Prosecution Insights
Last updated: October 02, 2026
Application No. 17/335,914

IDENTITY THEFT PROTECTION WITH NO PASSWORD ACCESS

Final Rejection §103
Filed
Jun 01, 2021
Examiner
ZARRINEH, SHAHRIAR
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
Micron Technology Inc.
OA Round
8 (Final)
77%
Grant Probability
Favorable
9-10
OA Rounds
0m
Est. Remaining
84%
With Interview

Examiner Intelligence

Grants 77% — above average
77%
Career Allowance Rate
354 granted / 458 resolved
+19.3% vs TC avg
Moderate +7% lift
Without
With
+6.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
29 currently pending
Career history
507
Total Applications
across all art units

Statute-Specific Performance

§101
9.4%
-30.6% vs TC avg
§103
56.5%
+16.5% vs TC avg
§102
12.7%
-27.3% vs TC avg
§112
15.9%
-24.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 458 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In communications filed on 07/0/2026. Claims 1, 8, and 15 are amended. Claims 1-20 are pending in this examination. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This examination is in response to US Patent Application No. 17/335,914. Specification Applicant submitted in Argument and Remarks filed on 11/29/2023 to replace the title with “Memory Device with Integrated Physically Unclonable Function for Enhanced Security via Device Fingerprint-Based Private Key Generation and Message Signing”. However, Examiner suggests Applicant to file the title change with USPTO office. Response to Amendment Applicants’ amendment filed on 07/07/2026 with respect to claims 1, 8, and 15 for newly added limitation have been considered but are moot because the arguments do not apply to any of the references being used in the current rejection. Response to Arguments Applicant's arguments filed 07/07/2026 have been fully considered but they are not persuasive: Applicant submits on pages 2-3 of remarks filed on 07/07/2026 regarding claim 1 that Beuque, and Neumann do not describe “associated with a public key generated from the device fingerprint and including a common name (CN) field identifying a user and used as login information.” Examiner respectfully disagrees with applicant argument for claim 1 filed on 07/07/2026 on pages 2-3 of remarks. Examiner maintains the rejection. While Beuque discloses the limitations as: [0006] the broadcaster responsible for producing the data packets stores the private key and calculates the signature value using the private key. The public key is stored in the decoders which are to receive the data by hard coding the public key into the memory of the decoder during manufacture. Upon reception of the data packet, the decoder verifies the signature value using the stored public key by comparing the received data with the result of applying the public key algorithm to the received signature value. [0111] With reference to FIG. 8, the public key 91 and broadcaster identifier 80 are provided to the user of the decoder in a digital certificate, preferably in the form of the well-known International Standards Organization (ISO) X.509 standard, hard coded into the memory of the decoder during manufacture. Such certificates are distributed to the manufacturers of decoders by trusted third parties, which are usually referred to as Certification Authorities (CAs). The use of such certificates is becoming more widespread primarily due to the Secure Socket Layer (SSL) secure transport protocol developed and standardized by Netscape Communications for securing credit card transactions over the World Wide Web (WWW).[0112] As well as the public key 91 and broadcaster identifier 80, the digital certificate associated with the broadcaster, or broadcaster certificate 90, also includes:[0113] a version number 92 of the broadcaster certificate 90;[0114] a serial number 93 of the broadcaster certificate 90;[0115] a CA identity 94 of the CA which distributed the broadcaster certificate 90;[0116] the validity period 95 of the broadcaster certificate 90 for indicating the start and end of the time period over which the certificate is intended to be used; and [0117] a signature value 96 of the broadcaster certificate 90. [0118] As will be appreciated from the above, the broadcaster certificate includes two different identifiers, a first "issuer name" identifier corresponding to the identity 94 of the distributer of the certificate, and a second "subject name" identifier corresponding to the identifier 80 which identifies the public key 91( equated to login information). [0119] The CA calculates the signature value 96 of the broadcaster certificate 90 by applying a private key of the CA, or CA private key, to at least some or all of the data within the broadcaster certificate. The decoder can then verify this signature value 96 by processing the signature using a corresponding CA public key 101 identified by the CA identity 94 to determine that the contents of the certificate have not been modified subsequent to signature by the CA.[0120] The decoder may store a plurality of such certificates for different respective broadcasters. Furthermore, Neumann discloses: [¶55, a certificate issued from CA 235 identifies a user to the data center 200 via well-known mechanisms, e.g., a certificate generated in accordance with the International Telecommunication Union (ITU) X.509 recommendation. The identity of the certificate issue is held in subject fields as a hierarchically structured name, email address, uniform resource identifier (URI) or other unique identifier. This identity may be used to specify a user account on which the user's applications data are maintained. As previously stated, access to data center resources is controlled by a user's overall applied policy, which is discussed further below. Policy regulator 245 applies the applicable policies in a predetermined order of precedence to produce an overall effective user policy upon a successful user logon to the data center 200]. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-6, 8-13, and 15-19 are rejected under 35 U.S.C. 103 as being unpatentable over US Patent No. (US2019/0305973) (filed in IDS 10/12/2022) issued to Dewan, and further in view of US Patent No. (US2019/0138753) issued Wallrabenstein, and further in view of (NPL: On Improving Reliability of SRAM-Based Physically Unclonable) issued to Arunkumar Vijayakumar, and further in view of US Patent No. ( US2023/0143362) issued to Datskos, and further in view of Hamlet (US8848905), and further in view of Beuque ( US2004/0125959), and further in view of US Patent No. (US2006/0041761) issued to Neumann. Regarding claims 1, 8, and 15, Dewan discloses generating a private key, signing the message using the private key to generate a signed message, and returning the signed message to the host processor [¶25... The attestation engine may include a PUF circuit 202, a PRNG 204, a key generation engine 206, and a signing and verification engine 208. In embodiments, each of the PUF circuit, PRNG 204, key generation engine 206, and signing and verification 208 may be embedded in hardware of component including the attestation engine 104. The PUF circuit generates a unique response r 212 based on a challenge c 210. The present techniques are agnostic to the type of PUF used. In embodiments, the PUF may be an optical PUF, silicon PUF, arbiter PUF, a ring oscillator PUF, and SRAM PUF, the present techniques are also agnostic to the exact circuit parameters that are extracted from the circuit to generate the response r.], and [ ¶¶ 29-31, The PRNG 204 generates random numbers that are sent to the key generation engine 206 until at least two prime numbers are obtained. These primes, P0 and P1, may be referred to as co-primes 214. The random numbers generated by the PRNG 204 are based on the input