DETAILED ACTION
Notice of Pre-AIA or AIA Status
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
2. Claims 1-21 are pending on this application. Claims 1 and 14-15 are in independent forms. Claims 1, 3-4, 8, and 14-15 has been amended. Claim 13 has been canceled.
Priority
3. Foreign priority has been claimed to CN application # 202110552404.1 filed on 05/20/2021, CN application # 202210855758.8 filed on 07/21/2022.
Information Disclosure Statement
4. The information disclosure statements (IDS's) submitted on 01/22/2025 is in compliance with provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Drawings
5. The drawings filed on 01/17/2025 are accepted by the examiner.
Claim Rejections - 35 USC § 112
6. The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
7. Claim 16 recites : “A chip, coupled to a memory and is configured to execute a computer program stored in the memory to implement the method according to claim1.”
Claim 1 recites: “An implementation method for a security device, comprising:
waiting….
determining….
parsing….
generating….
writing….
Claim 16 is rejected as the claim is vague and indefinite. When claim 1 is rejoined with claim 16, the whole claim creates any antecedent basis issue. Appropriate correction is necessary.
Claim Rejections - 35 USC § 103
8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
9. Claims 1-4, 6, 14-19, and 21 are rejected under 35 U.S.C. 103 as being unpatentable over Chen WO Application No. 2020048287 (hereinafter Chen) in view of Chen WO Application No. 2020228451 (hereinafter Chen2) in further view of Han et al. CN Application No. 112953970 (hereinafter Han) in further view of Lu et al. CN Application No. 103729588 (hereinafter Lu).
Regarding claim 1, Chen discloses an implementation method for a security device, comprising:
“step 1, waiting, by the security device, for receiving an instruction sent by a client” (see Chen page 3, lines 43-45, after the user terminal receives the registration request message received by the user terminal safety locally performing biometric identification binding key using authority), then the user terminal sends instruction to the authenticator element fingerprint mouse, requiring the user to perform fingerprint matching verification, generating two pairs of secret keys by the fingerprint mouse; respectively is the FIDO key (user public key and user private key pair) and PKI key (certificate public key and certificate private key));
“step 3, parsing, by the security device, the preset FIDO instruction to obtain a preset parameter, obtaining a functional instruction according to the preset parameter, determining a type of the functional instruction, and performing step 4 when the functional instruction is a certificate request generation instruction, or performing step 5 when the function instruction is a writing certificate object instruction” (see Chen page 5, lines 24-27, page 6, lines 1-18, Step S2120: The server parses the password verification result in the Signature in the second FIDO authentication response instruction. If the password verification result indicates that the verification is passed, the server obtains the access right of the smart card security device, and then allows access to the smart card security device. if the smart card security device supports a predetermined extended function, it can be set by including a predetermined code in the KeyHandle or X509 certificate. For example, assuming that it is set by KeyHandle, the KeyHandle may include an encoding in the format Flag1 + Flag2 + UserKey. Step S340: The server determines whether the smart card security device supports the predetermined extended function according to the FIDO registration response instruction. If not, the access permission of the smart card security device fails, and step S350 is performed, and if yes, step S360 is performed. Step S350: Continue to directly send the KeyHandle (Flag1 + Flag2 + UserKey) returned during registration to the smart card security device according to the FIDO specification through the FIDO authentication request instruction, so that the smart card security device internally verifies the correctness of the UserKey, thereby realizing the standard process of FIDO. Step S360: Generate a first FIDO authentication request instruction according to the password verification service request. The KeyHandle of the first FIDO authentication request instruction includes a random number acquisition instruction of a predetermined protocol encapsulated in a predetermined format, and sends the first FIDO authentication request instruction to the client terminal. A FIDO authentication request instruction. The client terminal receives the first FIDO authentication request instruction);
“step 2, determining whether the received instruction is a preset fast identity online (FIDO) instruction when a first interface of the security device receives the instruction, based on that the received instruction is the preset FIDO instruction, performing step 3, based on that the received instruction is not the preset FIDO instruction, performing corresponding operation of the instruction and performing step 1, (see Chen page 4, lines 18-32, Step S240: The server determines whether the smart card security device supports the predetermined extended function according to the FIDO registration response instruction. If not, the access permission of the smart card security device fails, and step S250 is performed, and if so, step S260 is performed. Step S250: If the smart card security device supports the FIDO specification, according to the FIDO specification, directly send the KeyHandle (Flag1 + Flag2 + UserKey) returned during registration to the smart card security device through the FIDO authentication request instruction, so that the smart card security device internally verifies that the UserKey is correct To achieve the standard process of FIDO. If the smart card security device does not support the FIDO specification, the access fails. Step S260: Generate a first FIDO authentication request instruction according to the password verification service request. The KeyHandle of the first FIDO authentication request instruction includes a random number acquisition instruction of a predetermined protocol encapsulated in a predetermined format, and sends the first FIDO authentication request instruction to the client terminal. A FIDO authentication request instruction. The client terminal receives the first FIDO authentication request instruction);
Chen does not explicitly discloses wherein the first interface is a fast identity online human interface device (FIDO HID) interface.
