Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This communication is in response to the amendment filed on 07/21/2026.
Claims 1-20 are pending and rejected. Claims 1, 4-6, 8, 11-15, and 18-19 have been amended.
Response to Arguments
Applicants’ arguments with respect to claims 1, 8, and 15 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Further, the process of generating key/ID associated with a user request corresponds to a dynamic signature.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Wang (US 20240364523 A1) in view of Okuyama (US 20230164142 A1).
Regarding claim 1, Wang teaches a method comprising:
receiving, by a server configured to perform signature authentication on a terminal device, a
signature authentication request sent by the terminal device ([0072] The web end sends, to an application server, a key request used to request a key needed for enabling TOTP ;[0099] The authentication server receives an enabling confirmation request that is sent by a business application end and that includes a second signature, where the second signature is obtained after the business application end signs, by using a second private key in a second public-private key pair, the device information of a terminal device that the business application end is located);
determining whether the terminal device that sends the signature authentication request is a
contaminated device ([0103] The authentication server can store a blacklist, including devices with a low security level. The authentication server can identify the device model in the blacklist through searching. If the device type can be identified, it is considered that the security level of the terminal device does not satisfy the enabling need (contaminated device));
in response to determining that the terminal device that sends the signature authentication
request is a contaminated device, determining a dynamic signature parameter that needs to be used for the signature authentication ([0104] The authentication server queries the second public key in the second public-private key pair based on the obtained device model);
re-authorizing the terminal device to enable verification permissions ([0117] The authentication server obtains, based on the received enabling confirmation request, a device model of the terminal device that the business application end is located; determines, based on the obtained device model, whether a security level of the terminal device satisfies an enabling need);
notifying the terminal device to collect the dynamic signature parameter ([0123] The business application end performs token calculation based on the secretKey by using the TA application in the TEE, and provides a calculated token to a user);
receiving a value of the dynamic signature parameter that is sent by the terminal device ([0126] The application server performs token calculation based on the secretKey stored by the application server, and determines whether a calculated token is consistent with the token included in the identity verification request, where if the calculated token is consistent with the token included in the identity verification request, the identity verification is “legal”; otherwise, the identity verification is “illegal”.); and
performing a second signature authentication based on the value of the dynamic signature
parameter [0064] the authentication server receives the enabling confirmation request that is sent by the business application end and that includes the second signature, and the authentication server performs signature verification on the second signature by using the foregoing second public key).
Wang does not explicitly teach
wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises:
selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication.
Okuyama teaches
wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication ([0120] The authentication unit 205 determines whether, among the plurality of sets of feature values registered in the database, there is at least one set of feature values whose similarity to the set of matching target feature values is a predetermined value or more; [0133], fig. 2, fig. 12, the service registration request unit 303 selects the user ID and the password from the above three items of information (the personal information, the user ID, and the password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID and password and the corresponding service provider ID to the authentication server 10).
It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, select dynamic signature from database, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information.
Regarding claims 2, 9, and 16, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15, wherein Wang further teaches a service private key required for signature authentication is embedded in a trusted execution environment (TEE) of the terminal device ([0061] The second private key in the second public-private key pair can be stored in the TEE of the terminal device), and
a signature required by the signature authentication request is completed by the TEE after a
biological feature entered by a user is successfully verified ([0062] performed by the TA in the TEE of the terminal device that the business application end is located, that is, the TA signs, in the TEE by using the second private key stored in the TEE, the device information of the terminal device that the business application end is located, to obtain the second signature).
Regarding claims 3, 10, and 17, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15, wherein the determining whether the terminal device that sends the signature authentication request is a contaminated device comprises:
obtaining model information of the terminal device or version information that is carried in
the signature authentication request ([0103] the authentication server can identify the device model the blacklist through searching); and
determining that the model information of the terminal device or the version information is
in a pre-obtained blacklist, and in response, determining that the terminal device that sends the
signature authentication request is a contaminated device ([0103] The authentication server can store a blacklist, including devices with a low security level. If the device type can be identified, it is considered that the security level of the terminal device does not satisfy the enabling need).
