DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-3, 6-7, 9-11, 15, 18-20 are rejected under 35 U.S.C. 101 because the claimed invention lacks patentable utility. Please note that claims 1 recites a system that concludes with sending to a host device, the public identifier and the public key, which appears to be an intermediate step. Claims 6 recite similar limitations. Sending information to a host device without any disclosure of what that information is being used lacks patentable utility. Claims 4 and 5 appears to provide the utility by using the public identifier and the public key to verify an identity. Similarly claims 15 concludes with just generating a public key and a private key without establishing any utility. Dependent claims 2-3, 7, 9-11 and 19-20 also do not establish any utility and just further limit independent claims without establishing the utility. Correction/Clarification is required.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “a first asymmetric generator”, “a second asymmetric generator”, “an encryptor”, “first decryptor”, “second decryptor” and “a merging component”.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-9 and 12-13 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Le Saint (US 2018/0205539 A1), hereinafter, “Le Saint”.
Regarding Claim 1, Le Saint discloses a system comprising:
a first asymmetric generator configured to generate a public identifier and a private identifier (See, Paragraph 0005, “A blinded user device public key may be generated from a user device public key stored on the portable user device and a cryptographic nonce (e.g., a random value). Similarly, a blinded user device private key may be generated from a user device private key corresponding the user device public key and the cryptographic nonce”);
a second asymmetric generator configured to generate a public key and a private key (See, Paragraph 0046, “At step 201, access device 102 generates an ephemeral public/private key pair. The public/private key pair may be generated in any suitable manner, such as through the use of a random or pseudo-random number generator. In addition, the key pair may be generated in any suitable key format, such as RSA or elliptic curve cryptography (ECC). In some embodiments, the ephemeral key pair may be generated before portable user device 101 enters the contactless field of access device 102”); and
at least one processor configured to send, to a host device, the public identifier and the public key (See, Paragraph 0082, “In some embodiments, user device data may include other data, such as a user device identifier and/or the cryptographic nonce used to generate the blinded user device public key” and Paragraph 0063, “At step 303, encrypted user device data and a blinded user device public key are received from portable user device 101. A “blinded user device public key” may be generated from a user device public key. For example, the blinded user device public key may be a combination of the user device public key and a cryptographic nonce. The “encrypted user device data” may include any data or information associated with a user device. For example, in some embodiments, the encrypted user device data may include an encrypted user device certificate and the cryptographic nonce used to generate the blinded user device public key”.
Regarding Claim 2, the rejection of claim 1 is incorporated and Le Saint further discloses wherein the processor is further configured to: generate a random number; wherein the random number is used an input to the second asymmetric generator to generate the public key and the private key (See, Paragraphs 0005 and 0046).
Regarding Claim 3, the rejection of claim 1 is incorporated and Le Saint further discloses comprising an encryptor configured to generate a certificate, wherein the processor is further configured to send, to the host device, the certificate (See, Paragraphs 0005 and 0063, Note: examiner is interpreting the encrypted used device data as a certificate).
Regarding Claim 4, the rejection of claim 3 is incorporated and Le Saint further discloses wherein the host device is configured to verify an identity using the public identifier, the certificate, and the public key (See, Paragraph 0066).
Regarding Claim 5, the rejection of claim 1 is incorporated and Le Saint further discloses wherein the host device is configured to verify an identity using the public identifier and the public key (See, Paragraph 0066).
