Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This office action is in response to the application filed on 07/13/2025. In which, claims 1-10 are pending and being considered, claims 1 and 10 are independent, claims 1-10 are rejected.
Specification
The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification.
Applicant is reminded of the proper language and format for an abstract of the disclosure.
The abstract should be in narrative form and generally limited to a single paragraph on a separate sheet within the range of 50 to 150 words in length. The abstract should describe the disclosure sufficiently to assist readers in deciding whether there is a need for consulting the full patent text for details.
The language should be clear and concise and should not repeat information given in the title. It should avoid using phrases which can be implied, such as, “The disclosure concerns,” “The disclosure defined by this invention,” “The disclosure describes,” etc. In addition, the form and legal phraseology often used in patent claims, such as “means” and “said,” should be avoided.
The abstract of the disclosure is objected to because “disclosure” is stated on line 1 of the Abstract. A corrected abstract of the disclosure is required and must be presented on a separate sheet, apart from any other text. See MPEP § 608.01(b).
Claim Objections
Claim 1, 4 and 6 are objected to because of the following informalities:
In regards to Claim 1 and 6, the applicant recites the limitation “behavioural” this is a typographical error and the claim should read “behavioral”. Appropriate correction is required.
In regards to Claim 1, the applicant recites the limitation “the monitored parameters” this is a typographical error as there is a lack of antecedent basis. The claim should read “monitored parameters” and remove the phrase “the”. Appropriate correction is required.
In regards to Claim 1, the applicant recites the limitation “the monitored events” this is a typographical error as there is a lack of antecedent basis. The claim should read “monitored events” and remove the phrase “the”. Appropriate correction is required.
In regards to Claim 4, the applicant recites the limitation “behaviour” this is a typographical error and the claim should read “behavior”. Appropriate correction is required.
In regards to Claim 6, the applicant recites the limitation “the authentication score” this is a typographical error as there is a lack of antecedent basis. Examiner suggest amending the claim by removing the phrase “the” or using the limitation previous recited in the claims “confidence score”. Appropriate correction is required.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 4, 7 and 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Thomas et al. (U.S Pub. No. 20230308460, hereinafter referred to as “Thomas”) further in view of Biagi et al. (U.S Pub. No. 20240330933, hereinafter referred to as “Biagi”)
In regards to Claim 1, Thomas teaches a system for event-driven authentication, the system comprising: (Par. (0031-0034); system for events and authentication)
at least one processor; and (Par. (0227); processor))
a memory operatively associated with the processor, the memory, including machine executable instructions that when executed by the processor cause the processor to: (Par. (0227); processor and memory))
monitor, in real time, events associated with authentication requests received from one or more external devices, (Par. (0230-0231); external devices (security agents and remote resource) receiving request for authentication associated with event vectors)), (Par. (0181 and 0186); monitoring in real time events (event minoring gather events from sensors and events associated with authentication request))
the events comprising one or more of real-time user interactions, device telemetry, and contextual security events; (Par. (0196); events comprising real-time user interaction (events associated with behavior of entities)), (Par. (0209-0210); events comprising contextual security events (events corresponding to security, risk, threats and remedial measures detected from deviations))
dynamically adjust authentication requirements based on the generated confidence score for the authentication request, thereby enabling the system to select reduced authentication requirements or increased authentication requirements. (Par. (0109); based on sufficient confidence score adjust authentication requirements (adjusting security settings within a security policy)), (Par. (0224); adjusting authentication requirements (adjusting policy) based on generated confidence score (based on risk score)), (Par. (0229); dynamically adjusting authentication factors corresponding to risk score with changes)), (Par. (0229); thereby enabling the system to select reduced authentication requirements or increased authentication requirements. (increasing authentication requirement by adjusting and adding changes to factors required based on risk score))
Thomas does not explicitly teach generate an adaptive authentication profile based on at least on behavioural deviations, external device parameters, and the monitored parameters; generate a confidence score for the authentication requests by dynamically scoring the authentication requests based on the adaptive authentication profile and taking into account the monitored events; and
Wherein Biagi teaches generate an adaptive authentication profile based on at least on behavioural deviations, external device parameters, and the monitored parameters; (Par. (0018 and 0023); generate an adaptive authentication profile based on at least on behavioural deviations (creating and updating accounts based on observed behaviors and detecting risk in certain behaviors)), (Par. (0039); generate an adaptive authentication profile based on external device parameters (account based on spikes in processing resources based on fraudulent activities, usage etc.)), (Par. (0040); adaptive authentication profile based on monitored parameters (a time in which behavior is detected associated with account)), (Examiner note: In the instant application the specification is silent on what external device parameters, and the monitored parameters represents therefore it will be broadly and reasonably interpreted that external device parameters, and the monitored parameters include parameters within a device such as detection of processing associated with device and time and detected parameters associated with account).
