DETAILED ACTION
This action is in response to the amendment filed on June 16, 2026. Claims 1 and 10 have been amended. Claim 19 was previously canceled and has been reintroduced. Claims 20-21 remain canceled. Claims 1-19 are pending. Of such, Claims 1-9 represent a method and claims 10-19 represent a system directed to privacy-preserving biometric authentication.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Objections
Claim 19 was canceled in the reply filed on April 7, 2025. The claim listing of record reintroduces the subject matter of former claim 19 under the same claim number 19 without the “(New)” status identifier.
The does not comply with 37 CFR .126. 1. The numbering of claims is not in accordance with 37 CFR 1.126 which requires the original numbering of the claims to be preserved throughout the prosecution. When claims are canceled, the remaining claims must not be renumbered. When new claims are presented, they must be numbered consecutively beginning with the number next following the highest numbered claims previously presented (whether entered or not).
The Applicant’s statement that “no new claims have been added” on page 8 of the Remarks is inconsistent with the claim listing. Applicant is required to correct the claim listing by renumbering Claim 19 with the next available “New” claim number (i.e. Claim 22).
Further Independent Claims 1 and 10 are marked as “Original”, however they have been amended since previously presented to remove the limitation “distinct from the first transducer”, yet was not addressed in the amended claims. Appropriate correction is required.
Response to Arguments
Applicant's arguments filed June 16, 2026 have been fully considered but they are not persuasive.
In sections I.B, II, and III of the Remarks, the Applicant argues that Teranishi requires the same user device, the same computing and storage facility, for both enrollment and authentication, and so it falls outside of claim 1.
This argument is not persuasive.
Claim 1 recites only one distinctness limitation a first and second transducer. It does not require the authentication computing facility to be distinct from the enrollment computing facility, and it does not exclude storing a shard on a device. Applicant’s argument that Teranishi reuses one user device, and stores the shares v[0] and s[0] on it, therefore does not address that limitation. Whether the two computing facilities are the same device, and where the individual shard is stored is not recited as a limitation in claim 1. Even if claim 1 were to read to require distinct computing facilities, Teranishi still meets these requirements. As Teranishi describes in Col. 31, lines 2-15, a “dedicated machine for recording verification information…in advance”. The dedicated machine records the information, not mere image capture. It is therefore a separate computing device that performs enrollment-side processing, distinct from the user device that later performs authentication.
In section I.A of the Remarks, the Applicant argues that every embodiment of Teranishi requires apparatus (device) authentication together with user authentication, and never one without the other.
This argument is not persuasive.
Apparatus authentication is a separate process. It operates on shares of the user device’s secret key, while the rejection reads claim 1 on the user-authentication process, which operates on shares of verification information, generating and distributing shards, performing multi-party computation among a subset of servers, and producing an output value. The argument that Teranishi additionally performs apparatus authentication is not essential to what the claim recites.
In section I.B of the Remarks, the Applicant argues that Teranishi teaches away from authenticating on a different device, pointing to its warning that the user device may be hijacked.
This argument is not persuasive.
Claim 1 was rejected under 35 USC 102, whether the reference teaches toward or away from a configuration is an obviousness consideration and does not bear on anticipation. Teranishi discloses a different device. The Applicant’s direction to Col 19 of Teranishi disclosing the concept of hijacking is a concern for an attacker’s fraudulent device, not a legitimate enrollment performed on a dedicated machine, so it would not establish teaching away in any event.
In Section I.C and III or the Remarks, the Applicant argues that the single “dedicated machine” sentence in Teranishi (Col. 31) neither discloses the claimed distinct transducer nor erases Teranishi’s requirement that the same user device be used for both enrollment and authentication.
This argument is not persuasive.
Teranishi discloses that “a dedicated machine for recording the verification information may be prepared and used to perform recording in advance.” That dedicated machine is a separate device with its own acquisition part, the sensor that captures the biometric, distinct from the user device’s acquisition part used at authentication. That is the distinct first and second transducer the claim requires. Further, the applicant references Fig. 4, acquisition parts share reference numeral 41111 and that no figure depicts a second user device. A reference anticipates a claim if even one configuration it describes has all of the claimed elements, it does not matter that the same reference also describes other configurations that do not.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-3, 8, 10-12 and 17 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Teranishi et al. (US 11063941), hereinafter referred to as Teranishi.