Regarding claims 4, 11, 18, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15, wherein Okuyama further teaches the selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication comprises:
selecting, by the server from the dynamic signature parameter library by using a random selection method or a one-by-one selection method, the dynamic signature parameter that needs to be used for the signature authentication ([0133], fig. 2, fig. 12, the service registration request unit 303 selects the user ID and the password from the above three items of information (the personal information, the user ID, and the password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID and password and the corresponding service provider ID to the authentication server 10).
It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, select dynamic signature from database, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information.
Regarding claims 5, 12, and 19, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15 wherein Okuyama further teaches the dynamic signature parameter library comprises:
a fingerprint ID, a device ID, an application APP package name, a service scenario, and a user
ID ([0048] a fingerprint, [0010] first ID that uniquely determines a user in a system, [0064] a user ID, [0130] a terminal 40 may download an application provided by the service provider).
It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, a user ID, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information.
Regarding claims 6 and 13, Wang and Okuyama teach all limitations of parent claims 1 and 8, wherein Wang further teaches the dynamic signature parameter library comprises a parameter associated with a service ([0036] The application server that supports TOTP is disposed in a server that provides a corresponding business service for a business application).
Regarding claims 7, 14, and 20, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15, wherein the method further comprises:
setting a corresponding parameter sequence number for each parameter in a dynamic signature parameter library ([0008] A first TA application in a TEE of the terminal device performs the step of performing signature verification on the first signature by using a first public key in the first public-private key pair obtained in advance; and/or a second TA application in the TEE of the terminal device performs the step of performing token calculation based on the key); and
the notifying the terminal device to collect the dynamic signature parameter comprises: sending a notification message to the terminal device, wherein a first field in the notification message comprises a parameter sequence number corresponding to the dynamic signature parameter that needs to be used for the signature authentication, and a second field in the notification message indicates a length of the first field ([0009] receiving the key and a first signature sent by the application server, where the first signature is obtained after an authentication server signs the key by using a first private key in a first public-private key pair; generating a two-dimensional code by using the received key and the received first signature, and sending the two-dimensional code to a business application end; receiving a token input by a user, and adding the token to an identity verification request and sending the identity verification request to the application server; and receiving an identity verification result sent by the application server).
Regarding claim 8, Wang teaches a computer-implemented device comprising:
one or more processors ([0139] a memory and a processor); and
one or more tangible, non-transitory, machine-readable media storing one or more
instructions that ([00138] The computer-readable storage medium stores a computer program), when executed by the one or more processors, perform one or more operations
comprising:
receiving, by the computer-implemented device configured to perform signature authentication on a terminal device, a signature authentication request sent by the terminal device ([0072] The web end sends, to an application server, a key request used to request a key needed for enabling TOTP; [0099] The authentication server receives an enabling confirmation request that is sent by a business application end and that includes a second signature, where the second signature is obtained after the business application end signs, by using a second private key in a second public-private key pair, the device information of a terminal device that the business application end is located);
determining whether the terminal device that sends the signature authentication request is a
contaminated device ([0103] The authentication server can store a blacklist, including devices with a low security level. The authentication server can identify the device model in the blacklist through searching. If the device type can be identified, it is considered that the security level of the terminal device does not satisfy the enabling need (contaminated device));
in response to determining that the terminal device that sends the signature authentication
request is a contaminated device, determining a dynamic signature parameter that needs to be used for the signature authentication ([0104] The authentication server queries the second public key in the second public-private key pair based on the obtained device model);
re-authorizing the terminal device to enable verification permissions ([0117] The authentication server obtains, based on the received enabling confirmation request, a device model of the terminal device that the business application end is located; determines, based on the obtained device model, whether a security level of the terminal device satisfies an enabling need);
notifying the terminal device to collect the dynamic signature parameter ([0123] The business application end performs token calculation based on the secretKey by using the TA application in the TEE, and provides a calculated token to a user);
receiving a value of the dynamic signature parameter that is sent by the terminal device ([0126]: The application server performs token calculation based on the secretKey stored by the application server, and determines whether a calculated token is consistent with the token included in the identity verification request, where if the calculated token is consistent with the token included in the identity verification request, the identity verification is “legal”; otherwise, the identity verification is “illegal”); and
performing a second signature authentication based on the value of the dynamic signature
parameter ([0064] the authentication server receives the enabling confirmation request that is sent by the business application end and that includes the second signature, and the authentication server performs signature verification on the second signature by using the foregoing second public key).
