DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 02/03/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Objections
The acronym ‘OOB’ as recited in the claims 9 and 12 should be spelled out and/or defined the first time it is recited in the claims.
Priority/Benefit
Acknowledgment is made of domestic priority data as claimed by applicant application is a 371 of PCT/EP2023/071228 08/01/2023 has been filed 08/01/2023.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-13 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Claim 1 recites a method which appears to be a ‘process’ and one of the four statutory subject matter categories of invention (Step 1 of the Subject Matter Eligibility Test).
However, the claim appears to not qualify for a streamlined analysis thus a full eligibility and thus a fully eligibility analysis is necessary (Step 2A and Step 2B of the Subject Matter Eligibility Test).
In Step 2A, Prong One, examiners evaluate whether the claim recites a judicial i.e., whether a law of nature, natural phenomenon, or abstract idea is set forth or described in the claims. The claim recites the steps of:
“acquiring, … a certificate of the server”
“checking whether a root certificate of a certificate chain to which the certificate belongs, or the certificate itself, if it is a self-signed certificate, is in a trusted store of trusted certificates”
“if the root certificate, or the certificate itself, if it is a self-signed certificate, is not in the trusted store, checking whether the server is local to the network, and if the server is local to the network, adding the root certificate, or, if the certificate is a self-signed certificate, adding the certificate itself to the store”
if the server is not local to the network, aborting execution of the method.
The steps performing amount to an abstract idea which falls under a judicial exception (Step 2A, Prong 1, of Subject Matter Eligibility). Abstract ideas falls in the category. The abstract idea falls in the categories of a mental process, for evaluation, judgments, and opinions (MPEP 2106.04(a)(2) & MPEP 2106.06). The claims simply automated a process that can be performed without computers or with a computer a tool. Furthermore, the court found that the claims simply related to the collection and analysis of data is an abstract idea in which there is not inventive concept, and there are no details in the claim that describe an improvement to existing computer technology, Fairwarning IP, LLC v. Iatric Sys, Inc., No. 15-1985 (Fed. Cir. 2016).
In Step 2A, Prong Two, examiner determine whether the claim as a whole integrates the judicial exception into a practical application to disqualify abstract as a judicial exception. However, the judicial exception in claim 1 is not integrated into practical because the generically recited elements:
…a client …
…a server …
do not add meaningful limitation to an abstract idea because they amount to simply implementing the abstract idea on a computer. The claim do not include additional elements that are sufficient to amount to significantly more than the judicial exception because simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, e.g., a claim to an abstract idea requiring no more than a generic computer to perform generic computer function that are well-understood, routine and conventional activities previously known to the industry, as discussed in Alice Corp., 573 U.S. at 225, 110 USPQ2d at 1984.
Thus, the analysis concludes is ineligible under 35 U.S.C. § 101 as it is directed to a judicial exception.
With respect to dependent claims 2-8 10-15 and 17-20, the additional limitations do not change the characterization of the claims as being directed to an abstract idea and do not amount to significantly more, as explained below.
Claims 2 and 4 further define the server and does not integrate the exception into a practical application or provide an inventive concept.
Claims 3 and 5 adds checking for the certificate and does not integrate the exception into a practical application or provide an inventive concept.
Claims 6 and 7 adds method of obtaining the certificate and does not integrate the exception into a practical application or provide an inventive concept.
Claims 8 and 9 adds configuring an enrollee and does not integrate the exception into a practical application or provide an inventive concept.
Claims 11-13 are like claim 1 and therefore rejected for the same rational as claim 1.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 3-5, 11 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Witten et al. (US 10,958,666) in view of Anthe, II et al. (Pub. No.: US 2004/0250075).
