DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
1. This is in response to the communications filed on 14 July 2025.
2. Claims 1-20 are pending in the application.
3. Claims 1-20 have been rejected.
Information Disclosure Statement
4. The examiner has considered the information disclosure statement (IDS) filed on 25 June 2025 and 14 July 2025.
Specification
5. The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
6. Claims 1, 8 and 15 rejected on the ground of nonstatutory double patenting as being unpatentable over claim 1 of U.S. Patent No. 12,408,221 B2 (hereinafter the ‘221 patent) in view of Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete).
As to claim 1, the ‘221 patent teaches a network server processing and communication system, comprising:
at least one processor configured to:
receive a request for authorization information and at least one device identifier associated with a communication device [column 42, lines 12-16];
acquire from the at least one non-transient data storage device, a user identifier corresponding to the received device identifier [column 42, lines 47-52];
create authorization information from the acquired user identifier [column 42, lines 47-52].
The ‘221 patent does not teach at least one non-transient data storage device storing data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier is associated with a user identifier. The ‘221 patent does not teach transmit the acquired user identifier and the created authorization information to the communication device.
Streete teaches at least one non-transient data storage device storing data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier is associated with a user identifier (i.e. database table stored in credential data store that includes device identifier key that is mapped to credential set data) [column 7, lines 11-39]. Streete teaches transmit the acquired user identifier and the created authorization information to the communication device (i.e. credential manager sends the generated credential data response message to the client) [column 6, lines 27-33].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the ‘221 patent so that at least one non-transient data storage device would have stored data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier was associated with a user identifier. The acquired user identifier and the created authorization information would have been transmitted to the communication device.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the ‘221 patent by the teaching of Streete because it prevents unsophisticated attacks by unauthorized parties that threaten the security of the target device and/or associated network system [column 1, lines 18-34].
As to claim 8, the ‘221 patent teaches a non-transitory computer-readable medium of a network server processing and communication system, the medium comprising computer-readable instructions such that, when executed, causes processing electronics of the network server processing and communication system to control the communication device to:
receive a request for authorization information and at least one device identifier associated with a communication device (i.e. client may send a credential data request message that includes the device identifier key associated with the computing device) [column 5 line 64 to column 6 line 26];
acquire from the at least one non-transient data storage device, a user identifier corresponding to the received device identifier (i.e. credential manage may acquire the mapped credential set data and subsequently generate a credential data response message that includes the credential set data) [column 5 line 64 to column 6 line 26];
create authorization information from the acquired user identifier (i.e. credential data response message) [column 5 line 64 to column 6 line 26].
The ‘221 patent does not teach transmit the acquired user identifier and the created authorization information to the communication device.
Streete teaches transmit the acquired user identifier and the created authorization information to the communication device (i.e. credential manager sends the generated credential data response message to the client) [column 6, lines 27-33].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the ‘221 patent so that the acquired user identifier and the created authorization information would have been transmitted to the communication device.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the ‘221 patent by the teaching of Streete because it prevents unsophisticated attacks by unauthorized parties that threaten the security of the target device and/or associated network system [column 1, lines 18-34].
As to claim 15, the ‘221 patent teaches a method for a network server processing and communication system, the method comprising:
storing, in at least one non-transient data storage device, data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier is associated with a user identifier (i.e. database table stored in credential data store that includes device identifier key that is mapped to credential set data) [column 7, lines 11-39]; and
configuring at least one processor to:
receive, over a communication network, a request for authorization information and at least one device identifier associated with a communication device (i.e. client may send a credential data request message that includes the device identifier key associated with the computing device) [column 5 line 64 to column 6 line 26];
acquire from the at least one non-transient data storage device, a user identifier corresponding to the received device identifier (i.e. credential manage may acquire the mapped credential set data and subsequently generate a credential data response message that includes the credential set data) [column 5 line 64 to column 6 line 26];
create authorization information from the acquired user identifier (i.e. credential data response message) [column 5 line 64 to column 6 line 26]; and
transmit, over the communication network, the acquired user identifier and the created authorization information to the communication device (i.e. credential manager sends the generated credential data response message to the client) [column 6, lines 27-33].
