Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
1. This action is responsive to: an original application filed on 28 February 2025 with acknowledgement that this application is a continuation Japanese Application filed on 1 March 2024.
2. Claims 1-15 are currently pending. Claims 1, 8, 9, and 15, are independent claims.
3. The IDS submitted on 28 February 2025 has been considered.
Claim Rejections – 35 USC § 103
4. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
5. Claims 1-2, 8-9, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Hori U.S. Patent Application Publication No. 2021/0281556 (hereinafter ‘556) in view of Lamber U.S. Patent Application Publication No. 2014/0156998 (hereinafter ‘998).
As to independent claim 1, “An authentication apparatus that authenticates an authentication target apparatus, comprising: an acquisition unit configured to acquire, from the authentication target apparatus, information indicating secret data stored in the authentication target apparatus, a first hash value that corresponds to the secret data” is taught in ‘556 Abstract, Fig. 2, paragraphs 4 and 23, note ‘secret data’ is interpreted equivalent to the password;
the following is not explicitly taught in ‘556:
“and a repeat count N, wherein N is an integer of 2 or more; an operation unit configured to obtain a second hash value from input data that is based on the secret data, by performing N repeated operations using a one-way function” however ‘998 teaches obtaining a hiding value h and using the hiding value h to compute a masked response to a challenge using a function f(*) that could be a cryptographic hash function that accepts the hiding value h, as input in paragraphs 42-45;
“and an authentication unit configured to authenticate the authentication target apparatus by comparing the first hash value acquired by the acquisition unit from the authentication target apparatus with the second hash value obtained by the operation unit” however ‘998 teaches the functions are choose so that the masked response matches expected matched response in paragraphs 51 and 72.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of an authentication system for authentication of target apparatus taught in ‘556 to include a means to utilize a repeat count N (i.e. hiding value) to obtain a second hash value. One of ordinary skill in the art would have been motivated to perform such a modification to mitigate replay attacks between devices see ‘998 paragraph 58.
As to dependent claim 2, “The authentication apparatus according to claim 1, wherein the authentication unit determines that authentication of the authentication target apparatus is unsuccessful if the first hash value does not match the second hash value” is taught in ‘998 paragraphs 51 and 72.
As to independent claim 8. An image forming apparatus that comprises an authentication apparatus, and from which a unit is detachable, the unit including an authentication target apparatus to be authenticated by the authentication apparatus, wherein the authentication apparatus includes: an acquisition unit configured to acquire, from the authentication target apparatus, information indicating secret data stored in the authentication target apparatus, a first hash value that corresponds to the secret data” is taught in ‘556 Abstract, Fig. 2, paragraphs 4, 21, and 23, note ‘secret data’ is interpreted equivalent to the password;
the following is not explicitly taught in ‘556:
“and a repeat count N, wherein N is an integer of 2 or more; an operation unit configured to obtain a second hash value from input data that is based on the secret data, by performing N repeated operations using a one-way function” however ‘998 teaches obtaining a hiding value h and using the hiding value h to compute a masked response to a challenge using a function f(*) that could be a cryptographic hash function that accepts the hiding value h, as input in paragraphs 42-45;
“and an authentication unit configured to authenticate the authentication target apparatus by comparing the first hash value acquired by the acquisition unit from the authentication target apparatus with the second hash value obtained by the operation unit” however ‘998 teaches the functions are choose so that the masked response matches expected matched response /as well provides examples of the first and second device ‘The first device 2 may be printer and the second device 4 may be a component of the printer, such as an ink cartridge’ in paragraphs, 30, 51 and 72.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of an authentication system for authentication of target apparatus taught in ‘556 to include a means to utilize a repeat count N (i.e. hiding value) to obtain a second hash value. One of ordinary skill in the art would have been motivated to perform such a modification to mitigate replay attacks between devices see ‘998 paragraph 58.
