DETAILED ACTION
Notice of Pre-AIA or AIA Status
In the present application, filed on or after March 16, 2013, claims 1-20 have been considered and examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(B) CONCLUSION – The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112(pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre- AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Claim 1 lacks antecedent basis for “the time-based code series instance” in the limitations of “generate a generated time-based code from the time-based code series instance using (i) a current clock value from the access control device clock and (ii) the time-based code generation schedule.”
Claim 1 recites the limitations of “wherein each time period is associated with a clock begin value and a clock end value (which could be the same)” which is not clear whether the limitations of (which could be the same) refers to the time period, the clock begin value or the clock end value, etc.
Claims 2-19 are rejected because of being dependent on a rejected claim 1.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement.
See MPEP § 717 .02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(1)(1) - 706.02(1)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.32l(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer tohttp ://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-l.jsp.
Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b).
Claims 1-20 are rejected on the ground of nonstatutory double patenting over claims 15-29 of the copending US 2025/0131783 A1 since the claims, if allowed, would improperly extend the "right to exclude" already granted in the patent.
The subject matter claimed in the instant application is fully disclosed in the patent and is covered by the US 2025/0131783 A1.
The access control system in the copending US 2025/0131783 A1 does not perform the limitations of “wherein receiving an input time-based code comprises receiving an input time-based code at least in part via at least one from the following list: radio frequency identification (RFID); Bluetooth; near-field communication (NFC); WiFi; audio signal; vibration pattern; light pattern; and temperature pattern.”
However, it has been known in the art of access control system, Ho discloses wherein receiving an input time-based code comprises receiving an input time-based code (Ho: [0044]-[0045], [0052], [0068]-[0071], and FIG. 4-5) at least in part via at least one from the following list: radio frequency identification (RFID); Bluetooth; near-field communication (NFC); WiFi; audio signal; vibration pattern; light pattern; and temperature pattern (Ho: [0022]-[0024], [0027], [0045], [0051]-[0052], [0064], and FIG. 1-5: in other embodiments, the user device 310, for example, a mobile device or a hardware token of the user, may be configured to transmit the first factor authentication data to the electronic lock 210 without requiring any manual entry on the electronic lock 210. For example, the application server 160 may enable the user device 310 to transmit the first factor authentication data using 802.11 wireless standards, Bluetooth Low Energy (BLE), near field communication (NFC), or other suitable short-range or long-range wireless communication protocols. The electronic lock 210 includes a wireless transceiver for communicating with the user device 310. In some embodiments, where the first factor authentication data includes a fingerprint information or facial profile, the user may use a biometric-enabled user device 310 that will capture his fingerprint information or facial profile via a mobile application using a fingerprint sensor or front camera of the mobile device or through a mobile application on the user device. The fingerprint information or facial profile information of the user is then transmitted wirelessly to the application server 160 through the electronic lock 210.).
Therefore, in view of teachings by the copending US 2025/0131783 A1 and Ho, it would have been obvious to implement in the access control system of US 2025/0131783 A1 to include the limitations of wherein receiving an input time-based code comprises receiving an input time-based code at least in part via at least one from the following list: radio frequency identification (RFID); Bluetooth; near-field communication (NFC); WiFi; audio signal; vibration pattern; light pattern; and temperature pattern, as suggested by Ho. The motivation for this is to implement a known alternative method step for receiving identification code.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, 4-6, 13, 15-17, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. (Ho – US 2021/0319639 A1) in view of Klapman et al. (Klapman – US 2022/0414205 A1) and Kamkar et al. (Kamkar – US 2021/0360403 A1).
As to claim 1, Ho discloses an access control system, comprising:
an access management server (Ho: [0017], [0048], [0052], [0060]-[0071], and FIG. 1 the application server 160: the application server 160 will validate the first factor authentication data with the first factor authentication data associated with the user and permission levels stored in the lock user database 161… the application server 160 will validate the second factor authentication data with the second factor authentication data associated with the user and permission levels stored in the lock user database 161. The application server 160 will also check the permission levels associated with the user, for example, available date and times, unavailable dates and times, or other limits);
an access control device (Ho: [0073]-[0078] and FIG. 5 the electronic lock 210) that is physically remote from the access management server (Ho: [0017], [0048], [0052], [0060]-[0071], [0073]-[0078], and FIG. 5 the electronic lock 210: Upon receipt of the second factor authentication data by the electronic lock 210, the electronic lock, which is arranged in wireless communication with the application server, will transmit the second factor authentication data to the application server 160);
a first time-based code series instance (Ho: [0044]-[0045], [0052], [0068]-[0071], and FIG. 4-5), comprising:
non-transitory computer executable instructions that are stored at the access control device and that, when executed (Ho: [0037], [0048], [0079]-[0080], and FIG. 5), cause the access control device to:
receive an input time-based code (Ho: [0044]-[0045], [0052], [0054]-[0055], [0068]-[0072], and FIG. 4-5: Upon receipt of the second factor authentication data by the electronic lock 210, the electronic lock, which is arranged in wireless communication with the application server, will transmit the second factor authentication data to the application server 160. At step 422, the application server 160 will validate the second factor authentication data with the second factor authentication data associated with the user and permission levels stored in the lock user database 161);
based on the match between the generated time-based code and the input time-based code, perform an action (Ho: [0017], [0048], [0052], [0060]-[0071], [0073]-[0078], and FIG. 4-5 the electronic lock 210: If the second factor authentication data received from the user matches the second factor authentication data stored on the lock user database 161, the application server 160 will send a positive signal to the electronic lock which will cause the electronic lock to release its locking mechanism at step 426 to allow entry to the entry point );
wherein receiving an input time-based code comprises receiving an input time-based code (Ho: [0044]-[0045], [0052], [0068]-[0071], and FIG. 4-5) at least in part via at least one from the following list:
radio frequency identification (RFID);
Bluetooth;
near-field communication (NFC);
WiFi;
audio signal;
vibration pattern;
light pattern; and
temperature pattern (Ho: [0022]-[0024], [0027], [0045], [0051]-[0052], [0064], and FIG. 1-5: in other embodiments, the user device 310, for example, a mobile device or a hardware token of the user, may be configured to transmit the first factor authentication data to the electronic lock 210 without requiring any manual entry on the electronic lock 210. For example, the application server 160 may enable the user device 310 to transmit the first factor authentication data using 802.11 wireless standards, Bluetooth Low Energy (BLE), near field communication (NFC), or other suitable short-range or long-range wireless communication protocols. The electronic lock 210 includes a wireless transceiver for communicating with the user device 310. In some embodiments, where the first factor authentication data includes a fingerprint information or facial profile, the user may use a biometric-enabled user device 310 that will capture his fingerprint information or facial profile via a mobile application using a fingerprint sensor or front camera of the mobile device or through a mobile application on the user device. The fingerprint information or facial profile information of the user is then transmitted wirelessly to the application server 160 through the electronic lock 210.).
