DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 17 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 17 recites the limitation "the second operation command" in lines 3-4. There is insufficient antecedent basis for this limitation in the claim.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-12, 17 and 20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1 and 20 recite “determining at least one of a second authentication policy or a second security policy of the first tag”, which falls into the “Mental Process” grouping of step 2A, prong one analysis for subject matter eligibility (MPEP 2106.04(a)). Additionally, MPEP 2106.04(a)(2), section III, explains that courts do not distinguish between mental processes that are performed entirely in the human mind and mental processes that require a human to use a physical aid (e.g., pen and paper) to perform the limitation (See Benson, 409 U.S. at 67, 65, 175 USPQ at 674-75, 674 (noting that the claimed "conversion of [binary-coded decimal] numerals to pure binary numerals can be done mentally," i.e., "as a person would do it by head and hand."); Synopsys, Inc. v. Mentor Graphics Corp., 839 F.3d 1138, 1139, 120 USPQ2d 1473, 1474 (Fed. Cir. 2016) (holding that claims to a mental process of "translating a functional description of a logic circuit into a hardware component description of the logic circuit" are directed to an abstract idea, because the claims "read on an individual performing the claimed steps mentally or with pencil and paper"). Nor do the courts distinguish between claims that recite mental processes performed by humans and claims that recite mental processes performed on a computer. As the Federal Circuit has explained, "[c]ourts have examined claims that required the use of a computer and still found that the underlying, patent-ineligible invention could be performed via pen and paper or in a person’s mind." Versata Dev. Group v. SAP Am., Inc., 793 F.3d 1306, 1335, 115 USPQ2d 1681, 1702 (Fed. Cir. 2015). See also Intellectual Ventures I LLC v. Symantec Corp., 838 F.3d 1307, 1318, 120 USPQ2d 1353, 1360 (Fed. Cir. 2016) (‘‘[W]ith the exception of generic computer-implemented steps, there is nothing in the claims themselves that foreclose them from being performed by a human, mentally or with pen and paper.’’); Mortgage Grader, Inc. v. First Choice Loan Servs. Inc., 811 F.3d 1314, 1324, 117 USPQ2d 1693, 1699 (Fed. Cir. 2016) (holding that computer-implemented method for "anonymous loan shopping" was an abstract idea because it could be "performed by humans without a computer").
This judicial exception is not integrated into a practical application because the additional elements include “obtaining security information”, “receiving a first operation command”, and “sending a first command”. These steps amount to mere data gathering for the mental process step, and do not integrate the judicial exception into a practical application.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements amount to well-understood, routine, and conventional computer functionality. Therefore, the claims do not include an inventive concept that is significantly more than the abstract idea.
Claims 2-12 include limitations similar to the above-mentioned limitations that were not sufficient to integrate the judicial exception into a practical application. Nor would the additional elements be considered to be sufficient to amount to significantly more than the judicial exception.
Claim 17 recites “wherein the first security policy is determined based on the subscription information of the first tag”, which falls into the “Mental Process” grouping of step 2A, prong one analysis for subject matter eligibility (MPEP 2106.04(a)). Claim 17 does not include any additional elements that integrate the abstract idea into a practical application, or that are sufficient to amount to significantly more than the judicial exception. Additionally, claim 17 depends from claim 13, which only includes a “sending” step and a “receiving” step, which amount to mere data gathering for the mental process step, and do not integrate the judicial exception into a practical application.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 13-19 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Gupta, U.S. Patent No. 9,609,022. Referring to claim 13, Gupta discloses a tag reader 160 implemented as part of device 120 that reads an identifier (ID) and command from a tag 150 (Col. 3, lines 37-48: any information from the tag 150 can be considered the key since the key is never functionally utilized and would therefore be considered to be data; MDM server 110 reads on the claimed first device) and sends the ID and command to an MDM server 110 (Col. 3, lines 48-56), which meets the limitation of sending one or more of a key to a first device. Server 110 retrieves specific policies that correspond to the received ID and sends policies to device 120 (Col. 3, lines 57-65: policies read on the claimed second security policies/authentication policy/security policy; Examiner notes that the name of the policy does not define structure nor does the policy name require functional steps to be performed. Therefore, the policy name would be considered to be non-functional descriptive material, which is not given patentable weight. See MPEP 2111.04-2111.05) and the policies include identifiers corresponding to the tags (Col. 5, lines 30-40: Table 1 shows that the policies include the identifiers. Therefore, when the MDM server sends the policies, the identifiers are also being sent), which meets the limitation of receiving a first command from the first device, wherein the first command comprises at least one of a second authenticaiotn policy or a second security policy, and a tag identifier of a first tag. Gupta discloses that the MDM server 110 performs device authentication and user authentication (Col. 8, lines 18-40: mechanisms utilized to perform authentication can be considered a “policy” in general and would therefore read on the claimed authentication/security policy and first operation command security policy where the first operation command is authenticate either the device or the user; This “policy” information is held by the MDM server and would therefore be “related” to the retrieved specific polices to the extent that they each reside on the MDM server), which meets the limitation of and at least one of the second authentication policy or the second security policy is related to at least one of the first authentication policy or the first security policy and a first operation command security policy corresponding to a first operation command.
