DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This application has PRO 63/124,718 12/12/2020
Claim Status
Claims 1-20 are currently pending and rejected.
Claim Rejection – 35 U.S.C. 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-3, 5, 6, 11-13, 15, and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kuoh et al. (Pub. No.: US 2018/0108080), in view of Wang et al. (CN 104967887 B) and Watson et al. (Pub. No.: US 2020/0028843) and Boult et al. (Pub. No.: US 2009/0271634).
As per claim 1, Kuoh teaches a computer system for authenticating a user using an extended reality (XR) system using behavioral biometrics, the computer system comprising:
a processor (see paragraph 0037, 0058, and 0064-0065); and
a memory storing software arranged to execute on the processor, the software comprising instructions operative upon execution by the processor to (see paragraph 0031, 0035, 0059-0060, and 0063-0064):
based on detecting the user using the XR system, automatically collect a first set of passive behavioral biometric data of the user using the XR system via a sensor of the XR system (see paragraph 0007, “a biometric authentication module configured to receive biometric data relating to a user and authenticate the user based on the received biometric data”; see paragraph 0014, “include an input module configured to receive a purchase instruction form the user device to purchase the product, and the biometric authentication module may be configured to initiate authentication of the user upon receipt of the purchase instruction; see paragraph 0046, “The biometric authentication module 100 can be further configured to initiate authentication of the user upon receipt of the purchase instruction. In other words, the purchase instruction from the user acts as a trigger for authentication of the user”; also see paragraph 0012, 0017, and 0051), and
based on matching the first set of passive behavioral biometric data to a second set of passive behavioral biometric data stored in the XR system, authenticate the user to access a subset of payment data in an XR environment of the XR system, thereby enabling the user to request a transaction within the XR environment (see paragraph 0012, 0022, 0051, “The biometric authentication module may be in communication with a biometric authentication directory server, and the received biometric data relating to the user is compared to reference biometric data stored in the biometric authentication directory server for authenticating the user”; also see paragraph 0007, 0017, 0039-0040, “The transceiver module 110 for product purchase upon successful authentication of the user by the biometric authentication module 104”).
Examiner notes however, Kuoh does not explicitly teach detect a user using the XR system, the XR system including augmented reality (AR) glasses worn by the user; based on detecting the user using the XR system, automatically capture at least one movement pattern of the user interacting with XR content of the XR system via a sensor of the XR system, the at least one movement pattern defining a first set of passive behavioral biometric data of the user; match the first biologic key to a biometric key of the user stored in the XR system, the biometric key being based on a second set of passive biometric data; authenticate the user to access a subset of content in an XR environment of the XR system.
Wang teaches detect a user using the XR system, the XR system including augmented reality (AR) glasses worn by the user; based on detecting the user using the XR system, automatically capture at least one biometric feature of the user interacting with XR content of the XR system via a sensor of the XR system; match the first biologic key to a biometric key of the user stored in the XR system, the biometric key being based on a second set of passive biometric data; authenticate the user to access a subset of content in an XR environment of the XR system (see page 2, “virtual reality glasses obtaining biometric features of the user, and authenticating the user identity according to the biological characteristic”; see page 5, “step s100, virtual reality glasses obtaining biometric features of the user, and authenticating the user according to the biological feature”; see page 6, “When virtual reality glasses if identification of collected user characteristic and characteristic database pre-stored user characteristic are matched, the authentication is successful, otherwise the authentication fails”; prior art does not say the biometric feature collection is performed after prompting user, and the biometric collection step is the very first step of the process; as such, it is interpreted that the biometric is captured as soon as the VR glasses detects the presence of the user).
