Prosecution Insights
Last updated: October 02, 2026
Application No. 18/958,417

AUTHENTICATION SYSTEM, AUTHENTICATION DEVICE, AND STORAGE MEDIUM STORING AUTHENTICATION PROGRAM

Final Rejection §103
Filed
Nov 25, 2024
Priority
Jun 29, 2022 — JP 2022-104543 +1 more
Examiner
BHANDARI, SHREYAJ RAM
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Denso Corporation
OA Round
2 (Final)
100%
Grant Probability
Favorable
3-4
OA Rounds
7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 100% — above average
100%
Career Allowance Rate
1 granted / 1 resolved
+42.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
18 currently pending
Career history
15
Total Applications
across all art units

Statute-Specific Performance

§101
2.4%
-37.6% vs TC avg
§103
75.0%
+35.0% vs TC avg
§102
2.4%
-37.6% vs TC avg
§112
20.2%
-19.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1, 2, 12, 13, 14, and 15 have been amended. Claim 8 has been canceled. Claims 1-7 and 9-15 are pending. Response to Arguments Applicant’s arguments filed on July 10, 2026, have been considered. With respect to arguments regarding 112(f), the argument is persuasive, and the 112(f) interpretation is withdrawn in view of the claim amendments. With respect to arguments regarding 112(b), the arguments are persuasive, and the 112(b) rejections are withdrawn in view of the claim amendments. With respect to arguments that the cited references do not teach a vehicle function database configured to store the vehicle information collected by the vehicle function block, examiner respectfully disagrees. “Vehicle information” can be any type of information about the vehicle and information regarding users with authorization access to a respective vehicle is considered “vehicle information,” and the feature is taught by paragraph [0046] of Hiruta. With respect to arguments that the cited references don’t teach the authorization process management table, examiner respectfully disagrees. The authorization process management table is a database with information about authorized users, the different forms of confidential information, and the services they have authorization to. This feature is taught by Umezawa in view of Bowers as Umezawa teaches a database of users with authorization, and Bowers teaches the different forms of disclosed information and that users have different access to different services based on their credentials. With respect to the argument that the cited references teach away from the claimed invention, this argument is not persuasive, as all of the references have an element of authentication with authorization conditions involved and teach the features as stated in the claims. With respect to arguments that the cited references are improper, this argument is not persuasive. Hiruta teaches user authentication into a vehicle with authorization conditions involved, and features not taught by Hiruta are taught by the cited secondary references which all teach that elements of vehicle authentication and authorization conditions that are recited in the claims. The motivations to combine each of the references are stated throughout the office action. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-7, 9, 11-15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Hiruta (US 20200307515 A1, hereinafter referred to as Hiruta) in view of Umezawa (US 20100077446 A1, hereinafter referred to as Umezawa) in further view of Bowers (US 20140149747 A1, hereinafter referred to as Bowers) in further view of Howard (US 20210056553 A1, hereinafter referred to as Howard). Regarding claim 1, Hiruta discloses: An authentication system (Hiruta: Paragraph [0046] states, "The user management section 2010 generates a unique user ID 2111 and unique electronic key basic information 2112 for the use applicant. The electronic key basic information 2112 includes authentication information used by the vehicle 1 to authenticate the electronic key 800.") comprising: at least one service application configured to provide a service to a user utilizing a vehicle, by using vehicle information related to the vehicle (Hiruta: Paragraph [0105] states, "When the electronic key basic information 2112 matches and when the attribute indicated by the attribute information 2114 is a specific user, the vehicle start authentication section 316 determines that the user 900 carrying the portable terminal 3 that has transmitted the request to start the vehicle 1 is a user 900 having the authority to start the vehicle 1 and transmits the determination result to the vehicle start authorization section 317 as the authentication result. On the other hand, when the attribute is a non-specific user, if the reservation ID 2121 does not match or the current time does not fall within the use time indicated by the use time information 2122, the vehicle start authentication section 316 makes the same determination as that in the case of a mismatch of the electronic key basic information 2112 and transmits this determination result to the vehicle start authorization section 317 as the authentication result."); a vehicle function block, implemented by at least one of a circuit and a processor with a memory storing computer program code executable by the processor, configured to collect the vehicle information from a plurality of electronic control units mounted on the vehicle (Hiruta: Paragraph [0060] states, "The vehicle-mounted system 100 is provided with a use control ECU (Electronic Control Unit) 300, which is an electronic control unit (ECU), a body control module (BCM) 400, application execution unit 500 and a telemetry control unit (TCU) 600." Paragraph [0063] states, "the BCM 400 is provided with a BCM processing section 410." Paragraph [0066] states, "The BCM processing section 410 is provided with a start operation detection section 411, a FOB communication section 412, a power control section 413 and a door control section 414 as functional elements or functional units." Paragraph [0071] states, "Upon receiving a notification indicating that the FOB key 4 has been detected from the FOB communication section 412, the start operation detection section 411 requests the power control section 413 to start the vehicle 1. On the other hand, upon receiving a notification indicating that the FOB key 4 has not been detected from the FOB communication section 412, the start operation detection section 411 determines whether or not a start authorization, which is a notification indicating an authorization to start the vehicle 1, has been received from the use control ECU 300."); a vehicle function database configured to store the vehicle information collected by the vehicle function block (Hiruta: Paragraph [0046] states, "Upon receiving the approval response from the terminal apparatus owned by the owner 910 (not shown), the user management section 2010 sets an attribute of a specific user or non-specific user to the use applicant based on the relationship information 2113 included in the approval response. The user management section 2010 sets this attribute from the relationship information 2113 according to a predetermined rule. The user management section 2010 generates a unique user ID 2111 and unique electronic key basic information 2112 for the use applicant. The electronic key basic information 2112 includes authentication information used by the vehicle 1 to authenticate the electronic key 800. The user management section 2010 generates user information 2116 associated with the generated user ID 2111, electronic key basic information 2112, attribute information 2114 indicating the set attribute and access terminal information 2115 included in the received issuance request for the electronic key 800. The user management section 2010 stores the generated user information 2116 in the server-side user DB 2110 stored in the server storage section 210." Examiner's note: The users with access to the vehicle is interpreted as the vehicle information, and this information is being stored in a database.); an authentication authorization management unit, implemented by at least one of a circuit and a processor with a memory storing computer program code executable by the processor, configured to determine whether to authorize a [confidential] information acquisition request when the at least one service application [issues the confidential information acquisition request to] acquire [confidential] information among the vehicle information via the vehicle function block (Hiruta: Paragraph [0102] states, "In the start authorization authentication processing, the vehicle start authentication section 316 determines whether or not the start authorization authentication information 3202 matches the start authorization authentication information 3202 stored in the ECU storage section 320." Paragraph [0105] states, "When the electronic key basic information 2112 matches and when the attribute indicated by the attribute information 2114 is a specific user, the vehicle start authentication section 316 determines that the user 900 carrying the portable terminal 3 that has transmitted the request to start the vehicle 1 is a user 900 having the authority to start the vehicle 1 and transmits the determination result to the vehicle start authorization section 317 as the authentication result. On the other hand, when the attribute is a non-specific user, if the reservation ID 2121 does not match or the current time does not fall within the use time indicated by the use time information 2122, the vehicle start authentication section 316 makes the same determination as that in the case of a mismatch of the electronic key basic information 2112 and transmits this determination result to the vehicle start authorization section 317 as the authentication result."), but fails to explicitly disclose: when the at least one service application issues the confidential information acquisition request to acquire confidential information. However, in the same field of endeavor, Umezawa discloses: at least one service application issues the confidential information acquisition request to acquire confidential information (Umezawa: Paragraph [0050] states, "The center apparatus 50 sends an ID password authentication request A502 to the terminal apparatus 30n. The authentication processing unit 305 of the terminal apparatus 30n acquires the user ID and password registered in the user information unit 304 (S303)."). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the teaching of Hiruta and include the above limitation with the teaching of Umezawa in order to ensure that "user authentication methods are switched according to the usage of the terminal apparatus, thereby making it possible to perform more appropriate authentication processing" (Umezawa: Paragraph [0023]). This motivation applies to the remainder of the claim. Hiruta further discloses: a [confidential] information management table defining a user who has authorization rights [for each of a plurality of confidential information] (Hiruta: Paragraph [0049] states, "One piece of the user information 2116 stored in the server-side user DB 2110 includes the user ID 2111, electronic key basic information 2112, relationship information 2113, attribute information 2114 and access terminal information 2115. The server-side user DB 2110 shown in FIG. 3 stores the user information 2116 for each of the owner 910, family user 920 and guest user 930."), but fails to explicitly disclose: confidential information…authorization rights for each of a plurality of confidential information. However, in the same field of endeavor, Bowers discloses: confidential information…authorization rights for each of a plurality of confidential information (Bowers: Paragraph [0069] states, "The token owner could preemptively authorize disclosing selected data records 870 such as: (i) annual income; (ii) credit rating; (iii) driving record; (iv) general geographic location; and (v) the age and model of the token owner's current vehicle."). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the teaching of Hiruta as modified by Umezawa and include the above limitation with the teaching of Bowers in order "to facilitate identity rights management; and/or preemptively authorized data querying techniques to preserve the anonymity of disclosed personal data" (Bowers: abstract). This motivation applies to the remainder of the claim. Bowers fails to explicitly disclose: and an authorization process management table defining an authorization process for authorizing the confidential information acquisition request for each of a plurality of users, [for each of the plurality of confidential information], and for each service application, wherein the authentication authorization management unit determines the authorization process based on the confidential information management table and the authorization process management table, and determines whether to authorize the confidential information acquisition request using the determined authorization process, and when the confidential information acquisition request is authorized, the at least one service application acquires the confidential information via the vehicle function block, [wherein the authorization process includes an automatic approval notification process that authorizes the [confidential information acquisition] request without requesting approval for the [confidential information acquisition] request from a predetermined approver and notifies the approver that the [confidential information acquisition] request has been authorized]. However, Umezawa further discloses: and an authorization process management table defining an authorization process for authorizing the confidential information acquisition request for each of a plurality of users [and for each of the plurality of confidential information, and for each service application], wherein the authentication authorization management unit determines the authorization process based on the confidential information management table and the authorization process management table, and determines whether to authorize the confidential information acquisition request using the determined authorization process (Umezawa: Paragraph [0054] states, "In the user authentication method determining process (S503) of the center apparatus 50 in FIG. 4, by referring to the authentication policy DB 505, a user authentication method which is requested to the terminal apparatus 30n can be determined." Paragraph [0055] states, "FIG. 7 shows an example of the user information registered in the user information DB 507 of the center apparatus 50, where a user ID and an authentication method are associated with each other and registered. The secret information is information to which the authentication processing unit 506 of the center apparatus refers in the user authentication processing (S504 and S506) of the center apparatus 50."), but fails to explicitly disclose: and for each of the plurality of confidential information, and for each service application. However, Bowers further discloses: and for each of the plurality of confidential information (Bowers: Paragraph [0069] states, "The token owner could preemptively authorize disclosing selected data records 870 such as: (i) annual income; (ii) credit rating; (iii) driving record; (iv) general geographic location; and (v) the age and model of the token owner's current vehicle."), and for each service application (Bowers: Paragraph [0068] states, "an owner of confidential information, or token holder, may preemptively grant qualified vendors of a particular product or service the ability to "bid" their product or service to the token owner based upon the token owner's purchaser qualification data being preemptively authorized for disclosure."). Umezawa further discloses: and when the confidential information acquisition request is authorized, the at least one service application acquires the confidential information via the vehicle function block (Umezawa: Paragraph [0050] states, "The center apparatus 50 sends an ID password authentication request A502 to the terminal apparatus 30n. The authentication processing unit 305 of the terminal apparatus 30n acquires the user ID and password registered in the user information unit 304 (S303)."), but fails to explicitly disclose: wherein the authorization process includes an automatic approval notification process that authorizes the confidential information acquisition request without requesting approval for the confidential information acquisition request from a predetermined approver and notifies the approver that the confidential information acquisition request has been authorized. However, in the same field of endeavor, Howard discloses: wherein the authorization process includes an automatic approval notification process that authorizes the [confidential information acquisition] request without requesting approval for the [confidential information acquisition] request from a predetermined approver and notifies the approver that the [confidential information acquisition] request has been authorized (Howard: Paragraph [0069] states, "the application security level may be configured to automatically accept the authorization request without configuring or presenting a notification to the user. In cases where the notification is presented to the user (Step 310), the user resource may be configured to receive the user reply to the notification step 315."). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the teaching of Hiruta as modified by Umezawa and Bowers and include the above limitation with the teaching of Howard in order for "an improved way of automatically identifying an authorized change in a consumer's regular travel, transaction, and/or consumption patterns, and updating service providers to ensure the desired performance of the consumer's services" (Howard: Paragraph [0006]). Howard fails to explicitly disclose: confidential information acquisition. However, Umezawa further discloses: confidential information acquisition (Umezawa: Paragraph [0050] states, "The center apparatus 50 sends an ID password authentication request A502 to the terminal apparatus 30n. The authentication processing unit 305 of the terminal apparatus 30n acquires the user ID and password registered in the user information unit 304 (S303)."). The same motivation to modify with Umezawa, as in claim 1, applies. Regarding claim 2, Hiruta discloses: The authentication system according to claim 1, further comprising: a user authentication unit configured to authenticate the user, wherein the vehicle function block, upon acquiring belonging assignment information that is set in advance as information that needs to be associated with belonging of the [confidential] information among the plurality of [confidential] information, the belonging indicating an owner user to whom the belonging assignment information belongs, associates the acquired belonging assignment information with the belonging information indicating the user to be authenticated by the user authentication unit, and stores the acquired belonging assignment information in association with the belonging information (Hiruta: Paragraph [0046] states, "Upon receiving the approval response from the terminal apparatus owned by the owner 910 (not shown), the user management section 2010 sets an attribute of a specific user or non-specific user to the use applicant based on the relationship information 2113 included in the approval response. The user management section 2010 sets this attribute from the relationship information 2113 according to a predetermined rule. The user management section 2010 generates a unique user ID 2111 and unique electronic key basic information 2112 for the use applicant. The electronic key basic information 2112 includes authentication information used by the vehicle 1 to authenticate the electronic key 800. The user management section 2010 generates user information 2116 associated with the generated user ID 2111, electronic key basic information 2112, attribute information 2114 indicating the set attribute and access terminal information 2115 included in the received issuance request for the electronic key 800. The user management section 2010 stores the generated user information 2116 in the server-side user DB 2110 stored in the server storage section 210."), but fails to explicitly disclose: plurality of confidential information. However, Bowers further discloses: plurality of confidential information (Bowers: Paragraph [0068] states, "A preemptive data/metadata disclosure authorization allows an owner of confidential information to preemptively open selected data on a data storage device for ongoing access to the public or to querying parties who can show a generic qualification for accessing the confidential information." Paragraph [0069] states, "The token owner could preemptively authorize disclosing selected data records 870 such as: (i) annual income; (ii) credit rating; (iii) driving record; (iv) general geographic location; and (v) the age and model of the token owner's current vehicle."). The same motivation to modify with Bowers, as in claim 1, applies. Regarding claim 3, Hiruta discloses: The authentication system according to claim 2, wherein the user authentication unit is configured to authenticate a user using at least one of login authentication, device authentication, and biometric authentication (Hiruta: Paragraph [0046] states, "The electronic key basic information 2112 includes authentication information used by the vehicle 1 to authenticate the electronic key 800."). Regarding claim 4, the combination of Hiruta as modified by Umezawa, Bowers, and Howard discloses: The authentication system according to claim 1. Umezawa further discloses: wherein the authorization process management table further defines the authorization process for each of the at least one service application (Umezawa: Paragraph [0054] states, "In the user authentication method determining process (S503) of the center apparatus 50 in FIG. 4, by referring to the authentication policy DB 505, a user authentication method which is requested to the terminal apparatus 30n can be determined." Paragraph [0055] states, "FIG. 7 shows an example of the user information registered in the user information DB 507 of the center apparatus 50, where a user ID and an authentication method are associated with each other and registered. The secret information is information to which the authentication processing unit 506 of the center apparatus refers in the user authentication processing (S504 and S506) of the center apparatus 50."). The same motivation to modify with Umezawa, as in claim 1, applies. Regarding claim 5, the combination of Hiruta as modified by Umezawa, Bowers, and Howard discloses: The authentication system according to claim 4. Umezawa further discloses: further comprising: an access control unit configured to manage transmission and reception of data between the at least one service application and the vehicle function block, wherein the access control unit is configured to identify the at least one service application that is a transmission source of the confidential information acquisition request when acquiring the confidential information acquisition request from the at least one service application, and the authentication authorization management unit is configured to determine the authorization process based on the at least one service application identified by the access control unit, the confidential information management table, and the authorization process management table (Umezawa: Paragraph [0036] states, "The terminal apparatus 30n includes: a communication unit 301 for transmitting/receiving data to/from the center apparatus 50 via the network 40 or 60; a data transmission/reception unit 302 for transmitting/receiving data to/from the user device 20m via