Prosecution Insights
Last updated: August 17, 2026
Application No. 18/944,905

SYSTEMS AND METHODS FOR IDENTIFYING AND TRACKING DIGITAL CERTIFICATES FOR SECURE INTERFACING IN A DISTRIBUTED NETWORK

Non-Final OA §101§102§103§112
Filed
Nov 12, 2024
Examiner
TRAN, TRI MINH
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Bank of America Corporation
OA Round
1 (Non-Final)
82%
Grant Probability
Favorable
1-2
OA Rounds
9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
464 granted / 567 resolved
+23.8% vs TC avg
Strong +34% interview lift
Without
With
+34.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
16 currently pending
Career history
573
Total Applications
across all art units

Statute-Specific Performance

§101
12.9%
-27.1% vs TC avg
§103
51.8%
+11.8% vs TC avg
§102
20.8%
-19.2% vs TC avg
§112
5.4%
-34.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 567 resolved cases

Office Action

§101 §102 §103 §112
DETAILED ACTION Claims 1-20 are pending. This is in response to the application filed on November 12, 2024. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 13-17 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because the computer program product, under broadest interpretation, is not one of eligible subject matter. It is read as a software claim. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 1 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 recites the limitation "the at least one communication device" in the second limitation. There is insufficient antecedent basis for this limitation in the claim. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-20 are rejected under 35 U.S.C. 103 as being anticipated by Pub 20050071630 (hereinafter Thornton) Regarding claim 1, Thornton discloses a system for identifying and tracking digital certificates for secure interfacing in a distributed network, the system comprising: a memory device with computer-readable program code stored thereon; at least one processing device operatively coupled to the at least one memory device and the at least one communication device (Figs. 5-6 and par. [0138]-[0140] discloses a system to manage certificates for enterprises comprise servers, clients, etc. where the certificate manager in Fig. 6 combines all functionalities of 55-60 as illustrated in Fig. 5. It is inherent the certificate manager comprises memory, program code, processor, etc. as a standard computing device at the least), wherein executing the computer-readable code is configured to cause the at least one processing device to: generate a certificate reader component, wherein the certificate reader component is coupled to at least one host server (the scanner is a reader and host servers S1-S4); identify, by the certificate reader component, at least one digital certificate applied to the at least one host server (par. [0139]); automatically collect digital certificate data for the at least one digital certificate; generate a digital certificate database comprising the collected digital certificate data for the at least one digital certificate (par. [0139]); receive a query for the digital certificate database, wherein the query comprises at least one of a digital certificate identifier, a website identifier, an application identifier, or a host identifier (par. [0081]-[0084] discloses certificates are stored in a database, hence suggesting using queries to perform functions related to database access and par. [0165] discloses certificate id and the common name recorded in each certificate. See also Appendix A for same example related to query statements that can resulted in errors 100, 101, etc.); and generate, based on the query, a report interface component, wherein the report interface component comprises the collected digital certificate data for at least one of the digital certificate identifier, the website identifier, the application identifier, or the host identifier (Fig. 28). Regarding claim 2, Thornton discloses wherein the certificate reader component is coupled to a public key infrastructure component associated with the at least one host server (as known in the art, certificates represent Public key infrastructure (PKI)). Regarding claim 3, Thornton discloses wherein the at least one digital certificate is associated with at least one application or website hosted on the at least one host server (par. [0096] and [0194] discloses servers S1-S4 can be web servers, application servers, etc.). Regarding claim 4, Thornton discloses wherein the identification of the at least one digital certificate by the certificate reader component is identified in real-time to the application of the at least one digital certificate to the at least one host server (Fig. 5 and related text disclose certificate scanning based on IP address range and can be set to scan by interval or immediate). Regarding claim 5, Thornton discloses identify at least one application associated with the identified at least one digital certificate; identify a plurality of host servers hosting the at least one application; and update the digital certificate database with a plurality of host server identifiers associated with the plurality of host servers (Figs. 31, 61 and related text discloses different host servers for different types of applications). Regarding claim 6, Thornton discloses wherein the certificate reader component identifies all digital certificates hosted on the at least one host server (par. [0166] and [0173] discloses an exemplary view reporting all managed certificates). Regarding claim 7, Thornton discloses wherein the collected digital certificate data comprises at least one of an expiration for the at least one digital certificate, at least one of an application identifier or a website identifier for the at least one digital certificate, at least one of a website public key or an application public key for the at least one digital certificate, or at least one of a live status or a dead status for the at least one digital certificate (Fig. 10 and related text discloses managing certificate based on its status). Regarding claim 8, Thornton discloses scan, by the certificate reader component, the at least one host server, wherein the scan is a full file system scan of the at least one host server; automatically collect, based on the scan of the at least one host server, live digital certificate data and historical digital certificate data; and update the digital certificate database with the live digital certificate data and the historical digital certificate data associated with the at least one host server (Figs. 16-17 and related text discloses certificate management comprises editing, removing, historical activity. Also, par. [0105] discloses locating the server configuration file referencing the certificates on the server). Regarding claim 9, Thornton discloses wherein the at least one host server scanned is a network comprising the at least one host server, and wherein the scan is a full file system scan of the network (par. [01015] discloses scanning certificate information to all server files). Regarding claim 10, Thornton discloses wherein the network scanned comprises a range of networks, and wherein the range of networks is based on a range of internet protocol (IP) addresses (Fig. 25). Regarding claim 11, Thornton discloses wherein the certificate reader component scans the network at a pre-determined interval (Fig. 25). Regarding claim 12, Thornton discloses validate the collected digital certificate data that was previously collected by the digital certificate component by comparing the live digital certificate data and historical digital certificate data of the at least one host server (Figs. 9-10 and par. [0113], [0137] discloses certificate management for a server. Note that par. [0174] discloses comparing current certificate against past/revoked certificate in an example of a client device. One would expect the same procedure should apply to a server or any device for certificate management). Regarding claims 13 and 18, the claims are rejected in view of claim 1 rejection. Regarding claims 14 and 19, the claim is rejected in view of claim 2 rejection. Regarding claim 15, the claims are rejected in view of claim 4 rejection. Regarding claim 16, the claim is rejected in view of claim 5 rejection. Regarding claims 17 and 20, the claims are rejected in view of claim 8 rejection. Inquiry communication Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRI M TRAN whose telephone number is (571)270-1994. The examiner can normally be reached Mon-Fri: 9am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469)295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TRI M TRAN/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Nov 12, 2024
Application Filed
Jun 10, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688290
LOW RESOURCE NEARLINE ATTACK DETECTION
2y 3m to grant Granted Jul 21, 2026
Patent 12683929
SINGLE CONFIGURATION FOR MULTI-CLOUD FIREWALL DEPLOYMENT
2y 3m to grant Granted Jul 14, 2026
Patent 12682060
LLM TECHNOLOGY FOR POLYMORPHIC GENERATION OF SAMPLES OF MALWARE FOR FUTURE MALWARE DETECTION
2y 1m to grant Granted Jul 14, 2026
Patent 12657309
DELIVERING AUGMENTED THREAT ASSESSMENT VALUES TO A SECURITY THREAT MANAGEMENT FACILITY
2y 11m to grant Granted Jun 16, 2026
Patent 12659132
PROVIDING RANDOM NUMBERS OVER AN INSECURE CHANNEL USING DISGUISED CYPHERTEXTS
1y 10m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
82%
Grant Probability
99%
With Interview (+34.4%)
2y 6m (~9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 567 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month