As to independent claim 9, “An authentication target apparatus that is to be authenticated by an authentication apparatus, comprising: a storage unit configured to store information indicating a plurality of pieces of secret data, first hash values that respectively correspond to the plurality of pieces of secret data” is taught in ‘556 Abstract, Fig. 2, paragraphs 4 and 23, note ‘secret data’ is interpreted equivalent to the password;
the following is not explicitly taught in ‘556:
“and a repeat count N, wherein N is an integer of 2 or more; and a processing unit configured to perform processing of transmitting the information stored in the storage unit to the authentication apparatus in accordance with an instruction from the authentication apparatus” however ‘998 teaches obtaining a hiding value h and using the hiding value h to compute a masked response to a challenge using a function f(*) that could be a cryptographic hash function that accepts the hiding value h, as input / that transmits information to an authentication apparatus (i.e. first device and second device exchange response values/challenges) in paragraphs 42-45, 51-52, and 72;
“wherein a first hash value corresponding to secret data of the plurality of pieces of secret data is obtained from input data that is based on the secret data, by N repeated operations using a one-way function” however ‘998 teaches computing the hash value based on a plurality pieces of data paragraphs 42-46 and 50.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of an authentication system for authentication of target apparatus taught in ‘556 to include a means to utilize a repeat count N (i.e. hiding value) to obtain a second hash value. One of ordinary skill in the art would have been motivated to perform such a modification to mitigate replay attacks between devices see ‘998 paragraph 58.
As to independent claim 15. A replacement unit for an image forming apparatus, comprising an authentication target apparatus that is to be authenticated by an authentication apparatus of the image forming apparatus, wherein the authentication target apparatus includes: a storage unit configured to store information indicating a plurality of pieces of secret data, first hash values that respectively correspond to the plurality of pieces of secret data” is taught in ‘556 Abstract, Fig. 2, paragraphs 4, 21, and 23, note ‘secret data’ is interpreted equivalent to the password;
the following is not explicitly taught in ‘556:
“and a repeat count N, wherein N is an integer of 2 or more; and a processing unit configured to perform processing of transmitting the information stored in the storage unit to the authentication apparatus in accordance with an instruction from the authentication apparatus” however ‘998 teaches obtaining a hiding value h and using the hiding value h to compute a masked response to a challenge using a function f(*) that could be a cryptographic hash function that accepts the hiding value h, as input / that transmits information to an authentication apparatus (i.e. first device and second device exchange response values/challenges) in paragraphs 42-45, 51-52, and 72;
“and the a first hash value corresponding to secret data of the plurality of pieces of secret data is obtained from input data that is based on the secret data, by N repeated operations using a one-way function” however ‘998 teaches the functions are choose so that the masked response matches expected matched response /as well provides examples of the first and second device ‘The first device 2 may be printer and the second device 4 may be a component of the printer, such as an ink cartridge’ in paragraphs, 30, 42-46, 51 and 72.
6. Claims 3-4 and 10-11, are rejected under 35 U.S.C. 103 as being unpatentable over Hori U.S. Patent Application Publication No. 2021/0281556 (hereinafter ‘556) in view of Lamber U.S. Patent Application Publication No. 2014/0156998 (hereinafter ‘998) in further view of Daemen et al. U.S. Patent Application Publication No. 2019/0222421 (hereinafter ‘421).
As to dependent claim 3, the following is not explicitly taught in ‘556 and ‘998: “The authentication apparatus according to claim 1, wherein the acquisition unit is further configured to acquire, from the authentication target apparatus, signature information for verifying the information indicating the repeat count, and the authentication unit determines that authentication of the authentication target apparatus is unsuccessful if verification using the signature information is unsuccessful” however ‘421 teaches an authentication process that utilized signature calculation in order to perform authentication in paragraphs 105-110.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of an authentication system for authentication of target apparatus taught in ‘556 and ‘998 to include a means to utilize signature calculation to authenticate new apparatus. One of ordinary skill in the art would have been motivated to perform such a modification to protect against non-authorized access see ‘421 paragraphs 2-5.
As to dependent claim 4, “The authentication apparatus according to claim 3, wherein the authentication target apparatus stores a plurality of pieces of secret data and a plurality of first hash values that correspond to the plurality of pieces of secret data, and the signature information is information for verifying the information indicating the repeat count, and information indicating a third hash value that is obtained, using the one-way function, based on a value in which the plurality of first hash values are concatenated with each other” is taught in ‘421 paragraphs 105 -110.