Watson teaches automatically capture at least one movement pattern of the user interacting with XR content of the XR system via a sensor of the XR system, the at least one movement pattern defining a first set of passive behavioral biometric data of the user; and match the first biometric to a biometric key of the user stored in the XR system, the biometric key being based on a second set of passive behavioral biometric data (see paragraph 0006, “as to whether the user performing the new motion is an authenticated user based on comparing the detected biometric data with stored biometric data for a prior motion performed by the authenticated user; see paragraph 0028, “authenticating a user in virtual reality or an augmented reality environment involves using invoice or gestures to authenticate the user”; see paragraph 0042 and 0055 for gesture pattern authentication; see paragraph 0053, “sensor system 216 comprises at least one of an accelerometer, a magnetometer, a gyroscope, a camera, an optical-tracking sensor, an eye-tracking sensor, a motion sensor, a force sensor, or some other suitable type of sensor”; also see paragraph 0056, “Motion actions models 244 can be models for movement of at least one of a finger, an arm, a head, a hand, a leg, a foot, an eye, a jaw, or some other part of a person”).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Wang and Watson to include detect a user using the XR system, the XR system including augmented reality (AR) glasses worn by the user; based on detecting the user using the XR system, automatically capture at least one movement pattern of the user interacting with XR content of the XR system via a sensor of the XR system, the at least one movement pattern defining a first set of passive behavioral biometric data of the user; match the first biologic key to a biometric key of the user stored in the XR system, the biometric key being based on a second set of passive biometric data; authenticate the user to access a subset of content in an XR environment of the XR system. The modification would have been obvious, because it is merely applying a known technique (i.e., collecting user behavioral biometric and authenticating user based on matching the collected user behavioral biometric to stored user behavioral biometric) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., automatically authenticating user).
Examiner further notes the combination of Kuoh, Wang, and Watson still does not teach perform a tokenization process using a tokenizer module of the XR system to transform the first set of passive behavior biometric data into a first biometric token.
Boult teaches perform a tokenization process using a tokenizer module of the XR system to transform the first set of passive behavior biometric data into a first biometric token (see paragraph 0010, “An alternative approach to protecting biometric data is to transform the data into some form of revocable token”; prior art suggests that transforming biometric data into token was well-known in 2008; see paragraph 0026-0027, “The process of generating a biotoken allows nesting, where the residuals r(f,j), are passed through each nesting level without change, but the encoded fields w(f,j) can be subject to additional layers of encrypting/hashing with added transform/encryption parameters…These multiple nested transforms can be applied over each field of the secure revocable biotokens”; also see paragraph 0032); and
match the first biometric token to a biometric key token of the user stored in the XR system, the biometric key token being based on a second set of passive behavioral biometric data (see paragraph 0027-0028 and 0040).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify the combination of Kuoh, Wang, and Watson with teaching from Boult to include perform a tokenization process using a tokenizer module of the XR system to transform the first set of passive behavior biometric data into a first biometric token; and match the first biometric token to a biometric key token of the user stored in the XR system, the biometric key token being based on a second set of passive behavioral biometric data. The modification would have been obvious, because it is merely applying a known technique (i.e., tokenizing biometric data) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., enhance security).
As per claim 2, Kuoh teaches wherein the instructions are further operative upon execution by the processor to:
based on detecting the user using the XR system, automatically collect a third set of passive behavioral biometric data of the user using the XR system via the sensor (see paragraph 0007, “a biometric authentication module configured to receive biometric data relating to a user and authenticate the user based on the received biometric data”; see paragraph 0014, “include an input module configured to receive a purchase instruction form the user device to purchase the product, and the biometric authentication module may be configured to initiate authentication of the user upon receipt of the purchase instruction; see paragraph 0046, “The biometric authentication module 100 can be further configured to initiate authentication of the user upon receipt of the purchase instruction. In other words, the purchase instruction from the user acts as a trigger for authentication of the user”; also see paragraph 0012, 0017, and 0051),
wherein authenticating the user to access a subset of content and payment data is further based on matching the third set of passive behavioral biometric data to the second set of passive behavioral biometric data (see paragraph 0012, 0022, 0051, “The biometric authentication module may be in communication with a biometric authentication directory server, and the received biometric data relating to the user is compared to reference biometric data stored in the biometric authentication directory server for authenticating the user”; also see paragraph 0007, 0017, 0039-0040, “The transceiver module 110 for product purchase upon successful authentication of the user by the biometric authentication module 104”).
