DETAILED ACTION
Notice of Pre-AIA or AIA Status
In the present application, filed on or after March 16, 2013, claims 1-20 have been considered and examined under the first inventor to file provisions of the AIA .
Respond to Applicant’s Arguments/Remarks
Applicant’s arguments, see Remarks, filed 05/07/2026, with respect to the rejection(s) of claims 1-20 has been fully considered and the results as followings:
On pages 8-11 of Applicant’s remarks, Applicant argues that the combination of Min and Piri does not teach the claimed invention because Min discloses the active electronic key includes an electrical power source to provide electrical power supply to all electronic keys and the passive electronic lock. Thus, replacing the physical keys of Min with contactless cards would eliminate the disclosed power source for the passive key and the lock itself to render the system unsatisfactory for its intended purpose.
Examiner respectfully disagrees with Applicant because the claimed invention does not recite any limitations for the power source. Further, as discussed in the Non-Final rejection mailed on 02/09/2026, the rejection relied upon Min to disclose a lock system to receive the first key information and the second key information for performing authentication of users to control operations of the lock (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively), except for the claimed limitations of the first key information and the second key information received from contactless cards and the process steps by the authentication server.
However, it has been known in the art of user authentications to implement the process steps performed by an authentication server, and the data from contactless cards, as suggested by Piri, which discloses the process steps performed by an authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15), and the data from contactless cards (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145).
As in Piri’s teachings, the RFID/NFC reader includes power for operations to obtain information of contactless cards for authentication (Piri: Abstract, column 2 lines 37-column 3 lines 45, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260).
Therefore, in view of teachings by Min and Piri, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the electronic locking system of Min to include the process steps performed by an authentication server, and the data from contactless cards, as suggested by Piri. The motivation for this is to implement a known alternative method for processing user authentication using contactless cards.
As a result, Applicant arguments are not deemed persuasive, and the previous rejections pertaining to the previous set of claims are sustained.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 04/17/2026 are in compliance with the provision of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by Examiner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 7-12, and 14-18 are rejected under 35 U.S.C. 103 as being unpatentable over Min (Min – US 2023/0169806 A1) in view of Piri et al. (Piri – US 12,309,585 B1).
As to claim 1, Min discloses a method comprising:
receiving first encrypted data from a first contactless key associated with a first user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: receive an active digital key from the active electronic key 2001 via an active communication channel 20151 of the electronic lock controller 110… In certain embodiments, the first user is a management staff of the passive electronic lock 100 and uses the active electronic key 2001, the second user is a customer and uses the passive electronic key 2002) and second encrypted data from a second contactless key associated with a second user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: a passive digital key from the passive electronic key 2002 via a passive communication channel 20152 of the electronic lock controller 110… In certain embodiments, the first user is a management staff of the passive electronic lock 100 and uses the active electronic key 2001, the second user is a customer and uses the passive electronic key 2002);
determining based on the first encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) and the second encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100), whether the first user account and the second user account are authorized to alter a state of an access control system (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively); and
in response to both the first user account and the second user account being authorized, causing, a signal to be sent to the access control system to alter the state thereof (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively).
Min does not explicitly disclose the process steps performed by an authentication server, and the data from contactless cards.
However, it has been known in the art of user authentications to implement the process steps performed by an authentication server, and the data from contactless cards, as suggested by Piri, which discloses the process steps performed by an authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15), and the data from contactless cards (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145).
Therefore, in view of teachings by Min and Piri, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the electronic locking system of Min to include the process steps performed by an authentication server, and the data from contactless cards, as suggested by Piri. The motivation for this is to implement a known alternative method for processing user authentication using contactless cards.
As to claim 2, Min and Piri disclose the limitations of claim 1 further comprising the method of claim 1, wherein receiving the first encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) and the second encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) includes receiving, by the authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15), the first encrypted data via a contactless card reader (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145) proximate to the access control system (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively).
As to claim 3, Min and Piri disclose the limitations of claim 2 further comprising the method of claim 2, further comprising receiving the first encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) and the second encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) via a routing network (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110 via the bridge device 115 and the mobile device 150, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145) connected between the authentication server and the contactless card reader (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15).
