DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04 June 2026 has been entered.
Response to Amendment
Applicant’s amendment filed 04 June 2026 amends claims 2, 13, and 21. Applicant’s amendment has been fully considered and entered.
Response to Arguments
Applicant argues on page 7 of the response, “Without conceding the merits of the rejection, the independent claims have been amended.” This argument has been fully considered and is persuasive. Therefore, the previous §112 rejection has been withdrawn.
Applicant argues on page 8 of the response, “The Examiner relies on Zilberberg for assigning ‘multiple levels of trust’ to different financial institutions. However, the relied upon portions of Zilberberg do not teach or suggest assigning a level of trust to a financial institution based on ‘device-level fraud detection signals for the client device.’” This argument is not persuasive because the claims do not define what constitutes “device-level fraud detection signals”. Therefore, the broadest reasonable interpretation of the limitation is being applied to the prior art. Specifically, Zilberberg discloses that the financial institution trust levels are set based upon evaluations of the financial institution information ([0079]-[0081]). These evaluation procedures can read on the claimed evaluation of device-level fraud detection signals because an evaluation is performed is specific to the financial institution data having instances of misinformation or unreliable information.
Applicant argues on pages 8-9 of the response, “…the Examiner alleges that Ornelas meets the ‘without revealing a unique identity’ limitation because Ornelas does not explicitly state that its public keys are generated based upon uniquely identifiable information. However, Ornelas explicitly requires traceability to the specific signing entity. Paragraph 32 of Ornelas provides that ‘Every digital cent would be able to be traced to a currency request and minting request’…” This argument is not persuasive because Ornelas makes it clear that the traceability is possible due to an ID of the requester included in the request ([0035]). Additionally, this ID corresponds with the user and not the financial institution, which is mapped to the claimed client device. Therefore, the public keys of Ornelas do not provide identification of the financial institution as required by the claims.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 2, 3, 11-14, 21 are rejected under 35 U.S.C. 103 as being unpatentable over Ornelas, U.S. Publication No. 2021/0182806, in view of Zilberberg, U.S. Publication No. 2015/0127660.
Referring to claims 2, 21, Ornelas discloses a computing device 116 that receives a minting request (Figure 4A, step 410 & [0106]: minting request reads on the claimed attestation token), from a financial institution (Figure 4A, step 402 & [0098]: financial institution computing device reads on the claimed client device), that includes a plurality of digital signatures and a currency request (Figure 3A, element 336 & [0103]: currency request reads on the claimed set of data; any one of the signatures in the minting request can read on the claimed digital signature since the signatures are of the entire request that includes the currency request; minting request attests to the trustworthiness of the financial institution to the extent that the request includes a digital signature), which meets the limitation of receiving, from a client device, an attestation token that attests to trustworthiness of the client device, the attestation token comprising a set of data and a digital signature generated using the set of data. Computing device 116 verifies at least one signature of the received minting request ([0106]) by using first-level public keys and attempting to verify the signature using each of the first-level public keys until one of the first-level public keys successfully verifies the signature or all the first-level public keys have been tried ([0113]), which meets the limitation of validating the attestation token based on the digital signature, including, evaluating, for one or more group verification keys of a plurality of group verification keys, a verification function using the group verification key, the set of data, and the digital signature to identify a given group verification key for which the digital signature is verified successfully, wherein each category of trustworthiness has a published group verification key. The public keys are generated ([0030]: public keys are not disclosed as being generated based upon any uniquely identifiable information, which reads on the claimed without revealing a unique identity of the client device limitation), which meets the limitation of to enable verification of category of trustworthiness of the client device while precluding identification of the specific client device from among a plurality of client devices assigned to the same respective category of trustworthiness. If the minting request includes multiple digital signature (i.e., third signature, fourth signature, etc.), verification can include attempting to verify the third/fourth signatures against each of the second-level public keys until one of the second-level public keys successfully verifies the third/fourth signature or all the second-level public keys have been tried ([0114]) and additional signatures (i.e., fifth/sixth signatures) can be verified by utilizing each of the third-level public keys until one of the third-level public keys successfully verifies the fifth/sixth signature or all the third-level public keys have been tried ([0115]), which meets the limitation of determining the [category of trustworthiness of the client device corresponding to the] given group verification key, validating the attestation token based at least one the [category of trustworthiness of the client device]. Upon successful verification of the digital signatures of the minting request, the requested digital currency is minted ([0119]), which meets the limitation of performing an action in response to validating the attestation token.
