Prosecution Insights
Last updated: October 02, 2026
Application No. 18/906,336

PRIVACY PRESERVING CREDENTIAL TOKEN ISSUANCE

Non-Final OA §103
Filed
Oct 04, 2024
Examiner
MAI, KEVIN S
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
International Business Machines Corporation
OA Round
3 (Non-Final)
30%
Grant Probability
At Risk
3-4
OA Rounds
2y 8m
Est. Remaining
56%
With Interview

Examiner Intelligence

Grants only 30% of cases
30%
Career Allowance Rate
131 granted / 438 resolved
-28.1% vs TC avg
Strong +26% interview lift
Without
With
+25.8%
Interview Lift
resolved cases with interview
Typical timeline
4y 8m
Avg Prosecution
25 currently pending
Career history
477
Total Applications
across all art units

Statute-Specific Performance

§101
14.2%
-25.8% vs TC avg
§103
58.2%
+18.2% vs TC avg
§102
8.3%
-31.7% vs TC avg
§112
18.0%
-22.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 438 resolved cases

Office Action

§103
DETAILED ACTION This Office Action has been issued in response to Applicant's RCE filed August 10, 2026. Claims 1, 11, and 20 have been amended. Claims 1-20 have been examined and are pending. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on July 21, 2026 has been entered. Response to Arguments Applicant's arguments filed July 21, 2026 have been fully considered but they are moot in view of the new grounds of rejection. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-3, 6-13, and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over US Pub. No. 2024/0323021 to de Kok et al. (hereinafter “de Kok”) and further in view of US Pat. No. 11277415 to Rinehart (hereinafter “Rinehart”) and further in view of US Pub. No. 2023/0177137 to Murdoch et al. (hereinafter “Murdoch”). As to Claim 1, de Kok discloses a method, in a data processing system, for [re-issuance] of credentials in a data network, the method comprising: receiving, from a requester entity, a first request to [re-issue] a target credential in a plurality of credentials of a public credential listing, [wherein multiple sets of attributes are attached to an original public key associated with the target credential, wherein the first request specifies one of the multiple sets of attributes] wherein any entity, in a plurality of entities, can request re-issuance of any credential in the plurality of credentials and have the credential successfully re-issued to that entity, wherein the first request is received without authenticating the requester entity and wherein the target credential is not associated with the requester entity (Paragraph [0133] of de Kok discloses the credential holder and the credential issuer setting up an anonymous communication channel and the credential holder requesting the credential from the credential issuer. Paragraph [0134] of de Kok discloses the claim information might relate specifically to the credential holder, e.g. whether the credential holder is employed by a certain company, whether the credential holder has been vaccinated (the issuer being health-care staff), an access authorization, or privileged contact information, or it might not relate specifically to the credential holder, e.g. an anonymous concert ticket or a concert ticket in the name of a different credential holder); in response to the first request to [re-issue] the target credential, re-randomizing the original public key associated with the target credential to generate a re-randomized public key (Paragraph [0124] of de Kok discloses performing, at the system of the credential issuer, polymorphic re-randomization and/or polymorphic pseudonymization on the signing information obtained in step 103. Step 203 comprises creating, at the system of the credential issuer, the proof for the claim information by creating the signature with the re-randomized and/or pseudonymized signing information obtained in step 201); generating a new credential based on the target credential but with the original public key replaced with the re-randomized public key, [wherein the new credential is for the one of the multiple sets of attributes specified by the first request] (Paragraph [0124] of de Kok discloses performing, at the system of the credential issuer, polymorphic re-randomization and/or polymorphic pseudonymization on the signing information obtained in step 103. Step 203 comprises creating, at the system of the credential issuer, the proof for the claim information by creating the signature with the re-randomized and/or pseudonymized signing information obtained in step 201); and providing the new credential to the requester entity, wherein the requester entity can use the new credential for authentication transactions successfully only if the requester entity is an owner of the target credential (Paragraph [0120] of de Kok discloses providing, by the system of the credential holder, a presentation of the verifiable credential received in step 111 to a system of a credential verifier). de Kok does not explicitly disclose re-issue. However, Rinehart discloses this. Column 8 lines 40-45 of Rinehart disclose the credential renewal request can include a request for new credentials for multiple expiring credentials. It would have been obvious to one of ordinary skill in the art before the effective filing of the invention to combine the credential system as disclosed by de Kok, with re-issuing multiple credentials as disclosed by Rinehart. One of ordinary skill in the art would have been motivated to combine to