Prosecution Insights
Last updated: October 02, 2026
Application No. 18/420,641

SYSTEMS AND METHODS FOR GENERATING A BLOCKCHAIN-BASED USER PROFILE

Non-Final OA §103
Filed
Jan 23, 2024
Priority
May 24, 2017 — continuation of 11/025,409 +1 more
Examiner
TRUVAN, LEYNNA THANH
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
State Farm Mutual Automobile Insurance Company
OA Round
3 (Non-Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
1y 0m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
397 granted / 519 resolved
+18.5% vs TC avg
Strong +20% interview lift
Without
With
+20.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
15 currently pending
Career history
540
Total Applications
across all art units

Statute-Specific Performance

§101
7.3%
-32.7% vs TC avg
§103
51.8%
+11.8% vs TC avg
§102
23.2%
-16.8% vs TC avg
§112
4.5%
-35.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 519 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 2. The amendment to claims 1-22, filed 6/24/2026, is acknowledged and considered for examination. Claims 1, 3-10, 12-22 are pending. Claims 21-22 are new. Claims 2 and 11 are cancelled by Applicant. Claims 1, 10, and 19 are independent claims. Continued Examination Under 37 CFR 1.114 3. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 6/24/2026 has been entered. Priority 4. The current application has relationship to the following: CON of 15604178, filing date 5/24/2017 CON of 17306529, filing date 5/3/2021 Allowable Subject Matter 5. Claim 22 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Response to Arguments 6. Applicant’s arguments with respect to claim(s) 1, 3-10, 12-22 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Applicant’s arguments are moot as they are directed towards new limitations that are now addressed by Griffin in view of Gross, et al. rejection. Claims 1, 3-10, 12-22 has overcome the rejection on the ground of nonstatutory double patenting, necessitated by the current amendment. The new limitations in the current amendment have further narrowed the claims from the claim set of US patent 11917050. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 7. Claim(s) 1, 3-10, 12-21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Griffin, et al. [US 20210211468] in view of Gross, et al [US 10997595]. As per claim 1: Griffin teaches a blockchain-based system, comprising: a processor; and [Griffin: para 0033] a memory storing computer-executable instructions that, when executed by the processor [Griffin: para 0033], cause the blockchain-based system to: receive, via a network and from a computing device, a request to perform an activity associated with a user, the request including a blockchain ID associated with the user; [Griffin: para 0020; The compliance blockchain system thus allows for a simple and effective means of selectively encrypting sensitive compliance data, while providing permissioned and selective access to various compliance information to a requesting entity (i.e. user, subscriber, client). Para 0050; the blockchain facilitator and the requesting entity each have their own respective asymmetric private KEK and public KEK certificates. The key management circuit negotiates the exchange of the blockchain facilitator certificate and the requesting entity certificate. The key management circuit generate the blockchain facilitator's asymmetric key pair and use the requesting entities public key to compute a common shared secret that can be used to generate a KEK. The “blockchain ID” may broadly be in the form of a key or certificate or other types of data that identifies the blockchain. More examples on para 0027, 0031] identify, from a blockchain, one or more blockchain transactions associated with the blockchain ID; [Griffin: para 0077-0078; compliance event data can be time stamped, encrypted, and published to the event blockchain as the compliance event occurs. The compliance event data are time stamped upon receipt, cataloged, and stored over a period of time, eventually the plurality of compliance events of the period of time are encrypted and published to the event blockchain.] generate, based on the one or more blockchain transactions, a trust profile of the user, the trust profile including a first authentication level to perform the activity; [Griffin: para 0024; The compliance data processing method allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. Specifically, the encryption techniques allow the compliance information (e.g., the adopted policies, practices, operations, incidents, monitoring, etc.) to be made available to auditors, regulators, subscribers, and legal entities by authorizing access to selective parts of the information in accordance with their credentials and clearance. As such, the policy or access to selective parts of the information suggest a first authentication level. Para 0029; the encryption techniques make it possible for the compliance information to be made available to auditors, regulators, subscribers, and attorneys by authorizing their access to selective information and providing them with any needed credentials and keys. The compliance information are available to trusted subscriber profiles or the user profile. More examples on para 0003, 0038, 0045-0046] **determine that the first authentication level is less than a threshold; [**rejected under a secondary