Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1-30 remain for examination. Applicant's arguments filed on 07/13/2026 have been fully considered but they are not persuasive. The rejections are maintained and incorporated by reference the last Office action on 05/28/2026. Accordingly, this action has been made final.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-30 are rejected under 35 U.S.C. 103 as being unpatentable over Durairaj (US 20240039873 A1) in view of Hallock US 20210352471 A1.
As to claim 1, Durairaj teaches a system for providing a simulated including access to secure online content, the system comprising (Durairaj Pa. [0095]) [user interfaces and be configured to access a variety of local resources (e.g., a calendar or contact information on the customer device) or remote resources]: an artificial intelligence (AI) controlled agent (Durairaj Pa. [0062]) [Referring now to FIG. 1, a system 100 for co-browsing by chat bots by leveraging artificial intelligence (AI) and asynchronous session handling is shown”, “AI-powered bots to handle co-browse sessions] [0068] [an executable program that can be launched according to demand for the particular chat bot (e.g., by a cloud-based system]; a cloud browser (Durairaj Pa. [0070]) [The system 100 may retrieve and execute a co-browse script 108] [0134] [one or more cloud-based systems. In cloud-based embodiments, the cloud-based system may be embodied as a server-ambiguous computing solution, for example, that executes a plurality of instructions on-demand, contains logic to execute instructions only when prompted by a particular activity/trigger]; and a processor configured to (Durairaj Pa. [0123]) [one or more processors executing computer program instructions and interacting with other system components for performing the various functionalities described herein]: receive, from a first client device associated with a validated user entity (Durairaj Pa. [0070]) [when there is a matching user intent determined by the intent classification API 106 and the user has authorized a co-browsing session for assistance (e.g., completing a web-based form], a request to initiate a secure browsing session (Durairaj Pa. [0070]) [AI-powered bots to handle co-browse sessions]; execute the request, using the cloud browser (Durairaj Pa. [0070]) [the chat bot may request the data directly from the user during the co-browse session], wherein the cloud browser is able to engage in a simulated browsing session within content that has a payload (Durairaj Pa. [0068]) [the chat bot simulates and processes human conversation (either written or spoken), allowing humans to interact with digital devices as if the humans were communicating with another human.] or involves a bot-detection process relating to access to the secure online content using validation data provided by the first client device or another authorization source (Durairaj Pa. [0101]) [The analytics module 250 also may have access to the interaction database, which stores data related to interactions and interaction content (e.g., transcripts of the interactions and events detected therein)]; grant the AI controlled agent navigational control over the cloud browser, thus enabling the AI controlled agent to have access to the secure online content on a post-payload or a post-bot-detection basis via the cloud browser (Durairaj Pa. [0153]) [the system 100 may allow the user to opt to transfer an interaction or co-browse session between the user and chat bot to a human agent at any point during the interaction/session (e.g., via respective user input), and in response, the chat bot may immediately router/transfer the interaction/session to the human agent.]
It is noted that Durairaj does not explicitly disclose generate a temporary or blanket access license that is associated with the secure browsing session, the access license comprising a unique session identifier and a time-limited or session-based authorization token; provide the temporary or blanket access license to the AI controlled agent.
However, Hallock discloses generate a temporary or blanket access license that is associated with the secure browsing session, the access license comprising a unique session identifier and a time-limited or session-based authorization token; provide the temporary or blanket access license to the AI controlled agent (Hallock claim 1, Pa. [0125, 0132]) [A unique session identifier token to be employed as part of an authentication session to uniquely identify the authentication session from other authentication sessions, the unique session identifier token comprising: a unique identifier object having a time component and a unique data object; and whereas the time component represents a time of creation of the unique session identifier token.]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks (Hallock [0002])
As to claims 2-3, the combination of Durairaj and Hallock teaches wherein the payload comprises a Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) (Hallock [0010]) [the outer layer of security delivers a challenge to the person seeking access; personal identifier credentials of some nature are presented in response to the challenge]; wherein the validation data includes a session cookie, a local storage object or other form of validation data, that enables the cloud browser to bypass the payload or the bot-detection process (Durairaj Pa. [0101]) [the chat bot may detect that the user may need assistance based on some criteria (e.g., the user has remained stuck at a particular webpage for at least a threshold period of time while completing a form on the webpage)]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 4, the combination of Durairaj and Hallock teaches wherein granting the AI controlled agent the navigational control further comprises: activating, by the processor, in-page control passing that transfers navigational control authority from the first client device to the AI controlled agent (Durairaj Pa. [0068]) [the chat bot may automatically perform a set of desired actions (e.g., web actions) on a webpage with which the user is interacting through embedded JavaScript and/or other technologies]; and maintaining, by the processor, a communication channel with the first client device to allow the validated user entity to revoke the temporary or blanket access license and reclaim navigational control of the simulated browsing session (Durairaj Pa. [0068]) [the chat bot simulates and processes human conversation (either written or spoken), allowing humans to interact with digital devices as if the humans were communicating with another human]
As to claim 5, the combination of Durairaj and Hallock teaches further comprising an encoder configured to process visual data generated by the cloud browser into a real-time transmission stream, wherein the processor is further configured to: redact, using the encoder, sensitive information fields from the real-time transmission stream based on a machine-learning model trained to identify personally identifiable information, financial data or other forms of sensitive data within rendered online content (Durairaj Pa. [0096]) [performed off-line, e.g., responding to emails, attending training, and other activities that do not entail real-time communication with a customer.]