However, in analogues art, Chen2 discloses wherein the first interface is a fast identity online human interface device (FIDO HID) interface (see Chen2 page 4, lines 6-9, After receiving the response data from the FIDO smart card, the online fast identity verification device returns the data format of FIDO HID to the terminal, completing a request and response business operation process, and realizing the complete interaction process between the FIDO smart card and the terminal).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Chen2 into the system of Chen to include an online fast identity verification device can recognize the FIDO HID data protocol format and analyze the first FIDO application request instruction (see Chen2 page 3 lines 11-12).
Chen in view of Chen2 does not explicitly discloses step 4, generating, by the security device, a key pair and storing the key pair in a storage file, signing user input information in the certificate request generation instruction and a public key of the key pair with a private key of the key pair to generate a signature value, generating a response to the certificate request generation instruction according to the signature value, the public key of the key pair and the user input information, generating response data according to the response to the certificate request generation instruction, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1.
However, in analogues art, Han discloses step 4, generating, by the security device, a key pair and storing the key pair in a storage file, signing user input information in the certificate request generation instruction and a public key of the key pair with a private key of the key pair to generate a signature value, generating a response to the certificate request generation instruction according to the signature value, the public key of the key pair and the user input information, generating response data according to the response to the certificate request generation instruction, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1 (see Han page 8 line 35-page 9, line 13, after the user terminal receives the registration request message received by the user terminal safety locally performing biometric identification binding key using authority), then the user terminal sends instruction to the authenticator element fingerprint mouse, requiring the user to perform fingerprint matching verification, generating two pairs of secret keys by the fingerprint mouse; respectively is the FIDO key (user public key and user private key pair) and PKI key (certificate public key and certificate private key). the user private key and certificate private key safety stored in the local (safety mouse), the user public key and binding relation, certificate application information and so on using the user private key signature, the uniform authentication protocol generating registration response message is sent to the server end; the server end receives the registration response message, the FIDO SERVER for verification, the FIDO SERVER after verification sends the certificate application information (P10 format) to the CA digital certificate registration system. The use of the certificate is in accordance with the national financial related policy, transaction to the user, transfer, login provides professional, safety, shortcut guarantee. the CA digital certificate registration system after receiving the certificate application information, issuing the corresponding user digital certificate, after issuing the user digital certificate is sent to the server end, finishing the digital certificate distribution).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Han into the system of Chen and Chen2 for the authenticator element generates user public and private key, at the same time, the authenticator element generates certificate public and private key, user private key and certificate private key stored in the authenticator element (see Han page 3 lines 14-17).
Chen in view of Chen2 in further view of Han does not explicitly discloses step 5, writing, by the security device, certificate data in the writing certificate object instruction into the storage file, constituting response data according to a successful status code, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1.
However, in analogues art, Lu discloses step 5, writing, by the security device, certificate data in the writing certificate object instruction into the storage file, constituting response data according to a successful status code, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1 (see Lu pars. 0085-0089, whether there is the record file corresponding to the file name based on the file name whether the current application, if so, executing the second step, or else generating writing recording response message including the status code, the value SW1SW2 preferably, in this step is the eighth preset value, for example the eighth preset value is 0x6A93. judging whether the offset exceeds the size of the recording file, if so, generating a written record of the state code response message, or determining a specified address in record document, the record data to be written is written in the designated address. Preferably, the value SW1SW2 of this step is the ninth preset value, for example the ninth preset value is 0x6B00).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Lu into the system of Chen, Chen2, and Han for a file name under the present application find a record file according to offset determines a write address in record document, the record data to be written is written in the write address (see Lu par. 0082).
