DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office Action is in response to Application 19145440 filed on 07/02/2025. Claims 8-9, 24, and 34 were currently amended via the preliminary amendments. Claims 10, 12-22, 31-32, and 35 were currently cancelled via the preliminary amendments. Claims 1, 23, and 34 are independent claims. Claims 1-9, 11, 23-30, and 33-34 have been examined and are pending in this application. This Office Action is made Non-Final.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 07/02/2025, 12/18/2025, and 03/30/2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Objections
Claims 2, 9, and 24 are objected to because of the following informalities:
Regarding claim 2, 9, and 24, the acronym ‘EAP” are used without spelling out in full at its first occurrence in the claims. Appropriate correction is required.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 23, and 34 are rejected under 35 U.S.C. 103 as being unpatentable over LIU et al. (“LIU,” CN 102970308, published on 03/13/2013) in view of Kobayashi et al. (“Kobayashi,” US 20190095598, published on 03/28/2019).
Regarding Claim 1;
LIU discloses a terminal authentication method, which is applied to an access device, comprising (par 0003; provide a can support authentication method and server of the plurality of authentication source to improve the user authentication service performance):
sending a first packet to each of multiple authentication servers respectively, wherein the first packet is used to request an authentication server to perform access authentication on a terminal (par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source); and
in response to a second packet sent by any one of the authentication servers is received and the second packet is a second packet firstly sent by the multiple authentication servers after receiving the first packet (par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0048; In step 810, the user authentication server through the data in the local cache is searched from the user terminal obtaining the user name and password information, if the user name and password information exists in the local cache, then executing step 840, returning the authentication success information; par 0055; as long as receiving the successful authentication message of one data source of the plurality of authentication sources in the predetermined time, the authentication is successful),
sending a third packet to the terminal (par 0048; In step 810, the user authentication server through the data in the local cache is searched from the user terminal obtaining the user name and password information, if the user name and password information exists in the local cache, then executing step 840, returning the authentication success information, otherwise, returning the authentication failure information, and executing the step 820.; par 0049; In step 820, the authentication server to authenticate the user through multiple authentication sources, if the user authentication is successful, executing step 821; par 0050; In step 821, the user authentication server sends the successful authentication of the user name, password, authentication source and authentication time stored in the local buffer),
wherein the second packet and the third packet are both used to indicate that the access authentication on the terminal is successful (par 0048; In step 810, the user authentication server through the data in the local cache is searched from the user terminal obtaining the user name and password information, if the user name and password information exists in the local cache, then executing step 840, returning the authentication success information; par 0049; if the user authentication is successful, executing step 821; par 0050; In step 821, the user authentication server sends the successful authentication of the user name, password, authentication source and authentication time stored in the local buffer).
LIU disclose in response to a second packet sent by any one of the authentication servers is received and the second packet is a second packet firstly sent by the multiple authentication servers after receiving the first packet as recited above, but do not explicitly disclose determining that a second packet sent by any one of the authentication servers.
However, in an analogous art, Kobayashi discloses control method system/method that includes:
determining that a second packet sent by any one of the authentication servers (Kobayashi: par 0067; identifies the authorization endpoint URL of the region using the specified region information and Table 1, obtains the authorization token and refresh token from the authorization server identified by this authorization endpoint URL).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Kobayashi with the method/system of LIU to include determining that a second packet sent by any one of the authentication servers. One would have been motivated to identifies an authorization endpoint based on region information received from an application and associated with the user, transmits an authorization code request to an authorization endpoint, and receives an authorization code response from the authorization endpoint, corresponding to the authorization code request (Kobayashi: abstract).
Regarding Claim 23;
This Claim recites a device that perform the same steps as method of Claim 1, and has limitations that are similar to Claim 1, thus are rejected with the same rationale applied against claim 1.
Regarding Claim 34;
This Claim recites a non-transitory machine readable storage medium that perform the same steps as method of Claim 1, and has limitations that are similar to Claim 1, thus are rejected with the same rationale applied against claim 1.