Referring to claim 14, Gupta discloses that the tag reader 160 sends the area ID and command to the OS of device 120 (Col. 3, lines 48-50: OS of device 120 reads on the claimed application function entity), which meets the limitation of sending at least the key to an application function entity.
Referring to claim 15, Gupta discloses that the MDM server 110 performs user authentication before performing device authentication (Col. 8, lines 18-24), which meets the limitation of wherein the first authentication policy and the first security policy are executed before the first device receives the first operation command.
Referring to claim 16, Gupta discloses that the MDM server provides for the registration of users wherein user information obtained and stored in a user database (Col. 4, lines 10-18) and the MDM server provides for the registration of the user devices (Col. 4, lines 19-38), which meets the limitation of wherein the first authentication policy comprises an authentication policy during registration. The MDM server 110 performs user authentication before performing device authentication (Col. 8, lines 18-24: shows user authentication command performed before device authentication command), which meets the limitation of wherein the first authentication policy comprises an authentication policy determined for a second operation command before the first operation command.
Referring to claim 17, Gupta discloses that the MDM server 110 performs user authentication before performing device authentication (Col. 8, lines 18-24), which meets the limitation of where the first security policy comprises a security policy determined for the second operation command before the first operation command.
Referring to claim 18, Gupta discloses that server 110 retrieves specific policies that correspond to the received ID and sends policies to device 120 (Col. 3, lines 57-65: policies read on the claimed security policy) and the policies include identifiers corresponding to the tags (Col. 5, lines 30-40: Table 1 shows that the policies include the identifiers. Therefore, when the MDM server sends the policies, the identifiers are also being sent; Device 120 OS utilizes the received policy to reconfigure the device, which would show that the OS “expects” the security policy for the purposes of reconfiguration. See column 3, lines 64-67), which meets the limitation of receiving a second command from the first device, wherein the second command comprises the tag identifier of the first tag and the security policy expected by the application function entity.
Referring to claim 19, Gupta discloses that once device 120 has been reconfigured using the received policy, device 120 sends a confirmation message to the MDM server that device 120 is compliant with the policy (Col. 3, line 67- Col. 4, line 6: Examiner notes that the content of the transmission is never functionally utilized by the claimed first device. Therefore, the contents of the transmission to the first device would be considered to be non-functional descriptive material which is not given patentable weight. See MPEP 2111.04-2111.05. Any data could then read on the contents of the claimed response message.), which meets the limitation of sending a response message corresponding to the second command to the first device, wherein the response message comprises the first authentication policy.
Allowable Subject Matter
Claims 1-12 and 20 are allowable over the prior art.
The following is an examiner’s statement of reasons for allowance:
The prior art does not disclose or make obvious the claimed obtaining of security information and command security policies from subscription information of a first tag such that the security information is utilized, along with a command security policy selected from the command security policies using a first command received from an application function entity, to determine an authentication/security policy for the first tag. The determined authentication/security policy is then transmitted to a device.
The closest prior art Gupta, U.S. Patent No. 9,609,022, discloses an MDM server 110 that receives an identifier and command, which originated from an RFID tag, and utilizes this identifier and command to retrieve a security policy such that the retrieved security policy is provided to a device 120 for the purposes of reconfiguration.
Gupta does not specify that the MDM server 110 determines this security policy using the specific information that includes either the identifier/command, which could be considered the claimed security information, a policy selected from one of the policies obtained from tag subscription information using a command received from an application function entity. Gupta discloses that the device 120 OS sends reconfiguration commands, but these reconfiguration commands are based on the security policies received from the MDM server 110. The MDM server 110 of Gupta does not determine this security policy based on any commands received from the device 120 OS and the other information specifically required by the claims.
Any comments considered necessary by applicant must be submitted no later than the payment of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such submissions should be clearly labeled “Comments on Statement of Reasons for Allowance.”
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Zhang, U.S. Publication No. 2025/0047674, discloses security verification of commands from a network device.
Zhu, U.S. Publication No. 2023/0345243, discloses an authentication scheme for networked tag devices.
Patil, U.S. Patent No. 11,589,226, discloses a multi-factor authentication system for home network user equipment.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BENJAMIN E LANIER whose telephone number is (571)272-3805. The examiner can normally be reached M-Th: 5:30-4:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at 5712705143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BENJAMIN E LANIER/ Primary Examiner, Art Unit 2437