Prosecution Insights
Last updated: August 17, 2026
Application No. 19/063,255

IMPLEMENTING A PRIVACY INFRASTRUCTURE FOR THE INTERNET OF THINGS

Non-Final OA §103§112§DOUBLEPATENT
Filed
Feb 25, 2025
Priority
Jul 22, 2016 — provisional 62/493,972 +4 more
Examiner
CRIBBS, MALCOLM
Art Unit
Tech Center
Assignee
Carnegie Mellon University
OA Round
1 (Non-Final)
89%
Grant Probability
Favorable
1-2
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
695 granted / 782 resolved
+28.9% vs TC avg
Moderate +15% lift
Without
With
+14.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
15 currently pending
Career history
788
Total Applications
across all art units

Statute-Specific Performance

§101
14.2%
-25.8% vs TC avg
§103
43.6%
+3.6% vs TC avg
§102
8.8%
-31.2% vs TC avg
§112
21.9%
-18.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 782 resolved cases

Office Action

§103 §112 §DOUBLEPATENT
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This action is in response to the correspondence filed 02/26/2025. Claims 1-27 are presented for examination. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-27 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-29 of U.S. Patent No. 12,511,409. Although the claims at issue are not identical, they are not patentably distinct from each other because each of the claim limitations of claims 1, 16, 26 and 27 of the present application are anticipated by each of the limitations of claims 1, 16, 26 and 27 of U.S. Patent No. 12,511,409. Claim Objections Claims 3 and 18 are objected to because of the following informalities: the initial instance of “API” does not include the words which correspond to each letter of the acronym. Appropriate correction is required. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitations use a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are: “an Internet of Things (IoT) resource for…” and “an IoT resource registry for…” in claims 1, 15, 16 and 25. Because these claim limitations are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, they are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have these limitations interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitations to avoid them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitations recite sufficient structure to perform the claimed function so as to avoid them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-25 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. As to claims 1, 15, 16 and 25, claim limitations “an Internet of Things (IoT) resource for…” and “an IoT resource registry for…” invoke 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. Applicant may: (a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. Claims 2-14 and 17-24 do not cure the deficiency of claims 1 and 16 and are rejected under 35 USC § 112 for their dependency upon claims 1 and 16. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-4, 6, 10, 11, 13, 14 and 26 are rejected under 35 U.S.C. 103 as being unpatentable over US 2017/0187749 to Tyler in view of US 2006/0123462 to Lunt et al. in further view of US 2024/0416246 to Justman. As to claims 1 and 26, Tyler teaches a system comprising: an Internet of Things (IoT) resource for remotely sensing data about a user (paragraphs 15, 43 and 74, IoT devices which collect user data); and a computing device of the user (FIG. 3 and paragraph 43, computing device), wherein the computing device comprises a processor that executes a personal privacy app ("PPA") (FIG. 3 and paragraph 44, privacy management application) that: receives data about the IoT resource (paragraphs 15, 43 and 58, request sent to the computing device from the IoT devices read as the received data); and communicates a privacy request for the user with respect to the IoT resource, wherein the privacy request communicated by the PPA is based on the data received about the IoT resource (paragraph 59, asserting via the first computing device, the user privacy policy to the second computing device). Tyler does not explicitly teach the data about the IoT resource comprising available user-specific privacy requests related to data practices of the IoT resource; and the privacy request being one of the available user-specific privacy requests. However, Lunt teaches the data about the IoT resource comprising available user-specific privacy requests related to data practices of the IoT resource; and the privacy request being one of the available user-specific privacy requests (paragraphs 44, 60, 62 and 64, the privacy policy of the requestor which is communicated to the user, wherein a privacy agreement is determined by the user based on the privacy policy of the requestor, wherein the requestor’s policy includes the requestor’s set of acceptable parameters for the privacy agreement; the requestor’s acceptable parameters communicated to the user read as the available user-specific privacy request and the determination made based on the requestor’s acceptable parameters read as the privacy request being one of the available user-specific privacy requests). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the teachings of Tyler to include the available user-specific privacy requests as taught by Lunt in order to increase the likelihood that the user will provide the requested information by disclosing the specifics of the requestor, thus increasing the overall efficiency and trust of the system (paragraph 64). Tyler and Lunt do not explicitly teach in response to a query related to the privacy request, causes electronic documentation to be transmitted that demonstrates that the user qualifies to submit the privacy request, such that the privacy request is applied to data collected about the user by the IoT resource. However, Justman teaches in response to a query related to the privacy request, causes electronic documentation to be transmitted that demonstrates that the user qualifies to submit the privacy request, such that the privacy request is applied to data collected about the user by the IoT resource (paragraphs 46-48, 52 and 53, in response to the request, the passport is provided which includes identification information of the user, privacy and mapping preferences, the passport read as the electronic documentation and qualifying the user as it identifies the user). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the teachings of Tyler and Lunt to include the electronic documentation as taught by Justman in order to verify the identity of the source of the privacy request, thus ensuring the actual user is submitting the request optimizing the overall security and integrity of the system. As to claim 2, Tyler teaches wherein the PPA receives the data about the IoT resource from an IoT resource description for the IoT resource hosted by an IoT privacy infrastructure (paragraph 43, wherein the IoT devices include and store applications wherein the applications depicted separate from the devices have associated hardware infrastructure such as computer server implementation, delivery hardware, etc.). As to claim 3, Tyler teaches wherein the PPA receives the data about the IoT resource via API calls to the IoT resource, wherein an API for the API call is included in the IoT resource description (paragraphs 44 and 45, interacting with the IoT API module). As to claim 4, Lunt teaches wherein the data about the IoT resource comprises privacy requests supported by the IoT resource (paragraphs 62 and 64, wherein the requestor’s policy includes the requestor’s set of acceptable parameters for the privacy agreement; the requestor’s acceptable parameters communicated to the user read as the available user-specific privacy request and the determination made based on the requestor’s acceptable parameters read as the privacy request being one of the available user-specific privacy requests). As to claim 6, Lunt teaches wherein the data about the IoT resource comprises default privacy practices of the IoT resource (paragraphs 62 and 64, wherein the requestor’s policy includes the requestor’s set of acceptable parameters for the privacy agreement). As to claim 10, Lunt teaches wherein the PPA is further configured to determine the privacy request for the user using a privacy preference model for the user and using the data about the IoT resource (paragraph 60, determination based on at least one of: a privacy policy associated with the user; a privacy policy associated with the requestor; a recommended privacy policy and the impact of releasing the requested information). As to claim 11, Justman teaches wherein the electronic documentation comprises a digital image (paragraphs 43 and 44, digital passport). As to claim 13, Justman teaches wherein the electronic document evidences an attribute of the user, wherein the attribute is one of an age of the user, a location of residence of the user, membership of the user in an organization, or a clean criminal record (paragraph 46, name, email, avatar, phone number, physical and/or network addresses, and identification documents). As to claim 14, Tyler teaches wherein the available user-specific privacy requests at least one of opt-in or opt-out settings for a data practice of the IoT resource, a request for deletion of the data collected about the user, or a request to review the data collected about the user (paragraphs 56, 59 and 66, allowing or denying access read as opt-in or opt-out). Claims 16-19, 21, 23 and 27 are rejected under 35 U.S.C. 103 as being unpatentable over Tyler in view of Lunt in further view of South, Tobin, et al. "Authenticated delegation and authorized ai agents." arXiv preprint arXiv:2501.09674 (2025) (hereinafter South). As to claims 16 and 27, Tyler teaches a system comprising: an Internet of Things (IoT) resource for remotely sensing data about a user (paragraphs 15, 43 and 74, IoT devices which collect user data); a computing device of the user, wherein the computing device comprises a processor that executes a personal privacy app ("PPA") (FIG. 3 and paragraph 44, privacy management application); wherein the PPA: receives data about the IoT resource (paragraphs 15, 43 and 58, request sent to the computing device from the IoT devices read as the received data); and communicates a privacy request for the user with respect to the IoT resource, wherein the privacy request is based on the data received about the IoT resource (paragraphs 15, 43, 58 and 59, asserting via the first computing device, the user privacy policy to the second computing device based on the received request). Tyler does not explicitly teach the data about the IoT resource comprising available user-specific privacy requests related to data practices of the IoT resource. However, Lunt teaches the data about the IoT resource comprising available user-specific privacy requests related to data practices of the IoT resource (paragraphs 44, 60, 62 and 64, the privacy policy of the requestor which is communicated to the user, wherein a privacy agreement is determined by the user based on the privacy policy of the requestor, wherein the requestor’s policy includes the requestor’s set of acceptable parameters for the privacy agreement; the requestor’s acceptable parameters communicated to the user read as the available user-specific privacy request and the determination made based on the requestor’s acceptable parameters read as the privacy request being one of the available user-specific privacy requests). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the teachings of Tyler to include the available user-specific privacy requests as taught by Lunt in order to increase the likelihood that the user will provide the requested information by disclosing the specifics of the requestor, thus increasing the overall efficiency and trust of the system (paragraph 64). Tyler and Lunt do not explicitly teach an authorized agent that is authorized to submit privacy requests on behalf of the user and is a trusted source of privacy requests for the IoT resource, communicating to the authorized agent and wherein the authorized agent communicates the privacy request for the user for implementation with respect to data collected about the user by the IoT resource. However, South teaches an authorized agent that is authorized to submit privacy requests on behalf of the user and is a trusted source of privacy requests for the IoT resource, communicating to the authorized agent and wherein the authorized agent communicates the privacy request for the user for implementation with respect to data collected about the user by the IoT resource (Pages 6 and 7, § 3.2 and 3.3, the AI agent includes a user’s ID-token which authorizes it based on the user, an agent-ID token which authorizes the AI agent with the service it is communicating with on behalf of the user and a delegation token which authorizes the AI agent to act on the user’s behalf; Pages 9 and 10, § 4.4, the user indicates to the AI agent to perform a request and the AI agent performs the request with a corresponding service and/or another AI agent). