Prosecution Insights
Last updated: October 02, 2026
Application No. 18/222,297

SCALABLE DATA OBFUSCATION FOR DIFFERENT IDENTIFIER TYPES

Non-Final OA §101§103
Filed
Jul 14, 2023
Examiner
MUNGUIA, DUILIO
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
71%
Grant Probability
Favorable
1-2
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 71% — above average
71%
Career Allowance Rate
10 granted / 14 resolved
+11.4% vs TC avg
Strong +67% interview lift
Without
With
+66.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
12 currently pending
Career history
37
Total Applications
across all art units

Statute-Specific Performance

§101
3.9%
-36.1% vs TC avg
§103
72.9%
+32.9% vs TC avg
§102
14.2%
-25.8% vs TC avg
§112
5.8%
-34.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 14 resolved cases

Office Action

§101 §103
Detailed Action Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted in on 07/14/2023 is being considered by the examiner. Specification The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification. Drawings Drawing objection elements 214, 216, 217, 220, 222, and 224, of fig. 2 appears to be boxes with numbers and having labels for them would help one to understand the drawings/applicants invention better. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea, without significantly more. The claims recite a mathematical concepts including “…determining a domain size of the input value”, “determining a rank score of the input value”, “using the domain size and the rank score to generate a unique value…”, “unranking the unique value by converting characters of the unique value to create a masked string value”. The claims further recite generic computer implementation, such as a processor, logic and computer-readable storage medium, and generic data-receiving and data replacement steps. These additional elements do not integrate the judicial exception into a practical application. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. Dependent claims 2-9, 11-18, and 20 taken individually do not amount to “significantly more” than just the abstract idea either. Therefore claims 1-20 are directed to an abstract idea. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Sloane et al. (US-20210248154-A1 hereafter Sloane), in view of Wu et al. (US-20220253544-A1 hereafter Wu). Regarding claim 1 Sloane a computer-implemented method, comprising: receiving a request to mask an input value (see Sloane par.0037: “the system receives a data transmission from the managing entity system 300 or the remote server(s) 400, containing a dataset to be obfuscated as well as associated metadata containing a plurality of decision factors to be utilized by the decision engine 270. The decision factors may include but are not limited to factors such as data type”); and replacing the input value with the masked string value (see Sloane par.0038-0039: “The process may then continue to block 630, where for each value or set of values to be format-preserved, the system may determine a sequence of obfuscation algorithms to be applied to the data to maximize obfuscation complexity while preserving computational power. In 640 of FIG. 3, the process continues with the sequence of format-preserving obfuscation algorithms being applied to the dataset via the format-preservation module 280. The output of this step is an obfuscated dataset, where all, some, or none of the data values within the set may match the original data format.”). Sloane do not explicitly teach in response to receiving the request, determining a domain size of the input value; determining a rank score of the input value; using the domain size and the rank score to generate a unique value correlated with the input value; unranking the unique value by converting characters of the unique value to create a masked string value. In this instance examiner notes the teaching of prior art reference Wu. With regards to applicant’s claim limitation elements of, response to receiving the request, determining a domain size of the input value (see Wu par.0015-0016: “At 104, the tree data-structure is identified having a domain of values representing all the variations of a set of characters that satisfy the format within which the data string is defined…A first offset value is calculated for individual characters of the data string relative to the domain of values in the tree data-structure. This first offset value is indicative of one or more calculations occurring relative to each of the individual characters of the data string.”); determining a rank score of the input value (see Wu par.0016: “At 108, a ranking value of the data string is calculated relative to the offset value calculated for each of the individual characters of the data string.”); using the domain size and the rank score to generate a unique value correlated with the input value (see Wu par.0031-0038: “A first calculation is to identify the step count of the letter “A” in the character count of the characters in the character set A-Z. The character count of the character set A-Z is twenty-six (26) because there are 26 characters in the set. Because “A” is the first character in the character set A-Z, the step count to get to the letter “A” within the set is zero (0). To clarify, to identify a step count for a character in a character set, the first character in the set is identified with a step count of zero, the second character in the set is identified with a step count of one, the third character in the set is identified with a step count of 2, and so