seed value response r 212. The co-primes 214 are identified from the sequence of random numbers sent from the PRNG to the key generation engine 206. The key generation engine 206 discovers co-primes in the sequence of random numbers transmitted from the PRNG 204 and notifies the PRNG 206 to terminate transmission of random numbers. the key pair 216 may be according to the public key encryption algorithm developed by Rivest, Shamir, and Adelman (RSA). The RSA key pair includes two keys, one a public key and the other a private key.... The signing and verification engine 208, signs the blob with the private key and transmits the signed blob to the device. The device transmits the blob signed back to the host application processor. Using the public key, host application processor can verify the signed blob]; and and firmware performing operations of receiving a message from a host processor, Even though Dewan discloses the limitation as: [¶23…This can be further extended to attesting the firmware of the device to a remote entity. In particular, once the hardware is attested, the ROM in the hardware can measure the firmware that is loaded and send the measurements to the application processor/attestation entity. The manufacturer can now issue a certificate for {c, K.sub.pub} and revoke the certificate if the corresponding K.sub.priv stored at the SoC is compromised], and [¶31, a host application processor sends a challenge and blob to a device including the system 200. The device may be, for example, an on-board voltage regulator. The blob can be few bytes of data or any nonce value.]. The combination of Dewan, Wallrabenstein, and Vijayakumar discloses the limitations below: A memory device comprising: a static random-access memory (SRAM) physically unclonable function (PUF) configured to generate a unique value based on power-up states of SRAM cells, wherein the unique value comprises a consistent device fingerprint associated with the memory device, the consistent device fingerprint being determined by physical manufacturing variations of the SRAM cells that cause each SRAM cell to consistently initialize to a same logic state upon power-up, thereby enabling the device fingerprint to remain remaining constant across multiple power cycles of the memory device; and firmware performing operations of: receiving a message from a host processor, reading the device fingerprint from the SRAM PUF by reading the power-up states of the SRAM cells upon power-up, generating a private key, wherein the firmware regenerates the private key for each signing operation. While Dewan discloses: [¶25... The attestation engine may include a PUF circuit 202, a PRNG 204, a key generation engine 206, and a signing and verification engine 208. In embodiments, each of the PUF circuit, PRNG 204, key generation engine 206, and signing and verification 208 may be embedded in hardware of component including the attestation engine 104. The PUF circuit generates a unique response r 212 based on a challenge c 210. The present techniques are agnostic to the type of PUF used. In embodiments, the PUF may be an optical PUF, silicon PUF, arbiter PUF, a ring oscillator PUF, and SRAM PUF, the present techniques are also agnostic to the exact circuit parameters that are extracted from the circuit to generate the response r.], and [ ¶¶ 29-31, The PRNG 204 generates random numbers that are sent to the key generation engine 206 until at least two prime numbers are obtained. These primes, P0 and P1, may be referred to as co-primes 214. The random numbers generated by the PRNG 204 are based on the input seed value response r 212. The co-primes 214 are identified from the sequence of random numbers sent from the PRNG to the key generation engine 206. The key generation engine 206 discovers co-primes in the sequence of random numbers transmitted from the PRNG 204 and notifies the PRNG 206 to terminate transmission of random numbers. the key pair 216 may be according to the public key encryption algorithm developed by Rivest, Shamir, and Adelman (RSA). The RSA key pair includes two keys, one a public key and the other a private key.... The signing and verification engine 208, signs the blob with the private key and transmits the signed blob to the device. The device transmits the blob signed back to the host application processor. Using the public key, host application processor can verify the signed blob], and [see FIG.2 and corresponding text for more detail]. Furthermore, Wallrabenstein discloses: [¶¶30-31, According to some embodiments, the PUF 112 can comprise circuitry that generates an output dependent on unique physical properties of the PUF 112. For example, variations in manufacturing process and parts may produce a chip comprising electrical circuits with unique hardware characteristics. The PUF 112 may comprise one or more electrical circuits on the chip that generate outputs based on the unique hardware characteristics specific to the one or more electrical circuits. Examples of other PUFs include optical PUFs, magnetic PUFs, and acoustic PUFs. In some embodiments, the PUF 112 can further be configured to generate outputs based on an input. For example, in response to receiving an input, the PUF 112 can be configured to generate an output based on unique hardware properties of the PUF 112 and the input. In some embodiments, the PUF 112 can be configured to generate an output without receiving an input. In one example, a PUF based on SRAM can provide PUF outputs based on the state of the memory bits. By requesting the state of the memory bits at a memory address or addresses a unique value can be obtained and used in encoding secret values, keys, shares, etc. In some embodiments, an output of the PUF 112 may be noisy and vary slightly across multiple evaluations of a constant input. In some embodiments, the device 110 can use a fuzzy extractor to generate a value using an output of the PUF 112 that is constant for a fixed input (equated to consistent device fingerprint) t. In one example, fuzzy extraction can be implemented using error correction code (ECC) and a helper value to recover a constant value for a fixed input using a PUF]. Furthermore, Vijayakumar discloses: [ Pages 1-4, The salient properties that make a PUF attractive for security applications are its tamper-proof nature and uniqueness. It has been claimed that PUFs are tamper-proof because they exploit inherent disorder in the manufacturing process, and any attempt to break package or delayer metal interconnections will change that physical disorder [2]. Uniqueness, on the other hand, is harnessed by exploiting inherent variations of the semiconductor manufacturing process to create unique identifiers/keys. Thus, PUFs are unclonable by both the manufacturer and designer. These properties provide a major advantage over non-volatile memory based key storage, which has been shown to be vulnerable to physical attacks [7]. SRAM PUFs are the most popular Weak PUFs. An SRAM usually starts up in the same initial state upon power-up [4]. This state varies from chip to chip. This is the basis of SRAM PUF function [8]. Unfortunately, PUF circuit characteristics are affected by environmental variations, noise and aging. This impacts repeatability of the response, which is called reliability, in the context of PUFs. Reliability of PUFs is a key design concern in Weak PUFs, as the responses are typically used for cryptographic key generation (or identification) and need to be quite robust to prevent data corruption downstream… SRAM cells that are constituent of embedded memories typically consist of cross-coupled inverters connected by access transistors. Figure 1 shows a typical 6-Transistor SRAM cell. Due to intrinsic process variations, an SRAM cell on start-up