Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed Action
Claims 1, 2, 4, and 5 are amended
Claim 3 is cancelled
Claims 1, 2, 4, and 5 are pending
Priority
This application is a continuation application of International Application PCT/JP2022/027677 filed on Jul. 14, 2022. Therefore, the effective filing date of this application is 07/14/2022.
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 04/17/2026 and 05/01/2026. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements have been considered by the examiner.
Response to Arguments
Applicant’s arguments filed on 04/14/2026 have been fully considered.
With respect to the double patenting rejection for claims 1, 4, and 5. Applicant has mentioned that a terminal disclaimer has been filed. However, no terminal disclaimer has been filed. Therefore, the double patenting rejection is being maintained.
With respect to the USC 112(b) rejection for claims 1-5. The rejection has been overcome due to Applicant’s amendments.
With respect to the USC 101 abstract rejection for claim 1. Applicant has argued that the claimed invention does not recite a mental process. Applicant has argued that the limitation of generating a zero-knowledge proof requires the need of a computer and cannot be performed manually by a human. Examiner respectfully disagrees. A zero knowledge proof is a cryptographic method that can be performed by a user either mentally or with pencil and paper, regardless of how tedious it might be. Applicant has further argued that the claim language integrates into a practical application by mentioning that the specification identifies a technical problem of the difficulty of verifying the validity of a cumulative value. Examiner respectfully disagrees. The claim limitations do not integrate into a practical application. The claims currently recite of generating for a first process a zero knowledge proof, causing a blockchain to record the zero-knowledge proof, wherein generating the zero-knowledge proof includes receiving an input of a cumulative value of a second process, generating the cumulative value of the first process by accumulating a predetermined cumulative value and the received cumulative value of the second process, and wherein the predetermined cumulative value obtained is a zero value. None of these limitations integrate into a practical application. Simply generating a zero knowledge proof by accumulating values and recording the proof in a blockchain is not a practical application. The steps relate to data generation, data manipulation, and data storage. Applicant has further argued that the claim invention includes an inventive concept amounting to significantly more. Examiner respectfully disagrees. A blockchain and zero-knowledge proof generation can be performed on a generic computing hardware as recited in the claims. Claim 1 recites of a generic non-transitory computer-readable medium storing a proof generation program that causes a computer to execute processing. Similarly in claim 5 a generic memory and processor is recited. The claims do not teach of a specialized hardware to perform these limitations. Therefore, the claims are directed towards an abstract idea and the USC 101 rejection is maintained.
With respect to the USC 102 rejection Applicant has argued that SAHAI fails to teach of the newly amended limitation of “wherein the generating of the zero-knowledge proof includes: receiving an input of a cumulative value of a second process performed immediately before the first process in the supply chain; and generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information stored in a storage device and the received cumulative value of the second process, and wherein the predetermined cumulative value obtained from the dummy trail information is a zero value.” However, SAHAI teaches “wherein the generating of the zero-knowledge proof includes: receiving an input of a cumulative value of a second process performed immediately before the first process in the supply chain; ([SAHAI, Preliminaries, page 135] “A cryptographic accumulator [6] is a one-way function, that succinctly commits a set of values to a constant size digest. The commitments are hiding and binding, and support succinct proofs of membership, and often, non-membership of values in the accumulator. RSA accumulator [10] is a dynamic accumulator”) ([SAHAI, Security Analysis, page 141] “Our protocol satisfies the above notion of contamination tracing by using cryptographic accumulators. As described in Section V and V-A, each document contains accumulator for the set of all its upstream documents.”) ([SAHAI, Entry, page 137] “Since this document does not have any previous references, InDocs is set to empty list ([]).”)