Prosecution Insights
Last updated: October 02, 2026
Application No. 19/056,968

METHODS AND SYSTEMS FOR COOKIE PROCESSING OPTIMIZATION

Final Rejection §102§103
Filed
Feb 19, 2025
Priority
Apr 10, 2024 — provisional 63/632,306 +1 more
Examiner
HUSSAIN, TAUQIR
Art Unit
Tech Center
Assignee
Shopify Inc.
OA Round
2 (Final)
84%
Grant Probability
Favorable
3-4
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
699 granted / 829 resolved
+24.3% vs TC avg
Strong +26% interview lift
Without
With
+25.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
29 currently pending
Career history
865
Total Applications
across all art units

Statute-Specific Performance

§101
6.3%
-33.7% vs TC avg
§103
56.1%
+16.1% vs TC avg
§102
19.0%
-21.0% vs TC avg
§112
7.2%
-32.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 829 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment This office action is in response to amendment/reconsideration filed on07/29/2026, the amendment/reconsideration has been considered. Claims 1, 9 and 16 have been amended, claims 3, 10 and 17 are canceled. Claims 1-2, 4-9, 11-16 and 19-20 are pending for examination as cited below. Claim Objections Claim 9 is objected to because of the following informalities: The status of claim 9 rendered as original rather than “amended.” Appropriate correction is required. Response to Arguments Applicant's arguments filed on 07/29/2026 have been fully considered but they are not persuasive. In remarks applicant argues in substance that: (a) Applicant argues that cited reference does not disclose, “sending a revised cookie when freshness timer has not expired.” Examiner respectfully disagree because, Carp explicitly teaches that the client computer always receives a session token from the server at step 222, regardless of whether the refreshinterval has expired. In [0038], Carp states that when the refresh intervals have not expired, “the session is still valid and the unaltered session token on the client computer 102 may not be updated.” Immediately thereafter, paragraph [0039] explains that “the client computer 102 receives a session token from the server computer 112.” Thus, Carp discloses the claimed behavior: determining that freshness timer has not expired, leaving the encrypted portion unchanged, and sending the session token (i.e., the cookie) back to the client. Applicant’s argument that Carp performs “no further action” is contradicted by the explicit disclosure of Step 222, which occurs in both the refresh-expired and refresh-not-expired branches of the flowchart. (b) Applicant further argues that cited reference “Carp” does not mention an expiration timer. Examiner respectfully disagree because Carp defines session expiration using a specific timing condition: the session expires when “(current time – lastrefreshtime)>= (refreshinterval + Overdue)” as stated in paragraph [0032-0033]. This is an expiration timer, even if Carpenter uses different terminology. The expiration time is determined by the combination of LastRefresh Time, RefreshInterval, and Overdue, and Carp further teaches updating LastRefreshTime when the overdue period is entered [0035]. Because expiration time is defined relative to LastRefreshTime, updating LastRefreshTime directly updates the expiration time. Therefore, Carp discloses and expiration timer and teaches updating expiration timing information, contrary to applicants’ argument. (c) Applicant argues that Carp does nothing when freshness timer has not expired. Examiner respectfully disagree because Carp explicitly states in [0038] that when the refresh interval ahs not elapsed, “the session is still valid and the unaltered session token on the client computer 102 may not be updated.” This means the token is not modified, but Carp does not state that the token is not sent. In [0039] immediately follows and states : “ the client computer 102 receives a session token from the server computer 112.” The flowchart in Fig.2A shows that step 222 (sending the token back to the client) occurs after both eh refresh-expired and refresh-not-expired branches. Thus Carp discloses sending the cookie back to the client even when the freshness timer has not expired, matching the claimed behavior. (d) Applicant argues that Carp’s session token is not a revised cookie. Examiner respectfully disagree because Carp explicitly states that “the session token is also known as the cookie” in [0035]. Carp further discloses generating a new cookie [0035] , updating the cookie [0037], leaving the cookie unaltered when refresh has not expired [0038] and sending the cookie back to the client in all cases [0039]. These behaviors correspond directly to the claimed “revised cookie,” which may be updated or altered depending on the freshness timer. Therefore, Carp session token meets the claims definition of a revised cookie. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-2, 4-6, 9, 11-13, and 16, 18-20 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Carpenter et al. (Pub. No.: US 2018/0309836 A1), hereinafter “Carp”. As to claim 1, Carp discloses, a method at a computing device (Carp, Abstract), the method comprising: receiving a request from a web browser, the request including a received cookie having an unencrypted portion and an encrypted portion (Carp, [0028]-[0030], The session token may further contain a unique session identifier, which will also be sent to the server computer 112 every time the client computer 102 visits a new page on the site. [0030], The server computer 112 may be the only machine with the cryptographic key needed to decrypt the symmetrically or unsymmetrically encrypted session token.); determining, from the unencrypted portion of the received cookie, that a freshness timer has not expired (Carp, [0038], the session is still valid and the unaltered session token on the client computer 102 may not be updated.) based on the determining, creating a revised cookie, the revised cookie using the encrypted portion and freshness timer from the received cookie (Carp, [0038], the session is still valid and the unaltered token on the client computer 102 may not be updated.) and an updated expiration timer within a revised cookie unencrypted portion that differs from an expiration timer of the received cookie (Carp, [0035], Carp teaches updating expiration-related information in the cookie. Carp states, “when the overdue period is entered, the server computer 112 may updated the value of LastRefereshTime saved in the client computer’s session token.” Because Carp defines expiration as: “(current time – lastrefreshtime)>= (refreshinterval + Overdue)” as stated in paragraph [0032-0033]). Any update to LastRefreshTime necessarily updates the expiration time. Thus Carp discloses a revised cookie with an updated expiration timer that differs from the expiration timer of the received cookie.); and sending the revised cookie to the web browser (Carp, [0038-0039], then at 222, the client computer 102 receives a session token from the server computer 112.). As to claim 9. Carp discloses, a computing device (Carp, Abstract) comprising: a processor (Carp, fig.1, element-104); and a communication subsystem, wherein the computing device (Carp, fig.1) is configured to: receive a request from a web browser, the request including a received cookie having an unencrypted portion and an encrypted portion (Carp, [0028]-[0029], The session token may further contain a unique session identifier, which will also be sent to the server computer 112 every time the client computer 102 visits a new page on the site. [0030], The server computer 112 may be the only machine with the cryptographic key needed to decrypt the symmetrically or unsymmetrically encrypted session token.); determine, from the unencrypted portion of the received cookie, whether a freshness timer has expired (Carp, [0032]-[0033], the current request time) and the value saved in the client computer's 102 session token for LastRefreshTime (i.e. last refresh time) is greater than or equal to the aggregate of RefreshInterval and Overdue (i.e. the difference value), values which are configured and saved in the server computer 112.); when the freshness timer has expired (Carp, [0032]): send a request to a network server for an updated encrypted portion (Carp, [0034], The client authentication process may enable the server computer 112 to obtain identifying information from the client computer 102.); receive the updated encrypted portion (Carp, [0035], Within the session token, the server computer 112 may set a value for LastRefreshTime, representing the time that the session token was created.); reset the freshness timer (Carp, [0035]); create a revised cookie with the updated encrypted portion and reset freshness timer (Carp, [0035], [0039], The session token may have an updated LastRefreshTime as described at 216); and send the revised cookie to the web browser (Carp, [0035]); and when the freshness timer has not expired: create the revised cookie, the revised cookie using the encrypted portion and the freshness timer from the received cookie (Carp, [0038], the session is still valid and the unaltered token on the client computer 102 may not be updated.), and un updated expiration timer within a revised cookie unencrypted portion that differs from an expiration timer of the received cookie. (Carp, [0035], Carp teaches updating expiration-related information in the cookie. Carp states, “when the overdue period is entered, the server computer 112 may updated the value of LastRefereshTime saved in the client computer’s session token.” Because Carp defines expiration as: “(current time – lastrefreshtime)>= (refreshinterval + Overdue)” as stated in paragraph [0032-0033]). Any update to LastRefreshTime necessarily updates the expiration time. Thus Carp discloses a revised cookie with an updated expiration timer that differs from the expiration timer of the received cookie.) ; and send the revised cookie to the web browser (Carp, [0039], the client computer 102 receives a session token from the server computer 112.). As to claim 16 is rejected for same rationale as applied to claim 9 above. As to claim 2. Carp discloses, further comprising: receiving a second request from the web browser, the second request including a second received cookie having a second received cookie unencrypted portion and a second received cookie encrypted portion (Carp, [0028]-[0029], The session token may further contain a unique session identifier, which will also be sent to the server computer 112 every time the client computer 102 visits a new page on the site. [0030], The server computer 112 may be the only machine with the cryptographic key needed to decrypt the symmetrically or unsymmetrically encrypted session token.); determining, from the unencrypted portion of the second received cookie, that the freshness timer has expired (Carp, [0032]-[0033], the current request time) and the value saved in the client computer's 102 session token for LastRefreshTime (i.e. last refresh time) is greater than or equal to the aggregate of RefreshInterval and Overdue (i.e. the difference value), values which are configured and saved in the server computer 112.); sending a request to a network server for an updated