The ‘221 patent does not teach at least one non-transient data storage device storing data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier is associated with a user identifier. The ‘221 patent does not teach transmit the acquired user identifier and the created authorization information to the communication device.
Streete teaches at least one non-transient data storage device storing data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier is associated with a user identifier (i.e. database table stored in credential data store that includes device identifier key that is mapped to credential set data) [column 7, lines 11-39]. Streete teaches transmit the acquired user identifier and the created authorization information to the communication device (i.e. credential manager sends the generated credential data response message to the client) [column 6, lines 27-33].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the ‘221 patent so that at least one non-transient data storage device would have stored data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier was associated with a user identifier. The acquired user identifier and the created authorization information would have been transmitted to the communication device.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the ‘221 patent by the teaching of Streete because it prevents unsophisticated attacks by unauthorized parties that threaten the security of the target device and/or associated network system [column 1, lines 18-34].
7. Claims 2, 9 and 16 rejected on the ground of nonstatutory double patenting as being unpatentable over U.S. Patent No. 12,408,221 B2 (hereinafter the ‘221 patent) and Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) in view of Loladia et al U.S. Patent No. 10,678,906 B1 (hereinafter Loladia).
As to claims 2, 9 and 16, the combination of the ‘221 patent and Streete do not teach the system according to claim 1, wherein the request for authorization information and the device identifier are received via MQTT protocol.
Loladia teaches that the request for authorization information and the device identifier are received via MQTT protocol (i.e. requests are published and received in accordance with MQTT) [column 12, lines 15-24].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete so that the request for authorization information and the device identifier was received via MQTT protocol.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete by the teaching of Loladia because it ensures that messages are not directly sent between two client devices [column 2, lines 31-55].
8. Claims 3, 10 and 17 rejected on the ground of nonstatutory double patenting as being unpatentable over U.S. Patent No. 12,408,221 B2 (hereinafter the ‘221 patent) and Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) in view of Limaye et al US 2021/0344668 A1 (hereinafter Limaye).
As to claims 3, 10 and 17, the combination of the ‘221 patent and Streete do not teach the system according to claim 1, wherein the authorization information comprises HTTPS access authorization information for communication via HTTPS protocol.
Limaye teaches that the authorization information comprises HTTPS access authorization information for communication via HTTPS protocol (i.e. the username and password may be used for HTTPS basic authentication of the supplicant device) [0017].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete so that the authorization information would have comprised HTTPS access authorization information for communication via HTTPS protocol.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete by the teaching of Limaye because it helps protect the network against unauthorized access and attacks [0001].
9. Claims 4, 11 and 18 rejected on the ground of nonstatutory double patenting as being unpatentable over U.S. Patent No. 12,408,221 B2 (hereinafter the ‘221 patent) and Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) in view of Ziraknejad et al U.S. Patent No. 10,769,262 B1 (hereinafter Ziraknejad).
As to claims 4, 11 and 18, the combination of the ‘221 patent and Streete do not teach receive a request for data, the request for data being associated with the authorization information. The combination of the ‘221 patent and Streete do not teach confirm that the authorization information associated with the request for data is valid. The combination of the ‘221 patent and Streete do not teach transmit the retrieved data to the communication device upon confirming that the authorization information is valid.
Ziraknejad teaches receiving a request for data, the request for data being associated with the authorization information (i.e. sending a request for credential information of a user of a client device) [column 13, lines 28-54]. Ziraknejad teaches confirming that the authorization information associated with the request for data is valid (i.e. confirming that the user’s credential is valid) [column 14 line 54 to column 15 line 21]. Ziraknejad teaches transmitting the retrieved data to the communication device upon confirming that the authorization information is valid (i.e. the server system communicates with the credential-issuing organization that issued the credential to receive updated credentials [column 14 line 54 to column 15 line 21].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete so that a request for data would have been received, the request for data would have been associated with the authorization information. It would have been confirmed that the authorization information associated with the request for data was valid. The retrieved data would have been transmitted to the communication device upon confirming that the authorization information was valid.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete by the teaching of Ziraknejad because it helps control the use of credentials and resources that are associated with the credentials [column 4, lines 62-63].
