DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 06/19/2026 have been fully considered but they are not persuasive.
A – Applicant argues:
Claims 19 and 20 are rejected under 35 U.S.C. § 112(d) or Pre-AIA 35 U.S.C. § 112, 4th paragraph, as being of improper dependent form. Applicant respectfully traverses this rejection.
In response, Applicant has amended claims 19-20 for clarity.
Further, Applicant respectfully submits claims 19 and 20 are in proper dependent form because they add further limitations to the subject matter of claim 1.
Claim 19 adds the structural elements of an electronic equipment (at least one processor and a memory) that is specifically programmed to execute the method of claim 1. Claim 20 adds the limitations of a non-transitory computer-readable storage medium storing a computer program that implements the method of claim 1. The mere fact that the dependent claims are in a different statutory category (apparatus/medium) than the base claim (method) does not automatically render them improper. MPEP § 608.01(n) explicitly states that "the fact that an independent claim and a dependent claim are in different statutory classes, for example, an apparatus and a method, does not alone make the dependent claim improper." The test under 35 U.S.C. § 112(d) is substantive: a dependent claim must specify a further limitation of the claimed subject matter and be narrower than the claim from which it depends. Here, claims 19-20 are unquestionably narrower than claim 1 because they require tangible components (processor, memory, storage medium) that are not required by claim 1. Any infringement of claims 19-20 necessarily requires practicing the method of claim 1, thereby satisfying the "further limitation" requirement.
Accordingly, reconsideration and withdrawal of the rejection of claims 19 and 20 under 35 U.S.C. § 112(d) or Pre-AIA 35 U.S.C. § 112, 4th paragraph, are respectfully requested.
A – The Examiner respectfully disagrees:
Claims 19-20 do not add a further limitation to independent claim 1. Claim 1 describes a method of a data message to be sent (communication) via a terminal. This describes structural elements of electronic equipment. Further, Storage media is part of structural elements of electronic equipment (See figure 8 of instant application). Claim 19-20 containing a processor and or memory merely identify components expected in claim 1.
Therefore the rejection is maintained.
B – Applicant argues:
Claim 1 discloses that, after determining the type of a data message to be sent, strong verification is performed on a first data message and weak verification is performed on a second data message, where the strong verification has a higher security level than the weak verification. In particular, the strong verification includes performing cryptographic calculation on the data message to generate a first verification value and adding the first verification value to the data message, while the weak verification includes adding stored authorization verification information to the data message according to IP information carried by the data message.
However, Xu does not disclose the above technical solution.
B – The Examiner respectfully disagrees:
As described in Xu, paragraph 40, an authorization request including credentials is provided to generate an authorization token. This creates a first verification value (credentials validated). The token is added to further messages for validation, however the strong verification of verifying the credentials is not required.
The rejections are maintained.
C – Applicant argues:
One of ordinary skill in the art would understand that Xu only describes generation, signing, and verification of an authorization token; authentication in Xu is achieved through cryptographic algorithms, private-key signing, and public-key verification; even for a subsequent service request, authentication is still performed by verifying a signed authorization token. Therefore, Xu does not disclose applying different verification mechanisms having different security levels to different types of data messages, nor does Xu disclose performing a weak verification having a lower security level than the strong verification for a second data message.
Furthermore, claim 1 discloses that the weak verification includes "adding stored authorization verification information to the data message according to IP information carried by the data message."
C – The Examiner respectfully disagrees:
As described in Xu, paragraph 40, an authorization request including credentials is provided to generate an authorization token. This creates a first verification value (credentials validated). The token is added to further messages for validation, however the strong verification of verifying the credentials is not required.
The rejections are maintained.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(d):
(d) REFERENCE IN DEPENDENT FORMS.—Subject to subsection (e), a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers.
The following is a quotation of pre-AIA 35 U.S.C. 112, fourth paragraph:
Subject to the following paragraph [i.e., the fifth paragraph of pre-AIA 35 U.S.C. 112], a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers.
Claims 19-20 are rejected under 35 U.S.C. 112(d) or pre-AIA 35 U.S.C. 112, 4th paragraph, as being of improper dependent form for failing to further limit the subject matter of the claim upon which it depends, or for failing to include all the limitations of the claim upon which it depends. Claims 19 and 20 change the embodiment of claim 1, however claims 19-20 do not further limit claim 1. Applicant may cancel the claim(s), amend the claim(s) to place the claim(s) in proper dependent form, rewrite the claim(s) in independent form, or present a sufficient showing that the dependent claim(s) complies with the statutory requirements.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claim(s) 1-3, 5-20 is/are rejected under 35 U.S.C. 102(a)(1), (a)(2) as being anticipated by Xu et al., (US Publication No. 2019/0074979), hereinafter “Xu”.