As to dependent claim 10, “The authentication target apparatus according to claim 9, wherein the storage unit further stores signature information for verifying the information indicating the repeat count” is shown in ‘421 paragraphs 105-110.
As to dependent claim 11, “The authentication target apparatus according to claim 10, wherein the signature information is information for verifying the information indicating the repeat count, and information indicating a third hash value that is obtained, using the one-way function, based on a value in which the plurality of first hash values respectively corresponding to the plurality of pieces of secret data are concatenated with each other” is disclosed in ‘421 paragraphs 105-110.
7. Claims 5-7 and 12-14, are rejected under 35 U.S.C. 103 as being unpatentable over Hori U.S. Patent Application Publication No. 2021/0281556 (hereinafter ‘556) in view of Lamber U.S. Patent Application Publication No. 2014/0156998 (hereinafter ‘998) in further view of Daemen et al. U.S. Patent Application Publication No. 2019/0222421 (hereinafter ‘421) in further view of Collinge et al. U.S. Patent Application Publication No. 2015/0058949 (hereinafter ‘949).
As to dependent claim 5, the following is not explicitly taught in ‘556, ‘998, and ‘421: “The authentication apparatus according to claim 4, wherein the acquisition unit is further configured to acquire the plurality of first hash values and the third hash value from the authentication target apparatus, the operation unit is configured to obtain a fourth hash value, using the one-way function, based on a value in which the plurality of first hash values are concatenated with each other, and the authentication unit determines that authentication of the authentication target apparatus is unsuccessful if the third hash value acquired by the acquisition unit from the authentication target apparatus does not match the fourth hash value obtained by the operation unit” however ‘949 teaches comparing multiple hash values, i.e. first, second, third, and fourth for authentication see the Abstract and paragraphs 8-11.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention of an authentication system for authentication of target apparatus taught in ‘556, ‘998, and ‘421 to include a means to utilize a plurality of hash values for authentication. One of ordinary skill in the art would have been motivated to perform such a modification because stronger authentication method are needed see ‘949 paragraph 6.
As to dependent claim 6, “The authentication apparatus according to claim 1, wherein the acquisition unit is further configured to acquire an identifier of the authentication target apparatus from the authentication target apparatus, and the input data is concatenated data of the secret data and data indicating the identifier” is taught in ‘949 paragraphs 8-11.
As to dependent claim 7, “The authentication apparatus according to claim 6, wherein the operation unit is configured to obtain the second hash value, by obtaining first output data using the input data as an input to the one-way function, and obtaining (k+1)-th output data using concatenated data of k-th output data and the data indicating the identifier as an input to the one-way function in a repeated manner from k=1 to N−1” is shown in ‘998 paragraphs 42-43, 61, and 72.
As to dependent claim 12, “The authentication target apparatus according to claim 9, wherein the input data is concatenated data of the secret data and data indicating an identifier of the authentication target apparatus” is shown in ‘949 paragraphs 8-11.
As to dependent claim 13, “The authentication target apparatus according to claim 12, wherein the first hash value corresponding to the secret data is obtained, by obtaining first output data using the input data as an input to the one-way function, and obtaining (k+1)-th output data using concatenated data of k-th output data and the data indicating the identifier as an input to the one-way function in a repeated manner from k=1 to N−1” is disclosed in ‘998 paragraphs 42-43, 61, and 72.
As to dependent claim 14, “The authentication target apparatus according to claim 9, wherein, if a number of times of reading the plurality of pieces of secret data by the authentication apparatus reaches an upper limit, the processing unit is further configured not to respond to an instruction to read out secret data from the authentication apparatus or to notify the authentication apparatus that the secret data is not to be transmitted” is taught in ‘949 paragraphs 65 and 73.
Conclusion
8. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ELLEN C TRAN whose telephone number is (571) 272-3842. The examiner can normally be reached Monday-Friday.
Examiner interviews are available via telephone and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeff Pwu can be reached at 571-272-6798. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
____________________________/ELLEN TRAN/Primary Examiner, Art Unit 2433 10 July 2026