10. Claims 5, 12 and 19 rejected on the ground of nonstatutory double patenting as being unpatentable over U.S. Patent No. 12,408,221 B2 (hereinafter the ‘221 patent) and Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) in view of Ziraknejad et al U.S. Patent No. 10,769,262 B1 (hereinafter Ziraknejad).
As to claims 5, 12 and 19, the ‘221 patent does not teach the system according to claim 4, wherein the at least one processor is further configured to retrieve the requested data from the at least one non-transient data storage device.
Streete teaches the system according to claim 4, wherein the at least one processor is further configured to retrieve the requested data from the at least one non-transient data storage device (i.e. credential manager configured to extract the device identifier key and the query credential data store) [column 5 line 64 to column 6 line 26].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the ‘221 patent so that the at least one processor would have been further configured to retrieve the requested data from the at least one non-transient data storage device.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the ‘221 patent by the teaching of Streete because it prevents unsophisticated attacks by unauthorized parties that threaten the security of the target device and/or associated network system [column 1, lines 18-34].
11. Claims 6, 13 and 20 rejected on the ground of nonstatutory double patenting as being unpatentable over U.S. Patent No. 12,408,221 B2 (hereinafter the ‘221 patent) and Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) in view of Wall US 2016/0226853 A1.
As to claims 6, 13 and 20, the combination of the ‘221 patent and Streete do not teach the system according to claim 1, further comprising confirming that the acquired user identifier corresponds to a user account registered with the server, before creating or transmitting the authorization information.
Wall teaches confirming that the acquired user identifier corresponds to a user account registered with the server, before creating or transmitting the authorization information (i.e. check a database to confirm that the received username corresponds to the existing account) [0023].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete so that it would have been confirmed that the acquired user identifier corresponded to a user account registered with the server, before creating or transmitting the authorization information.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete by the teaching of Wall because it helps protect electronic accounts [0004].
12. Claims 7 and 14 rejected on the ground of nonstatutory double patenting as being unpatentable over U.S. Patent No. 12,408,221 B2 (hereinafter the ‘221 patent) and Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) in view of Prendergast et al US 2023/0080249 A1 (hereinafter Prendergast).
As to claims 7 and 14, the combination of the ‘221 patent and Streete do not teach the system according to claim 1, further comprising confirming that the request for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information.
Prendergast teaches confirming that the request for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information (i.e. based on the response message sent providing resource availability level associated with the user identifier) [0013].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete so that the request would have been confirmed for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified the combination of the ‘221 patent and Streete by the teaching of Prendergast because it helps provide a resource threshold event regarding a user account [0001].
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
13. Claim(s) 1, 8 and 15 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete).
As to claim 1, Streete discloses a network server processing and communication system, comprising:
at least one non-transient data storage device storing data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier is associated with a user identifier (i.e. database table stored in credential data store that includes device identifier key that is mapped to credential set data) [column 7, lines 11-39]; and
at least one processor configured to:
receive a request for authorization information and at least one device identifier associated with a communication device (i.e. client may send a credential data request message that includes the device identifier key associated with the computing device) [column 5 line 64 to column 6 line 26];
acquire from the at least one non-transient data storage device, a user identifier corresponding to the received device identifier (i.e. credential manage may acquire the mapped credential set data and subsequently generate a credential data response message that includes the credential set data) [column 5 line 64 to column 6 line 26];
create authorization information from the acquired user identifier (i.e. credential data response message) [column 5 line 64 to column 6 line 26]; and
transmit the acquired user identifier and the created authorization information to the communication device (i.e. credential manager sends the generated credential data response message to the client) [column 6, lines 27-33].
As to claim 8, Streete discloses a non-transitory computer-readable medium of a network server processing and communication system, the medium comprising computer-readable instructions such that, when executed, causes processing electronics of the network server processing and communication system to control the communication device to:
receive a request for authorization information and at least one device identifier associated with a communication device (i.e. client may send a credential data request message that includes the device identifier key associated with the computing device) [column 5 line 64 to column 6 line 26];
acquire from the at least one non-transient data storage device, a user identifier corresponding to the received device identifier (i.e. credential manage may acquire the mapped credential set data and subsequently generate a credential data response message that includes the credential set data) [column 5 line 64 to column 6 line 26];
create authorization information from the acquired user identifier (i.e. credential data response message) [column 5 line 64 to column 6 line 26]; and
transmit the acquired user identifier and the created authorization information to the communication device (i.e. credential manager sends the generated credential data response message to the client) [column 6, lines 27-33].
