Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This Office Action is in response to the amendment filed 6./9/2026 for application 18/961,567.
Claims 1-4, 6-10, 12-16, and 18-24 have been examined and are pending. Claims 5, 11, and 17 have been canceled. Claims 1, 7, 8, and 13 have been amended. Claims 19-24 have been added. Claims 1, 7, and 13 are independent claims. This Action is made FINAL.
Response to Arguments
The nonstatutory double patenting of claims 1-18 has been withdrawn in light of Applicant’s submission of a terminal disclaimer, which has been approved.
Applicants’ arguments in the instant Amendment, filed on 6/9/2026, with respect to limitations listed below, have been fully considered.
Applicant asserts as follows: Applicants have herein amended independent claims 1, 7 and 13 to include features based on claims 5, 11 and 17, respectively, while further clarifying that the active authentication technique produces a scalar result, and respectfully submit that such features are not disclosed or fairly suggested by the cited art. For example, on page 20 of the Office Action, the Examiner admits that "Shi and Chang do not explicitly disclose wherein all of the at least one active authentication technique does not have a binary outcome comprising success or failure," and relies upon paragraph [0012] of Yokoi to remedy this deficiency. However, Yokoi discloses a system for adjusting threshold values used in biometric authentication to control the false rejection rate (FRR) and false acceptance rate (FAR) - that is, Yokoi is directed to optimizing the threshold parameters of a multistage collation apparatus, not to producing a scalar (non-binary) outcome from an active authentication technique itself. Paragraph [0012] of Yokoi merely describes that a first threshold value is set to lower the FRR when an input password matches a registered password, and a second threshold value is set to lower the FAR when the input password does not match. This is a binary password-match determination - the password either matches or it does not - with threshold adjustment applied to that binary outcome. The reference to FRR and FAR in Yokoi describes the probability of error in the binary accept/reject decision of a multistage collation system, not a scalar score produced as the outcome of an active authentication technique. Yokoi, alone or in combination with Shi nor Chang, does not teach, suggest, or disclose at least one selected active authentication technique that produces a scalar outcome - a graded, continuous, or multi-valued score reflecting a degree of authentication - rather than a simple success-or-failure result, and using this scalar outcome to determine whether the user is authentic. Accordingly, Applicants request the Examiner to reconsider and withdraw the above rejection.
Examiner respectfully submits claim 1 is properly rejected by the combination of Shi, Chang, and Dotan Regarding claim 1, Shi and Chang disclose determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique; providing the feature to the user of the user device, in response to determining that the user is authentic from the at least one selected active authentication technique, but do not explicitly disclose determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure; providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique. Dotan discloses, col. 3, lines 14-38, determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure by disclosing the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity, col. 3, lines 14-38, providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique by disclosing the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity. Dotan discloses determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure (Dotan, col. 3, lines 14-38, ,the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity);providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique (Dotan, col. 3, lines 14-38, ,the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity).
Applicant asserts as follows: New Claims New claims 19-24 have been added. Applicants submit that new claims are allowable based on their own merits as well as their dependency. For example, the cited art does not disclose or fairly suggest a computational formula or threshold that varies based on at least one of: the feature requested, a type of the feature requested, the user device, or a type of the user device, let alone using such a varying formula or threshold to combine the plurality of component scores into an authentication score, let alone subsequently increasing this computed authentication score based on the scalar outcome from active authentication techniques in response to being unable to determine the user is authentic from passive authentication information.
Examiner respectfully submits claim 19 is properly rejected by the combination of Shi, Chang, and Dotan Regarding claim 19, Shi, Chang, and Dotan disclose the method of claim 2, wherein the providing provides the feature to the user of the user device, in response to the determining that the user is authentic based on the combination of the passive authentication information and the active authentication information by (Shi, abstract, passive user identification, implementing an active authentication process); combining the plurality of component scores into an authentication score (Shi, abstract, passive user identification, implementing an active authentication process); using a computational formula or threshold that varies based on at least one of: the feature requested, a type of the feature requested, the user device, or a type of the user device (Shi, paragraph 0047, sensors, characteristics, scoring, threshold); comparing the authentication score to the threshold to determine whether the user is authentic from the passive authentication information (Shi, paragraph 0057, sensor management, passive user identification, verification, scoring).