Ornelas discloses that verification using the public keys verifies that the public keys came from trusted financial institutions ([0144]-[0145]), which meets the limitation of wherein each group verification key corresponds to a [respective category of] trustworthiness. Ornelas does not disclose multiple trust levels for the financial institutions. Zilberberg discloses assigning multiple levels of trust to different financial institutions such as banks ([0080]: As applied to Ornelas each level of public keys would correspond to a level of trust. Therefore, financial institutions in Ornelas with public keys at specific levels would have a corresponding level of trust), which meets the limitation of wherein each group corresponds to a respective category of trustworthiness of client devices, determining the category of trustworthiness of the client devices corresponding to the given group verification key. The financial institution trust levels are set based upon evaluations of the financial institution information ([0079]-[0081]: evaluation procedure reads on the claimed evaluation of device-level fraud detection signals because the evaluation is performed is specific to the financial institution data having instances of misinformation or unreliable information), which meets the limitation of wherein the given group verification key corresponds to a respective category of trustworthiness that is assigned to the client device based on an evaluation of device-level fraud detection signals for the client device. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the trusted financial institutions of Ornelas to have been assigned trust level from a plurality of trust levels in order to provide a more accurate representation of the trust for that financial institution as suggested by Zilberberg ([0030] & [0068]).
Referring to claim 3, Ornelas discloses a computing device 116 that receives a minting request (Figure 4A, step 410 & [0106]: minting request reads on the claimed attestation token), from a financial institution (Figure 4A, step 402 & [0098]) that includes a currency request (Figure 3A, element 336 & [0103]), which meets the limitation of receiving the attestation token comprises receiving, from the client device, a request that includes the attestation token. Upon successful verification of the digital signatures of the minting request, the requested digital currency is minted and the newly-minted tokens are transferred to the requesting financial institution ([0119]), which meets the limitation of performing the action comprises sending, the client device, a response to the request.
Referring to claim 11, Ornelas discloses that the computing device 116 receives the plurality of public keys before receiving the minting request ([0082]), which meets the limitation of obtaining the plurality of group verification keys prior to receiving the attestation token.
Referring to claim 12, Ornelas discloses that the public keys can be rotated ([0071] & [0074]), which meets the limitation of obtaining the plurality of group verification keys periodically.
Referring to claim 13, Ornelas discloses a computing device 116 that includes a processor ([0177]) and a memory storing instructions for execution by the processor ([0178]), which meets the limitation of a system comprising one or more processors, and one or more storage devices storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations. The computing device 116 receives a minting request (Figure 4A, step 410 & [0106]: minting request reads on the claimed attestation token), from a financial institution (Figure 4A, step 402 & [0098]: financial institution computing device reads on the claimed client device), that includes a plurality of digital signatures and a currency request (Figure 3A, element 336 & [0103]: currency request reads on the claimed set of data; any one of the signatures in the minting request can read on the claimed digital signature since the signatures are of the entire request that includes the currency request), which meets the limitation of receiving, from a client device, an attestation token that attests to trustworthiness of the client device, the attestation token comprising a set of data and a digital signature generated using the set of data. Computing device 116 verifies at least one signature of the received minting request ([0106]) by using first-level public keys and attempting to verify the signature using each of the first-level public keys until one of the first-level public keys successfully verifies the signature or all the first-level public keys have been tried ([0113]), which meets the limitation of validating the attestation token based on the digital signature, including, evaluating, for one or more group verification keys of a plurality of group verification keys, a verification function using the group verification key, the set of data, and the digital signature to identify a given group verification key for which the digital signature is verified successfully, wherein each category of trustworthiness has a published group verification key. The public keys are generated ([0030]: public keys are not disclosed as being generated based upon any uniquely identifiable information, which reads on the claimed without revealing a unique identity of the client device limitation), which meets the limitation of to enable verification of a category of trustworthiness of the client device while precluding identification of the specific client device from among a plurality of client devices assigned to the same respective category of trustworthiness. If the minting request includes multiple digital signature (i.e., third signature, fourth signature, etc.), verification can include attempting to verify the third/fourth signatures against each of the second-level public keys until one of the second-level public keys successfully verifies the third/fourth signature or all the second-level public keys have been tried ([0114]) and additional signatures (i.e., fifth/sixth signatures) can be verified by utilizing each of the third-level public keys until one of the third-level public keys successfully verifies the fifth/sixth signature or all the third-level public keys have been tried ([0115]), which meets the limitation of determining the [category of trustworthiness of the client device corresponding to the] given group verification key, validating the attestation token based at least one the [category of trustworthiness of the client device]. Upon successful verification of the digital signatures of the minting request, the requested digital currency is minted ([0119]), which meets the limitation of performing an action in response to validating the attestation token.
