DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In response to the restriction requirement, the Applicant has elected species 1, claims 2-11, without traverse for prosecution. Claim 1 is canceled, claims 12-20 are withdrawn from consideration, claims 2 and 21 are independent claims. Claims 2-11 and 21 have been examined and are pending in this application.
Priority
Acknowledgment is made of Applicant’s claim for priority under 35 U.S.C. 120 to Parent Application No.: 18/526,942, filed on 12/01/2023, Parent Application No.: 17/726,424, filed on 04/21/2022, Parent Application No. 16/688,848, filed on 11/19/2019.
Information Disclosure Statement
The information disclosure statements (IDS), submitted on 06/09/2026 and 04/07/2025, are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement.
Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 2-11 and 21 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 and 3-4 of U.S. Patent No. 11,334,655, claims 1-20 of U.S. Patent No.: 11,847,201. Although the claims at issue are not identical, they are not patentably distinct from each other because claim(s) 2-11 and 21 are broader than and similar in scope to the claims 1 and 3-4 of U.S. Patent No. 11,334,655 and claims 1-20 of U.S. Patent No.: 11,847,201 (see table below). If the claims in Application No. 19/025,874 are allowed, it could improperly extend the “right to exclude” for the same invention in two different Patents.
Claims 2-11 and 21 are directed to a first server and a method; said first server and method are associated with the method of U.S. Patent No. 11,334,655 and the method, server, and non-transitory computer readable medium claimed in claims 1-20 of U.S. Patent No. 11,847,201.
The subject matter claimed in the instant application is fully disclosed in U.S. Patent No. 11,334,655 and U.S. Patent No. 11,847,201 and is covered by U.S. Patent No. 11,334,655 and U.S. Patent No. 11,847,201 since U.S. Patent No. 11,334,655, U.S. Patent No. 11,847,201, and the instant application are claiming common subject matter, as follows:
Application No. 19/025,874 (Instant App.)
US Patent No. 11,334,655
Claim 2: A first server, comprising: one or more memory devices; and one or more processors coupled with the one or more memory devices and configured to cause the first server to: receive, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receive, from the device, a first key for authenticating the device; determine the first key as valid based at least in part on the first certificate; establish a first connection between the device and a first service based at least in part on determining the first key as valid; receive, from the device, a second key for authenticating the device; determine the second key as valid based at least in part on the second certificate; and establish a second connection between the device and a second service based at least in part on determining the second key as valid.
Claim 21: A method by a first server, comprising: receiving, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receiving, from the device, a first key for authenticating the device; determining the first key as valid based at least in part on the first certificate; establishing a first connection between the device and a first service based at least in part on determining the first key as valid; receiving, from the device, a second key for authenticating the device; determining the second key as valid based at least in part on the second certificate; and establishing a second connection between the device and a second service based at least in part on determining the second key as valid.
Claim 1: A method, comprising:
receiving, by a field server, a notification that a software update is sent to a device, the field server for authenticating that software of the device is secure;
setting, by the field server, a flag that indicates an association between the device and the software update in a memory based at least in part on receiving the notification;
receiving, from the device, a connection request that comprises a certificate associated with a first key for authenticating the device;
determining that the first key received from the device is invalid based at least in part on receiving the connection request;
determining the first key as valid based at least in part on the flag indicating the association; and
establishing a connection between the device and a service based at least in part on determining the first key as valid.
Claim 3: The method of claim 2, further comprising:
receiving an updated certificate associated with the device after the software of the device is updated; and
updating a second certificate associated with the device stored by the field server based at least in part on receiving the updated certificate.
Claim 4: The method of claim 3, further comprising:
processing an additional connection request from the device based at least in part on determining the first key as valid.
Application No. 19/025,874 (Instant App.)
