Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments about the 35 U.S.C 101 with respect to amendment filed on 05/12/2026 have been fully considered and are persuasive. The previous rejection 35 U.S.C 101 has been withdrawn.
Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1, 9 and 17 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Hecht (U.S. Pub. U.S. Pub. 2020/0057848 A1)
With respect to claim 1, Hecht discloses a computer-implemented method comprising:
generating an authentication key corresponding to a user account of an authenticated data structure of a distributed digital ledger transaction network (i.e., “the data associated with the plurality of authentication credentials may be maintained in a common ledger, the common ledger storing updates to the plurality of authentication credentials”(0010) and “ user accounts 118) may require authentication, such as through the use of a privileged credential, e.g., password, SSH key, symmetric (e.g., public/private) key, or other type of cryptographic data or privileged access token, in order for another identity to access them.”(0049) or and “At step 502, the system may securely maintain data associated with a plurality of authentication credentials, e.g., data stored in vault 108, that are useable by a plurality of identities to obtain access to one or more access-controlled network resources, e.g., servers 110, databases 112, workstations 114, devices 116, accounts 118, and/or the like… he data associated with the authentication credentials may include a plurality of hashes indicative of and/or data derived from passwords, keys, credentials, etc., associated with the plurality of identities”(0074 and hash can be authentication key value as claimed invention and fig. 3 shows vault 108 content with user account (0056))); the authentication key being stored as an attribute of the user account within the authenticated data structure (i.e., “the data associated with the plurality of authentication credentials may be maintained in a common ledger, the common ledger storing updates to the plurality of authentication credentials”(0010) and “the data associated with the plurality of authentication credentials may include a plurality of hashes indicative of passwords associated with the plurality of identities”(0007) ( Examiner asserts that data as authentication key maintained in or authenticated data structure such as common ledger that storing authentication),
identifying a transaction for modifying the authentication key corresponding to the user account (i.e., “ network resources (e.g., servers 110, databases 112, workstation 114, user devices 116, and user accounts 118) may require authentication, such as through the use of a privileged credential, e.g., password, SSH key, symmetric (e.g., public/private) key, or other type of cryptographic data or privileged access token, in order for another identity to access them.”(0049); “perform operations for controlling changes to authentication
credentials. The operations may comprise securely maintaining data associated with a plurality of authentication credentials, the plurality of authentication credentials being useable by a plurality of identities to obtain access to one or more access-controlled network resources; generating, as a function of the data associated with a selected group of the plurality of authentication credentials, a secret data element; making available, the secret data element, to be embedded in a first authentication
credential; identifying an attempt to change the first authentication credential, the attempt including new authentication credential data to replace data in the first authentication credential; validating, conditional on whether the new authentication credential data includes the secret data element, the new authentication credential data; and determining, based on the validating, whether to perform a control action based on the new authentication credential data.”(0066) and “ the data associated with the plurality of authentication credentials is maintained in a common ledger that
stores updates to the plurality of authentication credentials. For example, as discussed above, a blockchain-based authentication technique may be used for determining am approved password-change process.”(0075)); and
upon authenticating the transaction utilizing the authentication key, executing the transaction by generating a new authentication key for the user account (i.e., “the intermediate value 310 may be generated using a password-dependent hash solution. In some embodiments, a password “blockchain” can be used in which every created block for each newly added password is connected or linked to another block. The intermediate value 310 resulting from the dependent hash of the password chain may be only known to security server 104, which knows all the passwords (from the beginning of the chain) that are stored in vault 108.”(0057) and fig. 4 shows step 408,410 or fig. 5 at step 510-512 and “If the new password is validated, at step 410, the new password is stored in vault 108 as a valid credential”(0039)).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2-8, 10-16 and 28-20 are rejected under 35 U.S.C 103(a) as being unpatentable over Hecht (U.S. Pub. 2020/0057848 A1) in view of Avetisov et al. (U.S. Pub. 2020/0067907 A1).
