Prosecution Insights
Last updated: October 02, 2026
Application No. 19/211,614

AUTHENTICATION SERVER, AUTHENTICATION SYSTEM, CONTROL METHOD OF AUTHENTICATION SERVER, AND STORAGE MEDIUM

Non-Final OA §103§DOUBLEPATENT
Filed
May 19, 2025
Priority
Apr 10, 2020 — nonprovisional of PCTJP2020016177 +1 more
Examiner
CHIANG, JASON
Art Unit
Tech Center
Assignee
NEC Corporation
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
464 granted / 558 resolved
+23.2% vs TC avg
Strong +28% interview lift
Without
With
+28.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
14 currently pending
Career history
569
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
60.8%
+20.8% vs TC avg
§102
10.0%
-30.0% vs TC avg
§112
7.1%
-32.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 558 resolved cases

Office Action

§103 §DOUBLEPATENT
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This action is in response to the communication filed on 05/19/2025. Claims 1-13 are under examination. The Information Disclosure Statements filed on 05/19/2025 has been entered and considered. Priority Acknowledgment is made of applicant's claim for foreign priority under 35 U.S.C. 119(a)-(d). Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/forms/. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1-13 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 10-13 of U.S. Patent No. 12,363,107 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the subject matter claimed in the instant application is fully disclosed in the patent and is covered by the patent since the patent and the application are claiming common subject matter, as follows: An authentication server comprising: at least one memory storing a set of instructions; and at least one processor configured to execute the set of instructions to: acquire a first ID that uniquely determines a user in a system and first biological information that is used for authentication of the user; and process a service registration request that includes the first ID and a second ID that identifies a service that the user wishes to use, wherein the at least one processor is further configured to execute the set of instructions to: generate a third ID that is uniquely determined by a combination of the user and the service; and store the first biological information, the first ID, the second ID, and the third ID in association with each other, and wherein storing the first biological information, the first ID, the second ID, and the third ID in association with each other comprises storing the biological information, the first ID, the second ID, and the third ID in a same table. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Ko (US 2017/0055146 A1), Esaki et al. (US 2013/0219461 A1) and Grassadonia et al. (US 2016/0125370 A1). Regarding claim 1, Ko discloses An authentication server [par. 0042, authentication server 400] comprising: at least one memory storing a set of instructions; and at least one processor configured to execute the set of instructions to: acquire a first ID that uniquely determines a user in a system and first biological information that is used for authentication of the user [par. 0070, “the authentication server's database(s) 401, 403 stores a set of vectors representing each user's ID and cryptographically hashed values of the user's biometric data… the user must pre-register his biometric feature vector set at the authentication server 400 as the first feature vector set”]; and store the first biological information, the first ID in association with each other [par. 0070, “the authentication server's database(s) stores a set of vectors representing each user's ID and cryptographically hashed values of the user's biometric data. The user ID is used to uniquely identify each user and the user's cryptographically hashed biometric data”]. Ko does not explicitly disclose process a service registration request that includes the first ID and a second ID that identifies the service that the user wishes to use, wherein the at least one processor is further configured to: generate a third ID that is uniquely determined by a combination of the user and the service; and store the first biological information, the first ID, the second ID, and the third ID in association with each other. However Esaki et al. teaches process a service registration request that includes the first ID and a second ID that identifies the service that the user wishes to use [par. 0098, “when an operation completion of an SP user repository 302 including the service provider ID of the service provider device and the user ID included in the user attribute partial information is notified from the service provider device 300 of the transmission source of the account collaboration request message”], wherein the at least one processor is further configured to: generate a third ID that is uniquely determined by a combination of the user and the service [par. 0098, “registering the authentication collaboration ID to the user attribute information 201a included in the IDP user repository 201 based on the service provider ID and the user ID”, par. 0184, the IDP account provisioning unit 211 issues the authentication collaboration ID shared between the service provider device 300 to which the SP account collaboration request message is transmitted]; and store the first biological information, the first ID, the second ID, and the third ID in association with each other [par. 0190, the IDP account provisioning unit 211 registers the authentication collaboration ID issued in step S45 to a USER_A record of the IDP user repository 201a, par. par. 0063]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Esaki et al. into the teaching of Ko with the motivation to providing an authentication collaboration system, an ID provider device, and a program, which are low in the user's burden and capable of deciding whether or not a service can be used