Regarding claims 2 and 17, Chen in view of Chen2 in further view of Han in further view of Lu discloses the method according to claim 1, the security device according to claim 14,
Lu further discloses wherein the storage file is a container file, and the container file has a corresponding container identifier (see Lu par. 0123, the signature instruction comprises application ID and the container ID designated container under the current application is determined, according to the key specified in the container file structure is a file ID and record number).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Lu into the system of Chen, Chen2, and Han for a file name under the present application find a record file according to offset determines a write address in record document, the record data to be written is written in the write address (see Lu par. 0082).
Regarding claim 3, Chen in view of Chen2 in further view of Han in further view of Lu discloses the method according to claim 2,
Lu further discloses wherein in the step 4, the generating, by the security device, the key pair and storing the key pair in the storage file comprises: generating, by the security device, the key pair and storing the key pair in the container file corresponding to the container identifier in the certificate request generation instruction (see Lu par. 0008, when the device judges the type of the instruction to generate a key instruction, judging whether the pre-set memory area storing a signature pre-processing result, firstly removing the pre-set memory area in the signature pre-processing result and executing the generating key pair; otherwise, directly executing the generating key pair; the generating key included in the operation of the command according to the key-generating application identification and container identification confirming the appointed container under current application included in instruction generated according to the key of the key information in the designated container creating a private file structure); wherein in the step 5, the writing, by the security device, the certificate data in the writing certificate object instruction into the storage file comprises: writing, by the security device, the certificate data in the writing certificate object instruction into the container file corresponding to the container identifier in the writing certificate object instruction (see Lu par. 0013, when judging the type of the instruction to write recording instruction device, recording in the write instruction comprises application identification determining current application; recording in the write instruction includes the file name of one recording file is found under the present application, recording in the write instruction comprises the offset of the write record command contained in the recording data to be written into the corresponding address in the said record file, return writing recording response message to the upper computer).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Lu into the system of Chen, Chen2, and Han for a file name under the present application find a record file according to offset determines a write address in record document, the record data to be written is written in the write address (see Lu par. 0082).
Regarding claims 4 and 19, Chen in view of Chen2 in further view of Han in further view of Lu discloses the method according to claim 2, the security device according to claim 17,
Lu further discloses wherein the performing step 4 when the functional instruction is the certificate request generation instruction comprises: determining, by the security device, whether there is the container file corresponding to the container identifier in the certificate request generation instruction, based on that there is the container file corresponding to the container identifier in the certificate request generation instruction, performing step 4, based on that there is not the container file corresponding to the container identifier in the certificate request generation instruction, creating, by the security device, the container file corresponding to the container identifier in the certificate request generation instruction and performing step 4 (see Lu pars. 0025-0026, when device judges the type of the command is opening the container instruction contained in said open container instruction application identification to determine the current application, in the open container instruction comprises the container name open current application to the container name corresponding to the specified container, returning open container response message to the upper computer, when the device judges the type of the instruction to generate a key instruction, judging whether the pre-set memory area storing a signature pre-processing result, firstly removing the pre-set memory area in the signature pre-processing result and executing the generating key pair; otherwise, directly executing the generating key pair).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Lu into the system of Chen, Chen2, and Han for a file name under the present application find a record file according to offset determines a write address in record document, the record data to be written is written in the write address (see Lu par. 0082).
Regarding claims 6 and 21, Chen in view of Chen2 in further view of Han in further view of Lu discloses the method according to claim 2,
Lu further discloses wherein step 2 further comprises: when a second interface of the security device receives the instruction and a type of the received instruction is a reading certificate instruction, obtaining, by the security device, certificate data from a container file corresponding to the reading certificate instruction, returning the certificate data to the client, and performing step 1 (see Lu pars. 0130-0131, finding a record file according to the file ID, can read one record data in the record file according to the record number. if not finding the application on the device according to the application ID, generating the signature response message preferably includes a state code, the value of the status code SW1SW2 is a sixth predetermined value, such as the sixth preset value is 6A88. if the container ID in the current application does not find the specified container, generating a signature response message preferably includes a state code, the value of the status code SW1SW2 is eleventh, such as the eleventh preset value is 6A94, if the obtained key from the specified container).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Lu into the system of Chen, Chen2, and Han for a file name under the present application find a record file according to offset determines a write address in record document, the record data to be written is written in the write address (see Lu par. 0082).
