Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
1. Claims 1-20 have been examined.
Information Disclosure Statement
2. The information disclosure statements (IDS) submitted on 03/27/2025 and 12/29/2025 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner.
Claim Interpretation
3. For claim 1, the “or” and “and/or” limitations have been given the broadest, reasonable interpretation of only requiring a single element from the given options in order to satisfy the requirements of the limitation.
Claim Objections
4. Claims 1-5 are objected to because of the following informalities:
Claim 1 recites “…a communication unit, comprising communication circuitry, configured to perform communication with … one or more external electronic devices device connected to a dedicated network”. Examiner believes “one or more external electronic devices device” is a typographical error.
Claims 2-5 inherit the deficiency of the claim they depend on.
Appropriate correction is required.
5. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
6. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Islam et al. (U.S. Patent Application Publication 2017/0187723; hereafter “Islam”), and further in view of Agarwal et al. (U.S. Patent Application Publication 2023/0012787; hereafter “Agarwal”), and further in view of Brown et al. (U.S. Patent Application Publication 2004/0210633; hereafter “Brown”).
For claims 1 and 6, Islam teaches a service server (note paragraph [0041], trust broker system 130) and method, comprising:
memory (note paragraph [0083], memory);
a communication unit (note paragraph [0085], network communication module), comprising communication circuitry, configured to perform communication with a user terminal connected to a public network (note paragraph [0041], trust broker system communicates with client system connected to network 110) and/or one or more external electronic devices device connected to a dedicated network; and
at least one processor comprising processing circuitry electrically connected to the memory and/or the communication unit (note paragraph [0082], CPU connected to memory and network interface), wherein the at least one processor is configured individually or collectively to:
encrypt an access key for authentication of the user terminal (note paragraphs [0064] and [0105], trust broker system encrypts a user identifier, i.e. access key, for authenticating client system);
transmit an authentication file including the encrypted access key to a remote service target electronic device, which is one of the one or more external electronic devices (note paragraphs [0064] and [0105], trust broker transmits the encrypted user identifier to the server system), through the communication unit;
transmit a connection address for accessing an internal proxy, and the access key, to the user terminal through the communication unit (note paragraphs [0064] and [0103], trust broker system transmits encrypted user identifier and network address of server agent, i.e. internal proxy, to client system); and
Islam differs from the claimed invention in that they fail to teach:
a communication unit configured to perform communication with one or more external electronic devices device connected to a dedicated network; and
at least one processor configured to perform relaying between the user terminal and the external electronic device, wherein the at least one processor is configured individually or collectively to:
transfer a connection request message including the access key received from the user terminal connected to the internal proxy to the remote service target electronic device through the internal proxy using the connection address.
Agarwal teaches:
a communication unit, comprising communication circuitry, configured to perform communication with a user terminal connected to a public network and/or one or more external electronic devices (note paragraph [0043], LAN and WAN interfaces) device connected to a dedicated network (note paragraph [0120], gateway device communicates with servers on an internal network); and
at least one processor comprising processing circuitry electrically connected to the memory and/or the communication unit (note paragraph [0041], processor connected to memory and network interface) and configured to perform relaying between the user terminal and the external electronic device (note paragraphs [0121] and [0123], gateway is an intermediate device between user devices on public network and servers on private network and is used to access resources on the private network), wherein the at least one processor is configured individually or collectively to:
transfer a connection request message including the access key received from the user terminal connected to the internal proxy to the remote service target electronic device through the internal proxy using the connection address (note paragraphs [0159] and [0161], a browser requesting message including an access token is transferred by the gateway device to the remote web site).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the dynamically assigned proxy server with an access identifier of Islam and the gateway connecting devices to a private network of resources of Agarwal to form a combination where the trusted broker system of Islam acts as a gateway to a private network issuing access tokens to clients to access network resources (note paragraph [0064] of Islam and paragraph [0161] of Agarwal). One of ordinary skill would have been motivated to combine Islam and Agarwal because it would protect devices on a private network while still allowing a client to access the private network resources it does not have a direct connection to (note paragraphs [0002] and [0119] of Agarwal).
The combination of Islam and Agarwal differs from the claimed invention in that they fail to teach:
encrypt an access key for authentication of the user terminal using a symmetric key
Brown teaches:
encrypt an access key for authentication of the user terminal using a symmetric key (note paragraphs [0060] and [0071], servers use symmetric keys for to encrypt and decrypt access tickets)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the combination of Islam and Agarwal to form a combination where the trusted broker system of Islam encrypts an access token with a symmetric key to send to the server. One of ordinary skill would have been motivated to combine Islam, Agarwal and Brown because symmetric encryption would provide a quick, lower resource using method of protecting the access key.
