DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Lauer et al. (U.S. PGPub. 2018/0077030), hereinafter Lauer, in view of METRAL (U.S. PGPub. 2016/0057145), hereinafter Metral.
Regarding claim 1, Lauer teaches A computer-implemented method performed via one or more processors, the method comprising:
receiving, via an electronic device, a request to access a network (Lauer, Paragraph [0021], see “After the electronic device is granted network access by the authentication server…”, which is being read as receiving via an electronic device, a request to access a network, which subsequently gets granted by the authentication server);
determining that the electronic device has previously been authenticated during a first communication session (Lauer, Paragraph [0021], see “…If the electronic device has not previously utilized the network, the authentication server may associate the electronic device with a default access profile. On the other hand, if the electronic device has previously utilized the network, then the access profile may be the same profile as previously associated with the electronic device…”, which is being read as determining that the electronic device has previously been authenticated (e.g., previously utilized the network, which requires authentication) during a first communication session);
monitoring a network usage associated with the electronic device during a second communication session (Lauer, Paragraph [0040], see “…the profile database 150 may also store a usage profile corresponding to the electronic devices 110. The usage profile may include historical records that indicate with which applications and/or services the electronic devices 110 communicated…”, which is being read as monitoring a network usage associated with the electronic device during a second communication session (e.g., due to the usage profile being queried in a subsequent (second) communication session to evaluate historical records)), wherein monitoring the network usage comprises querying a usage profile assigned to the electronic device (Lauer, Paragraph [0075], see “…the network regulation server may query the usage profile for the electronic device to retrieve the latency value corresponding to the particular application”), the usage profile including a usage behavior-based metric associated with traffic from the electronic device during the first communication session (Lauer, Paragraph [0027], see “…The network regulation server may utilize the recorded and/or aggregated usage statistics to generate a usage profile within the profile database that corresponds to the electronic device”) (Lauer, Paragraph [0033], see “…the usage profile may also be analyzed by the network regulation server to improve the network experience for the user of the electronic device”) (Lauer, Paragraph [0040], see “…The usage profile may include historical records that indicate with which applications and/or services the electronic devices 110 communicated…the usage profile may list any application with which the electronic devices 110 communicated, when the communications occurred, and/or an amount of data communicated”, where “The usage profile may include historical records and may list any application with which the electronic devices 110 communicated, when the communications occurred, and/or an amount of data communicated” is analogous to the usage profile including a usage behavior-based metric (usage statistics) based upon monitoring traffic received from the electronic device during the communication sessions); and
automatically re-authenticating the electronic device based on the monitoring via determining whether at least a portion of a set of data packets from the electronic device satisfies the usage behavior-based metric indicated in the usage profile (Lauer, Paragraph [0046], see “…to authenticate the electronic device 210, the authentication server 220 may query the profile database 250 to assign the electronic device 210 an access profile…the authentication server may utilize the device identity to search for a record in the profile database 250 that corresponds to the electronic device…the electronic device may have been utilized within a local network operated by the same (or affiliated) network operator as the current local network…”, which is being read as the authentication server utilizing device identities to search for a record to re-authenticate the electronic device based on its access profile (behavior-based metrics indicated in a usage profile)) (Lauer, Paragraph [0051], see “…the network regulation server 240 may compare measured transmission characteristics of the data stream addressed to the secured server to known sets of transmission characteristics indicative of particular types of applications and/or application categories…”) (Lauer, Paragraph [0052], see “…the network regulation server 240 may compare each application and/or application category associated with a data stream to be queried access profile to determine a respective regulation activity to apply to each data stream…the access profile may indicate that video traffic should be blocked but email traffic should be allowed…if the electronic device 210 transmits both video and email data, the network regulation server may block the video data from being transmitted to an external network; whereas the network regulation server 240 may route the email data over an external communication link to respectively corresponding destination addresses”, which is being read as automatically re-authenticating (e.g., by allowing the electronic device to communicate over the network) the electronic device based on the monitoring via determining whether at least a portion of a set of data packets from the electronic device satisfies the usage behavior-based metric indicated in the usage profile).
However, assuming arguendo that Lauer does not adequately teach receiving, via an electronic device, a request to access a network, the Examiner introduces Metral, which more specifically teaches the above limitation, see Metral, Paragraph [0044], see “…client computing device 102 may send out one or more broadcast packets that include a device identifier of client computing device 102 when client computing device 102 is attempting to connect to network 106”, which is being read as receiving from an electronic device, a request to access a network.
Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Lauer, by implementing techniques of receiving a request to access a network, disclosed of Metral.
One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for network authentication using monitored traffic activity, comprising of receiving a request to access a network. This allows for better security management and efficiency by gatekeeping access to the network by requiring a request for access with proper credentials, which ultimately stops unauthorized entry to the network. Metral is deemed as analogous art due to the art disclosing techniques of receiving a request to access a network (Metral, Paragraph [0044]).
