DETAILED ACTION
This Office Action is in response to the amendment filed on 03/12/2026 in which Claims 1-16 are presented for examination on the merits.
Notice of Pre-AIA or AIA Status
The present application is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted 05/13/2026 has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Form PTO-1449 is signed and attached hereto.
Response to Arguments
1. With regards to the rejection under 35 USC § 103(a), Applicant's arguments in pages 6-9 of the REMARKS filed on 03/12/2026 have been considered. However, after careful review, the rejection under 35 U.S.C. 103(a) to claims 1-16 are maintained for the reasons specified in the rejection below.
2. Regarding independent claims 1 and 9 rejected under 35 U.S.C. 103(a), applicant argues, for example:
“..neither Bruno nor Scott, whether taken alone or in combination, teaches or renders obvious the claimed limitation of generating a verification response indicating possession of at least one attribute..” and further argues that Bruno merely discloses local wallet unlocking and presentation of credentials, rather than generating a targeted verification response.
The argument is not persuasive. The Office Action previously mapped this limitation to Bruno’s disclosure of electronic identification instruments and tokens being generated, associated, and validated via a credential system (e.g., token engine and credential engine). Bruno teaches that identity information (e.g., electronic identification instruments) and corresponding tokens are provisioned to a wallet and subsequently validated by comparing received data with stored validation information. Such validation inherently communicates that a user possesses a qualifying credential or attribute.
Contrary to Applicant’s characterization, the claimed “verification response” does not require any particular form, format, or semantic content beyond indicating possession of an attribute. Under the broadest reasonable interpretation (BRI), the validation result or token-based confirmation transmitted in Bruno constitutes a response that indicates possession of at least one attribute (e.g., possession of a valid credential, identity instrument, or associated token).
Further, Scott teaches responding to transaction or access requests using wallet-stored credentials and secure tokens in communication with trusted platforms. Such responses inherently indicate that the user possesses the underlying credential or authorization required for the transaction.
Applicant’s distinction between: (i) “unlocking a wallet and presenting contents,” and (ii) “generating a targeted verification response,” is not commensurate with the scope of the claims. The claims do not require a specialized or tailored “targeted” response beyond indicating possession of an attribute. The combined teachings of Bruno and Scott clearly provide mechanisms where: credentials/tokens are generated and stored, and responses based on those credentials are transmitted to requesting entities.
Accordingly, one of ordinary skill in the art would have understood that the validation or token-based response in Bruno (as enhanced by Scott’s transaction-based response mechanisms) meets the claimed limitation.
Moreover, even if Bruno alone does not explicitly describe the response as “indicating possession,” Scott’s disclosure of responding to requests using tokens and credentials renders the limitation obvious when combined. The combination merely applies known credential validation outputs in a predictable manner (KSR).
3. Regarding independent claims 1 and 9 rejected under 35 U.S.C. 103(a), applicant argues, for example:
“..Applicant respectfully submits that neither Bruno nor Scott, alone or in combination, teaches or suggests this claimed feature...... the apparatus transmits to the verifying entity a verification response and attested data confirming the user possesses a qualifying attribute” asserting that Bruno transmits full identification documents containing personal data.
After careful review, the Examiner respectfully disagrees. Bruno explicitly discloses the use of tokens associated with electronic identification instruments, where the token is distinct from the underlying personal data. Tokens function as proxies for sensitive data and are used for validation and authentication purposes. As such, Bruno teaches a system in which: the credential (or identity information) is abstracted via a token, and the token is used in communications instead of directly transmitting the underlying personal data. This is consistent with the claimed concept of transmitting attested data while excluding personal data.
Further, Scott reinforces this teaching by disclosing secure payment tokens and trusted platform communications, where sensitive data is not directly exposed during transactions. Scott’s system relies on tokenization and secure processing to validate transactions without transmitting raw personal information.
Applicant’s argument that Bruno “inherently contains personal data” overlooks the explicit role of tokens as substitutes or abstractions of such data. The use of tokens and credential validation mechanisms would have suggested to one of ordinary skill in the art the well-known design choice of: transmitting proof of possession (via tokens or validation results), rather than transmitting raw personal data.