US Patent No. 11,847,201
Claim 21: A method by a first server, comprising: receiving, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receiving, from the device, a first key for authenticating the device; determining the first key as valid based at least in part on the first certificate; establishing a first connection between the device and a first service based at least in part on determining the first key as valid; receiving, from the device, a second key for authenticating the device; determining the second key as valid based at least in part on the second certificate; and establishing a second connection between the device and a second service based at least in part on determining the second key as valid.
Claim: 9: The first server of claim 2, wherein the first version of the software and the second version of the software are associated with an append write mode of the device.
Claim 1: A method, comprising:
identifying, at a server, an update for software for a device, wherein the update includes additional information for the software;
configuring a portion of the device to operate in an append write mode based at least in part on identifying the update for the software;
transmitting, to the device, the update to the software comprising the additional information based at least in part on identifying the update for the software for the device; and
receiving, from the device, a completion message indicating that the device performed the update for the software.
Claim 8: The method of claim 1, further comprising:
transmitting, from the server to a second server, an updated certificate associated with the device based at least in part on receiving the completion message.
Claim 2: A first server, comprising: one or more memory devices; and one or more processors coupled with the one or more memory devices and configured to cause the first server to: receive, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receive, from the device, a first key for authenticating the device; determine the first key as valid based at least in part on the first certificate; establish a first connection between the device and a first service based at least in part on determining the first key as valid; receive, from the device, a second key for authenticating the device; determine the second key as valid based at least in part on the second certificate; and establish a second connection between the device and a second service based at least in part on determining the second key as valid.
Claim: 9: The first server of claim 2, wherein the first version of the software and the second version of the software are associated with an append write mode of the device.
Claim 10: A non-transitory computer-readable medium storing code, the code comprising instructions executable by a processor to:
identify, at a server, an update for software for a device, wherein the update includes additional information for the software;
configure a portion of the device to operate in an append write mode based at least in part on identifying the update for the software;
transmit, to the device, the update to the software comprising the additional information based at least in part on identifying the update for the software for the device; and
receive, from the device, a completion message indicating that the device performed the update for the software.
Claim 17: The non-transitory computer-readable medium of claim 10, wherein the instructions are further executable by the processor to:
transmit, from the server to a second server, an updated certificate associated with the device based at least in part on receiving the completion message.
Claim 2: A first server, comprising: one or more memory devices; and one or more processors coupled with the one or more memory devices and configured to cause the first server to: receive, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receive, from the device, a first key for authenticating the device; determine the first key as valid based at least in part on the first certificate; establish a first connection between the device and a first service based at least in part on determining the first key as valid; receive, from the device, a second key for authenticating the device; determine the second key as valid based at least in part on the second certificate; and establish a second connection between the device and a second service based at least in part on determining the second key as valid.
Claim: 9: The first server of claim 2, wherein the first version of the software and the second version of the software are associated with an append write mode of the device.
Claim 19: An server, comprising:
a processor;
memory coupled with the processor; and
instructions stored in the memory and executable by the processor to cause the server to:
identify an update for software for a device, wherein the update includes additional information for the software;
configure a portion of the device to operate in an append write mode based at least in part on identifying the update for the software;
transmit, to the device, the update to the software comprising the additional information based at least in part on identifying the update for the software for the device; and
receive, from the device, a completion message indicating that the device performed the update for the software.
Claim 17: The non-transitory computer-readable medium of claim 10, wherein the instructions are further executable by the processor to:
transmit, from the server to a second server, an updated certificate associated with the device based at least in part on receiving the completion message.
Claim(s) 2-11 and 21 are provisionally rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over claim(s) 2-21 of copending Application No. 18/526,942. Although the conflicting claims are not identical, they are not patentably distinct from each other because claim(s) 2-11 and 21are similar in scope to the claim(s) in copending Application No. 18/526,942 (see table below). If the claims in Application No. 19/025,874 are allowed, it could improperly extend the “right to exclude” for the same invention in two different Patents.
Claims 2-11 and 21 are directed to a method and a first server; said method and first server are associated with the method, server, and non-transitory computer readable medium claimed in claim(s) 2-21 of the copending Application No. 18/526,942.