generate a confidence score for the authentication requests by dynamically scoring the authentication requests based on the adaptive authentication profile and taking into account the monitored events; and (Par. (0004); generate a confidence score for the authentication requests (generating risk metric for request)), (Par. (0019, 0039); authentication request (request for access and authentication)), (Par. (0029-0032); authentication requests based on the adaptive authentication profile (request corresponding to accounts)), (Par. (0027, 0037); and taking into account the monitored events (request corresponding to detected events))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas to incorporate the teaching of Biagi to utilize the above feature because of the analogous concept of event detection based on behavior and metrics, with the motivation of authentication of user accounts by assessing possible risk and determining based on profile and accounts factors to prevent fraudulent activity based on detected events associated with behavior and patterns. (Biagi Par. (0018-0021))
In regards to Claim 4, the combination of Thomas and Biagi teach the system of claim 1, Thomas further teaches the system according to claim 1, wherein to generate the confidence score, (Par. (0004); generate a confidence score for the authentication requests (generating risk metric for request))
the processor is configured to determine deviations from baseline behaviors, and (Par. (0227); processor)), (Par. (0196); determine (observing and minoring) deviations from baseline behaviors (monitoring deviations from baseline behaviors))
upon determining that the determined deviation is greater than a threshold value, (Par. (0210-0211); deviations from baseline exceed a threshold))
the processor is configured to trigger system lockdown or conditional access restrictions. (Par. (0210-0211); detected deviations above threshold and lockdown/ conditional access restrictions (removal of compute instances)), (Par. (0242); deviating from expected baseline of behavior and changing authentication requirements)), (Par. (0236); conditional access restrictions (prevent access based on above threshold and risk scores))
In regards to Claim 7, the combination of Thomas and Biagi teach the system of claim 1, Thomas further teaches the system according to claim 1, wherein the processor is configured to dynamically adjust authentication requirements based on one or more of proximity- based security policies, real-time anomaly detection, and cross-device verification. (Par. (0224); adjusting authentication requirements (adjusting policy) based on generated confidence score (based on risk score)), (Par. (0229); dynamically adjusting authentication factors corresponding to risk score with changes)), (Par. (0028-0029); adjusting authentication requirements (adjusting authentication factors) based on real-time anomaly detection (changes to risk score and risk assessment)), (Par. (0230-0231); real-time anomaly detection (changes to authentication factor based on changes to risk assessment that including determining a posing risk an events with threat management)) (Examiner Note: By using the phrase “one or more” followed by the phrase “and cross-device verification” Examiner broadly and reasonably interprets one or more to be only one of the following three limitations “proximity- based security policies, real-time anomaly detection, and cross-device verification” to be fully mapped by the applicant using the phrase “or”.))
