DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This is in response to the correspondence filed on 07/02/25. Claims 21-40 are still pending and have been considered below.
Claim Objections
Claims 27 and 35 are objected to because of the following informalities: the instant claims do not recite a “period” at the end of the claim. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 21-40 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 21, 22, 39 and 40 recite the limitation "the access credentials" throughout the claims. There is insufficient antecedent basis for this limitation in the claims. Examiner notes that the preceding claim language does not appear to establish any first instance of just “access credentials” by itself; thus, render the claims indefinite in that it is unclear as to what the limitation in question is in reference to.
Claim 24 recites the limitation "wherein the updated credentials comprise credentials are generated in real-time…" in line 2. Examiner notes that the limitation appears to contain grammatical errors; thus, renders the claim indefinite.
Claim 25 recites the limitation "the updated security credentials" in line 1. There is insufficient antecedent basis for this limitation in the claim.
Claim 27 recites the limitation "the at least one line server" in line 3. There is insufficient antecedent basis for this limitation in the claim.
Claims 21-38 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being incomplete for omitting essential steps, such omission amounting to a gap between the steps. See MPEP § 2172.01.
Examiner notes that the claims are directed to a method of automatically off-boarding a user from accessing online accounts; however, merely comprises one step of using a processor for “executing” an automated access agent that is configured to performing various functions.
Therefore, Examiner respectfully submits that the claims, as currently recited, do not appear to necessarily require the automated access agent to actually perform any of the recited functions because the exact metes and bounds of what “executing” the automated access agent entails is not further clarified by the claim language.
Claims 39 and 40 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being incomplete for omitting essential elements, such omission amounting to a gap between the elements. See MPEP § 2172.01.
Examiner notes that the claims are directed to a system and non-transitory medium for automatically off-boarding a user from accessing online accounts; however, merely comprises one element of a processor configured to “execute” an automated access agent that is configured to performing various functions, and program instructions for causing a processor to do the same.
Therefore, Examiner respectfully submits that the claims, as currently recited, do not appear to necessarily require the automated access agent to actually perform any of the recited functions because the exact metes and bounds of what “executing” the automated access agent entails is not further clarified by the claim language.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 21-28, 32-36, 39 and 40 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Cavanagh et al. (2017/0011214).
Claim 21: Cavanagh et al. discloses a method of automatically off-boarding a user from accessing online accounts, comprising:
using at least one processor for executing an automated access agent configured to:
transmit an access credentials reset request to reset access to at least one account of at least one online server accessed by the user(require the user to reset the password for the first time) [page 12, paragraph 0084];
intercept at least one credentials reset message generated in response to the access credentials reset request, the at least one credentials reset message including a credentials reset network address(URL for changing password) [page 9, paragraph 0059 | page 11, paragraph 0077];
access the credentials reset network address(identifies field(s) to input a new password by password manager, where the new password is randomly/dynamically generated by the password manager and with increased security strength) [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082]; and
reset the access credentials, via the accessed credential reset network address, for revoking permission of the user to access the at least one account(Examiner notes that once the previous password has been replaced with the new password, the previous password would no longer have any reasonable amount of access; thus, would be understood as effectively revoking permission of the user to access the at least one account with the previous password) [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082].
Claim 22: Cavanagh et al. discloses the method of claim 21, wherein reset the access credentials comprises replace existing access credentials with updated credentials [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082].
Claim 23: Cavanagh et al. discloses the method of claim 22, wherein the automated access agent is further configured to discard the updated credentials without storing the updated credentials [page 11, paragraph 0074].
Claim 24: Cavanagh et al. discloses the method of claim 22, wherein the updated credentials comprise credentials are generated in real-time and are updated in a secure credentials repository accessible to the at least one automated access agent [page 7, paragraph 0047 | page 10, paragraph 0065].
Claim 25: Cavanagh et al. discloses the method of claim 22, wherein the updated security credentials are predefined and retrieved from a secure credentials repository accessible to the at least one automated access agent(set of rules for passwords of each website account) [page 7, paragraph 0047 | page 10, paragraph 0065].
Claim 26: Cavanagh et al. discloses the method of claim 21, wherein the at least one account includes a private online account associated with an off-boarded user [page 3, paragraph 0027].
Claim 27: Cavanagh et al. discloses the method of claim 21, wherein the automated access agent is further configured to: in response to revoking permission of the user, delete the at least one account at the at least one line server(at a later time user can also de-register any of the user’s client devices from access) [page 11, paragraph 0074]
Claim 28: Cavanagh et al. discloses the method of claim 27, wherein the delete the at least one account includes deleting stored data associated with the at least one account [page 11, paragraph 0074].
Claim 32: Cavanagh et al. discloses the method of claim 21, wherein the at least one account includes at least one restricted online account, private and/or shared, which are accessible only to employees [page 3, paragraphs 0023 & 0027].
Claim 33: Cavanagh et al. discloses the method of claim 21, wherein the user is an employee leaving a company [page 3, paragraphs 0023 & 0027].
Claim 34: Cavanagh et al. discloses the method of claim 21, wherein the automated access agent is triggered to revoke permission according to at least one predefined rule being met [page 7, paragraph 0047 | page 11, paragraph 0074].
