DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claim1-20 rejected on the ground of nonstatutory double patenting as being unpatentable over claim1-20 of U.S. Patent No 12,355,760. Although the claims at issue are not identical, they are not patentably distinct from each other because they are both drawn to multifactor authentication utilizing similar steps and/or components described in each application/patent. See for example the table below mapping out similarities between the claims:
Instant Application:19/228,066
Patent No: 12,355,760
1. A method comprising: sending, from an authentication application deployed on a second computing device to a system, a first authentication code, the first authentication code being generated from a shared code and an authentication application time, wherein the shared code is a code previously shared between the second computing device and the system, and the authentication application time is based on a first current device time of the second computing device; receiving, at the second computing device, an authentication error message from the system; responsive to receiving the authentication error message, determining, by the authentication application, a timing synchronisation measure between the authentication application time and system time;determining, by the authentication application, a synchronised authentication application time based on a subsequent current device time of the second computing device and the timing synchronisation measure; andsending, from the authentication application to the system, a second authentication code, the second authentication code being generated from the shared code and the synchronised authentication application time.
2. The method of claim 1, further comprising:determining, by the authentication application, an offset parameter value based on the timing synchronisation measure, wherein the synchronised authentication application time is based on the subsequent current device time of the second computing device and the offset parameter value.
3. The method of claim 1, further comprising:receiving, at a first computing device from a system in communication with the first computing device across a communications network, a first verification request in response to a first authentication request for a user;wherein the first authentication code is sent in response to receiving the first verification request.
4. The method of claim 1, further comprising:receiving, from the system at a first computing device, a second verification request in response to a subsequent second authentication request for a user.
5. The method of claim 1, comprising:sharing a secret code between the second computing device and the system during registration of a user with an application of the system.
6. The method of claim 2, comprising:maintaining, by the authentication application, a register of offset parameter values, the register comprising the offset parameter value associated with the system, and one or more other offset parameter values associated with respective other systems.
7. The method of claim 2, further comprising:automatically updating, by the authentication application, the offset parameter value as a sum of the offset parameter value and the determined timing synchronisation measure.
8. The method of claim 1, wherein determining the timing synchronisation measure comprises:sending, by the authentication application, a timing request to the system;receiving, by the authentication application, a timing response to the timing request from the system; anddetermining the timing synchronisation measure from the timing response.
9. The method of claim 1, wherein determining the timing synchronisation measure comprises:sending, by the authentication application, a timing request for UTC to a universal coordinated time (UTC) server;receiving, by the authentication application, a timing response from the UTC server; anddetermining the timing synchronisation measure from the timing response.
10. The method of claim 8, wherein the timing response comprises:(i) an origin timestamp indicative of a device time when sending the timing request;(ii) a receive timestamp indicative of the system time when the timing request was received;(iii) a transmit timestamp indicative of the system time when sending the timing response; and(iv) a destination timestamp indicative of the device time when the timing response was received.
11. The method of claim 1, further comprising:sending, from a third computing device to the system, a first authentication request for a user.
12. The method of claim 3, further comprising:sending, from a third computing device to the system, the first authentication request for the user; andsending, from the third computing device to the system, a second authorisation request for the user.
13. The method of claim 11, wherein a first computing device is the third computing device and is associated with the user.
14. The method of claim 11, wherein a first computing device and the third computing device are different devices and are both associated with the user.
15. The method of claim 3, wherein the first computing device is the second computing device and is associated with the user.
16. The method of claim 1, wherein a first computing device and the second computing device are different devices and are both associated with a user.
17. The method of claim 3, wherein the first authentication request for a user is a second or subsequent step of a multi-factor authentication process.
18. A computing device comprising:one or more processors; andmemory comprising computer executable instructions, which when executed by the one or more processors, cause the computing device to:send, from an authentication application deployed on a second computing device to a system, a first authentication code, the first authentication code being generated from a shared code and an authentication application time, wherein the shared code is a code previously shared between the second computing device and the system, and the authentication application time is based on a first current device time of the second computing device;receive, at the second computing device, an authentication error message from the system;responsive to receiving the authentication error message, determine, by the authentication application, a timing synchronisation measure between the authentication application time and system time;determine, by the authentication application, a synchronised authentication application time based on a subsequent current device time of the second computing device and the timing synchronisation measure; andsend, from the authentication application to the system, a second authentication code, the second authentication code being generated from the shared code and the synchronised authentication application time.