Claim 2, 9, and 24 are rejected under 35 U.S.C. 103 as being unpatentable over LIU et al. (CN 102970308) in view of Kobayashi et al. (US 20190095598), and further in view of ZHANG et al. (“ZHANG,” CN 102833750, published on 12/19/2012).
Regarding Claim 2;
The combination of LIU and Kobayashi disclose the method of claim 1,
LIU discloses wherein after sending a first packet to each of multiple authentication servers, the method further comprises (LIU: par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source): in response to a fourth packet sent by any one of the authentication servers is received and the fourth packet is a fourth packet firstly sent by the multiple authentication servers after receiving the first packet (LIU: par 0028; when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source; par 0037; Radius server sends the user name information and database information comparing and analyzing, if the user name exists, then sends the confirming information to the authentication server; par 0055; as long as receiving the successful authentication message of one data source of the plurality of authentication sources in the predetermined time, the authentication is successful), sending a fifth packet to the terminal (LIU: par 0038 the authentication server after receiving the confirmation information from the Radius server, continuously sent to Radius server acquired by the password information from the user terminal; par 0039; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information), receiving a sixth packet sent by the terminal, wherein the sixth packet comprises user identity information, and the user identity information is encrypted by the authentication parameter (LIU: par 0026; sends the user name information of the authentication request, and waiting for return to a plurality of authentication data source; par 0028; when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source; par 0031; sending the authentication request packet to the Radius server; par 0032; Radius server compares and analyzes the user information and database information, if there is user name, sending the random code to the authentication server); and sending a seventh packet to each of the authentication servers respectively, wherein the seventh packet comprises the sixth packet and the packet, to enable the authentication server to verify the user identity information based on the authentication parameter (LIU: par 0026; sends the user name information of the authentication request, and waiting for return to a plurality of authentication data source; par 0032; Radius server compares and analyzes the user information and database information, if there is user name, sending the random code to the authentication server; par 0033; transmits the received random code performing encryption processing, and returns after encrypting the random code to the Radius server; par 0034; Radius server for random code encrypted validity check, if the check is successful, returning the authentication success information to the authentication server).
Kobayashi further discloses determining that a fourth packet sent by any one of the authentication servers (Kobayashi: par 0067; identifies the authorization endpoint URL of the region using the specified region information and Table 1, obtains the authorization token and refresh token from the authorization server identified by this authorization endpoint URL).
The motivation is the same that of claim 1 above.
The combination of LIU and Kobayashi disclose sending a fifth packet to the terminal as recited above, but do not explicitly disclose wherein the fifth packet comprises an authentication parameter, and the authentication parameter is carried by an EAP packet comprised in the fourth packet; the EAP packet.
However, in an analogous art, ZHANG discloses message transmission system/method that includes:
wherein the fifth packet comprises an authentication parameter, and the authentication parameter is carried by an EAP packet comprised in the fourth packet (ZHANG: par 0028; added an EAP Message MTU parameter as the authentication message using the TCP connection for transmitting the threshold value. Length is greater than the MTU for the message to be transmitted); the EAP packet (ZHANG: par 0028; added an EAP Message MTU parameter as the authentication message using the TCP connection for transmitting the threshold value. Length is greater than the MTU for the message to be transmitted).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of ZHANG with the method/system of LIU and Kobayashi to include wherein the fifth packet comprises an authentication parameter, and the authentication parameter is carried by an EAP packet comprised in the fourth packet; the EAP packet. One would have been motivated to judge whether the length of the message to be transmitted is greater than the preset EAP Message MTU; if so, adopting the TCP transmission mode to transmit message to be transmitted (ZHANG: abstract).