forth. So for the character set A-Z, the step count of the character “A” is zero (0), the step count of the character “B” is one (1), the step count of the character “C” is two (2), and so forth through the character set, with the final step count of the character “Z” being twenty-five (25). A next calculation is to divide the node value 17,576,000 (of node 240), by the character count of 26 to identify an intermediate offset value of 676,000. This intermediate offset value is then multiplied by the character “A” step count of zero (0) to identify the final offset value of the character “A”, which is zero (0) in this instance. These calculations for identifying the offset value for the individual character “A” are summarized as follows: For the character “A”: 26=character count of character set A-Z 0=step count of character “A” in character count of character set 17,576,000=node value (node 240) 17,576,000/26=676,000 intermediate offset 676,000×0 step count=0 offset value for individual character “A””, furthermore par.0039-0074. Par.0075-0084: “the final ranking value for the data string “ABC123” is calculated as follows: 1,757,600 (domain value of first (left) branch at node 204) +174,002,400 (domain value of second (middle) branch at node 216) +0 (offset of character “A”) +26,000 (offset of character “B”) +2,000 (offset of character “C”) +100 (offset of character “1”) +20 (offset of character “2) +3 (offset of character “3”) 175,788,123 (ranking value) (unique value) The ranking value of 175,788,123 may then be encrypted, using format preserving encryption for example, into a cipher value.”); unranking the unique value by converting characters of the unique value to create a masked string value (see Wu par.0017: “the cipher value is de-ranked into a cipher string of individual characters. This is accomplished by referencing the cipher value and a second offset value calculated relative to the domain of values from the tree data-structure to identify each of the individual characters of the cipher string. This second offset value is also indicative of one or more calculations relative to the domain of values for identifying each of the individual characters in the cipher string. The resulting cipher string (masked string value) is a format preserving encryption cipher string representative of the data string.”). Therefore It would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have combined Sloane teaching “there is a need to dynamically choose the most effective data obfuscation algorithms for implementation. By using machine learning techniques, the present invention provides the functional benefit of analyzing both the data to be obfuscated, as well as available computational resources, to determine when it is appropriate to apply a format-preserving masking algorithm to the data. Accordingly, the present invention may ensure that organizational data is appropriately masked while preventing the resource strain associated with preserving the format of all original data.”, (see Sloane par.0024) with Wu teaching because Wu teaching of, “computing systems to rank a data string into a ranking value, and de-rank a cipher value, representative of an encrypted version of the ranking value, into a cipher string, using a tree data-structure. This ranking and de-ranking using the tree data-structure works well for format-preserving encryption (FPE) purposes. The tree data-structure defines domain values representative of variations of a set of characters that satisfy a format within which the data string is defined. The data string is processed relative to the tree data-structure and converted to a ranking value based on offset values, relative to the domain values, for each character of the data string. The resulting ranking value is FPE encrypted to generate a cipher value. The cipher value is then processed using the tree data-structure and, based on offset values calculated relative to the domain values, the cipher value is de-ranked into a cipher string that is an FPE cipher of the data string.”, (see Wu par.0009). The reason to combine would have been to create a dynamic data masking. Regarding claim 10 is a computer program product, claim that recites similar limitations as the method claim 1 and is rejected based on the same rational as claim 1. comprising a computer readable storage medium having program instructions embodied therewith, the program instructions readable by a processor, executable by the processor, or readable and executable by the processor (see Sloane par.0034: “”the processing device 220 may include a control unit, a digital signal processor device, a microprocessor device, and various analog-to-digital converters, digital-to-analog converters, and other support circuits and/or combinations of the foregoing. Control and signal processing functions of the data obfuscation system 200 may be allocated between these processing devices according to their respective capabilities…a processing device may be “configured to” perform a certain function in a variety of ways, including, for example, by having one or more general-purpose circuits perform the function by executing particular computer-executable program code embodied in computer-readable medium, and/or by having one or more application-specific circuits perform the function.), to cause the processor to: Regarding claim 19 is a system claim that recites similar limitations as the method claim 1 and is rejected based on the same rational as claim 1. a processor (see Sloane par.0034: “the processing device 220 