Ho does not explicitly disclose
a first time-based code series instance , comprising:
a shared seed code that is known to both the access management server and to the access control device;
a time-based code generation algorithm that is known to both the access management server and to the access control device;
an access control device clock that is synchronized to an access management server clock; and
a time-based code generation schedule that is known to both the access management server and to the access control device, wherein (i) the time-based code generation schedule comprises a set of time periods wherein each time period is associated with a clock begin value and a clock end value (which could be the same); and (ii) the set of time periods may be based on an algorithm for generating time periods based on an input clock value; and
non-transitory computer executable instructions that are stored at the access control device and that, when executed, cause the access control device to:
receive an input time-based code;
generate a generated time-based code from the time-based code series instance using (i) a current clock value from the access control device clock and (ii) the time-based code generation schedule;
compare the input time-based code with the generated time-based code;
determine that the input time-based code matches the generated time-based code; and
based on the match between the generated time-based code and the input time-based code, perform an action.
However, it has been known in the art of security systems to implement the first time-based code series instance as claimed, as suggested by Klapman, which discloses
a first time-based code series instance (Klapman: [0037], [0051], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5) , comprising:
a shared seed code (Klapman: [0037], [0051], [0077]-[0078], and FIG. 4-5: the TOTP passcodes produced by generation routine 500 produces are a form of hash-based message authentication code (HMAC), where the source of uniqueness is typically a value generated from the current time and a unique seed number);
a time-based code generation algorithm that is known to both the access management server and to the access control device (Klapman: Abstract, [0023]: wherein the input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the data storage device; and provide access to the user content data via a data port of the data storage device in response to the first passcode matching with a second passcode generated by the data storage device, wherein the second passcode includes at least the unlock passcode, [0034]: the second passcode generated by the DSD 100 includes only the dynamically changing unlock passcode that is matched to a corresponding “input” passcode constituting the received first passcode. The input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the access controller, [0037]-[0038]: the user device 120 determines the input passcode, to be entered by the user into the DSD, by retrieving the input passcode or a seed value to generate the input passcode from a remote location, such as a passcode server, [0075]);
an access control device clock that is synchronized to an access management server clock (Klapman: Abstract, [0023]: wherein the input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the data storage device; and provide access to the user content data via a data port of the data storage device in response to the first passcode matching with a second passcode generated by the data storage device, wherein the second passcode includes at least the unlock passcode, [0034]: the second passcode generated by the DSD 100 includes only the dynamically changing unlock passcode that is matched to a corresponding “input” passcode constituting the received first passcode. The input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the access controller, [0037]-[0038]: the user device 120 determines the input passcode, to be entered by the user into the DSD, by retrieving the input passcode or a seed value to generate the input passcode from a remote location, such as a passcode server, [0048], [0052], [0055], [0073], [0075], [0120], and FIG. 1: a synchronization data message enabling synchronization of the reference time value T.sub.ref for the device 100 and the other user's DSDMA; and any other parameter data required for the other user's DSDMA to compute unlock codes for the device 100. The synchronization data message can include a reference time relative to a common clock, and established via a distributed time synchronization protocol (e.g., the Network Time Protocol (NTP))); and
a time-based code generation schedule that is known to both the access management server and to the access control device (Klapman: [0038], [0050]-[0052], [0072]-[0073], [0092]-[0093], FIG. 1, and FIG. 6: Processor 111 repeats the generation of a new passcode in response to a predefined time period value having expired, such as every 5 minutes, 30 minutes, 1 hour, 12 hours or any other time value. User device 120 is synchronized and therefore also generates new passcode at the same times),
wherein (i) the time-based code generation schedule comprises a set of time periods wherein each time period is associated with a clock begin value and a clock end value (which could be the same); and (ii) the set of time periods may be based on an algorithm for generating time periods based on an input clock value (Klapman: [0037], [0051]-[0052], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Processor 111 receives a clocking signal from clock 112, which is processed to produce timestamp values representing instants in real-time. Processor 111 is configured to repeatedly and automatically generate a dynamically changing passcode (the “unlock passcode”), which is a time-varying code used for unlocking the data storage device 100, by processing the stored passcode generation key and reference time value. The reference time value is determined based on a time value obtained periodically from the clock 112 (i.e., to calculate a time differential, as described herein below). Processor 111 repeats the generation of a new passcode in response to a predefined time period value having expired, such as every 5 minutes, 30 minutes, 1 hour, 12 hours or any other time value. User device 120 is synchronized and therefore also generates new passcode at the same times); and
non-transitory computer executable instructions that are stored at the access control device and that, when executed, cause the access control device (Klapman: FIG. 1 the access controller 110 of the data storage device (DSD) 100) to:
receive an input time-based code (Klapman: [0048]-[0051], [0053]-[0055], [071]-[0075], [0088], and FIG. 1 the input passcode at input component 102: The DSD 100 receives a passcode from user 101 (either by manual input via the input components 102, or electronically), including at least the input passcode provided by user device 120. In this embodiment, as shown in step 406, the received passcode is the input passcode generated synchronously by the DSDMA 300 of the user device 120 with the generation of the unlock passcode by the access controller 110 of the DSD 100. FIG. 6 illustrates a flow diagram for an input passcode generation routine 600 performed by the DSDMA 300 and invoked by user 101. At step 602, the user 101 configures the application 300 to manage the DSD 100, thereby enabling the generation of input passcode values for the device 100);
generate a generated time-based code from the time-based code series instance using (i) a current clock value from the access control device clock and (ii) the time-based code generation schedule (Klapman: [0037], [0051]-[0052], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Processor 111 receives a clocking signal from clock 112, which is processed to produce timestamp values representing instants in real-time. Processor 111 is configured to repeatedly and automatically generate a dynamically changing passcode (the “unlock passcode”), which is a time-varying code used for unlocking the data storage device 100, by processing the stored passcode generation key and reference time value. The reference time value is determined based on a time value obtained periodically from the clock 112 (i.e., to calculate a time differential, as described herein below). Processor 111 repeats the generation of a new passcode in response to a predefined time period value having expired, such as every 5 minutes, 30 minutes, 1 hour, 12 hours or any other time value. User device 120 is synchronized and therefore also generates new passcode at the same times);
compare the input time-based code with the generated time-based code (Klapman: Abstract, [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: The access controller 110 is configured to provide access to the user content data 109 in response to a match between the (first) received passcode entered into, or otherwise electronically provided to, the DSD 100 and the (second) passcode generated by the DSD 100, which are the input and unlock passcodes respectively in the described embodiments (i.e., as indicated in step 408). In some examples, a verification operation is performed by the access controller 110 to processes the unlock passcode and the input passcode. Processor 111 performs a comparison operation on the data representations of each code to check whether the input passcode matches with the unlock passcode);
determine that the input time-based code matches the generated time-based code (Klapman: Abstract, [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: The access controller 110 is configured to provide access to the user content data 109 in response to a match between the (first) received passcode entered into, or otherwise electronically provided to, the DSD 100 and the (second) passcode generated by the DSD 100, which are the input and unlock passcodes respectively in the described embodiments (i.e., as indicated in step 408). In some examples, a verification operation is performed by the access controller 110 to processes the unlock passcode and the input passcode. Processor 111 performs a comparison operation on the data representations of each code to check whether the input passcode matches with the unlock passcode); and
based on the match between the generated time-based code and the input time-based code, perform an action (Klapman: Abstract, [0005], [0054], [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: In response to the first passcode matching with a second passcode, the second passcode being generated by the access controller 110 and including at least the unlock passcode, the access controller 110 provides access to the user content data 109 via the data port 106. That is, in this case the user providing the input passcode is considered as an authorized user of the DSD 100);
wherein receiving an input time-based code comprises receiving an input time-based code (Klapman: [0037], [0051], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5) at least in part via at least one from the following list:
radio frequency identification (RFID);
Bluetooth;
near-field communication (NFC);
WiFi;
audio signal;
vibration pattern;
light pattern; and
temperature pattern (Klapman: [0037], [0048]-[0049], [0051], [0055], [0067], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Communications module 302 may implement one or more protocols for inter-device communication, such as for example Transmission Control Protocol (TCP) or Internet Protocol (IP) for the exchange of data over the Internet. The communications module 302 also provides functionality to enable direct communication between the DSDMA 300 and the one or more other devices (such as the DSD 100). For example, direct communication may occur wirelessly via Bluetooth, WiFi, or Near Field Communication (NFC) in order to synchronize the secret passcode generation key and the reference time value between the DSD 100 and the user device 120 executing the DSDMA 300. In other embodiments, the communications module 302 may support an exchange of data between the DSD 100 and the user device 120 over a physical connection, such as for example a USB connection between the I/O device interface 208 of the device 120 and the data port 106 of the DSD 100).