As to claim 4, Min and Piri disclose the limitations of claim 3 further comprising the method of claim 3, wherein the first encrypted data and the second encrypted data are received sequentially (Min: [0082]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: while the active electronic key 2001 is still in the active electronic keyhole 1011 of the passive electronic lock 100, a second user inserts the passive electronic key 2002 into the passive electronic keyhole 1012 of the passive electronic lock 100 to receive electrical power supply from the passive electronic lock 100 through an electrical power module 20445 of the passive electronic key 2002 and a passive electronic key power supply port 20162 from the passive electronic lock 100, and the passive electronic key 2002 provides a passive digital key to the passive electronic lock 100 through a passive communication channel 20152 of the passive electronic key 2002 ) by the contactless card reader (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110 via the RFID/NFC card reader 125, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15).
As to claim 7, Min and Piri disclose the limitations of claim 1 further comprising the method of claim 1, wherein altering the state of the access control system includes altering a locked state of a locking mechanism of one or more of the following: a bank vault, a branch access door, and a teller’s drawer (Min: [0002], [0145]-[151], and FIG. 10: These boxes are often kept in vaults and can be rented throughout the lifetime of a customer for an annual fee. Usually, opening the safe deposit box requires at least two keys, one for a bank management staff, and the other one for the customer. Both keys are required to open the safe deposit box. Currently, most banks still use mechanical safe deposit boxes with a set of keys. These mechanical lock's keys are easy to duplicate and the safety of the contents in the safe deposit box is not guaranteed. It is desirable to have electronic locks with electronic keys that people are unable to duplicate).
As to claim 8, Min discloses an access control system comprising:
a locking mechanism to prevent physical access to an area (Min: [0002], [0145]-[151], and FIG. 10: These boxes are often kept in vaults and can be rented throughout the lifetime of a customer for an annual fee. Usually, opening the safe deposit box requires at least two keys, one for a bank management staff, and the other one for the customer. Both keys are required to open the safe deposit box. Currently, most banks still use mechanical safe deposit boxes with a set of keys. These mechanical lock's keys are easy to duplicate and the safety of the contents in the safe deposit box is not guaranteed. It is desirable to have electronic locks with electronic keys that people are unable to duplicate);
a memory for storing executable instructions; a processing circuit in communication with the locking mechanism, the processing circuit to execute the executable instructions (Min: FIG. 6), which when executed cause the processing circuit to:
receive first encrypted data associated with a first user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: receive an active digital key from the active electronic key 2001 via an active communication channel 20151 of the electronic lock controller 110… In certain embodiments, the first user is a management staff of the passive electronic lock 100 and uses the active electronic key 2001, the second user is a customer and uses the passive electronic key 2002) and second encrypted data associated with a second user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: a passive digital key from the passive electronic key 2002 via a passive communication channel 20152 of the electronic lock controller 110… In certain embodiments, the first user is a management staff of the passive electronic lock 100 and uses the active electronic key 2001, the second user is a customer and uses the passive electronic key 2002);
determine whether the first user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) and the second user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) are authorized to alter a state of the locking mechanism (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively);
in response to receiving, from the authentication server, an indication that the first user account and the second user account are authorized, send a control signal to the locking mechanism to alter the state thereof to thereby allow or prevent access to the area (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively).
Min does not explicitly disclose the process steps performed by an authentication server as recited in the limitations of send the first encrypted data and the second encrypted data to an authentication server to determine the first encrypted data and the second encrypted data are authorized to alter a state of the locking mechanism.
However, it has been known in the art of user authentications to implement the process steps performed by an authentication server as recited in the limitations of send the first encrypted data and the second encrypted data to an authentication server to determine the first encrypted data and the second encrypted data are authorized to alter a state of the locking mechanism, as suggested by Piri, which discloses the process steps performed by an authentication server as recited in the limitations of send the first encrypted data and the second encrypted data to an authentication server to determine the first encrypted data and the second encrypted data are authorized to alter a state of the locking mechanism (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15).
