In 2023, two appeals filed by Microsoft Technology have been decided by the Delhi High Court.

The first appeal impugns order dated 05th March, 2012 passed by the Controller of Patents and Design whereby Indian Patent Application No. 487/DELNP/2006 titled as “ADVANCED BI-DIRECTIONAL PREDICTIVE CODING OF INTERLACED VIDEO” was rejected under Section 15 of the Act.

The appellants argued that:

  • Impugned order provides insufficient and insignificant reasoning to support the conclusion.
  • No thoughtful analysis has been applied, and the claims in the subject patent have been rejected on an ambiguous rationale of not following a “method step format”.
  • The phrase “method step format”, as employed by the Controller, is puzzling and not defined in the Act.
  • Controller has used similar vague terms and phrases for claims 1 to 10, labelling them as “redundant” and “large sized”.
  • Neither the Patent Act nor the Rules framed thereunder prescribe any limitation on the number and/ or size of claims.
  • Controller has also not applied the correct legal principles for rejecting the subject patent holding it to be beyond the scope of Section 3(k) of the Act.

The Court identified the following errors in the order:-

  1. The Controller formed an opinion that claims 1 to 41 are not in “method step format”. Claims 1 through 41 do not exclusively contain method claims, as claims 37 to 41, are system claims. The respondent has treated all claims uniformly.
  2. During the examination process, if the examiner identifies any issues and/ or deficiencies related to the claims, they can inform the applicant of such specific issues and seek a response. The applicant then has an opportunity to amend the claims or provide arguments addressing the concerns. In the present matter, the respondent has failed to identify the issues. The Controller must identify the issues, if any, qua the subject patent and intimate the same to the appellant with sufficient information so that the appellant is able to address them by amending the application or providing clarifications, as required. Merely labelling the claims to be not as per format, would not be enough.
  3. Respondent also finds the claims to be “verbose”, “redundant” and “large sized”. The Court held the reasoning is imprecise and highlights the generic methodology employed by the respondent.

As regards objection under Section 3(k) of the Act, the Court notes that the impugned order notes that “The Inventive concept lies in algorithm steps, merely receiving, encoded data […]”. The Court noted that in Ferid Allani v. Union of India and Ors., the Court has dealt with the patentability under Section 3(k) of the Act.

Ferid Allani v. Union of India and Ors., was not available when the impugned order was issued. The Court, in view of the above, remanded the case back to the patent office for reconsideration, however, the Respondent, was directed that while deciding the patent application afresh, the controller must take into account the Ferid Allani v. Union of India and Ors judgment to see whether the claimed invention has a presence of technical effect/ technical contribution.

The second decision is focused on the controversy surrounding the interpretation of the phrase “computer program per se” in the exclusionary Section 3(k) of the Patent Act, 1970 [“the Act”].

Though, in the first case discussed above, the Court relied on Ferid Allani v. Union of India and Ors, in the present case, the Court discussed Section 3(k) in detail.  

The second decision is in respect of Indian patent application No. 1373/DEL/2003 relating to “METHODS AND SYSTEMS FOR AUTHENTICATION OF A USER FOR SUB-LOCATIONS OF A NETWORK LOCATION” which was refused vide an order dated 11th April, 2019.

The appellant argued that Section 3(k) of the Act has been wrongly interpreted in the impugned order insofar as it concludes that claims 1-28 relate to an algorithm implemented by computer program per se.  The Appellant further argued that:

  • The intent of the legislature to add the words “per se” does not mean that patents to a computer program shall not be granted altogether, rather the intent was to reject grant of patent protection to computer programs as such.
  • Technical contribution/ effect in the subject patent lies in the improved security of the existing computer and computer networks and hence, the same ought to be granted a patent.
  • Patent Office has disregarded the decisions of this Court in Ferid Allani v. Union of India and Ors., 2 and Telefonaktiebolaget LM Ericsson (PUBL) v. Intex Technologies (India) Ltd.3

With regard to the subject matter of the application refused, the appellant argued that:

  • The subject patent provides a technical solution to achieve secure authentication by a user while accessing one or more sublocations in a network address.
  • It involves a two-tier authentication by way of two different cookies.
  • Conventionally, computer server allow users to access information stored at a network location, within various sub-locations thereof, such as individual directories of one or more servers or individual servers of a server farm.
  • To prevent unauthorized access to the network locations and their various sub-locations, user(s) authentication for accessing network location(s) is carried out in the following manner:
  • A user may be required to enter a username and password before accessing the network location and corresponding sub-location(s). However, as the number of network locations/ sub-locations that a user may wish to access increases, it requires him/ her to enter a username and password for gaining access each time and this becomes cumbersome.
  • The subject patent operates by generating a cookie and after authentication for the network location based on the first cookie, the sublocation cookies are generated for authenticated user for one or more sublocations.
  • Authentication is done via cookies at the network location and any/ all sub-locations, where access is desired, within the network location. In such a case, when a user attempts to visit a network location, he/ she is directed to the trusted network location which issues an encrypted cookie which is used by the user when directed back to the server of the network location. After requesting the cookie from the user’s computer, the server validates it by decryption, as long as it hasn’t expired. If the validation is successful, the user is authenticated and granted access.