As to claim 6, the combination of Durairaj and Hallock teaches wherein the AI controlled agent utilizes a visual engine to analyze the real-time transmission stream to determine a contextual state of the secure online content before transmitting one or more simulated human browsing inputs to the cloud browser (Durairaj Pa. [0068]) [the chat bot simulates and processes human conversation (either written or spoken), allowing humans to interact with digital devices as if the humans were communicating with another human]
As to claim 7, the combination of Durairaj and Hallock teaches wherein the temporary or blanket access license expires upon termination of the simulated browsing session Hallock claim 1, Pa. [0125, 0132]) [A unique session identifier token to be employed as part of an authentication session to uniquely identify the authentication session from other authentication sessions, the unique session identifier token comprising: a unique identifier object having a time component and a unique data object; and whereas the time component represents a time of creation of the unique session identifier token.]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 8, the combination of Durairaj and Hallock teaches wherein the one or more simulated human browsing inputs comprise at least one of a cursor movement, a click event, a text string injection, a text input, scrolling, zooming, selecting, highlighting, hovering, downloading, or uploading (Durairaj Pa. [0037]) [solution may be selected from the plurality of sequences of actions performed by the human contact center agents during the corresponding co-browse sessions to resolve the user intent.]
As to claim 9, the combination of Durairaj and Hallock teaches wherein the system is configured to record an audit log of all simulated browsing actions performed by the AI controlled agent while the temporary or blanket access license is active, the audit log linking the actions to the unique session identifier (Hallock claim 1, Pa. [0125, 0132]) [A unique session identifier token to be employed as part of an authentication session to uniquely identify the authentication session from other authentication sessions, the unique session identifier token comprising: a unique identifier object having a time component and a unique data object; and whereas the time component represents a time of creation of the unique session identifier token.]
As to claim 10, the combination of Durairaj and Hallock teaches wherein the AI controlled agent is configured to autonomously populate one or more data fields within the secure online content using the temporary or blanket access license (Hallock [0130]) [personal identification device is in possession of the first user is negative and decreased. Nearfield trackers]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 11, claim 11 recites the claimed that contain similar limitations as claims 1 therefore, it is rejected under the same rationale.
As to claim 12, the combination of Durairaj and Hallock teaches wherein the digital license includes a cryptographic key associated with a specific enterprise component, and wherein the cloud browser instance is isolated from other instances within the processor (Hallock [0131]) [Encryption and cryptographic digital signing]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 13, the combination of Durairaj and Hallock teaches wherein the processor is further configured to: periodically verify validity of the persistent authentication state; and transmit, when the persistent authentication state is invalid due to expiration, a re-authentication request to a human administrator or an authorization device linked to the digital license (Hallock [0137]) [the Relying Party verifies the subscribing party or Personal Identifier mobile device OTP code and timestamp and determines if the mobile device user identity is true or false. Time augmentation is an additional security measure to validate time in transit and to disqualify tokens not received in a timely manner.]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 14, the combination of Durairaj and Hallock teaches wherein the AI controlled agent interacts with the third-party online resource via a visual perception model that interprets or predicts an encoded video stream of the cloud browser instance (Durairaj Pa. [0012]) [the plurality of actions may include at least one of a mouse movement, mouse interaction, screen pointer, screen change, audio instruction, video instruction, or text entry]
As to claim 15, the combination of Durairaj and Hallock teaches wherein the secure online content comprises a dynamic document object model (DOM), and wherein the processor is further configured to: synchronize changes in the DOM to the AI controlled agent using the synchronization server (Durairaj Pa. [0064]) [if there is not already a matching configuration file stored in association with a user intent, the chat bot may seamlessly transfer the session to a human contact center agent, and the system 100 may capture the Document Object Model (DOM) elements of a web page and web actions performed by the agent during the agent-led co-browse session for storage and analysis]
As to claim 16, the combination of Durairaj and Hallock teaches wherein the secure session storage is configured to prevent the AI controlled agent from extracting the credentials for the third-party online resource, while permitting the AI controlled agent to utilize the persistent authentication state (Hallock Pa. [0010]) [cyber world when a user name and password are required to access online accounts,]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 17, the combination of Durairaj and Hallock teaches wherein the trigger request from the AI controlled agent is triggered by an external event detected by the AI controlled agent, and wherein the processor is further configured to: dynamically allocate resources to the cloud browser instance in response to the trigger request (Durairaj Pa. [0081]) [a cloud execution model generally includes a service provider dynamically managing an allocation and provisioning of remote servers for achieving a desired functionality.]