would, typically, consistently settle in either logic-0 or logic-1 values. The settlement state is determined by mismatch in process variations in the cell transistors. Settlement to consistent yet random states allow values from multiple cells to be collected for use as a key or identifier. An SRAM PUF is expected to produce this key each and every time during power-up operation. …As mentioned earlier, PUF circuits can be broadly classified as Weak and Strong PUFs. Weak PUFs such as SRAM PUFs typically have few CRPs, while Strong PUFs such as Arbiter PUFs have an exponentially large number of CRPs..., Weak PUF responses are typically used for cryptographic key generation (or identification) where the responses are expected to be extremely reliable. Hence, alternative solutions such as error-correcting codes are more critical for Weak PUFs. As the reliability requirements of Weak PUFs are more demanding, we focus on improving their reliability for the remainder of this paper. To derive a stable key from a string of bits where a few locations in the string are unreliable, a number of technology and algorithmic solutions have been proposed to improve the reliability of keys produced from SRAM PUFs. Since an ideal accuracy of 100% would require a large cost, typically, a low error rate such as an error rate of 10−6 is used as the design target [9,10]. The solutions are discussed below…Jang and Ghosh [19] proposed an 8T SRAM PUF with a PMOS latch and a low-power 7T SRAM cell with an embedded Magnetic Tunnel Junction (MTJ) to enhance the reliability of the PUF in the presence of environmental fluctuations during multiple power-ups]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Dewan, Wallrabenstein, and the teaching of Vijayakumar in order to generate a constant(fixed) private key (cryptographic key) for SRAM PUF with consistent fingerprint (unique value) and use the same key for each signing message operation. Dewan, Wallrabenstein, and Vijayakumar do not explicitly disclose, however, Datskos discloses generating a private key by using the device fingerprint to seed a key generation algorithm with the device fingerprint without storing the private key in non-volatile memory, wherein the device fingerprint serves as a replacement for a random number in the key generation algorithm and is input directly to the key generation algorithm without being passed through a pseudo-random number generator [Abstract, Described herein is using an array of microelectromechanical systems (MEMS) oscillators to produce unique identifiers. At least some of the MEMS oscillators will “couple” or influence each other when exposed to an external stimulus, such that the frequency of the device is not equal to the combination of individual MEMS oscillator frequencies. The frequency of the device provides a unique “fingerprint” that allows the device to be identified with accuracy but is incredibly difficult to copy, meaning the response may be a physical unclonable function (PUF)], and [¶¶65- 67, The device 100 described herein may serve as a hardware cryptographic primitive to generate a unique key. PUFs are based on a challenge-response pair mechanism that can generate a key without the need for storage. During the registration process described herein, each chip or device may be challenged with seed and configuration parameters. Each chip or device may produce a unique reproducible response/key that serves as a private key. The response along with the configuration parameters may be used to generate a public/private pair]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Dewan, Wallrabenstein, and Vijayakumar with the teaching of Datskos in order to generate a public/private pair via physical unclonable function (PUF) response which provides unique “fingerprint” that allows the device to be identified with accuracy but is incredibly difficult to copy. While Dawn discloses storing the private key only in a register or temporary storage location during the signing, wherein the firmware regenerates the private key for each signing operation, thereby ensuring that the private key is removed upon power off and not persistently stored as: [ ¶209, The key generation engine then generates a private and public key pair (K.sub.pub and K.sub.priv) from the prime numbers 214. The key pair K.sub.pub and K.sub.priv are subsequently provided to the signing and verification engine 208. The private key K.sub.priv of the key pair 216 never leaves the key generation/signing and verification engine. Since the public key is made available to the world while the private key never leaves the key generation/signature engine, the key generation engine is asymmetric. Additionally, the private key is never stored anywhere and is generated at runtime]. Dewan, Wallrabenstein, and Vijayakumar, and Datskos do not explicitly disclose, and Hamlet discloses [Col.9 lines15-31, It is noteworthy, that at no time is private key transmitted external to device 505, and furthermore in some embodiments private key is not stored or retained any longer than required to respond to a given challenge. Each time the device 505 is cryptographically challenged on its authenticity, the private key is regenerated using PUF circuit 540]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Dewan, Wallrabenstein, Vijayakumar, Datskos and the teaching of Hamlet in order to indicate that the device has not been subverted and only an authentic device with possession of private key would be able to decrypt a data. Dewan, Wallrabenstein, Vijayakumar, Datskos and Hamlet do not explicitly disclose, however, while Beuque discloses receiving a request for a digital certificate from the host processor, the digital certificate being associated with a public key generated from the device fingerprint and including a common name (CN) field identifying a user and used as login information and returning the digital certificate to the host processor. [0006] the broadcaster responsible for producing the data packets stores the private key, and calculates the signature value using the private key. The public key is stored in the decoders which are to receive the data by hard coding the public key into the memory of the decoder during manufacture. Upon reception of the data packet, the decoder verifies the signature value using the stored public key by comparing the received data with the result of applying the public key algorithm to the received signature value. [0111] With reference to FIG. 8, the public key 91 and broadcaster identifier 80 are provided to the user of the decoder in a digital certificate, preferably in the form of the well-known International Standards Organization (ISO) X.509 standard, hard coded into the memory of the decoder during manufacture. Such certificates are distributed to the manufacturers of decoders by trusted third parties, which are usually referred to as Certification Authorities (CAs). The use of such certificates is becoming more widespread primarily due to the Secure Socket Layer (SSL) secure transport protocol developed and standardized by Netscape Communications for securing credit card transactions over the World Wide Web (WWW).