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1- 24 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Regarding claims 1, 7, and 13 and regarding claims 20, 22, and 24; claims 1, 16, and 17 recite the limitation “determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure,” and “determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique” and claims 20, 22, and 24 recite the limitation “increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique” (emphasis added); however, the limitation “scalar” is not discussed in the specification. Although the Applicants point out “Applicants have herein (1) amended independent claims 1, 7 and 13 to include features based on claims 5, 11 and 17, respectively, while further clarifying that the active authentication technique produces a scalar result, and have (2) added new claims 19-24, which are based on the claims presented during the interview proceeding but with further details regarding the computing of the authentication score.,” the term scalar does not appear in the original disclosure and there is not sufficient support for the newly added limitation “scalar.” The Examiner respectfully requests the Applicant to point out where in the specification support can be found for the aforementioned newly added limitations. Applicant is required to cancel the new matter in the reply to this Office Action.
Regarding claims 2-6, 8-12, 14-19, 21, and 23; claims 2-6, 8-12, 14-19, 21, and 23 are dependent on claims 1, 7, and 13, and therefore inherit the 35 U.S.C 112, first paragraph issues of the independent claim.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically discloses as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-4, 7-10, 13-16, 19, 21, and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Shi (US20120167170), filed December 28, 2010, in view of Chang (US8285656), filed March 28, 2008, and Dotan (US9237143), filed September 26, 2013.
Regarding claim 1, Shi discloses a computer-implemented method of operating a server to grant a user of a user device a feature among a plurality of features available for an account associated with the user, comprising:
receiving, from the user device, a request to provide the feature from among the plurality of features; (Shi, paragraph 0060, request for accessing private data, user);
collecting passive authentication information from the user device and/or the user, the passive authentication information being usable to passively authenticate the user device and/or the user with the server without interaction with the user; (Shi, paragraph 0009, aggregating biometric classification processes conducted in the background operation of the device; paragraph 0054, data from sensors employed by host domain to perform multi-modal passive user identification);
providing the feature to the user of the user device, in response to the comparing determining that the user is authentic from the passive authentication information; and (Shi, paragraph 0060, request for accessing private data, user);
in response to the comparing being unable to determine the user is authentic from the passive authentication information, requesting and receiving, from the user, active authentication information associated with at least one selected active authentication technique from among a plurality of active authentication techniques by, (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication);
determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique, (Shi, paragraph 0064, selectively implementing an active authentication process; paragraph 0065, selectively implementing an active authentication process);
collecting the active authentication information associated with the at least one selected active authentication technique through interaction with the user, and (Shi, paragraph 0065, requiring manual user entry of authentication information);
providing the feature to the user of the user device, in response to determining that the user is authentic from the at least one selected active authentication technique. (Shi, paragraph 0027, provide data to user).
Shi does not explicitly disclose computing, by a hardware computer processor coupled to a computer memory, a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information; comparing the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information; ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques.
However, in an analogous art, Chang discloses computing, by a hardware computer processor coupled to a computer memory, a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information (Chang, col. 12, lines 4-20, compare the accuracy of the data verification methods and rank the methods, check the accuracy of data verification methods, dynamically rank);
comparing the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information (Chang, col. 12, lines 4-20, compare the accuracy of the data verification methods and rank the methods, check the accuracy of data verification methods, dynamically rank);
ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques (Chang, col. 6, lines 50-65, trustworthiness ranking).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Chang with the method/ server/ non-transitory computer readable medium of Shi, to include computing, by a hardware computer processor coupled to a computer memory, a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information; comparing the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information; ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques, to provide users with the benefits of verifying the integrity and quality of data relating to existing or potential customers (Chang: col. 1, lines 25-29).
Shi and Chang disclose determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique; providing the feature to the user of the user device, in response to determining that the user is authentic from the at least one selected active authentication technique, but do not explicitly disclose determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure; providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique.
However, in an analogous art, Dotan discloses determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure (Dotan, col. 3, lines 14-38, ,the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity);
providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique (Dotan, col. 3, lines 14-38, ,the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Dotan with the method/ server/ non-transitory computer readable medium of Shi and Chang, to include wherein all of the at least one active authentication technique does not have a binary outcome comprising success or failure, to provide users with the benefits of preventing an attacker from determining system resources (Dotan, col. 2, lines 12-25).
Regarding claim 2, Shi, Chang, and Dotan disclose the method of claim 1. Shi, Chang, and Dotan disclose wherein the providing provides the feature to the user of the user device, in response to the determining that the user is authentic based on a combination of the passive authentication information and the active authentication information (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication).
Regarding claim 3, Shi, Chang, and Dotan disclose the method of claim 2. Shi, Chang, and Dotan disclose additionally comprising: selecting the at least one active authentication technique based on the threshold (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication).