Examiner notes however, Kuoh does not explicitly teach detect a user using the XR system; based on detecting the user using the XR system, automatically collect a first set of passive behavioral biometric data in a background of the user using the XR system via a sensor of the XR system; authenticate the user to access a subset of content in an XR environment of the XR system.
Wang based on detecting the user using the XR system, automatically collect a third set of passive behavioral biometric data in the background of the user using the XR system via the sensor; wherein authenticating the user to access a subset of content and payment data is further based on matching the third set of passive behavioral biometric data to the second set of passive behavioral biometric data (see page 2, “virtual reality glasses obtaining biometric features of the user, and authenticating the user identity according to the biological characteristic”; see page 5, “step s100, virtual reality glasses obtaining biometric features of the user, and authenticating the user according to the biological feature”; see page 6, “When virtual reality glasses if identification of collected user characteristic and characteristic database pre-stored user characteristic are matched, the authentication is successful, otherwise the authentication fails”; prior art does not say the biometric feature collection is performed after prompting user, and the biometric collection step is the very first step of the process; as such, it is interpreted that the biometric is captured as soon as the VR glasses detects the presence of the user).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Wang to include based on detecting the user using the XR system, automatically collect a third set of passive behavioral biometric data in the background of the user using the XR system via the sensor; and based on detecting the user using the XR system, automatically collect a third set of passive behavioral biometric data in the background of the user using the XR system via the sensor. The modification would have been obvious, because it is merely applying a known technique (i.e., detecting user identity using behavioral biometric data and providing personalized content based on detected identity) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., use behavioral biometric to further enhance security).
As per claim 3, Kuoh does not teach wherein the first set of passive behavioral biometric data is a gesture pattern of the user, wherein the third set of passive behavioral biometric data is an eye movement pattern of the user, and wherein the second set of passive behavioral biometric data comprises eye movement pattern data and head movement pattern data.
Watson teaches wherein the first set of passive behavioral biometric data is a gesture pattern of the user, wherein the third set of passive behavioral biometric data is an eye movement pattern of the user, and wherein the second set of passive behavioral biometric data comprises eye movement pattern data and head movement pattern data (see paragraph 0028, “authenticating a user in virtual reality or an augmented reality environment involves using invoice or gestures to authenticate the user”; see paragraph 0042 and 0055 for gesture pattern authentication; see paragraph 0053, “sensor system 216 comprises at least one of an accelerometer, a magnetometer, a gyroscope, a camera, an optical-tracking sensor, an eye-tracking sensor, a motion sensor, a force sensor, or some other suitable type of sensor”; also see paragraph 0056, “Motion actions models 244 can be models for movement of at least one of a finger, an arm, a head, a hand, a leg, a foot, an eye, a jaw, or some other part of a person”).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Watson to include wherein the first set of passive behavioral biometric data is a gesture pattern of the user, wherein the third set of passive behavioral biometric data is an eye movement pattern of the user, and wherein the second set of passive behavioral biometric data comprises eye movement pattern data and head movement pattern data. The modification would have been obvious, because it is merely applying a known technique (i.e., using well-researched behavior features to identify a user) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., enhance payment security without being intrusive).
