes generating a list of context-specific challenges and randomly selecting the context-specific challenge from the list of context-specific challenges.
Douglas teaches wherein generating the context-specific challenge for the user includes generating a list of context-specific challenges and randomly selecting the context-specific challenge from the list of context-specific challenges (see Douglas paragraph 0063 i.e. At 410, process 400 (e.g., using one or more components described above) enables the system to generate a plurality of risk metrics for the user based on generating risk metrics for the one or more features. For example, the system may determine a corresponding risk determination model for a corresponding feature of the one or more features. The system may generate a corresponding risk metric for the user based on providing the one or more media recordings to the corresponding risk determination model for the corresponding feature. As an illustrative example, the system may input each detected feature (e.g., each object or sound detected in media recordings from the user device) into risk determination models that handle that corresponding feature type. By doing so, the system may output risk metrics corresponding to a presence, absence, or change in the detected features. To illustrate, the system may provide detected background noises as input into a first risk determination model associated with evaluation of background noises and detected background objects as input into a second risk determination model associated with evaluation of background objects. Based on outputs from each risk determination model, the system may determine corresponding risk metrics. By doing so, the system may evaluate various factors associated with recordings provided by the user for risk of impersonation or fraud also see paragraphs 0039 and 0041).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy and Niinuma in view of Douglas to have input indications of features detected within media recordings received from a user device (e.g., illustrated by data structure 140) into corresponding risk determination models and generate, as output, corresponding risk metrics as a way to authenticate the user (see Douglas paragraph 0039).
With respect to claim 11 Sambamurthy in view of Niinuma teach the computer system of claim 8, but do not disclose wherein generating the context-specific challenge for the user includes generating a list of context-specific challenges and randomly selecting the context-specific challenge from the list of context-specific challenges.
Douglas teaches wherein generating the context-specific challenge for the user includes generating a list of context-specific challenges and randomly selecting the context-specific challenge from the list of context-specific challenges (see Douglas paragraph 0063 i.e. At 410, process 400 (e.g., using one or more components described above) enables the system to generate a plurality of risk metrics for the user based on generating risk metrics for the one or more features. For example, the system may determine a corresponding risk determination model for a corresponding feature of the one or more features. The system may generate a corresponding risk metric for the user based on providing the one or more media recordings to the corresponding risk determination model for the corresponding feature. As an illustrative example, the system may input each detected feature (e.g., each object or sound detected in media recordings from the user device) into risk determination models that handle that corresponding feature type. By doing so, the system may output risk metrics corresponding to a presence, absence, or change in the detected features. To illustrate, the system may provide detected background noises as input into a first risk determination model associated with evaluation of background noises and detected background objects as input into a second risk determination model associated with evaluation of background objects. Based on outputs from each risk determination model, the system may determine corresponding risk metrics. By doing so, the system may evaluate various factors associated with recordings provided by the user for risk of impersonation or fraud also see paragraphs 0039 and 0041).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy and Niinuma in view of Douglas to have input indications of features detected within media recordings received from a user device (e.g., illustrated by data structure 140) into corresponding risk determination models and generate, as output, corresponding risk metrics as a way to authenticate the user (see Douglas paragraph 0039).
With respect to claim 17 Sambamurthy in view of Niinuma teach the non-transitory computer-readable medium of claim 15, but do not disclose wherein generating the context-specific challenge for the user includes generating a list of context-specific challenges and randomly selecting the context-specific challenge from the list of context-specific challenges.
Douglas teaches wherein generating the context-specific challenge for the user includes generating a list of context-specific challenges and randomly selecting the context-specific challenge from the list of context-specific challenges (see Douglas paragraph 0063 i.e. At 410, process 400 (e.g., using one or more components described above) enables the system to generate a plurality of risk metrics for the user based on generating risk metrics for the one or more features. For example, the system may determine a corresponding risk determination model for a corresponding feature of the one or more features. The system may generate a corresponding risk metric for the user based on providing the one or more media recordings to the corresponding risk determination model for the corresponding feature. As an illustrative example, the system may input each detected feature (e.g., each object or sound detected in media recordings from the user device) into risk determination models that handle that corresponding feature type. By doing so, the system may output risk metrics corresponding to a presence, absence, or change in the detected features. To illustrate, the system may provide detected background noises as input into a first risk determination model associated with evaluation of background noises and detected background objects as input into a second risk determination model associated with evaluation of background objects. Based on outputs from each risk determination model, the system may determine corresponding risk metrics. By doing so, the system may evaluate various factors associated with recordings provided by the user for risk of impersonation or fraud also see paragraphs 0039 and 0041).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy and Niinuma in view of Douglas to have input indications of features detected within media recordings received from a user device (e.g., illustrated by data structure 140) into corresponding risk determination models and generate, as output, corresponding risk metrics as a way to authenticate the user (see Douglas paragraph 0039).
Claims 21-23 are rejected under 35 U.S.C. 103 as being unpatentable over Sambamurthy et al (US 2014/0283016) in view of Niinuma et al (US 2013/0147972) in view of Steelberg et al (US 2022/0269761).
With respect to claim 21 Sambamurthy in view of Niinuma teaches the process of claim 1, but do not disclose wherein the list of items detected in the first image comprises at least one of: people, objects, buildings, locations, or landmarks semantically identified by the multi-modal model.