Regarding Claim 1, Teranishi discloses:
A method for using biometric data to authenticate a subject as an individual (In the abstract, Teranishi discloses “An authentication system is provided with: a user device; user side assistance device(s) to assist user authentication that authenticates a user of the user device”) whose biometric data have been previously obtained using an enrollment computing facility that is coupled to a first transducer (In Col 31, Line 2, Teranishi further discloses “In the present exemplary embodiment, in user authentication advance preparation the user 44 records verification information in advance. Various methods may be used as a method of recording the verification information in advance. FIG. 4 shows a case where the verification information is recorded in advance by using the acquisition part 4111 of the user device 41. However, in a case where, for example, a company records all new recruits together in an authentication system, a dedicated machine for recording the verification information may be prepared and used to perform recording in advance in the verification part.”), the method utilizing computer processes comprising: under a condition wherein enrollment shards have been generated from the individual's biometric data received from the first transducer (In Col 31, Line 27, Teranishi discloses “Step 513: a verification information distribution part 41222 inputs verification information and the number M of user side assistance devices 43, and outputs distributed shares v[0], v[1], . . . , v[M] of the verification information.”) and distributed to a first plurality of servers in an array of servers (In Col 31, Line 34, Teranishi discloses “Step 515: the assistance communication part 4141 of the communication part 414 transmits the distributed share v[1] to the user side assistance device 43[1], and . . . , distributed share v[M] to the user side assistance device 43[M].”): causing generation of authentication shards from a digital electronic signal characterizing a biometric of the subject (In Col 32, Line 27, Teranishi discloses “Step 713: the authentication information distribution part 41212 inputs authentication information and the number M of user side assistance devices 43, and outputs distributed shares s[0], s1], . . . , s[M] of the authentication information.”), such signal obtained using an authentication computing facility that is coupled to a second transducer (In Col 32, Line 22, Teranishi discloses “Step 711: the acquisition part 4111 obtains user unique information from the user 44.”) and causing distribution of the authentication shards to a second plurality of servers in the array of servers (In Col 32, Line 31, Teranishi discloses “Step 714: for i=1, . . . , M, the assistance communication part 4141 of the communication part 414 transmits the distributed share s[i] of the authentication information to the user side assistance device 43[i].”); causing performance of a data exchange process, which includes multiparty computation that involves direct communication among a subset of servers in the array and that also involves a subset of enrollment shards and a subset of the authentication shards to develop authentication information relating to authentication of the subject (In Col 32, Line 59, Teranishi discloses “For i=1, . . . , M, the user side assistance device 43[i] inputs distributed share s[i] of the authentication information, distributed share v[i] of the verification information, advance computation data p[i] (if it exists), and verification protocol for user authentication, to the user side assistance device user authentication MPC part 4311[i]. In this way, “user authentication MPC” is executed. As an execution result, the user device 41 obtains the user authentication result share a[0]. For i=1, . . . M, the user side assistance device 43[i] obtains the user authentication result share a[i]. It is to be noted that details of the “user authentication MPC” are described later.” and further discloses in Col 25, Line 30, Teranishi discloses “The i-th user side assistance device performs user authentication by using v[i], f[i], the authentication information derivation algorithm, the verification information derivation algorithm, and the user authentication algorithm to perform MPC while carrying out intercommunication with other user side assistance devices.”); and following development of the authentication information, causing processing of the authentication information to generate an output value indicating whether the subject is authenticated as the individual (In Col 38, Line 14, Teranishi discloses “an authentication result is outputted. The user side assistance device 43[1] transmits GC to the user device 41 using the communication part 433[1].”).
Regarding Claim 2, Teranishi discloses:
A method according to claim 1, wherein the computer processes are performed by computing entities configured as information-sharing restricted with respect to a set of items of information selected from the group consisting of the output value, the digital electronic signal, the individual's biometric data, the subject's biometric, the authentication shards, and combinations thereof (In Col 37, Line 17, Teranishi discloses “In the present exemplary embodiment, by employing a server machine as the user side assistance device, deviation from the MPC protocol by the user side assistance device is prevented. At this time, the user device only creates a legitimacy proof, and it is possible to omit generation of legitimacy proof by the server side assistance device.”).
Regarding Claim 3, Teranishi discloses:
A method according to claim 1, wherein the data exchange process includes the multiparty computation under conditions wherein none of the servers in the array of servers obtains intermediate values of the multiparty computation. (In Col 25, Line 30, Teranishi discloses “The i-th user side assistance device performs user authentication by using v[i], f[i], the authentication information derivation algorithm, the verification information derivation algorithm, and the user authentication algorithm to perform MPC while carrying out intercommunication with other user side assistance devices.”)
Regarding Claim 8, Teranishi discloses:
A method according to claim 1, wherein causing distribution of the authentication shards includes extracting a confident subset of a set of biometric values of the subject in the digital electronic signal. (In Col 29, Line 54, Teranishi discloses “The authentication information derivation part 41211 and the verification information derivation part 41221 extract a characteristic amount of biometric information from the image data, and use the extracted characteristic amount as the authentication information and verification information.”)