Wang does not explicitly teach the term “dynamic signature” in the limitation “determining a dynamic signature parameter that needs to be used for the signature authentication”.
Wang does not explicitly teach
wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises:
selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication.
Okuyama teaches
wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication ([0120] The authentication unit 205 determines whether, among the plurality of sets of feature values registered in the database, there is at least one set of feature values whose similarity to the set of matching target feature values is a predetermined value or more; [0133], fig. 2, fig. 12, the service registration request unit 303 selects the user ID and the password from the above three items of information (the personal information, the user ID, and the password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID and password and the corresponding service provider ID to the authentication server 10).
It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, select dynamic signature from database, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information.
Regarding claim 15, Wang teaches a non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising ([0138] The computer-readable storage medium stores a computer program):
receiving, by a server configured to perform signature authentication on a terminal device, a
signature authentication request sent by the terminal device ([0072] The web end sends, to an application server, a key request used to request a key needed for enabling TOTP ;[0099] The authentication server receives an enabling confirmation request that is sent by a business application end and that includes a second signature, where the second signature is obtained after the business application end signs, by using a second private key in a second public-private key pair, the device information of a terminal device that the business application end is located);
determining whether the terminal device that sends the signature authentication request is a
contaminated device ([0103] The authentication server can store a blacklist, including devices with a low security level. The authentication server can identify the device model in the blacklist through searching. If the device type can be identified, it is considered that the security level of the terminal device does not satisfy the enabling need (contaminated device));
in response to determining that the terminal device that sends the signature authentication
request is a contaminated device, determining a dynamic signature parameter that needs to be used for the signature authentication ([0104] The authentication server queries the second public key in the second public-private key pair based on the obtained device model),
re-authorizing the terminal device to enable verification permissions ([0117] The authentication server obtains, based on the received enabling confirmation request, a device model of the terminal device that the business application end is located; determines, based on the obtained device model, whether a security level of the terminal device satisfies an enabling need);
notifying the terminal device to collect the dynamic signature parameter ([0123] The business application end performs token calculation based on the secretKey by using the TA application in the TEE, and provides a calculated token to a user);
receiving a value of the dynamic signature parameter that is sent by the terminal device ([0126]: The application server performs token calculation based on the secretKey stored by the application server, and determines whether a calculated token is consistent with the token included in the identity verification request, where if the calculated token is consistent with the token included in the identity verification request, the identity verification is “legal”; otherwise, the identity verification is “illegal”); and
performing a second signature authentication based on the value of the dynamic signature
parameter [0064] the authentication server receives the enabling confirmation request that is sent by the business application end and that includes the second signature, and the authentication server performs signature verification on the second signature by using the foregoing second public key).
Wang does not explicitly teach
wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises:
selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication.
Okuyama teaches
wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication ([0120] The authentication unit 205 determines whether, among the plurality of sets of feature values registered in the database, there is at least one set of feature values whose similarity to the set of matching target feature values is a predetermined value or more; [0133], fig. 2, fig. 12, the service registration request unit 303 selects the user ID and the password from the above three items of information (the personal information, the user ID, and the password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID and password and the corresponding service provider ID to the authentication server 10).
It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, select dynamic signature from database, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANH NGUYEN whose telephone number is (571)270-0657. The examiner can normally be reached M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached at 5712703037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ANH NGUYEN/Primary Examiner, Art Unit 2458