Regarding claim 14, Chen discloses a security device, comprising: at least one processor (Fig. 6, processor 200), a memory (Fig. 6, memory 100) and instructions stored in the memory and executable by the at least one processor, the at least one processor executes the instructions to cause the processor to execute steps of:
“step 1, waiting for receiving an instruction sent by a client” (see Chen page 3, lines 43-45, after the user terminal receives the registration request message received by the user terminal safety locally performing biometric identification binding key using authority), then the user terminal sends instruction to the authenticator element fingerprint mouse, requiring the user to perform fingerprint matching verification, generating two pairs of secret keys by the fingerprint mouse; respectively is the FIDO key (user public key and user private key pair) and PKI key (certificate public key and certificate private key));
“step 3, parsing the preset FIDO instruction to obtain a preset parameter, obtaining a functional instruction according to the preset parameter, determining a type of the functional instruction, and performing step 4 when the functional instruction is a certificate request generation instruction, or performing step 5 when the function instruction is a writing certificate object instruction” (see Chen page 5, lines 24-27, page 6, lines 1-18, Step S2120: The server parses the password verification result in the Signature in the second FIDO authentication response instruction. If the password verification result indicates that the verification is passed, the server obtains the access right of the smart card security device, and then allows access to the smart card security device. if the smart card security device supports a predetermined extended function, it can be set by including a predetermined code in the KeyHandle or X509 certificate. For example, assuming that it is set by KeyHandle, the KeyHandle may include an encoding in the format Flag1 + Flag2 + UserKey. Step S340: The server determines whether the smart card security device supports the predetermined extended function according to the FIDO registration response instruction. If not, the access permission of the smart card security device fails, and step S350 is performed, and if yes, step S360 is performed. Step S350: Continue to directly send the KeyHandle (Flag1 + Flag2 + UserKey) returned during registration to the smart card security device according to the FIDO specification through the FIDO authentication request instruction, so that the smart card security device internally verifies the correctness of the UserKey, thereby realizing the standard process of FIDO. Step S360: Generate a first FIDO authentication request instruction according to the password verification service request. The KeyHandle of the first FIDO authentication request instruction includes a random number acquisition instruction of a predetermined protocol encapsulated in a predetermined format, and sends the first FIDO authentication request instruction to the client terminal. A FIDO authentication request instruction. The client terminal receives the first FIDO authentication request instruction);
“step 2, determining whether the received instruction is a preset fast identity online (FIDO) instruction when a first interface of the security device receives the instruction, based on that the received instruction is the preset FIDO instruction, performing step 3, based on that the received instruction is not the preset FIDO instruction, performing corresponding operation of the instruction and performing step 1, (see Chen page 4, lines 18-32, Step S240: The server determines whether the smart card security device supports the predetermined extended function according to the FIDO registration response instruction. If not, the access permission of the smart card security device fails, and step S250 is performed, and if so, step S260 is performed. Step S250: If the smart card security device supports the FIDO specification, according to the FIDO specification, directly send the KeyHandle (Flag1 + Flag2 + UserKey) returned during registration to the smart card security device through the FIDO authentication request instruction, so that the smart card security device internally verifies that the UserKey is correct To achieve the standard process of FIDO. If the smart card security device does not support the FIDO specification, the access fails. Step S260: Generate a first FIDO authentication request instruction according to the password verification service request. The KeyHandle of the first FIDO authentication request instruction includes a random number acquisition instruction of a predetermined protocol encapsulated in a predetermined format, and sends the first FIDO authentication request instruction to the client terminal. A FIDO authentication request instruction. The client terminal receives the first FIDO authentication request instruction);
Chen does not explicitly discloses wherein the first interface is a fast identity online human interface device (FIDO HID) interface.
However, in analogues art, Chen2 discloses wherein the first interface is a fast identity online human interface device (FIDO HID) interface (see Chen2 page 4, lines 6-9, After receiving the response data from the FIDO smart card, the online fast identity verification device returns the data format of FIDO HID to the terminal, completing a request and response business operation process, and realizing the complete interaction process between the FIDO smart card and the terminal).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Chen2 into the system of Chen to include an online fast identity verification device can recognize the FIDO HID data protocol format and analyze the first FIDO application request instruction (see Chen2 page 3 lines 11-12).