As to claim 18, the combination of Durairaj and Hallock teaches wherein the processor is further configured to: execute the cloud browser to apply an automated redaction layer over one or more specific visual elements of the third-party online resource rendered in the cloud browser instance, such that the AI controlled agent can interact with the third-party online resource but is restricted from ingesting visual data corresponding to the one or more specific visual elements (Durairaj Pa. [0133]) [environment may be a virtual network environment where the various network components are virtualized. For example, the various machines may be virtual machines implemented as a software-based computer running on a physical machine. The virtual machines may share the same operating system, or, in other embodiments, different operating system may be run on each virtual machine instance. For example, a “hypervisor” type of virtualizing is used where multiple virtual machines run on the same host physical machine, each acting as if it has its own dedicated box. Other types of virtualization may be employed in other embodiments, such as, for example, the network (e.g., via software defined networking) or functions (e.g., via network functions virtualization).]
As to claim 19, the combination of Durairaj and Hallock teaches wherein the digital license is revocable, and wherein revocation triggers deletion of the persistent authentication state from the secure session storage (Durairaj Pa. [0149]) [the previous session data may be deleted from the co-browse action database 1]
As to claim 20, the combination of Durairaj and Hallock teaches wherein the AI controlled agent is configured to execute a workflow including a plurality of online actions using simulated keyboard events, the plurality of online actions comprising navigating to a specific Uniform Resource Locator (URL), identifying a form field via visual recognition, and inputting alphanumeric data into the form field (Hallock [0031]) [probability a human trait event of the present user of the personal identifier device is indicative of a like human trait event of the first user of the device on a time-aligned basis; the first level predictive process. There is a human trait predictive process for each human trait employed in an embodiment. The first level predictive process is periodically occurring at predetermined scheduled times or as a result of the receipt of sensor event notification. Determination the human trait event of the present user in possession is that of the first user is arrived at by capturing the measurable value indicative of the human trait and comparing that value]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 21, claim 21 recites the claimed that contain similar limitations as claims 1 therefore, it is rejected under the same rationale.
As to claim 22, the combination of Durairaj and Hallock teaches wherein the restricted payload or the bot-detection process is a biometric authentication challenge, and the validation input comprises biometric data transmitted from the authorization device to the cloud browser (Hallock [0012]) [statically stored credential: the password, the single-use token, the secret phrase, the biometric image, or the driver's license, passport or birth certificate. If an object is stored as a static thing, the object implicitly becomes available for discovery, hijacking, forgery, and theft.]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 23, the combination of Durairaj and Hallock teaches the method further comprising: monitoring the simulated browsing session for a subsequent payload or a subsequent bot-detection process; and automatically suspending the token and re-soliciting validation input from the authorization device in response to detecting the subsequent payload (Durairaj Pa. [0070]) [he chat bot may detect that the user may need assistance based on some criteria (e.g., the user has remained stuck at a particular webpage for at least a threshold period of time while completing a form on the webpage), and proactively offer the user assistance via a co-browse session.]
As to claim 24, claim 24 recites the claimed that contain similar limitations as claim 14 therefore, it is rejected under the same rationale.