Regarding Claim 9;
The combination of LIU, Kobayashi and ZHANG disclose the method of claim 2,
ZHANG discloses wherein the seventh packet comprises an EAP-Message attribute, and the EAP-Message attribute is used to carry the EAP packet (ZHANG: par 0028; added an EAP Message MTU parameter as the authentication message using the TCP connection for transmitting the threshold value. Length is greater than the MTU for the message to be transmitted), wherein the EAP-Message attribute has a preset length (ZHANG: par 0041; judging whether the length of the message to be transmitted is greater than a predetermined transmission threshold value EAP Message MTU); and in response to determining that the length of the EAP packet is greater than the preset length, the seventh packet comprises multiple EAP-Message attributes, and the EAP packet is carried in the multiple EAP-Message attributes in a form of fragmentation (ZHANG: par 0041; judging whether the length of the message to be transmitted is greater than a predetermined transmission threshold value EAP Message MTU; par 0044; if the length of the message to be transmitted is greater than a predetermined transmission threshold value after EAP Message MTU, judging result is no, then also uses user datagram protocol UDP transmission mode to transmit message to be transmitted).
The motivation is the same that of claim 2 above.
Regarding Claim 24;
The combination of LIU and Kobayashi disclose the access device of claim 23,
LIU discloses wherein the machine executable instructions further cause the processor to: in response to determining that a fourth packet sent by any one of the authentication servers is received through the transceiver and the fourth packet is a fourth packet firstly sent by the multiple authentication servers after receiving the first packet (LIU: par 0028; when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source; par 0037; Radius server sends the user name information and database information comparing and analyzing, if the user name exists, then sends the confirming information to the authentication server; par 0055; as long as receiving the successful authentication message of one data source of the plurality of authentication sources in the predetermined time, the authentication is successful), send a fifth packet to the terminal through the transceiver (LIU: par 0038 the authentication server after receiving the confirmation information from the Radius server, continuously sent to Radius server acquired by the password information from the user terminal; par 0039; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information), receive a sixth packet sent by the terminal through the transceiver, wherein the sixth packet comprises user identity information, and the user identity information is encrypted by the authentication parameter (LIU: par 0026; sends the user name information of the authentication request, and waiting for return to a plurality of authentication data source; par 0028; when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source; par 0031; sending the authentication request packet to the Radius server; par 0032; Radius server compares and analyzes the user information and database information, if there is user name, sending the random code to the authentication server); and send a seventh packet to each of the authentication servers through the transceiver, wherein the seventh packet comprises the sixth packet and the EAP packet, to enable the authentication server to verify the user identity information based on the authentication parameter (LIU: par 0026; sends the user name information of the authentication request, and waiting for return to a plurality of authentication data source; par 0032; Radius server compares and analyzes the user information and database information, if there is user name, sending the random code to the authentication server; par 0033; transmits the received random code performing encryption processing, and returns after encrypting the random code to the Radius server; par 0034; Radius server for random code encrypted validity check, if the check is successful, returning the authentication success information to the authentication server).
Kobayashi further discloses determining that a fourth packet sent by any one of the authentication servers (Kobayashi: par 0067; identifies the authorization endpoint URL of the region using the specified region information and Table 1, obtains the authorization token and refresh token from the authorization server identified by this authorization endpoint URL).
The motivation is the same that of claim 23 above.
The combination of LIU and Kobayashi disclose sending a fifth packet to the terminal as recited above, but do not explicitly disclose wherein the fifth packet comprises an authentication parameter and the authentication parameter is carried by an EAP packet comprised in the fourth packet; the EAP packet; wherein the seventh packet comprises an EAP-Message attribute, and the EAP-Message attribute is used to carry the EAP packet, and wherein the EAP-Message attribute has a preset length; and in response to determining that the length of the EAP packet is greater than the preset length, the seventh packet comprises multiple EAP-Message attributes, and the EAP packet is carried in the multiple EAP-Message attributes in a form of fragmentation.
