Prosecution Insights
Last updated: August 17, 2026
Application No. 18/987,548

AUTHENTICATION USING PERSISTENT TOKEN AND MDM CERTIFICATE

Non-Final OA §103§112
Filed
Dec 19, 2024
Examiner
MAHMOUDI, RODMAN ALEXANDER
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
197 granted / 247 resolved
+21.8% vs TC avg
Strong +17% interview lift
Without
With
+16.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
15 currently pending
Career history
274
Total Applications
across all art units

Statute-Specific Performance

§101
8.5%
-31.5% vs TC avg
§103
56.5%
+16.5% vs TC avg
§102
16.0%
-24.0% vs TC avg
§112
13.2%
-26.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 247 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 5 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the application regards as the invention. Regarding claim 5, it is unclear due to the lack of antecedent basis for “an MDM token” in line 2, as to whether this MDM token is the same MDM token recited in dependent claim 4. The claim is therefore rendered indefinite. Appropriate correction(s) is/are required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 11, 15, 17 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Manning (U.S. PGPub. 2014/0173705), in view of Wen (U.S. PGPub. 2014/0372544). Regarding claim 1, Manning teaches A system, comprising: one or more processors configured to (Manning, Paragraph [0081], see “…the computing environment 800 includes at least one central processing unit 810…”): determine whether a persistent token is cached locally on a client (Manning, FIG. 1, see “122”, which depicts a PERSISTENT CREDENTIAL STORAGE (locally) on a client) (Manning, Paragraph [0036], see “…the current credential can be checked to determine if it is older than the authentication refresh delay…If the current credential is not older than the authentication refresh delay…then a new credential will not be generated…If a new credential is not generated, then the client device will retain the current credential that is currently persisted at the client device and can use the current credential upon subsequent communication with the server environment”); in response to determining that the cached persistent token is not cached locally on the client, send from the client a request for the persistent token to a token resource, and obtain a new persistent token (Manning, Paragraph [0034], see “At 250, application processing is performed…application processing can comprise responding to an application services request from the user…”, where “request from the user” is being read as sending from a client a request for a persistent token to properly perform the application processing) (Manning, Paragraph [0035], see “Once the application processing has been performed at 250, a new credential is generated and provided to the client device for persistence at the client device…”) (Manning, Paragraph [0036], see “In some implementations, a new credential is only generated if the current credential is older than an authentication refresh delay…, where “current credential is older than an authentication refresh delay” is being read as the cached persistent token not being cached locally on the client due to it being expired); and authenticate the client with a portal based at least in part on the persistent token (Manning, Paragraph [0026], see “…any of the computing devices (e.g., nodes, application servers, etc.) of the server environment 110 that participate in the distributed authentication can service requests from the client device by receiving and authenticating the credential provided by the client device”); wherein: a cached persistent token is used for authentication in response to a determination that the cached persistent token is cached locally on the client (Manning, Paragraph [0036], see “…the current credential can be checked to determine if it is older than the authentication refresh delay…If the current credential is not older than the authentication refresh delay…then a new credential will not be generated…If a new credential is not generated, then the client device will retain the current credential that is currently persisted at the client device and can use the current credential upon subsequent communication with the server environment”); and the new persistent token is used for authentication in response to a determination that the persistent token is not cached locally on the client (Manning, Paragraph [0035], see “Once the application processing has been performed at 250, a new credential is generated and provided to the client device for persistence at the client device…”) (Manning, Paragraph [0036], see “In some implementations, a new credential is only generated if the current credential is older than an authentication refresh delay…, where the new persistent token is used for authentication in response to determining that the persistent token is not cached locally on the client (i.e., expired)); and a memory coupled to the one or more processors and configured to provide the one or more processors with instructions (Manning, Figure 8) (Manning, Paragraph [0081], see “…The memory 820 stores software…”). However, assuming arguendo that Manning does not adequately teach determining that the cached persistent token is not cached locally on the client, the Examiner introduces Wen which more specifically teaches the above limitation, see Wen, Paragraph [0059], see “Usually the session token is kept “alive” in the browser as long as the user is logged on to the Web server. In some cases the session token may be deleted when the user logs-out from the Web Server…” and Paragraph [0072], see “…the cookie with token was not found in the browser of the device that User1 is using, then the server generates a temporary session token and pushes it to User1’s browser…”, which is analogous to generating a new token after determining that the token is not cached locally on the client browser). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Manning, by implementing techniques of determining that the cached token is not cached locally on the client, disclosed of Wen. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for authentication using persistent tokens and MDM certificates, comprising of determining that the cached token is not cached locally on the client. This allows for better security management, as well as preventing silent failures, ultimately ensuring interrupted access due to expired or inexistant tokens while maintaining security protocols. Wen is deemed as analogous art due to the art disclosing techniques of determining that the cached token is not cached locally on the client (Wen, Paragraph [0059]). Regarding claim 11, Manning as modified by Wen teaches The system of claim 1, wherein the persistent token is valid for a predefined period of time (Manning, Paragraph [0036], see “…the current credential can be checked to determine if it is older than the authentication refresh delay (e.g., using the expiration time of the current credential)…”, which is being read as the persistent token (e.g., current credential) being valid for a predefined period of time). Regarding claim 15, Manning as modified by Wen teaches The system of claim 1, wherein the client stores an indication of the persistent token used in connection with a particular authentication of the client (Manning, Paragraph [0025], see “…the credentials can be stored by the client device 120 in persistent credential storage 122 (e.g., in a file, database, browser cookie, etc.)…the credentials are stored only at the client device 120, and not at the server environment 110…”, which is being read as the client storing an indication of the persistent token (e.g., credentials) used in connection with a particular authentication of the client, due to the credential being used in connection with a particular authentication of the client). Regarding claim 17, Manning as modified by Wen teaches The system of claim 1, wherein in response to a determination that authentication of the client fails for a reason other than the persistent token, the client maintains the persistent token for future authentication attempts (Manning, Paragraph [0019], see “…a client device using such a persistent stateless credential can authenticate in a secure manner to any of a number of servers of a server environment to access computing resources provided by the server environment…if a particular server of the server environment fails, then an already authenticated client can still use a different server without having to go through another logon procedure (e.g., if the user’s credential has not yet expired)”, which is being read as in response to a determination that authentication of the client fails for a reason other than the persistent token (e.g., server failure), the client maintains the persistent token for future authentication attempts (e.g., as long as it’s not expired)). Regarding claims 19-20, the claims are rejected under the same reasoning as claim 1. Claims 2-3 are rejected under 35 U.S.C. 103 as being unpatentable over Manning, in view of Wen, in further view of Gizis et al. (U.S. PGPub. 2023/0171683), hereinafter Gizis. Regarding claim 2, Manning as modified by Wen do not teach the following limitation(s) as taught by Gizis: The system of claim 1, wherein the client comprises a network security client running on a managed device (Gizis, Paragraph [0003], see “…the network being used for data services may be monitored and managed by the VPN to ensure the client device is using the network(s) designated by the VPN…”, which is analogous to the client comprising a network security client (e.g., VPN client) running on a managed device (e.g., VPN server)) (Gizis, Paragraph [0025], see “…a transport connection is a connection between the VPN client and the VPN server…”). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Manning, and techniques disclosed of Wen, by implementing techniques of the client comprising a VPN client running on a managed device, disclosed of Gizis. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for authentication using persistent tokens and MDM certificates, comprising of the client comprising a VPN client running on a managed device. This allows for better security management, privacy protection and data encryption by creating a secure tunnel between the client and Internet. Gizis is deemed as analogous art due to the art disclosing techniques of the client comprising a VPN client running on a managed device (Gizis, Paragraph [0003]). Regarding claim 3, Manning as modified by Wen do not teach the following limitation(s) as taught by Gizis: The system of claim 2, wherein the network security client is a VPN client (Gizis, Paragraph [0003], see “…the network being used for data services may be monitored and managed by the VPN to ensure the client device is using the network(s) designated by the VPN…”, which is analogous to the client comprising a network security client (e.g., VPN client)) (Gizis, Paragraph [0025], see “…a transport connection is a connection between the VPN client and the VPN server…”). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Manning, and techniques disclosed of Wen, by implementing techniques of the client comprising a VPN client, disclosed of Gizis. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for authentication using persistent tokens and MDM certificates, comprising of the client comprising a VPN client. This allows for better security management, privacy protection and data encryption by creating a secure tunnel between the client and Internet. Gizis is deemed as analogous art due to the art disclosing techniques of the client comprising a VPN client (Gizis, Paragraph [0003]). Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Manning, in view of Wen, in further view of Kubovcik et al. (U.S. Patent 12,166,872), hereinafter Kubo. Regarding claim 12, Manning as modified by Wen do not teach the following limitation(s) as taught by Kubo: The system of claim 1, wherein authenticating the client with the portal based at least in part on the persistent token comprises: prompting a user to select whether to a use a cached persistent token certificate or a mobile device management (MDM) token certificate (Kubo, Claim 1, see “…receive from the HSM through the secure link a list of certificates stored in the HSM, receive from the user a selected certificate from the list of certificates…”, which is analogous to prompting a user to select whether to use a cached token certificate or a mobile device token certificate). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Manning, and techniques disclosed of Wen, by implementing techniques of prompting a user to select whether to use a cached certificate or a mobile certificate, disclosed of Kubo. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for authentication using persistent tokens and MDM certificates, comprising of prompting a user to select whether to use a cached certificate or a mobile certificate. This allows for a more user-friendly environment, whilst optimizing authentication through balancing security, convenience and flexibility. Kubo is deemed as analogous art due to the art disclosing techniques of prompting a user to select whether to use a cached certificate or a mobile certificate (Kubo, Claim 1). Claim 16 is rejected under 35 U.S.C. 103 as being unpatentable over Manning, in view of Wen, in further view of Herzog et al. (U.S. PGPub. 2012/0090017), hereinafter Herzog. Regarding claim 16, Manning as modified by Wen do not teach the following limitation(s) as taught by Herzog: The system of claim 1, wherein the client uses different persistent tokens and corresponding certificates for authentication with different gateways (Herzog, Paragraph [0047], see “…the server name is validated through a certificate by any trusted root…”) (Herzog, Paragraph [0076], see “…Since the token is originally generated by the client and is dedicated to a specific gateway and server, the client can always contact the gateway and revoke the token…”, which is analogous to the client using different tokens and corresponding certificates for authentication with different gateways, due to the client having to generate a specific token dedicated to a respective gateway and each respective gateway having a corresponding certificate). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Manning, and techniques disclosed of Wen, by implementing techniques of the client using different tokens and corresponding certificates for authentication with different gateways, disclosed of Herzog. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for authentication using persistent tokens and MDM certificates, comprising of the client using different tokens and corresponding certificates for authentication with different gateways. This allows for better security management by ensuring that a compromised token only impacts a single, isolated gateway rather than the entire infrastructure. Herzog is deemed as analogous art due to the art disclosing techniques of the client using different tokens and corresponding certificates for authentication with different gateways (Herzog, Paragraph [0076]). Claim 18 is rejected under 35 U.S.C. 103 as being unpatentable over Manning, in view of Wen, in further view of Tomar (U.S. PGPub. 2024/0297790). Regarding claim 18, Manning as modified by Wen do not teach the following limitation(s) as taught by Tomar: The system of claim 1, wherein obtain the new persistent token comprises receiving the new persistent token from a provisioning gateway (Tomar, Paragraph [0154], see “…generating, by a service provider application of the user device, a provision new token inquiry message…determining, by the service provider application on the user device, to whether or not to submit a request to the network processing computer to provision the new token…”, where “service provider application” and/or “network processing computer” are analogous to a provisioning gateway structured to generate and forward a new token to the client device). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Manning, and techniques disclosed of Wen, by implementing techniques of receiving the new token from a provisioning gateway, disclosed of Tomar. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for authentication using persistent tokens and MDM certificates, comprising of receiving the new token from a provisioning gateway. This allows for better security management and operational efficiency for a centralized integrated system that automates the creation and modification of tokens across an entire infrastructure. Tomar is deemed as analogous art due to the art disclosing techniques of receiving the new token from a provisioning gateway (Tomar, Paragraph [0154]). Allowable Subject Matter Claims 4-10 and 13-14 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Additional Art Considered The prior art made of record and not relied upon is considered pertinent to the Applicants’ disclosure. The following prior art are cited to further show the state of the art at the time of Applicants’ invention with respect to authentication using persistent tokens and MDM certificates. a. Bisbee et al. (U.S. PGPub. 2004/0093493) discloses techniques for transmission, storage and retrieval of authenticated documents. Bisbee further discloses searching the issuing CA cache for the latest certificate data elements and retrieves a status of the certificate data elements. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to RODMAN ALEXANDER MAHMOUDI whose telephone number is (571)272-8747. The examiner can normally be reached on M-F 11:00am – 7:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached on (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RODMAN ALEXANDER MAHMOUDI/Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Dec 19, 2024
Application Filed
Jun 23, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705332
METHOD FOR VERIFYING THE AUTHENTICITY OF AN ACTUATOR COMMAND
3y 0m to grant Granted Aug 11, 2026
Patent 12694092
PRE-REGISTRATION OF AUTHENTICATION DEVICES
2y 0m to grant Granted Jul 28, 2026
Patent 12651053
APP PROFILE VERIFICATION SETUP
2y 0m to grant Granted Jun 09, 2026
Patent 12645780
VEHICLE CONTROL DEVICE, SYSTEM, AND METHOD
2y 0m to grant Granted Jun 02, 2026
Patent 12647432
Quantification of Adversary Tactics, Techniques, and Procedures using Threat Attribute Groupings and Correlation
1y 10m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
96%
With Interview (+16.7%)
2y 9m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 247 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month