Regarding claim 4, Shi, Chang, and Dotan disclose the method of claim 2. Shi, Chang, and Dotan disclose wherein the active authentication information does not comprise a password (Shi, paragraph 0058, user may authenticate by doing a fingerprint scan, answering certain security questions).
Regarding claim 7, Shi discloses a server for granting a user of a user device a feature among a plurality of features available for an account associated with the user, the server comprising:
a memory; and
processing circuitry configured to execute instructions stored in the memory to configure the server to (Shi, paragraph 0021, memories, server, processors, computer program products, software);
receive, from the user device, a request to provide the feature from among the plurality of features (Shi, paragraph 0060, request for accessing private data, user);
collect passive authentication information from the user device and/or the user, the passive authentication information being usable to passively authenticate the user device and/or the user with the server without interaction with the user (Shi, paragraph 0009, aggregating biometric classification processes conducted in the background operation of the device; paragraph 0054, data from sensors employed by host domain to perform multi-modal passive user identification);
provide the feature to the user of the user device, in response to determining that the user is authentic from the passive authentication information (Shi, paragraph 0060, request for accessing private data, user);
in response to the server being unable to determine the user is authentic from the passive authentication information, requesting and receiving, from the user, active authentication information associated with at least one selected active authentication technique from among a plurality of active authentication techniques by (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication);
determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique (Shi, paragraph 0064, selectively implementing an active authentication process; paragraph 0065, selectively implementing an active authentication process);
collecting the active authentication information associated with the at least one selected active authentication technique through interaction with the user (Shi, paragraph 0065, requiring manual user entry of authentication information);
providing the feature to the user of the user device, in response to determining that the user is authentic from the at least one selected active authentication technique (Shi, paragraph 0027, provide data to user).
Shi does not explicitly disclose compute a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information, compare a combination of the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information, ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques.
However, in an analogous art, Chang discloses compute a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information (Chang, col. 12, lines 4-20, compare the accuracy of the data verification methods and rank the methods, check the accuracy of data verification methods, dynamically rank);
compare a combination of the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information (Chang, col. 12, lines 4-20, compare the accuracy of the data verification methods and rank the methods, check the accuracy of data verification methods, dynamically rank);
ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques (Chang, col. 6, lines 50-65, trustworthiness ranking).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Chang with the method/ server/ non-transitory computer readable medium of Shi, to include compute a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information, compare a combination of the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information, ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques, to provide users with the benefits of verifying the integrity and quality of data relating to existing or potential customers (Chang: col. 1, lines 25-29).
Shi and Chang disclose determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique; providing the feature to the user of the user device, in response to determining that the user is authentic from the at least one selected active authentication technique, but do not explicitly disclose determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure; providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique.
However, in an analogous art, Dotan discloses determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure (Dotan, col. 3, lines 14-38, ,the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity);
providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique (Dotan, col. 3, lines 14-38, ,the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Dotan with the method/ server/ non-transitory computer readable medium of Shi and Chang, to include wherein all of the at least one active authentication technique does not have a binary outcome comprising success or failure, to provide users with the benefits of preventing an attacker from determining system resources (Dotan, col. 2, lines 12-25).
Regarding claim 8, Shi, Chang, and Dotan disclose the server of claim 7. Shi, Chang, and Dotan disclose wherein the processing circuitry is configured to provide the feature to the user of the user device, in response to determining that the user is authentic based on a combination of the passive authentication information and the active authentication information (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication)
Regarding claim 9, Shi, Chang, and Dotan disclose the server of claim 8. Shi, Chang, and Dotan disclose wherein the processing circuitry is further configured to select the at least one active authentication technique based on the threshold. (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication)
Regarding claim 10, Shi, Chang, and Dotan disclose the server of claim 8. Shi, Chang, and Dotan disclose wherein the active authentication information does not comprise a password. (Shi, paragraph 0058, user may authenticate by doing a fingerprint scan, answering certain security questions)
Regarding claim 13, Shi discloses a non-transitory computer readable medium having computer readable program code embodied therein that, when executed by a server, configures the server to grant a user of a user device a feature among a plurality of features available for an account associated with the user by (Shi, paragraph 0021, memories, server, processors, computer program products, software):
receiving, from the user device, a request to provide the feature from among the plurality of features (Shi, paragraph 0060, request for accessing private data, user);
collecting passive authentication information from the user device and/or the user, the passive authentication information being usable to passively authenticate the user device and/or the user with the server without interaction with the user (Shi, paragraph 0009, aggregating biometric classification processes conducted in the background operation of the device; paragraph 0054, data from sensors employed by host domain to perform multi-modal passive user identification);
providing the feature to the user of the user device, in response to the comparing determining that the user is authentic from the passive authentication information (Shi, paragraph 0060, request for accessing private data, user);
in response to the comparing being unable to determine the user is authentic from the passive authentication information, requesting and receiving, from the user, active authentication information associated with at least one selected active authentication technique from among a plurality of active authentication techniques by (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication);
determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique (Shi, paragraph 0064, selectively implementing an active authentication process; paragraph 0065, selectively implementing an active authentication process);
collecting the active authentication information associated with the at least one selected active authentication technique through interaction with the user (Shi, paragraph 0065, requiring manual user entry of authentication information);
providing the feature to the user of the user device, in response to determining that the user is authentic from the at least one selected active authentication technique (Shi, paragraph 0027, provide data to user).
