Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is a reply to the application filed on 5/30/2025, in which claim(s) 1-20 are pending.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 5/30/2025, has been reviewed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the examiner is considering the information disclosure statement.
Specification
The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification.
Drawings
The drawings filed on 5/30/2025 is/are accepted by The Examiner.
Claim Objections
Claims 1-20 are objected to because of the following informalities:
The claims reciting “IP” and “URI” without properly defining what they represent. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim(s) 20 is/are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Claim limitations “a backend processing infrastructure of a third party configured to…” in claim 20 are limitations that invoke 35 U.S.C. 112, sixth paragraph. The written description only implicitly or inherently sets forth the corresponding structure, material, or acts that perform the claimed function.
Pursuant to 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181, applicant should:
(a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112, sixth paragraph; or
(b) Amend the written description of the specification such that it expressly recites the corresponding structure, material, or acts that perform the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or
(c) State on the record what corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claim(s) 1-20 is/are rejected on the ground of nonstatutory double patenting over claim(s) 1-20 of U.S. Patent No. 12,323,808 since the claims, if allowed, would improperly extend the “right to exclude” already granted in the patent.
The subject matter claimed in the instant application is fully disclosed in the patent and is covered by the patent since the patent and the application are claiming common subject matter, as follows: Although the claims are not identical; however, the current application is fully anticipated by the parent application.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim(s) 1, 11 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Trinh et la. (US 10206099 B1; hereinafter Trinh) in view of Bakshi (US 20120253957 A1).
Regarding claims 1, 11 and 20, Trinh discloses a method, comprising:
receiving, at a backend processing infrastructure of a third party and from a backend processing infrastructure of a mobile application provider, a first copy of location information and an [[IP address]], wherein the location information and the [[IP address]] are associated with a mobile device (The authentication server then evaluates the received location of the authentication request relative to the location of the mobile device [Trinh; 3:23-43, 4:45-55]);
receiving, at the backend processing infrastructure of the third party and from a mobile application provided by the third party, a second copy of the location information and the [[IP address]], wherein the mobile application provided by the third party is executed on the mobile device (The application 117 retrieves the location of the mobile device 115 via the GPS 118 and sends the location to the authentication service 106, the server instead correlates location information of the authentication request and the mobile device. This approach provides ease-of-use to the user by allowing a seamless logon using 2FA [Trinh; 3:23-43, 4:45-55]); and
verifying, by the backend processing infrastructure of the third party, that the first copy of the location information and the [[IP address]] matches the second copy of the location information and the [[IP address]] (Once received, the authentication service 106 compare the location of the mobile device 115 with the location of the authentication request (e.g., obtained through various sources, such as the IP address, wireless network mappings, etc.). If the locations are within a specified range of one another, the authentication service 106 grants the user 109 access [Trinh; 3:23-43, 4:45-55]). Trinh does not explicilty discloses receiving from a backend processing infrastructure of a mobile application provider, an IP address, wherein the IP address are associated with a mobile device; however, in a related and analogous art, Bakshi teaches this feature.
In particular, Bakshi teaches retrieving from the location mapping database IP address of the mobile device and compared to authenticate the user [Bakshi; ¶33, 44; Fig. 3, 5 and associated text]. IT would have been obvious before the effective filing date of the claimed invention to modify Trinh in view of Bakshi to use location + IP address in the 2FA and the mobile subscriber location is saved locally in a database that is associated with the authorization entity with the motivation to reduce the number of locations look-ups performed [Bakshi; ¶8].
Claim(s) 2-7, 10 and 12-17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Trinh-Bakshi combination in view of Vongsouvanh et al. (US 20140223516 A1; hereinafter Vongsouvanh).
Regarding claims 2 and 12, Trinh-Bakshi combination does not explicilty discloses comprising:
sending, by the backend processing infrastructure of the third party and to the backend processing infrastructure of the mobile application provider, a request for a redirect URI, wherein the redirect URI includes requested user data and an action identifier as parameters of the URI; however, in a related and analogous art, Vongsouvanh teaches this feature.
In particular, Vongsouvanh teaches Authorization request 130 may include an identifier for client device 110, a requested scope for the requested authorization, local state, and/or a redirection Uniform Resource Identifier (URI) to which authorization service 122 may redirect mobile computing device 100 upon granting access to resource service 120. In this aspect, client device 110 sends authorization request 130 directly to computing device 100 by communication pathway 126 [Vongsouvanh; ¶26]. It would have been obvious before the effective filing date of the claimed invention to modify Trinh-Bakshi combination in view of Vongsouvanh with the motivation to easier direct the user to access the resources.