In regards to Claim 10, Thomas teaches a method comprising :monitoring, in real time, events associated with authentication requests received from one or more external devices, (Par. (0230-0231); external devices (security agents and remote resource) receiving request for authentication associated with event vectors)), (Par. (0181 and 0186); monitoring in real time events (event minoring gather events from sensors and events associated with authentication request))
the events comprising one or more of real-time user interactions, device telemetry, and contextual security events; (Par. (0196); events comprising real-time user interaction (events associated with behavior of entities)), (Par. (0209-0210); events comprising contextual security events (events corresponding to security, risk, threats and remedial measures detected from deviations))
dynamically adjusting authentication requirements based on the generated confidence score for the authentication request, thereby enabling selection of reduced authentication requirements or increased authentication requirements. (Par. (0109); based on sufficient confidence score adjust authentication requirements (adjusting security settings within a security policy)), (Par. (0224); adjusting authentication requirements (adjusting policy) based on generated confidence score (based on risk score)), (Par. (0229); dynamically adjusting authentication factors corresponding to risk score with changes)), (Par. (0229); thereby enabling the system to select reduced authentication requirements or increased authentication requirements. (increasing authentication requirement by adjusting and adding changes to factors required based on risk score))
Thomas does not explicitly teach generating an adaptive authentication profile based on at least on behavioural deviations, external device parameters, and the monitored parameters; generating a confidence score for the authentication requests by dynamically scoring the authentication requests based on the adaptive authentication profile and taking into account the monitored events; and
Wherein Biagi teaches generating an adaptive authentication profile based on at least on behavioural deviations, external device parameters, and the monitored parameters; (Par. (0018 and 0023); generate an adaptive authentication profile based on at least on behavioural deviations (creating and updating accounts based on observed behaviors and detecting risk in certain behaviors)), (Par. (0039); generate an adaptive authentication profile based on external device parameters (account based on spikes in processing resources based on fraudulent activities, usage etc.)), (Par. (0040); adaptive authentication profile based on monitored parameters (a time in which behavior is detected associated with account)), (Examiner note: In the instant application the specification is silent on what external device parameters, and the monitored parameters represents therefore it will be broadly and reasonably interpreted that external device parameters, and the monitored parameters include parameters within a device such as detection of processing associated with device and time and detected parameters associated with account).
generating a confidence score for the authentication requests by dynamically scoring the authentication requests based on the adaptive authentication profile and taking into account the monitored events; and (Par. (0004); generate a confidence score for the authentication requests (generating risk metric for request)), (Par. (0019, 0039); authentication request (request for access and authentication)), (Par. (0029-0032); authentication requests based on the adaptive authentication profile (request corresponding to accounts)), (Par. (0027, 0037); and taking into account the monitored events (request corresponding to detected events))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas to incorporate the teaching of Biagi to utilize the above feature because of the analogous concept of event detection based on behavior and metrics, with the motivation of authentication of user accounts by assessing possible risk and determining based on profile and accounts factors to prevent fraudulent activity based on detected events associated with behavior and patterns. (Biagi Par. (0018-0021))
Claim(s) 2 is/are rejected under 35 U.S.C. 103 as being unpatentable over Thomas et al. (U.S Pub. No. 20230308460, hereinafter referred to as “Thomas”) and Biagi et al. (U.S Pub. No. 20240330933, hereinafter referred to as “Biagi”) further in view of Andrews et al. (U.S Pub. No. 20210135943, hereinafter referred to as “Andrews”)
In regards to Claim 2, the combination of Thomas and Biagi teach the system of claim 1, Thomas further teaches the system according to claim 1, wherein to dynamically adjust the authentication requirements, (Par. (0224); adjusting authentication requirements (adjusting policy) based on generated confidence score (based on risk score)), (Par. (0229); dynamically adjusting authentication factors corresponding to risk score with changes)), (Par. (0229); thereby enabling the system to select reduced authentication requirements or increased authentication requirements. (increasing authentication requirement by adjusting and adding changes to factors required based on risk score))
Thomas and Biagi do not explicitly teach the processor is configured to select reduced authentication requirements in low-risk scenarios based on the confidence score and real-time event monitoring.
Wherein Andrews teaches the processor is configured to select reduced authentication requirements in low-risk scenarios based on the confidence score and real-time event monitoring. (Par. (0009); processor)) (Par. (0129); selecting a reduced authentication requirement (select workspace definition that requires no additional authentication) in low-risk scenarios based on the confidence score (request with low risk and risk score generated)), (Par. (0061); authentication requirement (workspace definition that is attributes that satisfy a security target)), (Par. (0095); and real-time event monitoring (threat monitoring in time))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas and Biagi to incorporate the teaching of Andrews to utilize the above feature because of the analogous concept of authentication based on metric scores and determining confidence/risk of system based on detection, with the motivation of creating security of protected user data to extend defenses and regulate access and identify compromise based on metric scores. (Andrews Par. (0004-0005 and 0011-0012))
Claim(s) 3 is/are rejected under 35 U.S.C. 103 as being unpatentable over Thomas et al. (U.S Pub. No. 20230308460, hereinafter referred to as “Thomas”) and Biagi et al. (U.S Pub. No. 20240330933, hereinafter referred to as “Biagi”) further in view of Gujarathi et al. (U.S Pub. No. 20220385656, hereinafter referred to as “Gujarathi”)
In regards to Claim 3, the combination of Thomas and Biagi teach the system of claim 1, Thomas further teaches the system according to claim 1, wherein to dynamically adjust the authentication requirements, (Par. (0224); adjusting authentication requirements (adjusting policy) based on generated confidence score (based on risk score)), (Par. (0229); dynamically adjusting authentication factors corresponding to risk score with changes)), (Par. (0229); thereby enabling the system to select reduced authentication requirements or increased authentication requirements. (increasing authentication requirement by adjusting and adding changes to factors required based on risk score))
Thomas and Biagi do not explicitly teach the processor is configured to select increased authentication requirements in high-risk scenarios based on the confidence score and real-time event monitoring.