As to claim 15, Streete discloses a method for a network server processing and communication system, the method comprising:
storing, in at least one non-transient data storage device, data including a plurality of device identifiers in association with a plurality of user identifiers, where each device identifier is associated with a user identifier (i.e. database table stored in credential data store that includes device identifier key that is mapped to credential set data) [column 7, lines 11-39]; and
configuring at least one processor to:
receive, over a communication network, a request for authorization information and at least one device identifier associated with a communication device (i.e. client may send a credential data request message that includes the device identifier key associated with the computing device) [column 5 line 64 to column 6 line 26];
acquire from the at least one non-transient data storage device, a user identifier corresponding to the received device identifier (i.e. credential manage may acquire the mapped credential set data and subsequently generate a credential data response message that includes the credential set data) [column 5 line 64 to column 6 line 26];
create authorization information from the acquired user identifier (i.e. credential data response message) [column 5 line 64 to column 6 line 26]; and
transmit, over the communication network, the acquired user identifier and the created authorization information to the communication device (i.e. credential manager sends the generated credential data response message to the client) [column 6, lines 27-33].
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
14. Claim(s) 2, 9 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) as applied to claims 1, 8 and 15 above, and further in view of Loladia et al U.S. Patent No. 10,678,906 B1 (hereinafter Loladia).
As to claim 2, Streete does not teach the system according to claim 1, wherein the request for authorization information and the device identifier are received via MQTT protocol.
Loladia teaches that the request for authorization information and the device identifier are received via MQTT protocol (i.e. requests are published and received in accordance with MQTT) [column 12, lines 15-24].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that the request for authorization information and the device identifier was received via MQTT protocol.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Loladia because it ensures that messages are not directly sent between two client devices [column 2, lines 31-55].
As to claim 9, Streete does not teach the system according to claim 8, wherein the request for authorization information and the device identifier are received via MQTT protocol.
Loladia teaches that the request for authorization information and the device identifier are received via MQTT protocol (i.e. requests are published and received in accordance with MQTT) [column 12, lines 15-24].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that the request for authorization information and the device identifier was received via MQTT protocol.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Loladia because it ensures that messages are not directly sent between two client devices [column 2, lines 31-55].
As to claim 16, Streete does not teach the system according to claim 15, wherein the request for authorization information and the device identifier are received via MQTT protocol.
Loladia teaches that the request for authorization information and the device identifier are received via MQTT protocol (i.e. requests are published and received in accordance with MQTT) [column 12, lines 15-24].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that the request for authorization information and the device identifier was received via MQTT protocol.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Loladia because it ensures that messages are not directly sent between two client devices [column 2, lines 31-55].
15. Claim(s) 3, 10 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) as applied to claims 1, 8 and 15 above, and further in view of Limaye et al US 2021/0344668 A1 (hereinafter Limaye).
As to claim 3, Streete does not teach the system according to claim 1, wherein the authorization information comprises HTTPS access authorization information for communication via HTTPS protocol.
Limaye teaches that the authorization information comprises HTTPS access authorization information for communication via HTTPS protocol (i.e. the username and password may be used for HTTPS basic authentication of the supplicant device) [0017].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that the authorization information would have comprised HTTPS access authorization information for communication via HTTPS protocol.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Limaye because it helps protect the network against unauthorized access and attacks [0001].
As to claim 10, Streete does not teach the system according to claim 8 wherein the authorization information comprises HTTPS access authorization information for communication via HTTPS protocol.
Limaye teaches that the authorization information comprises HTTPS access authorization information for communication via HTTPS protocol (i.e. the username and password may be used for HTTPS basic authentication of the supplicant device) [0017].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that the authorization information would have comprised HTTPS access authorization information for communication via HTTPS protocol.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Limaye because it helps protect the network against unauthorized access and attacks [0001].
As to claim 17, Streete does not teach the system according to claim 15, wherein the authorization information comprises HTTPS access authorization information for communication via HTTPS protocol.
