Prosecution Insights
Last updated: October 02, 2026
Application No. 18/623,817

TOKEN-BASED DEVICE TRACKING

Final Rejection §103
Filed
Apr 01, 2024
Priority
May 27, 2021 — divisional of 11/979,403
Examiner
PATEL, DHAIRYA A
Art Unit
2453
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
4 (Final)
72%
Grant Probability
Favorable
5-6
OA Rounds
1y 5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
537 granted / 747 resolved
+13.9% vs TC avg
Strong +27% interview lift
Without
With
+27.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
20 currently pending
Career history
776
Total Applications
across all art units

Statute-Specific Performance

§101
17.1%
-22.9% vs TC avg
§103
63.3%
+23.3% vs TC avg
§102
7.1%
-32.9% vs TC avg
§112
6.7%
-33.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 747 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is responsive to communication filed on 6/9/2026. Claims 1-3, 5-7 are subject to examination. Claim 7 is newly added claim. Claim 4 is cancelled. This amendment and applicant’s arguments have been fully considered and entered by the Examiner. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-3, 7 is/are rejected under 35 U.S.C. 103 as being unpatentable over Henry et al. U.S. Patent Publication # 2019/0028892 (hereinafter Henry) in view of Hanna et al. U.S. Patent Publication # 2009/0041252 (hereinafter Hanna) further in view of Paaske et al. U.S. Patent Publication # 2006/0107032 (hereinafter Paaske) further in view of Schrag et al. U.S. Patent Publication # 2021/0064730 (hereinafter Schrag) With respect to claim 1, Henry teaches a method comprising: -receiving, by a user device, a request for a token from one of one of an access node or an identity provider (i.e. server may send request information about the client device such as MAC address, device type and/or device capability of the client device) (Paragraph 62-63); -in response to the request, generating the token using a trusted platform module of the user device (i.e. the server generates private key for the client and associates the generated private key with the MAC address of the client device) (paragraph 62-64); and -transmitting, by the user device, the token to one of the access node or the identity provider (i.e. server sending the private key to the user/user device)(Paragraph 62-65), wherein an access decision for the user device is made based on the token (i.e. client device sends a network access request contains at least MAC address, a private key and upon receiving the authentication response from the server, the WLC authorizes access to the network assuming the encrypted string is not compromised and private keys are different) (Paragraph 65-67). Henry fails to teach wherein the request comprises a nonce value and wherein generating the token such that information identifying the user device is determinable based on the token, generating the token comprises a hashing the nonce value using internal key of the trusted platform module. Schrag teaches in response to the request, generating the token using a trust platform module of the user device (i.e. computing device may generate the token which includes information associated with the user device) (Paragraph 49), such that information identifying the user device is determinable based on the token (i.e. generate the token which includes information associated with the user device which is device identifier, a MAC address, a MDN, an IP address etc.) (Paragraph 49). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to implement Schrag’s teaching in Henry’s teaching to come up with generating the token using trusted platform module of the user device such that information identifying the user device is determinable based on the token. The motivation for doing so would be so the application based on receiving the token, may be deemed/considered a verified application installed (Paragraph 49) Schrag teaches having hashing the nonce value (Paragraph 48), but Henry and Schrag does not explicitly teach generating the token comprises a hashing the nonce value using internal key of the trusted platform module. Hanna teaches request comprises a nonce value (i.e. initial message includes digital signature based on TPM and a nonce value) (Paragraph 31); wherein generating the token comprises hashing the nonce value using an internal key of the trust platform module (i.e. generating a digital signature wherein the digital signature maybe result of (1) concatenating the TPM value and the nonce value, (2) generating a hash value by applying a hash function to this concatenation and (3) then using a private encryption key of a TPM chip in endpoint device to encrypt the hash value)(Paragraph 23-25). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to implement Hanna’s teaching in Henry and Schrag’s teaching to come up with having request comprising nonce value and generating token comprising hashing the nonce value using internal key of the TPM. The motivation for doing so would be to verify the identity of TPM and also verifying access control and denying unauthorized device or person access to resource network thereby controlling access control. Henry, Schrag and Haana teaches hashing the nonce value using an internal key of the trusted platform module, but does not explicitly teach wherein the internal key is unique to the trusted platform module. Paaske teaches wherein the internal key is unique to the trusted platform module (Paragraph 108). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to implement Paaske’s teaching in Henry, Schrag and Haan’s teaching to come up with having internal key is unique to the trusted platform module. The motivation for doing so would be to track the number of updates to the flash memory and internal keys is used to encrypt and perform authentication operation on information that is stored in the flash memory (Paragraph 109-110) With respect to claim 2, Henry teaches the method of Claim 1, wherein the access decision for the user device is made based on information about the user device determined based on the token (i.e. client device sends a network access request contains at least MAC address, a private key and upon receiving the authentication response from the server, the WLC authorizes access to the network assuming the encrypted string is not compromised and private keys are different) (Paragraph 65-67). With respect to claim 3, Henry teaches the method of Claim 2, wherein the access decision for the user device is made based on comparing the information about the user device with information in a database (i.e. the server uses the MAC address included in the authentication request to search its databases, the server finds an entry of the MAC address, the server retrieves a private key associated with the MAC address and generates an authentication response that includes the second private key) (Paragraph 66-67, 73) With respect to claim 7, Henry, Schrag, Hanna and Paaske teaches the method of claim 1, but Schrag further teaches wherein the information identifying the user device is determinable based on the token (Paragraph 49). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to implement Schrag’s teaching in Henry’s teaching to come up with generating the token using trusted platform module of the user device such that information identifying the user device is determinable based on the token. The motivation for doing so would be so the application based on receiving the token, may be deemed/considered a verified application installed (Paragraph 49) Claim(s) 5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Henry et al. U.S. Patent Publication # 2019/0028892 (hereinafter Henry) in view of Schrag in view of Hanna further in view of Paaske further in view of Bhattacharyya et al. U.S. Patent Publication # 2020/0137563 (hereinafter Bhattacharyya) With respect to claim 5, Henry, Schrag, Hanna and Paaske teaches the method of Claim 1, but fails to further comprising communicating, by the user device, a connection request using information from a detected beacon. Bhattacharyya teaches communicating, by the user device, a connection request using information from a detected beacon (Paragraph 38, 44, 46, 56). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to implement Bhattacharyya’s teaching in Henry, Schrag, Hanna and Paaske’s teaching to come up with communication a connection requesting information from a detected beacon. The motivation for doing so would be to establish a secure connection using the nonce value and token which comprises a hash of the nonce value. Claim(s) 6 is/are rejected under 35 U.S.C. 103 as being unpatentable over Henry et al. U.S. Patent Publication # 2019/0028892 (hereinafter Henry) in view of Schrag in view of Hanna further in view of Paaske further in view of Mutairi et al. U.S. Patent Publication # 2021/0377297 (hereinafter Mutairi) With respect to claim 6, Henry, Schrag, Hanna and Paaske teaches the method of Claim 1, but fails to further teach further comprising changing a MAC address of the user device after being disconnected from the access node. Mutairi teaches changing a MAC address of the user device after being disconnected from the access node (i.e. MAC spoofing) (Paragraph 1-2). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to implement Mutairi’s teaching in Henry, Schrag, Hanna and Paaske’s teaching to come up with changing a MAC address of the user device after being disconnected from the access node. The motivation for doing so would be to having to allow the bypassing of the access control lists on the communication network by either hiding the endpoint device on the communication network or allowing the endpoint device to impersonate another endpoint device (Paragraph 1). Response to Arguments Applicant’s arguments with respect to amended claim(s) 1-3, 5-6 have been considered but are moot in view of new grounds of rejection. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. A). Khalil et al. U.S. Patent Publication # 2016/0006719 which teaches about authentication request associated with third party server having MAC address so authentication server may authenticate with third party server on behalf of the user device. B). Achtari et al. U.S. Patent Publication # 2008/0301773 which teaches about identifying potential MAC spoofing including authenticating the device. C). Lee et al. U.S. Patent Publication # 2017/0078285 Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DHAIRYA A PATEL whose telephone number is (571)272-5809. The examiner can normally be reached M-F 7:30am-4:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal B Divecha can be reached at 571-272-5863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. DHAIRYA A. PATEL Primary Examiner Art Unit 2453 /DHAIRYA A PATEL/Primary Examiner, Art Unit 2453
Read full office action

