Prosecution Insights
Last updated: August 17, 2026
Application No. 19/006,714

CROSS PLATFORM CREDENTIAL SHARING

Non-Final OA §102§103
Filed
Dec 31, 2024
Priority
Sep 24, 2021 — provisional 63/248,391 +2 more
Examiner
SCHMIDT, KARI L
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Apple Inc.
OA Round
1 (Non-Final)
74%
Grant Probability
Favorable
1-2
OA Rounds
2y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
557 granted / 752 resolved
+16.1% vs TC avg
Strong +42% interview lift
Without
With
+42.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
14 currently pending
Career history
774
Total Applications
across all art units

Statute-Specific Performance

§101
17.1%
-22.9% vs TC avg
§103
50.9%
+10.9% vs TC avg
§102
10.9%
-29.1% vs TC avg
§112
13.1%
-26.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 752 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office Action is in response to application 19/006,714 filed on 12/31/2024. Claims 1-20 have been examined and are pending in this application. The examiner notes the IDS(s) filed on 12/31/2024, 4/21/2025, 10/22/2025, 11/10/2025, 12/16/2025 and 3/11/2026 has been considered. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claim(s) 1, 2, 9, 10, 16, and 17 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Yami et al. (US 2007/0033637 A1). Regarding Claim 1; Yami discloses one or more non-transitory, computer-readable media having instructions that, when executed by one or more processors of a recipient device ([0035] - In one embodiment, the personal data assistant 120 receives the document identification number and corresponding password. In another embodiment, the personal computer 122 receives the password and document identification number. Once entered, the document identification number is transmitted at step 304 to the server 106 of the document management system 104 on the document processing services network and [0039] - In the preferred embodiment, when the receiving user is the personal computer 122, the encrypted token is transmitted to the personal computer 12), cause the recipient device to: detect an indication of a storage location of an encrypted token associated with an access credential for providing access via the recipient device, the access credential to provide access to a secured entity ([0029] and [0035] - In the preferred embodiment, the receiving user, either authorized or unauthorized, is located at the multifunction peripheral device 102. In one embodiment, the personal data assistant 120 receives the document identification number and corresponding password. In another embodiment, the personal computer 122 receives the password and document identification number. Once entered, the document identification number is transmitted at step 304 to the server 106 of the document management system 104 on the document processing services network and [0038] - When the server 106 determines that the identification number is valid, flow proceeds to step 308 wherein the server 106 analyzes the token associated with the identification number. As previously discussed, the token is stored at the server 106 and is associated thereon with the identification number. A determination is then made at step 310 to determine whether the token is active and [0039] - In the preferred embodiment, when the receiving user is the personal computer 122, the encrypted token is transmitted to the personal computer 12 and [0042]); retrieve the encrypted token from the storage location on a relay server ([0029] and [0039] - When the token is still active, flow proceeds to step 312, wherein the encrypted token, stored in associated memory, is transmitted to the requesting device); decrypt the encrypted token to produce a token ([0029] and [0039] - Upon receipt, the token is decrypted using the submitted password at step 314.) ; retrieve a sharing bundle based at least in part on the token ([0039]-[0040] - The requesting device then transmits the decrypted token to the server 106 at step 316. It will be understood by those skilled in the art that the decrypted token suitably contains share details necessary for the server 106 to retrieve the shared document from the repository 108.); and utilize the sharing bundle to provision the access credential to the recipient device ([0040] - The server 106 then retrieves the electronic document designated by the document identification number and the decrypted token from the repository 108 at step 318. The retrieved electronic document and the corresponding share details are then transmitted to the requesting device at step 320. In accordance with the preferred embodiment of the present invention, the retrieved document and share details are transmitted to the multifunction peripheral device 102. Upon receipt of the electronic document and the share details, the allowed document processing operation or operations are performed in accordance with the capabilities of the requesting device and the share details at step 322). Regarding Claim 2; Yami discloses the media of Claim 1. Yami further teaches wherein the instructions, when executed by the one or more processors of the recipient device, further cause the recipient device to: execute an application programming interface (API) with a provisioning server ([0020] - The document management system 104 suitably includes a server 106. It will be understood by those skilled in the art that the document management system 104 is capable of including more than one server, with each server performing a different function, aspects of a function, or the same function in tandem... The server 