Wherein Gujarathi teaches the processor is configured to select increased authentication requirements in high-risk scenarios based on the confidence score and real-time event monitoring. (Par. (0032); processor)), (Par. (0113); when the confidence score (risk level) is determined to be high-risk (high risk level) select increased authentication requirements (selecting multi-factor authentication)), (Par. (0058, 0062); real-time event monitoring (processing raw event periodically))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas and Biagi to incorporate the teaching of Gujarathi to utilize the above feature because of the analogous concept of authentication based on metric scores and determining confidence/risk of system based on detection, with the motivation of identifying high and low risk scenarios to verify users identity and provide proper authentication to reduce number of attempts and based on time allow the system to identify valid users, prevent sharing of data to unauthorized users and create trust. (Gujarathi Par. (0006-0009))
Claim(s) 5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Thomas et al. (U.S Pub. No. 20230308460, hereinafter referred to as “Thomas”) and Biagi et al. (U.S Pub. No. 20240330933, hereinafter referred to as “Biagi”) further in view of Yu et al. (U.S Pub. No. 20190258818, hereinafter referred to as “Yu”)
In regards to Claim 5, the combination of Thomas and Biagi do not explicitly teach wherein the processor is configured to dynamically update the adaptive authentication profile based on historical session data and real-time session data.
Wherein Yu teaches wherein the processor is configured to dynamically update the adaptive authentication profile based on historical session data and real-time session data. (Par. (0005); processor)), Par. (0119); dynamically update the adaptive authentication profile (updating the user profile that was allowed access) based on historical session data and real-time session data (based on user history and preference data))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas and Biagi to incorporate the teaching of Yu to utilize the above feature because of the analogous concept of detected events based on behaviors and user authenticated profiles, with the motivation of authorizing access based of detected behavior to regulate data and provide actions based historical data of user and interactions. (Yu Par. (0005-0006))
Claim(s) 6 is/are rejected under 35 U.S.C. 103 as being unpatentable over Thomas et al. (U.S Pub. No. 20230308460, hereinafter referred to as “Thomas”) and Biagi et al. (U.S Pub. No. 20240330933, hereinafter referred to as “Biagi”) further in view of Martin et al. (U.S Pub. No. 20180004948, hereinafter referred to as “Martin”)
In regards to Claim 6, the combination of Thomas and Biagi teach the system of claim 1, Thomas further teaches the system according to claim 1, the processor is configured to continuously monitor the behavioural deviations over a period of time, and (Par. (0227); processor)), (Par. (0211, 0214); time of over ever two days, once per week etc. and detecting deviations of baseline of activity))
Thomas does not explicitly teach wherein to dynamically score the authentication requests, decay the authentication score over the period of time based on increased behavioural deviations.
Wherein Biagi teaches wherein to dynamically score the authentication requests, (Par. (0004); generate a confidence score for the authentication requests))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas to incorporate the teaching of Biagi to utilize the above feature because of the analogous concept of event detection based on behavior and metrics, with the motivation of scoring requests to create a level of trust within the system and detect possible fraud and reduce friction within devices. (Biagi Par. (0015))
Thomas and Biagi do not explicitly teach decay the authentication score over the period of time based on increased behavioural deviations.
