Prosecution Insights
Last updated: October 02, 2026
Application No. 18/658,587

SYSTEMS AND METHODS FOR PROVIDING ATTESTED VERIFICATION OF PERSONAL DATA

Final Rejection §103
Filed
May 08, 2024
Priority
May 09, 2023 — provisional 63/465,168
Examiner
RAHMAN, MAHFUZUR
Art Unit
2498
Tech Center
2400 — Computer Networks
Assignee
Tyco Fire & Security GmbH
OA Round
2 (Final)
91%
Grant Probability
Favorable
3-4
OA Rounds
1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 91% — above average
91%
Career Allowance Rate
694 granted / 764 resolved
+32.8% vs TC avg
Moderate +8% lift
Without
With
+8.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
13 currently pending
Career history
780
Total Applications
across all art units

Statute-Specific Performance

§101
21.9%
-18.1% vs TC avg
§103
49.8%
+9.8% vs TC avg
§102
5.5%
-34.5% vs TC avg
§112
10.9%
-29.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 764 resolved cases

Office Action

§103
DETAILED ACTION This Office Action is in response to the amendment filed on 03/12/2026 in which Claims 1-16 are presented for examination on the merits. Notice of Pre-AIA or AIA Status The present application is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted 05/13/2026 has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Form PTO-1449 is signed and attached hereto. Response to Arguments 1. With regards to the rejection under 35 USC § 103(a), Applicant's arguments in pages 6-9 of the REMARKS filed on 03/12/2026 have been considered. However, after careful review, the rejection under 35 U.S.C. 103(a) to claims 1-16 are maintained for the reasons specified in the rejection below. 2. Regarding independent claims 1 and 9 rejected under 35 U.S.C. 103(a), applicant argues, for example: “..neither Bruno nor Scott, whether taken alone or in combination, teaches or renders obvious the claimed limitation of generating a verification response indicating possession of at least one attribute..” and further argues that Bruno merely discloses local wallet unlocking and presentation of credentials, rather than generating a targeted verification response. The argument is not persuasive. The Office Action previously mapped this limitation to Bruno’s disclosure of electronic identification instruments and tokens being generated, associated, and validated via a credential system (e.g., token engine and credential engine). Bruno teaches that identity information (e.g., electronic identification instruments) and corresponding tokens are provisioned to a wallet and subsequently validated by comparing received data with stored validation information. Such validation inherently communicates that a user possesses a qualifying credential or attribute. Contrary to Applicant’s characterization, the claimed “verification response” does not require any particular form, format, or semantic content beyond indicating possession of an attribute. Under the broadest reasonable interpretation (BRI), the validation result or token-based confirmation transmitted in Bruno constitutes a response that indicates possession of at least one attribute (e.g., possession of a valid credential, identity instrument, or associated token). Further, Scott teaches responding to transaction or access requests using wallet-stored credentials and secure tokens in communication with trusted platforms. Such responses inherently indicate that the user possesses the underlying credential or authorization required for the transaction. Applicant’s distinction between: (i) “unlocking a wallet and presenting contents,” and (ii) “generating a targeted verification response,” is not commensurate with the scope of the claims. The claims do not require a specialized or tailored “targeted” response beyond indicating possession of an attribute. The combined teachings of Bruno and Scott clearly provide mechanisms where: credentials/tokens are generated and stored, and responses based on those credentials are transmitted to requesting entities. Accordingly, one of ordinary skill in the art would have understood that the validation or token-based response in Bruno (as enhanced by Scott’s transaction-based response mechanisms) meets the claimed limitation. Moreover, even if Bruno alone does not explicitly describe the response as “indicating possession,” Scott’s disclosure of responding to requests using tokens and credentials renders the limitation obvious when combined. The combination merely applies known credential validation outputs in a predictable manner (KSR). 3. Regarding independent claims 1 and 9 rejected under 35 U.S.C. 103(a), applicant argues, for example: “..Applicant respectfully submits that neither Bruno nor Scott, alone or in combination, teaches or suggests this claimed feature...... the apparatus transmits to the verifying entity a verification response and attested data confirming the user possesses a qualifying attribute” asserting that Bruno transmits full identification documents containing personal data. After careful review, the Examiner respectfully disagrees. Bruno explicitly discloses the use of tokens associated with electronic identification instruments, where the token is distinct from the underlying personal data. Tokens function as proxies for sensitive data and are used for validation and authentication purposes. As such, Bruno teaches a system in which: the credential (or identity information) is abstracted via a token, and the token is used in communications instead of directly transmitting the underlying personal data. This is consistent with the claimed concept of transmitting attested data while excluding personal data. Further, Scott reinforces this teaching by disclosing secure payment tokens and trusted platform communications, where sensitive data is not directly exposed during transactions. Scott’s system relies on tokenization and secure processing to validate transactions without transmitting raw personal information. Applicant’s