DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending.
Information Disclosure Statement
The IDS filed 3/14/2025 has been considered by the Examiner.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 14, and 18 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims recite registering for a single sign-on (SSO) service and accessing a resource using the SSO. This judicial exception is not integrated into a practical application because the limitations lack any claimed hardware and the method steps can be accomplished by human activity without computer intervention.
Step
Analysis
1: Statutory Category
Claim 1: A method recites a series of steps and, therefore, is a process and is a statutory process.
Claim 14: Non-transitory computer-readable medium and is one of the four statutory categories.
Claim 18: A device/computer claim and is one of the four statutory categories.
2A- Prong 1: Judicial Exception Recited
Claims 1, 14, and 18:
The limitations are directed to signing up for an SSO and then accessing resources using the SSO. These steps are functional, high-level operations describing a workflow i.e., controlling access to resources through SSO scheme. This is essentially managing authentication and access rights to resources, which is a form of organizing human activity and authentication, both recognized categories of abstract ideas.
2A, Prong 2
Claim 1 does not recite any additional elements. Claim 14 recites a non-transitory computer-readable medium as an additional element. Claim18 recite a computer as an additional element.
The steps are implemented on generic computing components (receiving/transmitting data, generating credentials). The claims focus on what is done rather than how it is done in a technically unconventional way. The claims do not integrate the abstract idea into a practical application- it uses a generic computer as a tool to carry out the abstract workflow.
2B
Claims 1, 14, and 18:
The operations (receive/transmit, generating credentials (tokens), and authentication) are conventional functions of computers and networks. No recitation of non-conventional hardware or unconventional technical arrangement. The claims are not patent eligible as currently written.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-12 and 14-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by US PG Pub. No. 2012/0011578 to Hinton et al. (hereinafter Hinton).
As to claims 1, 14, and 18, Hinton teaches:
a. At least one processor and at least one memory (Hinton, [0011]).
b. Receiving, by a console of a service provider, a first redirect message from a browser application based at least in part on a sign-up request (registration (sign-up) request is sent to cloud provider for processing the request) (Hinton, [0075-0076]).
c. Transmitting, by the console of the service provider, a second redirect message to the browser application (F-SSO redirects to the user’s browser) (Hinton, [0079]).
d. Receiving, by a sign-in portal of the service provider, the second redirect message from the browser application (with the redirect, the browser requests a key pair) (Hinton, [0079]).
e. Initiating, by the service provider, a security flow (registration is used to provide trust that the user is who the user says they are) (Hinton, [0045]).
f. Providing, by the service provider, access to a secure page at the console based at least in part on the security flow (user establishes a secure session) (Hinton, [0079]).
As to claims 2, 15, and 19, Hinton teaches the security flow comprises redirecting the browser application to an identity provider for authenticating a requester of the sign-up request (identity provider) (Hinton, [0074]).
As to claims 3 and 16, Hinton teaches redirecting the browser application to the identity provider comprises transmitting, by the sign-up portal, a security request message to the browser application (F-SSO redirects to the user’s browser) (Hinton, [0079]).
As to claims 4, 17, and 20, Hinton teaches the security request message comprises a security assertion markup language (SAML) request (SAML assertion) (Hinton, [0075]).
As to claim 5, Hinton teaches the service provider comprises a cloud infrastructure service provider comprising the console and the sign-in portal (cloud infrastructure includes network, servers, operating systems, storage, and applications) (Hinton, [0056]).
As to claim 6, Hinton teaches the second redirect message identifies the sign-in portal of the service provider (with the redirect, the browser requests a key pair in the provider’s cloud infrastructure) (Hinton, [0079]).
As to claim 7, Hinton teaches the first redirect message originates from an identity provider that received the sign-up request (registration (sign-up) request is sent to cloud provider for processing the request) (Hinton, [0075-0076]).
As to claim 8, Hinton teaches the sign-in portal is configured to perform authentication of a requester of the sign-up request (authentication is part of the registration process) (Hinton, [0045]).
As to claim 9, Hinton teaches the second redirect message includes a query string that identifies the requester and/or the service provider (the purpose of registering of a user to an SSO is for the service provider to authenticate the user and the service(s) they are requesting) (Hinton, [0079]).
As to claim 10, Hinton teaches the sign-in portal is configured to identify a new account associated with the requestor (CRL-like lists are used to match accounts with users when authenticating) (Hinton, [0089]).
As to claim 11, Hinton teaches the security flow comprises:
a. Receiving, by the sign-in portal of the service provider, a security response message from the browser application (user requests access to a service) (Hinton, 0045]).
b. Transmitting, by the sign-in portal of the service provider, a security token and an identity token to the browser application (security token includes user information and is sent to the user) (Hinton, [0045-0046]).
As to claim 12, Hinton teaches the security flow further comprises:
a. Receiving, by the console of the service provider, the security token and the identity token from the browser application (F-SSO receives security token) (Hinton, [0045-0046]).
b. Transmitting, by the console of the service provider, an authentication message to the browser application (user sends attributes cookie to service provider to access resource) (Hinton, [0046-0047]).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over US PG Pub. No. 2012/0011578 to Hinton et al. (hereinafter Hinton) as applied to claim 1 above, and further in view of US Patent No. 7,984,484 to Rakowski et al. (hereinafter Rakowski).
As to claim 13, Hinton does not explicitly recite using SPA. However, in an analogous art, Rakowski teaches the authentication message comprises a Secure Password Authentication (SPA) message (SPA is used for security purposes) (Rakowski, 7:4-12).
Therefore, one of ordinary skill in the art before the effective filing date of the instant invention would have been motivated to implement the cloud SSO scheme of Hinton with the use of Secure Password Authentication of Rakowski in order to messages more secure as suggested by Rakowski (Rakowski, 7:4-12).
Double Patenting
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of US Patent No. 11,895,106 and claims 1-20 of US Patent No. 12,261,834. Although the claims at issue are not identical, they are not patentably distinct from each other because the limitations of the patented independent claims are a combination of the instant application’s claims and they do not have the specificity of the patented claims. The instant’s application independent limitations are much more general in scope with other limitations that echo the patented limitations are present in dependent claims. Claims 1-3, 5, 10, and 13 of the instant application are present in the patented independent claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to WILLIAM S POWERS whose telephone number is (571)272-8573. The examiner can normally be reached M-F 7:30-17:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L Ortiz-Criado can be reached at (571) 272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/WILLIAM S POWERS/Primary Examiner, Art Unit 2496