However, in an analogous art, ZHANG discloses message transmission system/method that includes:
wherein the fifth packet comprises an authentication parameter and the authentication parameter is carried by an EAP packet comprised in the fourth packet (ZHANG: par 0028; added an EAP Message MTU parameter as the authentication message using the TCP connection for transmitting the threshold value. Length is greater than the MTU for the message to be transmitted); the EAP packet (ZHANG: par 0028; added an EAP Message MTU parameter as the authentication message using the TCP connection for transmitting the threshold value. Length is greater than the MTU for the message to be transmitted); wherein the seventh packet comprises an EAP-Message attribute, and the EAP-Message attribute is used to carry the EAP packet (ZHANG: par 0028; added an EAP Message MTU parameter as the authentication message using the TCP connection for transmitting the threshold value. Length is greater than the MTU for the message to be transmitted), and wherein the EAP-Message attribute has a preset length (ZHANG: par 0041; judging whether the length of the message to be transmitted is greater than a predetermined transmission threshold value EAP Message MTU); and in response to determining that the length of the EAP packet is greater than the preset length, the seventh packet comprises multiple EAP-Message attributes, and the EAP packet is carried in the multiple EAP-Message attributes in a form of fragmentation (ZHANG: par 0041; judging whether the length of the message to be transmitted is greater than a predetermined transmission threshold value EAP Message MTU; par 0044; if the length of the message to be transmitted is greater than a predetermined transmission threshold value after EAP Message MTU, judging result is no, then also uses user datagram protocol UDP transmission mode to transmit message to be transmitted).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of ZHANG with the method/system of LIU and Kobayashi to include wherein the fifth packet comprises an authentication parameter and the authentication parameter is carried by an EAP packet comprised in the fourth packet; the EAP packet; wherein the seventh packet comprises an EAP-Message attribute, and the EAP-Message attribute is used to carry the EAP packet, and wherein the EAP-Message attribute has a preset length; and in response to determining that the length of the EAP packet is greater than the preset length, the seventh packet comprises multiple EAP-Message attributes, and the EAP packet is carried in the multiple EAP-Message attributes in a form of fragmentation. One would have been motivated to judge whether the length of the message to be transmitted is greater than the preset EAP Message MTU; if so, adopting the TCP transmission mode to transmit message to be transmitted (ZHANG: abstract).
Claims 3-5 and 25-27 are rejected under 35 U.S.C. 103 as being unpatentable over LIU et al. (CN 102970308) in view of Kobayashi et al. (US 20190095598), and further in view of ZHANG et al. (CN 102833750) and Wang et al. (“Wang,” US 20190132419, published on 05/02/2019).
Regarding Claim 3;
The combination of LIU, Kobayashi and ZHANG disclose the method of claim 2,
LIU discloses wherein after sending a first packet to each of multiple authentication servers, the method further comprises (LIU: par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source): in response to determining that a same number of eighth packets as that of the multiple authentication servers are received within a first preset duration and an authentication result carried by each of the eighth packets indicates that the access authentication on the terminal is failed (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); the authentication result of each of the servers for the terminal as access authentication failure (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); and sending a ninth packet to the terminal, wherein the ninth packet is used to indicate that the access authentication on the terminal is failed (LIU: par 0043; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information to the authentication server, or else, returns authentication failure information to the authentication server).
The combination of LIU, Kobayashi and Ding disclose the authentication result of each of the servers for the terminal as access authentication failure as recited above, but do not explicitly disclose respectively recording the authentication result.
However, in an analogous art, Wang discloses service requests system/method that includes:
respectively recording the authentication result (Wang: par 0073; concurrently processes a large volume of requests, the subset of requests that fail the score threshold and result in a score offset respectively result in the initiation of a record with a small number of data items).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Wang with the method/system of LIU and Kobayashi and ZHANG to include respectively recording the authentication result. One would have been motivated to protect sensitive resources through a login interface my prohibit users from attempting to guess passwords of other users and resources, such as brute-force guessing of usernames and passwords (Wang: par 0001).