This is a provisional obviousness-type double patenting rejection because the conflicting claims have not in fact been patented.
The subject matter claimed in the instant application is fully disclosed in the Patent Application No. 18/526,942 and is covered by Patent Application No. 18/526,942 since Patent Application No. 18/526,942 and the instant application are claiming common subject matter, as follows:
Application No. 19/025,874 (Instant App.)
Application No. 18/526,942
Claim 2: A first server, comprising: one or more memory devices; and one or more processors coupled with the one or more memory devices and configured to cause the first server to: receive, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receive, from the device, a first key for authenticating the device; determine the first key as valid based at least in part on the first certificate; establish a first connection between the device and a first service based at least in part on determining the first key as valid; receive, from the device, a second key for authenticating the device; determine the second key as valid based at least in part on the second certificate; and establish a second connection between the device and a second service based at least in part on determining the second key as valid.
Claim 2: A server, comprising: one or more memory devices; and one or more processors coupled with the one or more memory devices and configured to cause the server to: receive a notification that a software update is sent to a device; receive an updated certificate associated with the device based at least in part on the notification; update a first certificate associated with the device stored by the server based at least in part on the updated certificate; receive, from the device, a key for authenticating the device; determine the key as valid based at least in part on updating the first certificate; and establish a connection between the device and a service based at least in part on determining the key as valid.
Claim 21: A method by a first server, comprising: receiving, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receiving, from the device, a first key for authenticating the device; determining the first key as valid based at least in part on the first certificate; establishing a first connection between the device and a first service based at least in part on determining the first key as valid; receiving, from the device, a second key for authenticating the device; determining the second key as valid based at least in part on the second certificate; and establishing a second connection between the device and a second service based at least in part on determining the second key as valid.
Claim 15: A method by a server, comprising: receiving a notification that a software update is sent to a device; receiving an updated certificate associated with the device based at least in part on the notification; updating a first certificate associated with the device stored by the server based at least in part on the updated certificate; receiving, from the device, a key for authenticating the device; determining the key as valid based at least in part on updating the first certificate; and establishing a connection between the device and a service based at least in part on determining the key as valid.
Claim 2: A first server, comprising: one or more memory devices; and one or more processors coupled with the one or more memory devices and configured to cause the first server to: receive, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receive, from the device, a first key for authenticating the device; determine the first key as valid based at least in part on the first certificate; establish a first connection between the device and a first service based at least in part on determining the first key as valid; receive, from the device, a second key for authenticating the device; determine the second key as valid based at least in part on the second certificate; and establish a second connection between the device and a second service based at least in part on determining the second key as valid.
Claim 19: A non-transitory computer-readable medium storing code comprising instructions which, when executed by one or more processors of an electronic device, cause the electronic device to: receive a notification that a software update is sent to a device; receive an updated certificate associated with the device based at least in part on the notification; update a first certificate associated with the device stored by a server based at least in part on the updated certificate; receive, from the device, a key for authenticating the device; determine the key as valid based at least in part on updating the first certificate; and establish a connection between the device and a service based at least in part on determining the key as valid.
Allowable Subject Matter
Regarding Claims 2-11 and 21, Claims 2-11 and 21 are allowed over the cited prior art.
The following is an Examiner’s statement of reasons for allowance:
The closest prior art includes Ishimoto et al. (US 2019/0073212; Hereinafter “Ishimoto”), Smith et al. (US 2019/0138294; Hereinafter “Smith”), Wang et al. (US 2020/0328902; Hereinafter “Wang”), and DeBickes et al. (US 10,728,237; Hereinafter “DeBickes”).