without involving a manual operation when account registration and collaboration are executed in the process of the SSO as taught by Esaki et al. [Esaki et al.: par. 0031]. They do not explicitly disclose wherein storing the first biological information, the first ID, the second ID, and the third ID in association with each other comprises storing the biological information, the first ID, the second ID, and the third ID in a same table. However, Grassadonia et al. teaches wherein storing the first biological information, the first ID, the second ID, and the third ID in association with each other comprises storing the biological information, the first ID, the second ID, and the third ID in a same table [par. 0027, “the payment service system can identify the recipient financial account for the money transfer by mapping the payment proxy included in the message (e.g., “$funnyguy311”) to the recipient financial account, based on association data stored in the payment service system's database that maintains information of users of the payment service”, par. 0106, “the PSS 110 searches one or more database tables of the DB 116 corresponding to, e.g., funnyguy311 or $funnyguy311. An example of the database tables are shown in FIG. 9 (e.g., database tables 902, 904, and 906). Within the database tables of the DB 116, the recipient user account can be represented by an identifier associated with the recipient. The identifier can include, for example, an email address, a telephone number, an application ID, a device ID, or biometric data (e.g., fingerprint, iris, voice, facial features, etc.)” (the first ID – email address, the second ID – an application ID, the third ID – account ID $funnyguy311)]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Grassadonia et al. into the teaching of Ko and Esaki et al. with the motivation to utilize the data stored in the databases to process payment transactions (e.g., money transfers) on behalf of customer users of the payment service as taught by Grassadonia et al. [Grassadonia et al.: par. 0155]. Regarding claim 2, the rejection of claim 1 is incorporated. Esaki et al. further teaches the at least one processor is further configured to execute the set of instructions to: receive an authentication request including second biological information of the user [par. 0061, the password referred to when the user performs the log-in process may be biometric authentication information such as the user's fingerprint] and the second ID from the service provider; determine the third ID by using the first and second biological information and the second ID; and transmit the determined third ID to the service provider [par. 0196, the IDP authentication collaborating unit 208 generates an assertion context including the authentication collaboration ID acquired in step S52 and the authentication scheme name of the log-in process performed in step S25, par. 0197, the IDP authentication collaborating unit 208 transmits the authentication collaboration response including the generated authentication assertion 208a and the user ID included in the received authentication collaboration execution request to the service provider device 300 of the transmission source of the authentication collaboration request ]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Esaki et al. into the teaching of Ko with the motivation to providing an authentication collaboration system, an ID provider device, and a program, which are low in the user's burden and capable of deciding whether or not a service can be used without involving a manual operation when account registration and collaboration are executed in the process of the SSO as taught by Esaki et al. [Esaki et al.: par. 0031]. Regarding claim 3, the rejection of claim 1 is incorporated. Ko further disclose acquire a password of the user; and store the first biological information, the first ID, the password [par. 0042, the authentication database(s) 401, 403 may include the user's personal information such as name, address, credit card information, biometric data, shopping preferences, password, user ID, and the like]. Esaki et al. further teaches store the second ID, and the third ID in association with each other[par. 0190, the IDP account provisioning unit 211 registers the authentication collaboration ID issued in step S45 to a USER_A record of the IDP user repository 201a, par. par. 0063]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Esaki et al. into the teaching of Ko with the motivation to providing an authentication collaboration system, an ID provider device, and a program, which are low in the user's burden and capable of deciding whether or not a service can be used without involving a manual operation when account registration and collaboration are executed in the process of the SSO as taught by Esaki et al. [Esaki et al.: par. 0031]. Regarding claim 11, it recites limitations like claim 1. The reason for the rejection of claim 1 is incorporated herein. Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Ko (US 2017/0055146 A1), Esaki et al. (US 2013/0219461 A1) and Grassadonia et al. (US 2016/0125370 A1) as applied to claims 1-3 and 11 above, and further in view of Henry et al. (US 6,996,718 B1). Regarding claim 4, the rejection of claim 3 is incorporated. Ko and Esaki et al. disclose generate a third ID. They do not explicitly disclose calculate a hash value by using the first ID, the password, and the second ID; and use the calculated hash value as the third ID. However Henry et al. teaches calculate a hash value by using the first ID, the password, and the second ID; and use the calculated hash value as the third ID [col. 3, line 60-col. 4, line 8, “to generate, process and validate the common password and associated designated passwords for each of a user's accounts, a password transform algorithm is utilized… Pd=Text(Hash(Ui+Pc+Si+Nr)) Where, Pd stands for a designated password, Ui for a user ID (such as a login ID selected by the user or provided by an account service provider), Pc for a common password (which is preferably selected by a user as discussed above), Si for a server name (such as the server name or URL of the user's account service provider), and Nr for a random number. The "Text( )" portion represents the text conversion and the "Hash( )" portion represents the hash function”]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Henry et al. into the teaching of Ko, Esaki et al. and Grassadonia et al. with the motivation to provide both convenience and security assurance for users who have multiple accounts protected by using a common password as taught by Henry et al. [Henry et al.: abs.]. Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over Ko (US 2017/0055146 A1), Esaki et al. (US 2013/0219461 A1) and Grassadonia et al. (US 2016/0125370 A1) as applied to claims 1-3 and 11 above, and further in view of HASEGAWA (US 2022/0058594 A1). Regarding claim 5, the rejection of claim 1 is incorporated. Ko and Esaki et al. disclose the first biological information. They do not explicitly disclose the first biological information includes a feature value generated from a face image of the user. However HASEGAWA teaches the first biological information includes a feature value generated from a face image of the user [par. 0075, “As the biometric information, a fingerprint, an iris, a face image, a voiceprint, a feature value of the fingerprint, the iris, the face image”]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of HASEGAWA into the teaching of Ko, Esaki et al. and Grassadonia et al. with the motivation to perform biometric authentication, based on biometric information and an authentication request being received from an external apparatus, and returns a result of the biometric authentication as taught by HASEGAWA [HASEGAWA: par. 0075]. Claims 6-8 and 10 are rejected under 35 U.S.C. 103 as being unpatentable over Ko (US 2017/0055146 A1), Esaki et al. (US 2013/0219461 A1), Grassadonia et al. (US 2016/0125370 A1) and Sakagami et al. (US 2010/0002250 A1). Regarding claim 6, it recites limitations like claim 1. The reason for the rejection of claim 1 is incorporated herein. Ko and Esaki et al. disclose the authentication system. They do not explicitly disclose a management server wherein the management server includes at least one memory storing a set of instructions; and at least one processor configured to execute the set of instructions to: acquire the first ID and personal information of the user from the user; acquire the third ID by transmitting the service registration request to the authentication server; and store personal information of the user and the third ID in association with each other. However Sakagami et al. teaches a management server wherein the management server includes at least one memory storing a set of instructions; and at least one processor configured to execute the set of instructions to: acquire the first ID and personal information of the user from the user; acquire the third ID by transmitting the service registration request to the authentication server; and store personal information of the user and the third ID in association with each other [par. 0080, “In the managing server 300, user information 310 and use limit information 313 for each individual user are stored in the auxiliary storage unit 34 in advance”, par. 0105, the managing server 300 acquires the use limit information 313 corresponding to the user ID 312, using the use limit information acquiring unit 320... The MFP 200 then controls its operation based on the use limit information 313 so that only one or more of the functions that are allowed to be used by the authenticated user are realized, par. 0203, the managing server 300A in step S3005 allows the user to login. In step S3006, the managing server 300A acquires from the AD server 500A a user ID corresponding to the authenticated IC card identifying information, and registers this user ID in the auxiliary storage unit 34, using the user information registering unit]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sakagami et al. into the teaching of Ko, Esaki et al. and Grassadonia et al. with the motivation for user authentication based on biometric information about a user and using managing server for managing user information as taught by Sakagami et al. [Sakagami et al.: abs., par. 0164]. Regarding claim 7, the rejection of claim 6 is incorporated. It recites limitations similar to claim 2. The reason for the rejection is incorporated herein. Esaki et al. further teaches the at least one processor is further configured to execute the set of instructions to: receive an authentication request including second biological information of the user [par. 0061, the password referred to when the user performs the log-in process may be biometric authentication information such as the user's fingerprint] and the second ID from the service provider; determine the third ID by using the first and second biological information and the second ID; and transmit the determined third ID to the service provider [par. 0196, the IDP authentication collaborating unit 208 generates an assertion context including the authentication collaboration ID acquired in step S52 and the authentication scheme name of the log-in process performed in step S25, par. 0197, the IDP authentication collaborating unit 208 transmits the authentication collaboration response including the generated authentication assertion 208a and the user ID included in the received authentication collaboration execution request to the service provider device 300 of the transmission source of the authentication collaboration request ]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Esaki et al. into the teaching of Ko with the motivation to providing an authentication collaboration