With respect to claim 2, Hecht discloses all limitations recited in claim 1 except for further comprising identifying an additional transaction sent using the user account; and upon authenticating the additional transaction utilizing the new authentication key for the user account, executing the additional transaction. However, Avetisov et al. discloses further comprising: identifying an additional transaction sent using the user account; and upon authenticating the additional transaction utilizing the new authentication key for the user account, executing the additional transaction (i.e., “some transactions, like those for establishing user identity records, federating accounts under those under identity records, and authorizing additional users and devices to identity record or federated account access may be processed through an authority, like a authentication server 155, which reputably establishes identity records. Other entities may be permitted access to the identity records. Transactions occurring with higher frequency, such as for authentication of a user to a user identity record, may not flow through the authority. The decentralization of the process and immutability of data stored in blockchains means that a complete history or ledger of the changes made to a user account records can be chained back to its initial entry into the blockchain. The data structure being used, in some embodiments, to store a user identity records will either be an establishment of a user identity record entry or modification/updating of an existing user identity records entry.”(0142” and “some functionality may be reserved for the authentication server 155, such as publication of an authorized user identity record for a user or addition/removal of keys, accounts, users or credentials under a user's user identity record. Other functionality may not be reserved, such as authentication of a user to a user identity, thereby allowing that user to access an online resource. In some embodiments, functions are performed, based at least in part, on one or more transactions committed to a decentralized data store”(0124)). )). It would have been obvious for a person of ordinary skill in the art, before the effective filing date of the claimed invention, to include Deal et al.’s feature in order to have different access without that server having access to the user’s identification data and further improve security for the stated purpose has been well known in the art as evidenced by teaching of Deal et al (0003, 0007).
With respect to claim 3, Avetisov et al. discloses wherein: the user account of the authenticated data structure of the distributed digital ledger transaction network corresponds to an address of the authenticated data structure (i.e., “an authentication function may take as input a transaction record address of a Net ID, access the record to identity the ID, and verify whether the accessed record is most current (e.g., by performing a search within published transaction records for the ID to identity any later record) prior to authentication. In some embodiments, a record of current transaction record addresses and associated IDs may be maintained by an authentication server and updated responsive to published transactions.”(0184)); and executing the transaction by generating the new authentication key for the user account comprises generating the new authentication key for the user account while maintaining the address of the authenticated data structure for the user account (i.e.,. “the smart contracts may have an address, for instance, in a data storage address space of the decentralized computing platform, like an address corresponding to a cryptographic hash of program code of the smart contracts.”(0132) (i.e., “Transactions occurring with higher frequency, such as for authentication of a user to a user identity record, may not flow through the authority. The decentralization of the process and immutability of data stored in blockchains means that a complete history or ledger of the changes made to a user account records can be chained back to its initial entry into the blockchain. The data structure being used, in some embodiments, to store a user identity records will either be an establishment of a user identity record entry or modification/updating of an existing user identity records entry.”(0142) and Examiner assert establishment of a user identify record entity or update of an existing user identify records entry is executing the transaction by generating a new authentication key for the user account and claims 7-8 and “some functionality may be reserved for the authentication server 155, such as publication of an authorized user identity record for a user or addition/removal of keys, accounts, users or credentials under a user's user identity record. Other functionality may not be reserved, such as authentication of a user to a user identity, thereby allowing that user to access an online resource. In some embodiments, functions are performed, based at least in part, on one or more transactions committed to a decentralized data store”(0124)) (with same motivation above);.
With respect to claim 4, Avetisov et al. discloses further comprising: identifying an additional transaction for modifying the new authentication key corresponding to the user account(i.e., “Transactions occurring with higher frequency, such as for authentication of a user to a user identity record, may not flow through the authority. The decentralization of the process and immutability of data stored in blockchains means that a complete history or ledger of the changes made to a user account records can be chained back to its initial entry into the blockchain. The data structure being used, in some embodiments, to store a user identity records will either be an establishment of a user identity record entry or modification/updating of an existing user identity records entry.”(0142)); and upon authenticating the additional transaction utilizing the new authentication key, executing the additional transaction by generating an additional authentication key for the user account (i.e., “Transactions occurring with higher frequency, such as for authentication of a user to a user identity record, may not flow through the authority. The decentralization of the process and immutability of data stored in blockchains means that a complete history or ledger of the changes made to a user account records can be chained back to its initial entry into the blockchain. The data structure being used, in some embodiments, to store a user identity records will either be an establishment of a user identity record entry or modification/updating of an existing user identity records entry.”(0142) and Examiner assert establishment of a user identify record entity or update of an existing user identify records entry is executing the transaction by generating a new authentication key for the user account and claims 7-8 and “some functionality may be reserved for the authentication server 155, such as publication of an authorized user identity record for a user or addition/removal of keys, accounts, users or credentials under a user's user identity record. Other functionality may not be reserved, such as authentication of a user to a user identity, thereby allowing that user to access an online resource. In some embodiments, functions are performed, based at least in part, on one or more transactions committed to a decentralized data store”(0124)) (with same motivation above);.