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the teachings of Tyler and Lunt to include the authenticated and delegated AI agent as taught by South in order to allow the passive control and monitoring of the user’s privacy requests with the ability to authorize and verify the agent and its actions to be performed, thus optimizing the security and integrity of the system (pages 1 and 2, § 1 and 2). As to claim 17, Tyler teaches wherein the PPA receives the data about the IoT resource from an IoT resource description for the IoT resource hosted by an IoT privacy infrastructure (paragraph 43, wherein the IoT devices include and store applications wherein the applications depicted separate from the devices have associated hardware infrastructure such as computer server implementation, delivery hardware, etc.). As to claim 18, Tyler teaches wherein the PPA receives the data about the IoT resource via API calls to the IoT resource, wherein an API for the API call is included in the IoT resource description (paragraphs 44 and 45, interacting with the IoT API module). As to claim 19, Tyler teaches wherein the data about the IoT resource comprises privacy requests supported by the IoT resource (paragraphs 62 and 64, wherein the requestor’s policy includes the requestor’s set of acceptable parameters for the privacy agreement; the requestor’s acceptable parameters communicated to the user read as the available user-specific privacy request and the determination made based on the requestor’s acceptable parameters read as the privacy request being one of the available user-specific privacy requests). As to claim 21, Lunt teaches wherein the data about the IoT resource comprises default privacy practices of the IoT resource (paragraphs 62 and 64, wherein the requestor’s policy includes the requestor’s set of acceptable parameters for the privacy agreement). As to claim 23, Lunt teaches wherein the PPA is further configured to determine the privacy request for the user using a privacy preference model for the user and using the data about the IoT resource (paragraph 60, determination based on at least one of: a privacy policy associated with the user; a privacy policy associated with the requestor; a recommended privacy policy and the impact of releasing the requested information). Claims 7, 8 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Tyler in view of Lunt in view of Justman in further view of South. As to claim 7, Tyler, Lunt and Justman do not explicitly teach wherein the PPA submits the privacy request to an authorized agent, wherein the authorized agent is a trust source of privacy requests for the IoT resource. However, South teaches wherein the PPA submits the privacy request to an authorized agent, wherein the authorized agent is a trust source of privacy requests for the IoT resource (Pages 6 and 7, § 3.2 and 3.3, the AI agent includes a user’s ID-token which authorizes it based on the user, an agent-ID token which authorizes the AI agent with the service it is communicating with on behalf of the user and a delegation token which authorizes the AI agent to act on the user’s behalf; Pages 9 and 10, § 4.4, the user indicates to the AI agent to perform a request and the AI agent performs the request with a corresponding service and/or another AI agent). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the teachings of Tyler, Lunt and Justman to include the authenticated and delegated AI agent as taught by South in order to allow the passive control and monitoring of the user’s privacy requests with the ability to authorize and verify the agent and its actions to be performed, thus optimizing the security and integrity of the system (pages 1 and 2, § 1 and 2). As to claim 8, Justman teaches where the PPA causes the electronic documentation to be transmitted to the authorized agent (paragraphs 46-48, 52 and 53, in response to the request, the passport is provided which includes identification information of the user, privacy and mapping preferences, the passport read as the electronic documentation and qualifying the user as it identifies the user). As to claim 24, Justman teaches wherein the PPA is further configured to, in response to a request, communicate to the authorized agent electronic documentation that demonstrates that the user qualifies to submit the privacy request (paragraphs 46-48, 52 and 53, in response to the request, the passport is provided which includes identification information of the user, privacy and mapping preferences, the passport read as the electronic documentation and qualifying the user as it identifies the user). Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Tyler in view of Lunt in view of Justman in view of South in further view of US 2003/0051171 to Pearson. As to claim 12, Tyler, Lunt, Justman and South do not explicitly teach wherein the electronic documentation comprises an electronic document digitally signed by an issuer of the electronic document. However, Pearson teaches an electronic documentation comprises an electronic document digitally signed by an issuer of the electronic document (paragraph 77, signed by the Privacy-CA). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the teachings of Tyler, Lunt, Justman and South to include the document being signed by an issuer of the document as taught by Pearson in order to allow the source and integrity of the document to be validated. Relevant Prior Art The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 2010/0024045 to Sastry et al. teaches a method for accepting and enforcing user selectable privacy settings for context awareness including location awareness data on a computing platform. The method may identify a requestor, assign a privacy setting to the requester then detect a request for location information from the requestor. The method may transmit location information to the requester based on the user selected privacy setting. The user selected privacy setting may have a granularity assigned to each requestor based on a privacy preference and the method may entirely block the location information from being disclosed or the method may modify the granularity/accuracy of the location information based on the privacy setting to report context of an appropriate level of granularity according to the privacy setting configured by the user. US 2003/0023451 to Willner et al. teaches a method for notifying a user of a privacy level associated with an interaction conducted by or otherwise involving the user either before, during or after the interaction. Once a determination is made regarding what level of privacy is being applied to an interaction, a notification may be sent to the user to inform the user of such privacy level. In some embodiments, the notification may include an icon or other image that is displayed on a user device (e.g., computer, cellular telephone) or with software that the user is using during the interaction. Different interactions between the user and the service provider may have different privacy levels associated with them. US 20130006904 A1 to Horvitz et al. teaches a long-term personal agent program, executable as network service and/or on one or more user computing devices and related method for identifying opportunities and making recommendations on behalf of one or more users, are disclosed herein. In one example, the personal agent program includes a monitoring engine configured to monitor and interpret a user's activities over time with a plurality of sensing and logging methodologies according to user authorization, the use of statistical methods for learning to understand a user's goals and behavioral patterns from data, and the use of procedures for computing the expected value of information guiding sensing and logging in different contexts. The personal agent further may include a recommendation methodology configured to make suggestions and to take actions on behalf of the user, in the present moment as well as for future times, based on inferences about user goals and opportunities in the world. Allowable Subject Matter Claims 5, 9, 15, 20, 22 and 25 would be allowable if rewritten to overcome the double patenting rejections and the rejections under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), 2nd paragraph, and set forth in this Office action and to include all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: Dependent claims 5 and 20 are allowable over the prior art of record, including Tyler, Lunt, Justman, Horvitz, South and the references cited by the Examiner and the Applicant’s IDS, taken individually or in combination, because the prior art of record fails to particularly disclose, fairly suggest or render obvious the data about the IoT resource comprising identification of documentation that demonstrates qualification to submit the privacy request, in view of the other limitations of their respective independent claims 1 and 16, as to claims 5 and 20; Dependent claims 9 and 22 are allowable over the prior art of record, including Tyler, Lunt, Justman, Horvitz, South and the references cited by the Examiner and the Applicant’s IDS, taken individually or in combination, because the prior art of record fails to particularly disclose, fairly suggest or render obvious the PPA receiving the data about the IoT resource from an IoT resource description for the IoT resource hosted by an IoT privacy infrastructure, and wherein the IoT resource description: identifies one or more authorized agents that are trusted sources for privacy requests for the IoT resource; and APIs to communicate with the one or more authorized agents, in view of the other limitations of their respective independent claims 1 and 16, as to claims 9 and 22; Dependent claims 15 and 25 are allowable over the prior art of record, including Tyler, Lunt, Justman, Horvitz, South and the references cited by the Examiner and the Applicant’s IDS, taken individually or in combination, because the prior art of record fails to particularly disclose, fairly suggest or render obvious an IoT resource registry for advertising the IoT resource, and wherein the PPA is for discovering the IoT resource registry based on a location of the computing device of the user, in view of the other limitations of their respective independent claims 1 and 16, as to claims 15 and 25. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MALCOLM CRIBBS whose telephone number is (571)270-1566. The examiner can normally be reached Monday-Friday 930a-330p; 430p-630p. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached at (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. MALCOLM . CRIBBS Examiner Art Unit 2497 /MALCOLM CRIBBS/ Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Feb 25, 2025
Application Filed
Jul 21, 2026
Non-Final Rejection mailed — §103, §112, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706881
Privacy Firewalls for Access Control
1y 12m to grant Granted Aug 11, 2026
Patent 12688333
METHOD FOR CHECKING DATA INTEGRITY
3y 1m to grant Granted Jul 21, 2026
Patent 12676765
METHOD AND APPARATUS FOR EDITING BLOCK CHAIN
2y 7m to grant Granted Jul 07, 2026
Patent 12657329
METHOD AND SYSTEM OF RESCINDING ACCESS TO BLOCKCHAIN DATA
2y 6m to grant Granted Jun 16, 2026
Patent 12647282
GENERATING DIGITAL SIGNATURE SHARES
2y 3m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+14.7%)
2y 4m (~10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 782 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month