Ornelas discloses that verification using the public keys verifies that the public keys came from trusted financial institutions ([0144]-[0145]), which meets the limitation of wherein each group verification key corresponds to a [respective category of] trustworthiness. Ornelas does not disclose multiple trust levels for the financial institutions. Zilberberg discloses assigning multiple levels of trust to different financial institutions such as banks ([0080]: As applied to Ornelas each level of public keys would correspond to a level of trust. Therefore, financial institutions in Ornelas with public keys at specific levels would have a corresponding level of trust), which meets the limitation of wherein each group corresponds to a respective category of trustworthiness of the client device, determining the category of trustworthiness of the client device corresponding to the given group verification key. The financial institution trust levels are set based upon evaluations of the financial institution information ([0079]-[0081]: evaluation procedure reads on the claimed evaluation of device-level fraud detection signals because the evaluation is performed is specific to the financial institution data having instances of misinformation or unreliable information), which meets the limitation of wherein the given group verification key corresponds to a respective category of trustworthiness that is assigned to the client device based on an evaluation of device-level fraud detection signals for the client device. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the trusted financial institutions of Ornelas to have been assigned trust level from a plurality of trust levels in order to provide a more accurate representation of the trust for that financial institution as suggested by Zilberberg ([0030] & [0068]).
Referring to claim 14, Ornelas discloses a computing device 116 that receives a minting request (Figure 4A, step 410 & [0106]: minting request reads on the claimed attestation token), from a financial institution (Figure 4A, step 402 & [0098]) that includes a currency request (Figure 3A, element 336 & [0103]), which meets the limitation of receiving the attestation token comprises receiving, from the client device, a request that includes the attestation token. Upon successful verification of the digital signatures of the minting request, the requested digital currency is minted and the newly-minted tokens are transferred to the requesting financial institution ([0119]), which meets the limitation of performing the action comprises sending, the client device, a response to the request.
Claims 4-6, 15-17 are rejected under 35 U.S.C. 103 as being unpatentable over Ornelas, U.S. Publication No. 2021/0182806, in view of Zilberberg, U.S. Publication No. 2015/0127660, and further in view of Brickell, U.S. Publication No. 2018/0287802. Referring to claims 4, 15, Ornelas discloses a computing device 116 that receives a minting request (Figure 4A, step 410 & [0106]), from a financial institution (Figure 4A, step 402 & [0098]), that includes a plurality of digital signatures and a currency request (Figure 3A, element 336 & [0103]).
Ornelas does not disclose the usage of a signature scheme that includes anonymous certificates. Brickell discloses digital signature generating using direct anonymous attestation protocol (DAA) such that the computing device receives an anonymous certificate from a trusted party executing in a trusted execution environment ([0013] & [0015] & [0017]), which meets the limitation of wherein the digital signature is generated using a group signature scheme and an anonymous certificate provided to the client device. The trusted party receives a certificate request from the client platform such that the request is signed with a private attestation key allowing the trusted platform to verify the signed request using the public attestation key ([0017: request verification procedure reads on the claimed device-level fraud detection), which meets the limitation of an anonymous certificate provided to the client device based on an evaluation of device-level fraud detection signals for the client device. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the signature scheme of Ornelas to have been implemented using DAA with the usage of anonymous certificates from a trusted parties executing in a trusted execution environment in order to attest to the authenticity of the computing device without revealing identity information (Brickell: [0010]) in a manner that is resistant to quantum computers (Brickell: [0015]).
Referring to claims 5, 16, Brickell suggests that anonymous key pairs and certificates are replaced with assignment of a new anonymous key pair and certificate (Figure 2B: suggests that the assignment of the device to the anonymous grouping is not revocable), which meets the limitation of wherein the anonymous certificate is a irrevocable anonymous certificate indicating that the client device has been irrevocably assigned to the given signature group. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the signature scheme of Ornelas to have been implemented using DAA with the usage of anonymous certificates from a trusted parties executing in a trusted execution environment in order to attest to the authenticity of the computing device without revealing identity information (Brickell: [0010]) in a manner that is resistant to quantum computers (Brickell: [0015]).