reference, discussion below] **based on the first authentication level being less than the threshold [**rejected under a secondary reference, discussion below], determine, based on the one or more blockchain transactions, one or more events that occurred within a time period, the one or more events being associated with respective timestamps; [Griffin: para 0038, 0065-0066; examples of determination of events occurred within a time period and the events associated to timestamps based on the one or more blockchain transactions] determine, based on the respective timestamps, an event of the one or more events that provides an indication of validity to perform the activity; [Griffin: para 0032; To provide integrity, authentication, and non-repudiation, the data logs may be signed by the blockchain facilitator, or another entity with authorization to publish to the compliance blockchains, using a digital signature method. Para 0068-0069; the blockchain facilitator store all compliance event data over a first time period before selectively encrypting and publishing the plurality of the compliance event data to the event blockchain. The blockchain facilitator policy in the policy blockchain and the blockchain facilitator compliance event logs related to each subscriber are accessible by the respective subscribers to evaluate compliance of the blockchain facilitator to the service policy regarding the respective subscriber. The blockchain facilitator publishes policies and subsequent policy versions to the policy blockchain. See also 0080] determine, based on the indication of validity, that the request to perform the activity is authorized; and [Griffin: para 0058; The network interface is structured to facilitate operative communication between the auditor computing system and the blockchain facilitator computing system. The auditor key negotiation circuit requests access to view restricted information on a blockchain facilitator blockchain and negotiates with the key management circuit of the blockchain facilitator computing system a KEK to securely transport the content encryption key that corresponds to the information access level of the auditor. See also para 0080-0081] transmit, via the network, an authorization to perform the activity to the computing device. [Griffin: para 0019; the data logs may be signed by the blockchain facilitator, or another entity with authorization to publish to the compliance blockchains, using a digital signature method. Para 0024; Each of the blockchain facilitator computing system, the subscribers, the auditor, and the compliance blockchain is in operative communication with the others via a network and allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. More examples on para 0053, 0096] Griffin suggests authentication level determination by teaching the compliance data processing method allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. Specifically, the encryption techniques allow the compliance information (e.g., the adopted policies, practices, operations, incidents, monitoring, etc.) to be made available to auditors, regulators, subscribers, and legal entities by authorizing access to selective parts of the information in accordance with their credentials and clearance[Griffin: para 0024]. The encryption techniques make it possible for the compliance information to be made available to auditors, regulators, subscribers, and attorneys by authorizing their access to selective information and providing them with any needed credentials and keys [Griffin: para 0029]. The compliance information are available to trusted subscriber profiles or the user profile. However, Griffin did not clearly teach “determine that the first authentication level is less than a threshold” and determine an event “based on the first authentication level being less than the threshold”. Gross teaches the social authentication circuit to reduce the authentication requirements based on a measure of social identity, where the social authentication circuit reduce authentication requirements based on a relationship measure between the one or more parties engaged in a transaction and based on the previous transaction history between the two or more parties. The social authentication circuit determine a level of trust based on the relationship measure being above a threshold relationship measure. Different threshold relationship measures correspond to a different levels of trust and accordingly require decreasing amounts of additional authentication. The social authentication circuit assign the threshold relationship measures to differing values for a maximum currency amount that can be part of the transaction and obtain further authentication through the use of financial information associated with an account of one or more of the parties. The social authentication circuit mitigate a low relationship measure by accessing or receiving additional information about the social media use of the potential receiving party [Gross: col.5, line 42-67]. As such, by the different threshold relationship measures correspond to a different levels of trust and accordingly require decreasing amounts of additional authentication obviously suggest “determine that the first authentication level is less than a threshold” and in turn the event associated therewith. One would be motivated to “determine that the first authentication level is less than a threshold” and determine an event “based on the first authentication level being less than the threshold” to determine a measure of social identity of the receiving party and a threshold level determines the receiving party is not a fake or fraudulent identity [Gross: col.6, line 5-10]. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Gross with Griffin to teach to “based on the first authentication level being less than the threshold, determine, based on the one or more blockchain transactions, an event that provides an indication of validity to perform the activity”, for the reason to determine a measure of social identity correspond to a different levels of trust to determines the receiving party is not a fake or fraudulent identity and accordingly require decreasing amounts of additional authentication [Gross: col.15, line 57-col.6, line 10]. Claim 2: Cancelled Claim 3: Griffin: para 0031, 0050 [key or timestamped associated to the blockchain of the subscriber]; discussing the blockchain-based system of claim 1, wherein the computer-executable instructions, when executed by the processor, cause the blockchain-based system to: receive an additional blockchain ID associated with the user; identify, from the blockchain, one or more additional blockchain transactions associated with the additional blockchain ID; and update the trust profile of the user based on the one or more additional blockchain transactions. Claim 4: Griffin: para 0032 in view of Gross: col.6, line 10-20 [authentication data include biometric information such as a finger print by the party (user) to initiate the transaction, suggesting “one or more non-blockchain transactions associated with the user based on the user ID”, under the same pretext and motivation as in claim 1]; discussing the blockchain-based system of claim 1, wherein the request includes a user ID associated with the user, and the computer-executable instructions, when executed by the processor, cause the blockchain-based system to: identify, from a database, one or more non-blockchain transactions associated with the user based on the user ID; and update the trust profile of the user based on the one or more non-blockchain transactions. Claim 5: Griffin: para 0024 in view of Gross: col.1, line 50-5 and col.9, line 37-57 [weighting the relationship measure by a factor consisting of a value and types of social media associations, suggesting “assign a first weight …the second weight”, under the same pretext and motivation as in claim 1]; discussing the blockchain-based system of claim 1, wherein the event includes a first event that provides a first indication of validity to perform the activity and a second event that provides a second indication of validity to perform the activity, and the computer-executable instructions, when executed by the processor, cause the blockchain-based system to: assign a first weight to the first event; assign a second weight to the second event; and determine the indication of validity to perform the activity based on the first event with the first weight and the second event with the second weight. Claim 6: Griffin: para 0025 view of Gross: col.9, line 37-57 [associations between the parties with weighting for certain types of social media associations, the relationship measure is weighted or further weighted by one or more factors, suggesting “first event…first weight”, under the same pretext and motivation as in claim 1]; discussing the blockchain-based system of claim 5, wherein the computer-executable instructions, when executed by the processor, cause the blockchain-based system to: determine that the first event occurs earlier than the second event; and configure the second weight to be greater than the first weight. Claim 7: Griffin: para 0030 in view of Gross: col.11, line 57-col.12, line 10 [interactions with profile information includes location and demographics, suggesting “first event is associated with a first location…a second location”, under the same pretext and motivation as in claim 1]; discussing the blockchain-based system of claim 5, wherein the computer-executable instructions, when executed by the processor, cause the blockchain-based system to: determine that the first event is associated with a first location, the first location being observed to be used by the user; determine that the second event is associated with a second location; and configure the first weight to be greater than the second weight. Claim 8: Griffin: para 0046 [receive an access request, authenticate the requestor, and provide the content encryption key that corresponds to the information access level of the requestor]; discussing the blockchain-based system of claim 1, where the computer-executable instructions, when executed by the processor, cause the blockchain-based system to: receive a security-based indicator of the user; and determine, based on the security-based indicator of the user, that the request to perform the activity is authorized. Claim 9: Griffin: para 0029, 0050 [, the TSA computing system, the subscriber computing system, the auditor computing system, and the compliance blockchain system are in operative communication with the others via a network]; discussing the blockchain-based system of claim 1, where the computer-executable instructions, when executed by the processor, cause