Therefore, in view of teachings by Min and Piri, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the electronic locking system of Min to include the process steps performed by an authentication server as recited in the limitations of send the first encrypted data and the second encrypted data to an authentication server to determine the first encrypted data and the second encrypted data are authorized to alter a state of the locking mechanism, as suggested by Piri. The motivation for this is to implement a known alternative method for processing user authentication using contactless cards.
As to claim 9, Min and Piri disclose the limitations of claim 8 further comprising the access control system of claim 8, further comprising one or more contactless card readers (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145) in communication with the processing circuit;
wherein the first encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) and the second encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) are received via the one or more contactless card readers (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145).
As to claim 10, Min and Piri disclose the limitations of claim 9 further comprising the access control system of claim 9, wherein the processing circuit is to send the first encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) and the second encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) through a routing network (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110 via the bridge device 115 and the mobile device 150, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145) to the authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15).
As to claim 11, Min and Piri disclose the limitations of claim 8 further comprising the access control system of claim 8, wherein the first encrypted data is received from a first contactless card associated with the first user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: receive an active digital key from the active electronic key 2001 via an active communication channel 20151 of the electronic lock controller 110… In certain embodiments, the first user is a management staff of the passive electronic lock 100 and uses the active electronic key 2001, the second user is a customer and uses the passive electronic key 2002 and Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145) and the second encrypted data is received from a second contactless card associated with the second user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: a passive digital key from the passive electronic key 2002 via a passive communication channel 20152 of the electronic lock controller 110… In certain embodiments, the first user is a management staff of the passive electronic lock 100 and uses the active electronic key 2001, the second user is a customer and uses the passive electronic key 2002 and Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145).
As to claim 12, Min and Piri disclose the limitations of claim 8 further comprising the access control system of claim 8, wherein the indication that the first user account and the second user account are authorized (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively) includes a first portion of a Shannon-Secret-Sharing key and a second portion of the Shannon-Secret-Sharing key (Piri: column 4 lines 45-58, column 6 lines 64-column 7 lines 13, column 16 lines 35-55, column 17 lines 40-62, and FIG. 2: The authentication service 260 processes the authentication request using the associated authenticator, and upon successful authentication, the authentication service 260 will receive 265 the corresponding user passkey 275 from the passkeys database 270. The authentication service 260 will then provide a response with the user's passkey 275 and relay it back 255 to the authenticator application 205 as the authentication response. The authenticator application 205 sends 225 the received request to a browser 215, enabling the user 105 to login to a requested application 210: In this rejection, Examiner takes Official Notice that the passkey as the Shannon-Secret Sharing Key as a known alternative code).
As to claim 14, Min and Piri disclose the limitations of claim 8 further comprising the access control system of claim 8, wherein the area includes one or more of: a bank vault, a branch room or lobby, and a teller’s drawer (Min: [0002], [0145]-[151], and FIG. 10: These boxes are often kept in vaults and can be rented throughout the lifetime of a customer for an annual fee. Usually, opening the safe deposit box requires at least two keys, one for a bank management staff, and the other one for the customer. Both keys are required to open the safe deposit box. Currently, most banks still use mechanical safe deposit boxes with a set of keys. These mechanical lock's keys are easy to duplicate and the safety of the contents in the safe deposit box is not guaranteed. It is desirable to have electronic locks with electronic keys that people are unable to duplicate).
As to claim 15, Min discloses a non-transitory computer-readable storage medium having executable instructions stored thereon, which, when executed by a processing circuit of an authentication server, cause the processing circuit to:
receive first encrypted data from a first contactless key associated with a first user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: receive an active digital key from the active electronic key 2001 via an active communication channel 20151 of the electronic lock controller 110… In certain embodiments, the first user is a management staff of the passive electronic lock 100 and uses the active electronic key 2001, the second user is a customer and uses the passive electronic key 2002) and second encrypted data from a second contactless key associated with a second user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: a passive digital key from the passive electronic key 2002 via a passive communication channel 20152 of the electronic lock controller 110… In certain embodiments, the first user is a management staff of the passive electronic lock 100 and uses the active electronic key 2001, the second user is a customer and uses the passive electronic key 2002);
determine, based on the first encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) and the second encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100), whether the first user account and the second user account are authorized to access a controlled area (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively); and
in response to both the first user account and the second user account being authorized, cause a signal to be sent to an access control system to alter a state thereof to grant or prevent access to the controlled area (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively).