Regarding claims 1, 19-20, Xu discloses
determining a type of a data message to be sent, wherein the type of the data message comprises a first data message and a second data message [Xu, paragraph 4, 40, figures 1, 6];
the first data message is a primary data message sent to a communication receiving terminal, and the second data message is a non-primary data message sent to the communication receiving terminal [Xu, paragraph 40, 200-201, figures 1, 6];
in response to that the data message is the first data message, performing strong verification on the data message [Xu, paragraph 40, 200-201, figures 1, 6];
in response to that the data message is the second data message, performing weak verification on the data message, wherein the strong verification is a verification with security higher than the weak verification [Xu, paragraph 40, 200-206, figures 1, 6]; and
in response to that verification passes, transmitting the data message to the communication receiving terminal [Xu, paragraph 40, 200-206, figures 1, 6];
wherein the communication protection method is applied to a first transmission node or a communication initiating terminal, the performing the strong verification on the data message comprises: performing cryptography calculation on the data message and generating a first verification value, and adding the first verification value to the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; and the performing the weak verification on the data message comprises: adding stored authorization verification information to the data message according to Internet Protocol, IP, information carried by the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 2, Xu further discloses
wherein the determining the type of the data message comprises: in response to that the data message carries an Internet Protocol, IP, of the communication receiving terminal appearing for a first time, determining the data message as the first data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 3, Xu further discloses
wherein the determining the type of the data message comprises: in response to that the data message carries the IP of the communication receiving terminal not appearing for a first time, determining the data message as the second data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 5, Xu further discloses
wherein the performing the cryptography calculation on the data message and generating the first verification value comprises: in response to that the communication protection method is applied to the first transmission node, performing cryptography calculation on information of the communication initiating terminal and/or the first transmission node by using a key of the first transmission node, and generating the first verification value, or performing cryptography calculation on information of the communication initiating terminal and/or the first transmission node by using a key of the communication initiating terminal, and generating the first verification value; or in response to that the communication protection method is applied to the communication initiating terminal, performing cryptography calculation on the information of the communication initiating terminal by using the key of the communication initiating terminal, and generating the first verification value [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 6, Xu further discloses
wherein after the adding the first verification value to the data message, the communication protection method further comprises: in response to that the communication protection method is applied to the first transmission node, performing authenticity inspection on the communication initiating terminal, wherein the authenticity inspection comprises one or more of following combinations: inspection based on access control, inspection based on a verification code, inspection based on cryptography, and inspection based on a token [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 7, Xu further discloses
wherein after the transmitting the data message to the communication receiving terminal, the communication protection method further comprises: receiving a response message returned from the communication receiving terminal, wherein the response message carries the authorization verification information; and storing the authorization verification information [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 8, Xu further discloses
wherein the communication protection method is applied to the first transmission node or the second transmission node or the communication receiving terminal, and the performing the strong verification on the data message comprises: verifying the first verification value carried by the data message; generating verification information for the data message, and adding the verification information to the data message; and the performing the weak verification on the data message comprises: verifying the authorization verification information carried by the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 9, Xu further discloses
wherein the verifying the first verification value carried by the data message comprises: in response to that the communication protection method is applied to the first transmission node, performing first verification on the first verification value by using the key of the communication initiating terminal and the information of the communication initiating terminal; or in response to that the communication protection method is applied to the second transmission node, performing first verification on the first verification value by using the key of the first transmission node and the information of the communication initiating terminal and/or the first transmission node, or performing first verification on the first verification value by using the key of the communication initiating terminal and the information of the communication initiating terminal and/or the first transmission node [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 10, Xu further discloses
wherein the verifying the first verification value carried by the data message comprises: in response to that the communication protection method is applied to the communication receiving terminal, performing first verification on the first verification value by using the key of the first transmission node and the information of the communication initiating terminal and/or the first transmission node, or performing first verification on the first verification value by using the key of the communication initiating terminal and the information of the communication initiating terminal and/or the first transmission node [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 11, Xu further discloses
wherein the generating the verification information for the data message comprises: in response to that the communication protection method is applied to the second transmission node, and in response to that the data message carries an IP of the communication receiving terminal appearing for a first time, generating the verification information according to an IP of the first transmission node and the IP of the communication receiving terminal; in response to that the data message carries an IP of the communication receiving terminal appearing for a first time and an IP of the communication initiating terminal appearing for a first time, generating the verification information according to the IP of the communication initiating terminal and the IP of the communication receiving terminal; or in response to that the communication protection method is applied to the first transmission node, generating the verification information according to the IP of the communication initiating terminal and the IP of the communication receiving terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 12, Xu further discloses
wherein the generating the verification information for the data message comprises: in response to that the communication protection method is applied to the communication receiving terminal, generating the verification information according to the IP of the first transmission node and the IP of the communication receiving terminal, or generating the verification information according to the IP of the communication initiating terminal and the IP of the communication receiving terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 13, Xu further discloses