Regarding Claim 4;
The combination of LIU, Kobayashi and ZHANG disclose the method of claim 2,
LIU discloses wherein after sending a first packet to each of multiple authentication servers, the method further comprises (LIU: par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source): in response to determining that no packet sent by any one of the authentication servers is received after expiration of a first preset duration, an authentication result of each of the servers for the terminal as authentication server being unreachable (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); and sending a ninth packet to the terminal, wherein the ninth packet is used to indicate that the access authentication on the terminal is failed (LIU: par 0043; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information to the authentication server, or else, returns authentication failure information to the authentication server).
The combination of LIU, Kobayashi and Ding disclose an authentication result of each of the servers for the terminal as authentication server being unreachable as recited above, but do not explicitly disclose respectively recording the authentication result.
However, in an analogous art, Wang discloses service requests system/method that includes:
respectively recording the authentication result (Wang: par 0073; concurrently processes a large volume of requests, the subset of requests that fail the score threshold and result in a score offset respectively result in the initiation of a record with a small number of data items).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Wang with the method/system of LIU and Kobayashi and ZHANG to include respectively recording the authentication result. One would have been motivated to protect sensitive resources through a login interface my prohibit users from attempting to guess passwords of other users and resources, such as brute-force guessing of usernames and passwords (Wang: par 0001).
Regarding Claim 5;
The combination of LIU, Kobayashi and ZHANG disclose the method of claim 2,
LIU discloses wherein after sending a first packet to each of multiple authentication servers, the method further comprises (LIU: par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source): in response to determining that eighth packets sent by a first number of authentication servers are received within a first preset duration and an authentication result carried by each of the eighth packets indicates that the access authentication on the terminal is failed (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails), authentication results of the first number of authentication servers on the terminal as access authentication failure (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); in response to determining that packets sent by a second number of authentication servers in the multiple authentication servers have not been received after expiration of the first preset duration, authentication results of the second number of authentication servers for the terminal as authentication server being unreachable (LIU: par 0055; as long as receiving the successful authentication message of one data source of the plurality of authentication sources in the predetermined time, the authentication is successful, otherwise, the authentication is failed; par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); and sending a ninth packet or a tenth packet to the terminal, wherein the ninth packet is used to indicate that the access authentication on the terminal is failed (LIU: par 0043; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information to the authentication server, or else, returns authentication failure information to the authentication server), and the tenth packet is used to indicate that the access authentication on the terminal is successful (LIU: par 0043; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information), and a sum of the first number and the second number is the same as the number of the multiple authentication servers (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails).
The combination of LIU, Kobayashi and Ding disclose authentication results of the first number of authentication servers on the terminal as access authentication failure as recited above, but do not explicitly disclose respectively recording the authentication result.
However, in an analogous art, Wang discloses service requests system/method that includes:
respectively recording the authentication result (Wang: par 0073; concurrently processes a large volume of requests, the subset of requests that fail the score threshold and result in a score offset respectively result in the initiation of a record with a small number of data items).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Wang with the method/system of LIU and Kobayashi and ZHANG to include respectively recording the authentication result. One would have been motivated to protect sensitive resources through a login interface my prohibit users from attempting to guess passwords of other users and resources, such as brute-force guessing of usernames and passwords (Wang: par 0001).
Regarding Claim 25;
This Claim recites a device that perform the same steps as method of Claim 3, and has limitations that are similar to Claim 3, thus are rejected with the same rationale applied against claim 3.
Regarding Claim 26;
This Claim recites a device that perform the same steps as method of Claim 4, and has limitations that are similar to Claim 4, thus are rejected with the same rationale applied against claim 4.
Regarding Claim 27;
This Claim recites a device that perform the same steps as method of Claim 5, and has limitations that are similar to Claim 5, thus are rejected with the same rationale applied against claim 5.
Claims 6-8 and 28-30 are rejected under 35 U.S.C. 103 as being unpatentable over LIU et al. (CN 102970308) in view of Kobayashi et al. (US 20190095598), and further in view of Wang et al. (“Wang,” US 20190132419, published on 05/02/2019).