Regarding claim 2, Lauer as modified by Metral teaches The computer-implemented method of claim 1, further comprising:
when the at least the portion of the set of data packets satisfies the usage behavior-based metric, routing, by the one or more processors and from the electronic device, the set of data packets to respective locations during the second communication session (Lauer, Paragraph [0042], see “…If the network regulation server 140 determines that data should be transmitted over the external communication link 147, network regulation server 140 may route the data to the plurality of modems 115 which forward and/or transmit this data to the external network 145…As part of this determination, the network regulation server 140 may then query the profile database 150 to retrieve an access profile associated with the electronic devices…depending on the particular parameters stored in the retrieved access profile, the network regulation server 140 may block the data packet, delay the transmission…transmit the data packet, prioritize…and/or perform any other network regulation activity”, which is being read as the network regulation server checking the profile database for an access profile of the electronic device to make sure the data packets satisfy the usage behavior-based metrics of the electronic device, and if it does, routing the set of data packets to respective locations).
Regarding claim 3, Lauer as modified by Metral teaches The computer-implemented method of claim 1, wherein the request to access the network indicates a device identifier of the electronic device (Lauer, Paragraph [0045], see “…the electronic device may transmit a device identity (e.g., IMSI, MEID, ICCID, MAC address, and so on)...Upon the authentication server determining that the electronic device transmitted the correct credentials, the authentication server 220 may authenticate the electronic device 210 to communicate over the local network”), and wherein the determining that the electronic device has previously been authenticated is based upon the device identifier (Lauer, Paragraph [0046], see “…the authentication server may utilize the device identity to search for a record in the profile database that corresponds to the electronic device…the electronic device may have been utilized within a local network operated by the same (or affiliated) network operator…the profile database may already store a record corresponding to the electronic device indicating any services that the user of the electronic device may have purchased…”, which is being read as utilizing the device identifier (e.g., record in the profile database) to determine whether the electronic device has previously been authenticated before or not (e.g., based on whether a profile exists for the electronic device)).
Regarding claim 4, Lauer as modified by Metral teaches The computer-implemented method of claim 3, wherein the device identifier comprises at least one of an international mobile subscriber identity (IMSI), a mobile equipment identifier (MEID), an integrated circuit card identifier (ICCID), a pseudo electronic serial number (pESN), a media access control (MAC) address, a strength of a wireless signal from an access point within the network as measured by the electronic device, a browser identifier, a destination uniform resource locator (URL), a service set identifier (SSID), or data related to a vehicle in which the network is implemented (Lauer, Paragraph [0045], see “…the electronic device may transmit a device identity (e.g., IMSI, MEID, ICCID, pESN, MAC address, and so on)…”).
Regarding claim 5, Lauer as modified by Metral teaches The computer-implemented method of claim 1, wherein the monitoring the network usage comprises:
identifying, by the one or more processors, that the network usage supports one or more applications or respective ports or application categories (Lauer, Paragraph [0078], see “…the traffic may be address to various locations external the local network to support a plurality of communication sessions with a plurality of applications”, which is being read as identifying that the network usage supports one or more applications); and
calculating, by the one or more processors, the usage behavior-based metric based on the identified one or more applications or respective ports or application categories (Lauer, Paragraph [0078], see “…the network regulation server may analyze the traffic to generate a plurality of usage statistics characterizing the traffic. After generating the usage statistics, the network regulation server may update the usage profile within the profile database that corresponds to the electronic device…”, which is being read as calculating the usage behavior-based metric based on the identified one or more applications that the traffic is to be communicated with).
Regarding claim 6, Lauer as modified by Metral teaches The computer-implemented method of claim 5, wherein monitoring the network usage further comprises:
separating, by the one or more processors, the traffic into individual data streams corresponding to each of the one or more applications or respective ports or application categories (Lauer, Paragraph [0050], see “…The network regulation server 240 may then separate the traffic into individual data streams corresponding to each communication session. The network regulation server 240 may further correspond the data stream to an application and/or application category…”);
calculating, by the one or more processors, a respective payload of the individual data streams (Lauer, Paragraph [0065], see “…the network regulation server may determine whether a measured byte volume for the traffic exceeds a threshold proportion of an overall bandwidth allocation indicated by the access profile…”, which is being read as calculating a respective payload of the individual data streams); and
calculating, by the one or more processors, the usage behavior-based metric based on the respective payload of the individual data streams (Lauer, Paragraph [0065], see “After each application has been assigned a priority level, the network regulation server may determine whether a measured byte volume for the traffic exceeds a threshold proportion of an overall bandwidth allocation indicated by the access profile. If the measured byte volume of the traffic does not exceed the threshold proportion, the network regulation server may route and/or transmit the data streams corresponding to applications associated with a first priority level…”, which is being read as calculating the usage behavior-based metric (e.g., threshold proportion of an overall bandwidth allocation indicated by the access profile) based on the respective payload (e.g., measured byte volume for the traffic) of the individual data streams).