For claims 11 and 16, the combination of Islam, Agarwal and Brown teaches an electronic device (note paragraph [0041] of Islam, server system) and method, comprising:
memory (note paragraph [0104] of Islam, memory);
a communication unit, comprising communication circuitry, (note paragraph [0043] of Agarwal, LAN and WAN interfaces) connected to a public network to allow only out-bound communication and configured to perform communication with a service server through a dedicated network (note paragraphs [0119]-[0120] of Agarwal, firewall and gateway device control incoming and outgoing traffic for internal network; paragraph [0002] of Agarwal, client might not have direct access to internal network); and
at least one processor comprising processing circuitry electrically connected to the memory and/or the communication unit (note paragraph [0038] of Agarwal, processor) and configured to provide a remote service to a user terminal by relaying by an internal proxy provided in the service server (note paragraphs [0121] and [0123] of Agarwal, gateway is an intermediate device between user devices on public network and servers on private network and is used to access resources on the private network), wherein the at least one processor is configured individually or collectively to:
receive an authentication file including an encrypted access key from the service server through the communication unit (note paragraph [0105] of Islam, server system receives encrypted access identifier);
obtain a first access key by decrypting the encrypted access key of the authentication file using a symmetric key (note paragraphs [0060] and [0071] of Brown, servers use symmetric keys for to decrypt received access tickets);
receive a connection request message from the user terminal (note paragraph [0106] of Islam, server system receives connection request from client) by relaying by the internal proxy (note paragraphs [0121] and [0123] of Agarwal, gateway is an intermediate device between user devices on public network, i.e. relaying by the internal proxy);
obtain a second access key from the connection request message (note paragraph [0106] of Islam, server system receives second access identifier in connection request); and
allow the remote service for the user terminal based on whether the first access key and the second access key correspond (note paragraph [0110] of Islam, if first and second access identifier match, service is allowed).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the dynamically assigned proxy server with an access identifier of Islam and the gateway connecting devices to a private network of resources of Agarwal to form a combination where the trusted broker system of Islam acts as a gateway to a private network issuing access tokens to clients to access network resources (note paragraph [0064] of Islam and paragraph [0161] of Agarwal). One of ordinary skill would have been motivated to combine Islam and Agarwal because it would protect devices on a private network while still allowing a client to access the private network resources it does not have a direct connection to (note paragraphs [0002] and [0119] of Agarwal).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the combination of Islam and Agarwal to form a combination where the trusted broker system of Islam encrypts an access token with a symmetric key to send to the server. One of ordinary skill would have been motivated to combine Islam, Agarwal and Brown because symmetric encryption would provide a quick, lower resource using method of protecting the access key.
For claims 2, 7, 12 and 17, the combination of Islam, Agarwal and Brown teaches claims 1, 6, 11 and 16, wherein at least one processor is configured individually or collectively to transfer an authentication result from the remote service target electronic device to the user terminal through the internal proxy (note paragraphs [0121] and [0123] of Agarwal, gateway is an intermediate device between user devices on public network, i.e. transfer a response by the internal proxy), in response to a decrypted access key decrypted from the encrypted access key using the symmetric key (note paragraphs [0060] and [0071] of Brown, servers use symmetric keys for to decrypt received access tickets) matching the access key included in the connection request message (note paragraph [0110] of Islam, if first and second access identifier match, service is allowed).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the dynamically assigned proxy server with an access identifier of Islam and the gateway connecting devices to a private network of resources of Agarwal to form a combination where the trusted broker system of Islam acts as a gateway to a private network issuing access tokens to clients to access network resources (note paragraph [0064] of Islam and paragraph [0161] of Agarwal). One of ordinary skill would have been motivated to combine Islam and Agarwal because it would protect devices on a private network while still allowing a client to access the private network resources it does not have a direct connection to (note paragraphs [0002] and [0119] of Agarwal).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the combination of Islam and Agarwal to form a combination where the trusted broker system of Islam encrypts an access token with a symmetric key to send to the server. One of ordinary skill would have been motivated to combine Islam, Agarwal and Brown because symmetric encryption would provide a quick, lower resource using method of protecting the access key.
For claims 3, 8, 13 and 18, the combination of Islam, Agarwal and Brown teaches claims 1, 6, 11 and 16, wherein at least one processor is configured individually or collectively to provide the user terminal with a session key that is a new string to replace the access key (note paragraphs [0049] and [0051] of Islam, client is provided session keys for encrypting communication, which are periodically changed), in response to a decrypted access key decrypted from the encrypted access key using the symmetric key matching the access key included in the connection request message (note paragraphs [0066] and [0110] of Islam, in response to matching access identifier, secure connection is established).
For claims 4, 9, 14 and 19, the combination of Islam, Agarwal and Brown teaches claims 1, 6, 11 and 16, wherein at least one processor is configured individually or collectively to:
include information about a valid use period preset for the encrypted access key in the authentication file and transfer to the remote service target electronic device (note paragraph [0106] of Islam, trust broker notifies server when encrypted access identifiers are no longer valid; identifiers expire after a predetermined amount of time).
For claims 5, 10, 15 and 20, the combination of Islam, Agarwal and Brown teaches claims 1, 6, 11 and 16, wherein at least one processor is configured individually or collectively to:
obtain, as the remote service target electronic device, an external electronic device selected from the user terminal (note paragraph [0063] of Islam, target server is selected by client system) succeeding in authentication for use of a remote service using a predetermined authentication scheme (note paragraphs [0054], [0058] and [0098] of Islam, client system is authenticated using password or device identifier).
Conclusion
7. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Ziegler et al. (U.S. Patent Application Publication 2021/0336788) discloses an access token provided to a service and a reverse proxy (note Fig. 4).
Huber et al. (U.S. Patent Application Publication 2018/0131694) discloses a gateway device that generates keys (note paragraph [0048]) for use in a private network (note paragraph [0034]).
Sarukkai et al. (U.S. Patent Application Publication 2016/0044124) discloses a proxy service that forwards a user request to a service with an encrypted authentication token (note paragraphs [0035] and [0044]).
Somani et al. (U.S. Patent Application Publication 2012/0284786) discloses a server decrypting a token generated by a proxy server using a shared key (note paragraph [0076]).
Claeys et al. (“Securing Complex IoT Platforms with Token Based Access Control and Authenticated Key Establishment”) discloses access tokens and a proxy for controlling IoT resources (note Abstract and pages 5-6).
8. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAVID J PEARSON whose telephone number is (571)272-0711. The examiner can normally be reached 8:30 - 6:00 pm; Monday through Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at (571)270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
DAVID J. PEARSON
Primary Examiner
Art Unit 2407
/David J Pearson/Primary Examiner, Art Unit 2407