[0112] As well as the public key 91 and broadcaster identifier 80, the digital certificate associated with the broadcaster, or broadcaster certificate 90, also includes:[0113] a version number 92 of the broadcaster certificate 90;[0114] a serial number 93 of the broadcaster certificate 90;[0115] a CA identity 94 of the CA which distributed the broadcaster certificate 90;[0116] the validity period 95 of the broadcaster certificate 90 for indicating the start and end of the time period over which the certificate is intended to be used; and [0117] a signature value 96 of the broadcaster certificate 90. [0118] As will be appreciated from the above, the broadcaster certificate includes two different identifiers, a first "issuer name" identifier corresponding to the identity 94 of the distributer of the certificate, and a second "subject name" identifier corresponding to the identifier 80 which identifies the public key 91( equated to login information). [0119] The CA calculates the signature value 96 of the broadcaster certificate 90 by applying a private key of the CA, or CA private key, to at least some or all of the data within the broadcaster certificate. The decoder can then verify this signature value 96 by processing the signature using a corresponding CA public key 101 identified by the CA identity 94 to determine that the contents of the certificate have not been modified subsequent to signature by the CA.[0120] The decoder may store a plurality of such certificates for different respective broadcasters. Furthermore, Neumann discloses: [¶55, a certificate issued from CA 235 identifies a user to the data center 200 via well-known mechanisms, e.g., a certificate generated in accordance with the International Telecommunication Union (ITU) X.509 recommendation. The identity of the certificate issue is held in subject fields as a hierarchically structured name, email address, uniform resource identifier (URI) or other unique identifier. This identity may be used to specify a user account on which the user's applications data are maintained. As previously stated, access to data center resources is controlled by a user's overall applied policy, which is discussed further below. Policy regulator 245 applies the applicable policies in a predetermined order of precedence to produce an overall effective user policy upon a successful user logon to the data center 200]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Dewan, Wallrabenstein, Vijayakumar, Datskos , Hamlet, and Beuque, with the teaching of Neumann in order to issue a certificate from CA which is used to authenticate the identity of users and machines to a requesting entity [ Neumann, ¶52]. Regarding claims 2, 9, and 16, Hamlet, and Beuque do not explicitly disclose, however, the combination of Dewan, Wallrabenstein, and Vijayakumar, and Datskos disclose wherein the firmware further performs the operations of: generating an asymmetric key pair using the device fingerprint, the asymmetric key pair comprising the private key and a corresponding public key; and writing the asymmetric key pair to a storage area of the memory device Dewan: [¶¶25-31], and [¶22, The key pair may be stored in fuses of the device]. Wallrabenstein: [¶¶30-31, By requesting the state of the memory bits at a memory address or addresses a unique value can be obtained]. Vijayakumar [ Pages 1-4]. Datskos [ Abstract, ¶¶65-67]. Regarding claims 5, 12, and 18, Hamlet, and Beuque, and Datskos do not explicitly disclose, however, the combination of Dewan, Wallrabenstein, and Vijayakumar disclose, wherein loading a private key comprises re- generating the private key using the unique value in response to the message Dewan: [ see FIGS 2-4A, ¶¶25-31, 38-40, 45]. Wallrabenstein: [¶30-¶31, By requesting the state of the memory bits at a memory address or addresses a unique value can be obtained]. Vijayakumar [ Pages 1-4]. Regarding claims 3, 10, and 17, Dewan discloses, wherein the firmware further performs the operations of: registering the public key with a certificate authority (CA); receiving a digital certificate from the CA [¶22, The manufacturer the provides a certificate for the public-private key pair], and [¶23, The manufacturer of the device takes as input the challenge and public key {c, K.sub.pub} and provides a certificate corresponding to the challenge and public key {c, K.sub.pub}. The certificate attests the authentic identity of the device to any entity, such as an application processor. This can be further extended to attesting the firmware of the device to a remote entity], and [¶30, The key pair 216 may be according to the public key encryption algorithm developed by Rivest, Shamir, and Adelman (RSA). The RSA key pair includes two keys, one a public key and the other a private key. The public key may be sent to a third party, such as a manufacturer, to obtain a certificate. Thus, the public key K.sub.pub and challenge c 218 are transmitted outside of the attestation engine 214. The manufacturer provides the certificate for the device corresponding to the challenge-public key pair 218 and can issue multiple certificates for the challenge-public key pair 218. The private key K.sub.priv of the key pair 216 is kept secret]. Dewan, Wallrabenstein, Vijayakumar, Datskos and Hamlet do not explicitly disclose; however, While Beuque discloses the digital certificate including a common name (CN) field identifying a user of the memory device; and writing the CA to the storage area [0006, 0111-0120]. Furthermore, Neumann discloses [¶55, a certificate issued from CA 235 identifies a user to the data center 200 via well-known mechanisms, e.g., a certificate generated in accordance with the International Telecommunication Union (ITU) X.509 recommendation. The identity of the certificate issue is held in subject fields as a hierarchically structured name, email address, uniform resource identifier (URI) or other unique identifier. This identity may be used to specify a user account on which the user's applications data are maintained. As previously stated, access to data center resources is controlled by a user's overall applied policy, which is discussed further below. Policy regulator 245 applies the applicable policies in a predetermined order of precedence to produce an overall effective user policy upon a successful user logon to the data center 200], and [ ¶45, each thin client device 180a-180n will additionally have stored thereon machine certificates issued from the certificate authority of each data center 110, 120, 130 to which that particular machine is allowed access]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Dewan, Wallrabenstein, Vijayakumar, Datskos , Beuque and Hamlet with the teaching of Neumann in order to issue a certificate from CA which is used to authenticate the identity of users and machines to a requesting entity [ Neumann, ¶52]. Regarding claims 4, and 11, Dewan discloses, wherein the storage area comprises a write- protected storage area [¶53, The storage device 618 may include an attestation authority 624D to enable asymmetric device attestation using physically unclonable functions for the storage device 618. The attestation authority 624D may be located within a storage controller or a storage engine of the storage device 618], and [ ¶29, Since the public key is made available to the world while the private key never leaves the key generation/signature engine, the key generation engine is asymmetric. Additionally, the private key is never stored anywhere and is generated at runtime], and [¶23, This can be further extended to attesting the firmware of the device to a remote entity. In particular, once the hardware is attested, the ROM in the hardware can measure the firmware that is loaded and send the measurements to the application processor/attestation entity. The manufacturer can now issue a certificate for {c, K.sub.pub} and revoke the certificate if the corresponding K.sub.priv stored at the SoC is compromised]. Regarding claims 6, 13, and 19, Dewan discloses, wherein the firmware further performs the operations of: receiving a request for a digital certificate from the host processor; reading the digital certificate from a write-protected storage area, the public key generated using the device fingerprint; and returning the digital certificate to the host processor [¶23, The present techniques extend the PUF circuit in the device