the network 60; a terminal apparatus information unit 303 for storing terminal apparatus information of the terminal apparatus 30n; a user information unit 304 for storing user information of one or more users; an authentication processing unit 305 which performs authentication processing according to an authentication request of the center apparatus 50; and a service enjoying unit 306 for enjoying a service provided by the center apparatus 50. An example of the terminal apparatus information in which the terminal apparatus information unit 303 stores includes a terminal apparatus ID." Paragraph [0055] states, "FIG. 7 shows an example of the user information registered in the user information DB 507 of the center apparatus 50, where a user ID and an authentication method are associated with each other and registered. The secret information is information to which the authentication processing unit 506 of the center apparatus refers in the user authentication processing (S504 and S506) of the center apparatus 50."). The same motivation to modify with Umezawa, as in claim 1, applies. Regarding claim 6, the combination of Hiruta as modified by Umezawa, Bowers, and Howard discloses: The authentication system according to claim 1. Bowers further discloses: wherein the authorization process includes an approval request process that requests approval for the confidential information acquisition request from a predetermined approver, and authorizes the confidential information acquisition request when approval is obtained from the approver (Bowers: Paragraph [0068] states, "A preemptive data/metadata disclosure authorization allows an owner of confidential information to preemptively open selected data on a data storage device for ongoing access to the public or to querying parties who can show a generic qualification for accessing the confidential information." Paragraph [0069] states, "The token owner could preemptively authorize disclosing selected data records 870 such as: (i) annual income; (ii) credit rating; (iii) driving record; (iv) general geographic location; and (v) the age and model of the token owner's current vehicle."). The same motivation to modify with Bowers, as in claim 1, applies. Regarding claim 7, Hiruta discloses: The authentication system according to claim 1, wherein the authorization process includes an automatic approval process that authorizes the confidential information acquisition request without requesting approval for the confidential information acquisition request from a predetermined approver (Hiruta: Paragraph [0105] states, "When the electronic key basic information 2112 matches and when the attribute indicated by the attribute information 2114 is a specific user, the vehicle start authentication section 316 determines that the user 900 carrying the portable terminal 3 that has transmitted the request to start the vehicle 1 is a user 900 having the authority to start the vehicle 1 and transmits the determination result to the vehicle start authorization section 317 as the authentication result."). Regarding claim 9, Hiruta discloses: The authentication system according to claim 1, wherein the authorization process includes an automatic denial process that denies the confidential information acquisition request without requesting approval for the confidential information acquisition request from a predetermined approver (Hiruta: Paragraph [0102] states, "When no match is determined, the vehicle start authentication section 316 assumes that the authentication has failed, determines that the user 900 carrying the portable terminal 3 that has transmitted the request to start the vehicle 1 is not the user 900 having the authority to start the vehicle 1 and transmits this determination result to the vehicle start authorization section 317 as an authentication result."). Regarding claim 11, the combination of Hiruta as modified by Umezawa, Bowers, and Howard discloses: The authentication system according to claim 1. Umezawa further discloses: wherein the authentication authorization management unit determines whether the user has authorization rights based on the confidential information management table, and when the user does not have authorization rights, determines the authorization process based on the authorization process management table (Umezawa: Paragraph [0037] states, "The center apparatus 50 includes:…an authentication method determining unit 504 which determines a user authentication method from the determination result of the terminal apparatus practical-use determining unit 502 and the authentication policy registered in the authentication policy DB; a plurality of authentication processing units 506j (j is an integer equal to or greater than 1 and j may be omitted.) which perform an authentication processing based on the determination of the authentication method determining unit 504." Paragraph [0047] states, "The authentication processing unit 506j of the center apparatus 50 performs user authentication by using the received digest authentication information A201 and the user information (specifically, secret information associated with the user ID) registered in the user information DB 507 (S506)." Paragraph [0048] states, "If it is determined that the user is not a valid user (S510), then the service provision by the service providing unit 508 is not performed, and the authentication processing unit 506j of the center apparatus 50 sends an authentication failure notification (A504), which is then displayed on the terminal apparatus 30n."). The same motivation to modify with Umezawa, as in claim 1, applies. Claim 12 recites features similar to those in claim 1, therefore it is rejected in a similar manner. Claim 13 recites features similar to those in claim 1, therefore it is rejected in a similar manner. Claim 14 recites features similar to those in claim 1, therefore those similar features are rejected in a similar manner. Hiruta further discloses: a first