may include a control unit, a digital signal processor device, a microprocessor device, and various analog-to-digital converters, digital-to-analog converters, and other support circuits and/or combinations of the foregoing. Control and signal processing functions of the data obfuscation system 200 may be allocated between these processing devices according to their respective capabilities”); and logic integrated with the processor, executable by the processor, or integrated with and executable by the processor (see Sloane par.0034: “The processing device 220 may further include functionality to operate one or more software programs based on computer-executable program code 240 thereof, which may be stored in a memory device 230, such as the processing system application 250 and the decision engine 270. As the phrase is used herein, a processing device may be “configured to” perform a certain function in a variety of ways, including, for example, by having one or more general-purpose circuits perform the function by executing particular computer-executable program code embodied in computer-readable medium, and/or by having one or more application-specific circuits perform the function.”), the logic being configured to: Regarding claim 2 Sloane in view of Wu disclose the computer-implemented method of claim 1, Wu further disclose wherein the domain size and the rank score are based at least in part on a number of potential values each character in the input value can have (see Wu par.0018: “This tree data-structure depicts an example domain that satisfies a character format defined by the following regular expression labeled (1): ([1-9][A-Z]{3})|[0-9]{3})|([0-9]{3}[A-Z]{3})|([A-Z]{3}[0-9]{3})”, par.0030: “the ranking value of the data string “ABC123” is identified with respect to a first offset value calculated for individual characters (each individual character) of the data string relative to the domain of values of the tree data-structure. This first offset value is indicative of one or more calculations occurring relative to each individual character evaluated. Then, the offset value of each of the individual characters is summed up to identify the final ranking value of the data string, including with respect to any offset values of sibling nodes skipped (e.g., nodes 204, 216) when identifying node 240 as the branch to traverse.”). Therefore It would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have combined Sloane in view of Wu teaching of claim 1 with Wu teaching because Wu teaching of, “Upon execution of the regular expression or receipt of the data string, the tree data-structure internal representation provides the ability to rank and de-rank the data string that conforms to the regular expression or data string format. The tree data-structure enables data strings (that satisfy the defined format, e.g., as defined by the regular expression) to be converted into their ordinal ranking value within the set of all strings defined by the format or regular expression. The tree data-structure also enables the reverse process to occur for de-ranking the ranking value into a cipher string. Representing regular expressions (or format defined strings) in an intermediate form of a tree data-structure, allows input data strings to be ranked and de-ranked efficiently while the overhead of processing and compiling the regular expression library or defined format occurs only once.”, (see Wu par.0012). Regarding claim 11 is a computer program product, claim that recites similar limitations as the method claim 2 and is rejected based on the same rational as claim 2. Regarding claim 3 Sloane in view of Wu disclose the computer-implemented method of claim 1, Wu further teaches wherein determining the rank score of the input value includes: converting each of the characters in the input value into a respective integer value (see Wu par.0075-0084: “A proper ranking scheme must have an exact 1:1 correspondence between input data string and rank value. Accordingly, the final ranking value for the data string “ABC123” is calculated as follows: 1,757,600 (domain value of first (left) branch at node 204) +174,002,400 (domain value of second (middle) branch at node 216) +0 (offset of character “A”) +26,000 (offset of character “B”) [0080] +2,000 (offset of character “C”) +100 (offset of character “1”) +20 (offset of character “2) +3 (offset of character “3”) 175,788,123 (ranking value)”); and combining the integer values to determine the rank score (see par.0075: “the final ranking value of the data string “ABC123” is identified relative to the tree data-structure and the offset values calculated. This is accomplished by summing up all the individual character offset values identified, and adding in the offset value of the third (right) branch node 240 relative to the tree data-structure.”, par.0076-0084: “the final ranking value for the data string “ABC123” is calculated as follows: 1,757,600 (domain value of first (left) branch at node 204) +174,002,400 (domain value of second (middle) branch at node 216) +0 (offset of character “A”) +26,000 (offset of character “B”) [0080] +2,000 (offset of character “C”) +100 (offset of character “1”) +20 (offset of character “2) +3 (offset of character “3”) 175,788,123 (ranking value)”). Therefore It would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have combined Sloane in view of Wu teaching of claim 1 with Wu teaching because Wu teaching of, “Upon execution of the regular expression or receipt of the data string, the tree data-structure internal