DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending, with claims 1, 8, and 15 being independent claims.
Information Disclosure Statement
The information disclosure statement filed 5/13/2025 fails to comply with 37 CFR 1.98(a)(2), which requires a legible copy of each cited foreign patent document; each non-patent literature publication or that portion which caused it to be listed; and all other information or that portion which caused it to be listed. Only those documents which have not been lined through have been considered.
Priority
Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. However, Examiner notes that independent claims 1 and 8 contain subject matter which would be considered new matter if added as amendments to the parent application, and thus they (and by extension, any claims dependent on these claims) do not receive the benefit of the parent’s filing date.
Specification
The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification.
Drawings
The drawings are objected to as failing to comply with 37 CFR 1.84(p)(4) because:
Regarding Figure 1:
The elements shown in the drawings should be provided with descriptive text labels. Suitable descriptive legends are necessary for understanding the drawing(s), 37 CFR 1.84(o).
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL. — The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
Claim(s) 1-14 is/are rejected under 35 U.S.C. 112(a) as failing to comply with the written description requirement. The claim(s) contain(s) subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, at the time the application was filed, had possession of the claimed invention.
Regarding claim(s) 1 and 8:
Claim 1 recites, “… determining that a similarity between the encrypted parameter and an expected response from the communication device satisfies a threshold …”. Claim(s) 8 recite(s) similar language. The specification fails to adequately describe this limitation. The specification teaches the use of a threshold only in the context of the passage of time and revoking an existing bind with the “communication device.” The specification is silent regarding a threshold used in determining similarity between expected and received parameters, and therefore fails to provide sufficient written description of steps or an algorithm by which a threshold is calculated or used in determining similarity. This rejection can be overcome by amending the claim(s) such that they recite only that subject matter which has adequate description in the original disclosure. For the purpose of examination vis a vie mapping to prior art and in the interest of compact prosecution, this limitation will be interpreted according to what is supported by the specification (a straightforward comparison between the received and expected values).
Regarding claim(s) 5 and 12:
Claim 5 recites, “… the new verification fingerprint is used to maintain a previously established communication session with the communication device.” Claim(s) 12 recite(s) similar language. The specification fails to adequately describe this limitation. While the specification at ¶ 0068 repeats the language in the claims, it does not provide description on how this “new fingerprint” is used to maintain the communication session. No further steps of authenticating or otherwise re-verifying the communication device are described, which involve this new fingerprint, that could be said to provide an algorithm for the functional claim of maintaining a previously established connection.
Regarding claims 2-4, 6, 7, 9-11, 13, and 14:
They are dependent on one or more rejected claims, and thus inherit those rejections. These rejections could be overcome by overcoming the rejection(s) to any claims upon which these claims depend, or by amending the claims such that they are no longer dependent on any rejected claim.
These rejections can be overcome by amending the claim(s) such that they recite only that subject matter which is has adequate description in the original disclosure.
It is important to note that in regards to an adequate written description, “It is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015)” (MPEP 2161.01).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3, 8, 10, 15-17, 19, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over ADLER et al (Doc ID US 20170359717 A1), and further in view of OKANO et al (Doc ID US 20240205206 A1).
Regarding claim 1:
ADLER teaches:
transmitting, via the communications network to the communication device, a message including the verification parameter and instructions for encrypting the verification parameter ([0096] "… The process 700 then sends (at 710) a hint and a nonce to the accessory device. The accessory device uses the hint to identify a shared link key stored at the accessory device.");
receiving, via the communications network from the communication device, a response message that includes an encrypted parameter ([0097] "At 715, the process 700 receives ... an encrypted portion. The encrypted portion is encrypted with a key that is derived from the shared link key. The encrypted portion ... includes an accessory entropy, the nonce that was sent (at 710) to the accessory ..."); and
responsive to determining that a similarity between the encrypted parameter and an expected response from the communication device satisfies a threshold, authenticating the communication device ([0100] "The process 700 then … verifies the decrypted information. In some embodiments, the process 700 verifies that the received message includes the nonce that was sent to the accessory …").