Regarding Claim 6, Le Saint discloses a method comprising:
generating a public identifier and a private identifier (See, Paragraph 0005, “A blinded user device public key may be generated from a user device public key stored on the portable user device and a cryptographic nonce (e.g., a random value). Similarly, a blinded user device private key may be generated from a user device private key corresponding the user device public key and the cryptographic nonce.”), wherein the public identifier is generated using a device secret (See, Paragraph 0082, “In some embodiments, user device data may include other data, such as a user device identifier and/or the cryptographic nonce used to generate the blinded user device public key”);
generating a public key and a private key (See, Paragraph 0046, “At step 201, access device 102 generates an ephemeral public/private key pair. The public/private key pair may be generated in any suitable manner, such as through the use of a random or pseudo-random number generator. In addition, the key pair may be generated in any suitable key format, such as RSA or elliptic curve cryptography (ECC). In some embodiments, the ephemeral key pair may be generated before portable user device 101 enters the contactless field of access device 102”); and
sending, to a host device, a certificate generated using a message from the host device (See, Paragraph 0005, “a shared secret may be generated using the blinded user device private key and the ephemeral public key. The shared secret may be used derive a session key, and the session key may be used to encrypt user device data such as a user device certificate” and Paragraph 0063, “At step 303, encrypted user device data and a blinded user device public key are received from portable user device 101. A “blinded user device public key” may be generated from a user device public key. For example, the blinded user device public key may be a combination of the user device public key and a cryptographic nonce. The “encrypted user device data” may include any data or information associated with a user device. For example, in some embodiments, the encrypted user device data may include an encrypted user device certificate and the cryptographic nonce used to generate the blinded user device public key”, Note: examiner is interpreting the encrypted used device data as a certificate)), the public identifier (See, Paragraph 0082, “In some embodiments, user device data may include other data, such as a user device identifier and/or the cryptographic nonce used to generate the blinded user device public key”), and the public key (See, Paragraph 0063, “At step 303, encrypted user device data and a blinded user device public key are received from portable user device 101. A “blinded user device public key” may be generated from a user device public key. For example, the blinded user device public key may be a combination of the user device public key and a cryptographic nonce. The “encrypted user device data” may include any data or information associated with a user device. For example, in some embodiments, the encrypted user device data may include an encrypted user device certificate and the cryptographic nonce used to generate the blinded user device public key).
Regarding Claim 7, the rejection of claim 6 is incorporated and Le Saint further discloses wherein the certificate is generated by an encryptor (See, Paragraph 0005).
Regarding Claim 8, the rejection of claim 6 is incorporated and Le Saint further discloses wherein the host device is configured to verify an identity using the public identifier, the certificate, and the public key (See, Paragraph 0066).
Regarding Claim 9, the rejection of claim 6 is incorporated and Le Saint further discloses generating a random number, wherein the random number is used an input to generate the public key and the private key (See, Le Saint, Paragraphs 0005 and 0046).
Regarding Claim 12, the rejection of claim 6 is incorporated and Le Saint further discloses wherein the host device is configured to verify an identity by concatenating the message and the certificate to provide first data (See, Paragraph 0005).
Regarding Claim 13, the rejection of claim 12 is incorporated and Le Saint further discloses wherein verifying the identity comprises decrypting the first data using the public key to provide second data (See, Paragraphs 0029 and 0069).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 10, 15-17 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Le Saint in view of Gotze et al. (US 2015/0092939 A1), hereinafter, “Gotze”.
Regarding Claim 15, Le Saint discloses a system comprising:
a first asymmetric generator configured to generate a public identifier and a private identifier (See, Paragraph 0005, “A blinded user device public key may be generated from a user device public key stored on the portable user device and a cryptographic nonce (e.g., a random value). Similarly, a blinded user device private key may be generated from a user device private key corresponding the user device public key and the cryptographic nonce.”), wherein the public identifier is generated using the device secret (See, Paragraph 0082, “In some embodiments, user device data may include other data, such as a user device identifier and/or the cryptographic nonce used to generate the blinded user device public key”); and
a second asymmetric generator configured to generate a public key and a private key, wherein the random number is used an input to the second asymmetric generator (See, Paragraph 0046, “At step 201, access device 102 generates an ephemeral public/private key pair. The public/private key pair may be generated in any suitable manner, such as through the use of a random or pseudo-random number generator. In addition, the key pair may be generated in any suitable key format, such as RSA or elliptic curve cryptography (ECC). In some embodiments, the ephemeral key pair may be generated before portable user device 101 enters the contactless field of access device 102” also see Paragraph 0005).
While Le Saint discloses using random number generator, Le Saint fails to discloses wherein the random number is generated using a physical unclonable function (PUF).
However, providing random numbers using PUF is well known in the art of computer security. Gotze discloses a system wherein a random number is generated using a physical unclonable function (PUF) (See, Paragraph 0012).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate, in the system of Le Saint, a random number using physical unclonable function as taught by Gotze “because it may be used to provide a unique, repeatable, and unpredictable random value within an integrated circuit” (See, Gotze, Paragraph 0012).
