Prosecution Insights
Last updated: August 06, 2026
Application No. 18/916,416

SENSITIVE DATA ATTRIBUTE TOKENIZATION SYSTEM

Final Rejection §101§103§112§DP
Filed
Oct 15, 2024
Priority
Dec 16, 2021 — continuation of 12/147,573
Examiner
SUH, ANDREW
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
Revspring Inc.
OA Round
2 (Final)
79%
Grant Probability
Favorable
3-4
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
145 granted / 183 resolved
+21.2% vs TC avg
Strong +40% interview lift
Without
With
+40.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
11 currently pending
Career history
195
Total Applications
across all art units

Statute-Specific Performance

§101
9.0%
-31.0% vs TC avg
§103
54.7%
+14.7% vs TC avg
§102
11.2%
-28.8% vs TC avg
§112
19.6%
-20.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 183 resolved cases

Office Action

§101 §103 §112 §DP
DETAILED ACTION Responsive to the Applicant reply filed on 06/12/2026, Applicant' s amendments to claims have been entered and respective arguments carefully considered and responded in following: On this Office Action, claims 21-26, 28-33, 35-39 and 41-43, consisting of independent claims 21, 28, and 35. Claims 21-26, 28-33, 35-39 and 41-43 are pending. Claims 21-26, 35-39, 41 and 43 are rejected under the 35 USC § 112. Claims 21-26, 28-33, 35-39 and 41-43 are rejected under the 35 USC § 103. Claims 21-26, 28-33, 35-39 and 41-43 are Double Patent rejected. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment The amendment filed 06/12/2026 has been entered. Claims 21, 28, and 31 have been amended. Claim 27, 34 and 40 has been canceled. Claim 41-43 have been newly added. Response to Arguments With respect to Claim Rejections - 35 USC § 112 Applicant’s arguments with respect to claim rejections under 35 USC § 112 have been fully considered and are persuasive. The rejection has been withdrawn. With respect to Claim Rejections - 35 USC § 101 Applicant’s arguments with respect to claim rejections under 35 USC § 101 have been fully considered and are persuasive. The rejection has been withdrawn. With respect to Claim Rejections - 35 USC § 103 Applicant's arguments with respect to claim rejections under 35 USC § 103 have been fully considered but they are not persuasive. The arguments regarding Lindsay, on page 9-10, are reproduced below: “For example, the data service 114 may include searching for an individual's address. The de-tokenized name of the individual can be used in the search. Once completed, the individual's name can be re-tokenized to prevent unauthorized access to the sensitive data attribute. In contrast, the cited references fail to disclose at least the above limitations because they focus on generating format preserved tokens and general access of the tokenized data rather than performing services that need access to the tokenized data. … While Lindsay describes features related to the token itself, these sections fail to disclose de-tokenizing a sensitive data attribute to compose a document with information based on the sensitive data attribute. Thus, Lindsay fails to disclose every limitation of amended claim 21” In response to applicant's argument that the Lindsay fails to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., “searching for an individual's address” and/or “The de-tokenized name of the individual can be used in the search”) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Lindsay states, in paragraph [0002] and [0006], that “this disclosure relates to data tokenization for protecting sensitive data. Even more particularly, this disclosure relates to data security systems, methods, and computer program products for creating and utilizing various types of tokens. … The tokenization operation can include generating a self-describing token for replacing a value of interest in the unstructured or semi-structured content,” and “ A data processing application communicatively connected to the tokenization system may, in processing a data file, a document, or a data record, request the tokenization system to generate tokens and replace sensitive data values in the data file, the document, or the data record with the tokens before producing a processed output.” Lindsay further states, in paragraph 0056, that the sensitive data including Values that have a variable length, such as addresses, names, etc. Furthermore, the instant application is also related to “tokenize unstructured data to generate a variable length token” (See paragraph [0030] and claim 24). The arguments regarding Koduru, on page 10-11, are reproduced below: “The cited sections of Koduru also fail to disclose the above indicated portions of amended claim 21 because Koduru focuses on de-tokenizing merely for access to the data. These sections do not describe using the data for composing a document with information based on the sensitive data, then retokenizing the sensitive data based on the data service completing. Koduru cannot then disclose each limitation of amended claim 21. …. The cited sections of Koduru also fail to disclose the above indicated portions of amended claim 21 because Koduru focuses on de-tokenizing merely for access to the data. These sections do not describe using the data for composing a document with information based on the sensitive data, then retokenizing the sensitive data based on the data service completing.” In response to Applicant's argument that Koduru fails to disclose certain features of the invention, the Examiner notes, as the applicant states above and in the previous