wherein the verifying the authorization verification information carried by the data message comprises: in response to that the communication protection method is applied to the second transmission node, and in response to that the data message carries the IP of the communication receiving terminal not appearing for a first time, verifying the authorization verification information carried by the data message according to the IP of the first transmission node and the IP of the communication receiving terminal; in response to that the data message carries the IP of the communication receiving terminal not appearing for a first time and the IP of the communication initiating terminal not appearing for a first time, verifying the authorization verification information carried by the data message according to the IP of the communication initiating terminal and the IP of the communication receiving terminal; or in response to that the communication protection method is applied to the first transmission node, verifying the authorization verification information carried by the data message according to the IP of the communication initiating terminal and the IP of the communication receiving terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 14, Xu further discloses
wherein the verifying the authorization verification information carried by the data message comprises: in response to that the communication protection method is applied to the communication receiving terminal, verifying the authorization verification information carried by the data message according to the IP of the first transmission node and the IP of the communication receiving terminal, or verifying the authorization verification information carried by the data message according to the IP of the communication initiating terminal and the IP of the communication receiving terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 15, Xu further discloses
wherein after the performing the strong verification on the data message, the communication protection method further comprises: screening the verification information according to a preset authorization standard to obtain the authorization verification information, wherein the authorization verification information and the response message of the communication initiating terminal are sent to the communication initiating terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 16, Xu further discloses
wherein in response to that the data message is not a non-primary data message sent to the communication receiving terminal and the security of the data message is poor, the data message is the first data message; in response to that the data message is a primary data message sent to the communication receiving terminal and the security of the data message is high, the data message is the second data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 17, Xu further discloses
a communication initiating terminal, a communication receiving terminal, a first transmission node and at least one second transmission node [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; wherein the first transmission node is configured to execute a communication protection method comprising: determining a type of a data message to be sent, wherein the type of the data message comprises a first data message and a second data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; the first data message is a primary data message sent to a communication receiving terminal, and the second data message is a non-primary data message sent to the communication receiving terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; in response to that the data message is the first data message, performing strong verification on the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; in response to that the data message is the second data message, performing weak verification on the data message, wherein the strong verification is a verification with security higher than the weak verification [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; in response to that verification passes, transmitting the data message to the communication receiving terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6], wherein the performing the strong verification on the data message comprises: performing cryptography calculation on the data message and generating a first verification value [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6], and adding the first verification value to the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; and the performing the weak verification on the data message comprises: adding stored authorization verification information to the data message according to Internet Protocol, IP, information carried by the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; and the second transmission node and the communication receiving terminal are configured to execute the communication protection method [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6], wherein the performing the strong verification on the data message further comprises: verifying the first verification value carried by the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; generating verification information for the data message, and adding the verification information to the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; and the performing the weak verification on the data message further comprises: verifying the authorization verification information carried by the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Regarding claim 18, Xu further discloses
a communication initiating terminal, a communication receiving terminal, and a first transmission node [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; wherein the communication initiating terminal is configured to execute a communication protection method comprising: determining a type of a data message to be sent, wherein the type of the data message comprises a first data message and a second data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; the first data message is a primary data message sent to a communication receiving terminal, and the second data message is a non-primary data message sent to the communication receiving terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; in response to that the data message is the first data message, performing strong verification on the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; in response to that the data message is the second data message, performing weak verification on the data message, wherein the strong verification is a verification with security higher than the weak verification [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; in response to that verification passes, transmitting the data message to the communication receiving terminal [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6], wherein the performing the strong verification on the data message comprises: performing cryptography calculation on the data message and generating a first verification value, and adding the first verification value to the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; and the performing the weak verification on the data message comprises: adding stored authorization verification information to the data message according to Internet Protocol, IP, information carried by the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; and the first transmission node and the communication receiving terminal are configured to execute the communication protection method [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6], wherein the performing the strong verification on the data message further comprises: verifying the first verification value carried by the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; generating verification information for the data message, and adding the verification information to the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6]; and the performing the weak verification on the data message further comprises: verifying the authorization verification information carried by the data message [Xu, paragraph 40, 54, 72-73, 200-206, figures 1, 6].
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to WILLIAM J GOODCHILD whose telephone number is (571)270-1589. The examiner can normally be reached M-F 8am-4:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeff Pwu can be reached at 571-272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/William J. Goodchild/Primary Examiner, Art Unit 2433