Claims 10-12 and 17 are directed to a system having functionality corresponding to the method of Claims 1-3 and 8 respectively, and is rejected by a similar rationale, mutatis mutandis.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 4-7, 13-16 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Teranishi et al. (US 11063941), hereinafter referred to as Teranishi, in view of Al Shahri et al (NPL: A secure network access protocol (SNAP)), hereinafter referred to as Al Shahri.
Regarding Claim 4, Teranishi discloses the limitations of Claim 1.
However, Teranishi does not explicitly teach the limitation of generation of new shares.
Al Shahri discloses:
wherein a selected group of the array of servers causes generation of new shards based on the authentication shards. (In section 4.1, Al Shahri discloses “The share revocation mechanism is important if the NSM is required to update or inform the network nodes about share revocation by providing new shares to be used instead of old shares.”).
One in ordinary skill in the art of cryptography would have been motivated, before the effective filing date of the claimed invention to modify Teranishi’s approach by utilizing Al Shahri’s approach of revocation of shares as the motivation would be not only the use of multi-party computation to reduce the load and increase efficiency across multiple nodes as well as protecting the data (shares) by allowing for revocation if compromised (see Al Shahri section 4).
Regarding Claim 5, Teranishi discloses the limitations of Claim 1.
However, Teranishi does not explicitly teach the limitation of revocation of shares.
Al Shahri discloses:
Wherein, a shard is revocable by a revocation process that includes the data exchange process (In section 4.1, Al Shahri discloses “The share revocation mechanism is important if the NSM is required to update or inform the network nodes about share revocation by providing new shares to be used instead of old shares.”).
One in ordinary skill in the art of cryptography would have been motivated, before the effective filing date of the claimed invention to modify Teranishi’s approach by utilizing Al Shahri’s approach of revocation of shares as the motivation would be not only the use of multi-party computation to reduce the load and increase efficiency across multiple nodes as well as protecting the data (shares) by allowing for revocation if compromised (see Al Shahri section 4).
Regarding Claim 6, the combination of Teranishi and Al Shahri disclose the limitations of Claim 5.
However, Teranishi does not explicitly teach the limitation of revocation of shares.
Al Shahri discloses:
Wherein the revocation process includes performing the data exchange process using a subset of the subset of authentication shards from a subset of the array of servers (In section 4.1, Al Shahri discloses “Thereafter, the AC is divided into n pieces (shares) and distributed to n selected nodes among the network nodes such that a quorum of k nodes is qualified to reconstruct the secret share from their shares.”)
One in ordinary skill in the art of cryptography would have been motivated, before the effective filing date of the claimed invention to modify Teranishi’s approach by utilizing Al Shahri’s approach of revocation of shares as the motivation would be not only the use of multi-party computation to reduce the load and increase efficiency across multiple nodes as well as protecting the data (shares) by allowing for revocation if compromised (see Al Shahri section 4).
Regarding Claim 7, the combination of Teranishi and Al Shahri disclose:
A method according to claim 6, wherein performing the data exchange process includes separately processing, by each server, its enrollment shards of the individual along with its authentication shards of the subject to generate a new set of shards, the new set of shards constituting the output value. (In Col 32, Line 59, Teranishi discloses “For i=1, . . . , M, the user side assistance device 43[i] inputs distributed share s[i] of the authentication information, distributed share v[i] of the verification information, advance computation data p[i] (if it exists), and verification protocol for user authentication, to the user side assistance device user authentication MPC part 4311[i]. In this way, “user authentication MPC” is executed. As an execution result, the user device 41 obtains the user authentication result share a[0].”)
Claims 13-16 are directed to a system having functionality corresponding to the method of Claims 4-7 respectively, and is rejected by a similar rationale, mutatis mutandis.
