DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 21-39 have been examined.
Response to Arguments
Applicant's arguments filed on 8/19/26 have been fully considered but they are not persuasive..
Regarding Applicant’s remarks, Applicant mainly argues that the prior art of record does not explicitly disclose verifying entity carrying out verification on the certificate based on one or more rules; and updating at least one of the one or more rules in response to a change in one or more criteria. Applicant asserts that the cited portion of Williams ([0038]) does not disclose the disputed limitations. However, the examiner disagrees.
The limitations of verifying based on “one or more rules” and updating in response to a change in “one or more criteria” are recited at a high level of generality. It is unclear what type of rule and criteria are involved in the verification process. Based on broadest reasonable interpretation consistent with the Specification, Williams in the cited portion ([0038], which corresponds to Fig. 2) discloses a process of generating verifiable health status certificate to track actions of manufacturer, healthcare provider, and participant. The process involves updating rules and criteria for validating/verifying identity of specific entity. Furthermore, Williams discloses that the verification can be used to ensure that health status information complies with a predetermined set of criteria for determining the health status information (Williams: [0055]) and the system can authenticate each participant, test kit manufacturers, and healthcare providers to verify that the participant has been tested and to verify the result (Williams: [0064]). Therefore, Applicant’s argument is not persuasive in light of above explanation.
Regarding 35 U.S.C. 101 rejection, the rejection is maintained based on reason set forth below.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim 39 is rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim does not fall within at least one of the four categories of patent eligible subject matter because it recites a computer program, which is software/signal per se. Although Applicant has amended the claim to recite “non-transitory computer program,” the claimed subject matter is still computer program. Applicant is advised to amend the claims to recite computer program product comprising non-transitory computer readable storage medium.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 21, 22 and 26-39 are rejected under 35 U.S.C. 102(a)(1)/(a)(2) as being anticipated by Williams et al. U.S. 2021/0313069 (hereinafter Williams).
As per claim 21 and 39, a method/computer program for digitally authenticating a user's health status, the method comprising:
sending a certificate representative of health data associated with a user to a verifying entity (Williams: Fig. 3 and [0043]: health certificate… the immunity certificate also includes a QR code that can be scanned to verify the immunity status);
the verifying entity carrying out verification on the certificate based on one or more rules (Williams: Fig. 5 and [0048]-[0051]: validation platform/verifying entity authenticates and validates health status information associated with first user by identifying a digital token associated with the QR code; [0055]: verification can be used to ensure that the health status information complies with a predetermined set of criteria for determining the health status information, which are subject to change),
updating at least one or more rules in response to a change in one or more criteria (Williams: Fig. 2 and [0038]: process of registering and updating health information associated with user; [0055]: verification can be used to ensure that the health status information complies with a predetermined set of criteria for determining the health status information, which are subject to change);
in response the certificate is verified, providing a credential based on the verified certificate (Williams: [0050]: second user device/authenticating device transmits the serialized data extracted from QR code to validation platform for verification of health status information); and
authenticating the user associated with the health data based on the credential (Williams: [0051]: the second user device authenticates the first user based on identity and health status information/credential transmitted from validation platform/verifying entity to authenticate the first user).
As per claim 22, Williams discloses the method of claim 21. Williams further discloses wherein the certificate comprises a data schema and definition describing data fields required by the verifying entity to carry out verification on the certificate (Williams: [0057]: different health status profiles correspond to different data required by different entities).
As per claim 25, Williams discloses the method of claim 21. Williams further discloses wherein the authenticating comprises checking the credential against a distributed ledger using cryptography and matching digital identifiers, DIDs, of the credential in the distributed ledger (Williams: [0052]-[0055]: health status certificate includes QR code referencing digital token previously stored in a distributed ledger).
As per claim 26, the method of claim 21, wherein the authenticating comprises requesting at least a portion of the credential, the portion of the credential including data required for the authenticating (Williams: [0049]: selectively display health status information and to authenticate and validate health status information).
As per claim 27, Williams discloses the method of claim 21. Williams further discloses wherein the credential comprises identity data associated with the user's identity (Williams: Fig. 3).
As per claim 28, Williams discloses the method of claim 27. Williams further discloses wherein the identity data comprises one or more of: biographic data associated with the user; biometric data associated with the user; and reference to a travel document (Williams: Fig. 3; [0064]).
As per claim 29, Williams discloses the method of claim 21. Williams further discloses wherein the credential does not comprise the user's health data (Williams: [0005]: share health status information in a manner that protects privacy of health information).
As per claim 30, Williams discloses the method of claim 21. Williams further discloses wherein the one or more rules comprise determining whether or not one or more of: the user has purchased insurance; the user has given consent; the user has completed one or more health questions; and health data has been verified (Williams: Fig. 2; [0038]-[0041]: process of registering and updating health status information involving manufacturer, healthcare provider, and participant are validated by the validation platform; [0055]: The verification can be used to ensure that the health status information complies with a predetermined set of criteria for determining the health status information).
As per claim 31, Williams discloses the method of claim 21. Williams does not explicitly disclose applying a cryptographic signature to the health data to prevent alteration of the health data, and wherein the credential provides cryptographically signed proof of the existence of the health certificate without providing the health data. However, Jarvis discloses verifying digital signature of the health certificate (Jarvis: [0085]: verify signature of the third party system…the third party system has verification of the data without actually having accessed the data; [0133]-[0142]: user presents credential data to indicate medical status). It would have been obvious to one having ordinary skill in the art to verify signature of certificate for data stored in blockchain as well known in the art.
