Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1 – 20 posted on 05/07/2025 are presently pending in the application and have been examined below, of which claims 1, 9 and 14 are presented in independent form.
Priority
This application is a continuation of application 17/461303, now patent No. 12301555, which is a continuation of application 16025885, now patent 11108764 which claimed priority date by 07/02/2018. Accordingly, the effective priority date for the subject matter defined in the pending claims of the instant application is 02/07/2018.
Drawings
The drawings were received on 05/07/2025. These drawings are accepted.
Information Disclosure Statement
The information disclosure statements (IDS) dated 05/07/2025 and 06/06/2025 have been received and considered.
Examiner Notes
Examiner cites paragraphs, columns and line numbers in the references as applied to the claims below for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the applicant fully consider the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by prior art or disclosed by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1 – 20 rejected under 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter “context value” which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. For examination purposes limitation “context value” is considered as a value or a parameter.
Double Patenting
The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the "right to exclude" granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on non-statutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). [AltContent: rect]
The filing of a terminal disclaimer by itself is not a complete reply to a non-statutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. [AltContent: rect]
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/ patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/ patents/apply/applying-online/eterminal-disclaimer.
Claims 1 – 20 rejected on the ground of double patenting as being unpatentable over claims 1 - 20 of U.S. Patent No. 12301555 (Reference Patent) and in view additional prior art, see below. Although the claims at issue are not identical, they are not patentably distinct from each other because claims of the Reference Patent anticipate claims of the instant application as shown below for the first claim set where the limitations in claim 1 of instant application are anticipated by limitations in claim 1 of the reference patent.
Claim #
Instant Application
Reference Patent (12301555)
Claim #
1
1.A method, comprising:
receiving, by a server system, a login request, wherein the login request includes a first factor in a multi-factor authentication (MFA) procedure;
requesting, by the server system in response to the login request, a response from a mobile device to include a second factor in the MFA procedure;
receiving, by the server system, the requested response token from the mobile device, wherein the response token comprises: an MFA token automatically generated based on data provided by a machine learning module at the mobile device without receiving input from a user of the mobile device;
and one or more context values of the mobile device; and determining, by the server system, that the received MFA token is valid and that at least one of the one or more context values complies with a login policy;
and sending, by the server system, an approval response to the login request.
1.A method comprising:
receiving, by a server system, a login request, wherein the login request corresponds to a first factor in a multi-factor authentication (MFA) procedure;
requesting, by the server system and in response to the login request, a response from a mobile device corresponding to a second factor in the MFA procedure;
receiving, by the server system, a response token from the mobile device, wherein the response token comprises: an MFA token automatically generated by a machine learning module at the mobile device based on MFA data received from the server system and without receiving input from a user of the mobile device to automate the MFA token;
and one or more context values of the mobile device; determining, by the server system, that the MFA token is valid and that at least one of the one or more context values complies with a login policy;
and sending, by the server system, an approval response to the login request.
.
1
The reference patent (12301555) discloses a method for automatic authentication using a multi-factor authentication scheme. The method is based on a machine-learning technique including server-mobile device communication for predefined set of parameters.
Compared to the reference patent, the claims in examined application are anticipated by the reference patent. Data communication procedures by the authentication in the instant application are somewhat different from those in the reference patent, however, the disclosed sets of operations in both applications are not patentably distinct from each other. The claims in the instant application are broader and rejected by the additional prior art.
Accordingly, claims 1 – 20 rejected on the ground of non-statutory double patenting rejection as being unpatentable over claims 1 - 20 of U.S. Patent No. 12301555 (Reference Patent) in view of the prior art as indicated in the office action below.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1 – 20 are rejected under 35 U.S.C. 103 as being unpatentable over Grajek et al. (US 20180069867) (hereafter Grajek), in view of Craib et al. (US 11164107) (hereafter Craib) and in view of Barhudarian et al (US 2020/0007535).
As per claim 1 Grajek discloses: A method, comprising: receiving, by a server system, a login request, wherein the login request includes a first factor in a multi-factor authentication (MFA) procedure (Grajek, in para. [0019, 0021] discloses a method to perform authentication including multi-factor authentication using machine learning technique);
requesting, by the server system in response to the login request, a response from a mobile device to include a second factor in the MFA procedure (Grajek, in para. [0004, 0021] discloses procedure to obtain access to the system resources including access/login request);
receiving, by the server system, the requested response token from the mobile device, wherein the response token comprises (Grajek, in para. [0008] discloses identification operations using identity tokens)
Grajek does not explicitly disclose response automation by authentication. However, Craib discloses:
an MFA token automatically generated based on data provided by a machine learning module at the mobile device without receiving input from a user of the mobile device (Craib, in col. 28, ll.58-63 clarifies automation as a process that occurs without any direct external input; this disclosure meets a definition of “automate” given by applicant in para. [0042] of SPECS); and one or more context values of the mobile device (Craib, in col. 4, ll.3-7 discloses tokenization, i.e., token generation, via the machine-learning technology);
It would have been obvious to one having ordinary skill in the art, before the effective filing date of the claimed invention, to combine the techniques of Grajek and Craib because they both disclose machine-learning based authentication. The motivation to combine would be to improve data processing by Grajek using method of Craib for operation automation to improve efficiency and security of the method.