Therefore, in view of teachings by Ho and Klapman, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho to include the first time-based code series instance, as suggested by Klapman. The motivation for this is to implement a known alternative time-based code for authentication a user before providing access to the user.
While the combination of Ho and Klapman discloses a method/system for generating a time-based code series instance using seed value (Klapman: [0037], [0051], [0077]-[0078], and FIG. 4-5: the TOTP passcodes produced by generation routine 500 produces are a form of hash-based message authentication code (HMAC), where the source of uniqueness is typically a value generated from the current time and a unique seed number), the combination of Ho and Klapman does not explicitly disclose a shared seed code that is known to both the access management server and to the access control device.
However, it has been known in the art of security system to implement a shared seed code that is known to both the access management server and to the access control device, as suggested by Kamkar, which discloses a shared seed code that is known to both the access management server and to the access control device (Kamkar: Abstract, [0017], [0020]-[0022], [0036], and FIG. 1: In embodiments based on a random or pseudo-random number generator, the number generator of each resource access device 103 may be seeded with a different value. Based on the seed value and the current time, the number generator generates different rolling codes that form a dynamic part of the access identifiers (e.g., “˜/43234” or “˜/678asd”). … In some such embodiments, access control unit 107 may be configured with the same seed value as each resource access device 103. Access control unit 107 may use the seed values to synchronously generate the same rolling code and/or access identifier at the same time as each resource access device 103. In this manner, the generation (at 212 and 214) of access identifiers at each resource access device 103 and access control unit 107 may be synchronized without the devices having to exchange access identifier data with one another).
Therefore, in view of teachings by Ho, Klapman, and Kamkar, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho and Klapman to include a shared seed code that is known to both the access management server and to the access control device, as suggested by Kamkar. The motivation for this is to implement a known alternative time-based code for authentication a user before providing access to the user.
As to claim 2, Ho, Klapman, and Kamkar disclose the limitations of claim 1 further comprising the access control system of claim 1, further comprising: a code-check algorithm comprising at least one of the following: a second time-based code series instance; and a configuration code instance (Klapman: [0038], [0044]-[0045], [0050]-[0052], [0072]-[0073], [0092]-[0093], FIG. 1, and FIG. 4-6: Processor 111 receives a clocking signal from clock 112, which is processed to produce timestamp values representing instants in real-time. Processor 111 is configured to repeatedly and automatically generate a dynamically changing passcode (the “unlock passcode”), which is a time-varying code used for unlocking the data storage device 100, by processing the stored passcode generation key and reference time value. The reference time value is determined based on a time value obtained periodically from the clock 112 (i.e., to calculate a time differential, as described herein below). Processor 111 repeats the generation of a new passcode in response to a predefined time period value having expired, such as every 5 minutes, 30 minutes, 1 hour, 12 hours or any other time value. User device 120 is synchronized and therefore also generates new passcode at the same times).
As to claim 4, Ho, Klapman, and Kamkar disclose the limitations of claim 1 further comprising the access control system of claim 1, wherein receiving an input time-based code comprises receiving an input time-based code at least in part via Bluetooth (Ho: [0022]-[0024], [0027], [0045], [0051]-[0052], [0064], and FIG. 1-5: in other embodiments, the user device 310, for example, a mobile device or a hardware token of the user, may be configured to transmit the first factor authentication data to the electronic lock 210 without requiring any manual entry on the electronic lock 210. For example, the application server 160 may enable the user device 310 to transmit the first factor authentication data using 802.11 wireless standards, Bluetooth Low Energy (BLE), near field communication (NFC), or other suitable short-range or long-range wireless communication protocols. The electronic lock 210 includes a wireless transceiver for communicating with the user device 310. In some embodiments, where the first factor authentication data includes a fingerprint information or facial profile, the user may use a biometric-enabled user device 310 that will capture his fingerprint information or facial profile via a mobile application using a fingerprint sensor or front camera of the mobile device or through a mobile application on the user device. The fingerprint information or facial profile information of the user is then transmitted wirelessly to the application server 160 through the electronic lock 210 and Klapman: [0037], [0048]-[0049], [0051], [0055], [0067], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Communications module 302 may implement one or more protocols for inter-device communication, such as for example Transmission Control Protocol (TCP) or Internet Protocol (IP) for the exchange of data over the Internet. The communications module 302 also provides functionality to enable direct communication between the DSDMA 300 and the one or more other devices (such as the DSD 100). For example, direct communication may occur wirelessly via Bluetooth, WiFi, or Near Field Communication (NFC) in order to synchronize the secret passcode generation key and the reference time value between the DSD 100 and the user device 120 executing the DSDMA 300. In other embodiments, the communications module 302 may support an exchange of data between the DSD 100 and the user device 120 over a physical connection, such as for example a USB connection between the I/O device interface 208 of the device 120 and the data port 106 of the DSD 100).
As to claim 5, Ho, Klapman, and Kamkar disclose the limitations of claim 1 further comprising the access control system of claim 1, wherein receiving an input time-based code comprises receiving an input time-based code at least in part via NFC (Ho: [0022]-[0024], [0027], [0045], [0051]-[0052], [0064], and FIG. 1-5: in other embodiments, the user device 310, for example, a mobile device or a hardware token of the user, may be configured to transmit the first factor authentication data to the electronic lock 210 without requiring any manual entry on the electronic lock 210. For example, the application server 160 may enable the user device 310 to transmit the first factor authentication data using 802.11 wireless standards, Bluetooth Low Energy (BLE), near field communication (NFC), or other suitable short-range or long-range wireless communication protocols. The electronic lock 210 includes a wireless transceiver for communicating with the user device 310. In some embodiments, where the first factor authentication data includes a fingerprint information or facial profile, the user may use a biometric-enabled user device 310 that will capture his fingerprint information or facial profile via a mobile application using a fingerprint sensor or front camera of the mobile device or through a mobile application on the user device. The fingerprint information or facial profile information of the user is then transmitted wirelessly to the application server 160 through the electronic lock 210 and Klapman: [0037], [0048]-[0049], [0051], [0055], [0067], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Communications module 302 may implement one or more protocols for inter-device communication, such as for example Transmission Control Protocol (TCP) or Internet Protocol (IP) for the exchange of data over the Internet. The communications module 302 also provides functionality to enable direct communication between the DSDMA 300 and the one or more other devices (such as the DSD 100). For example, direct communication may occur wirelessly via Bluetooth, WiFi, or Near Field Communication (NFC) in order to synchronize the secret passcode generation key and the reference time value between the DSD 100 and the user device 120 executing the DSDMA 300. In other embodiments, the communications module 302 may support an exchange of data between the DSD 100 and the user device 120 over a physical connection, such as for example a USB connection between the I/O device interface 208 of the device 120 and the data port 106 of the DSD 100).