Chen in view of Chen2 does not explicitly discloses step 4, generating a key pair and storing the key pair in a storage file, signing user input information in the certificate request generation instruction and a public key of the key pair with a private key of the key pair to generate a signature value, generating a response to the certificate request generation instruction according to the signature value, the public key of the key pair and the user input information, generating response data according to the response to the certificate request generation instruction, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1.
However, in analogues art, Han discloses step 4, generating a key pair and storing the key pair in a storage file, signing user input information in the certificate request generation instruction and a public key of the key pair with a private key of the key pair to generate a signature value, generating a response to the certificate request generation instruction according to the signature value, the public key of the key pair and the user input information, generating response data according to the response to the certificate request generation instruction, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1 (see Han page 8 line 35-page 9, line 13, after the user terminal receives the registration request message received by the user terminal safety locally performing biometric identification binding key using authority), then the user terminal sends instruction to the authenticator element fingerprint mouse, requiring the user to perform fingerprint matching verification, generating two pairs of secret keys by the fingerprint mouse; respectively is the FIDO key (user public key and user private key pair) and PKI key (certificate public key and certificate private key). the user private key and certificate private key safety stored in the local (safety mouse), the user public key and binding relation, certificate application information and so on using the user private key signature, the uniform authentication protocol generating registration response message is sent to the server end; the server end receives the registration response message, the FIDO SERVER for verification, the FIDO SERVER after verification sends the certificate application information (P10 format) to the CA digital certificate registration system. The use of the certificate is in accordance with the national financial related policy, transaction to the user, transfer, login provides professional, safety, shortcut guarantee. the CA digital certificate registration system after receiving the certificate application information, issuing the corresponding user digital certificate, after issuing the user digital certificate is sent to the server end, finishing the digital certificate distribution).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Han into the system of Chen and Chen2 for the authenticator element generates user public and private key, at the same time, the authenticator element generates certificate public and private key, user private key and certificate private key stored in the authenticator element (see Han page 3 lines 14-17).
Chen in view of Chen2 in further view of Han does not explicitly discloses step 5, writing certificate data in the writing certificate object instruction into the storage file, constituting response data according to a successful status code, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1.
However, in analogues art, Lu discloses step 5, writing certificate data in the writing certificate object instruction into the storage file, constituting response data according to a successful status code, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1 (see Lu pars. 0085-0089, whether there is the record file corresponding to the file name based on the file name whether the current application, if so, executing the second step, or else generating writing recording response message including the status code, the value SW1SW2 preferably, in this step is the eighth preset value, for example the eighth preset value is 0x6A93. judging whether the offset exceeds the size of the recording file, if so, generating a written record of the state code response message, or determining a specified address in record document, the record data to be written is written in the designated address. Preferably, the value SW1SW2 of this step is the ninth preset value, for example the ninth preset value is 0x6B00).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Lu into the system of Chen, Chen2, and Han for a file name under the present application find a record file according to offset determines a write address in record document, the record data to be written is written in the write address (see Lu par. 0082).