the blockchain-based system to: establish, via the network, a communication session between the computing device and the blockchain-based system to facilitate data transmission associated with performing the activity. As per claim 10: Griffin teaches a method implemented on a blockchain-based system having a processor and a memory storing computer-executable instructions, the method comprising: receiving, by the processor and via a network, a request to perform an activity associated with a user from a computing device, the request including a blockchain ID associated with the user; [Griffin: para 0020; The compliance blockchain system thus allows for a simple and effective means of selectively encrypting sensitive compliance data, while providing permissioned and selective access to various compliance information to a requesting entity (i.e. user, subscriber, client). Para 0050; the blockchain facilitator and the requesting entity each have their own respective asymmetric private KEK and public KEK certificates. The key management circuit negotiates the exchange of the blockchain facilitator certificate and the requesting entity certificate. The key management circuit generate the blockchain facilitator's asymmetric key pair and use the requesting entities public key to compute a common shared secret that can be used to generate a KEK. The “blockchain ID” may broadly be in the form of a key or certificate or other types of data that identifies the blockchain] identifying, by the processor and from a blockchain, one or more blockchain transactions associated with the blockchain ID; [Griffin: para 0077-0078; compliance event data can be time stamped, encrypted, and published to the event blockchain as the compliance event occurs. The compliance event data are time stamped upon receipt, cataloged, and stored over a period of time, eventually the plurality of compliance events of the period of time are encrypted and published to the event blockchain. More examples on para 0027, 0031] generating, by the processor and based on the one or more blockchain transactions, a trust profile of the user, the trust profile including a first authentication level to perform the activity; [Griffin: para 0024; The compliance data processing method allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. Specifically, the encryption techniques allow the compliance information (e.g., the adopted policies, practices, operations, incidents, monitoring, etc.) to be made available to auditors, regulators, subscribers, and legal entities by authorizing access to selective parts of the information in accordance with their credentials and clearance. As such, the policy or access to selective parts of the information suggest a first authentication level. Para 0029; the encryption techniques make it possible for the compliance information to be made available to auditors, regulators, subscribers, and attorneys by authorizing their access to selective information and providing them with any needed credentials and keys. The compliance information are available to trusted subscriber profiles or the user profile. More examples on para 0003, 0038, 0045-0046] **determining, by the processor, that the first authentication level is less than a threshold; [**rejected under a secondary reference, discussion below] **based on the first authentication level being less than the threshold [**rejected under a secondary reference, discussion below], determining, by the processor and based on the one or more blockchain transactions, one or more events that occurred within a time period, the one or more events being associated with respective timestamps; [Griffin: para 0038, 0065-0066; examples of determination of events occurred within a time period and the events associated to timestamps based on the one or more blockchain transactions] determine, based on the respective timestamps, an event of the one or more events that provides an indication of validity to perform the activity; [Griffin: para 0032; To provide integrity, authentication, and non-repudiation, the data logs may be signed by the blockchain facilitator, or another entity with authorization to publish to the compliance blockchains, using a digital signature method. Para 0068-0069; the blockchain facilitator store all compliance event data over a first time period before selectively encrypting and publishing the plurality of the compliance event data to the event blockchain. The blockchain facilitator policy in the policy blockchain and the blockchain facilitator compliance event logs related to each subscriber are accessible by the respective subscribers to evaluate compliance of the blockchain facilitator to the service policy regarding the respective subscriber. The blockchain facilitator publishes policies and subsequent policy versions to the policy blockchain. See also 0080] determining, by the processor and based the indication of validity, that the request to perform the activity is authorized; and [Griffin: para 0058; The network interface is structured to facilitate operative communication between the auditor computing system and the blockchain facilitator computing system. The auditor key negotiation circuit requests access to view restricted information on a blockchain facilitator blockchain and negotiates with the key management circuit of the blockchain facilitator