Office Action, that Koduru discloses “re-tokenization process.” The Examiner relied on 35 U.S.C. 103 to supplements the acknowledged deficiencies in Lindsay regarding re-tokenization process. Additionally, Koduru states, in paragraph [0044], that “the records 222 could be in EXCEL, WORD, TXT, ZIP, BZ2, JSON, DYNAMIC JSON, XML, HTML, PARQUET, AVRO, ORC, etc., to name a few non-limiting examples” and states, in paragraph [0041], that the records may include “personal information (e.g., name, date of birth, race and ethnicity, … , etc.), … , contact information (e.g., mailing address, email address, phone number, etc.), etc.” The remaining arguments presented in the Remarks are similar to those discussed above and are likewise unpersuasive. Accordingly, the applicant’s arguments are found not persuasive. With respect to Claim Double Patent Rejections Applicant's arguments regarding the nonstatutory double patent rejections have been fully considered but they are not persuasive for the reason set forth above and in the previous Office Action. Accordingly, the rejections are maintained. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 21 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as failing to set forth the subject matter which the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the applicant regards as the invention. For example, claim 21 recites the limitation "a final document composition process including the sensitive data attribute" in the “performing” limitation. There is insufficient antecedent basis for this limitation in the claim because the claim defines (1) the sensitive data attribute before replacing with the token, (2) the recovered sensitive data attribute after de-tokenizing and (3) the sensitive data attribute before re-tokenizing. Accordingly, it is unclear which previously recited sensitive data attribute is being referenced by “the sensitive data attribute.” The dependent claims 22-26 and 41 inherit the deficiencies of the independent claim from which they depend and are rejected as well. Independent claims 35 is directed to a non-transitory readable storage medium having a plurality of computer executable instructions that respectively corresponds to claim 21. Therefore, the claim is rejected for at least the same reasons as the method of claim 21. The dependent claims 36-39 and 43 inherit the deficiencies of the independent claim from which they depend and are rejected as well. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 21, 24-26, 28, 31-33, 35, 38-39 and 41-43 are rejected under 35 U.S.C. 103 as being unpatentable over Lindsay (US 20220067207 A1) in view of Koduru et al. (US 20210256149 A1, hereinafter “Koduru”). Regarding independent claim 21, (Currently Amended) Lindsay discloses a method for protecting sensitive data, the method comprising: Examiner’s interpretation: Lindsay states that, in paragraph [0226], “the functions of the invention can be achieved by any means as is known in the art. For example, distributed, or networked systems, components, and circuits can be used.” In view of this disclosure, the Examiner interprets Lindsay as teaching that each recited limitation may be performed by corresponding distributed or network components. Accordingly, each limitation discussed below is considered to be performed by the appropriate components as claimed. receiving, by a data loading and tokenization engine, a data file including a sensitive data attribute (Lindsay: [0152] a method 800 for securing data can include receiving, by a tokenization system from a first client computing system, a request for data anonymization, the request referencing a single field of data, file, record, or document (“a data file including a sensitive data attribute”) with unstructured or semi-structured content that contains values of interest for the data anonymization (801)); generating, by a tokenizer, a token to anonymize and visually represent the sensitive data attribute (Lindsay: [0152] The tokenization system can perform a tokenization operation on the input single field of data, file, record, or document (803)); replacing, by the tokenizer, the sensitive data attribute with the token in a tokenized data file (Lindsay: [0152] the tokenization operation produces an anonymized version of the single field of data, file, record, or document with self-describing tokens, each anonymizing and corresponding to one or more of the values of interest in the unstructured or semi-structured content); determining, by a composition and scripting engine, whether the sensitive data attribute is required for execution of a data service (Lindsay: [0152] the tokenization operation can include generating a self-describing token for replacing a value of interest in the unstructured or semi-structured content. In some embodiments, the self-describing token can have a preconfigured pattern, an indication of a protection strategy, and a token value); in response to determining that the sensitive data attribute is required for execution of the data service: de-tokenizing, by a de-tokenizer, the sensitive data attribute to recover the sensitive data attribute (Lindsay: [0153] In response, the tokenization system can perform a reveal operation on the anonymized version of the single field of data, file, record, or document (811). … The reveal operation produces a detokenized version of the anonymized version of the single field of data, file, record, or document (“recover the sensitive data attribute”, See para.