Regarding Claim 19, Teranishi discloses:
A system for securely enrolling biometric data of an individual for purposes of later authentication of a subject as the individual (In the abstract, Teranishi discloses “An authentication system is provided with: a user device; user side assistance device(s) to assist user authentication that authenticates a user of the user device”), the system having computing components comprising: a first transducer having a digital electronic signal output that characterizes a biometric of the individual (In Col 31, Line 2, Teranishi further discloses “In the present exemplary embodiment, in user authentication advance preparation the user 44 records verification information in advance. Various methods may be used as a method of recording the verification information in advance. FIG. 4 shows a case where the verification information is recorded in advance by using the acquisition part 4111 of the user device 41. However, in a case where, for example, a company records all new recruits together in an authentication system, a dedicated machine for recording the verification information may be prepared and used to perform recording in advance in the verification part.”); a first computing facility, coupled to the first transducer, configured to receive from, the first transducer, the digital electronic signal (In Col 31, Line 2, Teranishi further discloses “In the present exemplary embodiment, in user authentication advance preparation the user 44 records verification information in advance. Various methods may be used as a method of recording the verification information in advance. FIG. 4 shows a case where the verification information is recorded in advance by using the acquisition part 4111 of the user device 41. However, in a case where, for example, a company records all new recruits together in an authentication system, a dedicated machine for recording the verification information may be prepared and used to perform recording in advance in the verification part.”); an array of servers (In Col 19, Lines 4-5, Teranishi discloses “user side assistance devices 43[1]-43[M] (M is a natural number)”); and a second computing facility (In Col 31, Lines 55-60, Teranishi discloses “Step 61: the user device 41 executes the following….a key pair generation part 4125 generates a public key pk and a secret key sk … and outputs distributed shares k[0], . . . , k[M] of the secret key.”); the first computing facility, the array of servers, the second computing facility, and a computer-readable medium encoded with instructions, which upon execution by the foregoing computing components, establish computer processes comprising: causing generating of enrollment shards from the biometric of the individual characterized in the digital electronic signal (In Col 31, Line 34, Teranishi discloses “Step 515: the assistance communication part 4141 of the communication part 414 transmits the distributed share v[1] to the user side assistance device 43[1], and . . . , distributed share v[M] to the user side assistance device 43[M].”); computing multiparty computation (MPC) information for the individual, such MPC information being available for use in the later authentication of the subject (In Col 30, Lines 40-45, Teranishi discloses “In a case where an MPC carried out in user authentication or apparatus authentication requires advance computation, the user device 41 and the apparatus authentication server device 42 respectively store MPC advance computation data in the storage part 413 and the storage part 432.”); distributing, across the array of servers, the generated enrollment shards and the MPC information (In Col 53, Lines 59-65, Teranishi discloses “the user verification information distributed share generation device sends verification information distributed shares v[i] to the user side assistance device 43[i]. Thereafter, the user verification information distributed share generation device deletes user unique information, verification information, and verification information distributed shares v[1], . . . , v[M].”); and causing the array of servers to store the generated enrollment shards and the MPC information (In Col 53, Lines 65-67, Teranishi discloses “For i=1, . . . , M, the user side assistance device 43[i] receives verification information distributed share v[i] to be stored in the distributed share database 4321[i].”);
However, Teranishi does not explicitly teach the limitation of revocation of shares.
Al Shahri discloses:
the generated enrollment shards being stored under conditions wherein the generated enrollment shards are revocable. (In section 4.1, Al Shahri discloses “Thereafter, the AC is divided into n pieces (shares) and distributed to n selected nodes among the network nodes such that a quorum of k nodes is qualified to reconstruct the secret share from their shares.”)
One in ordinary skill in the art of cryptography would have been motivated, before the effective filing date of the claimed invention to modify Teranishi’s approach by utilizing Al Shahri’s approach of revocation of shares as the motivation would be not only the use of multi-party computation to reduce the load and increase efficiency across multiple nodes as well as protecting the data (shares) by allowing for revocation if compromised (see Al Shahri section 4).
Claims 9 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Teranishi et al. (US 11063941), hereinafter referred to as Teranishi, in view of Carmignani et al. (US 2020/0259638), hereinafter referred to as Carmignani.
Regarding Claim 9 Teranishi discloses the limitations of Claim 1:
However, Teranishi does not disclose the storing of future data.
Carmignani discloses:
wherein the computer processes further comprise: receiving and storing by the second plurality of servers in the array of servers a set of values to enable efficient subsequent generation of shards including receiving and storing items selected from the group consisting of Beaver triples, authentication shares, message authentication code shards, random shards, other shards, and combinations thereof. (In ¶ 120, Carmignani discloses “At operation 448, each generated new set of authentication circuit information ACI.sub.Cid_1, . . . , n for each new unique circuit identifier C.sub.id may be sent as a portion data 448d to respective nodes 70.sub.1, . . . , for storing each new set of authentication circuit information ACI.sub.Cid_1, . . . , n with publication keys pk.sub.u and pk.sub.d for enabling additional authentication attempts by the enrolled user and device in the future.”).
One in ordinary skill in the art of cryptography would have been motivated, before the effective filing date of the claimed invention to modify Teranishi’s approach by utilizing Carmignani’s approach of storing future shards as the motivation would be enhance the efficiency of the process by storing data for future authentication (see Carmignani ¶ 120).
Claim 18 is directed to a system having functionality corresponding to the method of Claims 9, and is rejected by a similar rationale, mutatis mutandis.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Sheets et al. (US 11943363) discloses a system for biometric authentication without exposing the authorizing entity to sensitive information.
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHADI H KOBROSLI whose telephone number is (571)272-1952. The examiner can normally be reached M-F 9am-5pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal Dharia can be reached at 571-272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHADI H KOBROSLI/Examiner, Art Unit 2492 /RUPAL DHARIA/Supervisory Patent Examiner, Art Unit 2492