computing system a KEK to securely transport the content encryption key that corresponds to the information access level of the auditor. See also para 0080-0081] transmitting, by the processor and via the network, an authorization to perform the activity to the computing device. [Griffin: para 0019; the data logs may be signed by the blockchain facilitator, or another entity with authorization to publish to the compliance blockchains, using a digital signature method. Para 0024; Each of the blockchain facilitator computing system, the subscribers, the auditor, and the compliance blockchain is in operative communication with the others via a network and allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. More examples on para 0053, 0096] Griffin suggests authentication level determination by teaching the compliance data processing method allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. Specifically, the encryption techniques allow the compliance information (e.g., the adopted policies, practices, operations, incidents, monitoring, etc.) to be made available to auditors, regulators, subscribers, and legal entities by authorizing access to selective parts of the information in accordance with their credentials and clearance[Griffin: para 0024]. The encryption techniques make it possible for the compliance information to be made available to auditors, regulators, subscribers, and attorneys by authorizing their access to selective information and providing them with any needed credentials and keys [Griffin: para 0029]. The compliance information are available to trusted subscriber profiles or the user profile. However, Griffin did not clearly teach “determine that the first authentication level is less than a threshold” and determine an event “based on the first authentication level being less than the threshold”. Gross teaches the social authentication circuit to reduce the authentication requirements based on a measure of social identity, where the social authentication circuit reduce authentication requirements based on a relationship measure between the one or more parties engaged in a transaction and based on the previous transaction history between the two or more parties. The social authentication circuit determine a level of trust based on the relationship measure being above a threshold relationship measure. Different threshold relationship measures correspond to a different levels of trust and accordingly require decreasing amounts of additional authentication. The social authentication circuit assign the threshold relationship measures to differing values for a maximum currency amount that can be part of the transaction and obtain further authentication through the use of financial information associated with an account of one or more of the parties. The social authentication circuit mitigate a low relationship measure by accessing or receiving additional information about the social media use of the potential receiving party [Gross: col.5, line 42-67]. As such, by the different threshold relationship measures correspond to a different levels of trust and accordingly require decreasing amounts of additional authentication obviously suggest “determine that the first authentication level is less than a threshold” and in turn the event associated therewith. One would be motivated to “determine that the first authentication level is less than a threshold” and determine an event “based on the first authentication level being less than the threshold” to determine a measure of social identity of the receiving party and a threshold level determines the receiving party is not a fake or fraudulent identity [Gross: col.6, line 5-10]. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Gross with Griffin to teach to “based on the first authentication level being less than the threshold, determine, based on the one or more blockchain transactions, an event that provides an indication of validity to perform the activity”, for the reason to determine a measure of social identity correspond to a different levels of trust to determines the receiving party is not a fake or fraudulent identity and accordingly require decreasing amounts of additional authentication [Gross: col.15, line 57-col.6, line 10]. Claim 11: Cancelled Claim 12: Griffin: para 0031, 0050 [key or timestamped associated to the blockchain of the subscriber]; discussing the method of claim 10, further comprising: receiving, by the processor, an additional blockchain ID associated with the user; identifying, by the processor and from the blockchain, one or more additional blockchain transactions associated with the additional blockchain ID; and updating, by the processor, the trust profile of the user based on the one or more additional blockchain transactions. Claim 13: Griffin: para 0032 in view of Gross: col.6, line 10-20 [authentication data include biometric information such as a finger print by the party (user) to initiate the transaction, suggesting “one or more non-blockchain transactions associated with the user based on the user ID”, under the same pretext and motivation as in claim 10]; discussing the method of claim 10, wherein the request includes a user ID associated with the user, and the method further comprises: further comprising: identifying, by the processor and from a database, one or more non-blockchain