[0067] regarding the sensitive information)); using, by the composition and scripting engine, the sensitive data attribute in executing the data service (Lindsay: [0153] The tokenization system can then return or otherwise communicate the detokenized version of the anonymized version of the single field of data, file, record, or document to the first client computing system or to the second client computing system (“using the sensitive data attribute”) (813)), wherein the data service includes composing a document with information based on the sensitive data attribute (Lindsay: [0153] The reveal operation produces a detokenized version of the anonymized version of the single field of data, file, record, or document); and performing, by a composition and finalization engine, a final document composition process including the sensitive data attribute (Lindsay: [0153] The reveal operation produces a detokenized version of the anonymized version of the single field of data, file, record, or document. The tokenization system can then return or otherwise communicate the detokenized version of the anonymized version of the single field of data, file, record, or document to the first client computing system or to the second client computing system (813) (“a final document composition process including the sensitive data attribute”)). However, Lindsay does not disclose, Koduru, in a same field of endeavor, teaches the method, re-tokenizing, by the tokenizer, the sensitive data attribute using the token responsive to completion of the data service, thereby resulting in a re-tokenized sensitive data attribute (Koduru: [0090] To implement a re-tokenization process, the re-tokenization service controller 1206 may generate tokens itself for the decrypted sensitive values in the de-tokenized file 1130. Or the re-tokenization service controller 1206 may instruct a token generator 1212 to generate tokens. … After receiving the tokens (“responsive to completion of the data service”), the re-tokenization service controller 1206 may generate a re-tokenized data file 1230 with the same format as the de-tokenized file 1130, by replacing the decrypted sensitive values with the re-tokenized values (“re-tokenizing, by the tokenizer, the sensitive data attribute using the token”)). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the tokenization system disclosed by Lindsay with the teachings of Koduru to re-tokenize, by the tokenizer, the sensitive data attribute using the token, thereby resulting in a re-tokenized sensitive data attribute. One of ordinary skill in the art would have been motivated to make this modification because re-tokenization may break the chain of historical data exposure. Regarding claim 24, (Previously Presented) the combination of Lindsay and Koduru teaches all elements of the current invention as stated above. Lindsay discloses the method of claim 21, wherein the sensitive data attribute includes unstructured data (Lindsay: [0152] the tokenization operation can include generating a self-describing token for replacing a value of interest in the unstructured or semi-structured content). Regarding claim 25, (Previously Presented) the combination of Lindsay and Koduru teaches all elements of the current invention as stated above. Lindsay discloses the method of claim 24, wherein the token comprises a same number of characters as the sensitive data attribute (Lindsay: [0152] the tokenization operation produces an anonymized version of the single field of data, file, record, or document with self-describing tokens, each anonymizing and corresponding to one or more of the values of interest in the unstructured or semi-structured content (“a same number of characters”, also See para. 0088 regarding “a piece of text in whitespace”)). Regarding claim 26, (Previously Presented) the combination of Lindsay and Koduru teaches all elements of the current invention as stated above. Lindsay further discloses the method of claim 21, wherein performing the final document composition process includes: generating an electronic document; and sending the electronic document to an individual (Lindsay: [0153] The reveal operation produces a detokenized version of the anonymized version of the single field of data, file, record, or document (“generate an electronic document”). The tokenization system can then return or otherwise communicate the detokenized version of the anonymized version of the single field of data, file, record, or document to the first client computing system or to the second client computing system (813) (“send the electronic document”)). Regarding independent claim 28, (Currently Amended) Lindsay discloses a system for protecting sensitive data, the system comprising: at least one processing device; at least one computer readable data storage device storing instructions that, when executed by the at least one processing device, cause the system to (Lindsay: [0219] FIG. 12 depicts a diagrammatic representation of a data processing system for implementing an embodiment disclosed herein. As shown in FIG. 12, data processing system 1200 may include one or more central processing units (CPU) or processors 1201 coupled to one or more user input/output (I/O) devices 1202 and memory devices 1203): receive a data file including a sensitive data attribute using a data loading and tokenization engine (Lindsay: [0152] a method 800 for securing data can include receiving, by a tokenization system from a first client computing system, a request for data anonymization, the request referencing a single field of data, file, record, or