DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Smullen et al. (US 2018/0212904) in view of Zalila-Wenkstern (US 2012/0259826).
Regarding claims 1, 11, and 18, Smullen teaches a method (and corresponding system and medium), comprising:
Receiving, from an application of a client device, a query indicating a request for information (Query from user for data - see [0133]).
Determining that a reply to the query is associated with the provider computing system or an external computing system external to the provider computing system (Content and functionality can range from simple static response (i.e., provider computing system) to integrated transactions with external systems - see [0135]).
Causing the application to present the reply to the query (Determine suitable reply - see [0126]. Generating a reply to the query - see [0357]).
Smullen further teaches making an authenticated call to an external system in order to pull information for a specific user - see [0240]. However, Smullen does not teach authenticating a user of the client device to a first authentication layer linked with the provider computing system in response to the reply and the user being associated with the provider computing system or authenticating the user of the client device to a second authentication layer linked with the external computing system in response to the reply and the user being associated with the external computing system.
Zalila-Wenktern teaches For instance, the web user interface 702 may authenticate the user to the "internal" user interface system by retrieving information from web UI database 712, which stores information concerning the web user interface 702 (including login credentials, color schemes, layouts, etc.), and then authenticating the user's credentials. The web user interface 702 may also authenticate the user to an "external" user interface (e.g., Facebook, Google, or OpenID providers, etc.) by authenticating the user-supplied credentials with the external, third-party site - see [0090].
This demonstrates the concept of internal vs. external authentication layers. Smullen teaches determining if a reply to a query is associated with the service provider or external to the service provider, as well as making an authenticated call to an external system in order to pull information for a user - see [0240]. Therefore, the combination of Smullen and Zalila-Wenktern suggests authenticating a user to different authentication layers in response to the user and reply being associated with the provider computing system or an external system, and the reply to the query being presented according to the authentication layer.
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Smullen by authenticating a user of the client device to a first authentication layer linked with the provider computing system in response to the reply and the user being associated with the provider computing system or authenticating the user of the client device to a second authentication layer linked with the external computing system in response to the reply and the user being associated with the external computing system, in order to use the appropriate level of authentication, based upon the beneficial teachings provided by Zalila-Wenktern. These modifications would result in better security for the system.
Regarding claims 2 and 12, Smullen teaches causing the application to present the reply according to data of the provider computing system, in response to the reply and the user being associated with the provider computing system - see [0135].
Regarding claims 4 and 14, Smullen teaches causing the application to present the reply including the data from the data provider computing system, in a chatbot format responsive to the query - see [0135].
Regarding claim 19, Smullen teaches: causing the application to present the reply according to data of the provider computing system, in response to the reply and the user being associated with the provider computing system and causing the application to present the reply including the data from the data provider computing system, in a chatbot format responsive to the query
Regarding claims 3 and 13, the combination of Smullen and Zalila-Wenktern teaches obtaining from the provider computing system via the first authentication layer, wherein the data of the provider computing system is restricted by the first authentication layer (Zalila-Wenktern teaches that credentials are required, thus restricting the data - see [0090]).
Regarding claims 5 and 15, Smullen teaches causing the application to present the reply according to data of the external computing system, in response to the reply and the user being associated with the external computing system - see [0135].
Regarding claims 6 and 16, the combination of Smullen and Zalila-Wenktern teaches obtaining the data from the external computing system via an API (Bots are designed to be able to pull information from external data systems. This may be done by any of a number of standard methods, such as API calls - see Smullen [0240]) configured according to the second authentication layer (The web user interface 702 may also authenticate the user to an "external" user interface (e.g., Facebook, Google, or OpenID providers, etc.) by authenticating the user-supplied credentials with the external, third-party site - see [0090] of Zalila-Wenktern), wherein the data of the external computing system is restricted by the second authentication layer (Zalila-Wenktern teaches that credentials are required, thus restricting the data - see [0090]).
Regarding claims 7 and 17, Smullen teaches causing the application to present the reply including the data from the data provider computing system, in a chatbot format responsive to the query - see [0135].
Regarding claim 20, the combination of Smullen and Zalila-Wenktern teaches obtaining the data from the external computing system via an API (Bots are designed to be able to pull information from external data systems. This may be done by any of a number of standard methods, such as API calls - see Smullen [0240]) configured according to the second authentication layer (The web user interface 702 may also authenticate the user to an "external" user interface (e.g., Facebook, Google, or OpenID providers, etc.) by authenticating the user-supplied credentials with the external, third-party site - see [0090] of Zalila-Wenktern), wherein the data of the external computing system is restricted by the second authentication layer (Zalila-Wenktern teaches that credentials are required, thus restricting the data - see [0090]). Smullen further teaches causing the application to present the reply including the data from the data provider computing system, in a chatbot format responsive to the query - see [0135].
Regarding claim 8, Zalila-Wenktern teaches authenticating the user of the client device to the first authentication layer, the second layer, or a third authentication layer indicating that the user is not authenticated (This is an “or” statement, and Zalila-Wenktern teaches authenticating the user to the first and second authentication layers, as discussed above).
Regarding claims 9 and 10, the combination of Smullen and Zalila-Wenktern teaches determining that the query is associated with a service of the provider computing system and authenticating the user of the client device to the first authentication layer in response to the determination that the query is associated with a service of the provider computing system AND determining that the query is associated with a service of the external computing system and authenticating the user of the client device to the second authentication layer in response to the determination that the query is associated with a service of the external computing system (Smullen teaches: Content and functionality can range from simple static response (i.e., provider computing system) to integrated transactions with external systems - see [0135]. Smullen further teaches making an authenticated call to an external system in order to pull information for a specific user - see [0240]. Zalila-Wenktern teaches the concept of internal vs. external authentication layers for service providers, as discussed above - see [0090]. Therefore, the combination of Smullen and Zalila-Wenktern teach the elements of claims 9 and 10.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LISA C LEWIS whose telephone number is (571)270-7724. The examiner can normally be reached Monday - Thursday 7am-2pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/LISA C LEWIS/Primary Examiner, Art Unit 2495