Steelberg teaches wherein the list of items detected in the first image comprises at least one of: people, objects, buildings, locations, or landmarks semantically identified by the multi-modal model (see paragraph 0026-0028 i.e. In some embodiments, the user can request the CMFA system to remember the user's current environment (e.g., surrounding, room, background, location). For example, the user can be using a computer in the user's home office that has a certain background. Once the user selects this option, the CMFA system can use an image and/or objection recognition neural networks to classify the background and any objects in the background and save it under a home office profile. The user can create multiple background or location profiles. In this way, the user can select a location profile during a future authentication process and the CMFA system can recall the saved profile and compare it with the current background of the live video stream. If the background does not match within a predetermined threshold, the user will not be authenticated and can be blocked for a set period of time and paragraph 0033-0034 i.e. the CMFA system can request the user to perform an action via instructions delivered aurally or visually. The instructions can request the user to repeat a sentence being aurally or visually presented. The instructions can also request the user to perform an action such as, but not limited to, holding up an object, making a certain facial expression, doing something with part of the user's body (e.g., wink, smile, look to the left) while the live video stream is active. The CMFA system can also send instructions to the user email address and/or phone number of record. At subprocess 120, the CMFA system can analyze, using an image or object classification neural network, the video data portion of the live multi-media stream (or video only data stream) to determine whether the user has performed the requested action such as to smile, look to the left, pick up an object, etc. and paragraph 0036).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy in view of Steelberg to have used an image and/or objection recognition neural networks to classify the background and any objects in the background and save it in which a Cognitive Multi-Factor Authentication can request the user to perform an action via instructions delivered aurally or visually in which the instructions request the user to perform an action such as, but not limited to, holding up an object, making a certain facial expression, doing something with part of the user's body (e.g., wink, smile, look to the left) as a way to continuous real-time authentication (see paragraph 0003-0004).
With respect to claim 22 Sambamurthy in view of Niinuma teaches the process of claim 1, but does not disclose wherein the context-specific challenge is presented to the user as text on the user device requesting the user to complete the context-specific challenge, and wherein a user response to the context-specific challenge is required within a predetermined duration.
Steelberg teaches wherein the context-specific challenge is presented to the user as text on the user device requesting the user to complete the context-specific challenge, and wherein a user response to the context-specific challenge is required within a predetermined duration (see paragraph 0026 i.e. For example, the CMFA system can request the user to hold up a computer mouse with her left hand. Using both the facial recognition and object recognition neural networks, the CMFA system can continuously or intermittently verify the user facial identity and whether the user picked up the computer mouse with her left hand. This process not only confirms that the user identification is properly authenticated but that the authentication process is performed in real time).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy in view of Steelberg to have used an image and/or objection recognition neural networks to classify the background and any objects in the background and save it in which a Cognitive Multi-Factor Authentication can request the user to perform an action via instructions delivered aurally or visually in which the instructions request the user to perform an action such as, but not limited to, holding up an object, making a certain facial expression, doing something with part of the user's body (e.g., wink, smile, look to the left) as a way to continuous real-time authentication (see paragraph 0003-0004).
With respect to claim 23 Sambamurthy in view of Niinuma teaches the process of claim 1, but does not disclose wherein the context-specific challenge requests the user to capture a new image at least one of depicting, incorporating, or relating to at least one item from the list of items detected in the first image.
Steelberg teaches wherein the context-specific challenge requests the user to capture a new image at least one of depicting, incorporating, or relating to at least one item from the list of items detected in the first image (see paragraph 0026-0028 i.e. In some embodiments, the user can request the CMFA system to remember the user's current environment (e.g., surrounding, room, background, location). For example, the user can be using a computer in the user's home office that has a certain background. Once the user selects this option, the CMFA system can use an image and/or objection recognition neural networks to classify the background and any objects in the background and save it under a home office profile. The user can create multiple background or location profiles. In this way, the user can select a location profile during a future authentication process and the CMFA system can recall the saved profile and compare it with the current background of the live video stream. If the background does not match within a predetermined threshold, the user will not be authenticated and can be blocked for a set period of time and paragraph 0033-0034 i.e. the CMFA system can request the user to perform an action via instructions delivered aurally or visually. The instructions can request the user to repeat a sentence being aurally or visually presented. The instructions can also request the user to perform an action such as, but not limited to, holding up an object, making a certain facial expression, doing something with part of the user's body (e.g., wink, smile, look to the left) while the live video stream is active. The CMFA system can also send instructions to the user email address and/or phone number of record. At subprocess 120, the CMFA system can analyze, using an image or object classification neural network, the video data portion of the live multi-media stream (or video only data stream) to determine whether the user has performed the requested action such as to smile, look to the left, pick up an object, etc. and paragraph 0036).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Sambamurthy in view of Steelberg to have used an image and/or objection recognition neural networks to classify the background and any objects in the background and save it in which a Cognitive Multi-Factor Authentication can request the user to perform an action via instructions delivered aurally or visually in which the instructions request the user to perform an action such as, but not limited to, holding up an object, making a certain facial expression, doing something with part of the user's body (e.g., wink, smile, look to the left) as a way to continuous real-time authentication (see paragraph 0003-0004).
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DEVIN E ALMEIDA whose telephone number is (571)270-1018. The examiner can normally be reached on Monday-Thursday from 7:30 A.M. to 5:00 P.M. The examiner can also be reached on alternate Fridays from 7:30 A.M. to 4:00 P.M.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Rupal Dharia, can be reached on 571-272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/DEVIN E ALMEIDA/Examiner, Art Unit 2492