with a PRNG and an asymmetric key generation module. Thus, when a challenger sends the challenge c, the PUF to provides a response r. The response r is provided as a seed value to the PRNG. The PRNG generates a set of random numbers, and the first two prime numbers are used to generate Rivest, Shamir, and Adelman (RSA) keys (K.sub.pub and K.sub.priv). The key derivation block subsequently releases the K.sub.pub to the SoC and the software. The manufacturer of the device takes as input the challenge and public key {c, K.sub.pub} and provides a certificate corresponding to the challenge and public key {c, K.sub.pub}. The certificate attests the authentic identity of the device to any entity, such as an application processor. This can be further extended to attesting the firmware of the device to a remote entity]. Furthermore, Wallrabenstein discloses device fingerprint [¶31]. Dewan, Wallrabenstein ¸ Vijayakumar ,Datskos and Hamlet do not explicitly disclose; however, While Beuque discloses the digital certificate associated with a public key corresponding to the private key and a common name (CN) field identifying a user and used as login information [0006, 0111-0120]. Furthermore, Neumann discloses: [¶55, a certificate issued from CA 235 identifies a user to the data center 200 via well-known mechanisms, e.g., a certificate generated in accordance with the International Telecommunication Union (ITU) X.509 recommendation. The identity of the certificate issue is held in subject fields as a hierarchically structured name, email address, uniform resource identifier (URI) or other unique identifier. This identity may be used to specify a user account on which the user's applications data are maintained. As previously stated, access to data center resources is controlled by a user's overall applied policy, which is discussed further below. Policy regulator 245 applies the applicable policies in a predetermined order of precedence to produce an overall effective user policy upon a successful user logon to the data center 200]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Dewan, Wallrabenstein, Vijayakumar, Datskos, Beuque, and Hamlet with the teaching of Neumann in order to issue a certificate from CA which is used to authenticate the identity of users and machines to a requesting entity [ Neumann, ¶52]. Claims 7, 14, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over US Patent No. (US2019/0305973) (filed in IDS 10/12/2022) issued to Dewan and further in view of US Patent No. (US2019/0138753) issued Wallrabenstein, and further in view of (NPL: On Improving Reliability of SRAM-Based Physically Unclonable) issued to Arunkumar Vijayakumar, and further in view of US Patent No. ( US2023/0143362) issued to Datskos, and further in view of Hamlet (US8848905), and further in view of Beuque ( US2004/0125959), and further in view of US Patent No. (US2006/0041761) issued to Neumann and further in view of US Patent No. (US20200067711A1) issued to Abadir. Regarding claims 7, 14, and 20, Dewan, Wallrabenstein, Vijayakumar, Datskos, Beuque, Hamlet and Neumann do not explicitly disclose; however, Abadir discloses, wherein the firmware further performs the operations of: receiving a second message from the host processor [¶4, receiving, from an electronic device, a request to initiate a session of the service (from the service electronic device)]; and the second message including an authentication token received from a server after logging into the server using the CN field and encrypted using the public key; decrypting the authentication token to obtain a decrypted authentication token [¶4, transmitting the encrypted authentication token to the electronic device. The method includes, by the electronic device, receiving the encrypted authentication token, retrieving a public key and a private key associated with the electronic device from a data store, retrieving a service public key from a data store, where the service public key is associated with the service, decrypting the encrypted authentication token using the private key to obtain the authentication token], and [¶23, typical out- of-band authentication process may involve providing: 1) a username and password of a user (first factor) to a webpage, application, or service]; and and generating a signed message, the signed message generated by signing data, the data including the authentication token [ ¶4, signing the authentication token with the private key to generate a signed authentication token]. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Dewan, Wallrabenstein, Vijayakumar, Datskos, Beuque , Hamlet and Neumann with the teaching of Abadir in order for performing out-of-band user authentication includes, by a service electronic device associated with a service a request to initiate a session of the service, generating an authentication token, encrypting the authentication token to generate an encrypted authentication token, and transmitting the encrypted authentication token to the electronic device[ Abadir, Abstract]. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Davies ( US2023/0362019)[ ¶86, the submitting party 103S could be using the ePUF 500 to produce a response for use as a key, or as a seed for generating a key. E.g. this could be used as a cryptographic key to encrypt or sign a message, e.g. to sign a part of a blockchain transaction.], and [¶171, In further variants of the method of FIG. 7, the response data stored in the response data store 601 may not comprise a record of the CR pair(s) generated at set-up. Instead, the response data may comprise a public key of a public-private key pair, or a set of such public keys, wherein each of the one or more key pairs was generated based on a respective PUF response Ri from the set-up phase 702. E.g. the response Ri may be used as a seed in a public-private key-pair generation algorithm], and [ ¶148]. GB 2541013 A [ The HUR 110 is a conceptual ASIC which incorporates a PUF 120 in its design at the silicon level. It uses the PUF as a subsystem to provide the private key; that key is not stored in non-volatile memory in the HUR, it only ever exists in RAM for short periods]. Charles Herder (NPL: "Physical Unclonable Functions and Applications: A Tutorial ") [ Pages 1127-1128, SECTION II. TYPES OF PUFs: The two primary applications of PUFs are for: 1) low-cost authentication; and 2) secure key generation. These two applications have resulted from the fact that PUFs designed during the past decade have mostly fallen into two broad categories. These categories are described as “strong PUFs” and “weak PUFs.” Strong PUFs are typically used for authentication, while weak PUFs are used for key storage. Each PUF can be modeled as a black-box challenge–response system. In other words, a PUF is passed an input challenge c, and returns a response r=f(c), where f(⋅) describes the input/output relations of the PUF. The black-box model is appropriate here, because the internal parameters of f(⋅) are hidden from the user since they represent the internal manufacturing variability that the PUF uses to generate a unique challenge–response set. Such parameters would include the variability of a circuit's internal gate delay as described in the Introduction. PUF security relies on the difficulty of measurement or estimation of these parameters as well as the difficulty of manufacturing two chips with the same set of parameters. The fundamental difference between weak and strong PUFs is the domain of f (⋅), or informally, the number of unique challenges c that the PUF can process. A weak PUF can only support a small number of challenges (in some cases only a single challenge). A strong PUF can support a large enough number of challenges such that complete determination/measurement of all