DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In communications filed on 06/25/2026. Claims 1-20 are pending in this examination.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This examination is in response to US Patent Application No. 19/249,995.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a) (1) as being anticipated by LUO GUANGZHEN (CN112765597A), hereinafter “LUO”( filed in IDS 11/13/2025).
Regarding claims 1, 13, and 20, LUO discloses an interception method performed by an electronic device, comprising:
[ Page 1, 1st paragraph, this application relates to the field of communication technology, and in particular to a software installation package detection method and device]; and
receiving a first operation of downloading a first target application
[Page 1, 2nd paragraph, During the downloading process of the software installation package]; and
obtaining a first download address of the first target application in response to the first operation
[Page 2, Para. 5th , acquiring software installation package download reference information, where the software installation package download reference information includes installation package data volume, installation package identification, and download channel information,
Respond to the software installation package download instruction, establish a download link with the server, and obtain the actual installation package data volume of the software installation package currently to be downloaded based on the download link]; and
downloading a first installation package of the first target application from a first download server based on the first download address
[Page 2, Para. 5th, acquiring software installation package download reference information, where the software installation package download reference information includes installation package data volume, installation package identification, and download channel information,
Respond to the software installation package download instruction, establish a download link with the server, and obtain the actual installation package data volume of the software installation package currently to be downloaded based on the download link]; and
obtaining, by the electronic device, first data of the first installation package
[ Page 1, 3rd Para., At present, the way to detect the software installation package is usually after the software installation package is downloaded, the MD5 value corresponding to the downloaded software installation package is calculated through the message digest algorithm (MD5 Message-Digest Algorithm, MD5), and then calculated The obtained MD5 value is compared with the MD5 value carried in the software installation package to verify whether the downloaded software installation package is the expected software installation package. If the calculated MD5 value is inconsistent with the MD5 value carried in the software installation package, it is considered that the software installation package has been tampered with]; and
sending the first data to the interception server ; receiving a first detection result sent by the interception server, wherein the first detection result results from detecting the first target application based on the first data, and outputting a first notification message, wherein the first notification message is used to notify a user of risk information of the first target application.
[ Page 17, Para. 4th-10th, Page 18 1st-3rd para., refer to FIG. 9, which is a schematic structural diagram of a software installation package detection device provided by an embodiment of the application, where the software installation package detection device may include a first acquisition unit 301, a second acquisition unit 302, a download unit 303, and an extraction unit 304, and the determining unit 305, and so on…..the determining unit 305 may be specifically used to: compare the actual installation package identifier with the installation package identifier; when the actual installation package identifier matches the installation package identifier, compare the actual download channel information with the download channel information; When the actual download channel information does not match the download channel information, it is determined that the target software installation package is an abnormal installation package].
[ Page 1, 3rd para. at present, the way to detect the software installation package is usually after the software installation package is downloaded, the MD5 value corresponding to the downloaded software installation package is calculated through the message digest algorithm (MD5 Message-Digest Algorithm, MD5), and then calculated The obtained MD5 value is compared with the MD5 value carried in the software installation package to verify whether the downloaded software installation package is the expected software installation package. If the calculated MD5 value is inconsistent with the MD5 value carried in the software installation package, it is considered that the software installation package has been tampered with.],
[ Page 11, 3rd Para. In one embodiment, when the actual installation package identifier does not match the installation package identifier, or the actual download channel information does not match the download channel information, determining that the target software installation package is an abnormal installation package may include: identifying the actual installation package with the installation package. Compare the package ID; when the actual installation package ID matches the installation package ID, compare the actual download channel information with the download channel information; when the actual download channel information does not match the download channel information, determine the target software installation package as an abnormal installation package],
[ Page 8, 3rd para. after obtaining the actual installation package data volume of the software installation package currently to be downloaded, the actual installation package data volume can be compared with the installation package data volume in the software installation package download reference information to verify the actual installation package data volume. When the actual installation package data volume matches (that is, the same), the verification of the actual installation package data volume is passed. At this time, the terminal can download the current software installation package to be downloaded from the server based on the download address carried in the download link , Get the target software installation package. When the actual installation package data volume does not match (that is, inconsistent), it means that the verification of the actual installation package data volume is not passed. At this time, the terminal may not download the current software installation package to be downloaded and may output the verification failed and rejected Relevant download prompt information reduces download waiting time and stalls. Before downloading the current software installation package to be downloaded, the actual installation package data (such as file size) can be quickly verified, so that it can quickly determine whether the current software installation package to be downloaded has been tampered with. The file size of the software installation package to be downloaded will change if it is tampered with or replaced. If the file size is inconsistent, the package will be considered washed, and the download will be cancelled. For example, as shown in Figure 4, when the actual installation package data volume does not match the installation package data volume, the terminal can also output "The XXX software installation package you downloaded has been quickly checked and found that the package has been washed by the manufacturer and turned into a third-party harmful Software, the download will be canceled for you soon" and other prompt messages to inform users that the software installation package currently to be downloaded may be risky, and buttons such as "Cancel" and "OK" can also be displayed for users to choose to continue downloading or cancel downloading].