As to claim 6, Ho, Klapman, and Kamkar disclose the limitations of claim 1 further comprising the access control system of claim 1, wherein receiving an input time-based code comprises receiving an input time-based code at least in part via WiFi (Ho: [0022]-[0024], [0027], [0045], [0051]-[0052], [0064], and FIG. 1-5: in other embodiments, the user device 310, for example, a mobile device or a hardware token of the user, may be configured to transmit the first factor authentication data to the electronic lock 210 without requiring any manual entry on the electronic lock 210. For example, the application server 160 may enable the user device 310 to transmit the first factor authentication data using 802.11 wireless standards, Bluetooth Low Energy (BLE), near field communication (NFC), or other suitable short-range or long-range wireless communication protocols. The electronic lock 210 includes a wireless transceiver for communicating with the user device 310. In some embodiments, where the first factor authentication data includes a fingerprint information or facial profile, the user may use a biometric-enabled user device 310 that will capture his fingerprint information or facial profile via a mobile application using a fingerprint sensor or front camera of the mobile device or through a mobile application on the user device. The fingerprint information or facial profile information of the user is then transmitted wirelessly to the application server 160 through the electronic lock 210 and Klapman: [0037], [0048]-[0049], [0051], [0055], [0067], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Communications module 302 may implement one or more protocols for inter-device communication, such as for example Transmission Control Protocol (TCP) or Internet Protocol (IP) for the exchange of data over the Internet. The communications module 302 also provides functionality to enable direct communication between the DSDMA 300 and the one or more other devices (such as the DSD 100). For example, direct communication may occur wirelessly via Bluetooth, WiFi, or Near Field Communication (NFC) in order to synchronize the secret passcode generation key and the reference time value between the DSD 100 and the user device 120 executing the DSDMA 300. In other embodiments, the communications module 302 may support an exchange of data between the DSD 100 and the user device 120 over a physical connection, such as for example a USB connection between the I/O device interface 208 of the device 120 and the data port 106 of the DSD 100).
As to claim 13, Ho, Klapman, and Kamkar discloses the limitations of claim 1 further comprising the access control system of claim 1, wherein performing an action comprises granting access to a resource (Ho: [0017], [0048], [0052], [0060]-[0071], [0073]-[0078], and FIG. 4-5 the electronic lock 210: If the second factor authentication data received from the user matches the second factor authentication data stored on the lock user database 161, the application server 160 will send a positive signal to the electronic lock which will cause the electronic lock to release its locking mechanism at step 426 to allow entry to the entry point, Klapman: Abstract, [0005], [0054], [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: In response to the first passcode matching with a second passcode, the second passcode being generated by the access controller 110 and including at least the unlock passcode, the access controller 110 provides access to the user content data 109 via the data port 106. That is, in this case the user providing the input passcode is considered as an authorized user of the DSD 100, and Kamkar: Abstract, [0024]-[0025], [0061], [0073], and FIG. 1-3: Access control unit 107 may determine if visitor UE 101 is authorized to access secured resource 105 based on the received visitor access code and/or the access identifier used by visitor UE 101 to access the dynamic interface. In response to successfully authorizing visitor UE 101 to access secured resource 105, access control unit 107 may issue (at 422) a command or signaling to secured resource 105. In response to the issued (at 422) command or signaling, secured resource 105 may provide (at 424) access or otherwise change state).
As to claim 15, Ho, Klapman, and Kamkar disclose the limitations of claim 1 further comprising the access control system of claim 1, wherein the first time-based code series instance is associated with a first user (Ho: Abstract, [0010], [0046], [0052]-[0055], [0068]-[0071], and FIG. 4-5: When the access right owner or the access right grantee is provisioned for right of entry and exit via the associated electronic lock identified by an associated lock ID, the administrator will capture the personal details of the access right owner and the access right grantees, which may include names, addresses, contact numbers, user device numbers, user device serial number or identification numbers, and/or biometric signatures that can be used for authentication of the first factor authentication or second factor authentication, Klapman: [0070], and FIG. 1: the data store 304 is implemented as a series of data tables forming a relational database accessible via a database management system (DBMS) submodule of the store 304. A user table is defined to store the user information including, in relation to user 101: a user ID key (UID) uniquely identifying the user 101 among all users of the DSDMA 300; a user account identifier (UAC) of an application account of user 101 for operation of the DSDMA 300; and personal details of the user 101 including a name, address, and phone number. The account identifier maps to a corresponding entry in a user account table containing information for the user 101 to authenticate themselves with the DSDMA 300, such as for example, user password data and recovery information (e.g., a secret question and answer combination). The data store 304 may store particular data in a secure form, such as for example by applying a cryptographic primitive (e.g., the SHA-1 hash function) to the values prior to their entry into the database, and Kamkar: [0014], [0027], [0073], [0088]-[0089], [0099], and FIG. 1-3: Access control unit 107 may authorize (at 122) visitor UE 101 access to secured resource 105 based on the data transmitted (at 120) by visitor UE 101 and/or the access identifier of the dynamic interface. In some embodiments, access control unit 107 may authorize (at 122) access by determining that access is requested for secured resource 105 based on the access identifier (e.g., the fixed first portion or the changing second portion of the URI) used to access the dynamic interface, determining that the dynamic interface is valid or was valid when accessed by visitor UE 101 (e.g., the authorization occurs within an expiration time of providing the dynamic interface to visitor UE 101), and comparing the transmitted visitor access code or login credentials against a list of valid visitor access codes or authorized users. Authorizing (at 122) may further include validating access according to any restrictions that are defined for the valid visitor code or authorized user).