([SAHAI, Merge, page 138] “we have the transaction initiator provide the value dAcco along with a zero knowledge proof π2 showing that the value is correct.”) and generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information stored in a storage device and the received cumulative value of the second process, and wherein the predetermined cumulative value obtained from the dummy trail information is a zero value. ([SAHAI, Fig. 2, page 137] “Supply Chain Graph”) ([SAHAI, Table 1, page 137] “DocAccumulator: An accumulator value corresponding to the set of IDs of all the upstream documents of the given document.”) ([SAHAI, Merge, page 138] “The merge transaction payload differs from those of entry and shipment transactions by including the accumulator value dAcco for the output document. In other transactions, the value of the accumulator can be calculated, however, in case of Merge, we wish dAcco to represent the union of set of upstream documents for each of the input documents, i.e, we wish to ensure: dAcco := acc(Ui,1 ∪ Ui,2 ∪ {dpo}) where Ui,j denotes the keys of all upstream documents of the document doci,j for j = 1, 2. For most accumulators, the smart contract cannot compute dAcco without the knowledge of sets Ui,1 and Ui,2. Instead, we have the transaction initiator provide the value dAcco along with a zero knowledge proof π2 showing that the value is correct”) ([SAHAI, Entry, page 137] “A product Entry operation introduces an item on the supply chain. The corresponding supply chain transaction outputs a document doco describing the introduced item. The transaction txentry consists of the tuple: txentry := dtentry, InDocs = [], OutDocs = [dpo], dh = [ho], pcert, π). Since this document does not have any previous references, InDocs is set to empty list ([]).”). As seen from these citations SAHAI teaches of each document contains an accumulator for the set of all its upstream documents, and of a cryptographic accumulator. SAHAI teaches receiving an accumulator value of a process performed immediately before because in SAHAI each document contains accumulator for the set of all its upstream documents. All upstream documents include a process performed immediately before. Furthermore, SAHAI teaches generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information stored in a storage device and the received cumulative value of the second process. SAHAI teaches ([SAHAI, Merge, page 138] “we wish dAcco to represent the union of set of upstream documents for each of the input documents, i.e, we wish to ensure: dAcco := acc(Ui,1 ∪ Ui,2 ∪ {dpo}) where Ui,j denotes the keys of all upstream documents of the document doci,j for j = 1, 2.”) If a document has no previous reference InDocs is set to an empty list. An empty list is analogous to a dummy tail information consisting of a zero value. Based on the amendment of “generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information” and on SAHAI not explicitly teaching that an accumulated predetermined value is zero, Examiner is modifying the rejection from a USC 102 to a USC 103.
Applicant has further argued “the proof-generation unit is intentionally designed with a fixed number of input units, which may be larger than the number of actual upstream processes for a given supplier. The claimed "dummy trail information" serves as a specific, functional padding mechanism, which provides a "zero value" as a computational input into the unused input units. This technical architecture solves the specific problem of how to provide a common proof generation program that is applicable to various suppliers having different numbers of upstream components, thereby avoiding the complexity and inefficiency of designing a unique proof generation circuit for each different supply chain structure.” However, this is not recited in the claim. The claim broadly recites of dummy trail information which is a zero value. Examiner suggests further amending the claim to clarify the claim language and help better distinguish from the cited prior art.
Additional arguments are moot in view of new grounds of rejection necessitated by the claim amendments.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1, 4, and 5 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 of U.S. Patent No. US 12267430 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the corresponding claims further recite similar/same limitation of the same subject matter.
Current application No. 18/938,436
U.S. Patent No. US 12267430 B2
1.) A non-transitory computer-readable recording medium storing a proof generation program that causes a computer to execute processing comprising: generating, for a first process being any one of a plurality of processes included in a supply chain, zero-knowledge proof that indicates validity of a cumulative value obtained by accumulating a value of each process from a most upstream process to the first process among the plurality of processes and information regarding the cumulative value; and causing a blockchain to record the zero-knowledge proof and the information regarding the cumulative value, wherein the generating of the zero-knowledge proof includes: receiving an input of a cumulative value of a second process performed immediately before the first process in the supply chain; and generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information stored in a storage device and the received cumulative value of the second process, and wherein the predetermined cumulative value obtained from the dummy trail information is a zero value.