Regarding claims 2, and 14, LUO discloses , wherein the step of obtaining the first data of the first installation package comprises: upon detecting that a data length of downloaded data in the first installation package reaches a preset length, determining the first data based on the downloaded data.
[ Page 7 , 5th Para. In one embodiment, obtaining the actual installation package data volume of the software installation package currently to be downloaded based on the download link may include: querying the file length storage field in the request header information of the download link; extracting the file length from the file length storage field, based on The file length determines the actual installation package data volume of the software installation package currently to be downloaded].
Regarding claims 3, and 15, LUO discloses, wherein the first data is the downloaded data or a hash value of the downloaded data.
[ Page 1, 1st Para. During the downloading process of the software installation package…].
Regarding claims 4, and 16, LUO disclose, wherein the first detection result results from detecting the first target application by the interception server based on a risky application database and the first data.
[Page 17, Para. 4th-10th, Page 18 1st-3rd para. refer to FIG. 9, which is a schematic structural diagram of a software installation package detection device provided by an embodiment of the application, where the software installation package detection device may include a first acquisition unit 301, a second acquisition unit 302, a download unit 303, and an extraction unit 304, and the determining unit 305, and so on…..the determining unit 305 may be specifically used to: compare the actual installation package identifier with the installation package identifier; when the actual installation package identifier matches the installation package identifier, compare the actual download channel information with the download channel information; When the actual download channel information does not match the download channel information, it is determined that the target software installation package is an abnormal installation package]., and
[Page 15, 1st Para. if the file size is inconsistent, the package is considered to be washed, and the download is canceled. When the actual file size does not match the file size, the terminal can also output a warning message that the game installation package currently to be downloaded may be risky to inform the user that the current game installation package to be downloaded may be risky, so that the user can choose to continue the download or cancel the download Wait].
Regarding claims 5, and 17, LUO disclose sending the first download address to the interception server, wherein the first detection result results from detecting the first target application based on the first data and the first download address.
[Page 17, Para. 4th-10th, Page 18 1st-3rd para. refer to FIG. 9, which is a schematic structural diagram of a software installation package detection device provided by an embodiment of the application, where the software installation package detection device may include a first acquisition unit 301, a second acquisition unit 302, a download unit 303, and an extraction unit 304, and the determining unit 305, and so on…..the determining unit 305 may be specifically used to: compare the actual installation package identifier with the installation package identifier; when the actual installation package identifier matches the installation package identifier, compare the actual download channel information with the download channel information; When the actual download channel information does not match the download channel information, it is determined that the target software installation package is an abnormal installation package.
Regarding claims 6,, and 18, LUO disclose, wherein before the step of obtaining the first data of the first installation package, the method further comprises: sending the first download address to the interception server; and receiving a second detection result sent by the interception server, wherein the second detection result results from detecting the first target application based on the first download address, and the second detection result indicates that the first target application has no security risk.
[refer to FIG. 9, which is a schematic structural diagram of a software installation package detection device provided by an embodiment of the application, where the software installation package detection device may include a first acquisition unit 301, a second acquisition unit 302, a download unit 303, and an extraction unit 304, and the determining unit 305, and so on…..the determining unit 305 may be specifically used to: compare the actual installation package identifier with the installation package identifier; when the actual installation package identifier matches the installation package identifier, compare the actual download channel information with the download channel information; When the actual download channel information does not match the download channel information, it is determined that the target software installation package is an abnormal installation package], and
[Page 15, 1st Para. if the file size is inconsistent, the package is considered to be washed, and the download is canceled. When the actual file size does not match the file size, the terminal can also output a warning message that the game installation package currently to be downloaded may be risky to inform the user that the current game installation package to be downloaded may be risky, so that the user can choose to continue the download or cancel the download Wait].
Regarding claims 7, and 19, LUO disclose, wherein when the first target application has a security risk, the first notification message notifies the user that the first target application has a security risk, and wherein the method further comprises: stopping downloading the first installation package.