encrypted portion; receiving the updated encrypted portion (Carp, [0034], The client authentication process may enable the server computer 112 to obtain identifying information from the client computer 102.); resetting the freshness timer (Carp, [0035]); creating a second revised cookie with the updated encrypted portion and reset freshness timer (Carp, [0038], the session is still valid and the unaltered token on the client computer 102 may not be updated.); and sending the second revised cookie to the web browser (Carp, [0039], the client computer 102 receives a session token from the server computer 112.). As to claim 4. Carp discloses, wherein the freshness timer is shorter than an expiration timer for the received cookie and the revised cookie (Carp, [0022], expiration occurs when the time since LastRefreshTime exceeds the aggregate of Refreshinterval and overdue. [0032-0033], establishing that the expiration timer is longer than the freshness timer. And [0023], explicitly distinguishes the shorter refresh interval from the longer timeout range.). As to claim 5. Carp discloses, further comprising storing at the computing device the encrypted portion of the received cookie in unencrypted form (Carp, [0030] receiving a cookie with encrypted portion. The server decrypts the encrypted portion “into a format which may be readable” The server then stores the decrypted value for later comparison. [0032], [0035], these stored values are used for subsequent expiration determination.). As to claim 6. Carp discloses, wherein the received cookie includes an identification number in the unencrypted portion, and wherein the revised cookie uses the same identification number in its unencrypted portion (Carp, [0029], cookie includes a unique session identifier. [0035], further teaches that when the server generates a revised cookie, it updates only the encrypted portion e.g., LastRefreshTime. [0039], and sends the revised cookie back to the client and [0029] the unique identifier is reused for each subsequent request.). As to claims 11 and 18 are rejected for same rationale as applied to claim 4 above. As to claims 12 and 19 are rejected for same rationale as applied to claim 5 above. As to claims 13 and 20 are rejected for same rationale as applied to claim 6 above. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 7, 8, 14 and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Carp as applied above in view of Onda et al. (Patent No.: US 8626842 B2), hereinafter "Onda". As to claim 7. Carp discloses the invention as cited above. Carp however is silent to disclose explicitly, wherein the received cookie includes a decryption key identifier in the unencrypted portion, and wherein the request to the network server includes the decryption key identifier. Onda discloses a similar concept in the same field of endeavor, wherein the received cookie includes a decryption key identifier in the unencrypted portion, and wherein the request to the network server includes the decryption key identifier. (Onda, Abstract, discloses a content transaction management server that stores decryption keys and associates them with user identifiers and storage addresses.). Therefore, before the effective fling date of the instant application it would have been obvious to one of the ordinary skilled in the art to incorporate the teachings of "Onda" into those of "Carp" to provide a method, content transaction management server device, content-data transactions can be performed efficiently without requiring cumbersome tasks to be carried out by the seller or purchaser using unique encryption and decryption key stored in a system storage for proper verification. As to claim 8. The combined system of Carp and Onda discloses the invention as applied above including, wherein the encrypted portion of the received cookie includes user profile information (Onda, Abstract, discloses a content transaction management server that stores decryption keys and associates them with user identifiers and storage addresses.). As to claim 14 is rejected for same rationale as applied to claim 7 above. As to claim 15 is rejected for same rationale as applied to claim 8 above. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Please see the attached PTO-892. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAUQIR HUSSAIN whose telephone number is (571)270-1247. The examiner can normally be reached M-F 7:00 - 8:00 with IFP. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Vivek Srivastava can be reached at 571 272-7304. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Tauqir Hussain/Primary Examiner, Art Unit 2446
Read full office action

Prosecution Timeline

Feb 19, 2025
Application Filed
May 18, 2026
Non-Final Rejection mailed — §102, §103
Jul 29, 2026
Response Filed
Sep 23, 2026
Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743547
Method, Device, Equipment and Medium for False-Report Elimination
2y 5m to grant Granted Sep 22, 2026
Patent 12744832
SYSTEMS AND METHODS FOR ENSURING CONTINUED ACCESS TO MEDIA OF A PLAYLIST DESPITE GEOGRAPHIC CONTENT RESTRICTIONS
1y 9m to grant Granted Sep 22, 2026
Patent 12739165
COMMUNICATION SYSTEM
1y 11m to grant Granted Sep 15, 2026
Patent 12726423
INFERRING QOE DEGRADATION FROM IMPLICIT SIGNALS IN USER BEHAVIOR
3y 5m to grant Granted Sep 01, 2026
Patent 12724869
DATA LINK LAYER AUTHENTICITY AND SECURITY FOR AUTOMOTIVE COMMUNICATION SYSTEM
2y 8m to grant Granted Sep 01, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+25.8%)
3y 0m (~1y 4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 829 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month