1.) A non-transitory computer-readable recording medium storing an information concealing program for causing a computer to execute processing in a predetermined stage of a plurality of stages included in a supply chain, the processing comprising:
obtaining, from an immediately upstream stage, a first random number and a first cumulative value, the first random number being a random number used to generate a first cumulative value commitment, the first cumulative value commitment being a cumulative value commitment obtained by concealing the first cumulative value that is from a most upstream stage to the immediately upstream stage;
generating, based on the first random number, an upstream component link commitment information obtained by concealing information indicative of a relationship between the immediately upstream stage and the predetermined stage;
calculating, based on the first cumulative value, a second cumulative value that is from the most upstream stage to the predetermined stage;
generating a cumulative value calculation proof information that indicates that the second cumulative value is calculated by using the correct first cumulative value and that is a zero-knowledge proof based on the upstream component link commitment information; and
causing the upstream component link commitment information and the cumulative value calculation proof information to be recorded in a blockchain.
Claims 4 and 5 are parallel claims to independent claim 1. Therefore, claims 4 and 5 are rejected in a similar manner.
Claims 1, 4, and 5 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 of U.S. Patent No. US 12301721 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the corresponding claims further recite similar/same limitation of the same subject matter.
Current application No. 18/938,436
U.S. Patent No. US 12301721 B2
1.) A non-transitory computer-readable recording medium storing a proof generation program that causes a computer to execute processing comprising: generating, for a first process being any one of a plurality of processes included in a supply chain, zero-knowledge proof that indicates validity of a cumulative value obtained by accumulating a value of each process from a most upstream process to the first process among the plurality of processes and information regarding the cumulative value; and causing a blockchain to record the zero-knowledge proof and the information regarding the cumulative value, wherein the generating of the zero-knowledge proof includes: receiving an input of a cumulative value of a second process performed immediately before the first process in the supply chain; and generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information stored in a storage device and the received cumulative value of the second process, and wherein the predetermined cumulative value obtained from the dummy trail information is a zero value.
1.) A non-transitory computer-readable storage medium storing an information management program that causes at least one computer to execute a process, the process comprising:
acquiring a first cumulative consideration amount from a most upstream process in a plurality of processes included in a supply chain to a first process of the plurality of processes based on a second cumulative consideration amount from the most upstream process to the first process, a first cumulative value from the most upstream process to the first process, and a second cumulative value from the most upstream process to a second process which is one upstream process of the first process;
generating a consideration amount commitment by concealing the first cumulative consideration amount by using a random number;
registering the consideration amount commitment in a blockchain;
generating a consideration amount proof that is a zero knowledge proof that proves validity of the second cumulative consideration amount without disclosing the second cumulative consideration amount; and
notifying the second process of the second cumulative consideration amount, the random number, and the consideration amount proof.
Claims 4 and 5 are parallel claims to independent claim 1. Therefore, claims 4 and 5 are rejected in a similar manner.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefore, subject to the conditions and requirements of this title.
Claims 1, 2, 4, and 5 are rejected under 35 U.S.C. 101 because they directed to an abstract idea.
Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim recites of a non-transitory computer-readable recording medium storing a proof generation program that causes a computer to execute processing comprising: generating, for a first process being any one of a plurality of processes included in a supply chain, zero-knowledge proof that indicates validity of a cumulative value obtained by accumulating a value of each process from a most upstream process to the first process among the plurality of processes and information regarding the cumulative value; and causing a blockchain to record the zero-knowledge proof and the information regarding the cumulative value, wherein the generating of the zero-knowledge proof includes: receiving an input of a cumulative value of a second process performed immediately before the first process in the supply chain; and generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information stored in a storage device and the received cumulative value of the second process, and wherein the predetermined cumulative value obtained from the dummy trail information is a zero value.
The limitation of generating, for a first process being any one of a plurality of processes included in a supply chain, zero-knowledge proof that indicates validity of a cumulative value obtained by accumulating a value of each process from a most upstream process to the first process among the plurality of processes and information regarding the cumulative value, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually generate for each process in a supply chain zero-knowledge proof that indicates validity of a cumulative value.
The limitation of causing a blockchain to record the zero-knowledge proof and the information regarding the cumulative value, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually cause a blockchain to record the zero-knowledge proof and the information regarding the cumulative value.
The limitation of wherein the generating of the zero-knowledge proof includes: receiving an input of a cumulative value of a second process performed immediately before the first process in the supply chain, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually receive a cumulative value of a second process performed immediately before the first process.
The limitation of and generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information stored in a storage device and the received cumulative value of the second process, and wherein the predetermined cumulative value obtained from the dummy trail information is a zero value, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually generate the cumulative value of the first process by accumulating a predetermined cumulative value and the received cumulative value of the second process.