19. A non-transitory computer-readable medium storing instructions that, when executed by a computer, cause the computer to perform operations including:sending, from an authentication application deployed on a second computing device to a system, a first authentication code, the first authentication code being generated from a shared code and an authentication application time, wherein the shared code is a code previously shared between the second computing device and the system, and the authentication application time is based on a first current device time of the second computing device;receiving, at the second computing device, an authentication error message from the system;responsive to receiving the authentication error message, determining, by the authentication application, a timing synchronisation measure between the authentication application time and system time;determining, by the authentication application, a synchronised authentication application time based on a subsequent current device time of the second computing device and the timing synchronisation measure; andsending, from the authentication application to the system, a second authentication code, the second authentication code being generated from the shared code and the synchronised authentication application time.
20. The computing device of claim 18, wherein the computer executable instructions, which when executed by the one or more processors, further cause the computing device to:maintain, by the authentication application, a register of offset parameter values, the register comprising the offset parameter value associated with the system, and one or more other offset parameter values associated with respective other systems.
1. A method comprising: sending, from an authentication application deployed on a second computing device to a system, a first authentication code, the first authentication code being generated from a shared code and an authentication application time, wherein the shared code is a code previously shared between the second computing device and the system, and the authentication application time is based on a first current device time of the second computing device and an offset parameter value; receiving, at the second computing device, an authentication error message from the system; responsive to receiving the authentication error message, determining, by the authentication application, a timing synchronization measure between the authentication application time and system time; determining, by the authentication application, an offset parameter value based on the timing synchronization measure; determining, by the authentication application, a synchronized authentication application time based on a subsequent current device time of the second computing device and the offset parameter value; and sending, from the authentication application to the system, a second authentication code, the second authentication code being generated from the shared code and the synchronized authentication application time.
2. The method of claim 1, further comprising: receiving, at a first computing device from a system in communication with the first computing device across a communications network, a first verification request in response to a first authentication request for a user; wherein the first authentication code is sent in response to receiving the first verification request.
3. The method of claim 1, further comprising: receiving, from the system at a first computing device, a second verification request in response to a subsequent second authentication request for a user.
4. The method of claim 1, comprising: sharing a secret code between the second computing device and the system during registration of a user with an application of the system.
5. The method of claim 1, comprising: maintaining, by the authentication application, a register of offset parameter values, the register comprising the offset parameter value associated with the system, and one or more other offset parameter values associated with respective other systems.
6. The method of claim 1, further comprising: automatically updating, by the authentication application, the offset parameter value as a sum of the offset parameter value and the determined timing synchronization measure.
7. The method of claim 1, wherein determining the timing synchronization measure comprises: sending, by the authentication application, a timing request to the system; receiving, by the authentication application, a timing response to the timing request from the system; and determining the timing synchronization measure from the timing response.
8. The method of claim 1, wherein determining the timing synchronization measure comprises: sending, by the authentication application, a timing request for UTC to a universal coordinated time (UTC) server; receiving, by the authentication application, a timing response from the UTC server; and determining the timing synchronization measure from the timing response.
9. The method of claim 7, wherein the timing response comprises: (i) an origin timestamp indicative of a device time when sending the timing request; (ii) a receive timestamp indicative of the system time when the timing request was received; (iii) a transmit timestamp indicative of the system time when sending the timing response; and (iv) a destination timestamp indicative of the device time when the timing response was received.
10. The method of claim 1, further comprising: sending, from a third computing device to the system, a first authentication request for a user.
11. The method of claim 2, further comprising: sending, from a third computing device to the system, the first authentication request for the user; and sending, from the third computing device to the system, a second authorisation request for the user.
12. The method of claim 10, wherein a first computing device is the third computing device and is associated with the user.
13. The method of claim 10, wherein a first computing device and the third computing device are different devices and are both associated with the user.
14. The method of claim 2, wherein the first computing device is the second computing device and is associated with the user.
15. The method of claim 1, wherein a first computing device and the second computing device are different devices and are both associated with a user.