[ Page 15, 1st Para. if the file size is inconsistent, the package is considered to be washed, and the download is canceled. When the actual file size does not match the file size, the terminal can also output a warning message that the game installation package currently to be downloaded may be risky to inform the user that the current game installation package to be downloaded may be risky, so that the user can choose to continue the download or cancel the download Wait].
Regarding claim 8, LUO disclose, wherein when the first target application has a security risk, the first notification message notifies the user that the first target application has a security risk, and wherein the method further comprises: deleting the downloaded data in response to a second operation performed on the first notification message; or deleting the downloaded data if no operation performed by the user on the first notification message is received within preset duration.
[Page 15, last paragraphs, S209: When the actual package name does not match the package name, delete the target game installation package…S211. When the actual channel number does not match the channel number, determine that the target game installation package is an abnormal installation package, and delete the target game installation package.], and
[Page 16, 2nd para. For example, after obtaining the actual package name, the terminal can first compare the actual package name with the package name. When the actual package name does not match the package name, it can determine that the target game installation package is an abnormal installation package and delete the target game installation package . When the actual package name matches the package name, the actual channel number is further compared with the channel number. When the actual channel number does not match the channel number, the target game installation package is determined to be an abnormal installation package, and the target game installation package is deleted], and
[Page 15,3rd Para. last paragraphs After determining that the target game installation package is an abnormal installation package, in order to avoid the risk of installing the abnormal target game installation package, and to save the storage space of the terminal, the target game installation package can be deleted
Regarding claim 9, LUO disclose wherein the electronic device stores a local risk database, and when the first target application has a security risk, the method further includes the first data and the first download address to the local risk database.
[Page 8, 3rd Para, after obtaining the actual installation package data volume of the software installation package currently to be downloaded, the actual installation package data volume can be compared with the installation package data volume in the software installation package download reference information to verify the actual installation package data volume. When the actual installation package data volume matches (that is, the same), the verification of the actual installation package data volume is passed( equated to no security risk). At this time, the terminal can download the current software installation package to be downloaded from the server based on the download address carried in the download link , Get the target software installation package], and
[ Page 15, 1st Para. if the file size is inconsistent, the package is considered to be washed, and the download is canceled. When the actual file size does not match the file size, the terminal can also output a warning message that the game installation package currently to be downloaded may be risky to inform the user that the current game installation package to be downloaded may be risky, so that the user can choose to continue the download or cancel the download Wait].
Regarding claim 10, LUO disclose, wherein when the first target application has no security risk, the first notification message indicates that the first target application has no security risk.
[Page 8, 3rd Para, after obtaining the actual installation package data volume of the software installation package currently to be downloaded, the actual installation package data volume can be compared with the installation package data volume in the software installation package download reference information to verify the actual installation package data volume. When the actual installation package data volume matches (that is, the same), the verification of the actual installation package data volume is passed( equated to no security risk). At this time, the terminal can download the current software installation package to be downloaded from the server based on the download address carried in the download link , Get the target software installation package], and
[ Page 15, 1st Para. if the file size is inconsistent, the package is considered to be washed, and the download is canceled. When the actual file size does not match the file size, the terminal can also output a warning message that the game installation package currently to be downloaded may be risky to inform the user that the current game installation package to be downloaded may be risky, so that the user can choose to continue the download or cancel the download Wait].
Regarding claim 11, wherein the electronic device stores a local risk database, and wherein the method further comprises: receiving a third operation of downloading a second target application; obtaining a second download address of the second target application in response to the third operation; downloading a second installation package of the second target application from a second download server based on the second download address; obtaining second data of the second installation package; and outputting a second notification message when the electronic device determines, based on the second data, the second download address, and the local risk database, that the second target application has a security risk, wherein the second notification message notifies the user that the second target application has a security risk.
This claim is interpreted and rejected for the same rational set forth in claim 1 referenced to LUO.
Regarding claim 12, wherein when the electronic device determines, based on the second data, the second download address, and the local risk database, that the second target application has no security risk, the method further comprises: sending the second data to the interception server; receiving a fourth detection result sent by the interception server, wherein the fourth detection result results from detecting the second target application based on the second data; and outputting a third notification message, wherein the third notification message notifies the user of risk information of the second target application
This claim is interpreted and rejected for the same rational set forth in claim 1 referenced to LUO.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's
disclosure.
See submitted 892 for more relevant references.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHAHRIAR ZARRINEH whose telephone number is (571)272-1207. The examiner can normally be reached Monday-Friday, 8:30am-5:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached at 571-272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHAHRIAR ZARRINEH/Primary Examiner, Art Unit 2496