OKANO teaches the following limitation(s) not taught by ADLER:
A method, comprising: receiving, via a communications network, an authentication request from a communication device ([0052] The federation unit 101 of the terminal 10 transmits an authentication request to the server 20 (step S101).);
responsive to receiving the authentication request, generating a verification parameter ([0053] Upon receiving the authentication request, the federation unit 201 of the server 20 generates a nonce nonce used in the OIDC (step S102).);
Sending a parameter (nonce) to an authenticating device, instructing the device to use a particular key to encrypt the nonce, and receiving and validating the encrypted nonce from the device is/are known technique(s) in the art, as demonstrated by ADLER. Further, receiving an authentication request and generating a “parameter” (nonce) to use in the authentication is/are known technique(s) in the art, as demonstrated by OKANO. It would have been obvious to a person having ordinary skill in the art (PHOSITA) before the effective filing date of the claimed invention to modify the device authentication of ADLER with the authentication pre-processing of OKANO with the motivation to include known steps in device authentication. Receiving an authentication request and generating a nonce are implied but not explicitly taught by ADLER; thus, the combination represents combining prior art elements according to known methods to yield predictable results.
Regarding claim 3:
The combination of ADLER and OKANO teaches:
The method of claim 1, wherein the verification parameter includes at least one of a randomly-generated token, a pseudo-randomly-generated token, or a set of alphanumeric characters (ADLER [0070] "… The nonces … are random (or pseudo-random) numbers that is sent back and forth between the device 110 and the accessory 120 …").
Regarding claim 8:
ADLER teaches:
An apparatus, comprising: a processor coupled to at least one memory device adapted to ([0110] "… above-described features and applications are implemented as ... instructions recorded on a computer readable storage medium .... When these instructions are executed by ... processors ... they cause the processing unit(s) to perform the actions indicated in the instructions."):
The remainder of this claim’s limitations are rejected with the same prior art mapping and justification, mutatis mutandis, as its counterpart claim 1.
Regarding claim(s) 10:
The listed claim(s) is/are rejected with the same justification, mutatis mutandis, as its/their counterpart claim(s) 3 above.
Regarding claim 15:
ADLER teaches:
receiving, via the communications network from the identity verifier, a message including a verification parameter and instructions for encrypting the verification parameter ([0096] "… The process 700 then sends (at 710) a hint and a nonce to the accessory device.");
retrieving, from memory, one or more component tokens indicated by the instructions for encrypting the verification parameter ([0096] "… The accessory device uses the hint to identify a shared link key stored at the accessory device.);
encrypting the verification parameter using the one or more component tokens ([0097] "At 715, the process 700 receives ... an encrypted portion. The encrypted portion is encrypted with a key that is derived from the shared link key. The encrypted portion ... includes an accessory entropy, the nonce that was sent (at 710) to the accessory ..."); and
transmitting, via the communications network to the identity verifier, the encrypted verification parameter ([0097] "At 715, the process 700 receives ... an encrypted portion. The encrypted portion is encrypted with a key that is derived from the shared link key. The encrypted portion ... includes an accessory entropy, the nonce that was sent (at 710) to the accessory ...").
OKANO teaches the following limitation(s) not taught by ADLER:
A method, comprising: transmitting, via a communications network, an authentication request to an identity verifier ([0052] The federation unit 101 of the terminal 10 transmits an authentication request to the server 20 (step S101).);
Receiving a parameter (nonce) and instructions at an authenticating device to use a particular key to encrypt the nonce, and sending the encrypted nonce to a verifying device is/are known technique(s) in the art, as demonstrated by ADLER. Further, sending an authentication request to a verifying device is/are known technique(s) in the art, as demonstrated by OKANO. It would have been obvious to a person having ordinary skill in the art (PHOSITA) before the effective filing date of the claimed invention to modify the device authentication of ADLER with the authentication pre-processing of OKANO with the motivation to include known steps in device authentication. Sending an authentication request is implied but not explicitly taught by ADLER; thus, the combination represents combining prior art elements according to known methods to yield predictable results.
Regarding claim 16:
The combination of ADLER and OKANO teaches:
The method of claim 15, wherein the verification parameter includes at least one of a randomly-generated token, a pseudo-randomly-generated token, or a set of alphanumeric characters (ADLER [0070] "… The nonces … are random (or pseudo-random) numbers that is sent back and forth between the device 110 and the accessory 120 …").
Regarding claim 17:
The combination of ADLER and OKANO teaches:
The method of claim 15, wherein the instructions for encrypting the verification parameter indicate a particular order in which the one or more component tokens are to be used to encrypt the verification token (ADLER [0097] "At 715, the process 700 receives ... an encrypted portion. The encrypted portion is encrypted with a key that is derived from the shared link key. The encrypted portion ... includes an accessory entropy, the nonce that was sent (at 710) to the accessory ...").
