DETAILED ACTION
This action is made in response to the communication filed on February 13, 2025. This action is made non-final. Claims 1, 8 and 14 are independent claims. Claims 1-20 are pending.
Notice of Pre-AIA or AIA Status
2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
3. This application claims priority to U.S. provisional application No. 63/721,398 filed on November 15, 2024.
Claim Rejections - 35 USC § 112
4. The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
5. Claims 15-18 and 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 15 and 17 recite “the inactive user.” There is insufficient antecedent basis for this limitation; claim 14, from which each depends, recites “a user of the computing device” whose login frequency fails to meet the login threshold, but does not recite an inactive user. For purposes of examination, the inactive user is interpreted as the user whose login frequency fails to meet the login threshold. Claims 16 and 18 are rejected as depending from claim 15 and 17, respectively, and incorporating their indefiniteness.
6. Claim 18 recites modifying the login threshold “to be more lenient,” and claim 20 recites that the login threshold “is made less lenient.” These terms render the claims indefinite because the claims do not define what direction of adjustment “lenient” denotes for the recited login threshold. Claim 5 recites that the login count threshold is “increased” in response to determining that the role is a shared public computing device, while claim 20 recites that the login threshold is made “less lenient” upon determining that the role is a shared computing device. The claims never specify whether an increased threshold correspond to more or less leniency. An increased threshold may require more logins within the time period, so that more users fail to meet it, or may reflect a longer retention criterion, so that fewer users fail to meet it. It is therefore unclear whether claims 5 and 20 recite the same adjustment or opposite adjustment for substantially similar device roles, and unclear what scope “more lenient” and “less lenient” define. For purposes of examination, “more lenient” is interpreted as adjusting the login threshold so that fewer users fail to meet it, and “less lenient” as adjusting it so that more users fail to meet it. In each case, the comparison is to the threshold as it stood before the adjustment. Under this interpretation, the increased login count threshold of claim 5 is a less lenient threshold.
Claim Rejections - 35 USC § 103
7. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
9. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
10. Claims 1, 2, 6-8 and 11 are rejected under 35 U.S.C. § 103 as being unpatentable over Tanaka (US 11,652,947 B1), hereafter Tanaka.
Regarding claim 1, Tanaka teaches a method comprising: receiving a record of user logins to a computing device; Tanaka’s image forming apparatus 100 is a computing device with a controller 2 and a memory 2M. The memory 2M stores registration information for each registered user, including “a latest log-in date and time,” and “[t]he latest log-in date and time is updated each time the user logs in” (Tanaka col. 3, line 25-59; Fig. 4). The controller 2 receives this record of user logins when it reads the registration information to determine which users have not logged in (col. 5, line 58 - col. 6, line 4; Fig.6, step S02).
determining a login count threshold of the computing device; Tanaka determines a criterion of the apparatus that a user’s login activity must satisfy to avoid deletion: at least one login within a predetermined period of time, “for example, 30 days” (col. 5, line 23-33; col 5, line 58 - 67). Tanaka further expressly discloses a count-based form of the criterion: selecting for deletion “the registration of the user who has least frequently logged in,” such as “the user who has logged in the fewest number of times, for example during the last 180 days” (col. 9, line 1-8). Each is a login count threshold of the computing device under the BRI. The term “login count threshold” is interpreted, consistent with [0066] and [0067] in the Specification, claims 6 and 7 (which recite that the login count threshold comprises a login recency threshold and a login frequency threshold, respectively) – as encompassing a criterion, measured from a record of user logins, that a user meets or fails based on the recency or the number of the user’s logins. A requirement that a user have logged in at least once within a defined time period is therefore a login count threshold applied over the time period.
identifying, from the record of user logins, a user that does not meet the login count threshold of the computing device over a defined period of time; Tanaka’s controller 2 periodically decides “whether any of the user have not logged in for a predetermined period of time or longer” and extracts each such user from the stored registration information (col. 5, line 49 – col. 6, line 21; Fig. 6, step S01-S02). A user who has not logged in for the pre-determined period of time (e.g., 30 days) is a user that does not meet the login count threshold over a defined time period. In Tanaka’s count-based alternative, the identified user is the user with the fewest logins during the last 180 days (col. 9, line 1-8) - identified from the record of user logins, against the threshold, over a defined time period.
