Prosecution Insights
Last updated: October 02, 2026
Application No. 19/021,644

SECURE INTEGRATION OF REAL-TIME STATUS INFORMATION IN APPLICATIONS

Non-Final OA §103
Filed
Jan 15, 2025
Examiner
MAHMOUDI, RODMAN ALEXANDER
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Truist Bank
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
204 granted / 254 resolved
+22.3% vs TC avg
Strong +16% interview lift
Without
With
+16.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
18 currently pending
Career history
279
Total Applications
across all art units

Statute-Specific Performance

§101
8.2%
-31.8% vs TC avg
§103
57.7%
+17.7% vs TC avg
§102
15.4%
-24.6% vs TC avg
§112
12.8%
-27.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 254 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 8 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Doshi (U.S. PGPub. 2014/0032707), in view of PLOMSKE et al. (U.S. PGPub. 2022/0222663), hereinafter Plomske, in further view of Rodriguez et al. (U.S. PGPub. 2025/0158889), hereinafter Rodriguez. Regarding claim 1, Doshi teaches A method, comprising: receiving, by a cloud application programming interface (API) executing on one or more processors, a subscription request from an application (Doshi, FIG. 1, see “Subscriber 108” and “Application (Client) 106”, where a cloud application programming interface (106) receives a subscription request from an application (108)) (Doshi, Paragraph [0047], see “…The subscriber 108 can be an application running on a client-side device that is in communication with or at least have an interface to the client application 106”) (Doshi, Paragraph [0083], discusses cloud computing), the subscription request comprising indications of an authentication token, an event, an entity, and a callback link (Doshi, Paragraph [0041], see “During application registration, a client identifier, one or more redirect URLs, and a client secret may be specified…”, where “one or more redirect URLs” is being read as a callback link, and where “a client secret” is being read as an authentication token) (Doshi, Paragraph [0048], see “The client application 106 receives a subscription request from the subscriber 108 requesting a subscription to receive selected events associated with the publisher 102”, which is being read as comprising indications of an event and an entity, where “publisher 102” is being read as an entity) (Doshi, Paragraph [0049], see “…The client application 106 calls a JavaScript-enabled API to obtain the registration identifier (or channel identifier) for the user of the subscriber 108 currently logged in to the client application 106”); generating, by an entity server associated with the entity, a subscription comprising indications of the event, (Doshi, Paragraph [0023], see “…The client component performs a registration flow where the client component receives a registration identifier (or channel identifier) and sends the identifier to the server component to be stored alongside a user record associated with the client component”) (Doshi, Paragraph [0054], see “…The registration identifier and event identifier are stored by the server application 104 in a data structure…”, where “server application 104” is being read as an entity server which generates a subscription comprising indications of the event (event identifier) and the application (e.g., part of the registration identifier which identifies the client application that is subscribed); storing, by the entity server, the subscription in a subscription repository (Doshi, Paragraph [0023], see “…The client component performs a registration flow where the client component receives a registration identifier (or channel identifier) and sends the identifier to the server component to be stored alongside a user record associated with the client component”) (Doshi, Paragraph [0054], see “…The registration identifier and event identifier are stored by the server application 104 in a data structure…”, which is being read as storing, by the entity server (server application 104), the subscription in a subscription repository). Doshi does not teach the following limitation(s) as taught by Plomske: encrypting, by a security platform, the authentication token (Plomske, Paragraph [0009], see “…generating a token for the transaction. The token includes a primary account number, expiration, and a group ID…The system may also encrypt the token”, where “system” is analogous to comprising a security platform, which encrypts the authentication token); providing, by the security platform, the encrypted authentication token to the cloud API (Plomske, Paragraph [0038], see “The token, which is encrypted, and clear text of the data supplied by the point of sale terminal 102 are returned to the tokenizer encryption service 110, and subsequently to the payment service(s) 104…”, which is analogous to providing, by the security platform, the encrypted authentication token to the cloud API (e.g., the tokenization and payment management system 120)) (Plomske, Paragraph [0060], which discusses cloud based networks); generating, by an entity server associated with the entity, a subscription comprising indications of the event, and the encrypted authentication token (Plomske, Paragraph [0037], see “…the expiration date of the token may be varied depending upon if the token is designated as a single use token, or for recurring transactions (i.e., a subscription)) (Plomske, Paragraph [0038], see “…The merchant may then store the encrypted token in a local database for later transactions”, which is analogous to generating a subscription comprising the encrypted authentication token). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Doshi, by implementing techniques of encrypting an authentication token, and generating a subscription comprising the encrypted authentication token, disclosed of Plomske. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for secure integration of real-time status information in applications, comprising of encrypting an authentication token, and generating a subscription comprising the encrypted authentication token. This allows for better security management by protecting sensitive user data from unauthorized viewing, whilst automating secure access to the subscription without a separate user login. Plomske is deemed as analogous art due to the art disclosing techniques of encrypting an authentication token, and generating a subscription comprising the encrypted authentication token (Plomske, Paragraphs [0037 – 0038]). Doshi as modified by Plomske do not teach the following limitation(s) as taught by Rodriguez: generating, by an entity server associated with the entity, a subscription comprising indications of the event, the callback link, the application, and the encrypted authentication token (Rodriguez, Paragraph [0063], see “…the NRF 101 may store the subscription ID, the subscription condition and the callback URL for each subscription request…”, which is analogous to generating a subscription comprising the callback link). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Doshi, and techniques disclosed of Plomske, by implementing techniques of generating a subscription comprising a callback link, disclosed of Rodriguez. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for secure integration of real-time status information in applications, comprising of generating a subscription comprising a callback link. This allows for better system efficiency by allowing systems to communicate automatically when events happen through the callback link. Rodriguez is deemed as analogous art due to the art disclosing techniques of generating a subscription comprising a callback link (Rodriguez, Paragraph [0063]). Regarding claims 8 and 15, the claims are rejected under the same reasoning as claim 1. Claims 4, 11 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Doshi, in view of Plomske, in further view of Rodriguez, in further view of UDUPI et al. (U.S. PGPub. 2015/0333904), hereinafter Udupi. Regarding claim 4, Doshi as modified by Plomske and further modified by Rodriguez do not teach the following limitation(s) as taught by Udupi: The method of claim 1, further comprising prior to receiving the subscription request: generating, by the entity server, a key pair comprising a public key and a private key (Udupi, Paragraph [0019], see “…a key publisher in a high security environment generates a list of encrypted key pairs and designates one pair as an active key pair”, where “key publisher” is analogous to an entity server and where “active key pair” is analogous to a key pair comprising a public and private key); and transmitting, by the entity server, the public key to the application (Udupi, Paragraph [0019], see “…The key publisher publishes the list to a key escrow service and sends the public key corresponding to the active key pair to a public key distributor…The public key distributor provides the active public key to client systems…”, where the key publisher (entity server) transmits the active public key to the application (client systems)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Doshi, techniques disclosed of Plomske, and techniques disclosed of Rodriguez, by implementing techniques of generating a key pair comprising a public and private key and transmitting the public key to the application, disclosed of Udupi. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for secure integration of real-time status information in applications, comprising of generating a key pair comprising a public and private key and transmitting the public key to the application. This allows for better security management by allowing encrypted messages to be sent/received without ever exposing the private key over the network. Udupi is deemed as analogous art due to the art disclosing techniques of generating a key pair comprising a public and private key and transmitting the public key to the application (Udupi, Paragraph [0019]). Regarding claims 11 and 18, the claims are rejected under the same reasoning as claim 4. Claims 5-6, 12-13 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Doshi, in view of Plomske, in further view of Rodriguez, in further view of Udupi, in further view of WALTERS et al. (U.S. PGPub. 2025/0028810), hereinafter Walters. Regarding claim 5, Doshi as modified by Plomske and further modified by Rodriguez and Udupi do not teach the following limitation(s) as taught by Walters: The method of claim 4, wherein the application encrypts authentication credentials of the subscription request based on the public key (Walters, Paragraph [0018], see “…The mobile application may encrypt the credentials before transmitting (e.g., using a public key)…”, which is analogous to the application encrypting authentication credentials of the request based on the public key). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Doshi, techniques disclosed of Plomske, techniques disclosed of Rodriguez, and techniques disclosed of Udupi, by implementing techniques of the application encrypting authentication credentials of the request based on the public key, disclosed of Walters. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for secure integration of real-time status information in applications, comprising of the application encrypting authentication credentials of the request based on the public key. This allows for better security management by ensuring that only the destination server can read the authentication credentials, even if the network connection is intercepted. Walters is deemed as analogous art due to the art disclosing techniques of the application encrypting authentication credentials of the request based on the public key (Walters, Paragraph [0018]). Regarding claim 6, Doshi as modified by Plomske and further modified by Rodriguez and Udupi do not teach the following limitation(s) as taught by Walters: The method of claim 5, further comprising prior to generating the subscription: decrypting, by the entity server the encrypted authentication credentials with the private key (Walters, Paragraph [0018], see “…the remote server may decrypt the credentials (e.g., using a private key))”; and validating, by the entity server, the decrypted authentication credentials, wherein the entity server generates the subscription based on the decryption and validation of the authentication credentials (Walters, Paragraph [0018], see “…the remote server may decrypt the credentials (e.g., using a private key)…the remote server may authenticate the user based on the credentials”) (Walters, Paragraph [0020], see “…the remote server may transmit, and the mobile application may receive, instructions for generating a user interface…”, which is analogous to generating a subscription (e.g., allowing the mobile application to gain access to the interface) based on the decryption and validation of the authentication credentials). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Doshi, techniques disclosed of Plomske, techniques disclosed of Rodriguez, and techniques disclosed of Udupi, by implementing techniques of decrypting the encrypted authentication credentials with the private key and validating the decrypted authentication credentials, wherein the entity server generates the subscription based on the decryption and validation, disclosed of Walters. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for secure integration of real-time status information in applications, comprising of decrypting the encrypted authentication credentials with the private key and validating the decrypted authentication credentials, wherein the entity server generates the subscription based on the decryption and validation. This allows for better security management and a highly secure and tamper-proof workflow by ensuring confidentiality and data integrity of the authentication credentials. Walters is deemed as analogous art due to the art disclosing techniques of decrypting the encrypted authentication credentials with the private key and validating the decrypted authentication credentials, wherein the entity server generates the subscription based on the decryption and validation (Walters, Paragraph [0018]). Regarding claim 12, the claim is rejected under the same reasoning as claim 5. Regarding claim 13, the claim is rejected under the same reasoning as claim 6. Regarding claim 19, the claim is rejected under the same reasoning as claims 5-6. Claims 7, 14 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Doshi, in view of Plomske, in further view of Rodriguez, in further view of Dhodapkar (U.S. PGPub. 2023/0252470), hereinafter Dhod. Regarding claim 7, Doshi as modified by Plomske and further modified by Rodriguez do not teach the following limitation(s) as taught by Dhod: The method of claim 1, wherein the event comprises a payment event processed at least in part by the entity (Dhod, Paragraph [0027], see “…When payment requests associated with one or more transactions are received in association with the secondary account, the payment service can approve or reject the transactions based on whether the one or more conditions are met”, where “payment service” is analogous to the entity, which processes the payment events) (Dhod, Paragraph [0265], see “…the “payment services” can be acquiring banks…issuing banks…card payment networks, and the like…”), wherein the application is associated with a third-party developer, wherein the third-party developer is distinct from the entity (Dhod, Paragraph [0380], see “…a software developer kit (SDK) can be provided by the payment service to allow third-party developers to include payment service functionality or avail payment service services in association with their own third-party applications…API(s) and SDK(s) can enable third-party developers to customize how their respective third-party applications interact with the payment service or vice versa”, which is analogous to the applications being associated with a third-party developer, wherein the third-party developer is distinct from the entity (payment services)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Doshi, techniques disclosed of Plomske, and techniques disclosed of Rodriguez, by implementing techniques of an event comprising a payment event and the application being associated with a third-party developer, disclosed of Dhod. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for secure integration of real-time status information in applications, comprising of an event comprising a payment event and the application being associated with a third-party developer. This allows for a more user-friendly environment by granting end users a unified experience and increased trust through their customized banking application interactions. Dhod is deemed as analogous art due to the art disclosing techniques of an event comprising a payment event and the application being associated with a third-party developer (Dhod, Paragraph [0380]). Regarding claims 14 and 20, the claims are rejected under the same reasoning as claim 7. Allowable Subject Matter Claims 2-3, 9-10 and 16-17 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Additional Art Considered The prior art made of record and not relied upon is considered pertinent to the Applicants’ disclosure. The following prior art are cited to further show the state of the art at the time of Applicants’ invention with respect to secure integration of real-time status information in applications. a. Thomas et al. (U.S. PGPub. 2022/0174127) discloses techniques of a subscription request, which comprises an access token, a callback URL and an event. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to RODMAN ALEXANDER MAHMOUDI whose telephone number is (571)272-8747. The examiner can normally be reached on M-F 11:00am – 7:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached on (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RODMAN ALEXANDER MAHMOUDI/Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Jan 15, 2025
Application Filed
Aug 11, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730900
SYSTEM DESIGN DEVICE, SYSTEM DESIGN METHOD, AND STORAGE MEDIUM
1y 8m to grant Granted Sep 08, 2026
Patent 12726361
METHOD, APPARATUS, AND COMPUTER-READABLE RECORDING MEDIUM FOR CONTROLLING ACCESS OF USER AND USER TERMINAL THAT ACCESS SERVER SYSTEM USING DIGITAL SIGNATURE
1y 11m to grant Granted Sep 01, 2026
Patent 12711228
Breach Response Data Management System and Method
1y 12m to grant Granted Aug 18, 2026
Patent 12705332
METHOD FOR VERIFYING THE AUTHENTICITY OF AN ACTUATOR COMMAND
3y 0m to grant Granted Aug 11, 2026
Patent 12694092
PRE-REGISTRATION OF AUTHENTICATION DEVICES
2y 0m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
97%
With Interview (+16.5%)
2y 9m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 254 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month