If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic statement such as “non-transitory computer-readable recording medium storing a proof generation program that causes a computer to execute a process”, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. The claim recites of generating for a first process a zero-knowledge proof, causing a blockchain to record the zero-knowledge proof, wherein generating the zero-knowledge proof includes receiving an input of a cumulative value of a second process, and generating the cumulative value of the first process by accumulating predetermined cumulative value and the cumulative value of a second process. The claim’s recitation of causing a blockchain to record the zero-knowledge proof is merely a form of storing data. Simply storing data does not integrate the claim into a practical application. The claim is directed to an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of “computer” amounts to no more than mere instructions to apply the exception using a generic computer. Mere instructions to apply an exception using a generic computer cannot provide an inventive concept. The claim is not patent eligible.
Claim 2 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the information regarding the cumulative value includes a cumulative value commitment for the cumulative value, and the zero-knowledge proof is generated using trail information that includes a trail that indicates that the first process has been performed and zero-knowledge proof that indicates validity of the cumulative value of the second process. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually generate a zero-knowledge proof using trail information that includes a trail that indicates that the process has been performed and zero-knowledge proof that indicates validity of a cumulative value of the second process.
Regarding claims 4 and 5. Claims 4 and 5 recite of features similar to that of independent claim 1. Without reciting additional features that are not directed to an abstract idea. Therefore, claims 4 and 5 are rejected in a similar manner as in the rejection of claim 1.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1, 2, 4, and 5 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1, 4, and 5 recite of the limitation “the received cumulative value of the second process”. However, there is insufficient antecedent basis for “the received cumulative value”. Claim 1 recites of “receiving an input of a cumulative value of a second process”. For the purpose of examination, Examiner is interpreting this limitation as “the received input of the cumulative value of the second process”. Appropriate correction is required.
Claim 2 depends on claim 1. Therefore, this claim also inherits the rejection.
Claim 2 recites of “the cumulative value”. It is unclear if this refers to the cumulative value of the first process or the second process. For the purpose of examination, Examiner is interpreting this limitation as “the cumulative value of the first process”. Appropriate correction is required.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 2, 4, and 5 are rejected under 35 U.S.C. 103 as being unpatentable over (“Enabling Privacy and Traceability in Supply Chains using Blockchain and Zero Knowledge Proofs”), hereinafter SAHAI.
Regarding claim 1, SAHAI teaches “A non-transitory computer-readable recording medium storing a proof generation program that causes a computer to execute processing comprising: ([SAHAI, abstract, page 134] “In recent years there have been increased efforts to make supply chains transparent and traceable to better protect the end consumer’s interests against counterfeiting … property enables an end consumer to be convinced about a product to be unaffected by identified faulty upstream processes (contamination) without access to the entire history of the product. Our solution makes novel use of cryptographic tools such as zero-knowledge proofs and cryptographic accumulators to provide these guarantees. The choice of the cryptographic components is grounded in concrete efficiency, and we present an experimental evaluation of the implementation of our protocol on Hyperledger Fabric, a popular platform for enterprise blockchains”) ([SAHAI, computation setup, page 141] “For our experiments, we used Hyperledger Fabric v2.0 as the underlying blockchain, deployed on Docker version 19.03.11. The chaincode and algorithms for generating provable primes and RSA accumulators were implemented in Golang. We used libsnark library [4] to build the circuits for basic gadgets discussed in Section V-B and for generating and verifying SNARK proofs. The experiments were run on an Intel i7-4770 CPU @ 3.40GHz with 8 cores and 32 GB RAM running Ubuntu 18.04.”) generating, for a first process being any one of a plurality of processes included in a supply chain, zero-knowledge proof that indicates validity of a cumulative