locating a login credential of the user stored in a credentials cache; The registration information stored in the memory 2M includes the user’s “user identifier (ID)” and the password, inputted by the user through the display/operation device 19, is stored in the memory 2M, the controller 2 permits the user to log in” (col. 3, line 30-43, Fig. 4). The memory 2M storing the user ID/password pairs used to authenticate logins to the apparatus is a credential cache, and the stored user ID/password pair is a login credential of the user. The delete 23 locates, among the registrations of the extracted users who have not logged in for the predetermined period of time, the user registration to be deleted (col. 5, line 30-36; col. 6, line 5-21). The term “credentials cache” is interpreted as storage of a computing device holding login credentials used to authenticate users to the device. Noted that the specification describes the credentials as cached on a computer device (see [0004]).
and removing the login credential of the user from the credentials cache. The delete 23 “deletes the user registration” of the identified user from the memory 2m (col. 5, line 30-36; col. 6, line 5-21). Because the user registration includes the user’s ID and password - the login credential used to authenticate the user - deleting the user registration removes the login credential of the user from the credentials cache.
To the extend claim 1 requires identifying the user by a numeric login count compared against the threshold over the defined time period, rather than by the absence of any login within the time period, Tanaka discloses both selection criteria as alternative within the same deletion process (col. 5, line 23-36; col. 9, line 1-8). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to implement Tanaka’s identification of the user whose registration is deleted using the disclosed count-over-time period criterion (e.g., the fewest logins during the last 180 days). This modification is the simple substitution of one selection rule disclosed by Tanaka for another, yielding the predictable result of deleting the registration (including the stored login credentials) of the least active user. Doing so frees registration capacity of the apparatus while retaining the users who actively use it (col. 5, line 23-29), and avoids the “troubles such as information leakage” that arise from retaining registrations of users who no longer use the device (col. 6, line 63-67).
Claim 2:
Regarding claim 2, Tanaka teaches the limitations of claim 1 as outlined above.
Tanaka further teaches wherein the login count threshold is relative to a total number of logins to the computing device. Tanaka selects for deletion “the registration of the user who has least frequently logged in,” such as “the user who has logged in the fewest number of times, for example during the last 180 days” (col. 9, line 4-8). The number of logins a user must exceed to avoid deletion is set by the login counts of the other users of the apparatus – that is, by how the total number of logins to the computing device. As the total login activity of the apparatus changes, the login count a user must exceed to avoid being the least-frequent user changes with it.
Claim 6:
Regarding claim 6, Tanaka teaches the limitations of claim 1 as outlined above.
Tanaka further teaches wherein the login count threshold comprises a login recency threshold, and wherein identifying that the user does not meet the login count threshold comprises determining that the user does not meet the login recency threshold. Tanaka identifies each user “who has not logged in for a predetermined period of time or longer,” for example 30 days, from the stored latest log-in date and time (col. 5, line 58 - col. 6, line 18; Fig. 6, step S02). The requirement that a user’s latest login fall within the predetermined period is a login recency threshold, and extracting the user whose latest login falls outside the period is determining that the user does not meet the login recency threshold.
Claim 7:
Regarding claim 7, Tanaka teaches the limitations of claim 1 as outlined above.
Tanaka further teaches wherein the login count threshold comprises a login frequency threshold, and wherein identifying that the user does not meet the login count threshold comprises determining that the user does not meet the login frequency threshold. Tanaka identifies “the user who has least frequently logged in,” such as “the user who has logged in the fewest number of times, for example during the last 180 days” (col. 9, line 1-8). The number of logins over the period that a user must meet to avoid deletion is a login frequency threshold, and selecting the user with the fewest logins over the period is determining that the user does not meet the login frequency threshold.
Claim 8:
Regarding claim 8, Tanaka teaches a non-transitory computer-readable storage medium having computer-executable instructions stored thereupon that, when executed by a processor, cause the processor to: Tanaka’s controller 2 includes an arithmetic device 2P having a processor (e.g., CPU), and the memory 2M includes a storage media such as a ROM, RAM, FEPROM, and a hard disk drive (HDD) (col. 2, line 48-58). The arithmetic device 2P act as the register 21, the storage device 22, and the deleter 23 when the processor executes a control program stored in the memory 2M. (Col. 2, line 55-58; col. 3, line 4-10).
receive usage data of a computing device; Tanaka’s memory 2M stores registration information for each registered user of the image forming apparatus 100, including “a latest log-in date and time” that “is updated each time the user logs in” (col. 3, line 25-29, Fig. 4). The term “usage data” and “usage threshold” are interpreted as encompassing the records of logins to the computing device and a threshold applied to such login activity. This interpretation is also consistent with [0026] in the specification and claim 9, which recites that the usage data is received from an event log of an authentication server or of the computing device. Tanaka’s record of user logins to the apparatus is usage data of the computing device under the BRI set forth above, and the controller 2 receives it when it reads the registration information (col. 5, line 49 - col. 6, line 18; Fig. 6, step S02).