Regarding claim 15, Chen discloses a non-transitory computer-readable storage medium, comprises a computer program therein, when the computer program runs on a computer, the processor executes steps of:
“step 1, waiting for receiving an instruction sent by a client” (see Chen page 3, lines 43-45, after the user terminal receives the registration request message received by the user terminal safety locally performing biometric identification binding key using authority), then the user terminal sends instruction to the authenticator element fingerprint mouse, requiring the user to perform fingerprint matching verification, generating two pairs of secret keys by the fingerprint mouse; respectively is the FIDO key (user public key and user private key pair) and PKI key (certificate public key and certificate private key));
“step 3, parsing the preset FIDO instruction to obtain a preset parameter, obtaining a functional instruction according to the preset parameter, determining a type of the functional instruction, and performing step 4 when the functional instruction is a certificate request generation instruction, or performing step 5 when the function instruction is a writing certificate object instruction” (see Chen page 5, lines 24-27, page 6, lines 1-18, Step S2120: The server parses the password verification result in the Signature in the second FIDO authentication response instruction. If the password verification result indicates that the verification is passed, the server obtains the access right of the smart card security device, and then allows access to the smart card security device. if the smart card security device supports a predetermined extended function, it can be set by including a predetermined code in the KeyHandle or X509 certificate. For example, assuming that it is set by KeyHandle, the KeyHandle may include an encoding in the format Flag1 + Flag2 + UserKey. Step S340: The server determines whether the smart card security device supports the predetermined extended function according to the FIDO registration response instruction. If not, the access permission of the smart card security device fails, and step S350 is performed, and if yes, step S360 is performed. Step S350: Continue to directly send the KeyHandle (Flag1 + Flag2 + UserKey) returned during registration to the smart card security device according to the FIDO specification through the FIDO authentication request instruction, so that the smart card security device internally verifies the correctness of the UserKey, thereby realizing the standard process of FIDO. Step S360: Generate a first FIDO authentication request instruction according to the password verification service request. The KeyHandle of the first FIDO authentication request instruction includes a random number acquisition instruction of a predetermined protocol encapsulated in a predetermined format, and sends the first FIDO authentication request instruction to the client terminal. A FIDO authentication request instruction. The client terminal receives the first FIDO authentication request instruction);
“step 2, determining whether the received instruction is a preset fast identity online (FIDO) instruction when a first interface of the security device receives the instruction, based on that the received instruction is the preset FIDO instruction, performing step 3, based on that the received instruction is not the preset FIDO instruction, performing corresponding operation of the instruction and performing step 1, (see Chen page 4, lines 18-32, Step S240: The server determines whether the smart card security device supports the predetermined extended function according to the FIDO registration response instruction. If not, the access permission of the smart card security device fails, and step S250 is performed, and if so, step S260 is performed. Step S250: If the smart card security device supports the FIDO specification, according to the FIDO specification, directly send the KeyHandle (Flag1 + Flag2 + UserKey) returned during registration to the smart card security device through the FIDO authentication request instruction, so that the smart card security device internally verifies that the UserKey is correct To achieve the standard process of FIDO. If the smart card security device does not support the FIDO specification, the access fails. Step S260: Generate a first FIDO authentication request instruction according to the password verification service request. The KeyHandle of the first FIDO authentication request instruction includes a random number acquisition instruction of a predetermined protocol encapsulated in a predetermined format, and sends the first FIDO authentication request instruction to the client terminal. A FIDO authentication request instruction. The client terminal receives the first FIDO authentication request instruction);
Chen does not explicitly discloses wherein the first interface is a fast identity online human interface device (FIDO HID) interface.
However, in analogues art, Chen2 discloses wherein the first interface is a fast identity online human interface device (FIDO HID) interface (see Chen2 page 4, lines 6-9, After receiving the response data from the FIDO smart card, the online fast identity verification device returns the data format of FIDO HID to the terminal, completing a request and response business operation process, and realizing the complete interaction process between the FIDO smart card and the terminal).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Chen2 into the system of Chen to include an online fast identity verification device can recognize the FIDO HID data protocol format and analyze the first FIDO application request instruction (see Chen2 page 3 lines 11-12).
Chen in view of Chen2 does not explicitly discloses step 4, generating a key pair and storing the key pair in a storage file, signing user input information in the certificate request generation instruction and a public key of the key pair with a private key of the key pair to generate a signature value, generating a response to the certificate request generation instruction according to the signature value, the public key of the key pair and the user input information, generating response data according to the response to the certificate request generation instruction, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1.
However, in analogues art, Han discloses step 4, generating a key pair and storing the key pair in a storage file, signing user input information in the certificate request generation instruction and a public key of the key pair with a private key of the key pair to generate a signature value, generating a response to the certificate request generation instruction according to the signature value, the public key of the key pair and the user input information, generating response data according to the response to the certificate request generation instruction, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1 (see Han page 8 line 35-page 9, line 13, after the user terminal receives the registration request message received by the user terminal safety locally performing biometric identification binding key using authority), then the user terminal sends instruction to the authenticator element fingerprint mouse, requiring the user to perform fingerprint matching verification, generating two pairs of secret keys by the fingerprint mouse; respectively is the FIDO key (user public key and user private key pair) and PKI key (certificate public key and certificate private key). the user private key and certificate private key safety stored in the local (safety mouse), the user public key and binding relation, certificate application information and so on using the user private key signature, the uniform authentication protocol generating registration response message is sent to the server end; the server end receives the registration response message, the FIDO SERVER for verification, the FIDO SERVER after verification sends the certificate application information (P10 format) to the CA digital certificate registration system. The use of the certificate is in accordance with the national financial related policy, transaction to the user, transfer, login provides professional, safety, shortcut guarantee. the CA digital certificate registration system after receiving the certificate application information, issuing the corresponding user digital certificate, after issuing the user digital certificate is sent to the server end, finishing the digital certificate distribution).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Han into the system of Chen and Chen2 for the authenticator element generates user public and private key, at the same time, the authenticator element generates certificate public and private key, user private key and certificate private key stored in the authenticator element (see Han page 3 lines 14-17).