apply a known technique to a known device ready for improvement to yield predictable results. de Kok and Rinehart are directed toward credential systems and as such it would be obvious to use the techniques of one in the other. Column 8 lines 40-60 because only security manager 305 knows which expiring credential has been compromised, the new credentials returned by third-party server 315 can be assigned to expiring credentials by security manager 305 while excluding (or deleting) the new credential for the expiring and compromised credential. Without an association between an expiring and compromised credential and a renewed credential, a malicious attack can be neutralized (or deviated to a honeypot) without providing a malicious attack further attack possibilities with freshly renewed credentials. de Kok does not explicitly disclose wherein multiple sets of attributes are attached to an original public key associated with the target credential, wherein the first request specifies one of the multiple sets of attributes and wherein the new credential is for the one of the multiple sets of attributes specified by the first request. However, Murdoch discloses this. Paragraph [0012] of Murdoch discloses the child verifiable credential is obtained by selecting the subset of verifiable claims from the parent verifiable credential, and causing a request to be transmitted to a claims issuer computing system for the child verifiable credential that includes the selected subset of verifiable claims to be generated from the parent verifiable credential. After the claims issuer computing system transmits the requested child verifiable credential to the claims holder computing system, the claims holder computing system detects receipt of the requested child verifiable credential. It would have been obvious to one of ordinary skill in the art before the effective filing of the invention to combine the credential system as disclosed by de Kok, with requesting a subset as disclosed by Murdoch. One of ordinary skill in the art would have been motivated to combine to apply a known technique to a known device ready for improvement to yield predictable results. de Kok and Murdoch are directed toward credential systems and as such it would be obvious to use the techniques of one in the other. Implementing the teachings of Murdoch into de Kok would improve the security of the system. As to Claim 2, de Kok-Rinehart-Murdoch discloses the method of claim 1, wherein the first request is one of a plurality of requests from the same requester entity, each request in the plurality of requests requesting re-issue of a corresponding other target credential (Column 8 lines 40-45 of Rinehart disclose the credential renewal request can include a request for new credentials for multiple expiring credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 3, de Kok-Rinehart-Murdoch discloses the method of claim 2, wherein the plurality of requests comprises the first request and one or more second requests that are decoy requests submitted to hide the first request within the plurality of requests (Column 8 lines 40-60 because only security manager 305 knows which expiring credential has been compromised, the new credentials returned by third-party server 315 can be assigned to expiring credentials by security manager 305 while excluding (or deleting) the new credential for the expiring and compromised credential. Without an association between an expiring and compromised credential and a renewed credential, a malicious attack can be neutralized (or deviated to a honeypot) without providing a malicious attack further attack possibilities with freshly renewed credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 6, de Kok-Rinehart-Murdoch discloses the method of claim 1, wherein the data processing system publishes all certified public keys and credentials, for all holders that have been issued a credential, in a published listing data structure accessible to all users (Paragraph [0027] of de Kok discloses the verification information comprising group information and public cryptographic information associated with the anonymity group). As to Claim 7, de Kok-Rinehart-Murdoch discloses the method of claim 1, wherein the requesting entity is not the identity holder of the target credential, and wherein when the requesting entity presents the new credential to a verifier, the requesting entity provides an invalid presentation of the new credential (Paragraph [0093] of de Kok disclose invalid signatures always fail verification). As to Claim 8, de Kok-Rinehart-Murdoch discloses the method of claim 1, wherein: the request is one of a plurality of requests from the requesting entity, which are submitted to the data processing system, each request in the plurality of requests is directed to a different target credential, each request is successful and generates a corresponding re-issued credential that is provided to the requesting entity, the requesting entity is an identity holder associated with the target credential, and the requesting entity uses the new credential in a presentation of the new credential as part of an interaction with a verifier and discards the other re-issued credentials (Paragraph [0120] of de Kok discloses providing, by the system of the credential holder, a presentation of the verifiable credential received in step 111 to a system of a credential verifier. Column 8 lines 40-45 of Rinehart disclose the