The following technical problem and solution were identified:-

The Technical Problem

A security risk existed where cookies are used to authenticate the user for the visited network location and the sub-location. A malicious user may attempt to steal such cookies that are uploaded from other user computer(s) when they are visiting the network location and can then impersonate such users to gain access to sub-locations within the network location. In few such cases, the malicious user may even be able to obtain personal, financial, or other sensitive information about the users being impersonated.

Technical solution, effect, and contribution

To address the above-outlined technical problem, the subject patent seeks to solve/ mitigate the security risk attached with accessing network locations and its various sub-locations and provide simplified interaction for users, with the content.

When a user logs in to a network location and/ or its sub-location, only the cookie for the network location and the cookie for the particular sublocation(s) are exposed within the sub-location(s) being visited. Even if both of these cookies are stolen by a malicious user, he/ she cannot gain unhindered access. The two-tier authentication envisaged in the subject patent accounts for a scenario where if a malicious user steals both the cookies, which authenticates the user for the network location, he/ she may gain access to the specific sub-location within the network location to which the second cookie pertains. Therefore, the malicious user may only be authenticated for that specific sub-location to which the second cookie pertains but is not further authenticated for any other sub-location(s), within the network location. This is so because the first cookie would not, as explained above, indicate that the user has just been authenticated. Hence, the present patent application provides for a technique for secure authentication of a user while accessing one or more sub-location(s) in a network address and effectively foils the attempts of a malicious user to gain access to network sub-location(s) by illegally obtaining cookies from another user.

The Court discussed the legislative history of the provision, Statement of Objects and Reasons to the Patents (Amendment) Act, 2005, the Report of Joint Parliamentary Committee on Patents (Second Amendment) Bill, 1999, the parliamentary debates, et al. and held that they all point towards the shift in relation to grant of patent protection for CRIs.

The Court held that :-

  • The term “per se” was added to make it clear that “computer programs as such” are non-patentable.
  • The Court reinforced the views expressed in Ferid Allani concerning the meaning of the term “computer program per se” in Section 3(k) of the Act.
  • The patent applications should be considered in the context of established judicial precedents, Section 3(k) of the Act, extant guidelines related to CRIs, and other materials that indicate the legislative framework.
  • If a computer-based invention provides a technical effect or contribution, it may still be patentable. The technical effect or contribution can be demonstrated by showing that the invention solves a technical problem, enhances a technical process, or has some other technical benefit.
  • The mere fact that an invention involves a mathematical or computer-based method does not automatically exclude it from being patentable. The invention can still satisfy the patentability requirements, including the requirement for a technical effect or contribution, to be eligible for patent protection.
  • Method claims in computer program patent may be patentable if it involves a technical advancement and provides a technical solution to a technical problem and has an improved technical effect on the underlying software.
  • The fact that the claimed invention involves a set of algorithms executed in a pre-defined sequential manner on a conventional computing device does not necessarily imply that it lacks a technical effect or contribution.
  • It is possible that the invention provides a technical solution to a technical problem, and the computer program use is merely a means to achieve the technical solution. If the subject matter is implemented on a general-purpose computer, but results in a technical effect that improves the computer system’s functionality and effectiveness, the claimed invention cannot be rejected on non-patentability as “computer program per se”

The Court also suggested that the Indian Patent Office must undertake the exercise of providing indicators/guidelines to the examiners by citing exhaustive list of worked examples, relating to patent eligibility. This practice will help examiners to be consistent with the eligible cases and distinguish the ineligible cases.

The Court held that the controller has erred in summarily rejecting the application by stating that it entails a set of algorithms to execute instructions in a pre-defined sequential manner. The Court further held that the invention provides a technical solution to the security risk associated with using cookies to authenticate users for sublocations within a network location. The use of two different cookies for providing authenticated access to a client computer accessing sub-location(s) in a network location ensures that even if both cookies are stolen by a malicious user, the malicious user cannot gain unhindered access to other sublocations within the network location. This technical solution goes beyond the user-interface level and provides a technical effect and contribution, that is patentable.

Additionally, the use of multiple cookies for authentication is a technical solution that goes beyond mere user interface design and involves complex network-level communication protocols. The respondent argued that the invention is only with improvement of user-interface, however, the Court held that the technical aspects of the invention are closer to the heart of computer and network technology, rather than user-interface. Furthermore, the fact that the invention improves the user experience does not necessarily mean that it is limited to the user-interface. User experience is undoubtedly an important aspect of any technology, and improvements in this area result from technical advancements at various levels in the computer architecture.

The impugned order was therefore set set-aside. Since, there is no discussion on other requirements, like novelty and inventive step of the claimed invention in the impugned order, which were raised in the Hearing Notice, the remanded the matter back to the Controller for further action.

Leave a comment

Greetings

Welcome to Patents Rewind, Anand and Anand’s Patents and Designs blog that offers you an Indian perspective on issues surrounding patent and design eligibility and enforcement through latest case law and developments in the Indian patents and designs landscape.

Let’s connect