value obtained by accumulating a value of each process from a most upstream process to the first process among the plurality of processes and information regarding the cumulative value; and ([SAHAI, abstract, page 134] “Our solution makes novel use of cryptographic tools such as zero-knowledge proofs and cryptographic accumulators to provide these guarantees.”) ([SAHAI, Trust model, page 137] “The payload of a transaction additionally contains zero-knowledge proofs for establishing the well-formedness of the document or establishing the relationship between the contents of input/output documents”) ([SAHAI, Merge, page 138] “π1 is a zero knowledge proof for the following: … (doci,1.Quantity + doci,2.Quantity == doco.Quantity) … The merge transaction payload differs from those of entry and shipment transactions by including the accumulator value dAcco for the output document. In other transactions, the value of the accumulator can be calculated, however, in case of Merge, we wish dAcco to represent the union of set of upstream documents for each of the input documents, i.e, we wish to ensure: dAcco := acc(Ui,1 ∪ Ui,2 ∪ {dpo}) where Ui,j denotes the keys of all upstream documents of the document doci,j for j = 1, 2. For most accumulators, the smart contract cannot compute dAcco without the knowledge of sets Ui,1 and Ui,2. Instead, we have the transaction initiator provide the value dAcco along with a zero knowledge proof π2 showing that the value is correct. ”) ([SAHAI, Document Types, page 136] “upstream documents constitute all the documents from which D is reachable, and downstream documents are all the reachable documents from D. Then, provenance for a document can be established by tracing back all its upstream documents.”) causing a blockchain to record the zero-knowledge proof and the information regarding the cumulative value. ([SAHAI, Merge, page 138] “The corresponding transaction is a multiple input single output transaction. The transaction txmerge is structured as: (dtmerge, InDocs, OutDocs, dh = [ho], dAccout, pcert, π1, π2) …. The transaction is added to the ledger and on successful validation the smart contract updates the state database as L[dpo] = doco, where doco = (dtmerge, ho, dpo, dAcco, InDocs).”) wherein the generating of the zero-knowledge proof includes: receiving an input of a cumulative value of a second process performed immediately before the first process in the supply chain; ([SAHAI, Preliminaries, page 135] “A cryptographic accumulator [6] is a one-way function, that succinctly commits a set of values to a constant size digest. The commitments are hiding and binding, and support succinct proofs of membership, and often, non-membership of values in the accumulator. RSA accumulator [10] is a dynamic accumulator”) ([SAHAI, Security Analysis, page 141] “Our protocol satisfies the above notion of contamination tracing by using cryptographic accumulators. As described in Section V and V-A, each document contains accumulator for the set of all its upstream documents.”) ([SAHAI, Entry, page 137] “Since this document does not have any previous references, InDocs is set to empty list ([]).”) ([SAHAI, Merge, page 138] “we have the transaction initiator provide the value dAcco along with a zero knowledge proof π2 showing that the value is correct.”) and generating the cumulative value of the first process by accumulating a predetermined cumulative value obtained from dummy trail information stored in a storage device and the received cumulative value of the second process ([SAHAI, Fig. 2, page 137] “Supply Chain Graph”) ([SAHAI, Table 1, page 137] “DocAccumulator: An accumulator value corresponding to the set of IDs of all the upstream documents of the given document.”) ([SAHAI, Merge, page 138] “The merge transaction payload differs from those of entry and shipment transactions by including the accumulator value dAcco for the output document. In other transactions, the value of the accumulator can be calculated, however, in case of Merge, we wish dAcco to represent the union of set of upstream documents for each of the input documents, i.e, we wish to ensure: dAcco := acc(Ui,1 ∪ Ui,2 ∪ {dpo}) where Ui,j denotes the keys of all upstream documents of the document doci,j for j = 1, 2. For most accumulators, the smart contract cannot compute dAcco without the knowledge of sets Ui,1 and Ui,2. Instead, we have the transaction initiator provide the value dAcco along with a zero knowledge proof π2 showing that the value is correct”) ([SAHAI, Entry, page 137] “A product Entry operation introduces an item on the supply chain. The corresponding supply chain transaction outputs a document doco describing the introduced item. The transaction txentry consists of the tuple: txentry := dtentry, InDocs = [], OutDocs = [dpo], dh = [ho], pcert, π). Since this document does not have any previous references, InDocs is set to empty list ([]).”)