As per claim 5, Kuoh teaches wherein the instructions are further operative upon execution by the processor to:
based on the user requesting a transaction within the XR environment, automatically collect a first set of passive biometric data of the user and a second set of passive biometric data of the user (see paragraph 0007, “a biometric authentication module configured to receive biometric data relating to a user and authenticate the user based on the received biometric data”; see paragraph 0014, “include an input module configured to receive a purchase instruction form the user device to purchase the product, and the biometric authentication module may be configured to initiate authentication of the user upon receipt of the purchase instruction; see paragraph 0046, “The biometric authentication module 100 can be further configured to initiate authentication of the user upon receipt of the purchase instruction. In other words, the purchase instruction from the user acts as a trigger for authentication of the user”; also see paragraph 0012, 0017, and 0051); and
based on matching the first set of passive biometric data and the second set of passive biometric data to a second set of passive biometric data stored in the XR system, send transaction request data and the payment data to a transaction processing entity (see paragraph 0012, 0022, 0051, “The biometric authentication module may be in communication with a biometric authentication directory server, and the received biometric data relating to the user is compared to reference biometric data stored in the biometric authentication directory server for authenticating the user”; also see paragraph 0007, 0017, 0039-0040, “The transceiver module 110 for product purchase upon successful authentication of the user by the biometric authentication module 104”).
Examiner notes Kuoh does not explicitly teach wherein the sets of passive biometric data are captured without specific interaction by the user with the XR environment.
Wang teaches the sets of passive biometric data are captured without specific interaction by the user with the XR environment (see page 2, “virtual reality glasses obtaining biometric features of the user, and authenticating the user identity according to the biological characteristic”; see page 5, “step s100, virtual reality glasses obtaining biometric features of the user, and authenticating the user according to the biological feature”; see page 6, “When virtual reality glasses if identification of collected user characteristic and characteristic database pre-stored user characteristic are matched, the authentication is successful, otherwise the authentication fails”; prior art does not say the biometric feature collection is performed after prompting user, and the biometric collection step is the very first step of the process; as such, it is interpreted that the biometric is captured as soon as the VR glasses detects the presence of the user).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Wang to include the sets of passive biometric data are captured without specific interaction by the user with the XR environment. The modification would have been obvious, because it is merely applying a known technique (i.e., continuously capturing user biometric data without interaction by the user) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., make user experience more seamless).
As per claim 6, Kuoh teaches wherein the first set of passive biometric data comprises a retinal pattern of an eye of the user, and wherein the second set of passive biometric data comprises facial recognition data captured while the user is wearing a headgear of the XR system (see paragraph 0016, “The biometric data may include one or more of iris data, fingerprint data, voice data, and facial feature data”).
Claim 11 is rejected for the same reason as claim 1.
Claim 12 is rejected for the same reason as claim 2.
Claim 13 is rejected for the same reason as claim 3.
Claim 15 is rejected for the same reason as claim 5. Claim 16 is rejected for the same reason as claim 6.
Claim(s) 4, 7, 14, and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kuoh et al. (Pub. No.: US 2018/0108080), in view of Wang et al. (CN 104967887 B) and Watson et al. (Pub. No.: US 2020/0028843) and Boult et al. (Pub. No.: US 2009/0271634), and further in view of Pfeuffer et al. (Pfeuffer et al., Behavioural Biometrics in VR, CHI 2019, May 4-9, 2019, Glasgow, Scotland UK).
As per claim 4, Kuoh does not teach wherein the first set of passive behavioral biometric data further comprises a walking gait pattern of the user, wherein the third set of passive behavioral biometric data further comprises a hand movement pattern of the user, and wherein the second set of passive behavioral biometric data further comprises walking gait pattern data and hand movement pattern data.
Watson teaches wherein the third set of passive behavioral biometric data further comprises a hand movement pattern of the user, (see paragraph 0056, 0060).