Regarding claim 7, Lauer as modified by Metral teaches The computer-implemented method of claim 1, further comprising:
updating, by the one or more processors, the usage behavior-based metric based on the set of data packets upon determining that the at least the portion of the first set of data packets satisfies the usage behavior-based metric (Lauer, FIG. 2, see “241 – 257”, which entails updating the usage behavior-based metric (e.g., update usage profile 257) based on determining that the at least the portion of the first set of data packets (e.g., Traffic 241) satisfies the usage behavior-based metric (e.g., 249, 253), where in 249, the network regulation server may identify that the traffic currently supports multiple communication sessions, which is being read as the traffic satisfying the current usage behavior-based metrics of the electronic device).
Regarding claim 8, Lauer as modified by Metral teaches The computer-implemented method of claim 1, wherein monitoring the network usage is based on monitoring at least one of:
one or more websites requested by the electronic device;
one or more applications in use by the electronic device;
one or more categories corresponding to the one or more applications;
one or more ports in use corresponding to the one or more applications;
payload corresponding to the one or more websites, the one or more applications, or the one or more ports; or
a usage pattern of the one or more websites, the one or more applications, or the one or more ports in use by the electronic device (Lauer, Paragraph [0021], see “…the access profile may indicate whether the electronic device is associated with a rate limit and/or whether the electronic device may utilize a particular application (e.g., a VPN application, a particular website, etc.) and/or an application category…”, wherein the “access profile” is monitored and analyzed for specific network usage criteria).
Regarding claims 9 and 17, the claims are rejected under the same reasoning as claim 1.
Regarding claims 10 and 18, the claims are rejected under the same reasoning as claim 2.
Regarding claim 11, the claim is rejected under the same reasoning as claim 3.
Regarding claim 12, the claim is rejected under the same reasoning as claim 4.
Regarding claims 13 and 19, the claims are rejected under the same reasoning as claim 5.
Regarding claim 14, the claim is rejected under the same reasoning as claim 6.
Regarding claims 15 and 20, the claims are rejected under the same reasoning as claim 7.
Regarding claim 16, the claim is rejected under the same reasoning as claim 8.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claim 1 is rejected on the ground of nonstatutory double patenting as being unpatentable over claim 1 of issued Patent 12,231,889. Although the claims at issue are not identical, they are not patentably distinct from each other. Claim 1 of the reference patent covers all the limitations of claim 1 of the instant application and, as such, anticipates claim 1 of the instant application.
Instant Application No. 19/055,359
Reference Patent No. 12,231,889
Claim 1: A computer-implemented method performed via one or more processors, the method comprising:
receiving, via an electronic device, a request to access a network;
determining that the electronic device has previously been authenticated during a first communication session;
monitoring a network usage associated with the electronic device during a second communication session, wherein monitoring the network usage comprises querying a usage profile assigned to the electronic device, the usage profile including a usage behavior-based metric associated with traffic from the electronic device during the first communication session; and
automatically re-authenticating the electronic device based on the monitoring via determining whether at least a portion of a set of data packets from the electronic device satisfies the usage behavior-based metric indicated in the usage profile
Claim 1: A method for re-authenticating an electronic device, the method comprising:
receiving, by one or more processors and from an electronic device, a request to access a local access network on-board a vehicle, the request including a device identifier of the electronic device;
querying, by the one or more processors and using the device identifier, an access profile assigned to the electronic device to determine that the electronic device has previously been authenticated during a first communication session, wherein the access profile is assigned to the electronic device based upon an indication of a user selection received from the electronic device;
monitoring, by the one or more processors, network usage associated with the electronic device during a second communication session, wherein monitoring network usage comprises: routing, by the one or more processors and from the electronic device, a first set of data packets to respective locations external to the local access network during the second communication session in accordance with the access profile; and
querying, by the one or more processors, a usage profile assigned to the electronic device, wherein the usage profile includes a usage behavior-based metric based upon monitoring traffic received from the electronic device during the first communication session; and
automatically re-authenticating, by the one or more processors, the electronic device based on the monitoring via determining, by the one or more processors, whether at least a portion of the first set of data packets satisfies the usage behavior-based metric indicated in the usage profile.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RODMAN ALEXANDER MAHMOUDI whose telephone number is (571)272-8747. The examiner can normally be reached on M-F 11:00am – 7:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached on (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RODMAN ALEXANDER MAHMOUDI/Examiner, Art Unit 2499