As to claim 25, the combination of Durairaj and Hallock teaches wherein the token restricts the AI controlled agent to a subset of URLs, preventing the AI controlled agent from accessing unauthorized domains (Hallock [0073]) [impossibility of preventing phishing attacks and thus the risk of BOT deployment, the present invention puts a focus on mitigation. When best efforts fail and a MITM BOT is deployed the next best defense is to prevent it from harvesting usable data. To achieve this the present invention discloses the Unique Session Identifier token concept and its unique associated cryptography methods. The unique session identifier token is a simply a small token, perhaps a UUID (Uniquely Universal Identifier)]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 26, the combination of Durairaj and Hallock teaches the method further comprising: identifying a sensitive data field within the secure online content; and masking the sensitive data field in a visual output provided to the AI controlled agent while maintaining functionality of the sensitive data field for data entry by the AI controlled agent (Durairaj Pa. [0076]) [a communications infrastructure and/or content center system, which may be used in conjunction with one or more of the embodiments described herein]
As to claim 27, the combination of Durairaj and Hallock teaches wherein the AI controlled agent utilizes a large language model (LLM) to interpret textual or visual data rendered within the secure online content and determine subsequent simulated browsing commands and their respective sequences (Durairaj Pa. [0100]) [models based on collected data, such as, for example, customer data, agent data, and interaction data]
As to claim 28, the combination of Durairaj and Hallock teaches wherein the validation input comprises a Single Sign-On (SSO) token, and the cloud browser inherits an authenticated state associated with the SSO token (Hallock [0012]) [the password, the single-use token,]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
As to claim 29, claim 29 recites the claimed that contain similar limitations as claims 8 therefore, it is rejected under the same rationale
As to claim 30, the combination of Durairaj and Hallock teaches wherein the system enables a plurality of AI controlled agents to share the token so as to perform distributed tasks within the secure online content (Hallock [0039]) [e unique session identifier token received with the original query and the snippet audio data thereby creating a Personal Identification Code message.]
Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Hallock to the access online content system of Durairaj would have yield predictable results and resulted in an improved system, namely, a system that would provide security, identification and access management and preventing “man-in-the-middle” attacks. (Hallock [0002])
Response to Arguments
Arguments
It is argued that:
Each of independent claims 1, 11, and 21 recites a cloud browser, and neither Durairaj nor Hallock discloses this feature. Independent claim 1 recites a cloud browser that is able to engage in a simulated browsing session and over which the Al controlled agent is granted navigational control. Independent claim 11 recites instantiating a cloud browser instance in which credentials for a third-party online resource are authenticated to produce a persistent authentication state. Independent claim 21 recites a cloud browser that renders online content from a target uniform resource locator. The cloud browser is thus a central element of every independent claim.
As described in the disclosure filed by Applicant, the cloud browser is a server-side component that independently obtains and renders online content while executing the interactions of a leading participant, and which then encodes and delivers the resulting frames to session participants. This architecture is explicitly and purposefully distinguished in the disclosure from client-side solutions, including co-browse scripts and JavaScript tag-based synchronized browsing systems, which require code placement or injection on each webpage to replicate interactions on a device that is local to the end user. The disclosure states: ...first generation shared browsing technologies that are built around the detection of the online interactions of one or more leading participants for independent replication by one or more following participants ... are typically considered highly invasive from an information technology (IT) implementation and security standpoint since they require the placement or injection of third party enabling code, such as JavaScript® tags, on each and every page that is eligible for shared
browsing. (See page 2 of the present application.)
The cloud browser disclosed by Applicant and recited by independent claims 1, 11 and 21 stands in direct contrast to such client-side approaches. It is a server-side browser that accesses web content, executes actions, and produces frame data, without requiring any code injection or client-side execution of browsing actions on the end user device.
In rejecting independent claim 1 over Durairaj in view of Hallock, the Office Action mapped the claimed cloud browser to the "co-browse script 108" in Durairaj, citing paragraph [0070] of Durairaj to assert: "The system 100 may retrieve and execute a co-browse script 108...." (See page 3 of the Office Action.) Applicant respectfully submits that this mapping is fundamentally incorrect and cannot support disclosure of the cloud browser that is affirmatively required by independent claims 1, 11 and 21.
Referring to Durairaj, co-browse script 108 is expressly described by Durairaj as including "native JavaScript code embedded into the webpage or web-based application beingPage
executed by the user device." (See paragraph [0070] of Durairaj.) This is an unambiguous characterization to the effect that the co-browse script operates on the user's own device, embedded within the webpage the user is already visiting. Thus, co-browse script 108 of Durairaj is a client-side feature, not a server-side cloud browser.