determine a usage threshold of the computing device; Tanaka determines a criterion of the apparatus that a user’s usage must satisfy to avoid deletion: at least one login within a predetermined time period, “for example, 30 days” (col. 5, line 23-33; col. 5, line 58 - 67), or in Tanaka’s disclosed alternative, more logins than “the user who has logged in the fewest number of times, for example during the last 180 days” (col. 9, line 1-8). Each is a usage threshold of the computing device.
identify, from the usage data, a user that fails to meet the usage threshold of the computing device; The controller 2 periodically determines “whether any of the users have not logged in for a predetermined time period or longer “ and extracts each such user from the stored registration information (col. 5, line 49 – col.6, line 21; Fig. 6, steps S01-S02). In the count-based alternative, the identified user is the user with the fewest logins during the last 180 days (col. 9, line 4-8)
locate a login credential of the user stored in a credentials cache; The registration information stored in the memory 2M includes the user’s “user identifier (ID)” and “password,” and the controller 2 permits the user to log in when the input user ID/password pair matches the pair stored in the memory 2M (col. 3, line 30-43; Fig. 43). The memory 2M is a credential cache and the stored user ID/password pair is the user’s login credential, as set forth in the rejection of claim 1 above. The deleter 2 locates, among the registrations of the extracted users, the user registration to be deleted (col. 5, line 30-36; col. 6, line 5-21).
and protect the login credential of the user stored in the credentials cache. The deleter 23 “deletes the user registration” of the identified user - including the stored user ID and password – from the memory 2M (Col. 5, line 30-36; col. 6, line 5-21). Under the BRI, and consistent with [0011] in the Specification and claim 11, deleting the login credential protects the login credential.
To the extend claim 8 requires identifying the user by comparing a measure of the user’s usage against the threshold, rather than by the absence of any login within the time period, the same reasoning set forth in the rejection of claim 1 applies. Tanaka discloses both selection criteria as alternative within the same deletion process. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to implement the identification using the disclosed count-over-time period criterion, a simple substitution of one disclosed selection rule for another yielding the predictable result (col. 5, line 23-36; col. 9, line 1-8). Doing so frees registration capacity of the apparatus while retaining the active users, and avoids the “troubles such as information leakage” that arise from retaining registrations of users who no longer use the device (col. 6, line 63-67).
Claim 11:
Regarding claim 11, Tanaka teaches the limitations of claim 8 as outlined above.
Tanaka further teaches wherein protecting the login credential of the user comprises encrypting or deleting the login credential of the user. The deleter 23 deletes the user registration of the identified user – including the stored user ID and password – from the memory 2M (col. 5, line 30-36; col. 6, line 5-21), which is the “deleting” alternative recited in the claim.
11. Claims 3, 4 and 10 are rejected under 35 U.S.C. § 103 as being unpatentable over Tanaka as applied to claim 1 and 8 above, and in view of Delker et al. (US 8,341,717 B1), hereafter Delker.
Regarding claim 3, Tanaka teaches the limitations of claim 1 as outlined above.
However, Tanaka does not teach determining a role of the computing device, wherein the login count threshold is determined based on the role of the computing device.
However, Delker teaches determining a role of the computing device. Delker teaches determining a role of a computing device and determining a policy of the device based on the role. Delker discovers a device classification “identifying the type of the… device” from the device’s identity certificate, and references a database to “determine a network policy to apply to the device classification” (Delker, col. 1, line 66 - col. 2, line 6), mapping “a first -device classification… to a first network policy” (col. 2, line 27-29). The term “role of the device” in claims 3 and 10 is interpreted, as encompassing a type of classification of the device. This interpretation is consistent with [0018] in the Specification and claim 5 (which recites that the role is determined to be a shared public computing device). Under the BRI, the device classification identifying the type of the device is a role of the computing device.
Delker is analogous art to the claimed invention because it pertains to selecting and applying a security policy to a computing device based on the type of the device, and is thus reasonably pertinent to the problem of setting a device’s login threshold based in its role.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to determine Tanaka’s login count threshold based on the classification of the apparatus, as taught by Delker. This combination uses a known technique (Delker’s selection of a device policy based on the device’s classification) to improve a similar system (Tanaka’s per-apparatus deletion threshold) in the same way, yielding the predictable result of a login count threshold determined by the role of the device. Doing so allows “more targeted delivery of services based on the device type” and “may promote improved network security, reduced management burden, and more efficient use of resources” (Delker, col. 3, line 23-27; col. 4, line 17-19).