Furthermore, the claimed “attested data” broadly encompasses any data confirming possession of an attribute. Tokens, validation outputs, or credential confirmations in Bruno and Scott meet this definition under broadest reasonable interpretation (BRI).
As is clearly evident from the above explicit teachings, even if the claimed language is not identical to that disclosed by the cited references, the differences between that which is disclosed and that which is claimed are considered to be so slight (i.e. predictable variance, KSR, MPEP 2143) that it would have been obvious to the skilled artisan to modify the teachings of Bruno and Scott as a design preference and make the invention as claimed especially when each feature and function of the claimed invention is present in the references.
The Applicant has failed to clearly explain the pertinence of each cited passage, by failing to clearly articulate the difference between claim features and specification, with a convincing rationale and factual support.
As is readily evident, the claimed invention as a whole was at least prima facie obvious, if not anticipated by the reference, especially in the absence of sufficient, clear, and convincing evidence to the contrary.
In view of the above teachings in Bruno, it would have been obvious to one of ordinary skilled in the art before the effective filing of the claimed invention, to attest data confirming the user possesses a qualifying attribute...transmit... the attested data without including the personal data...", because such a modification would have been considered a mere configuration preference, and thus, would have been obvious to try.
4. Regarding independent claims 1 and 9 rejected under 35 U.S.C. 103(a), applicant argues, for example:
“..Moreover, the Examiner's motivation to combine-"to enable the use of multiple payment accounts to fund purchases and other electronic transactions" (Scott Abstract) speaks to multi- account payment functionality, not to privacy-preserving attribute verification. Neither reference recognizes the problem of disclosing personal data during identity verification, let alone proposes the claimed solution of withholding personal data while transmitting only a verification response and attested data. Accordingly, neither Bruno nor Scott, whether taken alone or in combination, teaches or renders obvious the claimed limitation of transmitting the verification response and the attested data to the verifying entity without including the personal data.”
The Examiner respectfully submits that Scott et al. does not change the principle of operation of the primary reference or render the reference inoperable for its intended purpose. See MPEP § 2143.01. The test for obviousness is not whether the features of a secondary reference may be bodily incorporated into the structure of the primary reference Bruno. Rather, the test is what the combined teachings of those references would have suggested to those of ordinary skill in the art.” In re Keller, 642 F.2d 413, 425, 208 USPQ 871, 881 (CCPA 1981). See also In re Sneed, 710 F.2d 1544, 1550, 218 USPQ 385, 389 (Fed. Cir. 1983). It is not necessary that the inventions of the references be physically combinable to render obvious the invention under review.”; and In re Nievelt, 482 F.2d 965, 179 USPQ 224, 226 (CCPA 1973).
Combining the teachings of references Bruno and Scott does not involve an ability to combine their specific structures. Thus, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Therefore, prior arts must be considered in entirely, including discloses that teach away from the claims, MPEP § 2143.01-02.
The “mere existence of differences between the prior art and an invention does not establish the invention’s nonobviousness.” Dann v. Johnston, 425 U.S. 219, 230, 189 USPQ 257, 261 (1976). The gap between the prior art and the claimed invention may not be “so great as to render the [claim] nonobvious to one reasonably skilled in the art.” Id. MPEP 2141 (section III).
In view of the above, it would have been obvious to the skilled artisan to modify the teachings of Scott with the teachings of Bruno to perform the functions of the method as claimed including: “…generate a verification response indicating possession of the at least one attribute; identify, in a digital wallet, attested data issued by a trusted entity that confirms possession of the at least one attribute of the personal data; transmit, to the verifying entity, the verification response and the attested data without including the personal data; and receive a grant or denial of the access request from the verifying entity…”.
The proposed combination would have been obvious because: both references operate in the same field (digital wallets, credentials, secure transactions), both rely on tokens and credential validation, and combining them yields predictable results (secure verification of user attributes without exposing sensitive data).
Claim Rejections - 35 USC § 103
5. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
6. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
7. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
8. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
9. Claims 1-16 are rejected under 35 U.S.C. 103 as being unpatentable over Bruno et al. (US 20200265417 A1, hereinafter, Bruno) in view of Scott et al. (US 20220020016 A1, hereinafter, Scott).