Referring to claims 6, 17, Ornelas does not disclose the usage of a signature scheme that includes anonymous certificates. Brickell discloses digital signature generating using direct anonymous attestation protocol (DAA) such that the computing device receives an anonymous certificate from a trusted party executing in a trusted execution environment ([0013] & [0015] & [0017]), which meets the limitation of wherein the group signature scheme is a direct anonymous attestation (DAA) signing scheme. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the signature scheme of Ornelas to have been implemented using DAA with the usage of anonymous certificates from a trusted parties executing in a trusted execution environment in order to attest to the authenticity of the computing device without revealing identity information (Brickell: [0010]) in a manner that is resistant to quantum computers (Brickell: [0015]).
Claims 7, 8, 18, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Ornelas, U.S. Publication No. 2021/0182806, in view of Zilberberg, U.S. Publication No. 2015/0127660, in view of Brickell, U.S. Publication No. 2018/0287802, and further in view of Wentz, U.S. Publication No. 2020/0153627. Referring to claims 7, 8, 18, 19, Brickell does not disclose that the DAA signature scheme is an elliptic curve cryptography DAA scheme. Wentz discloses that the signing scheme could be a signing scheme with Barreto-Naehrig curves ([0121]), which meets the limitation of wherein the DAA signing scheme is an elliptic curve cryptographic (ECC) DAA signing scheme, wherein the ECC DAA signing scheme is an ECC DAA signing scheme with Barreto-Naehrig curves. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed information for the signing scheme of Ornelas, as modified in view of Brickell, to have been a signing scheme with Barreto-Naehrig curves because Wentz suggests ([0121]) that a signing scheme with Barreto-Naehrig curves is one of a finite number of signing schemes that could have been implemented by one of ordinary skill in the art with a reasonable expectation of success.
Claims 9, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Ornelas, U.S. Publication No. 2021/0182806, in view of Zilberberg, U.S. Publication No. 2015/0127660, and further in view of Chandoor, U.S. Publication No. 2017/0201520.
Referring to claims 9, 20, Ornelas discloses that the minting request includes a time stamp ([0102]), which meets the limitation of the attestation token comprises an attestation token creation timestamp indicating a time at which the attestation token is created. A computing device 116 that receives a minting request (Figure 4A, step 410 & [0106]), from a financial institution (Figure 4A, step 402 & [0098]).
Ornelas does not explicitly disclose comparing the time difference from minting request creation to receiving of the minting request to a threshold. Chandoor discloses a provisioning request that a timestamp is received and verified by comparing the difference between the current time and the time indicated by the timestamp with respect to a threshold ([0066]), which meets the limitation of validating the attestation token comprises determining that a different between a time at which the attestation token is received and the time at which the attestation token is created is within a threshold. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the computing device 116 of Ornelas to have compared the time difference from minting request creation to receiving of the minting request to a threshold in order to ensure that the request is valid as suggested by Chandoor ([0066]).
Claims 10 are rejected under 35 U.S.C. 103 as being unpatentable over Ornelas, U.S. Publication No. 2021/0182806, in view of Zilberberg, U.S. Publication No. 2015/0127660, in view of Chandoor, U.S. Publication No. 2017/0201520, and further in view of Pan, U.S. Publication No. 2020/0366608. Referring to claim 10, Ornelas discloses that the minting request includes a time stamp ([0102]). Ornelas does not specify the time resolution of the timestamp. Pan discloses timestamps providing a time resolution at the picosecond or microsecond scale ([0027]: picosecond and microsecond scales are less than millisecond scale and picosecond scale is less than the microsecond scale), which meets the limitation of wherein the attestation token creation timestamp has a time resolution that is less than about a millisecond or less than about a microsecond. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the time resolution of the timestamps in Ornelas to have been provided in the microsecond scale or picosecond scale because Pan discloses ([0027]) that microsecond and picosecond scales represent a finite number of possible time resolution scales that could have been implemented by one of ordinary skill in the art with a reasonable expectation of success.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BENJAMIN E LANIER whose telephone number is (571)272-3805. The examiner can normally be reached M-Th: 5:30-4:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at 5712705143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BENJAMIN E LANIER/Primary Examiner, Art Unit 2437