Claim 4:
Regarding claim 4, Tanaka and Delker teach the method of claim 3 as outlined above.
However, Tanaka does not teach monitoring the computing device for a change in the role of the computing device; and adjusting the login count threshold based on the change in the role of the computing device.
However, Delker teaches monitoring the computing device for a change in the role of the computing device; Delker monitors a computing device for a change in its role and adjusting the device’s policy based on the change. In Delker, “device may be permitted to reclassify with the authentication server as a different type of device and thereby be associated with a different virtual local area network and receive a different class of services (col. 4, line 19-23). Delker receives a second device identity certificate from the sane device, validates it, and maps the second device classification to a second network policy applied in place of the first policy (col. 2, line 34-44). The authentication server thereby monitors the device’s classification and applies the policy corresponding to the changed classification.
It would have been obvious to one of ordinary skill in the art before the effective filing date to monitor the apparatus of Tanaka for a change to its classification and to adjust the login count threshold to that determined for the new classification, as taught by Delker. This combination uses a known technique (Delker’s reclassification and reapplication of policy) to improve a similar system (the role-based threshold of claim 3) in the same way, yielding the predictable result of a login count threshold that tracks the device’s current role. Doing so permits a device “to be seen on the network as a different device and be granted other services” appropriate to it new classification (Delker, col. 4, line 26-28).
Claim 10:
Regarding claim 10, Tanaka teaches the limitations of claim 8 as outlined above.
However, Tanaka does not teach determine a role of the computing device, wherein determining the usage threshold of the computing device is based on the determined role of the computing device.
However, Delker teaches determine a role of the computing device. Delker teaches determining a role of a computing device and determining a policy of the device based on the role. Delker discovers a device classification “identifying the type of the… device” from the device’s identity certificate, and references a database to “determine a network policy to apply to the device classification” (Delker, col. 1, line 66 - col. 2, line 6), mapping “a first device classification… to a first network policy” (col. 2, line 27-29).
It would have been obvious to one of ordinary skill in the art before the effective filing date to determine Tanaka’s usage threshold based on the classification of the apparatus, as taught by Delker. This combination uses a known technique (Delker’s selection of a device policy based on the device’s classification) to improve a similar system (Tanaka’s per-apparatus deletion threshold) in the same way, yielding the predictable result of a usage threshold determined by the role of the device. Doing so allows “more targeted delivery of services based on the device type” and “may promote improved network security, reduced management burden, and more efficient use of resources” (Delker, col. 3, line 23-27; col. 4, line 17-19).
12. Claims 14-16, 19 and 20 are rejected under 35 U.S.C. § 103 as being unpatentable over Tanaka (US 11,652,947 A1), hereafter Tanaka, and in view of Delker et al. (US 8,341,717 B1), hereafter Delker.
Text underlined within a claim limitation indicates the portion that the cited reference does not teach.
Regarding claim 14, Tanaka teaches a computing device comprising: processor; and a non-transitory computer-readable storage medium storing computer-readable instructions that, when executed by the processor, cause the computing device to: Tanaka’s image forming apparatus 100 is a computer device whose controller 2 includes an arithmetic device 2P having a CPU, and whose memory 2M (ROM, RAM, FEPROM, HDD) stores a control program that, when executed by the processor, causes the apparatus to perform the operations of the register 21, the storge device 22, and the deleter 23 (col. 2, line 48-58; col. 3, line 4-10).
receive a record of user logins to a computing device; The memory 2M stores registration information for each registered user, including “a latest log-in date and time” stores registration information for each registered user, including “a latest log-in date and time” that is “updated each time the user logs in” (col. 3, line 25-59; Fig. 4), and the controller 2 receives this record when it reads the registration information (col. 5, line 49 – col. 6, line 18; Fig. 6, step S02).
determine, from the record of user logins, a login frequency of a user of the computing device; Tanaka determines, from the stored login records, “the user who has least frequently logged in,” such as “the user who has logged in the fewest number of times, for example during the last 180 days” (col. 9, line 1-8). Determining which user logged in the fewest number of times over the time period is determining a login frequency of a user of the computing device from the record of user logins.
determine that the login frequency of the user of the computing device fails to meet the login threshold; The user determined to have logged in the fewest number of times during the time period, - or, in the first-event embodiment, the user determined to have not logged in within the predetermined time period (col. 5, line 23-29) – is the user whose login frequency fails to meet the login threshold, and that user’s registration is selected for deletion (col. 5, line 30-36; col. 6, line 5-18; col. 9, line 1-8).