Durairaj does not disclose a component operating on a server that fetches, renders, and encodes web content into a stream, as the recited cloud browser requires. Moreover, the cloud- based system of Durairaj is not a cloud browser. Durairaj describes a cloud-based system that provides contact center functionality and that includes components such as a SIP server, a resource manager, a media control platform, a chat bot, and a voice generator. (See id. at paragraphs [0062], [0106], and [0120].) Durairaj further describes this system as a server- ambiguous computing solution that executes virtual functions on demand. (See id. at paragraph [0134].) That disclosure is directed to cloud computing infrastructure. It is not a browser, and it does not fetch, render, and encode web content in the manner recited. The passages relied upon in the Office Action for the cloud browser, namely paragraphs [0068], [0070], and [0134] of Durairaj, describe respectively a chat bot embodied as an executable program, a co-browse script embodied as JavaScript embedded in the webpage that is executed by the user device, and generic on demand cloud computing. None of these passages discloses the recited cloud browser.
This deficiency is especially clear with respect to independent claim 11. Independent claim 11 requires instantiating a cloud browser instance and authenticating credentials for a third-party online resource within that instance to produce a persistent authentication state that is stored and later restored. The co-browse offering described in Durairaj, which operates on the device of the user, does not instantiate a cloud browser instance and does not hold a persistent authentication state within any such instance. Although Durairaj describes restoring an incomplete co-browse session, what Durairaj restores is a set of co-browse actions and an intent
configuration file, rather than a persistent authentication state of a browser operating in the cloud. (See id. at paragraphs [0071], [0072], and [0144].) The restoration mechanism of Durairaj therefore does not supply the recited cloud browser instance or the persistent authentication state associated with it.
Referring to Hallock, Hallock is directed to a personal identification device, such as a cell phone, that uses sensor inputs and behavioral traits together with a session identifier token to authenticate a session and to prevent man-in-the-middle attacks. (See Abstract and paragraph [0002] of Hallock.) Hallock does not disclose any browser, and it certainly does not disclose a component operating in the cloud that fetches, renders, and encodes web content. The mention in Hallock of a user name and password used to access online accounts is a general reference to web authentication and does not disclose a cloud browser. (See id. at paragraph [0010].) Furthermore, Applicant notes that the Office Action does not rely on Hallock for disclosure of the cloud browser.
Neither Durairaj nor Hallock discloses, teaches, or suggests the recited cloud browser. As such, the proposed combination of Durairaj and Hallock also fails to disclose, teach, or suggest that feature. A prima facie case of obviousness requires that the applied prior art disclose, teach, or suggest every limitation of the claim. (See MPEP § 2143.03.) The cloud browser is recited in each of independent claims 1, 11, and 21, and it is absent from both Durairaj and Hallock. This deficiency alone is sufficient to overcome the rejection of independent claims 1, 11 and 21 over Durairaj in view of Hallock.
Nevertheless, independent claims 1, 11, and 21 further require operation in relation to a payload or a bot-detection process. Independent claim 1 recites a simulated browsing session within content that has a payload or involves a bot-detection process, and access to the secure online content on a post-payload or a post-bot-detection basis. Independent claim 11 recites that
the AI controlled agent is enabled to bypass a payload or a bot-detection process of the third- party online resource. Independent claim 21 recites detecting a restricted payload or a bot- detection process and receiving a validation input to satisfy that payload or process.
Durairaj does not disclose a payload or a bot-detection process. The co-browse of Durairaj is a cooperative interaction in which a chat bot assists a user who is already present in order to complete a form, such as opening a Senior Bank Account. (See paragraphs [0140] and [0149], and Figures 10 through 14 of Durairaj.) Durairaj does not describe a CAPTCHA, a bot- detection process, or any security challenge that is satisfied or bypassed. The passages relied upon in the Office Action, namely paragraphs [0101] and [0068] of Durairaj, describe an analytics module having access to an interaction database and a chat bot that simulates conversation. Neither passage discloses a payload or a bot-detection process relating to access to secure content.
Hallock does not cure this deficiency in Durairaj. The session identifier token of Hallock is disclosed for the purpose of proving that a genuine human is in possession of a device and of defeating bots and preventing replay and man-in-the-middle attacks. (See paragraphs [0071], [0072], and [0073] of Hallock.) The present independent claims, by contrast, employ the recited access license and token to enable an AI controlled agent, which is an automated agent, to access secure content that is protected by a payload or a bot-detection process. The purpose of the mechanism of Hallock is opposite to the recited use, and the Office Action supplies no reason why a person of ordinary skill in the art would apply an anti-bot and human presence mechanism in order to grant an automated agent access to content that is protected by a bot-detection process.