Prosecution Timeline

Show 5 earlier events
Nov 06, 2025
Final Rejection mailed — §103
Feb 06, 2026
Request for Continued Examination
Feb 20, 2026
Response after Non-Final Action
Mar 09, 2026
Non-Final Rejection mailed — §103
Jun 08, 2026
Applicant Interview (Telephonic)
Jun 09, 2026
Response Filed
Jun 13, 2026
Examiner Interview Summary
Aug 27, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743903
DATA VERIFICATION TERMINAL AND DATA VERIFICATION SERVER
2y 0m to grant Granted Sep 22, 2026
Patent 12732417
DETECTING NETWORK OPERATION VALIDATION ANOMALIES IN CONGLOMERATE-APPLICATION-BASED ECOSYSTEMS SYSTEMS AND METHODS
2y 7m to grant Granted Sep 08, 2026
Patent 12726433
Service Processing Method, Apparatus, Device, and System
3y 4m to grant Granted Sep 01, 2026
Patent 12719703
REVOKING ACCESS TO A NETWORK
3y 11m to grant Granted Aug 25, 2026
Patent 12712945
COUNTERFACTUAL ANALYSIS OF USER MODELS FOR PRESCRIPTIVE OUTPUT
2y 11m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
72%
Grant Probability
99%
With Interview (+27.0%)
3y 11m (~1y 5m remaining)
Median Time to Grant
High
PTA Risk
Based on 747 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month