16. The method of claim 2, wherein the first authentication request for a user is a second or subsequent step of a multi factor authentication process.
17. A computing device comprising: one or more processors; and memory comprising computer executable instructions, which when executed by the one or more processors, cause the computing device to: send, from an authentication application deployed on a second computing device to a system, a first authentication code, the first authentication code being generated from a shared code and an authentication application time, wherein the shared code is a code previously shared between the second computing device and the system, and the authentication application time is based on a first current device time of the second computing device and an offset parameter value; receive, at the second computing device, an authentication error message from the system; responsive to receiving the authentication error message, determine, by the authentication application, a timing synchronization measure between the authentication application time and system time; determine, by the authentication application, an offset parameter value based on the timing synchronization measure; determine, by the authentication application, a synchronized authentication application time based on a subsequent current device time of the second computing device and the offset parameter value; and send, from the authentication application to the system, a second authentication code, the second authentication code being generated from the shared code and the synchronized authentication application time.
18. A non-transitory computer-readable medium storing instructions that, when executed by a computer, cause the computer to perform operations including: sending, from an authentication application deployed on a second computing device to a system, a first authentication code, the first authentication code being generated from a shared code and an authentication application time, wherein the shared code is a code previously shared between the second computing device and the system, and the authentication application time is based on a first current device time of the second computing device and an offset parameter value; receiving, at the second computing device, an authentication error message from the system; responsive to receiving the authentication error message, determining, by the authentication application, a timing synchronization measure between the authentication application time and system time; determining, by the authentication application, an offset parameter value based on the timing synchronization measure; determining, by the authentication application, a synchronized authentication application time based on a subsequent current device time of the second computing device and the offset parameter value; and sending, from the authentication application to the system, a second authentication code, the second authentication code being generated from the shared code and the synchronized authentication application time.
19. The computing device of claim 17, wherein the computer executable instructions, which when executed by the one or more processors, further cause the computing device to: maintain, by the authentication application, a register of offset parameter values, the register comprising the offset parameter value associated with the system, and one or more other offset parameter values associated with respective other systems.
20. The computing device of claim 17, wherein the computer executable instructions, which when executed by the one or more processors, further cause the computing device to automatically update, by the authentication application, the offset parameter value as a sum of the offset parameter value and the determined timing synchronization measure.
As shown above, both the instant application and patent overlap significantly in subject matter rendering them obvious over one another.
Allowable Subject Matter
Claims 1-20 allowed.
As allowable subject matter has been indicated, applicant's reply must either comply with all formal requirements or specifically traverse each requirement not complied with. See 37 CFR 1.111(b) and MPEP § 707.07(a). In the instant case, the applicant should file a terminal disclaimer.
The following is an examiner’s statement of reasons for allowance:
The prior art, Tan et al (US 2023/0396609), discloses sending, from an authentication application deployed on a second computing device to the system, a first authentication code, the first authentication code being generated from a shared code and an authentication application time, wherein the shared code is a code previously shared between the second computing device and the system, and the authentication application time is based on a first current device time of the second computing device and an offset parameter value.
The prior art, Gallagher III (US 2023/0196357), discloses a secure user authentication system, operable over a client-server communications network to authenticate a system user. The system includes an application server which includes a site which is able to be enabled, and an authentication server, which is able to enable the application server site. The authentication server includes a core database, and receives and stores user authentication-enabling data in the core database. The system further includes a client, and a client program which is able to be actuated in the client. The client program includes the user authentication-enabling data. Upon actuation, the client program automatically directly connects to the authentication server, and sends the client authentication-enabling data to the authentication server, for secure user authentication by the authentication server.
The prior art, Guo et al (US 2022/0046003), discloses receiving, by a terminal device in an authentication process, a random number and a first sequence number from a core network device. After determining that a difference between the first sequence number and a locally prestored second sequence number is greater than a threshold, the terminal device concatenates a message authentication code after an exclusive OR value of an authentication key and the second sequence number to generate a synchronization failure parameter, where the authentication key is generated based on the random number, a locally prestored key K, and the message authentication code. A synchronization failure message carrying the synchronization failure parameter is sent to the core network device. The core network device generates the authentication key in a same manner, and obtains the second sequence number from the synchronization failure parameter.