argument that Bruno “inherently contains personal data” overlooks the explicit role of tokens as substitutes or abstractions of such data. The use of tokens and credential validation mechanisms would have suggested to one of ordinary skill in the art the well-known design choice of: transmitting proof of possession (via tokens or validation results), rather than transmitting raw personal data. Furthermore, the claimed “attested data” broadly encompasses any data confirming possession of an attribute. Tokens, validation outputs, or credential confirmations in Bruno and Scott meet this definition under broadest reasonable interpretation (BRI). As is clearly evident from the above explicit teachings, even if the claimed language is not identical to that disclosed by the cited references, the differences between that which is disclosed and that which is claimed are considered to be so slight (i.e. predictable variance, KSR, MPEP 2143) that it would have been obvious to the skilled artisan to modify the teachings of Bruno and Scott as a design preference and make the invention as claimed especially when each feature and function of the claimed invention is present in the references. The Applicant has failed to clearly explain the pertinence of each cited passage, by failing to clearly articulate the difference between claim features and specification, with a convincing rationale and factual support. As is readily evident, the claimed invention as a whole was at least prima facie obvious, if not anticipated by the reference, especially in the absence of sufficient, clear, and convincing evidence to the contrary. In view of the above teachings in Bruno, it would have been obvious to one of ordinary skilled in the art before the effective filing of the claimed invention, to attest data confirming the user possesses a qualifying attribute...transmit... the attested data without including the personal data...", because such a modification would have been considered a mere configuration preference, and thus, would have been obvious to try. 4. Regarding independent claims 1 and 9 rejected under 35 U.S.C. 103(a), applicant argues, for example: “..Moreover, the Examiner's motivation to combine-"to enable the use of multiple payment accounts to fund purchases and other electronic transactions" (Scott Abstract) speaks to multi- account payment functionality, not to privacy-preserving attribute verification. Neither reference recognizes the problem of disclosing personal data during identity verification, let alone proposes the claimed solution of withholding personal data while transmitting only a verification response and attested data. Accordingly, neither Bruno nor Scott, whether taken alone or in combination, teaches or renders obvious the claimed limitation of transmitting the verification response and the attested data to the verifying entity without including the personal data.” The Examiner respectfully submits that Scott et al. does not change the principle of operation of the primary reference or render the reference inoperable for its intended purpose. See MPEP § 2143.01. The test for obviousness is not whether the features of a secondary reference may be bodily incorporated into the structure of the primary reference Bruno. Rather, the test is what the combined teachings of those references would have suggested to those of ordinary skill in the art.” In re Keller, 642 F.2d 413, 425, 208 USPQ 871, 881 (CCPA 1981). See also In re Sneed, 710 F.2d 1544, 1550, 218 USPQ 385, 389 (Fed. Cir. 1983). It is not necessary that the inventions of the references be physically combinable to render obvious the invention under review.”; and In re Nievelt, 482 F.2d 965, 179 USPQ 224, 226 (CCPA 1973). Combining the teachings of references Bruno and Scott does not involve an ability to combine their specific structures. Thus, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Therefore, prior arts must be considered in entirely, including discloses that teach away from the claims, MPEP § 2143.01-02. The “mere existence of differences between the prior art and an invention does not establish the invention’s nonobviousness.” Dann v. Johnston, 425 U.S. 219, 230, 189 USPQ 257, 261 (1976). The gap between the prior art and the claimed invention may not be “so great as to render the [claim] nonobvious to one reasonably skilled in the art.” Id. MPEP 2141 (section III). In view of the above, it would have been obvious to the skilled artisan to modify the teachings of Scott with the teachings of Bruno to perform the functions of the method as claimed including: “…generate a verification response indicating possession of the at least one attribute; identify, in a digital wallet, attested data issued by a trusted entity that confirms possession of the at least one attribute of the personal data; transmit, to the verifying entity, the verification response and the attested data without including the personal data; and receive a grant or denial of the access request from the verifying entity…”. The proposed combination would have been obvious because: both references operate in the same field (digital wallets, credentials, secure transactions), both rely on tokens and credential validation, and combining them yields predictable results (secure verification of user attributes without exposing sensitive data). Claim Rejections - 35 USC § 103 5. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 6. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 7. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 8. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. 