The Office Action acknowledged that Durairaj does not disclose generating a temporary or blanket access license comprising a unique session identifier and a time-limited or session-
based authorization token, or providing that license to the AI controlled agent. (See page 4 of the Office Action.) The Office Action relied on the unique session identifier token in claim 1 of Hallock and paragraphs [0125] and [0132] of Hallock to supply this element. (See id. at page 5.)
However, the token of Hallock does not correspond to the recited access license. As Hallock explains, the unique session identifier token is created by the service provider, which is the relying party, and is signed by the personal identifier device in order to bind and verify an authentication session. (See paragraph [0131] of Hallock.) The token of Hallock is therefore a session binding value used to complete authentication. It is not a license that is provided to an agent in order to confer navigational control or access rights. Moreover, the time component of the token of Hallock represents a time of creation of the token, and not a time-limited authorization token in the sense of an expiring grant of access. The present independent claims, in contrast, require that the access license be provided to the AI controlled agent so as to grant that agent navigational control and access to secure content. Hallock never provides the token to an AI agent to authorize that AI agent to act, because the token of Hallock is used to keep unauthorized actors out. (See generally Hallock.)
The Office Action rejected independent claims 11 and 21 by stating that each recites limitations similar to independent claim 1 and is rejected under the same rationale. (See pages 9 and 14 of the Office Action.) However, claims 11 and 21 are independent claims that recite materially different limitations than independent claim 1, and those limitations were not addressed in the Office Action.
Independent claim 11 recites authenticating credentials for a third-party online resource within a cloud browser instance to produce a persistent authentication state, storing that persistent authentication state in a secure session storage that is associated with a synchronization server, and restoring that state in order to enable the AI controlled agent to
access the secure content. Independent claim 21 recites soliciting a validation input from an authorization device that is operated by a human entity, receiving the validation input in order to satisfy a restricted payload or a bot-detection process, generating a token, and granting the token to an AI controlled agent so as to enable access to the secure content. None of these limitations is addressed by the analysis directed to independent claim 1, and none is taught by Durairaj in view of Hallock. The failure to address these limitations is a further and independent reason that the present rejection cannot be sustained with respect to independent claims 11 and 21. (See § MPEP 2143.03.)
Accordingly, Applicant respectfully submits that independent claims 1, 11 and 21 are patentably distinguishable over Durairaj in view of Hallock, and should be allowed. As such, claims 2-10 depending from and further limiting patentable independent claim 1, claims 12-20 depending from and further limiting patentable independent claim 11, and claims 22-30 depending from and further limiting patentable independent claim 21, are also patentably novel and inventive over Durairaj in view of Hallock, and should also be allowed, for at least the reasons presented above, as well as for the additional limitations contained in the dependent claims.
Furthermore, regarding claim 5, claim 5 recites an encoder that processes visual data generated by the cloud browser into a real-time transmission stream, and redaction, using the encoder, of sensitive information components from that stream based on a machine-learning model trained to identify personally identifiable information, financial data, or other sensitive data within rendered online content. The Office Action cited paragraph [0096] of Durairaj to support rejection of claim 5. (See page 7 of the Office Action.) However, paragraph [0096] of Durairaj describes the interaction server managing deferrable back office activities such as responding to emails and attending training. It says nothing about an encoder, a real-time
transmission stream, or redaction based on a machine-learning model. Neither Durairaj nor Hallock discloses the recited encoder or the recited redaction. (See generally Durairaj and Hallock.) Thus, Applicant respectfully submits that claim 5 is patentably distinguishable over Durairaj in view of Hallock for this additional reason.
Regarding claim 10, claim 10 recites that the AI controlled agent autonomously populates one or more data fields within the secure online content using the temporary or blanket access license. The Office Action cited paragraph [0130] of Hallock to support rejection of claim 10. (See page 9 of the Office Action.) However, paragraph [0130] of Hallock describes nearfield trackers and the effect of tracker presence on the probability that a device is in the possession of a first user. It does not describe an AI agent populating data fields, and it does not describe the use of any access license to do so. Thus, Applicant respectfully submits that claim 10 is patentably distinguishable over Durairaj in view of Hallock for this additional reason.