The prior art, Hitchcock et al (US 10,878,080), discloses replicating authentication data between computing devices. A computing device detects a change to a user account made by a first client device associated with the user account. The computing device then determines that a second client device associated with the user account comprises locally stored authentication data that fails to reflect the change. The computing device then sends an update to the second client device.
The prior art, Goodsitt et al (US 2020/0220864), discloses a device detects a communication involving a user associated with an account and a service representative, and sends, to a user device associated with the account, an authentication notification that causes the user device to display an authentication field for the user. The device sends, to a service representative device associated with the service representative, a message that indicates that the service representative is to request, via the communication, the user to enter personal information associated with the user into the authentication field, where the user device is configured to generate a first authentication code based on a user input received from the user device in the authentication field. The device generates a second authentication code based on personal information associated with the account from a data structure, receives the first authentication code, and performs an action based on the first authentication code and the second authentication code.
The prior art, Sierra et al (US 2019/0312726), discloses a method for a first device to join a group of related devices. The method receives input of a password for an account with a centralized entity and a code generated by a second device in the group. When the second device determines that the code input on the first device matches the generated code, the method receives an authentication code from the second device for authorizing the first device with the entity as a valid device for the account. The method uses the password and information regarding the first device to generate an application to the group. After sending the application to the second device, the method receives information from the second device that enables the first device to add itself to the group. The second device verifies the generated application, and the method uses the information received from the second device to join the group.
The prior art, Briceno et al (US 2019/0253404), discloses performing advanced authentication techniques and associated applications. For example, one embodiment of a method comprises: receiving a policy identifying a set of acceptable authentication capabilities; determining a set of client authentication capabilities; and filtering the set of acceptable authentication capabilities based on the determined set of client authentication capabilities to arrive at a filtered set of one or more authentication capabilities for authenticating a user of the client.
The prior art, Hawkes et al (US 2016/0337861), discloses generating, at a secure user plane location (SUPL) server, a message to be sent to a mobile device, the message including: a server certificate including an identifier of the SUPL server and a public key of the SUPL server; and a request for a device certificate of the mobile device. The method also includes receiving a reply from the mobile device that includes a device certificate of the mobile device; and authenticating the mobile device as associated with a SUPL user based on the device certificate.
The prior art, Roth et al (US 9,106,405), discloses Secret information, such as seeds, codes, and keys, can be automatically renegotiated between at least one sender and at least one recipient. Various mechanisms, such as counters, events, or challenges, can be used to trigger automatic renegotiations through various requests or communications. These changes can cause the current secret information to diverge from older copies of the secret information that might have been obtained by unintended third parties. In some embodiments, a secret can be configured to "decay" over time, or have small changes periodically introduced that can be determined to be valid by an authorized party, but can reduce the effectiveness of prior versions of the secret information.
The prior art, Henshaw et al (US 2014/0208400), discloses a restricted-use authentication code are disclosed. One disclosed embodiment provides a method of generating a representation of a restricted-use authentication code for detection by another computing device to authenticate the other computing device to a remote service. The method includes receiving authentication information, the authentication information comprising a restricted-use authentication code and generating a representation of the authentication information. The method further includes presenting the representation of the authentication information to a sensor system of the other computing device for authentication.
The prior art, Chu et al (US 2011/0197266), discloses secure user authentication using a OTP involve, for example, pre-storing a OTP application on a first computing device for generating a valid OTP value for the user responsive to receiving entry of a valid PIN value of the user, no part of the valid PIN value is stored on the first computing device and pre-storing on a back-end server the valid PIN value and a valid shared secret for the user. Upon receiving entry of a purported PIN value of the user, a purported shared secret is dynamically synthesized on the first computing device by the OTP application based on the purported PIN value of the user and a purported OTP value is generated on the first computing device. When entry of the purported OTP value is received by the back-end server in an attempt to log on the back-end server from a second computing device, the back-end server cryptographically calculates a window of OTP values, and log on to the back-end server from the second computing device is allowed if the calculated window of OTP values corresponds to the received OTP value.