9. Claims 1-16 are rejected under 35 U.S.C. 103 as being unpatentable over Bruno et al. (US 20200265417 A1, hereinafter, Bruno) in view of Scott et al. (US 20220020016 A1, hereinafter, Scott). Regarding claim 1, Bruno discloses an apparatus for attested verification of personal data, comprising: one or more memories; and one or more hardware processors coupled with the one or more memories and configured, individually or in combination, to: transmit an access request to a verifying entity (Para 0019, 0027: receive/request and validate identity information from one or more identity providers wherein validation information is requested from the user) wherein the access request is for a service, product, or information accessible solely to an authorized user (Para 0047, 0051, 0031: tokens/credentials associated with a given merchant and trusted user made services accessible such as complete a transaction); receive, from the verifying entity, a verification request that indicates at least one attribute of personal data that classifies a user as the authorized user (Para 0019, 0027, 0031: receive/request and validate identity information from one or more identity providers wherein validation information is requested from the user. For example, validate, verify, authorize, and/or otherwise confirm if token being provided is authentic and/or corresponds to a particular user account). generate a verification response indicating possession of the at least one attribute; identify, in a digital wallet (Para 0015, 0040, 0051, 0085: processing users biometric (e.g., fingerprint, retina, and/or the like) authentication or credential information (e.g., username and password), wherein virtual wallet uses token or credentials for verification) [attested data issued by a trusted entity that confirms possession of the at least one attribute of the personal data]; transmit, to the verifying entity, the verification response [and the attested data] without including the personal data; and receive a grant or denial of the access request from the verifying entity (Para 0031, 0087, 0096: In response to receiving confirmation that the transaction account details have been verified and approved, the information/response is relayed back to the client that access is granted to complete transaction …..confirming that the token being provided is authentic and/or corresponds to a particular user account); Bruno does not explicitly state but Scott from the same or similar fields of endeavor teaches attested data issued by a trusted entity that confirms possession of the at least one attribute of the personal data (Scott, Para 0141, 0146, 0167: Wallet application verifies the certificate including a code or token uniquely identifying the certification status associated with user's credentials stored in wallet application) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention wherein attested data issued by a trusted entity that confirms possession of the at least one attribute of the personal data as taught by Scott in the teachings of Bruno in order to enable the use of multiple payment accounts to fund purchases and other electronic transactions associated with accounts or payment tokens which are stored on device(s) secure data sets known as virtual or electronic wallets (Scott, Abstract). Regarding claim 2, the combination of Bruno and Scott discloses the apparatus of claim 1, the verifying entity is configured to: confirm, with the trusted entity, whether the verification response is authentic (Bruno Paras 0030-0031: first token and the first electronic identification are presented together to the wallet reader of an identity requester to confirm that the first electronic identification data is authentic); and grant or deny the access request based on the whether the verification response is confirmed to be authentic (Bruno Para 0096: in response to receiving confirmation that the transaction account details have been verified, the information is relayed back to the merchant/customer, who completes the payment transaction. In response to the verification being denied, the payment processor relays the information to the merchant, who declines the transaction). Regarding claim 3, the combination of Bruno and Scott discloses the apparatus of claim 2, wherein the [attested data] in the digital wallet is encrypted by a first encryption key of the trusted entity, and wherein the verifying entity confirms whether verification response is authentic(Bruno, Para 0096, 0031: encrypting transaction account details including sensitive information the token, for example, which is being validated, verified, authorized and/or otherwise confirmed as authentic and corresponds to a particular user account by being configured to: transmit the verification response and the attested data to the trusted entity (Bruno, Para 0019, 0027: receive/request and validate identity information from one or more identity providers wherein validation information is requested from the user); and receive, from the trusted entity, confirmation that the verification response is authentic (Bruno, Para 0030-0031, 0087, 0096: In response to receiving confirmation that the transaction account details have been verified and approved, the information/response is relayed back to the client that access is granted to complete transaction …..confirming that the token being provided is authentic and/or corresponds to a particular user account) Bruno does not explicitly state but Scott from the same or similar fields of endeavor teaches attested data associated with aforesaid claim limitations (Scott, Para 0141, 0146, 0167: Wallet application verifies the certificate including a code or token uniquely identifying the certification status associated with user's credentials stored in wallet application) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have attested data as taught by Scott in the teachings of Bruno in order to enable the use of multiple payment accounts to fund purchases and other electronic transactions associated with accounts or payment tokens which are stored on device(s) secure data sets known as virtual or electronic wallets (Scott, Abstract). Regarding claim 4, the combination of Bruno and Scott discloses the apparatus of claim 