electronic control unit configured to manage vehicle information related to a vehicle (Hiruta: Paragraph [0062] states, "The BCM 400 detects the presence of the FOB key 4 by communicating with the FOB key 4. The BCM 400 also detects operation of a vehicle start switch (Start-Stop Switch) 401 and controls on/off of a power supply system 402 that supplies power to a drive motor (not shown) or the like of the vehicle 1. The BCM 400 controls operation of a door lock mechanism 403 that unlocks/locks the doors of the vehicle 1."); a second electronic control unit having a function of relaying data transmitted from a plurality of the first electronic control units (Hiruta: Paragraph [0144] states, "Generation trigger 1: Power of the vehicle 1 is turned on." Paragraph [0145] states, "Upon receiving an execution notification transmitted from the BCM 400 in step SA10 in FIG. 6, the authentication information generation section 313 determines that a generation trigger 1 has occurred." Paragraph [0084] states, "The ECU processing section 310 is provided with an information collection section 311, a door lock authentication section 312, an authentication information generation section 313…"), wherein the first electronic control unit includes: a first storage configured to store the vehicle information (Hiruta: Paragraph [0075] states, "the FOB communication section 412 compares the first authentication information included in the unlock request with second authentication information (not shown) stored in the BCM storage section 420."); and a first vehicle function block, implemented by at least one of a circuit and a processor with a memory storing computer program code executable by the processor, configured to acquire the vehicle information (Hiruta: Paragraph [0068] states, "The BCM processing section 410 controls each part of the BCM 400 based on data stored in the BCM storage section 420 by executing the program stored in the BCM storage section. The BCM processing section 410 controls the BCM wireless communication section 430 and the BCM bus communication section 440."), the second electronic control unit includes:…a second vehicle function block, implemented by at least one of a circuit and a processor with a memory storing computer program code executable by the processor, configured to acquire the vehicle information from the first electronic control unit (Hiruta: Paragraph [0144] states, "Generation trigger 1: Power of the vehicle 1 is turned on." Paragraph [0145] states, "Upon receiving an execution notification transmitted from the BCM 400 in step SA10 in FIG. 6, the authentication information generation section 313 determines that a generation trigger 1 has occurred." Paragraph [0084] states, "The ECU processing section 310 is provided with an information collection section 311, a door lock authentication section 312, an authentication information generation section 313…"). Claim 15 recites features similar to those in claim 2, therefore it is rejected in a similar manner. Claim(s) 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Hiruta (US 20200307515 A1, hereinafter referred to as Hiruta) in view of Umezawa (US 20100077446 A1, hereinafter referred to as Umezawa) in further view of Bowers (US 20140149747 A1, hereinafter referred to as Bowers) in further view of Howard (US 20210056553 A1, hereinafter referred to as Howard) in further view of Vogt (US 20170192428 A1, hereinafter referred to as Vogt). Regarding claim 10, the combination of Hiruta as modified by Umezawa, Bowers, and Howard discloses: The authentication system according to claim 1, but fails to explicitly disclose: wherein the authorization process includes an automatic denial notification process that denies the confidential information acquisition request without requesting approval for the confidential information acquisition request from a predetermined approver and notifies the approver that the confidential information acquisition request has been denied. However, in the same field of endeavor, Vogt discloses: wherein the authorization process includes an automatic denial notification process that denies the [confidential information acquisition] request without requesting approval for the [confidential information acquisition] request from a predetermined approver and notifies the approver that the [confidential information acquisition] request has been denied (Vogt: Paragraph [0082] states, "an unauthorized user attempting to access a touchscreen may be notified that access is denied (response #1); additionally, the vehicle owner may be notified of a denied access attempt (response #2)."). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify the teaching of Hiruta as modified by Umezawa, Bowers, and Howard and include the above limitation with the teaching of Vogt for "improving vehicle safety" (Vogt: Paragraph [0003]). Vogt fails to explicitly disclose: confidential information acquisition. However, Umezawa further discloses: confidential information acquisition (Paragraph [0050] states, "The center apparatus 50 sends an ID password authentication request A502 to the terminal apparatus 30n."). The same motivation to modify with Umezawa, as in claim 1, applies. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHREYAJ RAM BHANDARI whose telephone number is (571)272-0727. The examiner can normally be reached 7:30-5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHREYAJ RAM BHANDARI/ Examiner, Art Unit 2434 /NOURA ZOUBAIR/ Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Nov 25, 2024
Application Filed
Mar 10, 2026
Non-Final Rejection mailed — §103
May 14, 2026
Examiner Interview Summary
May 14, 2026
Applicant Interview (Telephonic)
Jul 10, 2026
Response Filed
Sep 15, 2026
Final Rejection mailed — §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
100%
Grant Probability
99%
With Interview (+0.0%)
2y 6m (~7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 1 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month