credential renewal request can include a request for new credentials for multiple expiring credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 9, de Kok-Rinehart-Murdoch discloses the method of claim 1, wherein successful collusion between an issuer of credentials and a verifier to generate a profile of an identity holder is prevented by the method since the new credential is not able to be correlated, by the issuer or verifier, with the target credential (Paragraph [0023] of de Kok discloses third parties cannot correlate verifiable credentials from the same credential issuer. Column 8 lines 40-60 because only security manager 305 knows which expiring credential has been compromised, the new credentials returned by third-party server 315 can be assigned to expiring credentials by security manager 305 while excluding (or deleting) the new credential for the expiring and compromised credential. Without an association between an expiring and compromised credential and a renewed credential, a malicious attack can be neutralized (or deviated to a honeypot) without providing a malicious attack further attack possibilities with freshly renewed credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 10, de Kok-Rinehart-Murdoch discloses the method of claim 1, wherein the target credential is a first JavaScript Object Notation (JSON) Web Token (JWT) and wherein the new credential is a second JWT comprising a same header, same attributes, but different public key and signature than the first JWT (Paragraph [0073] of de Kok disclose Different implementations may encapsulate the exchanged information in different ways, e.g. JSON, JSON-LD and XML. Paragraph [0124] of de Kok discloses performing, at the system of the credential issuer, polymorphic re-randomization and/or polymorphic pseudonymization on the signing information obtained in step 103. Step 203 comprises creating, at the system of the credential issuer, the proof for the claim information by creating the signature with the re-randomized and/or pseudonymized signing information obtained in step 201). As to Claim 11, de Kok discloses a computer program product comprising a computer readable storage medium having a computer readable program stored therein, wherein the computer readable program, when executed in a data processing system, causes the data processing system to: receive, from a requester entity, a first request to [re-issue] a target credential in a plurality of credentials of a public credential listing, [wherein multiple sets of attributes are attached to an original public key associated with the target credential, wherein the first request specifies one of the multiple sets of attributes], wherein any entity, in a plurality of entities, can request re-issuance of any credential in the plurality of credentials and have the credential successfully re-issued to that entity, wherein the first request is received without authenticating the requester entity and wherein the target credential is not associated with the requester entity (Paragraph [0133] of de Kok discloses the credential holder and the credential issuer setting up an anonymous communication channel and the credential holder requesting the credential from the credential issuer. Paragraph [0134] of de Kok discloses the claim information might relate specifically to the credential holder, e.g. whether the credential holder is employed by a certain company, whether the credential holder has been vaccinated (the issuer being health-care staff), an access authorization, or privileged contact information, or it might not relate specifically to the credential holder, e.g. an anonymous concert ticket or a concert ticket in the name of a different credential holder); re-randomize, in response to the first request to [re-issue] the target credential, the original public key associated with the target credential to generate a re-randomized public key (Paragraph [0124] of de Kok discloses performing, at the system of the credential issuer, polymorphic re-randomization and/or polymorphic pseudonymization on the signing information obtained in step 103. Step 203 comprises creating, at the system of the credential issuer, the proof for the claim information by creating the signature with the re-randomized and/or pseudonymized signing information obtained in step 201); generate a new credential based on the target credential but with the original public key replaced with the re-randomized public key, [wherein the new credential is for the one of the multiple sets of attributes specified by the first request] (Paragraph [0124] of de Kok discloses performing, at the system of the credential issuer, polymorphic re-randomization and/or polymorphic pseudonymization on the signing information obtained in step 103. Step 203 comprises creating, at the system of the credential issuer, the proof for the claim information by creating the signature with the re-randomized and/or pseudonymized signing information obtained in step 201); and provide the new credential to the requester entity, wherein the requester entity can use the new credential for authentication transactions successfully only if the requester entity is an owner of the target credential (Paragraph [0120] of de Kok discloses providing, by the system of the credential holder, a presentation of the verifiable credential received in step 111 to a system of a credential verifier). de Kok does not explicitly disclose re-issue. However, Rinehart