Regarding claim 16, claim 16 recites that the secure session storage is configured to prevent the AI controlled agent from extracting the credentials for the third-party online resource, while permitting the AI controlled agent to utilize the persistent authentication state. The Office Action cited paragraph [0010] of Hallock, which states only that a user name and password are required to access online accounts. (See pages 11-12 of the Office Action.) That general statement about web authentication does not disclose a storage that isolates credentials from an agent while still allowing the agent to use an authentication state. Such a credential isolation feature is disclosed by neither Durairaj nor Hallock. (See generally Durairaj and Hallock.) Thus, Applicant respectfully submits that claim 16 is patentably distinguishable over Durairaj in view of Hallock for this additional reason.
Regarding claim 18, claim 18 recites executing the cloud browser to apply an automated redaction layer over one or more specific visual elements of the third-party online resource
rendered in the cloud browser instance, such that the AI controlled agent can interact with the resource but is restricted from ingesting visual data corresponding to those elements. The Office Action cited paragraph [0133] of Durairaj for disclosure of these limitations. (See pages 12-13 of the Office Action.) However, paragraph [0133] of Durairaj describes a virtualized network environment and the use of virtual machines and a hypervisor. It does not describe any visual redaction layer, and it does not describe restricting an agent from ingesting visual data. Neither Durairaj nor Hallock discloses the recited redaction layer. (See generally Durairaj and Hallock.) Thus, Applicant respectfully submits that claim 18 is patentably distinguishable over Durairaj in view of Hallock for this additional reason.
Regarding claim 25, claim 25 recites that the token restricts the AI controlled agent to a subset of uniform resource locators, preventing the agent from accessing unauthorized domains. The Office Action cited paragraph [0073] of Hallock, which describes mitigation of man-in-the- middle bots and the unique session identifier token as a universally unique identifier. (See page 16 of the Office Action.) That disclosure does not describe a token that limits an agent to a subset of uniform resource locators, and it does not describe preventing access to unauthorized domains. Neither Durairaj nor Hallock discloses the recited restriction of the agent to a subset of uniform resource locators. (See generally Durairaj and Hallock.) Thus, Applicant respectfully submits that claim 25 is patentably distinguishable over Durairaj in view of Hallock for this additional reason.
Regarding claim 30, claim 30 recites that the system enables a plurality of AI controlled agents to share the token so as to perform distributed tasks within the secure online content. The Office Action cited paragraph [0039] of Hallock, which describes speaker identification in a setting with multiple potential speakers and the concatenation of a session identifier token with audio snippet data to form a personal identification code message. (See page 18 of the Office
Action.) However, that disclosure does not describe a plurality of agents sharing a token, and it does not describe the performance of distributed tasks. Neither Durairaj nor Hallock discloses the recited sharing of a token among multiple agents. (See generally Durairaj and Hallock.) Thus, Applicant respectfully submits that claim 30 is patentably distinguishable over Durairaj in view of Hallock for this additional reason.
Examiner’s response :
In response to applicant's argument, Examiner respectfully submits that claimed limitation is to be given their broadest reasonable interpretation during prosecution, and the scope of a claim cannot be narrowed by reading disclosed limitations into the claim. See In re Morris, 127 F.3d 1048, 1054, 44 USPQ2D 1023, 1027 (Fed. Cir. 1997); In re Zletz, 893 F.2d 319, 321, 13 USPQ2D 1320, 1322 (Fed. Cir. 1989). In this case, the combination of Durairaj and Hallock teaches fairly discloses the claimed limitation
a system for providing a simulated including access to secure online content, the system comprising (Durairaj Pa. [0095]) [user interfaces and be configured to access a variety of local resources (e.g., a calendar or contact information on the customer device) or remote resources]: an artificial intelligence (AI) controlled agent (Durairaj Pa. [0062]) [Referring now to FIG. 1, a system 100 for co-browsing by chat bots by leveraging artificial intelligence (AI) and asynchronous session handling is shown”, “AI-powered bots to handle co-browse sessions] [0068] [an executable program that can be launched according to demand for the particular chat bot (e.g., by a cloud-based system]; a cloud browser (Durairaj Pa. [0070]) [The system 100 may retrieve and execute a co-browse script 108] [0134] [one or more cloud-based systems. In cloud-based embodiments, the cloud-based system may be embodied as a server-ambiguous computing solution, for example, that executes a plurality of instructions on-demand, contains logic to execute instructions only when prompted by a particular activity/trigger]; and a processor configured to (Durairaj Pa. [0123]) [one or more processors executing computer program instructions and interacting with other system components for performing the various functionalities described herein]: receive, from a first client device associated with a validated user entity (Durairaj Pa. [0070]) [when there is a matching