Regarding claim 1, Bruno discloses an apparatus for attested verification of personal data, comprising: one or more memories; and one or more hardware processors coupled with the one or more memories and configured, individually or in combination, to: transmit an access request to a verifying entity (Para 0019, 0027: receive/request and validate identity information from one or more identity providers wherein validation information is requested from the user)
wherein the access request is for a service, product, or information accessible solely to an authorized user (Para 0047, 0051, 0031: tokens/credentials associated with a given merchant and trusted user made services accessible such as complete a transaction);
receive, from the verifying entity, a verification request that indicates at least one attribute of personal data that classifies a user as the authorized user (Para 0019, 0027, 0031: receive/request and validate identity information from one or more identity providers wherein validation information is requested from the user. For example, validate, verify, authorize, and/or otherwise confirm if token being provided is authentic and/or corresponds to a particular user account).
generate a verification response indicating possession of the at least one attribute; identify, in a digital wallet (Para 0015, 0040, 0051, 0085: processing users biometric (e.g., fingerprint, retina, and/or the like) authentication or credential information (e.g., username and password), wherein virtual wallet uses token or credentials for verification)
[attested data issued by a trusted entity that confirms possession of the at least one attribute of the personal data];
transmit, to the verifying entity, the verification response [and the attested data] without including the personal data; and receive a grant or denial of the access request from the verifying entity (Para 0031, 0087, 0096: In response to receiving confirmation that the transaction account details have been verified and approved, the information/response is relayed back to the client that access is granted to complete transaction …..confirming that the token being provided is authentic and/or corresponds to a particular user account);
Bruno does not explicitly state but Scott from the same or similar fields of endeavor teaches attested data issued by a trusted entity that confirms possession of the at least one attribute of the personal data (Scott, Para 0141, 0146, 0167: Wallet application verifies the certificate including a code or token uniquely identifying the certification status associated with user's credentials stored in wallet application)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention wherein attested data issued by a trusted entity that confirms possession of the at least one attribute of the personal data as taught by Scott in the teachings of Bruno in order to enable the use of multiple payment accounts to fund purchases and other electronic transactions associated with accounts or payment tokens which are stored on device(s) secure data sets known as virtual or electronic wallets (Scott, Abstract).
Regarding claim 2, the combination of Bruno and Scott discloses the apparatus of claim 1, the verifying entity is configured to: confirm, with the trusted entity, whether the verification response is authentic (Bruno Paras 0030-0031: first token and the first electronic identification are presented together to the wallet reader of an identity requester to confirm that the first electronic identification data is authentic); and
grant or deny the access request based on the whether the verification response is confirmed to be authentic (Bruno Para 0096: in response to receiving confirmation that the transaction account details have been verified, the information is relayed back to the merchant/customer, who completes the payment transaction. In response to the verification being denied, the payment processor relays the information to the merchant, who declines the transaction).
Regarding claim 3, the combination of Bruno and Scott discloses the apparatus of claim 2, wherein the [attested data] in the digital wallet is encrypted by a first encryption key of the trusted entity, and wherein the verifying entity confirms whether verification response is authentic(Bruno, Para 0096, 0031: encrypting transaction account details including sensitive information the token, for example, which is being validated, verified, authorized and/or otherwise confirmed as authentic and corresponds to a particular user account
by being configured to: transmit the verification response and the attested data to the trusted entity (Bruno, Para 0019, 0027: receive/request and validate identity information from one or more identity providers wherein validation information is requested from the user); and
receive, from the trusted entity, confirmation that the verification response is authentic (Bruno, Para 0030-0031, 0087, 0096: In response to receiving confirmation that the transaction account details have been verified and approved, the information/response is relayed back to the client that access is granted to complete transaction …..confirming that the token being provided is authentic and/or corresponds to a particular user account)
Bruno does not explicitly state but Scott from the same or similar fields of endeavor teaches attested data associated with aforesaid claim limitations (Scott, Para 0141, 0146, 0167: Wallet application verifies the certificate including a code or token uniquely identifying the certification status associated with user's credentials stored in wallet application)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have attested data as taught by Scott in the teachings of Bruno in order to enable the use of multiple payment accounts to fund purchases and other electronic transactions associated with accounts or payment tokens which are stored on device(s) secure data sets known as virtual or electronic wallets (Scott, Abstract).