Min does not explicitly disclose the process steps performed by an authentication server, and the data from contactless cards.
However, it has been known in the art of user authentications to implement the process steps performed by an authentication server, and the data from contactless cards, as suggested by Piri, which discloses the process steps performed by an authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15), and the data from contactless cards (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 26-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6: These identifiers are sourced from a connected reader device 125, such as a RFID/NFC reader, when a tap of RFID/NFC tags or access cards 110 is detected. The bridge device 115 receives a unique identifier from a short-range wireless device such as RFID/NFC tag or access card 110 using a card reader device 125. The card reader device 125 has an associated card reader interface 130 which resides on a computing device 145).
Therefore, in view of teachings by Min and Piri, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the electronic locking system of Min to include the process steps performed by an authentication server, and the data from contactless cards, as suggested by Piri. The motivation for this is to implement a known alternative method for processing user authentication using contactless cards.
As to claim 16, Min and Piri disclose the limitations of claim 15 further comprising the non-transitory computer-readable storage medium of claim 15, wherein the signal to be sent to the access control system is to alter a locked state of a locking mechanism that controls access to the controlled area, the controlled area including one or more of: a bank vault, a lobby or room of a bank branch, and a teller’s drawer (Min: [0002], [0145]-[151], and FIG. 10: These boxes are often kept in vaults and can be rented throughout the lifetime of a customer for an annual fee. Usually, opening the safe deposit box requires at least two keys, one for a bank management staff, and the other one for the customer. Both keys are required to open the safe deposit box. Currently, most banks still use mechanical safe deposit boxes with a set of keys. These mechanical lock's keys are easy to duplicate and the safety of the contents in the safe deposit box is not guaranteed. It is desirable to have electronic locks with electronic keys that people are unable to duplicate).
As to claim 17, Min and Piri disclose the limitations of claim 16 further comprising the non-transitory computer-readable storage medium of claim 16, wherein the processing circuit to receive the first encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) and the second encrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key from the active electronic key 2001 is encrypted by a digital key encryption/decryption module 20443 of the active electronic key 2001 and transmitted to the passive electronic lock 100, and the passive digital key from the passive electronic key 2002 is encrypted by a digital key encryption/decryption module 20443 of the passive electronic key 2002 and transmitted to the passive electronic lock 100) includes the processing circuit to receive the first encrypted data and the second encrypted data via one or more contactless card readers(Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15) in communication with the authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15).
As to claim 18, Min and Piri disclose the limitations of claim 17 further comprising the non-transitory computer-readable storage medium of claim 17, wherein the first encrypted data and the second encrypted data are received sequentially (Min: [0082]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: while the active electronic key 2001 is still in the active electronic keyhole 1011 of the passive electronic lock 100, a second user inserts the passive electronic key 2002 into the passive electronic keyhole 1012 of the passive electronic lock 100 to receive electrical power supply from the passive electronic lock 100 through an electrical power module 20445 of the passive electronic key 2002 and a passive electronic key power supply port 20162 from the passive electronic lock 100, and the passive electronic key 2002 provides a passive digital key to the passive electronic lock 100 through a passive communication channel 20152 of the passive electronic key 2002 ) via the one or more contactless card readers (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110 via the RFID/NFC card reader 125, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15).
Claims 5 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Min (Min – US 2023/0169806 A1) in view of Piri et al. (Piri – US 12,309,585 B1) and further in view of Rule et al. (Rule – US 2022/0284416 A1).