As per claim 32, Williams discloses the method of claim 21. Williams further discloses receiving the certificate representative of health data from a health data source, and wherein the receiving the certificate comprises establishing a secure link between the health data source and the user by a unique identifier associated with the user (Williams: [0029]).
As per claim 33, Williams discloses the method of claim 21. Williams further discloses if the certificate is not verified, determining the user as non-compliant and not authenticating the user (Williams: [0033]; [0054]).
As per claim 35, Williams discloses the method of claim 21. Williams further discloses deriving one or more additional credentials from a digital travel card embedded on the credential (Williams: [0022]: digital wallet stores various certifications).
As per claim 36, Williams discloses the method of claim 21. Williams further discloses wherein the verifying entity is a government authority; and/or the authenticating is performed by an authenticator, and the authenticator is an airline organization (Williams: [0057]).
As per claim 37, Williams discloses a method of digitally authenticating a user's health status, performed at a user device, the method comprising the user device:
sending a certificate representative of health data associated with a user (Williams: Fig. 3 and [0043]: health certificate… the immunity certificate also includes a QR code that can be scanned to verify the immunity status);
receiving a credential based on the certificate being verified based on one or more rules (Williams: Fig. 5 and [0048]-[0051]: validation platform/verifying entity authenticates and validates health status information associated with first user by identifying a digital token associated with the QR code; [0055]: verification can be used to ensure that the health status information complies with a predetermined set of criteria for determining the health status information, which are subject to change),
updating at least one or more rules in response to a change in one or more criteria (Williams: Fig. 2 and [0038]: process of registering and updating health information associated with user; [0055]: verification can be used to ensure that the health status information complies with a predetermined set of criteria for determining the health status information, which are subject to change);
providing the credential for authentication (Williams: [0050]-[0051]: second user device displays/provides information to allow the second user to verify health status and identity of the first user).
As per claim 38, Williams discloses a method of digitally authenticating a user's health status, performed at an authenticator, the method comprising the authenticator:
receiving a credential representative of a verified certificate representing health data associated with a user (Williams: Fig. 3; [0051]-[0052]: receive identity and health status information based on digital token associated with health certificate to verify first user);
wherein the verification is based on one or more rules (Williams: Fig. 5 and [0048]-[0051]: validation platform/verifying entity authenticates and validates health status information associated with first user by identifying a digital token associated with the QR code; [0055]: verification can be used to ensure that the health status information complies with a predetermined set of criteria for determining the health status information, which are subject to change),
updating at least one or more rules in response to a change in one or more criteria (Williams: Fig. 2 and [0038]: process of registering and updating health information associated with user; [0055]: verification can be used to ensure that the health status information complies with a predetermined set of criteria for determining the health status information, which are subject to change);
authenticating the user associated with the health data based on the credential (Williams: [0051]: receive identity and health status information from validating platform to verify user).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 23 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Williams in view of Androulaki et al. U.S. 2022/0150073 (hereinafter Androulaki).
As per claim 23, Williams discloses the method of claim 22. Williams further discloses wherein the authenticating is performed by an authenticator (Williams: [0033]: use of distributed ledger/decentralized blockchain to authenticate the user). Williams does not explicitly disclose the authenticator accessing an online network to locally cache the data schema and definition from a distributed ledger prior to authenticating the user. However, Androulaki discloses using data schema and definition of health certificate to verify user status using decentralized database/distributed ledger (Androulaki: [0031]-[0035]: each peer stores a copy of the blockchain and certificates are verified based on public key). It would have been obvious to one having ordinary skill in the art to store copy of blockchain according to schema and definition to verify health/identity certificate because they are analogous art involving verification of health certificate using blockchain. The motivation to combine would be that decentralized nature of blockchain to allow online or offline verification based on local copy is well-known in the art.
As per claim 24, Williams as modified discloses the method of claim 23. Williams as modified further discloses wherein the authenticating is performed offline using the data schema and definition locally cached by the authenticator (Androulaki: [0031). Same rationale applies here as above in rejecting claim 23.
Claim 25 is rejected under 35 U.S.C. 103 as being unpatentable over Williams in view of Jarvis U.S. 2024/0370577 (hereinafter Jarvis).
As per claim 34, Williams discloses the method of claim 21. Williams does not explicitly disclose revoking the credential if it is determined that the certificate should no longer be verified. However, Jarvis discloses revocation of digital certificate (Jarvis: [0069]). It would have been obvious to one having ordinary skill in the art to revoke credential when certificate is invalid as well-known in the art.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Boszczyk et al. U.S. 2021/0358068 discloses method for issuing a verified health pass to allow entry to a venue if specific health status meets predefined criteria.
Church et al. U.S. 2022/0301667 discloses method for verifying an immunization status.
Kocher et al. U.S. 11,430,553 discloses health verification system.
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHIN HON (ERIC) CHEN whose telephone number is (571)272-3789. The examiner can normally be reached Monday to Thursday 9am- 7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHIN-HON (ERIC) CHEN/Primary Examiner, Art Unit 2431