challenge–response pairs (CRPs) within a limited timeframe is not feasible. A. Weak PUF Model The first class of PUFs leveraging manufacturing variability are weak PUFs [also known as physically obfuscated keys (POKs)]. These PUFs can be thought of as PUFs that directly digitize some “fingerprint” of the circuit. This direct measurement results in a digital signature that can be used for cryptographic purposes. Because the fingerprint signature remains largely invariant, this means that the PUF can only be interrogated by one or a small number of challenges. In the above black-box description, this corresponds to f(⋅) having a domain of one or only a small number of inputs. Correspondingly, f(⋅) will also have a very small range, as a given challenge should always result in the same response (ignoring noise, which is considered later). One can clearly use several instances of the above black box to support more CRPs or response bits. However, this is still considered a weak PUF, because the number of responses is linearly related to the number of components subject to manufacturing variation. Explicitly stated, weak PUFs have the following properties: a small number of CRPs (linearly related to the number of components whose behavior depends on manufacturing variation); response is stable and robust to environmental conditions and multiple readings so that a challenge always yields the same response; responses are unpredictable and depend strongly on the innate manufacturing variability of the device; it is impractical to manufacture two devices with the same physical fingerprint. An example weak PUF is the power-on state of an SRAM. Although a SRAM cell is symmetric, manufacturing variability will give each cell a tendency toward a logical “1” or “0” at power-on. This variability is random across the entire SRAM, giving it a unique fingerprint on power-on that can be identified. In this case, if the “response” consists of the entire SRAM state at power-on, the notion of a “challenge” is not useful, as there is only one possible “challenge”: powering on the SRAM. The output signature is always the same (ignoring noise) (even applying multiple power cycles). One can allow for more output bits by increasing the size of the SRAM, but the response space is still linearly related to the number of components subject to manufacturing variation (each SRAM cell). The SRAM is an extreme example of a weak PUF in the sense that it only has one “CRP.” Note that since weak PUFs in general have only a small number of CRPs, these pairs must be kept secret. If a weak PUF only has one CRP, and it is revealed, then any device can emulate the PUF. For this reason, weak PUFs are well suited for use in key derivation processes. The PUF provides the randomness and secure storage, and the secret key (derived from the PUF's response bits) is never revealed during operation. Once the key is recovered by the PUF (this typically requires error correction), any cryptographic process may follow. For example, the weak PUF output may be used as the key in a keyed-hash message authentication code (HMAC) challenge–response sequence. In addition, the output may be used as a secret key to encrypt/decrypt data on the device]. AI generated the blow response: To produce a consistent SRAM PUF reading across multiple power cycles, the key strategy is to carefully select SRAM cells that exhibit strong power-up behavior, meaning they consistently settle to the same logic state (either '0' or '1') regardless of environmental variations like temperature or voltage fluctuations; this can be achieved by using techniques like cell characterization, bit selection algorithms, and potentially incorporating additional circuitry to enhance stability. Key approaches to achieve consistent SRAM PUF readings: Cell Characterization: Read multiple power-up states: Repeatedly power up the SRAM and read the state of individual cells to identify those with the most consistent responses. Analyze cell stability metrics: Develop metrics to quantify the reliability of each cell, such as the bit error rate (BER) under different conditions. Bit Selection Algorithms: Threshold-based selection: Choose cells that consistently power up to the same state within a predefined threshold of stability. Statistical analysis: Employ statistical methods to identify cells with the highest probability of maintaining a stable state. Circuit Design Techniques: Differential signaling: Use differential pairs of SRAM cells to amplify the difference between the power-up states, enhancing stability. Voltage ramping: Carefully control the power supply voltage during power-up to mitigate transient noise and improve cell reliability. Pre-charge circuits: Implement circuitry to pre-charge the SRAM cells before the actual power-up phase, potentially reducing instability. Wendong Wang (NPL: A Systematic Bit Selection Method for Robust SRAM PUFs: [ Abstract A physical unclonable function (PUF) is a digital circuit that can generate a die specifc unique and stable response, which can be used for authentication and key generation. Since no major design or manufacturing modifcations are required, exploitation of SRAMs to implement PUFs is a promising option. When initially powered up, in dividual SRAM cells acquire unique logic states based on the inherent bias of the cell. At advanced technology nodes, this bias is primarily due to unavoidable random manufacturing process variations, which are unpredictable and vary randomly from cell to cell, as well as chip to chip. When an SRAM is read out, these power-up states provide a unique output that is largely consistent during repeated power-up cycles for a given SRAM, but varies for diferent copies of the same part, as required of a PUF. However, this powerup state of SRAMs cannot be directly used (e.g. in cartographic key generation), due to unpredictability in some of the SRAM cells caused by electrical and electromagnetic noise and temperature fuctuations. We show in this paper that power-up states are also infuenced by the power supply ramp rate at power-up, which can be yet another source of cell instability. To address the general problem of instability in SRAM power-up states that can result in inconsistent responses from SRAM PUFs, we present an efective stable cell selection method to identify the cells in the SRAM that are strongly biased, thereby resistant to circuit noise, voltage and temperature changes, and also aging. The data from the Silicon experiments presented here shows that the selected stable SRAM cells are highly reliable over temperature and voltage variations, with a bit error rate (BER) close to zero. Rui Wang (NPL: Long-term Continuous Assessment of SRAM PUF and Source of Random Numbers): C. Randomness Evaluation Apart from what are important if SRAM PUFs are applied for key generation, randomness is evaluated to assess the feasibility of using SRAM PUFs as a random source [12]. Two randomness-related properties are presented below. 