identify a login credential of the user stored on a credentials cache of the computing device; The registration information stored in the memory 2M includes the user’s “user identifier (ID)” and “password,” and the controller 2 checks the input user’s ID/password pair to permit login (col.3, line 30-43; Fig. 43). The memory 2M is a credential cache of the computing device, as set forth in the rejection of claim 1 above. The deleter 2 identifies the registrations of the selected users to be deleted (col. 5, line 30-36; col. 6, line 5-21).
and remove the login credential of the user from the credentials cache of the computing device. The deleter 23 “deletes the user registration” of the identified user - including the stored user ID and password – from the memory 2M (col. 5, line 30-36; col. 6, line 5-21).
However, Tanaka does not teach select a login threshold based on a role of the computing device.
However, Delker teaches select a login threshold based on a role of the computing device. Delker teaches selecting a policy for a computing device based on the role of the computing device. Delker discovers a device classification “identifying the type of the… device” from the device’s identity certificate, and references a database to “determine a network policy to apply to the device classification” (Delker, col. 1, line 66 - col. 2, line 6), mapping “a first device classification… to a first network policy” (col. 2, line 27-29). The term “role of the device” in claim 14 and 19 is interpreted, as encompassing a type of classification of the device. This interpretation is consistent with [0018] in the Specification and claim 20 (which recites that the role is determined to be a shared computing device). Under the BRI, the device classification identifying the type of the device is a role of the computing device, and the policy selected based on the role.
Delker is analogous art to the claimed invention because it pertains to selecting and applying a security policy to a computing device based on the type of the device, and is thus reasonably pertinent to the problem of setting a device’s login threshold based in its role.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to select Tanaka’s login threshold, referring to the predetermined time period or the count-over-time period criterion against which the user’s login activity is measures - based on the classification of the apparatus, as taught by Delker. This combination uses a known technique (Delker’s selection of a device policy based on the device’s classification) to improve a similar system (Tanaka’s per-apparatus deletion threshold) in the same way, yielding the predictable result of a login threshold suited to type of the device. Doing so allows “more targeted delivery of services based on the device type” and “may promote improved network security, reduced management burden, and more efficient use of resources” (Delker, col. 3, line 23-27; col. 4, line 17-19), so that the deletion criterion match the manner in which the device is used.
Claim 15:
Regarding claim 15, Tanaka and Delker teach the limitations of claim 14 as stated above.
Tanaka further teaches remove or encrypt sensitive information of the inactive user. When the first event has occurred, in addition to deleting the user registration containing the user’s password, the deleter 23 “deletes the function information associated with the user whose registration has been deleted” (col. 5, line 37-42; col. 6, line 5-18). The deleted password and function information are sensitive information of the user identified as failing the login threshold, and deleting them is the remove alternative recited in the claim. The function information includes the set values of the user’s document box, the storage region assigned to the user in which the user’s image data and document data are stored (col. 4, line 54-59).
Claim 16:
Regarding claim 16, Tanaka teaches the limitations of claim 15 as stated above.
Tanaka further teaches wherein the sensitive information comprises a browser cookie, a password, a document, or a file. Tanaka’s deleted registration includes the user’s password (col. 3,line 30-33), and the user’s document box stores image data read by the scanner and document data received from the PC – document or files of the user (col. 4, line 54-59).
Claim 19:
Regarding claim 19, Tanaka and Delker teach the limitations of claim 14 as stated above.
However, Tanaka does not teach determine a role of the computing device; and adjust the login threshold according to the determined role.
However, Delker teaches determine a role of the computing device; Delker discovers a device classification identifying the type of the device, and determine the network policy applied to the device from its classification” (col. 1, line 66 - col. 2, line 6), and upon reclassification of the device, applies the policy of the new classification in place of the prior policy (col. 2, line 34-44; col. 4, line 19-30).
It would have been obvious to one of ordinary skill in the art before the effective filing date to adjust Tanaka’s login threshold based on the classification of the apparatus, as taught by Delker. This combination uses a known technique to improve a similar system in the same way, yielding the predictable result of a login threshold suited to type of the device. Doing so allows “more targeted delivery of services based on the device type” and “may promote improved network security, reduced management burden, and more efficient use of resources” (Delker, col. 3, line 23-27; col. 4, line 17-19), so that the deletion criterion match the manner in which the device is used.
Claim 20:
Regarding claim 20, Tanaka and Delker teach the limitations of claim 19 as stated above.