representation provides the ability to rank and de-rank the data string that conforms to the regular expression or data string format. The tree data-structure enables data strings (that satisfy the defined format, e.g., as defined by the regular expression) to be converted into their ordinal ranking value within the set of all strings defined by the format or regular expression. The tree data-structure also enables the reverse process to occur for de-ranking the ranking value into a cipher string. Representing regular expressions (or format defined strings) in an intermediate form of a tree data-structure, allows input data strings to be ranked and de-ranked efficiently while the overhead of processing and compiling the regular expression library or defined format occurs only once.”, (see Wu par.0012). Regarding claim 12 is a computer program product, claim that recites similar limitations as the method claim 3 and is rejected based on the same rational as claim 3. Regarding claim 4 Sloane in view of Wu disclose the computer-implemented method of claim 1, Wu further teaches wherein using the domain size and the rank score to generate the unique value includes: applying a format preserving encryption algorithm, a format preserving tokenization algorithm, or a format preserving encryption algorithm and a format preserving tokenization algorithm, to the rank score to generate the unique value (see Wu par.0009: “This ranking and de-ranking using the tree data-structure works well for format-preserving encryption (FPE) purposes. The tree data-structure defines domain values representative of variations of a set of characters that satisfy a format within which the data string is defined. The data string is processed relative to the tree data-structure and converted to a ranking value based on offset values, relative to the domain values, for each character of the data string. The resulting ranking value is FPE encrypted to generate a cipher value.”). Therefore It would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have combined Sloane in view of Wu teaching of claim 1 with Wu teaching because Wu teaching of, “Ranking manager 714 ranks a data string (e.g., for format-preserving encryption) using a tree data-structure according to the example methods previously described. The data string may be defined within the format of any regular expression or other pre-defined format for which the tree data-structure is defined.”, (see Wu par.0166). The reason to combine would have been to protect sensitive data in case the sensitive is stolen and make the attacker believe it has stolen unencrypted sensitive data. Regarding claim 13 is a computer program product, claim that recites similar limitations as the method claim 4 and is rejected based on the same rational as claim 4. Regarding claim 5 Sloane in view of Wu disclose the computer-implemented method of claim 4, Wu further teaches wherein the format preserving encryption algorithm and the format preserving tokenization algorithm use the domain size and the rank score (see Wu par.0009: “This ranking and de-ranking using the tree data-structure works well for format-preserving encryption (FPE) purposes. The tree data-structure defines domain values representative of variations of a set of characters that satisfy a format within which the data string is defined. The data string is processed relative to the tree data-structure and converted to a ranking value based on offset values, relative to the domain values, for each character of the data string. The resulting ranking value is FPE encrypted to generate a cipher value.”). Therefore It would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have combined Sloane in view of Wu teaching of claim 4 with Wu teaching because Wu teaching of, “Ranking manager 714 ranks a data string (e.g., for format-preserving encryption) using a tree data-structure according to the example methods previously described. The data string may be defined within the format of any regular expression or other pre-defined format for which the tree data-structure is defined.”, (see Wu par.0166). The reason to combine would have been to protect sensitive data in case the sensitive is stolen and make the attacker believe it has stolen unencrypted sensitive data. Regarding claim 14 is a computer program product, claim that recites similar limitations as the method claim 5 and is rejected based on the same rational as claim 5. Regarding claim 6 Sloane in view of Wu disclose the computer-implemented method of claim 1, Sloane further disclose wherein the masked string value includes a same format as the input value (see par.0038-0039: “the system may decide to preserve the format of the entire dataset, only certain values of the dataset, or no values of the dataset. The process may then continue to block 630, where for each value or set of values to be format-preserved, the system may determine a sequence of obfuscation algorithms to be applied to the data to maximize obfuscation complexity while preserving computational power. In 640 of FIG. 3, the process continues with the sequence of format-preserving obfuscation algorithms being applied to the dataset via the format-preservation module 280. The output of this step is an obfuscated dataset, where all, some, or none of the data values within the set may match the original data format.”). Regarding claim 15 is a computer program product, claim that recites similar limitations as the method claim 6 and is rejected based on the same rational as claim 6. Regarding claim 7 