Shi does not explicitly disclose computing a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information; comparing a combination of the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information; ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques.
However, in an analogous art, Chang discloses computing a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information (Chang, col. 12, lines 4-20, compare the accuracy of the data verification methods and rank the methods, check the accuracy of data verification methods, dynamically rank);
comparing a combination of the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information (Chang, col. 12, lines 4-20, compare the accuracy of the data verification methods and rank the methods, check the accuracy of data verification methods, dynamically rank);
ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques (Chang, col. 6, lines 50-65, trustworthiness ranking).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Chang with the method/ server/ non-transitory computer readable medium of Shi, to include computing a plurality of component scores for respective ones of a plurality of authentication techniques, responsive to the passive authentication information; comparing a combination of the plurality of component scores to a threshold to determine whether the user is authentic from the passive authentication information; ranking the plurality of active authentication techniques in an order based on inconvenience scores each indicating an amount of the interaction with the user for respective ones of the plurality of active authentication techniques, to provide users with the benefits of verifying the integrity and quality of data relating to existing or potential customers (Chang: col. 1, lines 25-29).
Shi and Chang disclose determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique; providing the feature to the user of the user device, in response to determining that the user is authentic from the at least one selected active authentication technique, but do not explicitly disclose determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure; providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique.
However, in an analogous art, Dotan discloses determining one or more of the plurality of active authentication techniques that would satisfy the threshold while minimizing a total of the inconvenience scores for the one or more of the plurality of active authentication techniques to determine the at least one selected active authentication technique such that an outcome of the at least one selected active authentication technique is scalar rather than a binary outcome comprising success or failure (Dotan, col. 3, lines 14-38, ,the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity);
providing the feature to the user of the user device, in response to determining that the user is authentic based on at least the scalar outcome from the at least one selected active authentication technique (Dotan, col. 3, lines 14-38, ,the authentication system 18 may provide a non-binary authentication results, such as a numeric score indicating a level of confidence in the authenticity).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Dotan with the method/ server/ non-transitory computer readable medium of Shi and Chang, to include wherein all of the at least one active authentication technique does not have a binary outcome comprising success or failure, to provide users with the benefits of preventing an attacker from determining system resources (Dotan, col. 2, lines 12-25).
Regarding claim 14, Shi, Chang, and Dotan disclose the non-transitory computer readable medium of claim 13. Shi, Chang, and Dotan disclose wherein the providing provides the feature to the user of the user device, in response to determining that the user is authentic based on a combination of the passive authentication information and the active authentication information (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication).
Regarding claim 15, Shi, Chang, and Dotan disclose the non-transitory computer readable medium of claim 14. Shi, Chang, and Dotan disclose additionally comprising, computer readable program code configured to cause the server to select the at least one active authentication technique based on the threshold (Shi, FIG. 4, 200-206, passive authentication, 210-212, active authentication).
Regarding claim 16, Shi, Chang, and Dotan disclose the non-transitory computer readable medium of claim 14. Shi, Chang, and Dotan disclose wherein the active authentication information does not comprise a password (Shi, paragraph 0058, user may authenticate by doing a fingerprint scan, answering certain security questions).