Regarding Claim 6;
The combination of LIU and Kobayashi disclose the method of claim 1,
LIU discloses wherein after sending a first packet to each of multiple authentication servers, the method further comprises (LIU: par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source): in response to determining that a same number of eighth packets as that of the multiple authentication servers are received within a second preset duration and an authentication result carried by each of the eighth packets indicates that the access authentication on the terminal is failed (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails), an authentication result of each of the servers for the terminal as access authentication failure (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); and sending a ninth packet to the terminal, wherein the ninth packet is used to indicate that the access authentication on the terminal is failed (LIU: par 0043; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information to the authentication server, or else, returns authentication failure information to the authentication server).
The combination of LIU, Kobayashi and Ding disclose an authentication result of each of the servers for the terminal as access authentication failure as recited above, but do not explicitly disclose respectively recording the authentication result.
However, in an analogous art, Wang discloses service requests system/method that includes:
respectively recording the authentication result (Wang: par 0073; concurrently processes a large volume of requests, the subset of requests that fail the score threshold and result in a score offset respectively result in the initiation of a record with a small number of data items).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Wang with the method/system of LIU and Kobayashi and Ding to include respectively recording the authentication result. One would have been motivated to protect sensitive resources through a login interface my prohibit users from attempting to guess passwords of other users and resources, such as brute-force guessing of usernames and passwords (Wang: par 0001).
Regarding Claim 7;
The combination of LIU and Kobayashi disclose the method of claim 1,
LIU discloses wherein after sending a first packet to each of multiple authentication servers, the method further comprises (LIU: par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source): in response to determining that no packet sent by any one of the authentication servers is received after expiration of a second preset duration (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails), an authentication result of each of the servers for the terminal as authentication server being unreachable (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); and sending a ninth packet to the terminal, wherein the ninth packet is used to indicate that the access authentication on the terminal is failed (LIU: par 0043; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information to the authentication server, or else, returns authentication failure information to the authentication server).
The combination of LIU, Kobayashi and Ding disclose authentication result of each of the servers for the terminal as authentication server being unreachable as recited above, but do not explicitly disclose respectively recording the authentication result.
However, in an analogous art, Wang discloses service requests system/method that includes:
respectively recording the authentication result (Wang: par 0073; concurrently processes a large volume of requests, the subset of requests that fail the score threshold and result in a score offset respectively result in the initiation of a record with a small number of data items).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Wang with the method/system of LIU and Kobayashi and Ding to include respectively recording the authentication result. One would have been motivated to protect sensitive resources through a login interface my prohibit users from attempting to guess passwords of other users and resources, such as brute-force guessing of usernames and passwords (Wang: par 0001).
Regarding Claim 8;
The combination of LIU and Kobayashi disclose the method of claim 1,
LIU discloses wherein after sending a first packet to each of multiple authentication servers, the method further comprises (LIU: par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source): in response to determining that eighth packets sent by a third number of authentication servers are received within a second preset duration and an authentication result carried by each of the eighth packets indicates that the access authentication on the terminal is failed (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails), authentication results of the third number of authentication servers for the terminal as access authentication failure (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); in response to determining that packets sent by a fourth number of authentication servers in the multiple authentication servers have not been received after expiration of the second preset duration (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails), respectively recording authentication results of the fourth number of authentication servers for the terminal as authentication server being unreachable (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails); and sending a ninth packet or a tenth packet to the terminal, wherein the ninth packet is used to indicate that the access authentication on the terminal is failed (LIU: par 0043; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information to the authentication server, or else, returns authentication failure information to the authentication server), and the tenth packet is used to indicate that the access authentication on the terminal is successful (LIU: par 0043; Radius server performing the validity test for password information, if the verification is successful, returning the authentication success information), and a sum of the third number and the fourth number is the same as the number of the multiple authentication servers (LIU: par 0028; where in the predetermined time, when the authentication server receives the failure authentication information to one of a plurality of authentication source authentication source, waiting authentication information of other authentication source, when all the authentication source returns an authentication failure message. the user authentication fails).