document (“a data file including a sensitive data attribute”) with unstructured or semi-structured content that contains values of interest for the data anonymization (801)); generate a token to anonymize and visually represent the sensitive data attribute (Lindsay: [0152] The tokenization system can perform a tokenization operation on the input single field of data, file, record, or document (803)), and replace the sensitive data attribute with the token in a tokenized data file using a tokenizer (Lindsay: [0152] the tokenization operation produces an anonymized version of the single field of data, file, record, or document with self-describing tokens, each anonymizing and corresponding to one or more of the values of interest in the unstructured or semi-structured content); use a composition and scripting engine to: determine whether the sensitive data attribute is required for execution of a data service (Lindsay: [0152] the tokenization operation can include generating a self-describing token for replacing a value of interest in the unstructured or semi-structured content. In some embodiments, the self-describing token can have a preconfigured pattern, an indication of a protection strategy, and a token value); in response to a determination that the sensitive data attribute is required for execution of the data service: de-tokenize, using a de-tokenizer, the sensitive data attribute to recover the sensitive data attribute (Lindsay: [0153] In response, the tokenization system can perform a reveal operation on the anonymized version of the single field of data, file, record, or document (811). … The reveal operation produces a detokenized version of the anonymized version of the single field of data, file, record, or document (“recover the sensitive data attribute”)); execute, using the sensitive data attribute, the data service, wherein the data service includes composing a document with information based on the sensitive data attribute (Lindsay: [0153] The tokenization system can then return or otherwise communicate the detokenized version of the anonymized version of the single field of data, file, record, or document to the first client computing system or to the second client computing system (“using the sensitive data attribute”) (813)); and perform final composition operations as part of generating a document for communication to a communication device or to be physically delivered using a composition and finalization engine (Lindsay: [0153] The reveal operation produces a detokenized version of the anonymized version of the single field of data, file, record, or document. The tokenization system can then return or otherwise communicate the detokenized version of the anonymized version of the single field of data, file, record, or document to the first client computing system or to the second client computing system (813) (“perform final composition operations”)). However, Lindsay does not disclose, Koduru, in a same field of endeavor, teaches the system, wherein re-tokenize, by using the tokenizer, the sensitive data attribute using the token responsive to completion of the data service, thereby resulting in a re-tokenized sensitive data attribute (Koduru: [0090] To implement a re-tokenization process, the re-tokenization service controller 1206 may generate tokens itself for the decrypted sensitive values in the de-tokenized file 1130. Or the re-tokenization service controller 1206 may instruct a token generator 1212 to generate tokens. … After receiving the tokens (“responsive to completion of the data service”), the re-tokenization service controller 1206 may generate a re-tokenized data file 1230 with the same format as the de-tokenized file 1130, by replacing the decrypted sensitive values with the re-tokenized values (“re-tokenizing, by the tokenizer, the sensitive data attribute using the token”)). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the tokenization system disclosed by Lindsay with the teachings of Koduru to re-tokenize, by using the tokenizer, the sensitive data attribute using the token responsive to completion of the data service, thereby resulting in a re-tokenized sensitive data attribute. One of ordinary skill in the art would have been motivated to make this modification because re-tokenization may break the chain of historical data exposure. Regarding independent claim 35, (Currently Amended) it is a non-transitory readable storage medium having a plurality of computer executable instructions that respectively corresponds to claim 21. Therefore, the claims are rejected for at least the same reasons as the system of claim 21. Regarding claims 31 and 38, (Previously Presented) they are a system and a non-transitory readable storage medium having a plurality of computer executable instructions that respectively corresponds to claim 24. Therefore, the claims are rejected for at least the same reasons as the system of claim 24. Regarding claims 32 and 39, (Previously Presented) they are a system and a non-transitory readable storage medium having a plurality of computer executable instructions that respectively corresponds to claim 25. Therefore, the claims are rejected for at least the same reasons as the system of claim 25. Regarding claim 33, (Previously Presented) it is a system that respectively corresponds to claim 26. Therefore, the claims are rejected for at least the same reasons as the system of claim 26. Regarding claim 41, (New) the combination of Lindsay and Koduru teaches all elements of the current invention as stated above. Koduru discloses the method of claim 21, wherein the data service includes searching for an address associated with the sensitive data attribute (Koduru: [0049] The tokenization service controller 206 may record the address of each sensitive data field when identifying and extracting the sensitive data fields 224, so that the replacement is exact). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the tokenization system disclosed by Lindsay with the teachings of Koduru to search for an address associated with the sensitive data attribute. One of ordinary skill in the art would have been motivated to make this modification because it may deliver faster retrieval, granular control, and immense operational efficiency. Regarding claims 42 and 43, (New) they are a system and a non-transitory readable storage medium having a plurality of computer executable instructions that respectively corresponds to claim 41. Therefore, the claims are rejected for at least the same reasons as the system of claim 41. Claims 22, 29 and 36 are rejected under 35 U.S.C. 103 as being unpatentable over Lindsay (US 20220067207 A1) in view of Koduru et al. (US 20210256149 A1, hereinafter “Koduru”) as applied to claims above, and further in view of SCHENK et al. (US 20170093812 A1, hereinafter “Schenk”). Regarding claim 22, (Previously Presented) the combination of Lindsay and Koduru teaches all elements of the current invention as stated above. However, the combination does not disclose, Schenk, in a same filed of endeavor, teaches the method of claim 21, further comprising storing the sensitive data attribute in a digital vault, and mapping the sensitive data attribute to: the data file; an attribute field in the data file that includes the sensitive data attribute; and the token (Schenk: [0036] data vaulting (“stored in a digital vault”) and tokenization server 36 has the ability to generate token values (“token”) using a named pattern such as payment card (e.g. credit or debit card, loyalty card, or the like (“the sensitive data attribute”)), or by using a pattern or string representing the format that the token should follow). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the tokenization system disclosed by Lindsay with the teachings of Schenk to include the sensitive data attribute is stored in a digital vault and to includes a mapping to the data file, an attribute field in the data file that includes the sensitive data attribute and the token. One of ordinary skill in the art would have been motivated to make this modification because the data vaulting and tokenization server runs vault processing software, which provides data tokenization and data vaulting capability (para. 0245). Thus, it allows auditing such as a history of all changes and load times and record sources. Regarding claims 29 and 36, (Previously Presented) they are a system and a non-transitory readable storage medium having a plurality of computer executable instructions that respectively corresponds to claim 22. Therefore, the claims are rejected for at least the same reasons as the system of claim 22. Claims 23, 30 and 37 are rejected under 35 U.S.C. 103 as being unpatentable over Lindsay (US 20220067207 A1) in view of Koduru et al. (US 20210256149 A1, hereinafter “Koduru”) in view of SCHENK et al. (US 20170093812 A1, hereinafter “Schenk”) as applied to claims above, and further in view of in view of ARDHANARI et al. (US 20210248268 A1, hereinafter “Ardhanari”). Regarding claim 23, (Previously Presented) the combination of Lindsay, Koduru and Schenk teaches all elements of the current invention as stated above. However, the combination does not disclose, Ardhanari, in a same filed of endeavor, teaches the method of claim 22, wherein the token comprises: a document identifier corresponding to the data file; and an attribute field identifier corresponding to the attribute field (Ardhanari: [0245] In some embodiments, the inverted list 1731-1739 may identify a document identifier corresponding to the document in which the token occurs, an offset within the document to the occurrence of the token, or the like (“document identifier corresponding to the data file”). In some embodiments, each entry in the inverted list 1731-1739 may include a plurality of location identifiers for each occurrence of each token (“attribute field identifier corresponding to the attribute field”)). Before the effective filing date of the claimed invention, it would have been obvious for one of ordinary skill in the art to have modified the tokenization system disclosed by Lindsay with the teachings of Ardhanari to include a document identifier corresponding to the data file; and an attribute field identifier corresponding to the attribute field. One of ordinary skill in the art would have been motivated to make this modification because the plurality of identifiers may be stored in an appropriate data structure (para. 0245). Thus, the plurality of identifiers in an appropriate data structure are used to distinguish fields from each other. Regarding claims 30 and 37, (Previously Presented) they are a system and a non-transitory readable storage medium having a plurality of computer executable instructions that respectively corresponds to claim 23. Therefore, the claims are rejected for at least the same reasons as the system of claim 23. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 21-26, 28-33, 35-39 and 41-43 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 and 3-8 of U.S. Patent No. US 12147573 B2 (hereinafter “Pat-573”). As per independent claims 21, 28, and 35, Pat-573’s claim 1 teaches all elements of the independent claims of the instant application. Although the claims are not identical - for example, with respect to the underlined features - they are not patentably distinct from each other. Specifically, claim 1 of Pat-573 contains every elements of the claim 21 of the instant application (see the comparison table below). Pat-573 Instant Application 18/916416 1 receiving, by a data loading and tokenization engine, a data file including a sensitive data attribute; identifying, by the data loading and tokenization engine, the sensitive data attribute; generating, by a tokenizer, a token to anonymize and visually represent the sensitive data attribute; replacing, by the tokenizer, the sensitive data attribute with the token in a tokenized data file; performing, by a composition and scripting engine, a document composition process for composing a document using the tokenized data file, wherein the document composition process comprises: determining, by the composition and scripting engine, whether the sensitive data attribute is required for execution of a data service in relation to the document composition process; in response to the determination that the sensitive data attribute is required for execution of the data service; de-tokenizing, by a de-tokenizer, the sensitive data attribute; using, by the composition and scripting engine, the sensitive data attribute in executing the data service as part of the document composition process; and re-tokenizing, by the tokenizer, the sensitive data attribute using the token, thereby resulting in a re-tokenized sensitive data attribute; de-tokenizing, by the de-tokenizer, the re-tokenized sensitive data attribute; and performing, by a composition and finalization engine, a final document process, wherein the document includes the sensitive data attribute. 21 receiving, by a data loading and tokenization engine, a data file including a sensitive data attribute; generating, by a tokenizer, a token to anonymize and visually represent the sensitive data attribute; replacing, by the tokenizer, the sensitive data attribute with the token in a tokenized data file; determining, by a composition and scripting engine, whether the sensitive data attribute is required for execution of a data service; in response to determining that the sensitive data attribute is required for execution of the data service: de-tokenizing, by a de-tokenizer, the sensitive data attribute to recover the sensitive data attribute; using, by the composition and scripting engine, the sensitive data attribute in executing the data service, wherein the data service includes composing a document with information based on the sensitive data attribute; re-tokenizing, by the tokenizer, the sensitive data attribute using the token responsive to completion of the data service, thereby resulting in a re-tokenized sensitive data attribute; and performing, by a composition and finalization engine, a final document composition process including the sensitive data attribute. As per respective claims of the independent claims above, they are respectively identical to claims 3-8 of Pat-573. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Mehta et al. (US 20240098069 A1): [0058] As seen in the example of FIG. 4, masking service 162 of computing system 160 initially may receive text data containing customer personal information, wherein the customer personal information originates from a customer-facing service associated with an externally-hosted application (300). Next, detection unit 164 of masking service 162 may detect the customer personal information in the text data using one or more detection layers, each detection layer configured to detect a different type of customer personal information (305). Next, anonymization unit 168 of masking unit 162 may generate, based on output of the one or more detection layers, tokenized data by replacing each instance of the customer personal information detected in the text data with a respective token (310). In some examples, anonymization unit 168 may also generate signaling information that defines the tokenization of the customer personal information (315). Furthermore, in some examples, anonymization unit 168 may cache the text data and the signaling information (320). Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANDREW SUH whose telephone number is (571)270-5524. The examiner can normally be reached 9:00 AM- 5:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ANDREW SUH/Primary Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Oct 15, 2024
Application Filed
Mar 16, 2026
Non-Final Rejection mailed — §101, §103, §112
Jun 12, 2026
Response Filed
Jul 07, 2026
Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688327
DYNAMIC BALANCING OF INTERESTS IN DATA PRIVACY INTEGRATION PROTOCOLS
2y 3m to grant Granted Jul 21, 2026
Patent 12675607
OBFUSCATING USER DATA VIA DIFFERENTIAL PRIVACY
3y 0m to grant Granted Jul 07, 2026
Patent 12671600
METHOD FOR IMPROVED HASH CHAINING AUTHENTICATION
2y 11m to grant Granted Jun 30, 2026
Patent 12659178
CONSORTIUM BLOCKCHAIN ADMISSION MANAGEMENT METHOD AND APPARATUS
1y 0m to grant Granted Jun 16, 2026
Patent 12645832
TOKEN-BASED DATA SECURITY SYSTEMS AND METHODS WITH EMBEDDABLE MARKERS IN UNSTRUCTURED DATA
2y 3m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+40.0%)
2y 9m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 183 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month