Pfeuffer wherein the first set of passive behavioral biometric data further comprises a walking gait pattern of the user, and wherein the second set of passive behavioral biometric data further comprises walking gait pattern data and hand movement pattern data (see page 2, “Use of body motions as behavioral biometrics has a long tradition in security related research [13, 49]. Gait has been extensively researched in the context of various possible features as users inhere unique walking patterns”, “Estimation of body height, shoulder breadth or stride information from cameras can be useful to design systems that identify users form multiple biometric sources”, and Mustafa et al. showed how head pointing motion from Google Cardboard sensors can be used to identify users”).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Watson and Pfeuffer to include wherein the first set of passive behavioral biometric data further comprises a walking gait pattern of the user, wherein the third set of passive behavioral biometric data further comprises a hand movement pattern of the user, and wherein the second set of passive behavioral biometric data further comprises walking gait pattern data and hand movement pattern data. The modification would have been obvious, because it is merely applying a known technique (i.e., using well-researched behavior features to identify a user) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., enhance payment security without being intrusive).
As per claim 7, Kuoh does not teach wherein the first set of passive biometric data further comprises a height of the user, and wherein the second set of passive biometric data further comprises data a shape and a proportion of the user.
Pfeuffer teaches the first set of passive biometric data further comprises a height of the user, and wherein the second set of passive biometric data further comprises data a shape and a proportion of the user (see page 2, “Use of body motions as behavioral biometrics has a long tradition in security related research [13, 49]. Gait has been extensively researched in the context of various possible features as users inhere unique walking patterns”, “Estimation of body height, shoulder breadth or stride information from cameras can be useful to design systems that identify users form multiple biometric sources”, and Mustafa et al. showed how head pointing motion from Google Cardboard sensors can be used to identify users”).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Pfeuffer to include the first set of passive biometric data further comprises a height of the user, and wherein the second set of passive biometric data further comprises data a shape and a proportion of the user. The modification would have been obvious, because it is merely applying a known technique (i.e., using well-researched behavior features to identify a user) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., enhance payment security without being intrusive).
Claim 14 is rejected for the same reason as claim 4.
Claim 17 is rejected for the same reason as claim 7.
Claim(s) 8-10 and 18-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kuoh et al. (Pub. No.: US 2018/0108080), in view of Wang et al. (CN 104967887 B) and Watson et al. (Pub. No.: US 2020/0028843) and Boult et al. (Pub. No.: US 2009/0271634), and further in view of Rabinowitz et al. (Pub. No.: US 2019/0281261).
As per claim 8, Kuoh does not teach a secure hardware chip distinct from the memory, wherein the secure hardware chip stores the second set of passive behavioral biometric data.
Rabinowitz teaches a secure hardware chip distinct from the memory, wherein the secure hardware chip stores the second set of passive behavioral biometric data (see paragraph 0093, “Biometric sensor 317 is configured to acquire a biometric identifier from a user and compare the acquired biometric identifier to a reference biometric identifier stored in a memory (e.g., of sensor 317 or a separate memory of key fob 306) to determine if a match between the acquired biometric identifier and the reference biometric is present”; see paragraph 0072, “key fob 306 includes a chip”).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Rabinowitz to include a secure hardware chip distinct from the memory. The modification would have been obvious, because it is merely applying a known technique (i.e., comparing acquired biometric to a stored biometric in a separate memory) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., to enhance security).
As per claim 9, Kuoh teaches wherein the instructions are further operative upon execution by the processor to: apply a hash function to the first set of passive behavioral biometric data and the second set of passive behavioral biometric data in a consistent manner, resulting in a first behavioral biometric token and a second behavioral biometric token that can directly compared to determine whether the first set of passive behavioral biometric data matches the second set of passive behavioral biometric data.
Boult teaches apply a hash function to the first set of passive behavioral biometric data and the second set of passive behavioral biometric data in a consistent manner, resulting in a first behavioral biometric token and a second behavioral biometric token that can directly compared to determine whether the first set of passive behavioral biometric data matches the second set of passive behavioral biometric data (see paragraph 0010, “An alternative approach to protecting biometric data is to transform the data into some form of revocable token”; prior art suggests that transforming biometric data into token was well-known in 2008; see paragraph 0026-0027, “The process of generating a biotoken allows nesting, where the residuals r(f,j), are passed through each nesting level without change, but the encoded fields w(f,j) can be subject to additional layers of encrypting/hashing with added transform/encryption parameters…These multiple nested transforms can be applied over each field of the secure revocable biotokens”; also see paragraph 0032).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Boult to include apply a hash function to the first set of passive behavioral biometric data and the second set of passive behavioral biometric data in a consistent manner, resulting in a first behavioral biometric token and a second behavioral biometric token that can directly compared to determine whether the first set of passive behavioral biometric data matches the second set of passive behavioral biometric data. The modification would have been obvious, because it is merely applying a known technique (i.e., transforming biometric data into token) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., protect biometric data).