Regarding Claim 16, the rejection of claim 15 is incorporated and the combination of Le Saint and Gotze further discloses a first decryptor configured to provide a first result based on a certificate (See, Le Saint, Paragraph 0005); and a second decryptor configured to provide a second result based on the first result, wherein the second result is used to verify an identity (See, Le Saint, Paragraphs 0029 and 0069).
Regarding Claim 17, the rejection of claim 15 is incorporated and the combination of Le Saint and Gotze further discloses wherein verifying the identity comprises concatenating a message and the certificate (See, Le Saint, Paragraph 0005).
Regarding Claim 20, the rejection of claim 15 is incorporated and the combination of Le Saint and Gotze further discloses further comprising a merging component configured to concatenate a message and a certificate to provide first data, wherein the first data is used as an input to the first decryptor to provide the first result (See, Le Saint, Paragraphs 0005, 0029 and 0069).
Regarding Claim 10, the rejection of claim 9 is incorporated and Le Saint further discloses does not explicitly disclose the random number is generated using a physical unclonable function.
However, providing random numbers using PUF is well known in the art of computer security. Gotze discloses a system wherein a random number is generated using a physical unclonable function (PUF) (See, Paragraph 0012).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate, in the system of Le Saint, a random number using physical unclonable function as taught by Gotze “because it may be used to provide a unique, repeatable, and unpredictable random value within an integrated circuit” (See, Gotze, Paragraph 0012).
Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Le Saint in view of Jeffrey (US 2015/0256522 A1), hereinafter, “Jeffrey”.
Regarding Claim 11, the rejection of claim 6 is incorporated and Le Saint further discloses wherein the public identifier is generated using a derived secret as an input to the first asymmetric generator (See, Paragraphs 0018 and 0025).
Le Saint fails to disclose using the device secret as an input to a message authentication code to generate a derived secret.
However, using the secret key as an input to a message authentication code to generate a derived secret is well known in the art of computer security. Jeffrey disclose using a device secret as an input to a message authentication code to generate a derived secret (See, Paragraph 0133).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to use, in the system of Le Saint, the secret key as an input to a message authentication code to generate a derived secret as taught by Jeffrey because it “is designed to provide a measure of message authenticity (i.e.--an attacker would need to know the secret MAC key in order to forge a message to a given recipient)” (See, Jeffrey, Paragraph 0133).
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1, 3-5 and 6-8 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim 7 of U.S. Patent No. 11,323,275 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because claims 1 and 3-5 simply require additional elements of processor and encryptor. Implementing the method using processor and encryptor are obvious to one of ordinary skill in the art in order to implement the method of claim 7 of U.S. Patent No. 11,323,275 B2.
Claims 2 and 9 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim 7 of U.S. Patent No. 11,323,275 B2 in view of Le Saint.
Claims 2 and 9 require following additional limitation: generate a random number; wherein the random number is used an input to the second asymmetric generator to generate the public key and the private key.
Le Saint discloses generating a random number; wherein the random number is used an input to the second asymmetric generator to generate the public key and the private key (See, Paragraphs 0005 and 0046).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate a random number; wherein the random number is used an input to the second asymmetric generator to generate the public key and the private key as taught by Le Saint so that public key and private key to create unpredictable values for securing data.
Claims 12-14 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim 4 of U.S. Patent No. 11,323,275 B2 in view of Le Saint.
Claims 12-14 requires following additional limitation: a first asymmetric generator configured to generate a public identifier and a private identifier and a second asymmetric generator configured to generate a public key and a private key.
La Saint discloses a first asymmetric generator configured to generate the first public identifier and private identifier (See, Paragraphs 0005) and a second asymmetric generator configured to generate a public key and a private key (See, Paragraph 0046).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate have a first asymmetric generator configured to generate the first public identifier and private identifier and a second asymmetric generator configured to generate a public key and a private key as taught by La Saint in order to generate blinded public adj private keys which are used to verify the user device certificate without the certificate being transmitted in cleartext.
Claim 10 is rejected on the ground of nonstatutory double patenting as being unpatentable over claim 7 of U.S. Patent No. 11,323,275 B2 in view of Le Saint and further in view of Gotze.
Claim 10 requires following additional limitation: the random number is generated using a physical unclonable function.