Regarding claim 19, Shi, Chang, and Dotan disclose the method of claim 2, wherein the providing provides the feature to the user of the user device, in response to the determining that the user is authentic based on the combination of the passive authentication information and the active authentication information by (Shi, abstract, passive user identification, implementing an active authentication process);
combining the plurality of component scores into an authentication score (Shi, abstract, passive user identification, implementing an active authentication process);
using a computational formula or threshold that varies based on at least one of: the feature requested, a type of the feature requested, the user device, or a type of the user device (Shi, paragraph 0047, sensors, characteristics, scoring, threshold);
comparing the authentication score to the threshold to determine whether the user is authentic from the passive authentication information (Shi, paragraph 0057, sensor management, passive user identification, verification, scoring).
Regarding claim 21, Shi, Chang, and Dotan disclose the server of claim 8, wherein the processing circuitry is configured to provide the feature to the user of the user device, in response to determining that the user is authentic based on the combination of the passive authentication information and the active authentication information by (Shi, abstract, passive user identification, implementing an active authentication process);
combining the plurality of component scores into an authentication score (Shi, abstract, passive user identification, implementing an active authentication process);
using a computational formula or threshold that varies based on at least one of: the feature requested, a type of the feature requested, the user device, or a type of the user device (Shi, paragraph 0047, sensors, characteristics, scoring, threshold);
comparing the authentication score to the threshold to determine whether the user is authentic from the passive authentication information (Shi, paragraph 0057, sensor management, passive user identification, verification, scoring).
Regarding claim 23, Shi, Chang, and Dotan disclose the non-transitory computer readable medium of claim 14, wherein the providing provides the feature to the user of the user device, in response to determining that the user is authentic based on the combination of the passive authentication information and the active authentication information by (Shi, abstract, passive user identification, implementing an active authentication process);
combining the plurality of component scores into an authentication score (Shi, abstract, passive user identification, implementing an active authentication process);
using a computational formula or threshold that varies based on at least one of: the feature requested, a type of the feature requested, the user device, or a type of the user device (Shi, paragraph 0047, sensors, characteristics, scoring, threshold);
comparing the authentication score to the threshold to determine whether the user is authentic from the passive authentication information (Shi, paragraph 0057, sensor management, passive user identification, verification, scoring).
Claims 6, 12, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Shi (US20120167170), filed December 28, 2010, in view of Chang (US8285656), filed March 28, 2008, and Dotan (US9237143), filed September 26, 2013, and further in view of Ross (US20100280955), filed April 30, 2009.
Regarding claim 6, Shi, Chang, and Dotan disclose the method of claim 1.
Shi, Chang, and Dotan do not explicitly disclose wherein all of the at least wherein the plurality of features include at least low security features and high security features such that, for a same one of the at least one of a plurality of devices, the high security features require a higher threshold for the user than the low security features, the high security features including features facilitating a transferring of assets out of the account associated with the user.
However, in an analogous art, Ross discloses wherein all of the at least wherein the plurality of features include at least low security features and high security features such that, for a same one of the at least one of a plurality of devices, the high security features require a higher threshold for the user than the low security features, the high security features including features facilitating a transferring of assets out of the account associated with the user (Ross, paragraph 0011, bank withdrawal, paragraph 0013, certain low security transaction s may be associated with a low threshold confidence level, while high security transactions may be associated with a higher threshold confidence level).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Ross with the method/ server/ non-transitory computer readable medium of Shi, Chang, and Dotan, to include wherein all of the at least one active authentication technique does not have a binary outcome comprising success or failure, to provide users with the benefits of approving or disapproving transactions automatically (Ross; paragraph 0013).
Regarding claim 12, Shi, Chang, and Dotan disclose the server of claim 7.
Shi, Chang, and Dotan do not explicitly disclose wherein the plurality of features include at least low security features and high security features such that, for a same one of the at least one of a plurality of devices, the high security features require a higher threshold for the user than the low security features, the high security features including features facilitating a transferring of assets out of the account associated with the user.
However, in an analogous art, Ross discloses wherein the plurality of features include at least low security features and high security features such that, for a same one of the at least one of a plurality of devices, the high security features require a higher threshold for the user than the low security features, the high security features including features facilitating a transferring of assets out of the account associated with the user (Ross, paragraph 0011, bank withdrawal, paragraph 0013, certain low security transaction s may be associated with a low threshold confidence level, while high security transactions may be associated with a higher threshold confidence level).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Ross with the method/ server/ non-transitory computer readable medium of Shi, Chang, and Dotan, to include wherein the plurality of features include at least low security features and high security features such that, for a same one of the at least one of a plurality of devices, the high security features require a higher threshold for the user than the low security features, the high security features including features facilitating a transferring of assets out of the account associated with the user, to provide users with the benefits of approving or disapproving transactions automatically (Ross; paragraph 0013).