However, Tanaka and Delker do not expressly teach “wherein the role is determined to be a shared computing device, and wherein the login threshold is made less lenient.”
However, Tanaka expressly teaches that “an information processing apparatus is shared by a plurality of users “ (col. 1, line 26-27) – the apparatus is a shared computing device – and Delker’s device classification identifies the type of the device (col. 1, line 66 – col. 2, line 6). Tanaka further teaches that permitting many users to utilize the apparatus “provoke troubles such as information leakage” (col. 6, line 63-66).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to determine, using Delker’s classification, that the role of the device is a shared computing device, and to make the login threshold less lenient for a device of that classification, so that the stored registrations of many transient users of a shared device are removed sooner, The modification is a predictable application of the role-based threshold of claim 19 to a known device type. Doing so applies a policy “more finely tuned to the requirement of the device class and better adapted to the risk inherent to devices of that class” (Delker, col. 4, line 9-13).
13. Claim 5 is rejected under 35 U.S.C. § 103 as being unpatentable over Tanaka and Delker as applied to claims 1 and 3 above, and further in view of Wei et al. (US 10,462,008 B2), hereafter Wei.
Regarding claim 5, Tanaka and Delker teach the method of claim 3 as applied above.
However, Tanaka and Delker do not expressly teach “wherein the role is determined to be a shared public computing device, and wherein the login count threshold is increased in response to determining the role to be a shared public computing device.” Delker classifies devices by type, but does not identify a shared public computing device as a type.
However, Wei teaches a shared public device. Wei describes shared computing devices, such as devices deployed in a school environment (col. 5, line 14-18), that are used by many users and can be configured “to allow users to login anonymously (e.g., providing no user name or account), or to allow the user to choose whether to login with their user account or anonymously” (col. 6, line 19-26) – a shared computing device open to use by the public. Wei further monitors “how frequently the account are logged into” the shared computing device and deletes accounts “based on the usage of the accounts, such as the least frequently used account(s)” (col. 5, line 28-51).
Wei is analogous art to the claimed invention because it is from the same field of endeavor: managing user accounts stored on a shared computing device based on the users’ login activity.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to determine, using Delker’s device classification, that the role of the device is a shared public computing device of the kind taught by Wei, and to increase the login count threshold applied to a device of that role. A shared public computing device accommodates many users, including anonymous and transient users, and Wei manages exactly such device by removing the accounts of the least frequent users (Wei, col. 5, line 38-51). Increasing the login count threshold for the shared public computing device is a predictable application of the role-based threshold of claim 3 to the device type taught by Wei, yielding the predictable result that the registrations of a shared public device’s transient users are removed sooner. Doing so deletes accounts so that the shared device’s resources do not run low (Wei, col. 5, line 38-48), and avoids the “troubles such as information leakage” that accumulate on a device used by many users (Tanaka, col. 6, line 63-66).
14. Claim 9 is rejected under 35 U.S.C. § 103 as being unpatentable over Tanaka as applied to claim 8 above, and in view of Zimmermann (US 2020/0137097 A1), hereafter Zimmermann.
Regard claim 9, Tanaka teaches the limitations of claim 8 as outlined above.
However, Tanaka does not expressly teach wherein the usage data is received from an event log of an authentication server or an event log of the computing device. Tanaka receives the usage data by reading the registration information stored in the memory 2M of the apparatus (col. 5, line 57 – col. 6, line 18).
However, Zimmermann teaches wherein the usage data is received from an event log of an authentication server. Zimmermann ingests and analyzes “event log data that may be sourced from the APIs of different service providers, such as Google, SFDC, Microsoft, Box, Dropbox, Okta and the like” (Zimmermann, [0171], [0174]). Zimmermann describes Okta as “a single sign-on (SSO)/identity and Access Management (IAM) system” ([0111]) – an authentication server – and the event log data includes “login event types” ([0175]. Zimmermann’s detection tasks identify “an account remain entirely dormant for a time period (e.g., 30 days)” from that event data ([0152]).
Zimmermann is analogous art to the claimed invention because it is from the same field of endeavor: identifying inactive uses from records of login activity and acting on their accounts to reduce security exposure.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to receive the usage data of Tanaka from an event log of an authentication server, as taught by Zimmermann. The combination uses a known technique (Zimmermann’s sourcing of login activity from event logs) to improve a similar system (Tanaka’s identification of users who have not logged in) in the same way, yielding the predictable result of the same inactivity determination made from event log data. Doing so supports “collection of all available event data and retention of all available event data” and “online detection” that can “surface alerts in near real time or real time” (Zimmermann, [0172]).