1) Stable cells: Both process variation and electrical noise impact the skewness of SRAM cells [4]. An SRAM cell which is always powered up to state 0 or 1 over a large number of power-ups is considered as a stable cell. More quantitatively, one-probability is introduced to assess the stability of SRAM cells. One-probability (pi) of a cell i at a certain SRAM is the probability that the response value of this cell (Ri) is ‘1’ over multiple power-ups [18], defined as: pi := Pr(Ri = 1) In practice, the cell with one-probability of zero or one over 1,000 consecutive measurements in a certain month is counted as a stable cell in that particular month. Cambou (US2020/0295954) [ 0031] non-limiting examples of measurable physical characteristics of devices used in PUF arrays are time delays of transistor-based ring oscillators and transistor threshold voltages. Additional examples include data stored in SRAM or information derived from such data. For instance, in a PUF array based on SRAM cells, an example of such physical characteristics may be the effective stored data values of individual SRAM devices (i.e., ‘0’ or ‘1’) after being subjected to a power-off/power-on cycle. Because the initial state (or other characteristics) of an individual PUF device may not be perfectly deterministic, statistics produced by repeated measurements of a device may be used instead of single measurements. In the example of an SRAM-based PUF device, the device could be power-cycled 100 times and the frequency of the ‘0’ or ‘1’ state could be used as a characteristic of that device. Other non-limiting examples of suitable characteristics include optical measurements. For instance, a PUF device may be an optical PUF device which, when illuminated by a light source such as a laser, produces a unique image. This image may be digitized and the pixels may be used as an addressable PUF array. A good PUF should be predictable, and subsequent responses to the same processing instruction should be similar to each other (and preferably identical)]. Mortiyama (US2018/0167205) [ 0071] As explained so far, in this configuration, a physically unclonable function is used as a technique for dynamically generating a private key that is used for encryption and decryption. In general, the physically unclonable function is used to derive a private key having a fixed value. In contrast, in this configuration, it is assumed that every time a signal X, which is a fixed input value, is input, an output signal of the signal generation unit, which is formed as a physically unclonable function unit, includes a different noise. By outputting an independent random number by using the noise source in this way, a different private key is generated. Therefore, in this configuration, since it is possible to use a private key that is not a fixed value because of a variation in the error included in the signal RA, it is possible to perform highly-secure data transmission compared to data transmission using a fixed secret key]. Minematsu (US2014/0137211) [ [0010] A method using a Static Random-Access Memory (SRAM) takes an advantage of that a default value of each bit upon power activation of a SRAM becomes random. This is disclosed in, for example, Non-Patent Literature 2], and [0011] In this case, in FIG. 1, the device physical information generator 120 functions as a SRAM, and input information to be inputted to the device physical information generator 120 is a bit position in the SRAM. In this case, the physical information mapping unit 130 simply outputs a default value of the bit position given as input information upon power activation. Upon authentication of the device terminal 150, the terminal device 150 generates this bit value in advance and registers the bit value in the server 160 in default setting processing. Upon authentication, the server 160 receives the bit value generated by the terminal device 150 then, and checks this bit value and a value registered in default setting processing. Cammarota (US2016/0364582) [ ¶32, Other types of challenge value generators can also be used by the MED 110 to generate the challenge value to be presented to the PUF module 115. The size of the challenge value can vary and may be dependent upon the size of the memory 130 for which the data is to be encrypted. The challenge value can include a sufficient number of bits to ensure that each block of the memory 130 can be protected with a unique challenge value]. CENG, Bo-hao (CN108243003) [FIG. 1 is a simplified block diagram of a device comprising a plurality of programmable resistive memory units and a controller, the controller for executing the PUF in the programmable resistive memory unit stored in a data set. In this case, the device comprises an integrated circuit 100, the integrated circuit 100 has a memory formed using programmable resistive memory cell of the memory using programming a PUF to create and store a unique data set, which can be used, for example, as a unique chip ID for authentication or key encryption protocol, or other types of secret or unique data value]. Hamlet (US 8848905 B1) [ (19) PUFs can be broadly categorized as delay based and memory based. Delay based PUFs, such as a ring oscillator PUF and an arbiter, measure the difference in delay through "identical" circuits. Memory based PUFs exploit variations in memory structures, such as cross-coupled logic gates and latches and SRAM cells;(40) the ID may be a serial number physically displayed on the part (e.g., sticker, engraving, printed, etc.) or it may be electronically stored within device 505 (e.g., within non-volatile memory).]. LU (US2018/0131527) [0010] FIG. 1 is a block diagram of a physically unclonable function (PUF) device 10 in accordance with some embodiments. Referring to FIG. 1, the PUF device 10 includes a memory block 11 such as a random-access memory (RAM) block or a static random-access memory (SRAM) block, a pseudo random number generator (PRNG) 12, a counter 14, multiplexers 15, 17, a row decoder 16, a bit multiplexer 18, a barrel shifter 19 and fuse devices 141, 151 and 171. The PUF device 10, an SRAM-based PUF, is configured to generate a response in response to a challenge. A challenge refers to an input to the PUF device 10, which indicates a specific cell address in the memory block 11, while a response refers to an output of the PUF device 10 in response to an input, which reads a data value stored in an indexed cell]. AWAN (US2019/0369902) [0029] Referring now to FIG. 2, a method of authenticating a storage device according to one aspect of the present embodiments is shown. At step 210, a unique value may be stored in a one-time programmable memory component, e.g., a DRAM, an SRAM, etc. In some embodiments, the one-time programmable memory component may reside within the controller of the disk drive 100. It is appreciated that the unique value may be signed or encrypted using an internal private key which can be validated using a public key. For example, the unique value stored on a DRAM may be signed and the DRAM's physical unclonable function (PUF) can be used to ensure that the device has not been tampered with. Bikumala (US2019/0238519) [ 0030] SOC 115 is an integrated circuit that integrates one or more components of a computer system. SOC 115 can include digital, analog, mixed-signal, and radio-frequency (RF) functions on a substrate. SOC 115 integrates at least a microcontroller or a microprocessor and a memory 120. As shown in FIG. 1, memory 120 includes a provisioned seed 125. In addition to memory 120, SOC 115 further includes a physical unclonable function (PUF) 130 (also called a physically unclonable function), and a random number generator (RNG) 135]. WO2019/027839A1 [ [0020] Methods to create binary random number generators (RNGs) from PUFs may utilize static random-access memory (SRAM), dynamic random-access memory (DRAM), Flash RAMs, Resistive RAM (ReRAM), or spin transfer torque magnetic random-access memory (STT MRAM). Intrinsic variations due to manufacturing variations in the memory arrays are exploited for binary random number generators. [0021] A method to generate random numbers with such PUF device-based systems involves characterizing a particular parameter T of the cells of the memory array in the PUF device with a "built-in self-test" (BIST) module. Each cell being different, the value of parameter T varies (in some cases, only by small amounts) cell to cell and follows a distribution with a median value T. In typical applications, the parameter T may be, for example, the set voltage