Regarding claim 18, Shi, Chang, and Dotan disclose the non-transitory computer readable medium of claim 13.
Shi, Chang, and Dotan do not explicitly disclose wherein the plurality of features include at least low security features and high security features such that, for a same one of the at least one of a plurality of devices, the high security features require a higher threshold for the user than the low security features, the high security features including features facilitating a transferring of assets out of the account associated with the user.
However, in an analogous art, Ross discloses wherein the plurality of features include at least low security features and high security features such that, for a same one of the at least one of a plurality of devices, the high security features require a higher threshold for the user than the low security features, the high security features including features facilitating a transferring of assets out of the account associated with the user (Ross, paragraph 0011, bank withdrawal, paragraph 0013, certain low security transaction s may be associated with a low threshold confidence level, while high security transactions may be associated with a higher threshold confidence level).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Ross with the method/ server/ non-transitory computer readable medium of Shi, Chang, and Dotan, to include wherein the plurality of features include at least low security features and high security features such that, for a same one of the at least one of a plurality of devices, the high security features require a higher threshold for the user than the low security features, the high security features including features facilitating a transferring of assets out of the account associated with the user, to provide users with the benefits of approving or disapproving transactions automatically (Ross; paragraph 0013).
Claims 20, 22, and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Shi (US20120167170), filed December 28, 2010, in view of Chang (US8285656), filed March 28, 2008, and Dotan (US9237143), filed September 26, 2013, and further in view of Graham (US20110270763), filed April 28, 2011.
Regarding claim 20, Shi, Chang, and Dotan disclose the method of claim 19, wherein the determining that the user is authentic based on the combination of the passive authentication information and the active authentication information further includes (Shi, abstract, passive user identification, implementing an active authentication process).
Shi, Chang, and Dotan do not explicitly disclose increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information, and recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information.
However, in an analogous art, Graham discloses increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information (Graham, generate user validation score);
recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information (Graham, paragraph 0437, reevaluate relative weight of each validation, user validation score).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Graham with the method/ server/ non-transitory computer readable medium of Shi, Chang, and Dotan, to include increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information, and recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information, to provide users with the benefits of allowing individuals and businesses to secure, protect, and control the dissemination of valuable information in a comprehensive and integrated manner (Graham: paragraphs 0011and 0012).
Regarding claim 22, Shi, Chang, and Dotan disclose the server of claim 21, wherein the processing circuitry is further configured to determine that the user is authentic based on the combination of the passive authentication information and the active authentication information by (Shi, abstract, passive user identification, implementing an active authentication process).
Shi, Chang, and Dotan do not explicitly disclose increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information, and recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information.
However, in an analogous art, Graham discloses increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information (Graham, generate user validation score);
recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information (Graham, paragraph 0437, reevaluate relative weight of each validation, user validation score).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Graham with the method/ server/ non-transitory computer readable medium of Shi, Chang, and Dotan, to include increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information, and recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information, to provide users with the benefits of allowing individuals and businesses to secure, protect, and control the dissemination of valuable information in a comprehensive and integrated manner (Graham: paragraphs 0011and 0012).
Regarding claim 24, Shi, Chang, and Dotan disclose the non-transitory computer readable medium of claim 23, wherein the determining that the user is authentic based on the combination of the passive authentication information and the active authentication information further includes (Shi, abstract, passive user identification, implementing an active authentication process).
Shi, Chang, and Dotan do not explicitly disclose increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information, and recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information.
However, in an analogous art, Graham discloses increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information (Graham, generate user validation score);
recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information (Graham, paragraph 0437, reevaluate relative weight of each validation, user validation score).
Therefore, it would have been obvious to one of ordinary skill in the art at or before the effective filing date of the claimed invention to combine the teachings of Graham with the method/ server/ non-transitory computer readable medium of Shi, Chang, and Dotan, to include increasing the authentication score based on the scalar outcome from the at least one selected active authentication technique, in response to the comparing being unable to determine the user is authentic from the passive authentication information, and recomparing the increased authentication score to the threshold to determine whether the user is authentic based on the combination of the passive authentication information and the active authentication information, to provide users with the benefits of allowing individuals and businesses to secure, protect, and control the dissemination of valuable information in a comprehensive and integrated manner (Graham: paragraphs 0011and 0012).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to WALTER J MALINOWSKI whose telephone number is (571)272-5368. The examiner can normally be reached 8-6:30 MTWH.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LUU PHAM can be reached at 5712705002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/W.J.M/Examiner, Art Unit 2439
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439