Regarding claims 3 and 13, Trinh-Bakshi-Vongsouvanh combination discloses comprising: receiving, at the backend processing infrastructure of the third party, the requested user data and the action identifier (retrieves and executes programming instructions stored in memory 520 as well as stores and retrieves application data residing in the storage 530 [Trinh; 7:29-33]).
Regarding claims 4 and 14, Trinh-Bakshi-Vongsouvanh combination discloses comprising: validating, by the backend processing infrastructure of the third party, that the requested user data matches user data for completing an action associated with the action identifier (compare the location of the mobile device 115 with the location of the authentication request. If the locations are within a specified range of one another is consider matching [Trinh; 3:23-43, 4:45-55]).
Regarding claims 5 and 15, Trinh-Bakshi-Vongsouvanh combination discloses comprising: sending, by the backend processing infrastructure of the third party and to the backend processing infrastructure of the mobile app provider, a request for the requested user data (requesting for user location [Trinh; 3:23-43, 4:45-55]).
Regarding claims 6 and 16, Trinh-Bakshi-Vongsouvanh combination discloses comprising: receiving, by the backend processing infrastructure of the third party and from the backend processing infrastructure of the mobile app provider, the requested data (If the locations are within a specified range of one another, the authentication service 106 grants the user 109 access [Trinh; 3:23-43, 4:45-55]).
Regarding claims 7 and 17, Trinh-Bakshi-Vongsouvanh combination discloses comprising: completing, by the backend processing infrastructure of the third party, the action using the requested data (If the locations are within a specified range of one another, the authentication service 106 grants the user 109 access [Trinh; 3:23-43, 4:45-55]).
Regarding claim 10, Trinh-Bakshi combination does not explicilty discloses the method of claim 1, comprising: receiving, by the backend processing infrastructure of the third party and from a mobile application provided by the third party, a user-confirmation to share the requested data; however, in a related and analogous art, Vongsouvanh teaches this feature.
In particular, Vongsouvanh teaches sharing of resources [Vongsouvanh; ¶16]. It would have been obvious before the effective filing date of the claimed invention to modify Trinh-Bakshi combination in view of Vongsouvanh with the motivation to easier direct the user to access the resources.
Claim(s) 8-9 and 18-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Trinh-Bakshi combination in view of Lawson et al. (US 20200302065 A1; hereinafter Lawson).
Regarding claims 8 and 18, Trinh-Bakshi combination discloses wherein the first copy of the location information and the IP address, and the second copy of the location information and the IP address, are hashed; however, in a related and analogous art, Lawson teaches this feature.
In particular, Lawson teaches hashing the path using salt value to prevent the path from being exposed [Lawson; ¶30, 46]. It would have been obvious before the effective filing date of the claimed invention to modify Trinh-Bakshi combination with Lawson to hash the location and IP address with the motivation to prevent the information from being obtained and protect user’s privacy.
Regarding claims 9 and 19, Trinh-Bakshi-Lawson combination discloses wherein a salt value is hashed with the first copy of the location information and the IP address, and the salt value is hashed with the second copy of the location information and the IP address (hashing of the data include salt value [Lawson; ¶30, 46]. The motivation to prevent the information from being obtained and protect user’s privacy.
Internet Communications
Applicant is encouraged to submit a written authorization for Internet communications (PTO/SB/439, http:ljwww.uspto.gov/sites/default/files/documents/sb0439.pdf) in the instant patent application to authorize the examiner to communicate with the applicant via email. The authorization will allow the examiner to better practice compact prosecution. The written authorization can be submitted via one of the following methods only: (1) Central Fax which can be found in the Conclusion section of this Office action; (2) regular postal mail; (3) EFS WEB; or (4) the service window on the Alexandria campus. EFS web is the recommended way to submit the form since this allows the form to be entered into the file wrapper within the same day (system dependent). Written authorization submitted via other methods, such as direct fax to the examiner or email, will not be accepted. See MPEP § 502.03.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAO Q HO whose telephone number is (571)270-5998. The examiner can normally be reached on 7:00am - 5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached on (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DAO Q HO/Primary Examiner, Art Unit 2432