14. Claim 12 is rejected under 35 U.S.C. § 103 as being unpatentable over Tanaka as applied to claim 8 above, and in view of Awad et al. (US 9,319,221 B1), hereafter Awad.
Regard claim 12, Tanaka teaches the limitations of claim 8 as outlined above.
However, Tanaka does not teach “wherein identifying a user that fails to meet the usage threshold comprises determining that the user is not an owner of the computing device.”
However, Awad teaches determining a user of a computing device is not an owner of the computing device. Awad describes computing devices that are “commonly owned by a primary user, but shared on a temporary basis with other users” (col. 3, line 62-67). The device “can maintain a profile for each known or authorized user of the device and can provide a score or probability that the current user is an authorized user, or not” (col. 4, line 21-28; Fig. 1), and when the user does not match the owner’s profile, the device restricts access, including “disabl[ing] social networking access or other saved passwords” (col. line 28-38).
Awad is analogous art to the claimed invention because it protects credentials and data stored on a computing device from users other than the device’s owner, and thus is reasonably pertinent to the inventor’s problem.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include, in identifying the user that fails to meet the usage threshold of Tanaka, determining that the user is not an owner of the computing device, as taught by Awad, so that the owner’s registration is retained regardless of login frequency and only non-owner users’ credentials are protected. The combination uses a known technique (Awad’s determination of whether a user of a device is its owner) to improve a similar system (Tanaka’s identification of users whose registrations are deleted) in the same way, yielding the predictable result of confining the deletion of non-owner users. Doing so addresses Awad’s recognition that there is likely to be data or functions on the device that the primary owner does not necessarily want readily available to other users (i.e., unauthorized users)” (col. 4, line 11-14), and ensures “steps can be taken to protect the authorized user[’s] (e.g., device owner[’] privacy” (col. 4, line 24-28).
15. Claim 13 is rejected under 35 U.S.C. § 103 as being unpatentable over Tanaka as applied to claim 8 above, and in view of Contenti (US 2018/0375665 A1), hereafter Contenti.
Regard claim 13, Tanaka teaches the limitations of claim 8 as outlined above.
However, Tanaka does not teach identify a first owner user of the computing device; monitor the computing device for a change of ownership to a second owner user; and protect the login credential of the first owner user in response to the change of ownership to the second owner user.
However, Contenti teach these limitations. Contenti maintains an ownership record identifying a user as owner of a device (Contenti [0002, and the data provisioned to the device under that record includes “the customer’s SSID/password for the user’s Wi-Fi,” applications, and user data ([0022]-[0023]). A first owner (user A) transfers ownership to a second owner (user B), and the provisioning service tracks the transfer by re-associating the device’s public key with user B’s account ([0056, Fig. 7). In the same Fig. 7 sale scenario, when the first owner deprovisions the device for transfer, the provisioning service “instructs the smart scale 706 to erase” the “data associated with the user A,” leaving the device “in an unclaimed” state so that “[a]ny subsequent user may provision the [device] for themselves ([0057]).
Contenti is analogous art to the claimed invention because it remove a user’s stored data and credentials from a computing device when the user no longer uses the device, and thus is reasonably pertinent to the inventor’s problem.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to identify a first owner of the computing device of Tanaka, monitor for a change of ownership to a second owner user, and protect the first owner’s login credential in response, as taught by Contenti. The combination uses a known technique (Contenti’s erasure of the prior device owner’s data upon an ownership transfer) to improve a similar system (Tanaka’s deletion of stored user registrations) in the same way, yielding the predictable result of protecting the prior device owner’s stored credentials when the device changes hands. Doing so erases the data associated with the prior owner before the device, left “in an unclaimed “ state, is provisioned by “[a]ny subsequent owner” (Contenti, [0057]) – with the result that the prior device owner’s stored data and credentials do not pass to the subsequent owner with the device..
16. Claims 17 and 18 are rejected under 35 U.S.C. § 103 as being unpatentable over Tanaka and Delker as applied to claim 14 above, and further in view of Microsoft, “4625(F): An account failed to log on” Windows Security auditing documentation, hereafter Event 4625, and further in view of ManageEngine, “Logon failure – account currently disabled,” ADAudit Plus documentation, hereafter ADAudit.
Regarding claim 17, Tanaka and Delker teach the limitations of claim 14 as stated above. In Tanaka, the controller 2 permits a user to log in only when the input user ID/password pair matches a pair stored in the memory 2M (col. 3, line 29-43). After the delete 23 had deleted the user’s registration, the user’s login attempt accordingly fails because the stored credential was removed.