Gotze discloses a system wherein a random number is generated using a physical unclonable function (PUF) (See, Paragraph 0012).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate a random number using physical unclonable function as taught by Gotze “because it may be used to provide a unique, repeatable, and unpredictable random value within an integrated circuit” (See, Gotze, Paragraph 0012).
Claim 11 is rejected on the ground of nonstatutory double patenting as being unpatentable over claim 7 of U.S. Patent No. 11,323,275 B2 in view of Le Saint and further in view of Jeffrey.
Claim 11 requires following additional limitation: wherein the public identifier is generated using a derived secret as an input to the first asymmetric generator (See, Paragraphs 0018 and 0025).
Le Saint fails to disclose using the device secret as an input to a message authentication code to generate a derived secret.
Jeffrey disclose using a device secret as an input to a message authentication code to generate a derived secret (See, Paragraph 0133).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to use the secret key as an input to a message authentication code to generate a derived secret as taught by Jeffrey because it “is designed to provide a measure of message authenticity (i.e.--an attacker would need to know the secret MAC key in order to forge a message to a given recipient)” (See, Jeffrey, Paragraph 0133).
Claims 15, 18 and 19 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim 7 of U.S. Patent No. 11,323,275 B2 in view of Gotze.
Claims 15, 18 and 19 requires following additional limitation: a physical unclonable function configured to generate a random number.
Gotze discloses a system wherein a random number is generated using a physical unclonable function (PUF) (See, Paragraph 0012).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate a random number using physical unclonable function as taught by Gotze “because it may be used to provide a unique, repeatable, and unpredictable random value within an integrated circuit” (See, Gotze, Paragraph 0012).
Claims 16, 17 and 20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim 11 of U.S. Patent No. 11,323,275 B2 in view of Gotze and Le Saint.
Claims 16 and 17 require following additional limitations: a physical unclonable function configured to generate a random number; a first asymmetric generator configured to generate a public identifier and a private identifier and a second asymmetric generator configured to generate a public key and a private key.
Gotze discloses a system wherein a random number is generated using a physical unclonable function (PUF) (See, Paragraph 0012).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate a random number using physical unclonable function as taught by Gotze “because it may be used to provide a unique, repeatable, and unpredictable random value within an integrated circuit” (See, Gotze, Paragraph 0012).
La Saint discloses a first asymmetric generator configured to generate the first public identifier and private identifier (See, Paragraphs 0005) and a second asymmetric generator configured to generate a public key and a private key (See, Paragraph 0046).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to generate have a first asymmetric generator configured to generate the first public identifier and private identifier and a second asymmetric generator configured to generate a public key and a private key as taught by La Saint in order to generate blinded public adj private keys which are used to verify the user device certificate without the certificate being transmitted in cleartext.
Claim 20 requires following additional limitation: a merging component configured to concatenate a message and a certificate to provide first data, wherein the first data is used as an input to the first decryptor to provide the first result.
Le Saint discloses further comprising a merging component configured to concatenate a message and a certificate to provide first data, wherein the first data is used as an input to the first decryptor to provide the first result (See, Le Saint, Paragraphs 0005, 0029 and 0069).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to concatenate a message and a certificate to provide first data, wherein the first data is used as an input to the first decryptor to provide the first result in order to generate blinded public adj private keys which are used to verify the user device certificate without the certificate being transmitted in cleartext.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 12-19 of U.S. Patent No. 12,284,292 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because claims 12-19 of U.S. Patent No. 12,284,292 B2 teaches most limitations of claims 1-20 and other limitation such as providing encryptors and decryptors are just names of the function performing the steps that are already taught by claims 12-19 of U.S. Patent No. 12,284,292 B2.
Allowable Subject Matter
Claim 14 would be allowable by filing a terminal disclaimer to overcome the non-statutory double patenting rejection, set forth in this Office action and to include all of the limitations of the base claim and any intervening claims.
Claims 18 and 19 would be allowable if rewritten to overcome the rejection(s) under 35 U.S.C. 101 and by filing a terminal disclaimer to overcome the non-statutory double patenting rejection, set forth in this Office action and to include all of the limitations of the base claim and any intervening claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to YOGESH PALIWAL whose telephone number is (571)270-1807. The examiner can normally be reached M-F 9:00AM-5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571)270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/YOGESH PALIWAL/Primary Examiner, Art Unit 2435