Sloane in view of Wu disclose the computer-implemented method of claim 1, Wu further disclose wherein determining the domain size of the input value includes: converting the characters in the input value into integer values (see par.0023: “the tree data-structure 200 at the root node 202, the domain of values representative of all variations of the set of characters that satisfy the character format defined by the regular expression (1) totals 193,336,000 (depicted as the node value of the node 202). Three branches stem from the root node 202, each depicting a subdomain of values representative of a subset of the variations of the set of characters that satisfy the character format within which the data string is defined (e.g., defined by the regular expression (1)). The first (left) branch, at node 204, identifies a node value indicating that there are 1,757,600 subdomain values representative of the number of variations of the set of characters that start with the character (number) zero (0) and also satisfy the character format defined by the regular expression (1). The second (middle) branch, at node 216, identifies a node value indicating that there are 174,002,400 subdomain values representative of the number of variations of the set of characters that start with any character of one through nine (1-9) and satisfy the character format defined by the regular expression (1). The third (right) branch, at node 240, identifies a node value indicating that there are 17,576,000 subdomain values representative of the number of variations of the set of characters that start with a letter A through Z (A-Z) and satisfy the character format defined by the regular expression (1).”, furthermore par.0031-0032); and combining the integer values to form the domain size (see Wu par.0023: “the root node 202, the domain of values representative of all variations of the set of characters that satisfy the character format defined by the regular expression (1) totals 193,336,000 (domain size) (depicted as the node value of the node 202).”, par.0076: “1,757,600 (domain value of first (left) branch at node 204) +174,002,400 (domain value of second (middle) branch at node 216)”). Therefore It would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have combined Sloane in view of Wu teaching of claim 1 with Wu teaching because Wu teaching of, “the initial data string is an encrypted cipher string that is processed relative to the tree data-structure and ranked to an encrypted cipher ranking value based on offset values, relative to the domain values, for each character of the cipher string. The resulting cipher ranking value is then decrypted to generate a decrypted value. The decrypted value is then processed using the tree data-structure and, based on offset values calculated relative to the domain values, the decrypted value is de-ranked into a decrypted data string relative to the initial encrypted cipher string.”, (see Wu par.0163). The reason to combine would have been to Add an additional layer of security and privacy control to protect sensitive data. Regarding claim 16 is a computer program product, claim that recites similar limitations as the method claim 7 and is rejected based on the same rational as claim 7. Regarding claim 8 Sloane in view of Wu disclose the computer-implemented method of claim 1, Wu further disclose wherein using the domain size and the rank score to generate the unique value includes generating a secure hash value of the rank score (see Wu par.0016: “At 106, a first offset value is calculated for individual characters of the data string relative to the domain of values in the tree data-structure. This first offset value is indicative of one or more calculations occurring relative to each of the individual characters of the data string. At 108, a ranking value of the data string is calculated relative to the offset value calculated for each of the individual characters of the data string. At 110, the ranking value of the data string is encrypted into a cipher value (secure hash value).”). Therefore It would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have combined Sloane in view of Wu teaching of claim 1 with Wu teaching because Wu teaching of, “The resulting cipher string is a format preserving encryption cipher string representative of the data string.”, (see par.0017). The reason to combine would have been to trick cyber-criminal into believing they have the plaintext data. Regarding claim 17 is a computer program product, claim that recites similar limitations as the method claim 8 and is rejected based on the same rational as claim 8. Regarding claim 9 Sloane in view of Wu the computer-implemented method of claim 8, Wu further teaches wherein unranking the unique value includes: applying a number of potential values each character in the input value can have to each character of the unique value to generate entries of the masked string value (see par.0085-0086: “This cipher value is then de-ranked using the tree data-structure 200 to identify a cipher string having individual cipher characters representative of the input data string “ABC123”. The de-ranking occurs by identifying a “second” offset value relative to the cipher value and the domain of values (e.g., node values) of the tree data-structure. This second offset value again is indicative of one or more calculations occurring relative to the node values for identifying each individual character that is a cipher character of the individual characters in the input data string “ABC123”. FIGS. 4-6 will