transactions associated with the user based on the user ID; and updating, by the processor, the trust profile of the user based on the one or more non-blockchain transactions. Claim 14: Griffin: para 0024 in view of Gross: col.1, line 50-5 and col.9, line 37-57 [weighting the relationship measure by a factor consisting of a value and types of social media associations, suggesting “assign a first weight …the second weight”, under the same pretext and motivation as in claim 1]; discussing the method of claim 10, wherein the event includes a first event that provides a first indication of validity to perform the activity and a second event that provides a second indication of validity to perform the activity, and the method further comprises: assigning, by the processor, a first weight to the first event; assigning, by the processor, a second weight to the second event; and determining, by the processor, the indication of validity to perform the activity based on the first event with the first weight and the second event with the second weight. Claim 15: Griffin: para 0025 view of Gross: col.9, line 37-57 [associations between the parties with weighting for certain types of social media associations, the relationship measure is weighted or further weighted by one or more factors, suggesting “first event…first weight”, under the same pretext and motivation as in claim 1]; discussing the method of claim 14, further comprising: determining, by the processor and based on the timestamps associated with the first event and the second event, that the first event occurs earlier than the second event; and configuring, by the processor, the second weight to be greater than the first weight. Claim 16: Griffin: para 0030 in view of Gross: col.11, line 57-col.12, line 10 [interactions with profile information includes location and demographics, suggesting “first event is associated with a first location…a second location”, under the same pretext and motivation as in claim 1]; discussing the method of claim 14, further comprising: determining, by the processor, that the first event is associated with a first location, the first location being observed to be used by the user; determining, by the processor, that the second event is associated with a second location; and configuring, by the processor, the first weight to be greater than the second weight. Claim 17: Griffin: para 0046 [receive an access request, authenticate the requestor, and provide the content encryption key that corresponds to the information access level of the requestor]; discussing the method of claim 10, further comprising: receiving a security-based indicator of the user; and determining, by the processor and based on the security-based indicator of the user, that the request to perform the activity is authorized. Claim 18: Griffin: para 0029, 0050 [the TSA computing system, the subscriber computing system, the auditor computing system, and the compliance blockchain system are in operative communication with the others via a network]; discussing the method of claim 10, further comprising: establishing, by the processor and via the network, a communication session between the computing device and the blockchain-based system to facilitate data transmission associated with performing the activity. As per claim 19: Griffin teaches a non-transitory computer-readable medium storing computer-executable instructions, that when executed by a processor of a blockchain-based system, cause the blockchain-based system to: receive, via a network and from a computing device, a request to perform an activity associated with a user, the request including a blockchain ID associated with the user; [Griffin: para 0020; The compliance blockchain system thus allows for a simple and effective means of selectively encrypting sensitive compliance data, while providing permissioned and selective access to various compliance information to a requesting entity (i.e. user, subscriber, client). Para 0050; the blockchain facilitator and the requesting entity each have their own respective asymmetric private KEK and public KEK certificates. The key management circuit negotiates the exchange of the blockchain facilitator certificate and the requesting entity certificate. The key management circuit generate the blockchain facilitator's asymmetric key pair and use the requesting entities public key to compute a common shared secret that can be used to generate a KEK. The “blockchain ID” may broadly be in the form of a key or certificate or other types of data that identifies the blockchain] identify, from a blockchain, one or more blockchain transactions associated with the blockchain ID; [Griffin: para 0077-0078; compliance event data can be time stamped, encrypted, and published to the event blockchain as the compliance event occurs. The compliance event data are time stamped upon receipt, cataloged, and stored over a period of time, eventually the plurality of compliance events of the period of time are encrypted and published to the event blockchain. More examples on para 0027, 0031] generate, based on the one or more blockchain transactions, a trust profile of the user, the trust profile including a first authentication level to perform the activity; [Griffin: para 0024; The compliance data processing method allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. Specifically, the