. With respect to claim 5, Avetisov et al. discloses wherein generating the authentication key corresponding to the user account of the authenticated data structure of the distributed digital ledger transaction network comprises: determining an address of the user account within the authenticated data structure (i.e., “the authentication server 155 may publish a smart contract 207 by which a computing node 201 may execute a process to authenticate a user based in part on information stored within the decentralized data store, and the result of the authentication may govern whether a given action requested by the user (e.g., to log-in to an account, access a resource, make a payment, etc., as described herein) is permitted within the computing platform.”(0129) and “ an entity, like the authentication server 155, may publish new smart contracts callable by the authentication servicer or other entities (e.g., application servers 245)…the smart contracts may have an address, for instance, in a data storage address space of the decentralized computing platform, like an address corresponding to a cryptographic hash of program code of the smart contracts”(0132)); and setting the authentication key corresponding to the user account to the address of the user account (i.e.,. “the identifying information for a particular notification may include a particular location or address (e.g., IP address and port number, identifier on a notification service, etc.) to which the authentication application 120 should transmit
output data and signed data”(0086) and “While tokens may be used in the above manner and afford convenient storage in a wallet to represent results of an authentication decision, the above should not suggest that a token must be used as a transaction record may as a transaction record of authentication results may also be referenced by its address and that transaction record may include (or reference other prior transaction records by way of cryptographic hash pointer that include) cryptographic hashes or associated keys (e.g., a public key for verification of a signature), by which the user may prove they effected the transaction by providing a signature (e.g., a representation of a credential signed with a private key) verifiable by the public key.”(0150) (with same motivation above)).
With respect to claim 6, Avetisov et al. discloses wherein generating the authentication key corresponding to the user account of the authenticated data structure of the distributed digital ledger transaction network comprises: identifying a public encryption key corresponding to the user account (i.e., “ a record of the identity may contain one or more cryptographic keys (e.g., public keys in an asymmetric encryption protocol) or representations of credentials whereby the user may prove knowledge of a corresponding private key and credential values retained in secret by the user”(0027)); generating a hash value by applying a hash function to the public encryption key (i.e., “credential values, and cryptographic hash
values based thereon, or various private cryptographic keys of asymmetric encryption protocols may be stored,”(0030)); and setting the hash value as the authentication key corresponding to the user account (i.e., “In the context of authentication, the data may be a credential value or a cryptographic hash value of the credential value and representative of a user authenticating a request to access online resources.”(0064) (with same motivation above)).
With respect to claim 7, Avetisov et al. discloses the computer-implemented method of claim 6, wherein authenticating the transaction utilizing the authentication key comprises: generating an additional hash value by applying the hash function to the public encryption key; and determining that the additional hash value corresponds to the authentication key (i.e. “ Some embodiments may input such a credential or value based thereon into a one-way cryptographic function, like a cryptographic hash function, such use SHA 256, and embodiments may supply the output or a value based thereon via a network to a remote computing device that determines whether the user is to be authenticated based on a comparison between the cryptographic hash value and a previously stored cryptographic hash value, for instance, supplied during registration or credential creation based on the same input and hash function. Upon determining that the cryptographic hash values match, the corresponding security criterion may be determined to be have been satisfied by the remote computing device.”(0052) and “The server may receive the result and may compare a cryptographically hashed input credential from the output data to a valid representation of the credential, where the valid representation of the credential was hashed with a same cryptographic hash function, in addition to verifying a signature, such as with a public key received in a prior registration process. ’(0084) (with same motivation above)) .
With respect to claim 8, Avetisov et al. discloses further comprising executing the transaction by generating a new public encryption key corresponding to the user account (i.e., “a record of the identity may contain one or more cryptographic keys (e.g., public keys in an asymmetric encryption protocol) or representations of credentials whereby the user may prove knowledge of a corresponding private key and credential values retained in secret by the user. ”(0027)), wherein generating the new authentication key for the user account comprises generating the new authentication key by applying a hash function to the new public encryption key corresponding to the user account (i.e., “representations of credential values may be dependent on one or more key values or function values used as input in a cryptographic hashing function or encryption algorithm to generate the representations. In turn, the key values or function values may be updated within the TEE 103 to generated refreshed representations, rather than requiring a user to provide a new credential values, which is particularly beneficial in instances where a user may be unable to change a credential value (e.g., for a specific biometric input)”(0109) (with same motivation above)).
With respect to claims 10-16 and 18-20, the claims 10-16 and 18-20 are rejected as rejection of set of claims 2-8 since the set of claims 10-16 and 18-20 are similar with set of claims 2-8 but different form.
Citation of Pertinent References
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
The patent to Narasimhan et al. discloses Public ledger authentication system, U.S. Patent No. 10,937,069 B2.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HUNG T VY whose telephone number is (571)272-1954. The examiner can normally be reached M-F 8-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Tony Mahmoudi can be reached at (571)272-4078. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HUNG T VY/Primary Examiner, Art Unit 2163 July 8, 2026