discloses this. Column 8 lines 40-45 of Rinehart disclose the credential renewal request can include a request for new credentials for multiple expiring credentials. Examiner recites the same rationale to combine used for claim 1. de Kok does not explicitly disclose wherein multiple sets of attributes are attached to an original public key associated with the target credential, wherein the first request specifies one of the multiple sets of attributes and wherein the new credential is for the one of the multiple sets of attributes specified by the first request. However, Murdoch discloses this. Paragraph [0012] of Murdoch discloses the child verifiable credential is obtained by selecting the subset of verifiable claims from the parent verifiable credential, and causing a request to be transmitted to a claims issuer computing system for the child verifiable credential that includes the selected subset of verifiable claims to be generated from the parent verifiable credential. After the claims issuer computing system transmits the requested child verifiable credential to the claims holder computing system, the claims holder computing system detects receipt of the requested child verifiable credential. Examiner recites the same rationale to combine used for claim 1. As to Claim 12, de Kok-Rinehart-Murdoch discloses the computer program product of claim 11, wherein the first request is one of a plurality of requests from the same requester entity, each request in the plurality of requests requesting re-issue of a corresponding other target credential (Column 8 lines 40-45 of Rinehart disclose the credential renewal request can include a request for new credentials for multiple expiring credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 13, de Kok-Rinehart-Murdoch discloses the computer program product of claim 12, wherein the plurality of requests comprises the first request and one or more second requests that are decoy requests submitted to hide the first request within the plurality of requests (Column 8 lines 40-60 because only security manager 305 knows which expiring credential has been compromised, the new credentials returned by third-party server 315 can be assigned to expiring credentials by security manager 305 while excluding (or deleting) the new credential for the expiring and compromised credential. Without an association between an expiring and compromised credential and a renewed credential, a malicious attack can be neutralized (or deviated to a honeypot) without providing a malicious attack further attack possibilities with freshly renewed credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 16, de Kok-Rinehart-Murdoch discloses the computer program product of claim 11, wherein the data processing system publishes all certified public keys and credentials, for all holders that have been issued a credential, in a published listing data structure accessible to all users (Paragraph [0027] of de Kok discloses the verification information comprising group information and public cryptographic information associated with the anonymity group). As to Claim 17, de Kok-Rinehart-Murdoch discloses the computer program product of claim 11, wherein the requesting entity is not the identity holder of the target credential, and wherein when the requesting entity presents the new credential to a verifier, the requesting entity provides an invalid presentation of the new credential (Paragraph [0093] of de Kok disclose invalid signatures always fail verification). As to Claim 18, de Kok-Rinehart-Murdoch discloses the computer program product of claim 11, wherein: the request is one of a plurality of requests from the requesting entity, which are submitted to the data processing system, each request in the plurality of requests is directed to a different target credential, each request is successful and generates a corresponding re-issued credential that is provided to the requesting entity, the requesting entity is an identity holder associated with the target credential, and the requesting entity uses the new credential in a presentation of the new credential as part of an interaction with a verifier and discards the other re-issued credentials (Paragraph [0120] of de Kok discloses providing, by the system of the credential holder, a presentation of the verifiable credential received in step 111 to a system of a credential verifier. Column 8 lines 40-45 of Rinehart disclose the credential renewal request can include a request for new credentials for multiple expiring credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 19, de Kok-Rinehart-Murdoch discloses the computer program product of claim 11, wherein successful collusion between an issuer of credentials and a verifier to generate a profile of an identity holder is prevented by the method since the new credential is not able to be correlated, by the issuer or verifier, with the target credential via a public key (Paragraph [0023] of de Kok discloses third parties cannot correlate verifiable credentials from the same credential issuer. Column 8 lines 40-60 because only security manager 305 knows which expiring credential has been compromised, the new credentials returned by third-party server 315 can be assigned to expiring credentials by security manager 305 while excluding (or deleting) the new credential for the expiring and compromised credential. Without an association between an expiring and compromised