DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on April 18, 2025 and July 17, 2026 have been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Form PTO-1449 is signed and attached hereto.
Drawings
The drawings filed on February 28, 2025 are accepted.
Specification
The specification filed February 28, 2025 is accepted.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-22 are rejected under 35 U.S.C. 103 as being unpatentable over Dispensa US 2009/0300745 A1 in view of Oikawa et al. US 2009/0235345 A1 [hereinafter Oikawa].
As per claim 1, Dispensa teaches a method for performing digital authentication, the method comprising:
providing a first login access point associated with a service provider for displaying on a first visual user interface [paragraph 0081], the first login access point including:
a first login credential request access point [paragraph 0081], and
a first login mode [paragraph 0081],
receiving a login request from a user device associated with a user [paragraph 0081], the login request including:
a user identity data element [paragraph 0081], and
a login request data element associated with the first login credential request access point [paragraph 0081];
retrieving, based on the login request, a supplemental data element from a database through a recording server [paragraphs 0081-0082];
determining whether the login request data element matches the supplemental data element [paragraphs 0081-0082];
in response to a determination that the login request data element matches the supplemental data element [paragraphs 0081-0082];
performing a two-factor authentication on the user device when receiving a two-factor authentication request from the user device [paragraphs 0083-0090];
configuring the first login mode as an authenticated status in response to the two-factor authentication [paragraphs 0083-0090];
providing a second login access point associated with the service provider for display on a second visual user interface [paragraphs 0083-0090],
the second login access point including:
a second login credential request access point [paragraphs 0083-0090]; and
configuring the second login mode as the authenticated status in response to the first login mode being configured as the authenticated status [paragraphs 0083-0090].
In the same field of endeavor, Oikawa teaches an authentication system including providing a login access point associated with a service provider for displaying on a visual user interface
a first login mode, the first login mode indicating an unauthenticated status [paragraphs 0104, 0113-0114 and 0147-0152]; and
a second login mode, the second login mode indicating the unauthenticated status [paragraphs 0104, 0113-0114 and 0147-0152]. It would have been obvious to one having ordinary skill in the art before the filing date of the application to employ the teachings of Oikawa within the system of Dispensa in order to enhance security of the system by maintaining and displaying user authentication status on user interface.
As per claim 11, Dispensa teaches a system for performing digital authentication, the system comprising:
an authentication server in communication with a user device associated with a user [paragraphs 0081-0082], the authentication server configured to:
receive a login request from the user device, the login request including a user identity data element and a login request data element [paragraphs 0081-0082];
retrieve, based on the login request, a supplemental data element associated with the user from a recording server [paragraphs 0081-0082];
determine whether the login request data element matches the supplemental data element [paragraphs 0081-0082]; and
in response to a determination that the login request data element matches the supplemental data element:
perform a two-factor authentication on the user device when receiving a two-factor authentication request from the user device [paragraphs 0083-0090]; and
configure the user device as authenticated in response to the two-factor authentication [paragraphs 0083-0090].
In the same field of endeavor, Oikawa teaches an authentication system including, in response to configuring a user device as authenticated: configure a first login mode as an authenticated status and configure a second login mode as the authenticated status [paragraphs 0104, 0113-0114 and 0147-0152]. It would have been obvious to one having ordinary skill in the art before the filing date of the application to employ the teachings of Oikawa within the system of Dispensa in order to enhance security of the system by maintaining authenticated status for authenticated user login.
As per claim 2, Dispensa further teaches the method wherein the first login access point is a trusted access point [paragraphs 0081-0090].
As per claim 3, Dispensa further teaches the method wherein the first login access point includes a user input field associated with the first login credential request access point [paragraphs 0081-0090].
As per claim 4, Dispensa further teaches the method wherein the login request data element includes at least one of a username, a password, a personal identification number, an account number, an email address, a biometric identification, or an answer to a security question [paragraphs 0081-0090].
As per claim 5, Dispensa further teaches the method further comprising: providing a functionality to the user device associated with the user through the first login access point when the first login mode indicates the authenticated status [paragraphs 0081-0090].
As per claim 6, Dispensa further teaches the method wherein the supplemental data element includes at least one of a username, a password, a personal identification number, an account number, an email address, a biometric identification, or a credential for a two-factor authentication service associated with the user [paragraphs 0081-0090].
As per claim 7, Dispensa further teaches the method further comprising: in response to a determination that the login request data element does not match the supplemental data element, providing a third login access point associated with the service provider for displaying on the first visual user interface, wherein the third login access point is the same as the first login access point [paragraphs 0081-0090].
As per claim 8, Dispensa further teaches the method wherein the login request is a first login request, the method further comprising: receiving a second login request, wherein a type of the second login request is different from a type of the first login request [paragraphs 0081-0090].
As per claim 9, Dispensa further teaches the method further comprising: receiving a third login request, wherein a type of the third login request is the same as the type of the first login request [paragraphs 0081-0090].
As per claim 10, Dispensa further teaches the method wherein the first and second login access points are associated with different services [paragraphs 0081-0090].
As per claim 12, Dispensa further teaches the system wherein the login request is received via a login access point, the login access point being associated with a service provider; and the first login mode is configured by default to indicate an unauthenticated status.
As per claim 13, Dispensa further teaches the system wherein the login access point is a trusted access point [paragraphs 0081-0090].
As per claim 14, Dispensa further teaches the system wherein the login access point includes a user input field [paragraphs 0081-0090].
As per claim 15, Dispensa further teaches the system wherein the login access point is a first login access point, and a second login access point is associated with the service provider and includes a second login credential request access point; and the second login mode is configured by default to indicate the unauthenticated status [paragraphs 0081-0090].
As per claim 16, Dispensa further teaches the system wherein the first and second login access points are associated with different services [paragraphs 0081-0090].
As per claim 17, Dispensa further teaches the system wherein the login request data element includes at least one of a username, a password, a personal identification number, an account number, an email address, a biometric identification, or an answer to a security question [paragraphs 0081-0090].
As per claim 18, Dispensa further teaches the system wherein the supplemental data element includes at least one of a username, a password, a personal identification number, an account number, a biometric identification, or a credential for a two-factor authentication service associated with the user [paragraphs 0081-0090].
As per claim 19, Dispensa further teaches the system wherein the login request is a first login request, the authentication server further configured to: in response to a determination that the login request data element does not match the supplemental data element, receive a second login request from the user device [paragraphs 0081-0090].
As per claim 20, Dispensa further teaches the system wherein a type of the second login request is different from a type of the first login request [paragraphs 0081-0090].
As per claim 21, Dispensa further teaches the system wherein the authentication server is further configured to: receive a third login request, wherein a type of the third login request is the same as the type of the first login request [paragraphs 0081-0090].
As per claim 22, Dispensa further teaches the system wherein the authentication server is further configured to: transmit the login request data element to the recording server for retrieving the supplemental data element from the recording server [paragraphs 0081-0090].
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BEEMNET W DADA whose telephone number is (571)272-3847. The examiner can normally be reached Monday-Friday, 9am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
BEEMNET W. DADA
Primary Examiner
Art Unit 2435
/BEEMNET W DADA/ Primary Examiner, Art Unit 2435