As per claim 10, Kuoh does not teach wherein matching the first set of passive behavioral biometric data to the second set of passive behavioral biometric data further comprises: determine whether the first behavioral biometric token matches the second behavioral biometric token within a defined confidence threshold, wherein all data values of the sets of behavioral biometric data are separately tokenized according to behavioral biometric data type.
Watson teaches wherein matching the first set of passive behavioral biometric data to the second set of passive behavioral biometric data further comprises: determine whether the first behavioral biometric token matches the second behavioral biometric token within a defined confidence threshold, wherein all data values of the sets of behavioral biometric data are separately tokenized according to behavioral biometric data type (see paragraph 0060, “variance 236 can defined how variation in a position of a hand from the position of the hand in stored biometric data 222 can be considered a match to motion action model for a motor action involving movement of a hand”; also see paragraph 0096, “the security threshold is a value that identifies how much variation between the detected biometric data for a new motion and stored biometric data for a prior motion is present for a sufficient match to occur in identifying the user as the authenticated user”; the biometric data is related to the user’s movement/gesture, thus it is behavioral biometric data).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Watson to include wherein matching the first set of passive behavioral biometric data to the second set of passive behavioral biometric data further comprises: determine whether the first behavioral biometric token matches the second behavioral biometric token within a defined confidence threshold, wherein all data values of the sets of behavioral biometric data are separately tokenized according to behavioral biometric data type. The modification would have been obvious, because it is merely applying a known technique (i.e., allow behavioral biometric data to be matched within a defined threshold) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., introduce some degree of fuzziness in matching, thus allow authentication to be easier in real life situations).
Claim 18 is rejected for the same reason as claim 9.
Claim 19 is rejected for the same reason as claim 10. As per claim 20, Kuoh teaches an extended reality (XR) headgear device comprising:
the XR device has computer-executable instructions that, upon execution by a processor, cause the processor to at least (see paragraph 0037, 0058, and 0064-0065):
automatically collect a second set of biometric data of the user with a sensor while the user is interacting with an XR environment of the XR device (see paragraph 0007, “a biometric authentication module configured to receive biometric data relating to a user and authenticate the user based on the received biometric data”; see paragraph 0014, “include an input module configured to receive a purchase instruction form the user device to purchase the product, and the biometric authentication module may be configured to initiate authentication of the user upon receipt of the purchase instruction; see paragraph 0046, “The biometric authentication module 100 can be further configured to initiate authentication of the user upon receipt of the purchase instruction. In other words, the purchase instruction from the user acts as a trigger for authentication of the user”; also see paragraph 0012, 0017, and 0051),
match the second set of eye movement pattern data to the first set of passive behavioral biometric data via the secure hardware processing chip (see paragraph 0012, 0022, 0051, “The biometric authentication module may be in communication with a biometric authentication directory server, and the received biometric data relating to the user is compared to reference biometric data stored in the biometric authentication directory server for authenticating the user”; also see paragraph 0007, 0017, 0039-0040, “The transceiver module 110 for product purchase upon successful authentication of the user by the biometric authentication module 104”),
authenticate the user to access to a subset of content and payment data in the XR environment, thereby enabling the user to request a transaction within the XR environment (see paragraph 0012, 0022, 0051, “The biometric authentication module may be in communication with a biometric authentication directory server, and the received biometric data relating to the user is compared to reference biometric data stored in the biometric authentication directory server for authenticating the user”; also see paragraph 0007, 0017, 0039-0040, “The transceiver module 110 for product purchase upon successful authentication of the user by the biometric authentication module 104”),