106 is operatively connected to one or more file repositories, illustrated in FIG. 1 as 108 and 110. The file repositories 108, 110 suitably contain one or more electronic files, preferably corresponding to a particular user, group of users, division, and the like and [0046] - Computer programs are also capable of being embedded in an integrated circuit. Any and all such embodiments containing code that will cause a computer to perform substantially the invention principles as described, will fall within the scope of the invention); and provide, via the API, the token to the provisioning server for retrieval of the sharing bundle ([0040] - The server 106 then retrieves the electronic document designated by the document identification number and the decrypted token from the repository 108 at step 318. The retrieved electronic document and the corresponding share details are then transmitted to the requesting device at step 320. In accordance with the preferred embodiment of the present invention, the retrieved document and share details are transmitted to the multifunction peripheral device 102. Upon receipt of the electronic document and the share details, the allowed document processing operation or operations are performed in accordance with the capabilities of the requesting device and the share details at step 322 and [0046] - Computer programs are also capable of being embedded in an integrated circuit. Any and all such embodiments containing code that will cause a computer to perform substantially the invention principles as described, will fall within the scope of the invention.) Regarding Claim(s) 9-10; claim(s) 9-10 is/are directed to a/an method associated with the media claimed in claim(s) 1-2. Claim(s) 9-10 is/are similar in scope to claim(s) 1-2, and is/are therefore rejected under similar rationale. Regarding Claim(s) 16-17; claim(s) 16-17 is/are directed to a/an device associated with the media claimed in claim(s) 1-2. Claim(s) 16-17 is/are similar in scope to claim(s) 1-2, and is/are therefore rejected under similar rationale. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 3, 11, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Yami et al. (US 2007/0033637 A1) in view of Ellison et al. (US 7,082,615 B1). Regarding Claim 3; Yami discloses the media of Claim 1. Yami discloses [concepts of an] an origination device sharing the access credential with the recipient device ([0006], [0029], [0035], [0038]-[0039] and [0042]). Yami fails to explicitly disclose wherein the instructions, when executed by the one or more processors of the recipient device, further cause the recipient device to: generate an asymmetric key pair; and provide a public key of the asymmetric key pair to [a device] to retrieve a signature from the origination device. However, in an analogous art, Ellison teaches wherein the instructions, when executed by the one or more processors of the recipient device, further cause the recipient device to: generate an asymmetric key pair; and provide a public key of the asymmetric key pair to [a device] to retrieve a signature from the origination device (col. 11, lines 1-30 - The signature algorithm used by the signature generator 320 may be public-key digital signature algorithm which makes use of a secret private key to generate the signature, and a public key to verify the signature. Example algorithms include ElGama, Schnorr and Digital Signature Algorithms schemes just to name a few. In one embodiment, the generation of the signature 304 includes hashing the subset 230 to generate a before hash value, which is then encrypted using the private key 328 to generate the signature 304. The signature 304 is then saved in a storage medium 322. At a later time, the signature is retrieved from the storage 322, and the retrieved signature 306 is used, along with public key 205, by the signature verifier 330 to verify the subset 230. The signature verifier 330 verifies whether the subset 230 has been modified, producing a modified/not-modified indicator 331. In one embodiment, the verification process includes decrypting the retrieved signature 306 using the public key 205 to expose the before hash value. The subset 230 is hashed to generate an after hash value. The before hash value is compared to the after hash value to detect whether the subset 230 has been modified. If the two hash values match, the subset 230 is the same as it was when the signature was generated). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Ellison to the media of Yami to include wherein the instructions, when executed by the one or more processors of the recipient device, further cause the recipient device to: generate an asymmetric key pair; and provide a public key of the asymmetric key pair to [a device] to retrieve a signature from the origination device. One would have been motivated to combine the teachings of Ellison to Yami to do so as it provides / allows to protect the integrity of the computer systems and increase the trust of users (col. 1, lines 28-30). Regarding Claim(s) 11; claim(s) 11 is/are directed to a/an method associated with the media claimed in claim(s) 3. Claim(s) 11 is/are similar in scope to claim(s) 3, and is/are therefore rejected under similar rationale. Regarding Claim(s) 18; claim(s) 18 is/are directed to a/an device associated with the media claimed in claim(s) 3. Claim(s) 18 is/are similar in scope to claim(s) 3, and is/are therefore rejected under similar rationale. Claim(s) 4, 12, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Yami et al. (US 2007/0033637 A1) in view of Ellison et al. (US 7,082,615 B1) and further in view of Saboori et al. (US 2014/0359281 A1). Regarding Claim 4; Yami in view of Ellison discloses the media of Claim 3. Yami further discloses wherein the instructions, when executed by the one or more processors of the recipient device, further cause the recipient device to: ... for provisioning of the access credential to the recipient device. ([0006], [0029], [0035], [0038]-[0039] and [0042]). Yami in view of Ellison fail to disclose ... detect the signature received from the origination device, the signature allowing for provisioning of the access credential... However, in an analogous art, Saboori teaches disclose ... detect the signature received from the [a] device, the signature allowing for provisioning of the access credential... ([0002]). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Saboori to the media of Yami in view of Ellison to include ... detect the signature received from the [a] device, the signature allowing for provisioning of the access credential... One would have been motivated to combine the teachings of Saboori to Yami in view of Ellison to do so as it provides / allows to verify its authenticity that the identity of the entity and authenticity of the certificate before... provisioning credentials (as gleaned, Saboori, [0002]). Regarding Claim(s) 12; claim(s) 12 is/are directed to a/an method associated with the media claimed in claim(s) 4. Claim(s) 12 is/are similar in scope to claim(s) 4, and is/are therefore rejected under similar rationale. Regarding Claim(s) 19; claim(s) 19 is/are directed to a/an device associated with the media claimed in claim(s) 4. Claim(s) 19 is/are similar in scope to claim(s) 4, and is/are therefore rejected under similar rationale. Claim(s) 5, 13, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Yami et al. (US 2007/0033637 A1) in view of Gehert et al. (US 9,608,970 B1). Regarding Claim 5; Yami discloses the media of Claim 1. Yami fails to explicitly disclose wherein the instructions, when executed by the one or more processors of the recipient device, further cause the recipient device to: retrieve metadata indicating the access credential to be provisioned; and display, on a display of the recipient device, a preview of the access credential based at least in part on the metadata. However, in an analogous art, Gehert teaches wherein the instructions, when executed by the one or more processors of the recipient device, further cause the recipient device to: retrieve metadata indicating the access credential to be provisioned (col. 4, lines 4-12 - When a credential issuing organization assigns a key to a user, a record can be created in the user's account within a credential management system, wherein the record indicates that the credential issuing organization has granted the user access to the key. When that user decides to share the key with another user, a share instance of the key can be created within the credential management system. After the key has been shared successfully with the intended recipient, another record can be created within the intended recipient's account, wherein the record links the intended recipient's account to the share instance. This allows the recipient to access to the corresponding resource (provided any relevant constraints associated with the share instance are satisfied) via a representation of the key that is linked to the share instance and col. 4, lines 13-20 and col. 5, lines 6-34 - In some implementations, optical machine-readable representations of credentials may encode data including or representing credential identifiers and any other suitable data. In other implementations, optical machine-readable representations of credentials may encode other identifiers that are linked to or otherwise associated with credential identifiers. To generate an optical machine-readable representation, a client device may use any suitable technique for encoding alphanumeric data within the optical machine-readable representation); and display, on a display of the recipient device, a preview of the access credential based at least in part on the metadata (col. 4, lines 4-12 and col. 5, lines 6-41 - To initiate the validation process for an optical machine-readable representation, a client device may output an optical machine-readable representation to a display of the client device. A validating device can scan the portion of the client device's display showing the representation of the credential and decode the representation of the credential to generate a set of alphanumeric characters that were encoded in the representation of the credential). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Gehert to the media of Yami to include wherein the instructions, when executed by the one or more processors of the recipient device, further cause the recipient device to: retrieve metadata indicating the access credential to be provisioned; and display, on a display of the recipient device, a preview of the access credential based at least in part on the metadata. One would have been motivated to combine the teachings of Gehert to Yami to do so as it provides / allows permits the person to access resources (e.g., physical and/or logical resources) and/or events (Gehert, col. 1, lines 15-18). Regarding Claim(s) 13; claim(s) 13 is/are directed to a/an method associated with the media claimed in claim(s) 5. Claim(s) 13 is/are similar in scope to claim(s) 5, and is/are therefore rejected under similar rationale. Regarding Claim(s) 20; claim(s) 20 is/are directed to a/an device associated with the media claimed in claim(s) 