Regarding claim 1: Witten teaches: A method of gaining trust in a server in a network, the method operated by a client, the method comprising:
- acquiring, by the client, a certificate of the server (Witten - [Col. 25, Line 20-21]: a client receives a certificate from a TLS server i);
- checking whether a root certificate of a certificate chain to which the certificate belongs, or the certificate itself, if it is a self-signed certificate, is in a trusted store of trusted certificates (Witten - [Col. 25, Line 21-31]: the client may first check to see if the certificate chains to a globally trusted root, such as roots routinely shipped by most browser and/or operating system vendors, or whether the certificate chains to a root existing in the local trust store of the device, but not globally trusted by browser and/or operating system vendors. If the certificate chains to a globally trusted root, the client may then begin sending data over the connection. If the certificate chains to locally trusted root which is not globally trusted, then the client may respond by requesting a certificate from the next upstream device from the client);
However, Witten doesn’t explicitly teach, but Anthe discloses:
- if the root certificate, or the certificate itself, if it is a self-signed certificate, is not in the trusted store, checking whether the server is local to the network, and if the server is local to the network, adding the root certificate, or, if the certificate is a self-signed certificate, adding the certificate itself to the store (Anthe – [0013]: The certificate authenticating component can then automatically install the self-signed web site certificate to domain web clients such that the self-signed web site certificate is trusted. [0031]: The signature component 120 additionally can automatically install the self-signed certificate to any web client that is local to the web site's domain (e.g., network), and automatically configure the web client(s) to employ the authentication and/or encryption mechanism (e.g., for at least a portion of the web site). [0034]: Thus, the web client on the local network can access the web site associated with the self-signed certificate without receiving a warning (e.g., that the web site is untrusted) and/or without manually trusting the self-signed certificate), and
if the server is not local to the network, aborting execution of the method (Anthe - [0005]: When a match is successful, the web client is typically provided access to the web site. However, when a match is unsuccessful, the web client is commonly provided with a notification indicating that the web site is untrusted).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Witten with Anthe so that checking if server is local is performed as part of verification before write certificate to trust store. The modification would have allowed the system to be more secure.
Regarding claim 3: Witten as modified teaches: comprising performing an ownership check of the certificate to verify if the certificate belongs to the server, and if the certificate belongs to the server, proceeding with execution of the method otherwise aborting the execution of the method (Witten - [0005]: the web site certificate can provide web site identification such as the web site's publisher, and can be employed to match a web site publisher with the certificate. When a match is successful, the web client is typically provided access to the web site. However, when a match is unsuccessful, the web client is commonly provided with a notification indicating that the web site is untrusted).
Regarding claim 4: Witten as modified teaches: wherein the server is without a connection to a Certification Authority (Anthe - [0037]: Typically, publishing a web site to the Internet comprises providing a web site certificate associated with the web site such that the validity (e.g., via SSL encryption) of the web site can be confirmed prior to the web browser accessing the web site. In general, the web site certificate can be purchased and/or created via certificate generating tools. Purchasing a web site certificate can be costly and can introduce a delay between requesting and receiving the web site certificate. The certificate generating component 210 provides the web publisher an inexpensive and efficient mechanism to generate the self-signed web site certificate, and mitigate delays from third party vendors).
The reason to combine is in the same rational as claim 1.
Regarding claim 5: Witten as modified teaches: comprising by the client, performing a signature check of the certificate, and, if the certificate is not a self-signed certificate, performing a signature check of all certificates in the certificate chain to which the certificate belongs (Witten - [Col. 25, Line 21-31]: the client may first check to see if the certificate chains to a globally trusted root, such as roots routinely shipped by most browser and/or operating system vendors, or whether the certificate chains to a root existing in the local trust store of the device) and if the result of the check is that at least one of the signatures is incorrect, aborting execution of the method (Anthe - [0005]: When a match is successful, the web client is typically provided access to the web site. However, when a match is unsuccessful, the web client is commonly provided with a notification indicating that the web site is untrusted).
The reason to combine is in the same rational as claim 1.
Regarding claim 11: Claim is directed to configurator device and do not teach or further define over the limitations recited in claim 1. Therefore, claim 11 are also rejected for similar reasons set forth in claim 1. Furthermore, Witten also discloses a wireless network interface to facilitate communication between computing system 910 and a private or public network including additional computing systems.
Regarding claim 13: this claim defines a computer program product claim that corresponds to method claim 1 and does not define beyond limitations of claim 1. Therefore, claim 13 is rejected with the same rational as in the rejection of claim 1.
Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Witten et al. (US 10,958,666) in view of Anthe, II et al. (Pub. No.: US 2004/0250075) and Vora et al. (US 2020/0028946).
Regarding claim 2: Witten as modified doesn’t explicitly teaches but Vora discloses wherein the server is a bootstrapping server and the client is a bootstrapping configurator (Vora - [0206]: When a device comes online for the first time, it contacts a bootstrap server. The bootstrap server provisions information on the device as well as in the platform service's server's back end to enable the device to communicate with the platform service's gateway servers. The bootstrap server implements a client-Initiated bootstrap interface).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Witten and Anthe with Vora so that The bootstrap server provisions information on the device. The modification would have allowed the system to implements a client-Initiated bootstrap interface.
Claims 6-7 rejected under 35 U.S.C. 103 as being unpatentable over Witten et al. (US 10,958,666) in view of Anthe, II et al. (Pub. No.: US 2004/0250075) and Benoit et al. (US 2015/0089216).
Regarding claim 6: Witten as modified doesn’t explicitly teaches but Benoit discloses where the certificate is obtained by an out-of-band (OOB) method (Benoit - [0030]: the certificate and the root public key are received out-of-band of the wireless network).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Witten and Anthe with Benoit so that the certificate is received out-of-band. The modification would have allowed the system to use OOB method.
Regarding claim 7: Witten as modified discloses where the OOB method involves a QR code or NFC (Benoit - [0029]: an out-of-band communication interface 460, such as an NFC and/or BLE connection).
The reason to combine is in the same rational as claim 6.
Claims 8-10 and 12 rejected under 35 U.S.C. 103 as being unpatentable over Witten et al. (US 10,958,666) in view of Anthe, II et al. (Pub. No.: US 2004/0250075) and SALUNKHE et al. (US 2024/0147229.
Regarding claim 8: Witten as modified doesn’t explicitly teaches but SALUNKHE discloses comprising configuring an enrollee for communication in a wireless network (SALUNKHE - [0051]: An enrollee client obtains an enrollee client specific configuration that enables the enrollee client to join a target network, for example, the Wi-Fi network).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Witten and Anthe with SALUNKHE so that enrolee is configured for communication in a wireless network. The modification would have allowed the system to use wireless communication.
Regarding claim 9: Witten as modified discloses comprising bootstrapping the enrollee by acquiring enrollee bootstrapping information by an OOB method (SALUNKHE - [0050]: a client device 4A communicating bootstrap information over Li-Fi as an OOB to an access point device 2).
The reason to combine is in the same rational as claim 8.
Regarding claim 10: Witten as modified doesn’t explicitly teaches but SALUNKHE discloses comprising the execution of a protocol according to the Wi-Fi Device Provisioning Protocol (SALUNKHE - [0052]: the DPP protocol is an extensible protocol that enables onboarding and configuration of network devices, such as one or more headless devices as illustrated in FIG. 3).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method of Witten and Anthe with SALUNKHE so that Device Provisioning Protocol is used. The modification would have allowed the system to configure a wi-fi device.
Regarding claim 12: Claim is directed to a bootstrapping configurator device that perform the method of claims 1 and 8-9. Therefore, claim 12 are also rejected for similar reasons set forth in claims 1 and 8-9. Furthermore, Witten also discloses a wireless network interface to facilitate communication between computing system 910 and a private or public network including additional computing systems.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Joglekar et al. US 12659135 - the issued certificate is provided by originator 602 to CPS identity service 606. The CPS identity service 606 may verify the certificate is valid (e.g., has a valid root of trust) and store the certificate for originator 602 so that other participants can discover originator.
Gollent et al. US 20230412397 - [0091] Once a verifying end entity receives the secondary crypto-agile certificate of the root CA, the verifying end entity can use the first root certificate of the root CA to verify the validity of the secondary crypto-agile certificate of the root CA, and then add the secondary crypto-agile certificate of the root CA to the trust store upon successful verification
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MENG LI whose telephone number is (571)272-8729. The examiner can normally be reached M-F 8:30-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MENG LI/
Primary Examiner, Art Unit 2437