Claim 35: Cavanagh et al. discloses the method of claim 21, wherein the automated access agent is triggered to revoke permission in response to receiving an off-boarding command from an administrative system indicating the user should no longer have access to the at least one account [page 7, paragraph 0047 | page 11, paragraph 0074]
Claim 36: Cavanagh et al. discloses the method of claim 21, wherein the automated access agent is triggered to revoke permission in response to a command received via a user interface [page 7, paragraph 0047 | page 11, paragraph 0074].
Claim 39: Cavanagh et al. discloses a system for automatically off-boarding a user from accessing online accounts, comprising:
at least one processor configured to execute an automated access agent configured to:
transmit an access credentials reset request to reset access to at least one account of at least one online server accessed by the user [page 12, paragraph 0084];
intercept at least one credentials reset message generated in response to the access credentials reset request, the at least one credentials reset message including a credentials reset network address [page 9, paragraph 0059 | page 11, paragraph 0077];
access the credentials reset network address [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082]; and
reset or replace the access credentials, via the accessed credential reset network address, for revoking permission of the user to access the at least one account [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082].
Claim 40: Cavanagh et al. discloses a non-transitory medium storing program instructions for automatically off-boarding a user from accessing online accounts, comprising program instructions which when executed by at least one processor, cause the at least one processor to:
execute an automated access agent configured to:
transmit an access credentials reset request to reset access to at least one account of at least one online server accessed by the user [page 12, paragraph 0084];
intercept at least one credentials reset message generated in response to the access credentials reset request, the at least one credentials reset message including a credentials reset network address [page 9, paragraph 0059 | page 11, paragraph 0077];
access the credentials reset network address [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082]; and
reset or replace the access credentials, via the accessed credential reset network address, for revoking permission of the user to access the at least one account [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082].
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 37 and 38 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cavanagh et al. (2017/0011214) in view of Everton et al. (2019/0036859).
Claim 37: Cavanagh et al. discloses the method of claim 21, but does not explicitly disclose wherein the at least one credentials reset message is intercepted during transmission via at least one correspondence channel associated with the user.
However, Everton et al. discloses a similar invention [page 11, paragraphs 0107-0108] and further discloses wherein the at least one credentials reset message is intercepted during transmission via at least one correspondence channel associated with the user [page 12, paragraphs 0111-0113].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further modify the disclosure of Cavanagh et al. with the additional features of Everton et al., in order to provide an improved technique for mobile device management by utilizing a client-agnostic and network-agnostic mobile device management system, as suggested by Everton et al. [page 1, paragraphs 0002-0003].
Claim 38: Cavanagh et al. and Everton et al. disclose the method of claim 37, and Everton et al. further discloses wherein the at least one correspondence channel includes an email account associated with the user [page 12, paragraphs 0111-0113].
Allowable Subject Matter
Claims 29-31 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 21-40 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-18 of U.S. Patent No. 12,081,539 in view of Cavanagh et al. (2017/0011214).
Although the claims at issue are not identical, they are not patentably distinct from each other because both inventions are directed to a substantially similar technique of increasing security of access to online accounts, which specifically intercepts a credentials reset message to access a credential reset network address; and only differing in that the instant claims go on to specify minor nuances not found in the patented claims, such as revoking permission of the user to access the at least one account.
However, Cavanagh et al. discloses a similar invention and goes on to disclose each of the various deficiencies not found in the patented claims [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082], as already discussed above in the prior art rejection(s).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further modify the patented claims with the additional features of Cavanagh et al., in order to facilitate a password management system that is less vulnerable to attacks and more efficiently manages and updates passwords, as suggested by Cavanagh et al. [page 1, paragraphs 0004-0005]; thus, arriving at patented claims which are not patently distinct from the instant claims and properly rejected on the grounds of nonstatutory double patenting.
Claims 21-40 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-22 of U.S. Patent No. 12,328,312 in view of Cavanagh et al. (2017/0011214).
Although the claims at issue are not identical, they are not patentably distinct from each other because both inventions are directed to a substantially similar technique of increasing security of access to online accounts, which specifically intercepts a credentials reset message to access a credential reset network address; and only differing in that the instant claims go on to specify minor nuances not found in the patented claims, such as revoking permission of the user to access the at least one account.
However, Cavanagh et al. discloses a similar invention and goes on to disclose each of the various deficiencies not found in the patented claims [page 7, paragraph 0047 | page 10, paragraph 0065 | page 11, paragraph 0079 | page 12, paragraphs 0081-0082], as already discussed above in the prior art rejection(s).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to further modify the patented claims with the additional features of Cavanagh et al., in order to facilitate a password management system that is less vulnerable to attacks and more efficiently manages and updates passwords, as suggested by Cavanagh et al. [page 1, paragraphs 0004-0005]; thus, arriving at patented claims which are not patently distinct from the instant claims and properly rejected on the grounds of nonstatutory double patenting.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Iverson et al. (2010/0325707).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDWARD ZEE whose telephone number is (571)270-1686. The examiner can normally be reached Monday-Friday 9AM-5PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EDWARD ZEE/Primary Examiner, Art Unit 2435