Grajek as modified does not explicitly disclose operations in compliance with a login policy. However, Barhudarian discloses:
and determining, by the server system, that the received MFA token is valid and that at least one of the one or more context values complies with a login policy (Barhudarian, in Para. [0025] discloses configuration unit 140 determining session values compliance with the predefined session policy); and sending, by the server system, an approval response to the login request (Barhudarian, in Para. [0017] discloses session, i.e., login session, management system 100 providing output about the session status).
It would have been obvious to one having ordinary skill in art, before the effective filing date of the claimed invention, to combine the techniques of Grajek-Craib and Barhudarian because they all disclose machine-learning based authentication. The motivation to modify would be to combine method of Grajek-Craib by inclusion of login policy as implemented by Barhudarian to improve efficiency and security of the method.
As per claim 2 Grajek as modified discloses: The method of claim 1, wherein at least one of the context values is one of: type of device, proximity to another device, location of device, time of day, current weather, and signal strength (Grajek, in para. [0024] discloses processing of data/values indicating device type).
As per claim 3 Grajek as modified discloses: The method of claim 1, further comprising, prior to receiving the login request: training, by the server system a plurality of machine learning modules using different context values of a plurality of mobile devices (Grajek, in para. [0077] discloses machine learning model training using specified data/values); and transmitting, by the server system to the mobile device, a trained machine learning module that is unique to the mobile device based on the training of the trained module being based on a plurality of context values of the mobile device (Grajek, in para. [0077] discloses intercommunication of the devices by data processing within the network).
As per claim 4 Grajek as modified discloses: The method of claim 1, wherein the data provided by the machine learning module seeds the requested response from the mobile device (Grajek, in para. [0004] discloses monitoring network activity of communicating devices using machine learning model, i.e., monitoring initiated device responses).
As per claim 5 Grajek as modified discloses: The method of claim 1, wherein the data provided by the machine learning module comprises one or more parameters for the response by the mobile device (Grajek, in para. [0008] discloses managing communication of mobile devices in the network).
As per claim 6 Grajek as modified discloses: The method of claim 5, wherein the one or more parameters are context values of the mobile device (Grajek, in para. [0024] discloses processing of data/values indicating device type, i.e., context values).
As per claim 7 Grajek as modified discloses: The method of claim 1, wherein the one or more context values include a frequency of login parameter that indicates how often the user of the mobile device logs into a set of one or more accounts (Grajek, in para. [0024] discloses monitoring variety of parameters related to the user logon activity including login history, i.e., how often users logs in system).
As per claim 8 Grajek as modified discloses: The method of claim 1, wherein the one or more context values include a wearable device parameter that indicates whether a wearable device is being worn by the user of the mobile device and whether the wearable device is unlocked (Grajek, in para. [0062] discloses monitoring by the system the lock-in and lock-out user activity).
As per claims 9, 10, claims 9, 10 encompass same or similar scope as claims 1, 8. Therefore, claims 9, 10 are rejected based on the same reasons set forth above in rejecting claims 1, 8.
As per claim 11 Grajek as modified discloses: The non-transitory computer-readable medium of claim 9, wherein the MFA data includes one or more context values that indicate personally identifiable information (PII) that is stored on the mobile device and is not shared with other devices (Grajek, in para. [0023] discloses user identification based on variety of personal information and data, i.e., personal identifiable information, using mobile devices).
As per claim 12 – 17, claims 12 – 17 encompass same or similar scope as claims 4, 2, 1, 2, 4 and 5, respectively. Therefore, claims 12 – 17 are rejected based on the same reasons set forth above in rejecting claims 4, 2, 1, 2, 4 and 5, respectively.
As per claim 18 Grajek as modified discloses: The system of claim 14, wherein the machine learning module at the mobile device is unique to the mobile device based on training of the machine learning module including training on a plurality of previous context values of the mobile device (Grajek, in para. [0040] discloses creation of a machine learning model for each individual user).
As per claim 19, claim 19 encompasses same or similar scope as claim 8. Therefore, claim 19 is rejected based on the same reasons set forth above in rejecting claim 8.
As per claim 20 Grajek as modified discloses: The system of claim 14, wherein the machine learning module at the mobile device is unique to the mobile device based on training of the machine learning module including training on a plurality of previous context values of the mobile device (Grajek, in para. [0040] discloses creation of a machine learning model for each individual user; creation of the model includes all events associated with the user, i.e., all respective previous context values).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: McNamara US_11402971, Cristensen US_11094015, Enqvist US_20170034183, Gupta US_20160110528, Hess US_10057227, Polar-Seminario US_12457127.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VLADIMIR IVANOVICH GAVRILENKO whose telephone number is (313)446-6530. The examiner can normally be reached on Monday-Friday 7:30-4:30 EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VLADIMIR I GAVRILENKO/Examiner, Art Unit 2431