As to claim 5, Min and Piri disclose the limitations of claim 1 further comprising the method of claim 1, further comprising:
decrypting, by the authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260) using, respectively, the first decryption key and second decryption key, the first encrypted data and the second encrypted data to obtain first decrypted data and second decrypted data, respectively (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively);
comparing, by the authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260), the first decrypted data and second decrypted data to a list of authorized user accounts and corresponding expected decrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively); and
determining, by the authentication server (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260: The authenticator application 205 sends 235 the login request along with the unique identifier to the network 245 and from there 250 to an authentication service 260 that is securely hosted on a remote server across a network. The authentication service 260 handles FIDO authentication requests. The virtually hosted authenticators are under the management of the authentication service 260. Each authenticator is configured to be exclusively accessible by a single user 105 through the association of a unique identifier. This approach ensures that the authentication service 260 can interact with the authenticator, retrieve pertinent data, and execute the authentication process. For this, the authentication service 260 maps the unique identifier to a virtually hosted authenticator (security key), and returns a response back 255 to the network 245 and from there 240 to the authenticator application 205 on the mobile device 15), that the first decrypted data matches a corresponding first expected decrypted data for the first user account and determining, by the authentication server, that the second decrypted data matches a corresponding second expected decrypted data for the second user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively).
The combination of Min and Piri does not explicitly disclose deriving, by the authentication server using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data;
deriving, by the authentication server using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data.
However, it has been known in the art of authenticating user to implement deriving, by the authentication server using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data;
deriving, by the authentication server using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data, as suggested by Rule, which discloses deriving, by the authentication server using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data (Rule: Abstract, [0022]-[0029], [ 0035]-[0036], [0038]-[0040], and FIG. 1 the counter value 104: the authentication application 123 may attempt to decrypt the cryptogram using a copy of the master key 105 stored by the server 120. In some embodiments, the authentication application 123 may identify the master key 105 and counter value 104 using the unencrypted customer ID 107 included in the data package 117. In some examples, the authentication application 123 may provide the master key 105 and counter value 104 as input to the cryptographic algorithm, which produces a diversified key 106 as output. The resulting diversified key 106 may correspond to the diversified key 106 of the contactless card 101, which may be used to decrypt the cryptogram in the data package 117);
deriving, by the authentication server using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data (Rule: Abstract, [0022]-[0029], [ 0035]-[0036], [0038]-[0040], and FIG. 1 the counter value 104: the authentication application 123 may attempt to decrypt the cryptogram using a copy of the master key 105 stored by the server 120. In some embodiments, the authentication application 123 may identify the master key 105 and counter value 104 using the unencrypted customer ID 107 included in the data package 117. In some examples, the authentication application 123 may provide the master key 105 and counter value 104 as input to the cryptographic algorithm, which produces a diversified key 106 as output. The resulting diversified key 106 may correspond to the diversified key 106 of the contactless card 101, which may be used to decrypt the cryptogram in the data package 117);
decrypting, by the authentication server using, respectively, the first decryption key and second decryption key, the first encrypted data and the second encrypted data to obtain first decrypted data and second decrypted data, respectively (Rule: Abstract, [0022]-[0029], [0035]-[0036], [0038]-[0040], and FIG. 1 the authentication application 122 of the server 120);
comparing, by the authentication server, the first decrypted data and second decrypted data to a list of authorized user accounts and corresponding expected decrypted data (Rule: Abstract, [0022]-[0029], [0035]-[0036], [0038]-[0040], and FIG. 1 the authentication application 122 of the server 120); and
determining, by the authentication server, that the first decrypted data matches a corresponding first expected decrypted data for the first user account and determining, by the authentication server, that the second decrypted data matches a corresponding second expected decrypted data for the second user account (Rule: Abstract, [0022]-[0029], [0035]-[0036], [0038]-[0040], and FIG. 1 the authentication application 122 of the server 120: the authentication application 123 may successfully decrypt the cryptogram, thereby verifying or authenticating the cryptogram in the data package 117 (e.g., by comparing the customer ID 107 that is produced by decrypting the cryptogram to a known customer ID stored in the account data 124, and/or based on an indication that the decryption using the key 105 and/or 106 was successful)… the authentication application 123 is unable to decrypt the cryptogram to yield the expected result (e.g., the customer ID 107 of the account associated with the contactless card 101), the authentication application 123 does not validate the cryptogram of the data package 117. In such an example, the authentication application 123 determines to refrain from activating the contactless card. The authentication application 123 and/or the web server 127 may transmit an indication of the failed decryption to the web browser 115).
Therefore, in view of teachings by Min, Piri, and Rule, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the electronic locking system of Min and Piri to include deriving, by the authentication server using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data;
deriving, by the authentication server using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data, as suggested by Rule. The motivation for this is to implement a known alternative method for performing user authentication using contactless cards based on counter values of the contactless cards.