based on the user requesting the transaction within the XR environment, automatically collect a second set of biometric data of the user (see paragraph 0007, “a biometric authentication module configured to receive biometric data relating to a user and authenticate the user based on the received biometric data”; see paragraph 0014, “include an input module configured to receive a purchase instruction form the user device to purchase the product, and the biometric authentication module may be configured to initiate authentication of the user upon receipt of the purchase instruction; see paragraph 0046, “The biometric authentication module 100 can be further configured to initiate authentication of the user upon receipt of the purchase instruction. In other words, the purchase instruction from the user acts as a trigger for authentication of the user”; also see paragraph 0012, 0017, and 0051), and
based on matching the second set of biometric data to the first set of biometric data stored, send transaction request data and the payment data to a transaction processing entity (see paragraph 0012, 0022, 0051, “The biometric authentication module may be in communication with a biometric authentication directory server, and the received biometric data relating to the user is compared to reference biometric data stored in the biometric authentication directory server for authenticating the user”; also see paragraph 0007, 0017, 0039-0040, “The transceiver module 110 for product purchase upon successful authentication of the user by the biometric authentication module 104”).
Examiner notes however, Kuoh does not explicitly teach detect a user using the XR system, the XR device, the XR device including augmented reality (AR) glasses worn by the user; based on detecting the user using the XR system, automatically capture at least one biometric feature of the user interacting with XR content in an XR environment of the XR device; match the first biometric token data to the biometric key token data via the secure hardware processing chip, the biometric key being based on a second set of passive biometric data; authenticate the user to access a subset of content in an XR environment of the XR system.
Wang teaches detect a user using the XR system, the XR device, the XR device including augmented reality (AR) glasses worn by the user; based on detecting the user using the XR system, automatically capture at least one biometric feature of the user interacting with XR content in an XR environment of the XR device; match the first biologic key to a biometric key of the user stored in the XR system, the biometric key being based on a second set of passive biometric data; authenticate the user to access a subset of content in an XR environment of the XR system (see page 2, “virtual reality glasses obtaining biometric features of the user, and authenticating the user identity according to the biological characteristic”; see page 5, “step s100, virtual reality glasses obtaining biometric features of the user, and authenticating the user according to the biological feature”; see page 6, “When virtual reality glasses if identification of collected user characteristic and characteristic database pre-stored user characteristic are matched, the authentication is successful, otherwise the authentication fails”; prior art does not say the biometric feature collection is performed after prompting user, and the biometric collection step is the very first step of the process; as such, it is interpreted that the biometric is captured as soon as the VR glasses detects the presence of the user).
Watson teaches an eye-tracking camera; a retinal scanning sensor; automatically collect a second set of eye movement pattern data of the user with the eye-tracking camera in a background while the user is interacting with XR content in an XR environment of the XR device, authenticate the user based on matching the second set of eye movement pattern data to the first set of eye movement pattern data, wherein the retinal scan data is captured without specific interaction by the user with the XR environment; authenticate the user based on matching the second set of retinal scan data to the first set of retinal scan data stored (see paragraph 0028, “authenticating a user in virtual reality or an augmented reality environment involves using invoice or gestures to authenticate the user”; see paragraph 0042 and 0055 for gesture pattern authentication; see paragraph 0053, “sensor system 216 comprises at least one of an accelerometer, a magnetometer, a gyroscope, a camera, an optical-tracking sensor, an eye-tracking sensor, a motion sensor, a force sensor, or some other suitable type of sensor”; also see paragraph 0056, “Motion actions models 244 can be models for movement of at least one of a finger, an arm, a head, a hand, a leg, a foot, an eye, a jaw, or some other part of a person”).