As to claim 16, Ho, Klapman, and Kamkar disclose the limitations of claim 2 further comprising the access control system of claim 2, wherein:
the code-check algorithm comprises a second time-based code series instance (Ho: [0045]-[0046], [0052]-[0055], [0063], [0066]-[0071], and FIG. 4-5: Upon receipt of the first factor authentication data by the electronic lock 210, the electronic lock 210 which is arranged in wireless communication with the application server will transmit the first factor authentication data, or its equivalent in a hash format, to the application server 160. At step 412, the application server 160 will validate the first factor authentication data with the first factor authentication data associated with the user and permission levels stored in the lock user database 161. The application server 160 will also check the permission levels associated with the user, for example, available date and times, unavailable dates and times, or other limits…The application server 160 will also check the permission levels associated with the user, for example, available date and times, unavailable dates and times, or other limits. The limits may be based on the specific roles and permission levels registered by the administrator or the access right owner on the role management module 110, user management module 112, lock management module 114 and grant access module 116. At step 424, if the second factor authentication data received by the user does not match the second factor authentication data generated by the server, the application server 160 may return an error message in response to the failed authentication, and the user will be requested to input the second factor authentication data again);
the second time-based code series instance (Ho: [0044]-[0045], [0052], [0068]-[0071], and FIG. 4-5, Klapman: [0037], [0051], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5) comprises:
a second shared seed code (Klapman: [0037], [0051], [0077]-[0078], and FIG. 4-5: the TOTP passcodes produced by generation routine 500 produces are a form of hash-based message authentication code (HMAC), where the source of uniqueness is typically a value generated from the current time and a unique seed number) that is known to both the access management server and to the access control device (Kamkar: Abstract, [0017], [0020]-[0022], [0036], and FIG. 1: In embodiments based on a random or pseudo-random number generator, the number generator of each resource access device 103 may be seeded with a different value. Based on the seed value and the current time, the number generator generates different rolling codes that form a dynamic part of the access identifiers (e.g., “˜/43234” or “˜/678asd”). … In some such embodiments, access control unit 107 may be configured with the same seed value as each resource access device 103. Access control unit 107 may use the seed values to synchronously generate the same rolling code and/or access identifier at the same time as each resource access device 103. In this manner, the generation (at 212 and 214) of access identifiers at each resource access device 103 and access control unit 107 may be synchronized without the devices having to exchange access identifier data with one another);
a second time-based code generation algorithm that is known to both the access management server and to the access control device (Klapman: Abstract, [0023]: wherein the input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the data storage device; and provide access to the user content data via a data port of the data storage device in response to the first passcode matching with a second passcode generated by the data storage device, wherein the second passcode includes at least the unlock passcode, [0034]: the second passcode generated by the DSD 100 includes only the dynamically changing unlock passcode that is matched to a corresponding “input” passcode constituting the received first passcode. The input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the access controller, [0037]-[0038]: the user device 120 determines the input passcode, to be entered by the user into the DSD, by retrieving the input passcode or a seed value to generate the input passcode from a remote location, such as a passcode server, [0075]);
a second access control device clock that is synchronized to a second access management server clock (Klapman: Abstract, [0023]: wherein the input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the data storage device; and provide access to the user content data via a data port of the data storage device in response to the first passcode matching with a second passcode generated by the data storage device, wherein the second passcode includes at least the unlock passcode, [0034]: the second passcode generated by the DSD 100 includes only the dynamically changing unlock passcode that is matched to a corresponding “input” passcode constituting the received first passcode. The input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the access controller, [0037]-[0038]: the user device 120 determines the input passcode, to be entered by the user into the DSD, by retrieving the input passcode or a seed value to generate the input passcode from a remote location, such as a passcode server, [0048], [0052], [0055], [0073], [0075], [0120], and FIG. 1: a synchronization data message enabling synchronization of the reference time value T.sub.ref for the device 100 and the other user's DSDMA; and any other parameter data required for the other user's DSDMA to compute unlock codes for the device 100. The synchronization data message can include a reference time relative to a common clock, and established via a distributed time synchronization protocol (e.g., the Network Time Protocol (NTP))); and
a second time-based code generation schedule that is known to both the access management server and to the access control device (Klapman: [0038], [0050]-[0052], [0072]-[0073], [0092]-[0093], FIG. 1, and FIG. 6: Processor 111 repeats the generation of a new passcode in response to a predefined time period value having expired, such as every 5 minutes, 30 minutes, 1 hour, 12 hours or any other time value. User device 120 is synchronized and therefore also generates new passcode at the same times),
wherein (i) the second time-based code generation schedule comprises a set of time periods wherein each time period is associated with a clock begin value and a clock end value (which could be the same); and (ii) the set of time periods may be based on an algorithm for generating time periods based on an input clock value (Klapman: [0037], [0051]-[0052], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Processor 111 receives a clocking signal from clock 112, which is processed to produce timestamp values representing instants in real-time. Processor 111 is configured to repeatedly and automatically generate a dynamically changing passcode (the “unlock passcode”), which is a time-varying code used for unlocking the data storage device 100, by processing the stored passcode generation key and reference time value. The reference time value is determined based on a time value obtained periodically from the clock 112 (i.e., to calculate a time differential, as described herein below). Processor 111 repeats the generation of a new passcode in response to a predefined time period value having expired, such as every 5 minutes, 30 minutes, 1 hour, 12 hours or any other time value. User device 120 is synchronized and therefore also generates new passcode at the same times); and
the non-transitory computer executable instructions stored at the access control device further comprise instructions that, when executed, cause the access control device (Klapman: FIG. 1 the access controller 110 of the data storage device (DSD) 100) to:
receive an input time-based code (Ho: [0044]-[0045], [0052], [0054]-[0055], [0068]-[0072], and FIG. 4-5: Upon receipt of the second factor authentication data by the electronic lock 210, the electronic lock, which is arranged in wireless communication with the application server, will transmit the second factor authentication data to the application server 160. At step 422, the application server 160 will validate the second factor authentication data with the second factor authentication data associated with the user and permission levels stored in the lock user database 161 and Klapman: [0048]-[0051], [0053]-[0055], [071]-[0075], [0088], and FIG. 1 the input passcode at input component 102: The DSD 100 receives a passcode from user 101 (either by manual input via the input components 102, or electronically), including at least the input passcode provided by user device 120. In this embodiment, as shown in step 406, the received passcode is the input passcode generated synchronously by the DSDMA 300 of the user device 120 with the generation of the unlock passcode by the access controller 110 of the DSD 100. FIG. 6 illustrates a flow diagram for an input passcode generation routine 600 performed by the DSDMA 300 and invoked by user 101. At step 602, the user 101 configures the application 300 to manage the DSD 100, thereby enabling the generation of input passcode values for the device 100);
generate a generated time-based code from the time-based code series instance using (i) a current clock value from the access control device clock and (ii) the time-based code generation schedule (Klapman: [0037], [0051]-[0052], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Processor 111 receives a clocking signal from clock 112, which is processed to produce timestamp values representing instants in real-time. Processor 111 is configured to repeatedly and automatically generate a dynamically changing passcode (the “unlock passcode”), which is a time-varying code used for unlocking the data storage device 100, by processing the stored passcode generation key and reference time value. The reference time value is determined based on a time value obtained periodically from the clock 112 (i.e., to calculate a time differential, as described herein below). Processor 111 repeats the generation of a new passcode in response to a predefined time period value having expired, such as every 5 minutes, 30 minutes, 1 hour, 12 hours or any other time value. User device 120 is synchronized and therefore also generates new passcode at the same times);
compare the input time-based code with the generated time-based code (Klapman: Abstract, [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: The access controller 110 is configured to provide access to the user content data 109 in response to a match between the (first) received passcode entered into, or otherwise electronically provided to, the DSD 100 and the (second) passcode generated by the DSD 100, which are the input and unlock passcodes respectively in the described embodiments (i.e., as indicated in step 408). In some examples, a verification operation is performed by the access controller 110 to processes the unlock passcode and the input passcode. Processor 111 performs a comparison operation on the data representations of each code to check whether the input passcode matches with the unlock passcode);