credential and a renewed credential, a malicious attack can be neutralized (or deviated to a honeypot) without providing a malicious attack further attack possibilities with freshly renewed credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 20, de Kok discloses an apparatus comprising: at least one processor; and at least one memory coupled to the at least one processor, wherein the at least one memory comprises instructions which, when executed by the at least one processor, cause the at least one processor to: receive, from a requester entity, a first request to [re-issue] a target credential in a plurality of credentials of a public credential listing, [wherein multiple sets of attributes are attached to an original public key associated with the target credential, wherein the first request specifies one of the multiple sets of attributes], wherein any entity, in a plurality of entities, can request re-issuance of any credential in the plurality of credentials and have the credential successfully re-issued to that entity, wherein the first request is received without authenticating the requester entity and wherein the target credential is not associated with the requester entity (Paragraph [0133] of de Kok discloses the credential holder and the credential issuer setting up an anonymous communication channel and the credential holder requesting the credential from the credential issuer. Paragraph [0134] of de Kok discloses the claim information might relate specifically to the credential holder, e.g. whether the credential holder is employed by a certain company, whether the credential holder has been vaccinated (the issuer being health-care staff), an access authorization, or privileged contact information, or it might not relate specifically to the credential holder, e.g. an anonymous concert ticket or a concert ticket in the name of a different credential holder); re-randomize, in response to the first request to [re-issue] the target credential, the original public key associated with the target credential to generate a re-randomized public key (Paragraph [0124] of de Kok discloses performing, at the system of the credential issuer, polymorphic re-randomization and/or polymorphic pseudonymization on the signing information obtained in step 103. Step 203 comprises creating, at the system of the credential issuer, the proof for the claim information by creating the signature with the re-randomized and/or pseudonymized signing information obtained in step 201); generate a new credential based on the target credential but with the original public key replaced with the re-randomized public key, [wherein the new credential is for the one of the multiple sets of attributes specified by the first request] (Paragraph [0124] of de Kok discloses performing, at the system of the credential issuer, polymorphic re-randomization and/or polymorphic pseudonymization on the signing information obtained in step 103. Step 203 comprises creating, at the system of the credential issuer, the proof for the claim information by creating the signature with the re-randomized and/or pseudonymized signing information obtained in step 201); and provide the new credential to the requester entity, wherein the requester entity can use the new credential for authentication transactions successfully only if the requester entity is an owner of the target credential (Paragraph [0120] of de Kok discloses providing, by the system of the credential holder, a presentation of the verifiable credential received in step 111 to a system of a credential verifier). de Kok does not explicitly disclose re-issue. However, Rinehart discloses this. Column 8 lines 40-45 of Rinehart disclose the credential renewal request can include a request for new credentials for multiple expiring credentials. Examiner recites the same rationale to combine used for claim 1. de Kok does not explicitly disclose wherein multiple sets of attributes are attached to an original public key associated with the target credential, wherein the first request specifies one of the multiple sets of attributes and wherein the new credential is for the one of the multiple sets of attributes specified by the first request. However, Murdoch discloses this. Paragraph [0012] of Murdoch discloses the child verifiable credential is obtained by selecting the subset of verifiable claims from the parent verifiable credential, and causing a request to be transmitted to a claims issuer computing system for the child verifiable credential that includes the selected subset of verifiable claims to be generated from the parent verifiable credential. After the claims issuer computing system transmits the requested child verifiable credential to the claims holder computing system, the claims holder computing system detects receipt of the requested child verifiable credential. Examiner recites the same rationale to combine used for claim 1. Claims 4, 5, 14, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over de Kok-Rinehart-Murdoch and further in view of US Pub. No. 2024/0135380 to Azgad-Tromer et al. (hereinafter “Azgad”). As to Claim 4, de Kok-Rinehart-Murdoch discloses the method of claim 1. de Kok-Rinehart does not explicitly disclose wherein generating the new credential comprises performing a blind signing of the new credential by the data processing system, wherein the blind signing comprises the data processing system signing the new credential without knowing whether