Rabinowitz teaches a secure hardware processing chip storing a first set of biometric data; and authenticate the user based on matching the second set of biometric data to the first set of biometric data stored (see paragraph 0093, “Biometric sensor 317 is configured to acquire a biometric identifier from a user and compare the acquired biometric identifier to a reference biometric identifier stored in a memory (e.g., of sensor 317 or a separate memory of key fob 306) to determine if a match between the acquired biometric identifier and the reference biometric is present”; see paragraph 0072, “key fob 306 includes a chip”).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify Kuoh with teaching from Wang and Watson and Rabinowitz to include detect a user using the XR system, the XR device, the XR device including augmented reality (AR) glasses worn by the user; based on detecting the user using the XR system, automatically capture at least one biometric feature of the user interacting with XR content in an XR environment of the XR device; match the first biometric token data to the biometric key token data via the secure hardware processing chip, the biometric key being based on a second set of passive biometric data; authenticate the user to access a subset of content in an XR environment of the XR system. The modification would have been obvious, because it is merely applying a known technique (i.e., collecting user behavioral biometric and authenticating user based on matching the collected user behavioral biometric to stored user behavioral biometric) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., automatically authenticating user).
Examiner further notes the combination of Kuoh, Wang, Watson, and Rabinowitz still does not teach perform a tokenization process using a tokenizer module of the XR system to transform a tokenization process using a tokenizer module of the XR device to transform the second set of eye movement pattern data of the user into a first biometric token; perform a tokenization process using a tokenizer module of the XR device to transform the second set of retinal scan data of the user into a second biometric token; and authenticate the user based on matching the second biometric token to the first biometric key token.
Boult teaches perform a tokenization process using a tokenizer module of the XR system to transform a tokenization process using a tokenizer module of the XR device to transform the second set of eye movement pattern data of the user into a first biometric token; perform a tokenization process using a tokenizer module of the XR device to transform the second set of retinal scan data of the user into a second biometric token (see paragraph 0010, “An alternative approach to protecting biometric data is to transform the data into some form of revocable token”; prior art suggests that transforming biometric data into token was well-known in 2008; see paragraph 0026-0027, “The process of generating a biotoken allows nesting, where the residuals r(f,j), are passed through each nesting level without change, but the encoded fields w(f,j) can be subject to additional layers of encrypting/hashing with added transform/encryption parameters…These multiple nested transforms can be applied over each field of the secure revocable biotokens”; also see paragraph 0032); and
authenticate the user based on matching the second biometric token to the first biometric key token (see paragraph 0027-0028 and 0040).
It would have been obvious to one of ordinary skill in the art at the time of the effective filing date of the present application to modify the combination of Kuoh, Wang, Watson, and Rabinowitz with teaching from Boult to include perform a tokenization process using a tokenizer module of the XR system to transform a tokenization process using a tokenizer module of the XR device to transform the second set of eye movement pattern data of the user into a first biometric token; perform a tokenization process using a tokenizer module of the XR device to transform the second set of retinal scan data of the user into a second biometric token; and authenticate the user based on matching the second biometric token to the first biometric key token. The modification would have been obvious, because it is merely applying a known technique (i.e., tokenizing biometric data) to a known system (i.e., XR payment system) ready to provide predictable result (i.e., enhance security).
Prior Art Cited Not Applied
He et al. (CN 208938130) is cited, because the prior art teaches “along with the increasing of security requirements, a set of fingerprint, ID by independent chip, portrait authentication information comparison, providing safety and prevent the requirement of information falsification system becomes large” (see page 2). In other words, He teaches the biometric token is compared to the biometric key token on a separate hardware chip from at least one other chip of the system such that the identification of the user profile is insulated from other processes being performed on the system.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HAO FU whose telephone number is (571)270-3441. The examiner can normally be reached 9:00 AM - 6:00 PM PST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Christine Behncke can be reached on (571) 272-8103. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HAO FU/Primary Examiner, Art Unit 3695 AUG-2026