The prior art, Perlman (US 7,874,010), discloses receiving desired expiration time at a server that manages keys, where time is received from an encrypter of a message. A secret associated with the time to be stored on the server is ensured, so that the secret is looked up using an identifier, and a hash is calculated to generate a key for encrypting and decrypting the message. The hash and the identifier are sent to the encrypter that is connected to a message reader. The hash is sent to the reader to enable the reader to decrypt, where the server reconstructs the secret key for the message
The prior art, Walker (US 2010/0228988), discloses a device for visual code transaction verification enables more secure electronic transactions. The method includes generating a window having a first pattern of elongated segments. A second pattern of elongated segments is then generated, wherein a dynamic visual code is produced when the window and the first pattern of elongated segments are superimposed with the second pattern of elongated segments. A transaction with a user is then verified by matching the dynamic visual code with a code string entered by the user.
The prior art, Yang et al (US 2007/0101412), discloses that logic determines the client device having the permission to access the server using the nonce and the nonce count by verifying that the nonce and the nonce count exist in the nonce table, thus conducting a secured communication between the client device and the server in the network.
The prior art, Asokan et al (US 2006/0251256), discloses managing access to a wireless local area network are provided. A wireless access point (AP) may use a unified approach that utilizes an out-of-band channel to communicate authentication key and network address information to a guest device, and utilizes an in-band channel to establish communications with the guest device, and also provides support for in-band setup on all devices. The ability to use out-of-band where possible provides for an increase to security and usability, and the possibility of delegating access from one device to another. The unified approach thereby also provides easy management of guest access to the WLAN.
The prior art, Hammell et al (US 2006/0064493), discloses integrating authentication protocols in the establishment of connections between a controlled-access first computing device and at least one second computing device. In one embodiment of the invention, network access user authentication data needed to access the at least one second computing device is transmitted to an authentication server automatically if the user has access to use the first computing device, thereby not requiring the user to manually enter the authentication data needed for such access at the first computing device. The network access user authentication data may be, for example, retrieved from a memory store of the first computing device and/or generated in accordance with an authentication data generating algorithm.
The prior art, Hwang (US 2006/0036857), discloses using a user device operated by an authorized user to produce and register a secret in a computer system. Two user inputs from a user requesting to access the system are used to initiate a challenge from the system and a response from the user to compare the registered secret with a user-side hash value. The registration of the secret comprises generating a pseudorandom number as an authentication secret.
The prior art, Jeffries et al (US 2005/0132192), discloses that a client retrieves the random values from the challenge token received from a server, and transmits retrieved random value and user identification (ID) to the server. The server generates one-time authentication token if received random value is correct, and transmits authentication token for providing access permission to client.
However, none of the prior arts of record, either alone or in combination, discloses all the limitations of the independent claim, 1, 18, and 19, including, but not limited to "sending, from an authentication application deployed on a second computing device to a system, a first authentication code, the first authentication code being generated from a shared code and an authentication application time, wherein the shared code is a code previously shared between the second computing device and the system, and the authentication application time is based on a first current device time of the second computing device; receiving, at the second computing device, an authentication error message from the system; responsive to receiving the authentication error message, determining, by the authentication application, a timing synchronisation measure between the authentication application time and system time; determining, by the authentication application, a synchronised authentication application time based on a subsequent current device time of the second computing device and the timing synchronisation measure; and sending, from the authentication application to the system, a second authentication code, the second authentication code being generated from the shared code and the synchronised authentication application time.” Therefore, independent claims 1, 18, and 19 are allowable over the prior arts of record. Likewise, the associated claims which depend from independent claims 1, 18, and 19 are allowable by virtue of their dependence on the independent claims.
Any comments considered necessary by applicant must be submitted no later than the payment of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such submissions should be clearly labeled “Comments on Statement of Reasons for Allowance.”
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
The prior art, Vincent (US 2003/0131238), discloses accepting a request for data from a client computer and transmitting a partial response to the client computer. The partial response contains a nonce value that is digitally signed and used to authorize a limited number of accesses to data on a remote computer.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KENDALL DOLLY whose telephone number is (571)270-1948. The examiner can normally be reached Monday-Friday 7am-3pm (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KENDALL DOLLY/Primary Examiner, Art Unit 2436