Examiner notes that given the claim language of "one or more component tokens" (shared link key), the "hint" of the prior art directing the use of one key (component token) reads on an "order" in which to apply the single token.
Regarding claim 19:
The combination of ADLER and OKANO teaches:
The method of claim 15, further comprising: receiving, via the communications network from the identity verifier, a second message including a second verification parameter and second instructions for encrypting the second verification parameter (ADLER [0096] "… The process 700 then sends (at 710) a hint and a nonce to the accessory device."); and
Examiner notes that no additional function is recited in this claim other than performing the already claimed process of receiving and encrypting a parameter. There is no teaching in the prior art which indicates it cannot be performed as many times as needed.
encrypting the second verification parameter in accordance with the second instructions (ADLER [0097] "At 715, the process 700 receives ... an encrypted portion. The encrypted portion is encrypted with a key that is derived from the shared link key. The encrypted portion ... includes an accessory entropy, the nonce that was sent (at 710) to the accessory ...").
Regarding claim 20:
The combination of ADLER and OKANO teaches:
The method of claim 19, wherein the second instructions indicate one or more second component tokens that can be used to encrypt the second verification parameter ([0096] "… The process 700 then sends (at 710) a hint and a nonce to the accessory device.").
See examiner's above note regarding iterating an already claimed process regarding claim 19.
Claims 2, 5, 9, and 12 are rejected under 35 U.S.C. 103 as being unpatentable over ADLER et al (Doc ID US 20170359717 A1) and OKANO et al (Doc ID US 20240205206 A1) as applied to claims 1 and 8 above, and further in view of MILLER et al (Doc ID US 7383440 B1).
Regarding claim 2:
The combination of ADLER and OKANO teaches:
The method of claim 1,
MILLER teaches the following limitation(s) not taught by the above combination:
further comprising generating a verification fingerprint, wherein the verification fingerprint is included in the message ((18) Col 7 lines 15-21 "In step S306, remote process 52 ... appends the current nonce to the response, double-encrypts the response ..., and sends a command response message to user host device 1 which includes the process identifier and the double-encrypted response.").
Including information in addition to a nonce sent as part of an authentication process is/are known technique(s) in the art, as demonstrated by MILLER. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device authentication of ADLER and OKANO with the additional authentication information of MILLER with the motivation to provide data unique to a device to an authentication protocol. Since similar methods are used to improve similar protocols, the combination yields predictable results.
Regarding claim 5:
The combination of ADLER and OKANO teaches:
The method of claim 1,
MILLER teaches the following limitation(s) not taught by the above combination:
further comprising: responsive to authenticating the communication device, generating a new verification fingerprint ((18) Col 7 lines 15-19 "In step S306, remote process 52 ... appends the current nonce to the response, double-encrypts the response …"); and
transmitting, via the communications network, the new verification fingerprint to the communication device ((18) Col 7 lines 19-21 "… sends a command response message to user host device 1 which includes the process identifier and the double-encrypted response."),
wherein the new verification fingerprint is used to maintain a previously established communication session with the communication device ((19) "... In the case that user host device 1 does not have a locally-stored most previous session nonce corresponding to remote process 52, or … (the session is being re-established) …").
Including information in addition to a nonce sent as part of an authentication process, and using that additional information to re-establish a communication session is/are known technique(s) in the art, as demonstrated by MILLER. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device authentication of ADLER and OKANO with the additional authentication information of MILLER with the motivation to provide data unique to a device to an authentication protocol to determine whether a communication session is re-established. Since similar methods are used to improve similar protocols, the combination yields predictable results.
Regarding claim(s) 9 and 12:
The listed claim(s) is/are rejected with the same justification, mutatis mutandis, as its/their counterpart claim(s) 2 and 5 above.
Claims 4, 11, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over ADLER et al (Doc ID US 20170359717 A1) and OKANO et al (Doc ID US 20240205206 A1) as applied to claims 1, 8, and 15 above, and further in view of HILTGEN (Doc ID US 20190138707 A1).