5. Claim(s) 20 is/are similar in scope to claim(s) 5, and is/are therefore rejected under similar rationale. Claim(s) 6-8 and 14-15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Yami et al. (US 2007/0033637 A1) in view of Wang et al. (US 2008/0065894 A1). Regarding Claim 6; Yami discloses the media of Claim 1. Yami teaches the encrypted token ([0029] and [0039]). Yami fails to explicitly disclose wherein the indication of the storage location includes a mailbox identifier (ID) corresponding to the storage location, and wherein to retrieve the ... includes to: transmit a request for data from the storage location corresponding to the mailbox ID. However, in an analogous art, Wang teaches wherein the indication of the storage location includes a mailbox identifier (ID) corresponding to the storage location, and wherein to retrieve the [pin or password] includes to: transmit a request for data from the storage location corresponding to the mailbox ID (FIG. 2 – 250-280 – Mailbox ID and [0025]-[0027] - Step 260, the authentication server then produces some secrecy that only the real user who possesses the correct password or PIN number of that can decrypt.... The authentication server produces a secrecy through the following procedure: First, authentication server queries from the database the corresponding PIN number or password stored based on the ID or user account name received. Secondly, authentication server runs some hash function such as SHA1 or MD5 on user ID and password to produce an encryption key. Finally, the authentication server uses this encryption key to encrypt a random number by using some encryption algorithm... The encrypted random number is the secrecy the authentication server sends back in Step 270). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Wang to the media of Yami to include wherein the indication of the storage location includes a mailbox identifier (ID) corresponding to the storage location, and wherein to retrieve the encrypted token includes to: transmit a request for data from the storage location corresponding to the mailbox ID. One would have been motivated to combine the teachings of Wang to Yami to do so as it provides / allows secure communication of [data] to a device (as gleaned from Wang, [0001]). Regarding Claim 7; Yami in view of Wang discloses the media of Claim 6. Wang further teaches wherein the instructions, when executed by the one or more processors of the recipient device, cause the recipient device to: generate a key based at least in part on the mailbox ID, wherein to decrypt the encrypted token includes to decrypt the encrypted token with the key to produce the token (FIG. 2 – 250 – Mailbox ID and [0025]-[0027] - Secondly, authentication server runs some hash function such as SHA1 or MD5 on user ID and password to produce an encryption key... In Step 280, the printer driver decrypts the secrecy to get the encryption key by using user account and password or mailbox ID and PIN that the user entered. Then in Step 290, once the authentication server's secrecy is successfully decrypted, user can use the decrypted random number to encrypt the document by some encryption algorithm and send it to the mailbox that user specified). Similar rationale and motivation is noted for the combination of Wang to Yami in view of Wang, as per claim 6, above. Regarding Claim 8; Yami in view of Wang discloses the media of Claim 7; Wang further teaches wherein the instructions, when executed by the one or more processors of the recipient device, cause the recipient device to: identify a password received from an origination device, wherein the key if further based at least in part on the password (FIG. 2 and [0025]-[0027] - In Step 280, the printer driver decrypts the secrecy to get the encryption key by using user account and password or mailbox ID and PIN that the user entered. Then in Step 290, once the authentication server's secrecy is successfully decrypted, user can use the decrypted random number to encrypt the document by some encryption algorithm and send it to the mailbox that user specified). Similar rationale and motivation is noted for the combination of Wang to Yami in view of Wang, as per claim 6, above. Regarding Claim(s) 14-15; claim(s) 14-15 is/are directed to a/an method associated with the media claimed in claim(s) 6-7. Claim(s) 14-15 is/are similar in scope to claim(s) 6-7, and is/are therefore rejected under similar rationale. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892 attached. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KARI L SCHMIDT whose telephone number is (571)270-1385. The examiner can normally be reached Monday-Friday 10am - 6pm (MDT). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KARI L SCHMIDT/ Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Dec 31, 2024
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705372
CONTROLLING AN INTERACTION USING ONLINE ACCOUNT OPENING INDICATORS
3y 1m to grant Granted Aug 11, 2026
Patent 12695782
UPDATING REMOTE SCAN ENGINES WITH CUSTOM VULNERABILITY CHECKS
1y 7m to grant Granted Jul 28, 2026
Patent 12689917
Determining a Subset of Base Stations in a Wireless Network
2y 3m to grant Granted Jul 21, 2026
Patent 12682026
MULTIDIMENSIONAL LOCAL LARGE LANGUAGE MODEL USER AUTHENTICATION
2y 5m to grant Granted Jul 14, 2026
Patent 12666259
Authentication of a Communications Device
5y 1m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
74%
Grant Probability
99%
With Interview (+42.4%)
3y 9m (~2y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 752 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month