Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1-20 are pending.
Claim Rejections - 35 USC § 103
I. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
II. CLAIMS 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over EVERHART et al (US 2016/0112408) in view of ANTAR et al (US 2020/0218795).
Per claim 14, EVERHART et al teach a non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to:
store a group digital certificate including a plurality of unique identifier (UID) values (paras 0026, 0028-29, 0031-32, 0034-37—generating and maintaining a group digital certificate including public encryption keys, unique identifiers);
generate and transmit a nonce value to a client device (paras 0034, 0046—group roster includes entities identifiers which is a numerical value that uniquely identifies an entity or group of entities);
receive from the client device: (ii) a digital signature generated using a private key corresponding to the public key (paras 0028, 0032-34—generating digital signature using corresponding private and public keys);
verifying the nonce value and the monotonic counter value (paras 0034, 0046—numerical values); and
confirming that the UID matches at least one UID in the group digital certificate (paras 0046, 0049-50—verification can involve the second entity identifying that the signature of the group roster cryptographically matches the group digital certificate).
EVERHART et al fail to teach the limitations, as applied above, “a Subject field and a plurality of corresponding public keys in a Subject Public Key Info field; receive from the client device: (i) onboarding data comprising the nonce value, a monotonic counter value, a UID of the client device, and a public key of the client device, and (ii) a digital signature generated using a private key corresponding to the public key; validate freshness of the onboarding data by verifying the nonce value and the monotonic counter value; and onboard the client device upon confirming that the UID matches”. ANTAR et al further teach a header section comprising various fields including a nonce, a counter and verified values in a publicKey field and subject identifiers in outputNode, targetNode, inputNode and name fields (paras 0070-72, 0074-75, 0077) while onboarding user identification and generated digital signatures using private and public keys (paras 0049-51, 0080, 0109-110, 0118-120).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed the invention was made to combine the teachings of EVERHART et al with ANTAR et al for the purpose of provisioning the onboarding of data for verifying and authorizing information using nonce values, digital signatures, public keys, private keys and fields for storing subject identifiers; which is well-known in the art.
Claims 1-4 and 8-10 contain limitations that are substantially equivalent to the claim limitations of claim 14, and are therefore rejected under the same basis.
Per claim 15, EVERHART et al with ANTAR et al teach the non-transitory computer-readable storage medium of claim 14, ANTAR et al further teach wherein validating the freshness of the onboarding data comprises comparing the received monotonic counter value with an expected monotonic counter value to prevent replay attacks (paras 0070, 0072-74—nonce counter to generate a correct hash, revoking unauthorized access).
Per claim 16, EVERHART et al with ANTAR et al teach the non-transitory computer-readable storage medium of claim 14, ANTAR et al further teach wherein validating the freshness of the onboarding data further comprises confirming that the received nonce value matches the generated nonce value (paras 0048, 0070, 0122, 0131—nonce counter to generate a correct hash, unique identifier and account matching; using database to confirm association with device).
Claims 5 and 11 contain limitations that are substantially equivalent to the claim limitations of claim 16, and are therefore rejected under the same basis.
Per claim 17, EVERHART et al with ANTAR et al teach the non-transitory computer-readable storage medium of claim 14, ANTAR et al further teach wherein the instructions further cause the processor to validate the digital signature by: using the public key of the client device to verify that the digital signature was generated using the private key; and determining that the digital signature was generated using the onboarding data (paras 0035, 0109-110, 0118-120---validating digital signature using private key; EVERHART et al: paras 0028, 0032-34—generating digital signature using corresponding private and public key).
Claim 6 contains limitations that are substantially equivalent to the claim limitations of claim 17, and are therefore rejected under the same basis.
Per claim 18, EVERHART et al with ANTAR et al teach the non-transitory computer-readable storage medium of claim 14, ANTAR et al further teach wherein onboarding the client device comprises: associating the client device with an account stored in a database; and transmitting a success response to the client device (paras 0047-49, 0099—using database to confirm association with client device for authorizing access, send acknowledgement in response to authorization of device).
Claims 7 and 13 contain limitations that are substantially equivalent to the claim limitations of claim 18, and are therefore rejected under the same basis.
Per claim 19, EVERHART et al with ANTAR et al teach the non-transitory computer-readable storage medium of claim 14, ANTAR et al further teach wherein the instructions further cause the processor to, upon failure to validate any of: the nonce value, the monotonic counter value, the digital signature, or the UID, transmit a failure message to the client device indicating which validation failed (paras 0073, 0093, 0109—revoking access based on permission authorization failure and transmitting revoke message to the distributed ledger).
Per claim 20, EVERHART et al with ANTAR et al teach the non-transitory computer-readable storage medium of claim 14, EVERHART et al wherein the group digital certificate is received from a key management system (KMS) that generates the group digital certificate by including multiple UIDs and corresponding public keys in a digital certificate format similar to X.509 (paras 0029-37, 0051—group manager module for generating group digital certificate associated with group roster including multiple user identifiers with corresponding public keys; ANTAR et al: paras 0074, 0084-85—digital certificate may comprise an X.509 certificate).
Per claim 5, EVERHART et al with ANTAR et al teach the device of claim 4, ANTAR et al further teach wherein the instructions are further executable to validate the identification information by confirming that the nonce value matches an expected nonce value and confirming that the monotonic counter value is valid (paras 0048, 0070, 0122, 0131—nonce counter to generate a correct hash, unique identifier and account matching; using database to confirm association with user device).
Claim 11 contains limitations that are substantially equivalent to the claim limitations of claim 5, and are therefore rejected under the same basis.
Per claim 12, EVERHART et al with ANTAR et al teach the method of claim 8, ANTAR et al further teach wherein validating the digital signature comprises: extracting the public key from the onboarding data; hashing the onboarding data to generate a first hash; decrypting the digital signature using the public key to generate a second hash; and comparing the first hash and the second hash to confirm that the digital signature is valid (paras 0025, 0027, 0035, 0046, 0049-51, 0070, 0076—identifier associated with the device may comprise a hash of a device public key associated with the device, digital signature may comprise a hash of transaction data encrypted with a private key corresponding to the public key and decrypting the digital signature with the public key, obtaining cryptographic hashed data from the distributed database, comparing generated hash with previous record hash).
Conclusion
III. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 2020/0382325; US 2021/0336797; US 2019/0238555.
IV. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KRISTIE D. SHINGLES whose telephone number is (571) 272-3888. The examiner can normally be reached on Monday-Thursday 10am-7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal Divecha can be reached on 571-272-5863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KRISTIE D SHINGLES/Primary Examiner, Art Unit 2453