now be discussed together for describing the de-ranking of a cipher value into a cipher string.”, par.0090: “node 216 is associated with the character set 1-9, so the character count is 9. Therefore, 174,002,400 node value/9 character count=19,333,600 step size (SS). Next, the step offset 98,242,400 is divided by the step size 19,333,600 to identify a step count (SC) of 5. This means that five steps are counted in the character set to identify the first de-rank cipher character. In this instance, with the current character set 1-9, five steps, or in other words skipping five characters in the set (5+1), identifies the character “6” (entries) within the set. This is the first de-ranked cipher character for the cipher string.”, furthermore par.0091-151); and aggregating the entries in a predetermined order to form the masked string value (see Wu par.0162: “the resulting de-ranking cipher string of “6890ZW” is shown. This cipher string comprises individual characters identified with respect to a second offset value calculated in the domain of values of the tree data-structure relative to the cipher value for each character.”). Therefore It would have been obvious to someone of ordinary skill in the art before the effective filing date of the claimed invention to have combined Sloane in view of Wu teaching of claim 8 with Wu teaching because Wu teaching of, “the initial data string is an encrypted cipher string that is processed relative to the tree data-structure and ranked to an encrypted cipher ranking value based on offset values, relative to the domain values, for each character of the cipher string. The resulting cipher ranking value is then decrypted to generate a decrypted value. The decrypted value is then processed using the tree data-structure and, based on offset values calculated relative to the domain values, the decrypted value is de-ranked into a decrypted data string relative to the initial encrypted cipher string.”, (see par.00163). The reason to combine would have been to maintains the integrity of the original data by concealing sensitive elements while retaining the structure and format required for analysis and processing. Regarding claim 18 is a computer program product, claim that recites similar limitations as the method claim 9 and is rejected based on the same rational as claim 9. Regarding claim 20 is a system claim that recites similar limitations as the method claim 9 and is rejected based on the same rational as claim 9. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Rozenberg et al.( US-20150358159-A1) ways to encrypt data while keeping the data in a usable format. It does this by building a “complex format” from smaller predefined format building blocks, called primitives. Each primitive has its own ranking and unranking methods, which let the system map between text and numbers. The system selects two or more primitives and combines them using operations such as concatenation or union. The combined format is then used to convert plaintext into ciphertext. The encrypted data can be sent to another computer. On the receiving side, the same complex format is used to decrypt the ciphertext back into the original plaintext. The approach is intended to preserve the structure of records such as SSNs, credit card numbers, dates, and addresses. Hansen et al. (US-8600048-B1) The system first turns the input string into a unique binary value, then encrypts that binary value, and then turns the result back into a string that matches a different target format. In this way, a plaintext item can become ciphertext that still fits a desired pattern or data field. The process can also be reversed so the ciphertext can be decrypted back into the original plaintext format. The application explains that the original and output formats are described by regular expressions, which act like rules for what strings are valid. It also says the underlying encryption may use format-preserving encryption so the intermediate binary stays usable for the conversion. The system can handle variable-length inputs and can even map one kind of data to a very different kind of data, such as a social security number into an email address. The approach is intended to make encrypted data easier to store, process, and pass between applications and databases. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DUILIO MUNGUIA whose telephone number is (571)270-5277. The examiner can normally be reached M-F 9:30AM - 5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DUILIO MUNGUIA/Examiner, Art Unit 2497 /ELENI A SHIFERAW/Supervisory Patent Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Jul 14, 2023
Application Filed
Nov 20, 2023
Response after Non-Final Action
Aug 25, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748872
MULTIPLE ARTIFICIAL INTELLIGENCE SYSTEMS FOR USE WITH DYNAMIC ACCESS CAPABILITIES
3y 4m to grant Granted Sep 29, 2026
Patent 12730925
MASKING COMPLIANCE MEASUREMENT SYSTEM
4y 1m to grant Granted Sep 08, 2026
Patent 12694102
In-Vehicle System and Electronic Control Device
2y 8m to grant Granted Jul 28, 2026
Patent 12683775
METHOD AND DEVICE FOR PRESERVING PRIVACY OF LINEAR REGRESSION DISTRIBUTED LEARNING
3y 2m to grant Granted Jul 14, 2026
Patent 12657331
SYSTEMS AND METHODS FOR USE IN GENERATING AUDIT LOGS RELATED TO NETWORK PACKETS
3y 9m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
71%
Grant Probability
99%
With Interview (+66.7%)
3y 0m (~0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 14 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month