the requester entity is an identity owner of the target credential. However, Azgad discloses this. Paragraph [0122] of Azgad discloses it may be signed using a “blind signature” in such a way that a person who possesses the credential information can interact with the authority to obtain a signature on this credential, without the authority learning any (or some) information on the credential. It would have been obvious to one of ordinary skill in the art before the effective filing of the invention to combine the credential system as disclosed by de Kok, with blind signatures as disclosed by Azgad. One of ordinary skill in the art would have been motivated to combine to apply a known technique to a known device ready for improvement to yield predictable results. de Kok and Azgad are directed toward credential system and as such it would be obvious to use the techniques of one in the other. Implementing the techniques of Azgad in de Kok improves user privacy. As to Claim 5, de Kok-Rinehart-Murdoch-Azgad discloses the method of claim 4, wherein after blind signing of the new credential, the new credential is a reissued credential that is not able to be related to the target credential via a public key since the original public key and the re-randomized public key are uncorrelatable (Paragraph [0023] of de Kok discloses third parties cannot correlate verifiable credentials from the same credential issuer. Column 8 lines 40-60 because only security manager 305 knows which expiring credential has been compromised, the new credentials returned by third-party server 315 can be assigned to expiring credentials by security manager 305 while excluding (or deleting) the new credential for the expiring and compromised credential. Without an association between an expiring and compromised credential and a renewed credential, a malicious attack can be neutralized (or deviated to a honeypot) without providing a malicious attack further attack possibilities with freshly renewed credentials). Examiner recites the same rationale to combine used for claim 1. As to Claim 14, de Kok-Rinehart-Murdoch discloses the computer program product of claim 11. de Kok-Rinehart does not explicitly disclose wherein generating the new credential comprises performing a blind signing of the new credential by the data processing system, wherein the blind signing comprises the data processing system signing the new credential without knowing whether the requester entity is an identity owner of the target credential. However, Azgad discloses this. Paragraph [0122] of Azgad discloses it may be signed using a “blind signature” in such a way that a person who possesses the credential information can interact with the authority to obtain a signature on this credential, without the authority learning any (or some) information on the credential. Examiner recites the same rationale to combine used for claim 4. As to Claim 15, de Kok-Rinehart-Murdoch-Azgad discloses the computer program product of claim 14, wherein after blind signing of the new credential, the new credential is a reissued credential that is not able to be related to the target credential via a public key since the original public key and the re-randomized public key are uncorrelatable (Paragraph [0023] of de Kok discloses third parties cannot correlate verifiable credentials from the same credential issuer. Column 8 lines 40-60 because only security manager 305 knows which expiring credential has been compromised, the new credentials returned by third-party server 315 can be assigned to expiring credentials by security manager 305 while excluding (or deleting) the new credential for the expiring and compromised credential. Without an association between an expiring and compromised credential and a renewed credential, a malicious attack can be neutralized (or deviated to a honeypot) without providing a malicious attack further attack possibilities with freshly renewed credentials). Examiner recites the same rationale to combine used for claim 1. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Kevin S Mai whose telephone number is (571)270-5001. The examiner can normally be reached Monday to Friday 9AM to 5PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KEVIN S MAI/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Show 5 earlier events
Jun 15, 2026
Final Rejection mailed — §103
Jul 18, 2026
Interview Requested
Jul 30, 2026
Examiner Interview Summary
Jul 30, 2026
Applicant Interview (Telephonic)
Jul 31, 2026
Response after Non-Final Action
Aug 10, 2026
Request for Continued Examination
Aug 15, 2026
Response after Non-Final Action
Aug 28, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744815
Regular Expression Rule Grouping Balancer
3y 0m to grant Granted Sep 22, 2026
Patent 12717862
WEBPAGE IMAGE MONITORING METHOD AND APPARATUS, ELECTRONIC DEVICE, AND COMPUTER-READABLE STORAGE MEDIUM
4y 4m to grant Granted Aug 25, 2026
Patent 12719832
CLOUD COMMENT STORAGE USING PER-ARTIFACT KEY
4y 2m to grant Granted Aug 25, 2026
Patent 12695638
OUTSTANDING REQUESTS RELATED TO AN UPCOMING MEETING
4y 7m to grant Granted Jul 28, 2026
Patent 12657306
BMC BASED HROT IMPLEMENTATION ESTABLISHING CHAIN OF TRUST IN A SECURED SERVER SYSTEM
3y 5m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
30%
Grant Probability
56%
With Interview (+25.8%)
4y 8m (~2y 8m remaining)
Median Time to Grant
High
PTA Risk
Based on 438 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month