Tanaka and Delker do not expressly teach “determine that a user login attempt failed because the login credential of the inactive user was removed; and alert a system administrator that the user login attempt failed because the login credential of the inactive user was removed.”
However, Event 4625 teaches determining that a user login attempt failed because the user’s credential or account no longer exists. Event 4625 documents that when a logon attempt fails, the Window operating system determines the reason for the failure and records a security audit event identifying that reason by a Sub Status code, including Sub Status 0xC0000064. “[u]ser logon with misspelled or bad user account,” i.e., the specified account does not exist on the system, Sub Status 0xC0000072, “[u]ser logon to account disabled by administrator,” and Sub Status 0x0000193, “[u]ser logon with expired account” (Event4625, pp.8-9) – thereby distinguishing failures caused by an invalid, disabled, expired or nonexistent account from failures caused by an incorrect password. Event 4625’s Security Monitoring Recommendations further direct practitioners to monitor for these Sub Status values, noting for Sub status 0xC0000064 that if you get several of these events in a row, it can be a sign of a user enumeration attack (pp.12, 14-15). ADAudit teaches alerting a system administrator of such failed logon events and their reasons. Its Login Failure report “help administrators verify the reason for the logon failure,” so that “the administrator can decide whether it is a potential security threat or not,” and ADAudit Plus “also has a real-time alert feature which alerts the admins in case of any unanticipated activity (ADAudit, p. 2)
Event 4625 and ADAudit are analogous art to the claimed invention because each is from the same field of endeavor: auditing user login attempts to a computing device and reporting failed logins and their causes.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to determine, in the combined system, that a user login attempt failed because the login credential of the identified was removed, and to alert a system administrator of that failed login and its cause. Tanaka’s controller determines at login that no stored credential matches, which is a condition the system’s own deletion created. Event 4625 shows that operating system determine and record the specific reason a logon fail, including that the user no longer exists. ADAudit teaches alerting an administrator of such failed logons and their reasons,
In the combined system, the reason so determine – that the login credentials no longer exists -is the removal of the credential. The identified user’s credential is absent from the memory 2M only because the deleter remove it under the inactively criterion. Determining that the login attempt failed because the credential no longer exists is therefore determining that it failed because the login credential of the identified user was remove. The combination uses known technique (recording the reason a logon attempt failed and alerting an administrator of the failure and its reason) to improve a similar system (Tanaka’s deletion of inactive users’ registrations) in the same way. The predictable result is that the administrator is notified when a removed user’s login attempt fails and may take appropriate action, such as re-registering the user.
Claim 18:
Regarding claim 18, Tanaka, Delker, Event 4625, and ADAudit teach the limitations of claim 14 as applied above.
However, the combination as applied to claim 17 does not expressly teach “modify the login threshold to be more lenient.”
However, Delker teaches modifying a device’s policy in the less restrictive direction. Upon reclassification, a device may “be granted other services or access to a different segment of an enterprise network with enhanced privileges” (Delker, col. 4, line 26-30).
It would have been obvious to one of ordinary skill in the art before the effective filing date to modify the login threshold of the combined system to be more lenient. In the combination set forth for claim 19, the login threshold is adjusted according to the device’s role. A threshold can be adjusted in only two directions. Adjusting the threshold according to the device’s role therefore included making it more lenient when the device’s role so warrants. For example, when the device is reclassified from a shared device to a device used by few users, the converse of the adjustment set forth in claim 20. Delker teaches policy adjustment in the less restrictive direction, granting “enhanced privileges” upon reclassification (Delker, col. 4, line 26-30). The selection of the lenient direction is a choice from a number of predictable options with a reasonable expectation of success. Moreover, in the combined system the administrator is alerted when a user’s login attempt fails because the user’s credential was removed (claim 17). Making the login threshold more lenient predictably reduced such failed logins of users who still use the service. Doing so applies a policy “more finely tuned to the requirement of the device class” (Delker, col. 4, line 9-13).
Conclusion
17. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Argoety et al. (US 2021/0157907 A1) discloses a security service that identifies inactive user accounts in an enterprise network by determining whether an account’s activity falls outside a threshold – for example, a date of last use exceeding 180 days or a frequency of use within a threshold amount such as two uses in the last six months - based on account activity data.
18. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BIN QING ZHENG whose telephone number is (703)756-1535. The examiner can normally be reached on M-F 9:30 am - 5:30 pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip J. Chea can be reached on 571-272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BIN QING ZHENG/
Examiner, Art Unit 2499
/PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499