Vset for a particular memory cell (i.e., the required voltage that must be applied to the memory cell to change its value). Due to manufacturing variance, each cell in a particular memory array may have different Vset values. In some cases, determining the parameter T value for a particular cell may involve sampling the parameter T values multiple times (the samples may vary by small amounts from one sample to the next) and then determining an average value of the various sample’s parameter T values. [0022] For challenge and response generation, all cells with T below T can be associated with a first value "0" and cells with T above T can be associated with a second value "1". The cells of memory arrays are segmented between the predictable cells, which reliably produce a "1" or "0", and other cells that are associated with a value of "X". Such cells are unstable and produce a value close to the threshold T. Upon taking multiple samples of the parameter T value for such an unstable or "X" cell, the parameter T values will sometimes be below the threshold T and sometimes above the threshold T. For example, unstable cells may be those cells (e.g., within a memory array) having a parameter T value that is very close to the median value T. These characteristics enable the design of both solid PUFs and ternary random number generators (TRNGs), as described herein. Chang (US2018/0278418) [ ¶23, The packaged integrated circuit or multichip module can include logic to execute a function, including a physical unclonable function such as, for example, functions described herein that rely on charge-trapping non-volatile memory cells as the physical circuits, using a set of memory cells in the memory array to produce the initial PUF key, and a random number generator to produce a random number to be combined by combinatorial logic to produce an enhanced key]. Cambou (US2017/0046129) [ Abstract, A method of identifying a memory cell state for use in random number generation (RNG) includes comparing at least one physical parameter of a memory cell with a threshold value of the physical parameter and identifying a relationship of the at least one physical parameter of the memory cell to the threshold value. A state of 0, 1, or X is associated to the memory cell based on the relationship of the at least one physical parameter to the threshold value. At least one state storage memory cell is programmed with a value corresponding with the associated 0, 1, or X state. The programmed value of the at least one state storage memory cell is included in an RNG data stream.], and [ see other paragraphs for PUF pattern]. WO(2012/136763 A2)( read the entire application ) [ Abstract, A random number generating system for generating a sequence of random numbers comprising a memory, the memory being writable, volatile and configured such that the memory contains an at least partially random memory content upon each powering-up of the memory, an instantiating unit configured for seeding the random number generating system with a seed dependent upon the at least partially random memory content, the sequence of random numbers being generated in dependence upon the seed, and an over-writing unit configured for over-writing at least part of the memory with random numbers generated by the random number generating system in dependence upon the seed]. KR 20150117226 A [ Figs. 7 and 8 are flowcharts illustrating a secure communication method according to an embodiment. The secure die-chip included in the authentication device is performing secure communication with the support of the smart card die-chip. FIG. 7 shows a receiving process of a session key for secure communication, and FIG. 8 shows secure transmission of data using the session key. 7, in step 710, a server or another device to securely communicate with the authentication device 700 encrypts the session key to be used for communication with the public key corresponding to the private key of the authentication device 700. [ Then, the encrypted session key 701 is transmitted to the device through the wide band, and the device transmits the encrypted session key 701 to the authentication device 700 (702). An interface of the smart card die-chip included in the authentication device 700 at the time of transmission may be used, such as Bluetooth, SD card slot, NFC, USB, and the like. When the smart card die-chip passes the encrypted session key 703 to the secure die-chip, the decryption of this session key is performed via the private key provided by the PUF in step 720. [ Whereby the authentication device 700 acquires the session key used for secure communication. Referring to FIG. 8, a message 801 that the device intends to transmit via secure communication is delivered to the smart card die-chip using the interfaces, and then transmitted 802 to the secure die-chip. Then, at step 810, the secure die-chip of the authentication device 800 performs encryption of the message 802 using the session key obtained above. The encrypted message 803 is delivered to the smart card die-chip, which is again communicated to the device via the interface (804). The device again forwards the encrypted message 805 to the server or other device over wideband communication, and in step 820 the decryption of the message using the session key is performed. WO 2018235799 A [ If the ECU 3 determines that the device is a valid device, the gateway 2 encrypts the session key stored therein by using the ECU public key corresponding to the ECU 3. The gateway 2 transmits the encrypted session key to the ECU 3. The ECU 3 having received the encrypted session key decrypts the session key using the ECU secret key stored therein. As a result, the ECU 3 can acquire a session key, and in the subsequent communication, can use the session key to generate / verify a message authenticator. YU (2013/0010957) [0040] Establishing a session key requires relatively little computation at the device. For example, as compared to using a PUF to generate a key to sign or encrypt a session key generated by the device, the approach does not require reliable regeneration of an exact device root key or temporary storage of the device root key between generations of session keys. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHAHRIAR ZARRINEH whose telephone number is (571)272-1207. The examiner can normally be reached Monday-Friday, 8:30am-5:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached at 571-272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHAHRIAR ZARRINEH/Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Show 18 earlier events
Sep 25, 2025
Response Filed
Nov 18, 2025
Final Rejection mailed — §103
Jan 20, 2026
Response after Non-Final Action
Feb 18, 2026
Request for Continued Examination
Feb 28, 2026
Response after Non-Final Action
Apr 07, 2026
Non-Final Rejection mailed — §103
Jul 07, 2026
Response Filed
Sep 17, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748883
Systems and Methods for Providing Improved Account Management Services
3y 9m to grant Granted Sep 29, 2026
Patent 12739110
METHOD, ELECTRONIC DEVICE, AND COMPUTER PROGRAM PRODUCT FOR IDENTITY AUTHENTICATION
2y 9m to grant Granted Sep 15, 2026
Patent 12732378
IMPLEMENTING LOGIC GATE FUNCTIONALITY USING A BLOCKCHAIN
7y 10m to grant Granted Sep 08, 2026
Patent 12695598
SYSTEMS AND METHODS FOR STORAGE, GENERATION AND VERIFICATION OF TOKENS USED TO CONTROL ACCESS TO A RESOURCE
3y 1m to grant Granted Jul 28, 2026
Patent 12683782
MUTUAL MULTI-FACTOR AUTHENTICATION TECHNOLOGY
5y 7m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

9-10
Expected OA Rounds
77%
Grant Probability
84%
With Interview (+6.9%)
2y 8m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 458 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month