SAHAI does not explicitly disclose of “wherein the predetermined cumulative value obtained from the dummy trail information is a zero value”. However, given the teaching of SAHAI it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to modify SAHAI to include a predetermined cumulative value being a zero value because in generating the cumulative value of the first process the predetermined value is accumulated with the received cumulative value of the second process. However, since the predetermined value is zero essentially nothing is being accumulated with the received cumulative value of the second process. This is equivalent to dAcco recited in SAHAI where if a document has no previous references, InDocs is set to empty list ([]) and therefore nothing would be accumulated. Therefore, it is obvious to accumulate a zero value.
Regarding claim 2, SAHAI teaches all limitations of claim 1. SAHAI further teaches “wherein the information regarding the cumulative value includes a cumulative value commitment for the cumulative value, and ([SAHAI, Preliminaries, page 135] “A cryptographic accumulator [6] is a one-way function, that succinctly commits a set of values to a constant size digest. The commitments are hiding and binding, and support succinct proofs of membership, and often, non-membership of values in the accumulator. RSA accumulator [10] is a dynamic accumulator”) the zero-knowledge proof is generated using trail information that includes a trail that indicates that the first process has been performed and zero-knowledge proof that indicates validity of the cumulative value of the second process. ([SAHAI, Fig. 2, page 137] “Supply Chain Graph”) ([SAHAI, Table 1, page 137] “DocAccumulator: An accumulator value corresponding to the set of IDs of all the upstream documents of the given document.”) ([SAHAI, Merge, page 138] “The merge transaction payload differs from those of entry and shipment transactions by including the accumulator value dAcco for the output document. In other transactions, the value of the accumulator can be calculated, however, in case of Merge, we wish dAcco to represent the union of set of upstream documents for each of the input documents, i.e, we wish to ensure: dAcco := acc(Ui,1 ∪ Ui,2 ∪ {dpo}) where Ui,j denotes the keys of all upstream documents of the document doci,j for j = 1, 2. For most accumulators, the smart contract cannot compute dAcco without the knowledge of sets Ui,1 and Ui,2. Instead, we have the transaction initiator provide the value dAcco along with a zero knowledge proof π2 showing that the value is correct”) ([SAHAI, Computing Accumulator for Merge Transaction Outputs, page 139] “the transaction validation requires certain predicates to be established over the document content, such as Sender-Recipient coupling or quantity conservation. We accomplish this by using Zero-Knowledge Succinct Arguments of Knowledge”)
Regarding claim 4, this claim recites of a method that performs the features of independent claim 1. Therefore, claim 4 is rejected in a similar manner as in the rejection of claim 1. SAHAI further teaches ([SAHAI, Evaluation of cryptographic components, page 141] “One of our protocol’s key features is to efficiently prove to an end-customer that given a document for a final product F, it does not involve an identified upstream document D.”)
Regarding claim 5, this claim recites of an information processing apparatus that performs the features of independent claim 1. Therefore, claim 5 is rejected in a similar manner as in the rejection of claim 1. SAHAI further teaches ([SAHAI, computation setup, page 141] “For our experiments, we used Hyperledger Fabric v2.0 as the underlying blockchain, … The experiments were run on an Intel i7-4770 CPU @ 3.40GHz with 8 cores and 32 GB RAM running Ubuntu 18.04.”)
Pertinent Art
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure.
ANDREINA (US-20210374274-A1): This prior art teaches of a method of generating a deniable commitment of personal data of a user with an unlinkable proof of the commitment of the personal data for securing user privacy in a digital identity system includes receiving the personal data of the user and receiving the commitment of the personal data according to a commitment scheme. An interactive zero-knowledge proof is engaged in with the user so as to verify that the commitment of the personal data opens to the personal data of the user.
HU (US-20200322128-A1): This prior art teaches of an example operation may include one or more of receiving one or more responses to a storage request for a blockchain from one or more endorser nodes of the blockchain, extracting transaction data of the storage request included in the one or more responses, generating a zero-knowledge proof of endorsement based on the extracted transaction data and the one or more responses, and transmitting the zero-knowledge proof to a blockchain node for inclusion within a data block among a hash-linked chain of data blocks.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFAQ ALI whose telephone number is (571)272-1571. The examiner can normally be reached Mon - Fri 7:30am - 5:30pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.A./
09/03/2026
/AFAQ ALI/Examiner, Art Unit 2434
/NOURA ZOUBAIR/Primary Examiner, Art Unit 2434