Chen in view of Chen2 in further view of Han does not explicitly discloses step 5, writing certificate data in the writing certificate object instruction into the storage file, constituting response data according to a successful status code, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1.
However, in analogues art, Lu discloses step 5, writing certificate data in the writing certificate object instruction into the storage file, constituting response data according to a successful status code, generating a response to the preset FIDO instruction according to the response data, sending the response to the preset FIDO instruction to the client, and performing step 1 (see Lu pars. 0085-0089, whether there is the record file corresponding to the file name based on the file name whether the current application, if so, executing the second step, or else generating writing recording response message including the status code, the value SW1SW2 preferably, in this step is the eighth preset value, for example the eighth preset value is 0x6A93. judging whether the offset exceeds the size of the recording file, if so, generating a written record of the state code response message, or determining a specified address in record document, the record data to be written is written in the designated address. Preferably, the value SW1SW2 of this step is the ninth preset value, for example the ninth preset value is 0x6B00).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Lu into the system of Chen, Chen2, and Han for a file name under the present application find a record file according to offset determines a write address in record document, the record data to be written is written in the write address (see Lu par. 0082).
Regarding claim 16, a chip, coupled to a memory and is configured to execute a computer program stored in the memory to implement the method according to claim1.
(claim 16 is rejected for the same reasons as claim 1).
Regarding claim 18, Chen in view of Chen2 in further view of Han in further view of Lu discloses the security device according to claim 14,
Lu further discloses the security device according to claim 17, wherein the at least one processor executes the instructions to cause the processor to execute steps of generating the key pair and store the key pair in the container file corresponding to the container identifier in the certificate request generation instruction; or writing the certificate data in the writing certificate object instruction into the container file corresponding to the container identifier in the writing certificate object instruction (see Lu par. 0008, when the device judges the type of the instruction to generate a key instruction, judging whether the pre-set memory area storing a signature pre-processing result, firstly removing the pre-set memory area in the signature pre-processing result and executing the generating key pair; otherwise, directly executing the generating key pair; the generating key included in the operation of the command according to the key-generating application identification and container identification confirming the appointed container under current application included in instruction generated according to the key of the key information in the designated container creating a private file structure).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to incorporate the teachings of Lu into the system of Chen, Chen2, and Han for a file name under the present application find a record file according to offset determines a write address in record document, the record data to be written is written in the write address (see Lu par. 0082).
Allowable Subject Matter
10. Claims 5, 7-12, and 20 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
11. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Rule et al. (US 2020/0104841 A1): discloses Systems and methods for authentication may include an authenticator. The authenticator may include a processor and a memory. The processor may be configured to: receive one or more challenges; generate a first instruction, the first instruction including a request to retrieve a first Fast Identity Online (FIDO) key; transmit the first instruction; receive the first FIDO key; sign the one or more challenges using the first FIDO key; and transmit one or more signed challenges for validation using a second FIDO key.
Osborn et al. (US 2020/0104841 A1): discloses systems and methods for data transmission between a contactless card and a client device in support of a FIDO authentication are provided. In an embodiment, upon receipt of a challenge issued by a server in connection with a pending transaction, the contactless card may authorize the client device to utilize a FIDO private key to respond to the challenge. If the response to the challenge is successful, the FIDO authentication may proceed and the transaction may be completed.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMUEL AMBAYE whose telephone number is (571)270-7635. The examiner can normally be reached M-F 9:00 AM - 6:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached at (571) 272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SAMUEL AMBAYE/Examiner, Art Unit 2433
/JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433