Ishimoto describes how a digital certificate for the updating software package is received by the terminal device from the server using the communication unit, whether the updating software package is an authorized package is checked with the digital certificate, and notification informing a failure in rewriting the software package of the control device is transmitted to the server by using the communication unit, if the updating software package is determined as not to be authentic. A software rewriting program of the above-described aspect of the present invention may be configured so as to cause the computer to execute the steps further including: a reception control step of receiving a digital certificate for the updating software package from the server by using the communication unit; an authentication control step of checking whether the updating software package is an authentic package based on the digital certificate; a notification control step of transmitting notification informing a failure in rewriting the software package of the control device to the server by using the communication unit, if the updating software package is determined as not to be authentic.
Smith teaches enabling derivation and distribution of an attestation manifest for a software update image are described. In an example, these systems and methods include orchestration functions and communications, providing functionality and components for a software update process which also provides verification and attestation among multiple devices and operators. One example of software update process relevant to network deployments is known as scalable embedded device attestation (SEDA) which allows updating device software to verify whether the update has been performed correctly. In a SEDA architecture, new software comes with a code certificate. After new software has been installed on device Di, the device sends a certificate authenticated with keys in Ki to all its neighbors, which then update their reference software configuration if the verification of certificate was successful. Otherwise, devices maintain the old software configuration. To prove that software update has been performed successfully, the device can either attest itself to all its neighbors using keys or to an external verifier using its secret key. Roll-back attacks, where an adversary installs old software versions that may contain exploitable security vulnerabilities, may be detected when attesting the swarm.
Wang teaches that the digital certificate requesting device may negotiate, with the digital certificate issuing device, establishment of the secure data channel using the obtained authorization code, generate the security key, and encrypt the message using the generated data communication key in a message interaction process between the digital certificate requesting device and the digital certificate issuing device, thereby effectively improving security of data transmission, and it may be adapted to automatic application, query, update, revoking and revocation list obtaining etc. of a digital certificate under multiple different types of scenes. Meanwhile, the digital certificate issuing device, using a verification to which a public key and a private key pertain, checks whether the digital certificate requesting device has “a private key corresponding to the public key thereof” or not, thus detecting whether the public key and the private key of the digital certificate requesting device are replaced and are wrong etc. or not. The digital certificate issuing device may only interact the message with the digital certificate requesting device having the correct public key and the correct private key, thereby avoiding leakage of privacy data of the digital certificate requesting device and further ensuring security of a digital certificate management process.
DeBickes claims receiving, at an electronic device, a software update notification for a software upgrade that upgrades software on the electronic device, wherein the software update notification comprises a security requirement, and the security requirement comprises at least one of a certificate requirement or an encryption requirement for evaluating a security level of a network connection used to receive the software update; determining, by the electronic device, based on the at least one of the certificate requirement or the encryption requirement, that a network connection is secure for receiving the software update, wherein the determining that the network connection is secure comprises comparing a certificate or an encryption of the network connection with the at least one of the certificate requirement or the encryption requirement included in the software update notification; and in response to determining that the network connection is secure, downloading, by the electronic device, the software update using the network connection.
However, none of Ishimoto, Smith, Wang, and DeBickes teaches or suggests, alone or in combination, the particular combination of steps or elements as recited in the independent claim 2 and 21. For example, none of the cited prior art teaches or suggest the steps of “receive, from a second server, a first certificate and a second certificate, the first certificate for identifying modification to a first version of software associated with a device, and the second certificate for identifying modification to a second version of the software; receive, from the device, a first key for authenticating the device; determine the first key as valid based at least in part on the first certificate; establish a first connection between the device and a first service based at least in part on determining the first key as valid; receive, from the device, a second key for authenticating the device; determine the second key as valid based at least in part on the second certificate; and establish a second connection between the device and a second service based at least in part on determining the second key as valid.” As a result, the claims are allowable over the cited prior art.
Any comments considered necessary by applicant must be submitted no later than the payment of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such submissions should be clearly labeled "Comments on Statement of Reasons for Allowance."
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Nelson Giddins whose telephone number is (571) 272-7993. The examiner can normally be reached on Monday - Friday, 9:00 AM - 5:00 PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached at (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/NELSON S. GIDDINS/ Primary Examiner, Art Unit 2408