Regarding claim 4:
The combination of ADLER and OKANO teaches:
The method of claim 1,
HILTGEN teaches the following limitation(s) not taught by the above combination:
wherein the instructions for encrypting the verification parameter indicate one or more component tokens to be used by the communication device for encrypting the verification parameter ([0041] "In an operation 404, a determination of which challenge type (of multiple challenge types) the first challenge corresponds may be effectuated." and [0042] "In an operation 406, ... use a key associated with a first challenge type to generate a first challenge response (for the first challenge) based on the first challenge corresponding to the first challenge type.").
Indicating and using a selection of multiple possible keys (tokens) to authenticate a device is/are known technique(s) in the art, as demonstrated by HILTGEN. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device authentication of ADLER and OKANO with the key selection of HILTGEN with the motivation to add unpredictability to the key being used so that a single compromised key does not necessarily grant an attacker access. Since similar methods are used to improve similar protocols, the combination yields predictable results.
Regarding claim(s) 11:
The listed claim(s) is/are rejected with the same justification, mutatis mutandis, as its/their counterpart claim(s) 4 above.
Regarding claim 18:
The combination of ADLER and OKANO teaches:
The method of claim 15,
HILTGEN teaches the following limitation(s) not taught by the above combination:
further comprising obtaining, via the communications network from the identity verifier, one or more messages indicative of a comparison between the encrypted verification parameter and an expected result ([0030] "... a user interface may enable the user to … obtain notifications of authentication or failure to authenticate with his/her token(s) 106 …").
Notifying an authenticating device of the results of the verification process is/are known technique(s) in the art, as demonstrated by HILTGEN. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device authentication of ADLER and OKANO with the verification notification of HILTGEN with the motivation to ensure that the authenticating device is made aware of the successful authentication. This is an obvious combination of prior art elements according to known methods to yield predictable results.
Claims 6 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over ADLER et al (Doc ID US 20170359717 A1), OKANO et al (Doc ID US 20240205206 A1), and MILLER et al (Doc ID US 7383440 B1) as applied to claims 5 and 12 above, and further in view of TERVO et al (Doc ID US 20160005042 A1).
Regarding claim 6:
The combination of ADLER, OKANO, and MILLER teaches:
The method of claim 5,
TERVO teaches the following limitation(s) not taught by the above combination:
generating a fresh component token and one or more new component tokens that can be used to encrypt the fresh component token ([0047] "… Moreover, the key collections at the mobile application may be updated with another key collection, when the possible key combinations have been exhausted, when the keys have been compromised, and/or any other time new key collections are desired."); and
transmitting, via the communications network, the fresh component token and the one or more new component tokens to the communication device ([0047] "… Specifically, a mobile application … may receive a key collection including a plurality of key parts from a server, such as gateway 125 and/or token provider 130.").
Refreshing the keys which are selectable for an authentication protocol and providing the updated keys to an authenticating device is/are known technique(s) in the art, as demonstrated by TERVO. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device authentication of ADLER, OKANO, and MILLER with the key selection refresh of TERVO with the motivation to ensure that the keys used in the protocol do not become stale. Since similar methods are used to improve similar protocols, the combination yields predictable results.
Regarding claim(s) 13:
The listed claim(s) is/are rejected with the same justification, mutatis mutandis, as its/their counterpart claim(s) 6 above.
Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over ADLER et al (Doc ID US 20170359717 A1) and OKANO et al (Doc ID US 20240205206 A1) as applied to claims 1 and 8 above, and further in view of GOERINGER et al (Doc ID US 20190166495 A1).
Regarding claim 7:
The combination of ADLER and OKANO teaches:
The method of claim 1,
GOERINGER teaches the following limitation(s) not taught by the above combination:
wherein authenticating the communication device includes creating a bind between the communication device and an identity verifier ([0014] "FIG. 2 illustrates the device 12 having attestations .... A binding may include the trusted authority 18 associating data or information with the device 12 in a manner intended to thwart other devices from masquerading or stealing identity from the device 12.").
Creating a bind between an authenticated device and a verifying device is/are known technique(s) in the art, as demonstrated by GOERINGER. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device authentication of ADLER and OKANO with the device binding of GOERINGER with the motivation to prevent any other device from authenticating as the already-authenticated device. This is an obvious combination of prior art elements according to known methods to yield predictable results.
Regarding claim(s) 14:
The listed claim(s) is/are rejected with the same justification, mutatis mutandis, as its/their counterpart claim(s) 7 above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON BINCZAK whose telephone number is (703) 756-4528. The examiner can normally be reached M-F 0800-1600 EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BB/Examiner, Art Unit 2437
/ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437