Limaye teaches that the authorization information comprises HTTPS access authorization information for communication via HTTPS protocol (i.e. the username and password may be used for HTTPS basic authentication of the supplicant device) [0017].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that the authorization information would have comprised HTTPS access authorization information for communication via HTTPS protocol.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Limaye because it helps protect the network against unauthorized access and attacks [0001].
16. Claim(s) 4, 5, 11, 12, 18 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) as applied to claims 1, 8 and 15 above, and further in view of Ziraknejad et al U.S. Patent No. 10,769,262 B1 (hereinafter Ziraknejad).
As to claim 4, Streete does not teach receive a request for data, the request for data being associated with the authorization information. Streete does not teach confirm that the authorization information associated with the request for data is valid. Streete does not teach transmit the retrieved data to the communication device upon confirming that the authorization information is valid.
Ziraknejad teaches receiving a request for data, the request for data being associated with the authorization information (i.e. sending a request for credential information of a user of a client device) [column 13, lines 28-54]. Ziraknejad teaches confirming that the authorization information associated with the request for data is valid (i.e. confirming that the user’s credential is valid) [column 14 line 54 to column 15 line 21]. Ziraknejad teaches transmitting the retrieved data to the communication device upon confirming that the authorization information is valid (i.e. the server system communicates with the credential-issuing organization that issued the credential to receive updated credentials [column 14 line 54 to column 15 line 21].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that a request for data would have been received, the request for data would have been associated with the authorization information. It would have been confirmed that the authorization information associated with the request for data was valid. The retrieved data would have been transmitted to the communication device upon confirming that the authorization information was valid.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Ziraknejad because it helps control the use of credentials and resources that are associated with the credentials [column 4, lines 62-63].
As to claim 5, Streete teaches the system according to claim 4, wherein the at least one processor is further configured to retrieve the requested data from the at least one non-transient data storage device (i.e. credential manager configured to extract the device identifier key and the query credential data store) [column 5 line 64 to column 6 line 26].
As to claim 11, Streete does not teach receive a request for data, the request for data being associated with the authorization information. Streete does not teach confirm that the authorization information associated with the request for data is valid. Streete does not teach transmit the retrieved data to the communication device upon confirming that the authorization information is valid.
Ziraknejad teaches receiving a request for data, the request for data being associated with the authorization information (i.e. sending a request for credential information of a user of a client device) [column 13, lines 28-54]. Ziraknejad teaches confirming that the authorization information associated with the request for data is valid (i.e. confirming that the user’s credential is valid) [column 14 line 54 to column 15 line 21]. Ziraknejad teaches transmitting the retrieved data to the communication device upon confirming that the authorization information is valid (i.e. the server system communicates with the credential-issuing organization that issued the credential to receive updated credentials [column 14 line 54 to column 15 line 21].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that a request for data would have been received, the request for data would have been associated with the authorization information. It would have been confirmed that the authorization information associated with the request for data was valid. The retrieved data would have been transmitted to the communication device upon confirming that the authorization information was valid.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Ziraknejad because it helps control the use of credentials and resources that are associated with the credentials [column 4, lines 62-63].
As to claim 12, Streete teaches the system according to claim 11, wherein the processing electronics is further configured to retrieve the requested data from the at least one non-transient data storage device (i.e. credential manager configured to extract the device identifier key and the query credential data store) [column 5 line 64 to column 6 line 26].
As to claim 18, Streete does not teach receive a request for data, the request for data being associated with the authorization information. Streete does not teach confirm that the authorization information associated with the request for data is valid. Streete does not teach transmit the retrieved data to the communication device upon confirming that the authorization information is valid.
Ziraknejad teaches receiving a request for data, the request for data being associated with the authorization information (i.e. sending a request for credential information of a user of a client device) [column 13, lines 28-54]. Ziraknejad teaches confirming that the authorization information associated with the request for data is valid (i.e. confirming that the user’s credential is valid) [column 14 line 54 to column 15 line 21]. Ziraknejad teaches transmitting the retrieved data to the communication device upon confirming that the authorization information is valid (i.e. the server system communicates with the credential-issuing organization that issued the credential to receive updated credentials [column 14 line 54 to column 15 line 21].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that a request for data would have been received, the request for data would have been associated with the authorization information. It would have been confirmed that the authorization information associated with the request for data was valid. The retrieved data would have been transmitted to the communication device upon confirming that the authorization information was valid.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Ziraknejad because it helps control the use of credentials and resources that are associated with the credentials [column 4, lines 62-63].