Regarding claim 4, the combination of Bruno and Scott discloses the apparatus of claim 3, wherein the trusted entity is configured to: decrypt the attested data using a second encryption key of the trusted entity; and confirm that the verification response is authentic in response to determine that the verification response matches with the attested data that is decrypted (Scott, Para 0206, 0174, 0055: verified transaction data is forwarded for decryption wherein token or payment credential is being processed as authentic matching the registered identifying information associated with the merchant's certificate)
Regarding claim 5, the combination of Bruno and Scott discloses the apparatus of claim 1, wherein the one or more hardware processors are further configured, individually or in combination, to: transmit, to the trusted entity, an attestation request and the personal data (Bruno Para 0015, Claims 8, 20: requesting access the electronic identification information comprising credential information from the user),
wherein the attestation request includes a plurality of attributes comprising the at least one attribute that the trusted entity should attest; receive, from the trusted entity, a plurality of attested data points generated based on the personal data (Bruno Para 0096, 015: an application service provider service that authorizes customer and the merchant information including biometric (e.g., fingerprint, retina, and/or the like) authentication or credential information (e.g., username and password, credential information),
wherein the plurality of attested data points includes the attested data confirming possession of the at least one attribute of the personal data; and store the plurality of attested data points in the digital wallet (Bruno Paras 0030-0031: first token and the first electronic identification are presented together to the wallet reader of an identity requester to confirm that the first electronic identification data is authentic).
Regarding claim 6, the combination of Bruno and Scott discloses the apparatus of claim 1, wherein the personal data includes a data point indicative of sensitive information and the attested data includes a confirmation that the data point is valid without revealing the data point (Scott Paras 0167, 0183: user personal data includes credit card or other sensitive information, such as confidential identifiers).
Regarding claim 7, the combination of Bruno and Scott discloses apparatus of claim 1, wherein access to the attested data in the digital wallet is protected by a user credential (Bruno Para 0015: wallet application access is secured using biometric (e.g., fingerprint, retina, and/or the like) authentication or credential information (e.g., username and password, credential information).
Regarding claim 8, the combination of Bruno and Scott discloses the apparatus of claim 7, wherein the user credential is one or more of: a username and password combination, a biometric input, or a pattern input (Bruno Para 0015: wallet application access is secured using biometric (e.g., fingerprint, retina, and/or the like) authentication or credential information (e.g., username and password, credential information).
Regarding claim 9; Claim 9 is similar in scope to claim 1, and is therefore rejected under similar rationale.
Regarding claim 10; Claim 10 is similar in scope to claim 2, and is therefore rejected under similar rationale.
Regarding claim 11; Claim 11 is similar in scope to claim 3, and is therefore rejected under similar rationale.
Regarding claim 12; Claim 12 is similar in scope to claim 4, and is therefore rejected under similar rationale.
Regarding claim 13; Claim 13 is similar in scope to claim 5, and is therefore rejected under similar rationale.
Regarding claim 14; Claim 14 is similar in scope to claim 6, and is therefore rejected under similar rationale.
Regarding claim 15; Claim 15 is similar in scope to claim 7, and is therefore rejected under similar rationale.
Regarding claim 16; Claim 16 is similar in scope to claim 8, and is therefore rejected under similar rationale.
Conclusion
10. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Fukuda et al. (US 11870907 B2) discloses a mechanism capable of safely using an online service provided by a portable device, the online service providing system comprising: a service providing server configured to provide a registered user with the online service through the Internet; an IC chip provided in a user device which is the portable device possessed by the user.
Walker et al. (US 20180007307 A1) discloses devices enabling a distributed broadcast receiver implementation where a gateway redistributes broadcast content to one or more personal devices over a local network.
11. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAHFUZUR RAHMAN whose telephone number is (571)270-7638. The examiner can normally be reached on Monday thru Friday.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached on 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MAHFUZUR RAHMAN/Primary Examiner, Art Unit 2498