determine that the input time-based code does not match the generated time-based code (Klapman: Abstract, [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: The access controller 110 is configured to provide access to the user content data 109 in response to a match between the (first) received passcode entered into, or otherwise electronically provided to, the DSD 100 and the (second) passcode generated by the DSD 100, which are the input and unlock passcodes respectively in the described embodiments (i.e., as indicated in step 408). In some examples, a verification operation is performed by the access controller 110 to processes the unlock passcode and the input passcode. Processor 111 performs a comparison operation on the data representations of each code to check whether the input passcode matches with the unlock passcode);
compare the input time-based code with a second generated time-based code generated from the second time-based code series instance (Klapman: Abstract, [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: The access controller 110 is configured to provide access to the user content data 109 in response to a match between the (first) received passcode entered into, or otherwise electronically provided to, the DSD 100 and the (second) passcode generated by the DSD 100, which are the input and unlock passcodes respectively in the described embodiments (i.e., as indicated in step 408). In some examples, a verification operation is performed by the access controller 110 to processes the unlock passcode and the input passcode. Processor 111 performs a comparison operation on the data representations of each code to check whether the input passcode matches with the unlock passcode) using (i) a current clock value from the second access control device clock and (ii) the second time-based code generation schedule (Klapman: [0037], [0051]-[0052], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5: Processor 111 receives a clocking signal from clock 112, which is processed to produce timestamp values representing instants in real-time. Processor 111 is configured to repeatedly and automatically generate a dynamically changing passcode (the “unlock passcode”), which is a time-varying code used for unlocking the data storage device 100, by processing the stored passcode generation key and reference time value. The reference time value is determined based on a time value obtained periodically from the clock 112 (i.e., to calculate a time differential, as described herein below). Processor 111 repeats the generation of a new passcode in response to a predefined time period value having expired, such as every 5 minutes, 30 minutes, 1 hour, 12 hours or any other time value. User device 120 is synchronized and therefore also generates new passcode at the same times); and
based on the match between the second generated time-based code and the input time-based code, perform a second action (Ho: [0017], [0048], [0052], [0060]-[0071], [0073]-[0078], and FIG. 4-5 the electronic lock 210: If the second factor authentication data received from the user matches the second factor authentication data stored on the lock user database 161, the application server 160 will send a positive signal to the electronic lock which will cause the electronic lock to release its locking mechanism at step 426 to allow entry to the entry point and Klapman: Abstract, [0005], [0054], [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: In response to the first passcode matching with a second passcode, the second passcode being generated by the access controller 110 and including at least the unlock passcode, the access controller 110 provides access to the user content data 109 via the data port 106. That is, in this case the user providing the input passcode is considered as an authorized user of the DSD 100 ).
As to claim 17, Ho, Klapman, and Kamkar discloses the limitations of claim 15 further comprising the access control system of claim 15, wherein performing a second action comprises granting access to a resource (Ho: [0017], [0048], [0052], [0060]-[0071], [0073]-[0078], and FIG. 4-5 the electronic lock 210: If the second factor authentication data received from the user matches the second factor authentication data stored on the lock user database 161, the application server 160 will send a positive signal to the electronic lock which will cause the electronic lock to release its locking mechanism at step 426 to allow entry to the entry point ).
As to claim 19, Ho, Klapman, and Kamkar discloses the limitations of claim 15 further comprising the access control system of claim 15, wherein the second time-based code series instance is associated with a second user (Ho: Abstract, [0010], [0046], [0052]-[0055], [0068]-[0071], and FIG. 4-5: When the access right owner or the access right grantee is provisioned for right of entry and exit via the associated electronic lock identified by an associated lock ID, the administrator will capture the personal details of the access right owner and the access right grantees, which may include names, addresses, contact numbers, user device numbers, user device serial number or identification numbers, and/or biometric signatures that can be used for authentication of the first factor authentication or second factor authentication).
As to claim 20, Ho, Klapman, and Kamkar disclose the limitations of claim 1 further comprising the access control system of claim 1, wherein:
the code-check algorithm comprises a configuration code instance (Ho: [0044]-[0045], [0052], [0068]-[0071], and FIG. 4-5 and Klapman: [0037], [0051], [0072]-[0073], [0076], [0078]-[0079], and FIG. 4-5);
the configuration code instance comprises:
a configuration code known by the access control device (Ho: [0017], [0048], [0052], [0060]-[0071], [0073]-[0078], and FIG. 4-5 the electronic lock 210: If the second factor authentication data received from the user matches the second factor authentication data stored on the lock user database 161, the application server 160 will send a positive signal to the electronic lock which will cause the electronic lock to release its locking mechanism at step 426 to allow entry to the entry point and Klapman: Abstract, [0023]: wherein the input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the data storage device; and provide access to the user content data via a data port of the data storage device in response to the first passcode matching with a second passcode generated by the data storage device, wherein the second passcode includes at least the unlock passcode, [0034]: the second passcode generated by the DSD 100 includes only the dynamically changing unlock passcode that is matched to a corresponding “input” passcode constituting the received first passcode. The input passcode is generated externally to the data storage device and synchronously with the generation of the unlock passcode by the access controller, [0037]-[0038]: the user device 120 determines the input passcode, to be entered by the user into the DSD, by retrieving the input passcode or a seed value to generate the input passcode from a remote location, such as a passcode server, [0075]);
non-transitory computer executable instructions that are stored at the access control device and that, when executed, cause the access control device (Ho: [0037], [0048], [0079]-[0080], and FIG. 5) to:
receive an input code (Ho: [0044]-[0045], [0052], [0054]-[0055], [0068]-[0072], and FIG. 4-5: Upon receipt of the second factor authentication data by the electronic lock 210, the electronic lock, which is arranged in wireless communication with the application server, will transmit the second factor authentication data to the application server 160. At step 422, the application server 160 will validate the second factor authentication data with the second factor authentication data associated with the user and permission levels stored in the lock user database 161 and Klapman: [0048]-[0051], [0053]-[0055], [071]-[0075], [0088], and FIG. 1 the input passcode at input component 102: The DSD 100 receives a passcode from user 101 (either by manual input via the input components 102, or electronically), including at least the input passcode provided by user device 120. In this embodiment, as shown in step 406, the received passcode is the input passcode generated synchronously by the DSDMA 300 of the user device 120 with the generation of the unlock passcode by the access controller 110 of the DSD 100. FIG. 6 illustrates a flow diagram for an input passcode generation routine 600 performed by the DSDMA 300 and invoked by user 101. At step 602, the user 101 configures the application 300 to manage the DSD 100, thereby enabling the generation of input passcode values for the device 100);
compare the input code to the configuration code (Klapman: Abstract, [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: The access controller 110 is configured to provide access to the user content data 109 in response to a match between the (first) received passcode entered into, or otherwise electronically provided to, the DSD 100 and the (second) passcode generated by the DSD 100, which are the input and unlock passcodes respectively in the described embodiments (i.e., as indicated in step 408). In some examples, a verification operation is performed by the access controller 110 to processes the unlock passcode and the input passcode. Processor 111 performs a comparison operation on the data representations of each code to check whether the input passcode matches with the unlock passcode);
based on a determination that the input code matches the configuration code, perform a configuration action (Ho: [0017], [0048], [0052], [0060]-[0071], [0073]-[0078], and FIG. 4-5 the electronic lock 210: If the second factor authentication data received from the user matches the second factor authentication data stored on the lock user database 161, the application server 160 will send a positive signal to the electronic lock which will cause the electronic lock to release its locking mechanism at step 426 to allow entry to the entry point and Klapman: Abstract, [0005], [0054], [0125]-[0126], [0128], [0131], FIG. 1, and FIG. 4-5: In response to the first passcode matching with a second passcode, the second passcode being generated by the access controller 110 and including at least the unlock passcode, the access controller 110 provides access to the user content data 109 via the data port 106. That is, in this case the user providing the input passcode is considered as an authorized user of the DSD 100).
Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. (Ho – US 2021/0319639 A1) in view of Klapman et al. (Klapman – US 2022/0414205 A1) and Kamkar et al. (Kamkar – US 2021/0360403 A1) and further in view of Sachdeva et al. (Sachdeva – US 2024/0096155 A1).
As to claim 3, Ho, Klapman, and Kamkar disclose the limitations of claim 1 except for the claimed limitations of the access control system of claim 1, wherein receiving an input time-based code comprises receiving an input time-based code at least in part via RFID .
However, it has been known in the art of electronic lock controls to implement wherein receiving an input time-based code comprises receiving an input time-based code at least in part via RFID, as suggested by Sachdeva, which discloses wherein receiving an input time-based code comprises receiving an input time-based code at least in part via RFID (Sachdeva: Abstract, [0047], and FIG. 1: The access control device 110 forms part of access control systems (PACS) which can include a reader (e.g., an online or offline reader) that holds authorization data and can be capable of determining whether credentials (e.g., from credential or key devices such as radio frequency identification (RFID) chips in cards, fobs, or personal electronic devices such as mobile phones) are authorized for an actuator or control mechanism (e.g., door lock, door opener, software control mechanism, turning off an alarm, etc.), or PACS can include a host server to which readers and actuators are connected (e.g., via a controller) in a centrally managed configuration. In centrally managed configurations, readers can obtain credentials from credential or key devices and pass those credentials to the PACS host server. The host server then determines whether the credentials authorize access to the secure area or secure asset and commands the actuator or other control mechanism accordingly).
Therefore, in view of teachings by Ho, Klapman, Kamkar, and Sachdeva it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho, Klapman, and Kamkar to include wherein receiving an input time-based code comprises receiving an input time-based code at least in part via RFID, as suggested by Sachdeva. The motivation for this is to selectively control a security access device based on a credential from an RFID device.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. (Ho – US 2021/0319639 A1) in view of Klapman et al. (Klapman – US 2022/0414205 A1) and Kamkar et al. (Kamkar – US 2021/0360403 A1) and further in view of Mensah et al. (Mensah – US 2021/0217438 A1).
As to claim 7, Ho, Klapman, and Kamkar disclose the limitations of claim 1 except for the claimed limitations of the access control system of claim 1, wherein receiving an input time-based code comprises receiving an input time-based code at least in part via audio signal.
However, it has been known in the art of electronic lock controls to implement wherein receiving an input time-based code comprises receiving an input time-based code at least in part via audio signal, as suggested by Mensah, which discloses wherein receiving an input time-based code comprises receiving an input time-based code at least in part via audio signal (Mensah: Abstract, [0004]-[0005], [0092]-[0101], [0104]-[0110], and FIG. 1-3: Briefly, process 300 includes receiving, from a proximity sensor that is located at a door of a property, proximity data indicating an object positioned within a set proximity to the door (302), based on receiving the proximity data indicating the object positioned within the set proximity to the door, activating a microphone at the door (304), receiving, from the microphone, audio data (306), determining that a similarity between the audio data and stored audio data representing a knocking pattern satisfies similarity criteria (308), and in response to on determining that the similarity between the audio data and the stored audio data satisfies similarity criteria, performing a monitoring system action (310)).
Therefore, in view of teachings by Ho, Klapman, Kamkar, and Mensah it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho, Klapman, and Kamkar to include wherein receiving an input time-based code comprises receiving an input time-based code at least in part via audio signal, as suggested by Mensah. The motivation for this is to selectively control a security access device based on audio patterns as a known alternative data for locking/unlocking operations of the security access device.
Claims 8-9 are rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. (Ho – US 2021/0319639 A1) in view of Klapman et al. (Klapman – US 2022/0414205 A1) and Kamkar et al. (Kamkar – US 2021/0360403 A1) and further in view of Johnson et al. (Johnson – US 2018/0135337 A1).
As to claim 8, Ho, Klapman, and Kamkar disclose the limitations of claim 1 except for the claimed limitations of the access control system of claim 1, wherein receiving an input time-based code comprises receiving an input time-based code at least in part via vibration pattern.
However, it has been known in the art of electronic lock controls to implement wherein receiving an input time-based code comprises receiving an input time-based code at least in part via vibration pattern, as suggested by Johnson, which discloses wherein receiving an input time-based code comprises receiving an input time-based code at least in part via vibration pattern (Johnson: Abstract, [0100]-[0102], [0105]-[0106], [0108], [0342], and FIG. 1: the vibration/tapping sensing device detects vibration or knocking applied to a door that is used to unlock or lock the intelligent door lock system 10. This occurs following programming the intelligent door lock system 10. The programming includes a user's vibration code/pattern, and the like. Additionally, a dwelling user, resource owner, or end-user, resource owner, or end-user can give a third person a knock code/pattern to unlock the intelligent door lock system of the door. The knocking is one that is recognized as having been defined by a user of the door lock system as a means to unlock the door. The knocking can have a variety of different patterns, tempos, duration, intensity and the like).
Therefore, in view of teachings by Ho, Klapman, Kamkar, and Johnson it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho, Klapman, and Kamkar to include wherein receiving an input time-based code comprises receiving an input time-based code at least in part via vibration pattern, as suggested by Johnson. The motivation for this is to selectively control a security access device based on vibration patterns.
As to claim 9, Ho, Klapman, Kamkar, and Johnson disclose the limitations of claim 8 further comprising the access control system of claim 8, wherein the vibration pattern is produced by a smartphone vibration functionality (Johnson: Abstract, [0100]-[0102], [0105]-[0106], [0108], [0342], and FIG. 1: Referring to FIG. 1(a) in one embodiment the door lock system 10 includes a vibration/tapping sensing device 11 configured to be coupled intelligent lock system 10. In one embodiment the intelligent door lock system 10 is in communication with a mobile device that includes a vibration/taping sensing device to lock or unlock a door associated with the intelligent door lock system 10).
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. (Ho – US 2021/0319639 A1) in view of Klapman et al. (Klapman – US 2022/0414205 A1) and Kamkar et al. (Kamkar – US 2021/0360403 A1) and further in view of Lin et al. (Lin – US 2016/0314634 A1).
As to claim 10, Ho, Klapman, and Kamkar disclose the limitations of claim 1 except for the claimed limitations of the access control system of claim 1, wherein receiving an input time-based code comprises receiving an input time-based code at least in part via light pattern.
However, it has been known in the art of electronic lock controls to implement wherein receiving an input time-based code comprises receiving an input time-based code at least in part via light pattern, as suggested by Lin, which discloses wherein receiving an input time-based code comprises receiving an input time-based code at least in part via light pattern (Lin: Abstract, [0009]-[0012], [0017]-[0018], and FIG. 1 the light source module 120: The identifying member 222 can compare the electrical signal received from the optical signal conversion controller 210 with the signal sample and send a controlling signal to the unlock module 230 if the comparison reveals the correct ID information…The unlock module 230 can be electrically coupled to the signal receiving module 220 and can be configured to lock or unlock the vehicle).
