Prosecution Insights
Last updated: October 04, 2026
Application No. 19/225,797

SELF-SOVEREIGN IDENTITY STRUCTURED MESSAGING FOR CROSS CHANNEL AUTHENTICATION

Non-Final OA §101§103
Filed
Jun 02, 2025
Priority
Jan 29, 2021 — CIP of 17/162,663 +1 more
Examiner
AUSTIN, JAMIE H
Art Unit
Tech Center
Assignee
Digital First Holdings LLC
OA Round
1 (Non-Final)
25%
Grant Probability
At Risk
1-2
OA Rounds
3y 7m
Est. Remaining
58%
With Interview

Examiner Intelligence

Grants only 25% of cases
25%
Career Allowance Rate
105 granted / 424 resolved
-35.2% vs TC avg
Strong +33% interview lift
Without
With
+33.2%
Interview Lift
resolved cases with interview
Typical timeline
4y 11m
Avg Prosecution
30 currently pending
Career history
465
Total Applications
across all art units

Statute-Specific Performance

§101
32.7%
-7.3% vs TC avg
§103
36.6%
-3.4% vs TC avg
§102
6.7%
-33.3% vs TC avg
§112
21.2%
-18.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 424 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status This action is in response to the preliminary amendment filed on 6/3/2025. Claims 1-20 are pending. No claims are amended. Claims 11-20 have been added. No claims have been cancelled. Claim Objections Claims 1 and 11 are objected to as being duplicate claims. Claims 1 and 11 contain the exact same language. Applicant is advised that should claim 1 be found allowable, claim 11 will be objected to under 37 CFR 1.75 as being a substantial duplicate thereof. When two claims in an application are duplicates or else are so close in content that they both cover the same thing, despite a slight difference in wording, it is proper after allowing one claim to object to the other as being a substantial duplicate of the allowed claim. See MPEP § 608.01(m). Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e. abstract idea) without anything significantly more. Step 1: Claims 1-18 are directed to a method and claims 19-20 are directed to a system. Therefore, claims 1-20 are directed to patent eligible categories of invention. Step 2A, Prong 1: The claim(s) recite(s) (mathematical relationships/formulas, mental process or certain methods of organizing human activity). Specifically, the independent claims recite: mental process: as drafted, the claims recites the limitations of receiving a request for a service, obtaining a DID for a SSI, establishing a DID connection, sending a second message, receiving a structured response, granting access to a service and managing a SSI, receiving a request, establishing a DID, sending a message, verifying a response, and authenticating a customer which is a process that, under its broadest reasonable interpretation, covers performance of the limitations in the mind but for the recitation of generic computer components. That is, other than reciting generic computer components nothing in the claim precludes the determining step from practically being performed in the human mind. For example, but for the “by a processor” language, the claim encompasses a user sending messages to gain access to a service. The mere nominal recitation of generic computing devices does not take the claim limitation out of the mental processes grouping. This limitation is a mental process. certain methods of organizing human activity: The claim as a whole recites a method of organizing human activity. The claimed invention is a method of verifying the identity of a person by issuing a challenge and evaluating a response before granting access to something which is a method of managing interactions between people and a fundamental economic practice. Thus, the claim recites an abstract idea. Dependent claims 2-4, 10, 14, 17-18, further narrow the abstract idea identified in the independent claims and do not introduce further additional elements for consideration. Dependent claims 5-9, 12-13, 15-16, 20, will be evaluated under Step 2A, Prong 2 below. Step 2A, Prong 2: Independent claims 1, 11, and 19 do not integrate the judicial exception into a practical application. Claims 1 and 11 are a method comprising “a DID…SSI-enabled wallet… FI wallet… secure channel… structured message.” Claim 19 is a system that comprises “a cloud server… one or more processors… a non-transitory computer readable medium… executable instructions.” These additional elements are mere instructions to implement an abstract idea using a computer in its ordinary capacity, or merely uses the computer as a tool to perform the identified abstract idea. Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, manipulate, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) does not integrate a judicial exception into a practical application. See MPEP 2106.05(f). Therefore, the additional elements of the independent claims, when considered both individually and in combination, are not sufficient to prove integration into a practical application. Dependent claims 2-4, 10, 14, 17-18, further narrow the abstract idea identified in the independent claims and do not introduce further additional elements for consideration, which does not integrate the judicial exception into a practical application. Dependent claim 5 introduces the additional element of “wherein obtaining further includes obtaining the DID as relationship DID that was provided a first time the FI wallet connected to the SSI-enabled wallet over the secure channel using the DID.” This limitation does not integrate the judicial exception into a practical application because it is nothing more than generally linking the use of the judicial exception to a particular technological environment. See MPEP 2106.05(h). Dependent claim 6, 13, introduces the additional elements of “encrypting the structured message challenge and signing with a signature of the FI wallet.” Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) does not integrate a judicial exception into a practical application. See MPEP 2106.05(f). Dependent claims 7, 15, introduces the additional element of “decrypting the structured response and verifying a second signature of the SSI-enabled wallet.” Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) does not integrate a judicial exception into a practical application. See MPEP 2106.05(f). Dependent claims 8, 16, introduces the additional element of “by validating correct… PII… against account records.” Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) does not integrate a judicial exception into a practical application. See MPEP 2106.05(f). Dependent claim 9 introduces the additional element of “wherein decrypting further includes authenticating the structured response by identifying an authorization in the structured response provided by the customer through the SSI-enabled wallet.” This limitation does not integrate the judicial exception into a practical application because it is nothing more than generally linking the use of the judicial exception to a particular technological environment. See MPEP 2106.05(h). Dependent claim 12 introduces the additional element of “wherein establishing further includes obtaining the SSI- enabled wallet from an SSI provider that is managed on a cloud server.” Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) does not integrate a judicial exception into a practical application. See MPEP 2106.05(f). Dependent claim 20 introduces the additional element of “wherein the operations further comprising :maintaining structured responses received from the SSI-enabled wallet during subsequent DID connections as an audit trail for Know Your Customer (KYC) requirements; encrypting subsequent structured messages sent over additional DID connections between the FI wallet and the SSI-enabled wallet during additional contacts for authenticating the customer; and digitally signing the subsequent structured messages by both the FI wallet and the SSI- enabled wallet.” This limitation provides nothing more than mere instructions to implement an abstract idea on a generic computer. See MPEP 2106.05(f). MPEP 2106.05(f) provides the following considerations for determining whether a claim simply recites a judicial exception with the words “apply it” (or an equivalent), such as mere instructions to implement an abstract idea on a computer: (1) whether the claim recites only the idea of a solution or outcome i.e., the claim fails to recite details of how a solution to a problem is accomplished; (2) whether the claim invokes computers or other machinery merely as a tool to perform an existing process; and (3) the particularity or generality of the application of the judicial exception. Therefore, this limitation is not sufficient to prove integration into a practical application. This limitation does not integrate the judicial exception into a practical application because it is nothing more than generally linking the use of the judicial exception to a particular technological environment. See MPEP 2106.05(h). Therefore, the additional elements of the dependent claims, when considered both individually and in the context of the independent claims, are not sufficient to prove integration into a practical application. Step 2B: Independent claims 1, 11, and 19 do not comprise anything significantly more than the judicial exception. As can be seen above with respect to Step 2A, Prong 2, Claims 1 and 11 are a method comprising “a DID…SSI-enabled wallet… FI wallet… secure channel… structured message.” Claim 19 is a system that comprises “a cloud server… one or more processors… a non-transitory computer readable medium… executable instructions.” These additional elements are mere instructions to implement an abstract idea using a computer in its ordinary capacity, or merely uses the computer as a tool to perform the identified abstract idea. Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) is not anything significantly more than the judicial exception. See MPEP 2106.05(f). The additional elements of the independent claims, when considered both individually and in combination, do not comprise anything significantly more than the judicial exception. Dependent claims 2-4, 10, 14, 17-18, further narrow the abstract idea identified in the independent claims and do not introduce further additional elements for consideration, which is not anything significantly more than the judicial exception. Dependent claim 5 introduces the additional element of “wherein obtaining further includes obtaining the DID as relationship DID that was provided a first time the FI wallet connected to the SSI-enabled wallet over the secure channel using the DID.” This limitation is not anything significantly more than the judicial exception because it is nothing more than generally linking the use of the judicial exception to a particular technological environment. See MPEP 2106.05(h). Dependent claim 6, 13, introduces the additional elements of “encrypting the structured message challenge and signing with a signature of the FI wallet.” Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) is not anything significantly more than the judicial exception. See MPEP 2106.05(f). Dependent claims 7, 15, introduces the additional element of “decrypting the structured response and verifying a second signature of the SSI-enabled wallet.” Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) is not anything significantly more than the judicial exception. See MPEP 2106.05(f). Dependent claims 8, 16, introduces the additional element of “by validating correct… PII… against account records.” Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) is not anything significantly more than the judicial exception. See MPEP 2106.05(f). Dependent claim 9 introduces the additional element of “wherein decrypting further includes authenticating the structured response by identifying an authorization in the structured response provided by the customer through the SSI-enabled wallet.” This limitation is not anything significantly more than the judicial exception because it is nothing more than generally linking the use of the judicial exception to a particular technological environment. See MPEP 2106.05(h). Dependent claim 12 introduces the additional element of “wherein establishing further includes obtaining the SSI- enabled wallet from an SSI provider that is managed on a cloud server.” Use of a computer or other machinery in its ordinary capacity for performing the steps of the abstract idea or other tasks (e.g., to receive, store, or transmit data) or simply adding a general purpose computer or computer components after the fact to an abstract idea (e.g., certain methods of organizing human activity) is not anything significantly more than the judicial exception. See MPEP 2106.05(f). Dependent claim 20 introduces the additional element of “wherein the operations further comprising :maintaining structured responses received from the SSI-enabled wallet during subsequent DID connections as an audit trail for Know Your Customer (KYC) requirements; encrypting subsequent structured messages sent over additional DID connections between the FI wallet and the SSI-enabled wallet during additional contacts for authenticating the customer; and digitally signing the subsequent structured messages by both the FI wallet and the SSI- enabled wallet.” This limitation provides nothing more than mere instructions to implement an abstract idea on a generic computer. See MPEP 2106.05(f). MPEP 2106.05(f) provides the following considerations for determining whether a claim simply recites a judicial exception with the words “apply it” (or an equivalent), such as mere instructions to implement an abstract idea on a computer: (1) whether the claim recites only the idea of a solution or outcome i.e., the claim fails to recite details of how a solution to a problem is accomplished; (2) whether the claim invokes computers or other machinery merely as a tool to perform an existing process; and (3) the particularity or generality of the application of the judicial exception. Therefore, this limitation is not anything significantly more than the judicial exception. This limitation is not anything significantly more than the judicial exception because it is nothing more than generally linking the use of the judicial exception to a particular technological environment. See MPEP 2106.05(h). The additional elements of the dependent claims, when considered both individually and in the context of the independent claims, are not anything significantly more than the judicial exception. Therefore, based on the above analysis as conducted based on MPEP 2106 from the United States Patent and Trademark Office the claims are viewed as a court recognized abstract idea, are viewed as a judicial exception, does not integrate the claims into a practical application, does not provide significantly more, and does not provide an inventive concept, therefore the claims are ineligible. Accordingly, claims 1-20 are rejected under 35 USC 101. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 3, 5-16, 18-20, is/are rejected under 35 U.S.C. 103 as being unpatentable over Kravitz et al. (US 20220385477 A1) in view of Pohjola et al. (US 20230075539 A1). Regarding claims 1 and 11, Kravitz discloses receiving a request for a service over a first channel from a customer (Fig. 2, 14, ¶ 31, 53-55, discloses the user communicating a request. ¶ 60); obtaining a Decentralized Identifier (DID) for a Self-Sovereign Identity (SSI)-enabled wallet of the customer (¶ 31-33, discloses assigning a unique value to each finalized token and use the assigned value as a KYC Identifier that appears on a blockchain. ¶ 40-43, the KYC unique decentralized ID is a reference used across all the wallets of a specific user.); sending a structured message challenge to the customer over the secure channel via the SSI-enabled wallet (¶ 39-41, discloses the KYC processor randomly/pseudorandomly generating Nonce values and digitally signs for retrieval/use.); receiving a structured response from the customer over the secure channel via the … wallet (¶ 40-42, discloses how a user provides specific information to the KYC Processor. The KYC processor acts as a third party wallet element and receives a structured multifield signed response ¶ 60, 121); and granting access to the service when the structured response is authenticated (¶ 34-35, 42, disclose the user being authenticated and being granted access. ¶ 53-54, 57). Kravitz does not specifically teach an FI wallet. Pohjola teaches obtaining a Decentralized Identifier (DID) for a Self-Sovereign Identity (SSI)-enabled wallet of the customer (¶ 20-21, discloses the specific language of a DID and a SSI); establishing a DID connection, over a secure channel, between a Financial Institution (FI) wallet and the SSI-enabled wallet using the DID (¶ 20-23, discloses the specific language of a DID and a SSI and a digital SSI wallet. ¶ 25-26, discloses bank issued credentials.). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform an FI wallet, as taught/suggested by Pohjola. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to accessing sensitive data using cryptographic keys for security purposes. One of ordinary skill in the art would have recognized that applying the known technique of Pohjola would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Pohjola to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such FI wallet features into similar systems. Further, applying a FI wallet would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow the user to specifically identify a holder of the wallet relaying. Regarding claim 3, Kravitz teaches wherein obtaining further includes obtaining the DID from an account record associated with an account of the customer based on a detail obtained from the customer directly or indirectly over the first channel that is indexed to the account (¶ 43, discloses the a KYC identity is looked up in a database accessible to the Attributes Registry/Coordinator. Data is accessed by the user. A new value generation is also disclosed. ¶ 25-27, 30-31). Also taught by Pohjola ¶ 23. Regarding claim 5, Kravitz teaches wherein obtaining further includes obtaining the DID as relationship DID that was provided a first time the … wallet connected to the SSI-enabled wallet over the secure channel using the DID (¶ 42-44, discloses that the Attributes Registry/Coordinator 125 should therefore attempt to look up the pre-KYCid in the database. If no entry is found, then a new random value is generated, entered in the database as associated with the pre-KYCid and used as the KYCid. The generation of the KYCid upon the wallet’s successful connection to the KYC processor is a relationship DID established at first connection). Kravitz does not specifically teach an FI wallet. Pohjola teaches Financial Institution (FI) wallet and the SSI-enabled wallet using the DID (¶ 20-23, discloses the specific language of a DID and a SSI and a digital SSI wallet. ¶ 25-26, discloses bank issued credentials.). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform an FI wallet, as taught/suggested by Pohjola. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to accessing sensitive data using cryptographic keys for security purposes. One of ordinary skill in the art would have recognized that applying the known technique of Pohjola would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Pohjola to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such FI wallet features into similar systems. Further, applying a FI wallet would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow the user to specifically identify a holder of the wallet relaying. Regarding claim 6, Kravitz teaches wherein sending further includes encrypting the structured message challenge and signing the structured message challenge with a signature of the … wallet (¶ 40, discloses retrieving a Signed Nonce tuple=[Nonce; Nonce_validity_period; Sign(Nonce; Nonce_validity_period)] (as included in Table 1) at 135 from the KYC Processor 120, where the KYC Processor 120 randomly/pseudorandomly generates Nonce values and digitally signs or uses another keyed function on each such Nonce and its associated validity period/expiration/timestamp.¶ 13-27, discloses both encrypting and signing the challenge before it is made available to a wallet.). Pohjola teaches Financial Institution (FI) wallet (¶ 20-23, discloses the specific language of a DID and a SSI and a digital SSI wallet. ¶ 25-26, discloses bank issued credentials.). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform an FI wallet, as taught/suggested by Pohjola. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to accessing sensitive data using cryptographic keys for security purposes. One of ordinary skill in the art would have recognized that applying the known technique of Pohjola would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Pohjola to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such FI wallet features into similar systems. Further, applying a FI wallet would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow the user to specifically identify a holder of the wallet relaying. Regarding claim 7, Kravitz teaches wherein receiving the structured response further includes decrypting the structured response and verifying a second signature of the SSI-enabled wallet on the structured response (¶ 42, discloses the KYC Processor would return an error to the Client 105 at 155 of FIG. 1. If no error occurs, the KYC Processor 120 computes hash(WalletSig) and hash(NonceSig) referred to in FIG. 1 as wallet output derivatives transmitted at 160. ¶ 13-27, discloses both encrypting and signing the challenge before it is made available to a wallet.). Also disclosed by Pohjola. Regarding claim 8, Kravitz teaches wherein decrypting further includes authenticating the structured response by validating correct personal identifiable information (PII) in the structured response against account records for an account associated with the customer (Fig. 2, ¶ 54, discloses an identity verification service. ¶ 30, 72, discloses validating user attributes. ¶ 41). Regarding claim 9, Kravitz teaches wherein decrypting further includes authenticating the structured response by identifying an authorization in the structured response provided by the customer through the SSI-enabled wallet (Fig. 2, ¶ 41-42, discloses verifying/authenticating by using the KYC processor for verification. ¶ 35, 45, 81-82). Regarding claim 10, Kravitz teaches retaining the structured response as evidence that Know Your Customer (KYC) requirements were satisfied when authenticating the customer for access to the service (¶ 30-31, 42, discloses verifying using KYC requirements. ¶ 35, 45, 53, 57, 79, 118, 139). Regarding claim 12, Kravitz teaches wherein establishing further includes obtaining the SSI- enabled wallet from an SSI provider that is managed on a cloud server (¶ 29, discloses The terms “wallet” as used herein is to be understood as being replaceable by a more general term, i.e., “key-pair-enabled app,” where such a key-pair-enabled app can be implemented as software or hardware or a combination thereof. Further, such key-pair-enabled app can run locally to a User or remotely or as a hybrid/combination thereof, e.g., as a Client-side software component, Client-embedded hardware, as a peripheral device supported by a Client, or as a cloud-based application. ¶ 128-138, disclose the coordinating network). Also disclosed by Pohjola. Regarding claim 13, Kravitz teaches wherein sending further includes encrypting the structured message challenge and signing the structured message challenge with a signature of the… wallet before sending over the secure channel (¶ 40, discloses retrieving a Signed Nonce tuple=[Nonce; Nonce_validity_period; Sign(Nonce; Nonce_validity_period)] (as included in Table 1) at 135 from the KYC Processor 120, where the KYC Processor 120 randomly/pseudorandomly generates Nonce values and digitally signs or uses another keyed function on each such Nonce and its associated validity period/expiration/timestamp.¶ 13-27, discloses both encrypting and signing the challenge before it is made available to a wallet.). Kravitz does not specifically teach a FI wallet. Pohjola teaches Financial Institution (FI) wallet (¶ 20-23, discloses the specific language of a DID and a SSI and a digital SSI wallet. ¶ 25-26, discloses bank issued credentials.). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform an FI wallet, as taught/suggested by Pohjola. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to accessing sensitive data using cryptographic keys for security purposes. One of ordinary skill in the art would have recognized that applying the known technique of Pohjola would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Pohjola to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such FI wallet features into similar systems. Further, applying a FI wallet would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow the user to specifically identify a holder of the wallet relaying. Regarding claim 14, Kravitz teaches wherein receiving further includes receiving the structured response as an off chain communication that does not write to a blockchain (¶ 40-42, discloses the transmissions that occurred before and separately from the later on posting of the results. ¶ 44-45, discloses that the platform does not write to a blockchain. ¶ 30, 35.). Also disclosed by Pohjola. Regarding claim 15, Kravitz teaches wherein receiving further includes decrypting the structured response and verifying a second signature of the SSI-enabled wallet on the structured response (¶ 42, discloses the KYC Processor would return an error to the Client 105 at 155 of FIG. 1. If no error occurs, the KYC Processor 120 computes hash(WalletSig) and hash(NonceSig) referred to in FIG. 1 as wallet output derivatives transmitted at 160. ¶ 13-27, discloses both encrypting and signing the challenge before it is made available to a wallet.). Also disclosed by Pohjola. Regarding claim 16, Kravitz teaches wherein granting further includes authenticating the structured response by validating correct Personal Identifiable Information (PII) in the structured response against account records for an account associated with the customer (Fig. 2, ¶ 54, discloses an identity verification service. ¶ 30, 72, discloses validating user attributes. ¶ 41). Regarding claim 18, Kravitz teaches wherein receiving further includes maintaining the structured response as evidence that Know Your Customer (KYC) requirements were satisfied when authenticating the customer for access to the service (¶ 30-31, 42, discloses verifying using KYC requirements. ¶ 35, 45, 53, 57, 79, 118, 139). Regarding claims 19, Kravitz discloses a cloud server comprising one or more processors and a non-transitory computer-readable storage medium; the non-transitory computer-readable storage medium comprising executable instructions; and the executable instructions when executed by the one or more processors performing operations comprising (Fig. 18, ¶ 128-138, disclose the apparatus, the memory, and the computer readable storage medium); managing a Self-Sovereign Identity (SSI) provider that creates and maintains SSI- enabled wallets for customers (¶ 29, discloses cloud based key paired enabled apps. ¶ 33, 43, maintaining the infrastructure that enables the issuance and maintenance of the wallets. ¶ 53, 59). receiving a request for authentication from a customer over a first channel (Fig. 2, 14, ¶ 31, 53-55, discloses the user communicating a request. ¶ 60); establishing a Decentralized Identifier (DID) connection between an SSI-enabled wallet of the customer and a… wallet over a secure channel (¶ 31-33, discloses assigning a unique value to each finalized token and use the assigned value as a KYC Identifier that appears on a blockchain. ¶ 40-43, the KYC unique decentralized ID is a reference used across all the wallets of a specific user. ¶ 68-69); sending an encrypted and signed structured challenge message from the … wallet to the SSI-enabled wallet (¶ 39-41, discloses the KYC processor randomly/pseudorandomly generating Nonce values and digitally signs for retrieval/use.); verifying a structured response received from the customer through the SSI- enabled wallet (¶ 40-42, discloses how a user provides specific information to the KYC Processor. The KYC processor acts as a third party wallet element and receives a structured multifield signed response ¶ 60, 121); authenticating the customer based on the verified structured response (¶ 34-35, 42, disclose the user being authenticated and being granted access. ¶ 53-54, 57). Kravitz does not specifically teach an FI wallet. Pohjola teaches managing a Self-Sovereign Identity (SSI) provider that creates and maintains SSI- enabled wallets for customers (¶ 20-21, discloses the specific language of a DID and a SSI); establishing a Decentralized Identifier (DID) connection between an SSI-enabled wallet of the customer and a… wallet over a secure channel (¶ 20-23, discloses the specific language of a DID and a SSI and a digital SSI wallet. ¶ 25-26, discloses bank issued credentials.). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform an FI wallet, as taught/suggested by Pohjola. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to accessing sensitive data using cryptographic keys for security purposes. One of ordinary skill in the art would have recognized that applying the known technique of Pohjola would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Pohjola to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such FI wallet features into similar systems. Further, applying a FI wallet would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow the user to specifically identify a holder of the wallet relaying. Regarding claim 20, Kravitz teaches maintaining structured responses received from the SSI-enabled wallet during subsequent DID connections as an audit trail for Know Your Customer (KYC) requirements (Fig. 2, ¶ 53-54, discloses an identity verification service. ¶ 30, 72, discloses validating user attributes., ¶ 30-31, 41-42, discloses verifying using KYC requirements. ¶ 35, 45, 57, 79, 118, 139); encrypting subsequent structured messages sent over additional DID connections between the… wallet and the SSI-enabled wallet during additional contacts for authenticating the customer (¶ 59, As shown in the extension of 340 back to the Client 305 from the KYC Processor 320 or end-to-end from a 3.sup.rd party monitoring service 325, the Client 305 may become aware of updates either synchronously with the update or at a later time upon pulling of such update information by the Client 305 prior to mounting a Query. This offers utility, in particular, in preventing false negatives during Query that could be caused by a Client providing outdated information to a Proxy on behalf of a User. ¶ 13-27); and digitally signing the subsequent structured messages by both the … wallet and the SSI- enabled wallet (¶ 40-41, discloses where the KYC Processor 120 randomly/pseudorandomly generates Nonce values and digitally signs or uses another keyed function on each such Nonce and its associated validity period/expiration/timestamp. ¶ 42-45, 30-31, 65-66). Kravitz does not specifically teach a FI wallet. Pohjola teaches Financial Institution (FI) wallet (¶ 20-23, discloses the specific language of a DID and a SSI and a digital SSI wallet. ¶ 25-26, discloses bank issued credentials.). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform an FI wallet, as taught/suggested by Pohjola. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to accessing sensitive data using cryptographic keys for security purposes. One of ordinary skill in the art would have recognized that applying the known technique of Pohjola would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Pohjola to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such FI wallet features into similar systems. Further, applying a FI wallet would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow the user to specifically identify a holder of the wallet relaying. Claim(s) 2, 17, is/are rejected under 35 U.S.C. 103 as being unpatentable over Kravitz et al. (US 20220385477 A1) in view of Pohjola et al. (US 20230075539 A1) in further view of Zhou et al. (US 20210383377 A1). Regarding claim 2, Kravitz discloses a web interface (¶ 29, 40, 55, 62, 84, 134) but does not disclose the other channels as claimed. Zhou discloses wherein receiving the request further includes identifying the first channel as a voice channel, a text messaging channel, a web-based channel, an application-based channel, or an in-person channel (¶ 71, discloses in person channels). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform the various channels as claimed, as taught/suggested by Zhou. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to blockchain based identify verification. One of ordinary skill in the art would have recognized that applying the known technique of Zhou would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Zhou to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such channel features into similar systems. Further, applying various channel options would have been recognized by those of ordinary skill in the art as resulting in an improved system that would improve routing and user experience. Regarding claim 17, Kravitz discloses a web interface (¶ 29, 40, 55, 62, 84, 134) but does not disclose the other channels as claimed. However, Zhou discloses wherein receiving the request further includes identifying the first channel as one of: a voice channel, a text messaging channel, a web-based channel, an application-based channel, or an in-person channel (¶ 71, discloses in person channels). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform the various channels as claimed, as taught/suggested by Zhou. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to blockchain based identify verification. One of ordinary skill in the art would have recognized that applying the known technique of Zhou would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Zhou to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such channel features into similar systems. Further, applying various channel options would have been recognized by those of ordinary skill in the art as resulting in an improved system that would improve routing and user experience. Claim(s) 4, is/are rejected under 35 U.S.C. 103 as being unpatentable over Kravitz et al. (US 20220385477 A1) in view of Pohjola et al. (US 20230075539 A1)m in further view of Dimmick et al. (US 20200090182 A1). Regarding claim 4, the combination of Kravitz and Pohjola discloses obtaining a DID but does not disclose the use of a phone number as claimed. However, Dimmick discloses identifying the detail as a phone number and searching accounts on the phone number to obtain the account record (¶ 42, disclose a card on file linked to a mobile phone number and a database. ¶ 60, disclose translating a mobile phone number to payment card account details. ¶ 46, 48, 80, 99, 177). It would have been obvious to one of ordinary skill in the art at the time of filing to modify Kravitz to include/perform identifying the detail as a phone number and searching accounts on the phone number to obtain the account record as claimed, as taught/suggested by Dimmick. This known technique is applicable to the system of Kravitz as they both share characteristics and capabilities, namely, they are directed to secure authentication systems for communications about a customer. One of ordinary skill in the art would have recognized that applying the known technique of Dimmick would have yielded predictable results and resulted in an improved system. It would have been recognized that applying the technique of Dimmick to the teachings of Kravitz would have yielded predictable results because the level of ordinary skill in the art demonstrated by the references applied shows the ability to incorporate such channel features into similar systems. Further, applying various channel options would have been recognized by those of ordinary skill in the art as resulting in an improved system that would allow for an additional way to look up an account. Other pertinent prior art includes Bernardi (US 11914684 B2) which discloses private blockchain and secure group node segmentation for sensitive data. Ryan et al. (US 20210366586 A1) discloses data that is generated at a point of sale (POS) and/or retail store server and the data is stored, at least in part, on a blockchain database or other secure database. Vigier et al. (US 20130110678 A1) discloses purchasing of a product in a store using a mobile device. Murdoch et al. (US 20200336483 A1) discloses a DID owner controlling a DID that represents an identity of a DID owner. Lougheed et al. (US 20200220726 A1) which discloses recurring presentation of a credential includes sending a credential presentation subscription request from a subscriber to a holder. Toth (US 20190097812 A1) which discloses user authentication, cryptographic methods, and hashing, with identity specification, virtualization, proofing, and attestation. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMIE H AUSTIN whose telephone number is (571)272-7363. The examiner can normally be reached Monday, Tuesday, Thursday, Friday 7am-2pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Brian Epstein can be reached at (571) 270 5389. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. JAMIE H. AUSTIN Examiner Art Unit 3625 /JAMIE H AUSTIN/Primary Examiner, Art Unit 3625
Read full office action

Prosecution Timeline

Jun 02, 2025
Application Filed
Sep 02, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12567079
MACHINE-LEARNING (ML)-BASED SYSTEM AND METHOD FOR GENERATING DSO IMPACT SCORE FOR FINANCIAL TRANSACTION
2y 10m to grant Granted Mar 03, 2026
Patent 12511601
SYSTEMS AND METHODS FOR PROVIDING A MARKETPLACE FOR ACCESSORIES OF A BUSINESS AUTOMATION SYSTEM
4y 6m to grant Granted Dec 30, 2025
Patent 12475474
SYSTEMS AND METHODS FOR DETERMINING AND ANALYZING CHARACTERISTICS OF DEVICES USED IN PAYMENT TRANSACTIONS
5y 3m to grant Granted Nov 18, 2025
Patent 12462266
METHODS AND SYSTEMS FOR EVALUATING CONTENT
3y 10m to grant Granted Nov 04, 2025
Patent 12444009
SYSTEMS AND METHODS FOR GENERATING AND TRAINING A MODULE SELECTION ENGINE FOR DISTRIBUTION ALLOCATION IN A NETWORK ENVIRONMENT
3y 1m to grant Granted Oct 14, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
25%
Grant Probability
58%
With Interview (+33.2%)
4y 11m (~3y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 424 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month