As to claim 19, Min and Piri disclose the limitations of claim 15 further comprising the non-transitory computer-readable storage medium of claim 15, wherein the processing circuit is further to:
derive, using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data;
derive, using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data;
decrypt (Piri: Abstract, column 2 lines 37-column 3 lines 21, column 14 lines 6-44, column 15 lines 40-57, column 17 lines 4-62, FIG. 1-3 the RFID/NFC card 110, and FIG. 5-6 the authentication service 260), using, respectively, the first decryption key and second decryption key, the first encrypted data and the second encrypted data, to obtain first decrypted data and second decrypted data, respectively (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively);
compare the first decrypted data and second decrypted data to a list of authorized user accounts and corresponding expected decrypted data (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively); and
determine that the first decrypted data matches a corresponding first expected decrypted data for the first user account and determine that the second decrypted data matches a corresponding second expected decrypted data for the second user account (Min: [0007]-[0013], [0081]-[0091], [0145]-[0151], FIG. 1, FIG. 6, and FIG. 10: the active digital key and the passive digital key received are decrypted by the digital key encryption/decryption module 10443 and authenticated by the digital key control module 10442 of the passive electronic lock 100. The electronic lock control module 10446 operates the electronic lock tongue 103 through the electronic locking mechanism 106 to lock or unlock the passive electronic lock 100, when the digital key authentication module 10444 determines that the active digital key and the passive digital key received match the active digital key and the passive digital key prestored in the digital key storage module 10441, respectively).
The combination of Min and Piri does not explicitly disclose derive, using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data; and
derive, using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data.
However, it has been known in the art of authenticating user to implement derive, using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data; and
derive, using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data, as suggested by Rule, which discloses derive, using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data (Rule: Abstract, [0022]-[0029], [ 0035]-[0036], [0038]-[0040], and FIG. 1 the counter value 104: the authentication application 123 may attempt to decrypt the cryptogram using a copy of the master key 105 stored by the server 120. In some embodiments, the authentication application 123 may identify the master key 105 and counter value 104 using the unencrypted customer ID 107 included in the data package 117. In some examples, the authentication application 123 may provide the master key 105 and counter value 104 as input to the cryptographic algorithm, which produces a diversified key 106 as output. The resulting diversified key 106 may correspond to the diversified key 106 of the contactless card 101, which may be used to decrypt the cryptogram in the data package 117); and
derive, using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data (Rule: Abstract, [0022]-[0029], [ 0035]-[0036], [0038]-[0040], and FIG. 1 the counter value 104: the authentication application 123 may attempt to decrypt the cryptogram using a copy of the master key 105 stored by the server 120. In some embodiments, the authentication application 123 may identify the master key 105 and counter value 104 using the unencrypted customer ID 107 included in the data package 117. In some examples, the authentication application 123 may provide the master key 105 and counter value 104 as input to the cryptographic algorithm, which produces a diversified key 106 as output. The resulting diversified key 106 may correspond to the diversified key 106 of the contactless card 101, which may be used to decrypt the cryptogram in the data package 117);
decrypt, using, respectively, the first decryption key and second decryption key, the first encrypted data and the second encrypted data, to obtain first decrypted data and second decrypted data, respectively (Rule: Abstract, [0022]-[0029], [0035]-[0036], [0038]-[0040], and FIG. 1 the authentication application 122 of the server 120);
compare the first decrypted data and second decrypted data to a list of authorized user accounts and corresponding expected decrypted data (Rule: Abstract, [0022]-[0029], [0035]-[0036], [0038]-[0040], and FIG. 1 the authentication application 122 of the server 120); and
determine that the first decrypted data matches a corresponding first expected decrypted data for the first user account and determine that the second decrypted data matches a corresponding second expected decrypted data for the second user account (Rule: Abstract, [0022]-[0029], [0035]-[0036], [0038]-[0040], and FIG. 1 the authentication application 122 of the server 120: the authentication application 123 may successfully decrypt the cryptogram, thereby verifying or authenticating the cryptogram in the data package 117 (e.g., by comparing the customer ID 107 that is produced by decrypting the cryptogram to a known customer ID stored in the account data 124, and/or based on an indication that the decryption using the key 105 and/or 106 was successful)… the authentication application 123 is unable to decrypt the cryptogram to yield the expected result (e.g., the customer ID 107 of the account associated with the contactless card 101), the authentication application 123 does not validate the cryptogram of the data package 117. In such an example, the authentication application 123 determines to refrain from activating the contactless card. The authentication application 123 and/or the web server 127 may transmit an indication of the failed decryption to the web browser 115).