Therefore, in view of teachings by Ho, Klapman, Kamkar, and Lin it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho, Klapman, and Kamkar to include wherein receiving an input time-based code comprises receiving an input time-based code at least in part via light pattern, as suggested by Lin. The motivation for this is to selectively control a security access device based on optical patterns.
Claims 11 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. (Ho – US 2021/0319639 A1) in view of Klapman et al. (Klapman – US 2022/0414205 A1) and Kamkar et al. (Kamkar – US 2021/0360403 A1) and further in view of Bhagat (Bhagat – US 2022/0182784 A1).
As to claim 11, Ho, Klapman, and Kamkar disclose the limitations of claim 1 except for the claimed limitations of the access control system of claim 1, wherein receiving the light pattern is produced by a smartphone flash light.
However, it has been known in the art of identification code generation to implement wherein receiving the light pattern is produced by a smartphone flash light, as suggested by Bhagat, which discloses wherein receiving the light pattern is produced by a smartphone flash light (Bhagat: Abstract, [0068]-[0070], [0079]-[0082], [0096], FIG. 1 and FIG. 8-9: Embodiments may provide location information as a service to the end user with the accuracy of few centimeters, by using fusion of sensing data provided by different sensor modalities while ensuring the detection and verification of the object identity, for example, by using the mobile phone flash light blink code, vehicle headlight blink code, and other similar user generated feedback mechanisms to be detected by the sensors including but not limited to lidar, radar, and camera described above).
Therefore, in view of teachings by Ho, Klapman, Kamkar, and Bhagat it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho, Klapman, and Kamkar to include wherein receiving the light pattern is produced by a smartphone flash light, as suggested by Bhagat. The motivation for this is to implement a known alternative method for generating a signal code using a smartphone flash light.
As to claim 14, Ho, Klapman, Kamkar, and Bhagat discloses the limitations of claim 11 further comprising the access control system of claim 11, wherein granting access to a resource comprises granting access to the resource for a period of time (Ho: [0066], [0071], and FIG. 4: The application server 160 will also check the permission levels associated with the user, for example, available date and times, unavailable dates and times, or other limits. The limits may be based on the specific roles and permission levels registered by the administrator or the access right owner on the role management module 110, user management module 112, lock management module 114 and grant access module 116. At step 424, if the second factor authentication data received by the user does not match the second factor authentication data generated by the server, the application server 160 may return an error message in response to the failed authentication, and the user will be requested to input the second factor authentication data again and Kamkar: Abstract, [0061], [0073], [0079]-[0080], [0082], [0098], FIG. 1-3, and FIG. 6: As shown in FIG. 6, the simplified dynamic interface may include virtual button 601 for requesting access to secured resource 105. The simplified dynamic interface, and more specifically, the current access identifier used to access the simplified dynamic interface may remain valid for a specified period of time (e.g., 5 seconds). After the specified period of time, the URI or current access identifier of the simplified dynamic interface for accessing secured resource 105 may be changed, and the simplified dynamic interface that is accessed prior to the access identifier changing may no longer be used to request and/or gain access to secured resource 105).
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. (Ho – US 2021/0319639 A1) in view of Klapman et al. (Klapman – US 2022/0414205 A1) and Kamkar et al. (Kamkar – US 2021/0360403 A1) and further in view of Song (Song – US 2009/0326843 A1).
As to claim 12, Ho, Klapman, and Kamkar disclose the limitations of claim 1 except for the claimed limitations of the access control system of claim 1, wherein receiving an input time-based code comprises receiving an input time-based code at least in part via temperature pattern.
However, it has been known in the art of identification code generation to implement wherein receiving an input time-based code comprises receiving an input time-based code at least in part via temperature pattern, as suggested by Song, which discloses wherein receiving an input time-based code comprises receiving an input time-based code at least in part via temperature pattern (Song: Abstract, [0022], [0043], [0047]-[0048], [0051]-[0052], FIG. 1 and FIG. 9: An apparatus for detecting temperature/voltage variations of a semiconductor integrated circuit includes an oscillator configured to generate an oscillation signal whose frequency is varied according to temperature/voltage variations, and a code generator configured to generate a code signal using the oscillation signal, wherein the code signal is used as a criterion for detecting the temperature/voltage variations in a circuit construction exterior of the apparatus for detecting the temperature/voltage variations).
Therefore, in view of teachings by Ho, Klapman, Kamkar, and Song it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho, Klapman, and Kamkar to include wherein receiving an input time-based code comprises receiving an input time-based code at least in part via temperature pattern, as suggested by Song. The motivation for this is to implement a known alternative method for generating a signal code based on temperature pattern/variation.
Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Ho et al. (Ho – US 2021/0319639 A1) in view of Klapman et al. (Klapman – US 2022/0414205 A1) and Kamkar et al. (Kamkar – US 2021/0360403 A1) and further in view of Davis et al. (Davis – US 2014/0068247 A1).
As to claim 18, Ho, Klapman, and Kamkar disclose the limitations of claim 15 except for the claimed limitations of the access control system of claim 15, wherein performing a second action comprises granting access to a resource for a second period of time that is different from the first period of time.
However, it has been known in the art of security locks to implement wherein performing a second action comprises granting access to a resource for a second period of time that is different from the first period of time, as suggested by Davis, which discloses wherein performing a second action comprises granting access to a resource for a second period of time that is different from the first period of time (Davis: Abstract, [0018], [0024], [0042]-[0048], [0053]-[0054], FIG. 2-3 and FIG. 7: The security locking device may generate multiple security access codes and the control server may generate multiple candidate access codes. A user who desires to open a security locking device may be assigned a candidate access code that is valid for a specific period of time. When the candidate access code is provided to the security access device by the user or delivery agent during a time period when the candidate access code is valid, then the security locking device may open… the security locking device may generate a new code for the 1 hour time interval 10 every hour at a specific time hourly epoch defined in advance. A time the new security access code may be generated is, for instance, on the hour every hour or at fifteen minutes after the hour, every hour. Similarly, for a 24 hour code 320, a new code may be generated each day at 12:00 midnight or at another selected time during each 24 hour period).
Therefore, in view of teachings by Ho, Klapman, Kamkar, and Davis, it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention to implement in the security system of Ho, Klapman, and Kamkar to include wherein performing a second action comprises granting access to a resource for a second period of time that is different from the first period of time, as suggested by Davis. The motivation for this is to selectively control a security access device based on setting periods.
Citation of Pertinent Art
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure:
Noce, US 2024/0106662 A1, discloses user credentials protecting from swapping attacks.
Moros Ortiz et al., US 2021/0271779 A1, discloses thermal imaging protection.
Weyer, US 2021/0007327 A1, discloses smart delivery treatment apparatus for remote treatment of an animal.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to QUANG PHAM whose telephone number is (571)-270-3668. The examiner can normally be reached 09:00 AM - 05:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, QUAN-ZHEN WANG can be reached at (571)-272-3114. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/QUANG PHAM/Primary Examiner, Art Unit 2685