user intent determined by the intent classification API 106 and the user has authorized a co-browsing session for assistance (e.g., completing a web-based form], a request to initiate a secure browsing session (Durairaj Pa. [0070]) [AI-powered bots to handle co-browse sessions]; execute the request, using the cloud browser (Durairaj Pa. [0070]) [the chat bot may request the data directly from the user during the co-browse session], wherein the cloud browser is able to engage in a simulated browsing session within content that has a payload (Durairaj Pa. [0068]) [the chat bot simulates and processes human conversation (either written or spoken), allowing humans to interact with digital devices as if the humans were communicating with another human.] or involves a bot-detection process relating to access to the secure online content using validation data provided by the first client device or another authorization source (Durairaj Pa. [0101]) [The analytics module 250 also may have access to the interaction database, which stores data related to interactions and interaction content (e.g., transcripts of the interactions and events detected therein)]; grant the AI controlled agent navigational control over the cloud browser, thus enabling the AI controlled agent to have access to the secure online content on a post-payload or a post-bot-detection basis via the cloud browser (Durairaj Pa. [0153]) [the system 100 may allow the user to opt to transfer an interaction or co-browse session between the user and chat bot to a human agent at any point during the interaction/session (e.g., via respective user input), and in response, the chat bot may immediately router/transfer the interaction/session to the human agent.]
Hallock discloses generate a temporary or blanket access license that is associated with the secure browsing session, the access license comprising a unique session identifier and a time-limited or session-based authorization token; provide the temporary or blanket access license to the AI controlled agent (Hallock claim 1, Pa. [0125, 0132]) [A unique session identifier token to be employed as part of an authentication session to uniquely identify the authentication session from other authentication sessions, the unique session identifier token comprising: a unique identifier object having a time component and a unique data object; and whereas the time component represents a time of creation of the unique session identifier token.]
Furthermore, claims 11 and 21 recite the claimed that contain similar limitations as claims 1 therefore, they are rejected under the same rationale.
In response to applicant's argument regarding claims 5, 10 16, 25 and 30 Examiner respectfully submits that claimed limitation is to be given their broadest reasonable interpretation during prosecution, and the scope of a claim cannot be narrowed by reading disclosed limitations into the claim. See In re Morris, 127 F.3d 1048, 1054, 44 USPQ2D 1023, 1027 (Fed. Cir. 1997); In re Zletz, 893 F.2d 319, 321, 13 USPQ2D 1320, 1322 (Fed. Cir. 1989).
Claim 5, further comprising an encoder configured to process visual data generated by the cloud browser into a real-time transmission stream, wherein the processor is further configured to; redact, using the encoder, sensitive information fields from the real-time transmission stream based on a machine-learning model trained to identify personally identifiable information, financial data or other forms of sensitive data within rendered online content (Durairaj Pa. [0096]) [performed off-line, e.g., responding to emails, attending training, and other activities that do not entail real-time communication with a customer.]
claim 10, wherein the AI controlled agent is configured to autonomously populate one or more data fields within the secure online content using the temporary or blanket access license (Hallock [0130]) [personal identification device is in possession of the first user is negative and decreased. Nearfield trackers]
claim 16, wherein the secure session storage is configured to prevent the AI controlled agent from extracting the credentials for the third-party online resource, while permitting the AI controlled agent to utilize the persistent authentication state (Hallock Pa. [0010]) [cyber world when a user name and password are required to access online accounts,]
claim 25, wherein the token restricts the AI controlled agent to a subset of URLs, preventing the AI controlled agent from accessing unauthorized domains (Hallock [0073]) [impossibility of preventing phishing attacks and thus the risk of BOT deployment, the present invention puts a focus on mitigation. When best efforts fail and a MITM BOT is deployed the next best defense is to prevent it from harvesting usable data. To achieve this the present invention discloses the Unique Session Identifier token concept and its unique associated cryptography methods. The unique session identifier token is a simply a small token, perhaps a UUID (Uniquely Universal Identifier)]
claim 30, wherein the system enables a plurality of AI controlled agents to share the token so as to perform distributed tasks within the secure online content (Hallock [0039]) [e unique session identifier token received with the original query and the snippet audio data thereby creating a Personal Identification Code message.]
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EVANS DESROSIERS whose telephone number is (571)270-5438. The examiner can normally be reached Monday -Friday 8:00 am - 5:30 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EVANS DESROSIERS/Primary Examiner, Art Unit 2491