system, an ID provider device, and a program, which are low in the user's burden and capable of deciding whether or not a service can be used without involving a manual operation when account registration and collaboration are executed in the process of the SSO as taught by Esaki et al. [Esaki et al.: par. 0031]. They do not explicitly disclose the management server is further configured to execute the set of instructions to determine personal information of the user by using the third ID acquired by transmitting the authentication request to the authentication server when a service is provided to the user. Sakagami et al. teaches the management server is further configured to execute the set of instructions to determine personal information of the user by using the third ID acquired by transmitting the authentication request to the authentication server when a service is provided to the user [par. 0105, the managing server 300 acquires the use limit information 313 corresponding to the user ID 312, using the use limit information acquiring unit 320... The MFP 200 then controls its operation based on the use limit information 313 so that only one or more of the functions that are allowed to be used by the authenticated user are realized, par. 0203, the managing server 300A in step S3005 allows the user to login. In step S3006, the managing server 300A acquires from the AD server 500A a user ID corresponding to the authenticated IC card identifying information, and registers this user ID in the auxiliary storage unit 34, using the user information registering unit]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sakagami et al. into the teaching of Ko, Esaki et al. and Grassadonia et al. with the motivation for user authentication based on biometric information about a user and using managing server for managing user information as taught by Sakagami et al. [Sakagami et al.: abs., par. 0164]. Regarding claim 8, the rejection of claim 7 is incorporated. Sakagami et al. further teaches an authentication terminal that acquires personal information of the user from the management server by transmitting biological information acquired from the user to the management server and that provides a service to the user by using the acquired personal information [par. 0230, The operating terminal 50 acquires biometric information using the functions of the biometric information reader 210a and the plugin 231. The biometric information is transmitted to the biometric authentication server 400 via the network 600, together with the user ID inputted…, par. 0231, From the operating terminal 50, the IC card identifying information is transmitted to the managing server 300A via the network 600. In the managing server 300A, a user ID corresponding to the IC card identifying information is obtained. The managing server 300A then supplies use limit information corresponding to the obtained user ID to the MFP 200a. Based on the use limit information, operation of the MFP 200a is controlled]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sakagami et al. into the teaching of Ko, Esaki et al. and Grassadonia et al. with the motivation for user authentication based on biometric information about a user and using managing server for managing user information as taught by Sakagami et al. [Sakagami et al.: abs., par. 0164]. Regarding claim 10, the rejection of claim 6 is incorporated. Sakagami et al. further teaches the personal information does not include biological information of the user [par. 0229, user information including IC card identifying information, a user ID, and a password]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sakagami et al. into the teaching of Ko, Esaki et al. and Grassadonia et al. with the motivation for user authentication based on biometric information about a user and using managing server for managing user information as taught by Sakagami et al. [Sakagami et al.: abs., par. 0164]. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Ko (US 2017/0055146 A1), Esaki et al. (US 2013/0219461 A1), Grassadonia et al. (US 2016/0125370 A1) and Sakagami et al. (US 2010/0002250 A1) as applied to claims 6-8 and 10 above, and further in view of HASEGAWA (US 2022/0058594 A1). Regarding claim 9, the rejection of claim 8 is incorporated. Ko and Esaki et al. disclose the first biological information. They do not explicitly disclose the authentication server stores a first feature value generated from a face image of the user as the first biological information, wherein the authentication terminal transmits the face image of the user to the management server, and wherein the management server uses a second feature value generated from the face image as the second biological information. However HASEGAWA teaches the authentication server stores a first feature value generated from a face image of the user as the first biological information [par. 0075, “The biometric authentication server 40 includes a storage unit, and stores second user registration information in which electronic receipt service-user identification information and biometric information about each user are associated with each other. As the biometric information, a fingerprint, an iris, a face image, a voiceprint, a feature value of the fingerprint, the iris, the face image”], wherein the authentication terminal transmits the face image of the user to the management server, and wherein the management server uses a second feature value generated from the face image as the second biological information [par. 0104, the electronic receipt issuing apparatus 10 includes an acquisition unit 14, an issuing unit 15, and a comparison unit 16, par. 0106, The comparison unit 16 performs biometric authentication that compares the biometric information acquired by the acquisition unit 14 and second user registration information. The second user registration information is information in which electronic receipt service-user identification information and biometric information about each user are associated with each other ]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of HASEGAWA into the teaching of Ko, Esaki et al., Grassadonia et al. and Sakagami et al. with the motivation to perform biometric authentication, based on biometric information and an authentication request being received from an external apparatus, and returns a result of the biometric authentication as taught by HASEGAWA [HASEGAWA: par. 0075]. Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Ko (US 2017/0055146 A1), Esaki et al. (US 2013/0219461 A1) and Grassadonia et al. (US 2016/0125370 A1) as applied to claims 1-3 and 11 above, and further in view of Vysogorets et al. (US 2012/0066757 A1). Regarding claim 12, the rejection of claim 3 is incorporated. Ko and Esaki et al. disclose generate a third ID. They do not explicitly disclose generating the third ID comprises combining the first ID and the second ID as the combination. However Vysogorets et al. teaches generating the third ID comprises combining the first ID and the second ID as the combination [par. 0084, “a data container identifier generated using a combination of a user ID and service provider ID”]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Vysogorets et al. into the teaching of Ko, Esaki et al. and Grassadonia et al. with the motivation of generating an access code based on a combination of data related to the authenticated user and data related to the authenticated service provider, and using the access code to access at least some of data storage locations as taught by Vysogorets et al. [Vysogorets et al.: abs.]. Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Ko (US 2017/0055146 A1), Esaki et al. (US 2013/0219461 A1) and Grassadonia et al. (US 2016/0125370 A1) as applied to claims 1-3 and 11 above, and further in view of Tamura (US 9,077,708 B2 B2). Regarding claim 13, the rejection of claim 3 is incorporated. Ko and Esaki et al. disclose generate a third ID. They do not explicitly disclose the at least one processor is further configured to execute the set of instructions to, based on the third ID, process implementation of a second service, other than the service, requested by the user. However Tamura teaches the at least one processor is further configured to execute the set of instructions to, based on the third ID, process implementation of a second service, other than the service, requested by the user [claim 1, “for each combination of a service user ID and an identity user ID in the SSO mapping setting information set as part of the single sign-on setting information, the service server provides a user, in the identity tenant and the service tenant and associated with a combination set by the setting unit as part of the single sign-on setting information, to receive access to the service of the service server, even users other than the user associated with the service user ID and the identity user ID who requested the collective users setting of single sign-on”, col. 3, lines 28-35, “when an SSO mapping setting request is accepted from the user, the service A 300 accesses the service B 400 using service B authentication information included in the SSO mapping setting request. If the authentication information is valid, the service B 400 transfers a second ID list 460, which can be acquired by the user authority identified by the authentication information, to the service A 300”]. Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Tamura into the teaching of Ko, Esaki et al. and Grassadonia et al. with the motivation such that it is possible in which the user accesses the service A, the user access is redirected to the service B via SSO as taught by Tamura [Tamura: col. 4, lines 38-45]. Conclusion The prior art made of record and not relied upon is considered pertinent to Applicant’s disclosure: US 20210367936 A1 AUTHENTICATION SYSTEM AND AUTHENTICATION METHOD USING PERSONAL ELECTRONIC IDENTITY GADGETS US 20190334889 A1 AUTHENTICATION CONTROL DEVICE AND AUTHENTICATION CONTROL METHOD US 20180145827 A1 METHOD FOR SECURELY TRANSMITTING A SECRET DATA TO A USER OF A TERMINAL US 20130170717 A1 AUTHENTICATION APPARATUS, AUTHENTICATION PROGRAM, AND METHOD OF AUTHENTICATION US 20130024919 A1 CLOUD SERVICE AUTHENTICATION US 20070130343 A1 Means And Method For Generating A Unique User's Identity For Use Between Different Domains US 7202773 B1 Authentication Information Communication System And Method, Portable Information Processing Device And Program Furnishing Medium Any inquiry concerning this communication or earlier communications from the examiner should be directed to JASON CHIANG whose telephone number is (571)270-3393. The examiner can normally be reached on 9 AM to 6 PM. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JASON CHIANG/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

May 19, 2025
Application Filed
Sep 16, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12719867
METHOD AND APPARATUS FOR SELECTING AN AUTHENTICATION TYPE FOR AUTHENTICATION RELATED TO A TERMINAL DEVICE
3y 0m to grant Granted Aug 25, 2026
Patent 12717949
DATA PROVIDING SYSTEM, DATA PROVIDING APPARATUS, AND DATA PROVIDING METHOD
2y 4m to grant Granted Aug 25, 2026
Patent 12711210
IDENTIFYING AND AUTHENTICATING USERS BASED ON PASSIVE FACTORS DETERMINED FROM SENSOR DATA
4y 11m to grant Granted Aug 18, 2026
Patent 12711260
AUTHORIZING AN OPERATION ON SENSITIVE DATA ASSOCIATED WITH A MOBILE DEVICE BY OBTAINING PERMISSION FROM AN AUTHORIZED USER
2y 4m to grant Granted Aug 18, 2026
Patent 12689630
METHOD AND SYSTEM FOR SUPPORTING DUAL PARTY CONTROL AUTHORIZATION FOR SENSITIVE OPERATIONS
2y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+28.4%)
2y 6m (~1y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 558 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month