Therefore, in view of teachings by Min, Piri, and Rule, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the electronic locking system of Min and Piri to include derive, using a first counter included in the first encrypted data, a first decryption key to decrypt the first encrypted data; and
derive, using a second counter included in the second encrypted data, a second decryption key to decrypt the second encrypted data, as suggested by Rule. The motivation for this is to implement a known alternative method for performing user authentication using contactless cards based on counter values of the contactless cards.
Allowable Subject Matter
Claims 6, 13, and 20 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all the limitations of the base claim and any intervening claims.
The following is a statement of reasons for the indication of allowable subject matter:
The prior art does not teach the combination of the limitations including in response to the authentication server determining that the first decrypted data matches the corresponding first expected decrypted data, sending a fist portion of a Shannon-Secret-Sharing key to the access control system as part of the signal; and in response to the authentication server determining that the second decrypted data matches the corresponding second expected decrypted data, sending a second portion of the Shannon-Secret-Sharing key to the access control system as part of the signal; wherein the first portion of the Shannon-Secret-Sharing key and the second portion of the Shannon-Secret-Sharing key are to be used by the access control system to alter the state thereof, as presented in claim 6. Although many of the limitations of the claims can be individually found in the prior art, there is no reasonable combination of references sufficient to teach the invention as claimed in claim 6.
The prior art does not teach the combination of the limitations including combine the first portion of the Shannon-Secret-Sharing key and the second portion of the Shannon-Secret-Sharing key to obtain a combined Shannon-Secret-Sharing key; compare the combined Shannon-Secret-Sharing key to an expected Shannon-Secret-Sharing key; and in response to the combined Shannon-Secret-Sharing key corresponding to the expected Shannon-Secret-Sharing key, send the control signal to the locking mechanism to alter the state thereof, as presented in claim 13. Although many of the limitations of the claims can be individually found in the prior art, there is no reasonable combination of references sufficient to teach the invention as claimed in claim 13.
The prior art does not teach the combination of the limitations including wherein the processing circuit is further to: in response to the processing circuit determining that the first decrypted data matches the corresponding first expected decrypted data, send a fist portion of a Shannon-Secret-Sharing key to the access control system as part of the signal to be sent to the access control system; in response to the authentication server determining that the second decrypted data matches the corresponding second expected decrypted data, send a second portion of the Shannon-Secret-Sharing key to the access control system as part of the signal to be sent to the access control system; wherein the first portion of the Shannon-Secret-Sharing key and the second portion of the Shannon-Secret-Sharing key are to be used by the access control system to alter the state thereof, as presented in claim 20. Although many of the limitations of the claims can be individually found in the prior art, there is no reasonable combination of references sufficient to teach the invention as claimed in claim 20.
Citation of Pertinent Art
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure:
Cozza, US 2023/0115152 A1, discloses multi-factor safe lock.
Cordiner et al., US 2017/0154483 A1, discloses an electronic locking system.
Diorio et al., US 12,536,399 B1, discloses digital identities for physical items.
Conclusion
All claims are drawn to the same invention claimed in the application prior to the entry of the submission under 37 CFR 1.114 and could have been finally rejected on the grounds and art of record in the next Office action if they had been entered in the application prior to entry under 37 CFR 1.114. Accordingly, THIS ACTION IS MADE FINAL. See MPEP §706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to QUANG PHAM whose telephone number is (571)-270-3668. The examiner can normally be reached 09:00 AM - 05:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, QUAN-ZHEN WANG can be reached at (571)-272-3114. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/QUANG PHAM/Primary Examiner, Art Unit 2685