As to claim 19, Streete teaches the system according to claim 18, wherein the at least one processor is further configured to retrieve the requested data from the at least one non-transient data storage device (i.e. credential manager configured to extract the device identifier key and the query credential data store) [column 5 line 64 to column 6 line 26].
17. Claim(s) 6, 13 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) as applied to claims 1, 8 and 15 above, and further in view of Wall US 2016/0226853 A1.
As to claim 6, Streete does not teach the system according to claim 1, further comprising confirming that the acquired user identifier corresponds to a user account registered with the server, before creating or transmitting the authorization information.
Wall teaches confirming that the acquired user identifier corresponds to a user account registered with the server, before creating or transmitting the authorization information (i.e. check a database to confirm that the received username corresponds to the existing account) [0023].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that it would have been confirmed that the acquired user identifier corresponded to a user account registered with the server, before creating or transmitting the authorization information.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Wall because it helps protect electronic accounts [0004].
As to claim 13, Streete does not teach the system according to claim 8, wherein the processing electronics is further configured to confirm that the acquired user identifier corresponds to a user account registered with the server, before creating or transmitting the authorization information.
Wall teaches confirming that the acquired user identifier corresponds to a user account registered with the server, before creating or transmitting the authorization information (i.e. check a database to confirm that the received username corresponds to the existing account) [0023].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that it would have been confirmed that the acquired user identifier corresponded to a user account registered with the server, before creating or transmitting the authorization information.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Wall because it helps protect electronic accounts [0004].
As to claim 20, Streete does not teach the system according to claim 15, further comprising confirming that the acquired user identifier corresponds to a user account registered with the server, before creating or transmitting the authorization information.
Wall teaches confirming that the acquired user identifier corresponds to a user account registered with the server, before creating or transmitting the authorization information (i.e. check a database to confirm that the received username corresponds to the existing account) [0023].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that it would have been confirmed that the acquired user identifier corresponded to a user account registered with the server, before creating or transmitting the authorization information.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Wall because it helps protect electronic accounts [0004].
18. Claim(s) 7 and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Streete et al U.S. Patent No. 10,785,219 B1 (hereinafter Streete) as applied to claims 1 and 8 above, and further in view of Prendergast et al US 2023/0080249 A1 (hereinafter Prendergast).
As to claim 7, Streete does not teach the system according to claim 1, further comprising confirming that the request for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information.
Prendergast teaches confirming that the request for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information (i.e. based on the response message sent providing resource availability level associated with the user identifier) [0013].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that the request would have been confirmed for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Prendergast because it helps provide a resource threshold event regarding a user account [0001].
As to claim 14, Streete does not teach the system according to claim 8, wherein the processing electronics is further configured to confirm that the request for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information.
Prendergast teaches confirming that the request for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information (i.e. based on the response message sent providing resource availability level associated with the user identifier) [0013].
Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete so that the request would have been confirmed for authorization information corresponds to one or more resources that are available to a user associated with the acquired user identifier, before creating or transmitting the authorization information.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains to have modified Streete by the teaching of Prendergast because it helps provide a resource threshold event regarding a user account [0001].
Relevant Prior Art
19. The following references have been considered relevant by the examiner:
A. Mutt et al US 2022/0070213 A1 directed to preventing attacks on websites, and more particularly for preventing a Cross Site Request Forgery attack on a website served from a web server [abstract].
B. Li et al US 2021/0099295 A1 directed to encrypting and decrypting data, and more particularly relate to key generation and applications for using generated keys for various purposes, such as authentication, encryption, and/or other purposes for which keys are useful [0002].
C. Adams et al US 2017/0272413 A1 directed to personalizing program credentials [abstract].
Conclusion
20. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ARAVIND K MOORTHY whose telephone number is (571)272-3793. The examiner can normally be reached M-F 4:30-3:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ARAVIND K MOORTHY/ Primary Examiner, Art Unit 2407