Wherein Martin teaches decay the authentication score over the period of time based on increased behavioural deviations. (Par. (0080); decay the authentication score (lower the outlier scores) over a period of time (preset duration) based on increased behavioral deviations (exceeding deviation threshold specifying behavior and re-ranking and lowering outlier scores))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas and Biagi to incorporate the teaching of Martin to utilize the above feature because of the analogous concept of detected events based on behavior and metric scoring for authentication, with the motivation of preventing malicious attempts, viruses and harm and cyber attacks by detecting patterns and weighing risk to alert users in the system of anomalous behavior . (Martin Par. (0026-0027, 0039, 0043 and 0079-0080))
Claim(s) 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Thomas et al. (U.S Pub. No. 20230308460, hereinafter referred to as “Thomas”) and Biagi et al. (U.S Pub. No. 20240330933, hereinafter referred to as “Biagi”) further in view of Sanders et al. (U.S Pub. No. 20250343839, hereinafter referred to as “Sanders”)
In regards to Claim 8, the combination of Thomas and Biagi do not explicitly teach wherein the adaptive authentication profile is associated with authentication signatures determined based on a sequence of user actions, system events, device interactions, and environmental conditions.
Wherein Sanders teaches wherein the adaptive authentication profile is associated with authentication signatures determined based on a sequence of user actions, system events, device interactions, and environmental conditions. (Par. (0005-0006); adaptive authentication profile (authenticated user with signature profile) with authentication signatures (profile of authenticated user with signatures)), (Par. (0044,0062); based on a sequence of user actions (list of action corresponding to signature and actions with signature and account of user)), (Par. (0005-0006); based on system events (signature corresponding to detected events and authenticated events with profile)), (Par. (0047); based on device interaction (signature corresponding to device collecting and transmitting signature to another apparatus over time)), (Par. (0007); signature based on environmental factors))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas and Biagi to incorporate the teaching of Sanders to utilize the above feature because of the analogous concept of detected events and authentication techniques, with the motivation of utilizing signatures based on environmental factors, to create authentication and ensure authenticity of an individual over time by using captured events as a form of comparison. (Sanders Par. (0002-0005))
Claim(s) 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Thomas et al. (U.S Pub. No. 20230308460, hereinafter referred to as “Thomas”),Biagi et al. (U.S Pub. No. 20240330933, hereinafter referred to as “Biagi”) and Sanders et al. (U.S Pub. No. 20250343839, hereinafter referred to as “Sanders”) further in view of Santarelli et al. (U.S Pub. No. 20210393168, hereinafter referred to as “Santarelli”)
In regards to Claim 9, the combination of Thomas, Biagi and Sanders do not explicitly teach wherein the processor is configured to update the authentication signatures based on one or more of federated learning and edge-based Artificial Intelligence (AI)models.
Wherein Santarelli teaches wherein the processor is configured to update the authentication signatures based on one or more of federated learning and edge-based Artificial Intelligence (AI)models. (Par. (0014, 0065); update the authentication signature (updating the reference user signature)), (Par. (0047-0048, 0050, 0053); update the authentication signatures (authentication of signature corresponding to AI models (machine learning models)), (Par. Edge-based (edge nodes))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Thomas, Biagi and Sanders to incorporate the teaching of Sanders to utilize the above feature because of the analogous concept of detected events and authentication techniques using machine learning, with the motivation of utilizing signatures based on environmental factors, to authenticate users more effectively to confirm identities, support users based on security requirements and utilizing machine learning to enhance the automated authentication process to classify and train data. (Sanders Par. (0006, 0053-0054 0095))
Relevant Prior Art
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Piel; Brian (U.S Pub. No. 20220191198) “SYSTEM ARCHITECTURE AND DATABASE FOR CONTEXT-BASED AUTHENTICATION”. Considered this reference because it addressed metrics and security level of detected events based on authentication requests.
Halim; Irwan (U.S Pub. No. 20210165861) “AUTHENTICATION PROFILES FOR USERS”. Considered this application because it relates to authenticating a user based on a profile and received contextual data.
Norgate; Richard (U.S Pub. No. 20240037224) “ANOMALY DETECTION”. Considered this application because it addressed behavior and anomaly detection of sensed and detected events to authenticate the system based on factors.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HASSAN A HUSSEIN whose telephone number is (571)272-3554. The examiner can normally be reached on 7:30am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HASSAN A HUSSEIN/ Examiner, Art Unit 2497