The combination of LIU, Kobayashi and Ding disclose authentication results of the third number of authentication servers for the terminal as access authentication failure as recited above, but do not explicitly disclose respectively recording the authentication result.
However, in an analogous art, Wang discloses service requests system/method that includes:
respectively recording the authentication result (Wang: par 0073; concurrently processes a large volume of requests, the subset of requests that fail the score threshold and result in a score offset respectively result in the initiation of a record with a small number of data items).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Wang with the method/system of LIU and Kobayashi and Ding to include respectively recording the authentication result. One would have been motivated to protect sensitive resources through a login interface my prohibit users from attempting to guess passwords of other users and resources, such as brute-force guessing of usernames and passwords (Wang: par 0001).
Regarding Claim 28;
This Claim recites a device that perform the same steps as method of Claim 6, and has limitations that are similar to Claim 6, thus are rejected with the same rationale applied against claim 6.
Regarding Claim 29;
This Claim recites a device that perform the same steps as method of Claim 7, and has limitations that are similar to Claim 7, thus are rejected with the same rationale applied against claim 7.
Regarding Claim 30;
This Claim recites a device that perform the same steps as method of Claim 8, and has limitations that are similar to Claim 8, thus are rejected with the same rationale applied against claim 8.
Claims 11 and 33 are rejected under 35 U.S.C. 103 as being unpatentable over LIU et al. (CN 102970308) in view of Kobayashi et al. (US 20190095598), and further in view of XING et al. (“XING,” CN 115801382, published on 3/14/2023).
Regarding Claim 11;
The combination of LIU and Kobayashi disclose the method of claim 1,
LIU discloses wherein the access device is connected to multiple sets of authentication servers; and the sending a first packet to each of multiple authentication servers comprises (LIU: par 0023; sends the authentication request for the user information is sent to the authentication source 13 (authentication source I, authentication source 2, ..., authentication source N), waiting for authentication feedback information; par 0029; sends an authentication request through the source to a plurality of authentication to authenticate the user, realizes the multiple authentication with authentication service function source):
The combination of LIU and Kobayashi disclose all the limitations as recited above, but do not explicitly disclose selecting a set of authentication servers from the multiple sets of authentication servers in a load-sharing manner, and sending the first packet to the selected set of authentication servers; or, selecting a preset number of authentication servers from each set of the multiple sets of authentication servers respectively in a load-sharing manner, and sending the first packet to the selected authentication servers.
However, in an analogous art, XING discloses information authentication system/method that includes:
selecting a set of authentication servers from the multiple sets of authentication servers in a load-sharing manner (XING: page 2, par 7; selecting the corresponding number of authentication servers from the plurality of authentication servers according to the security level, as the sending target; sending the biological characteristic ciphertext to the sending target), and sending the first packet to the selected set of authentication servers; or, selecting a preset number of authentication servers from each set of the multiple sets of authentication servers respectively in a load-sharing manner, and sending the first packet to the selected authentication servers (XING: page 2, par 7; selecting the corresponding number of authentication servers from the plurality of authentication servers according to the security level, as the sending target; sending the biological characteristic ciphertext to the sending target).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of XING with the method/system of LIU and Kobayashi to include selecting a set of authentication servers from the multiple sets of authentication servers in a load-sharing manner, and sending the first packet to the selected set of authentication servers; or, selecting a preset number of authentication servers from each set of the multiple sets of authentication servers respectively in a load-sharing manner, and sending the first packet to the selected authentication servers. One would have been motivated to use the processing mode corresponding to the authentication server to obtain the authentication information, matching the authentication information with the authentication information successfully authenticated before authentication, confirming the authentication result of the biological characteristic ciphertext (XING: abstract).
Regarding Claim 33;
This Claim recites a device that perform the same steps as method of Claim 11, and has limitations that are similar to Claim 11, thus are rejected with the same rationale applied against claim 11.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHAO WANG whose telephone number is (313)446-6644. The examiner can normally be reached on Monday-Friday 7:30-4:30PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached on (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/C.W./Examiner, Art Unit 2439
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439