3, wherein the trusted entity is configured to: decrypt the attested data using a second encryption key of the trusted entity; and confirm that the verification response is authentic in response to determine that the verification response matches with the attested data that is decrypted (Scott, Para 0206, 0174, 0055: verified transaction data is forwarded for decryption wherein token or payment credential is being processed as authentic matching the registered identifying information associated with the merchant's certificate) Regarding claim 5, the combination of Bruno and Scott discloses the apparatus of claim 1, wherein the one or more hardware processors are further configured, individually or in combination, to: transmit, to the trusted entity, an attestation request and the personal data (Bruno Para 0015, Claims 8, 20: requesting access the electronic identification information comprising credential information from the user), wherein the attestation request includes a plurality of attributes comprising the at least one attribute that the trusted entity should attest; receive, from the trusted entity, a plurality of attested data points generated based on the personal data (Bruno Para 0096, 015: an application service provider service that authorizes customer and the merchant information including biometric (e.g., fingerprint, retina, and/or the like) authentication or credential information (e.g., username and password, credential information), wherein the plurality of attested data points includes the attested data confirming possession of the at least one attribute of the personal data; and store the plurality of attested data points in the digital wallet (Bruno Paras 0030-0031: first token and the first electronic identification are presented together to the wallet reader of an identity requester to confirm that the first electronic identification data is authentic). Regarding claim 6, the combination of Bruno and Scott discloses the apparatus of claim 1, wherein the personal data includes a data point indicative of sensitive information and the attested data includes a confirmation that the data point is valid without revealing the data point (Scott Paras 0167, 0183: user personal data includes credit card or other sensitive information, such as confidential identifiers). Regarding claim 7, the combination of Bruno and Scott discloses apparatus of claim 1, wherein access to the attested data in the digital wallet is protected by a user credential (Bruno Para 0015: wallet application access is secured using biometric (e.g., fingerprint, retina, and/or the like) authentication or credential information (e.g., username and password, credential information). Regarding claim 8, the combination of Bruno and Scott discloses the apparatus of claim 7, wherein the user credential is one or more of: a username and password combination, a biometric input, or a pattern input (Bruno Para 0015: wallet application access is secured using biometric (e.g., fingerprint, retina, and/or the like) authentication or credential information (e.g., username and password, credential information). Regarding claim 9; Claim 9 is similar in scope to claim 1, and is therefore rejected under similar rationale. Regarding claim 10; Claim 10 is similar in scope to claim 2, and is therefore rejected under similar rationale. Regarding claim 11; Claim 11 is similar in scope to claim 3, and is therefore rejected under similar rationale. Regarding claim 12; Claim 12 is similar in scope to claim 4, and is therefore rejected under similar rationale. Regarding claim 13; Claim 13 is similar in scope to claim 5, and is therefore rejected under similar rationale. Regarding claim 14; Claim 14 is similar in scope to claim 6, and is therefore rejected under similar rationale. Regarding claim 15; Claim 15 is similar in scope to claim 7, and is therefore rejected under similar rationale. Regarding claim 16; Claim 16 is similar in scope to claim 8, and is therefore rejected under similar rationale. Conclusion 10. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Fukuda et al. (US 11870907 B2) discloses a mechanism capable of safely using an online service provided by a portable device, the online service providing system comprising: a service providing server configured to provide a registered user with the online service through the Internet; an IC chip provided in a user device which is the portable device possessed by the user. Walker et al. (US 20180007307 A1) discloses devices enabling a distributed broadcast receiver implementation where a gateway redistributes broadcast content to one or more personal devices over a local network. 11. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAHFUZUR RAHMAN whose telephone number is (571)270-7638. The examiner can normally be reached on Monday thru Friday. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached on 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MAHFUZUR RAHMAN/Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

May 08, 2024
Application Filed
Nov 15, 2025
Non-Final Rejection (signed) — §103
Dec 16, 2025
Non-Final Rejection mailed — §103
Mar 12, 2026
Response Filed
May 19, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743382
Key Management in Computer Processors
2y 10m to grant Granted Sep 22, 2026
Patent 12730865
AUTHENTICATION SYSTEM, AUTHENTICATION METHOD, AND COMPUTER READABLE MEDIUM
1y 11m to grant Granted Sep 08, 2026
Patent 12724859
WATERMARK PROCESSING
1y 9m to grant Granted Sep 01, 2026
Patent 12712716
QUANTUM-BASED DISTRIBUTED LEDGER
2y 1m to grant Granted Aug 18, 2026
Patent 12712885
SYSTEM FOR SIMPLIFYING EXECUTABLE INSTRUCTIONS FOR OPTIMISED VERIFIABLE COMPUTATION
1y 12m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
91%
Grant Probability
99%
With Interview (+8.4%)
2y 6m (~1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 764 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month