encryption techniques allow the compliance information (e.g., the adopted policies, practices, operations, incidents, monitoring, etc.) to be made available to auditors, regulators, subscribers, and legal entities by authorizing access to selective parts of the information in accordance with their credentials and clearance. As such, the policy or access to selective parts of the information suggest a first authentication level. Para 0029; the encryption techniques make it possible for the compliance information to be made available to auditors, regulators, subscribers, and attorneys by authorizing their access to selective information and providing them with any needed credentials and keys. The compliance information are available to trusted subscriber profiles or the user profile. More examples on para 0003, 0038, 0045-0046] determine that the first authentication level is less than a threshold; [**rejected under a secondary reference, discussion below] **based on the first authentication level being less than the threshold [**rejected under a secondary reference, discussion below], determine, based on the one or more blockchain transactions, one or more events that occurred within a time period, the one or more events being associated with respective timestamps; [Griffin: para 0038, 0065-0066; examples of determination of events occurred within a time period and the events associated to timestamps based on the one or more blockchain transactions] determine, based on the respective timestamps, an event of the one or more events that provides an indication of validity to perform the activity; [Griffin: para 0032; To provide integrity, authentication, and non-repudiation, the data logs may be signed by the blockchain facilitator, or another entity with authorization to publish to the compliance blockchains, using a digital signature method. Para 0068-0069; the blockchain facilitator store all compliance event data over a first time period before selectively encrypting and publishing the plurality of the compliance event data to the event blockchain. The blockchain facilitator policy in the policy blockchain and the blockchain facilitator compliance event logs related to each subscriber are accessible by the respective subscribers to evaluate compliance of the blockchain facilitator to the service policy regarding the respective subscriber. The blockchain facilitator publishes policies and subsequent policy versions to the policy blockchain. See also 0080] determine, based on the indication of validity, that the request to perform the activity is authorized; and [Griffin: para 0058; The network interface is structured to facilitate operative communication between the auditor computing system and the blockchain facilitator computing system. The auditor key negotiation circuit requests access to view restricted information on a blockchain facilitator blockchain and negotiates with the key management circuit of the blockchain facilitator computing system a KEK to securely transport the content encryption key that corresponds to the information access level of the auditor. See also para 0080-0081] transmit, via the network, an authorization to perform the activity to the computing device. [Griffin: para 0019; the data logs may be signed by the blockchain facilitator, or another entity with authorization to publish to the compliance blockchains, using a digital signature method. Para 0024; Each of the blockchain facilitator computing system, the subscribers, the auditor, and the compliance blockchain is in operative communication with the others via a network and allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. More examples on para 0053, 0096] Griffin suggests authentication level determination by teaching the compliance data processing method allows for the management of publicly viewable blockchain entries for policy data and event data that can have field-level components protected from unauthorized access. Specifically, the encryption techniques allow the compliance information (e.g., the adopted policies, practices, operations, incidents, monitoring, etc.) to be made available to auditors, regulators, subscribers, and legal entities by authorizing access to selective parts of the information in accordance with their credentials and clearance[Griffin: para 0024]. The encryption techniques make it possible for the compliance information to be made available to auditors, regulators, subscribers, and attorneys by authorizing their access to selective information and providing them with any needed credentials and keys [Griffin: para 0029]. The compliance information are available to trusted subscriber profiles or the user profile. However, Griffin did not clearly teach “determine that the first authentication level is less than a threshold” and determine an event “based on the first authentication level being less than the threshold”. Gross teaches the social authentication circuit to reduce the authentication requirements based on a measure of social identity, where the social authentication circuit reduce authentication requirements based on a relationship measure between the one or more parties engaged in a transaction and based on the previous transaction history between the two or more parties. The social authentication circuit determine a level of trust based on the relationship measure being above a threshold relationship measure. Different threshold relationship measures correspond to a different levels of trust and accordingly require decreasing amounts of additional authentication. The social authentication circuit assign the threshold relationship measures to differing values for a maximum currency amount that can be part of the transaction and obtain further authentication through the use of financial information associated with an account of one or more of the parties. The social authentication circuit mitigate a low relationship measure by accessing or receiving additional information about the social media use of the potential receiving party [Gross: col.5, line 42-67]. As such, by the different threshold relationship measures correspond to a different levels of trust and accordingly require decreasing amounts of additional authentication obviously suggest “determine that the first authentication level is less than a threshold” and in turn the event associated therewith. One would be motivated to “determine that the first authentication level is less than a threshold” and determine an event “based on the first authentication level being less than the threshold” to determine a measure of social identity of the receiving party and a threshold level determines the receiving party is not a fake or fraudulent identity [Gross: col.6, line 5-10]. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Gross with Griffin to teach to “based on the first authentication level being less than the threshold, determine, based on the one or more blockchain transactions, an event that provides an indication of validity to perform the activity”, for the reason to determine a measure of social identity correspond to a different levels of trust to determines the receiving party is not a fake or fraudulent identity and accordingly require decreasing amounts of additional authentication [Gross: col.15, line 57-col.6, line 10]. Claim 20: Hanna: para 0016-0017 [verification threshold level within the ledger] in view of Gross: col.1, line 50-5 and col.9, line 37-57 [weighting the relationship measure by a factor consisting of a value and types of social media associations, suggesting “assign a first weight …the second weight”, under the same pretext and motivation as in claim 1]; discussing the non-transitory computer-readable medium of claim 19, wherein the event includes a first event that provides a first validity to perform the activity and a second event that provides a second validity to perform the activity, and the computer-executable instructions that, when executed by the processor, cause the blockchain-based system further to: determine, based on the timestamps associated with the first event and the second event, that the first event occurs earlier than the second event; and decrease the first validity provided by the first event. Claim 21: Griffin: para 0031, 0050 [key or timestamped associated to the blockchain of the subscriber] in view of Gross: col.5, line 5-30 and col.12, line 45-67[suggesting “a second event … ignoring the event”, under the same pretext and motivation as in claim 1]; discussing the blockchain-based system of claim 3, wherein the computer-executable instructions, when executed by the processor, cause the blockchain-based system to: aggregate the one or more blockchain transactions and the one or more additional blockchain transactions to generate aggregated blockchain transactions; identify, from the aggregated blockchain transactions, a second event that provides a second indication of validity to perform the activity, wherein the second event occurs later than the event; and update, based on the second event and by ignoring the event, the first authentication level in the trust profile. Claim 22: Objected Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Leynna Truvan whose telephone number is (571)272-3851. The examiner can normally be reached Monday-Friday 9:00AM-5:00PM, EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. Leynna Truvan Examiner Art Unit 2435 /L.TT/Examiner, Art Unit 2435 /EDWARD ZEE/Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Show 4 earlier events
Dec 12, 2025
Examiner Interview Summary
Dec 15, 2025
Response Filed
Apr 15, 2026
Final Rejection mailed — §103
Jun 01, 2026
Interview Requested
Jun 15, 2026
Response after Non-Final Action
Jun 24, 2026
Request for Continued Examination
Jun 28, 2026
Response after Non-Final Action
Sep 10, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750217
SIGN-EFFICIENT ADDITION AND SUBTRACTION FOR STREAMINGCOMPUTATIONS IN CRYPTOGRAPHIC ENGINES
4y 2m to grant Granted Sep 29, 2026
Patent 12744819
FRICTIONLESS SUPPLEMENTARY MULTI-FACTOR AUTHENTICATION FOR SENSITIVE TRANSACTIONS WITHIN AN APPLICATION SESSION
2y 2m to grant Granted Sep 22, 2026
Patent 12726371
METHOD AND APPARATUS FOR CONTROLLING TITLE TO A PHYSICAL OBJECT
3y 3m to grant Granted Sep 01, 2026
Patent 12695616
NON-FUNGIBLE TOKENS FOR VIRTUAL ACCESSORIES DURING VIRTUAL MEETINGS
4y 0m to grant Granted Jul 28, 2026
Patent 12695611
METHODS AND SYSTEMS FOR GENERATING, SUBSCRIBING TO AND PROCESSING ACTION PLANS USING A BLOCKCHAIN
3y 4m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
97%
With Interview (+20.1%)
3y 9m (~1y 0m remaining)
Median Time to Grant
High
PTA Risk
Based on 519 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month