Prosecution Insights
Last updated: September 17, 2026
Application No. 18/179,964

Systems and Methods for Non-Custodial Key Storage and Digital Signatures

Non-Final OA §102§103
Filed
Mar 07, 2023
Examiner
GRIJALVA LOBOS, BORIS D
Art Unit
2400
Tech Center
2400 — Computer Networks
Assignee
Realio Technology Ltd.
OA Round
2 (Non-Final)
82%
Grant Probability
Favorable
2-3
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
328 granted / 399 resolved
+24.2% vs TC avg
Strong +19% interview lift
Without
With
+18.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
26 currently pending
Career history
417
Total Applications
across all art units

Statute-Specific Performance

§101
12.0%
-28.0% vs TC avg
§103
41.1%
+1.1% vs TC avg
§102
16.0%
-24.0% vs TC avg
§112
20.6%
-19.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 399 resolved cases

Office Action

§102 §103
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office action is in response to communications filed on 11/27/2025. Claims 1-12 and 29-36 are pending. Claims 13-28 have been cancelled. DETAILED ACTION Response to Arguments Applicant’s arguments, filed on 11/27/2025, with respect to the rejection(s) of claim(s) 1 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Enrico et al. (US 20200382308 A1). Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claim(s) 1-2, 4, 6-7, 9-12, 29, 31, 33-34, and 36 is/are rejected under 35 U.S.C. 102(A)(1) as being anticipated by Enrico et al. (US 20200382308 A1, hereinafter Enrico). Regarding claim 1, Enrico discloses a method for non-custodial cryptographic key storage (abstract, "method"), comprising: receiving, by a first computing device via an input device, an identifier of a user (¶[0015], "capture a plurality of images by means of an image sensor comprised in said apparatus, generate a sensor fingerprint on the basis of said plurality of images"; ¶[0016], "in order to decrypt said encrypted private key it is necessary to possess the fingerprint of the image sensor that, in order to be determined needs to have access to the user terminal with sufficient access rights to use the image sensor of said user apparatus" - note the images act as an identifier because they are taken to "make it possible to authenticate said user apparatus 1 at said device 1" (see ¶[0043] and further ¶[0101], "authenticate a user apparatus 1 using few images [...] it makes it practically impossible to authenticate another user apparatus having a different image sensor")); generating, by the first computing device, a seed value (¶[0095], "a new random bit string (seed)" - generating inherent); enciphering, by the first computing device, the identifier of the user and the seed value to generate a cipher value (¶[0043], "a registration fingerprint calculation phase E2, in which a registration sensor fingerprint is generated, through the processing means 11 of the user apparatus 1, on the basis of said plurality of images captured during said phase E1, and where said at least a portion of said registration sensor fingerprint is encoded (compressed), through the processing and control means of the user apparatus 1, using an algorithm of random projections, in such a way as to generate a compressed fingerprint W of said at least a portion of said registration sensor fingerprint"; ¶[0090], "user apparatus 1 can be configured to calculate a compressed version of each of the sensor fingerprints calculated by it through random projections, in other words through a multiplication (matrix product) between a compression matrix and a matrix that represents said sensor fingerprint (or vice-versa)"; ¶[0094], "the security of the system can be further increased by the method for generating random projections since it is based on the use of a pseudo-random number generator that is initialized by a seed kept secret on the device of the user"; ¶[0095], " it is advantageously possible to use a compressed fingerprint generated with a new random bit string (seed)"); retrieving, by the first computing device, a private key of a cryptographic key pair (¶[0046], "a key preparation phase E3, in which a copy of keys, i.e., a public key and a private key, is generated […] the private key is encrypted" (i.e., provided as an input after generation)); encrypting, by the first computing device, the private key with the cipher value (¶[0046], "a key preparation phase E3, in which a copy of keys, i.e., a public key and a private key, is generated and the public key is transmitted to the application server 2, whereas the private key is encrypted, preferably through a symmetrical cryptography algorithm, using said compressed fingerprint W as a key, so as to generate an encrypted private key "); and storing, by the first computing device, the encrypted private key and the seed value in association with a public key of the cryptographic key pair (¶[0094], "seed kept secret on the device of the user"; ¶[0046], "generate an encrypted private key (also called ‘sketch’) that is stored in the memory means 12,13"; ¶[0034], "FIG. 2, the user apparatus […] comprises the following components:"; ¶[0036], "volatile memory means 12"; ¶[0037], "mass memory means 13"). Regarding claim 2, Enrico discloses the method of claim 1, wherein the identifier of the user comprises a user-generated key (¶[0015], "capture a plurality of images by means of an image sensor comprised in said apparatus, generate a sensor fingerprint on the basis of said plurality of images"; ¶[0016], "in order to decrypt said encrypted private key it is necessary to possess the fingerprint of the image sensor that, in order to be determined needs to have access to the user terminal with sufficient access rights to use the image sensor of said user apparatus" - note the images act as an identifier because they are taken to "make it possible to authenticate said user apparatus 1 at said device 1" (see ¶[0043] and further ¶[0101], "authenticate a user apparatus 1 using few images [...] it makes it practically impossible to authenticate another user apparatus having a different image sensor" i.e., essentially a key)). Regarding claim 4, Enrico discloses the method of claim 1, wherein the seed value comprises a random number or a pseudo-random number (¶[0095], "it is advantageously possible to use a compressed fingerprint generated with a new random bit string (seed)"). Regarding claim 6, Enrico discloses the method of claim 1, wherein retrieving the private key further comprises generating, by the first computing device, the cryptographic key pair (¶[0046], "a key preparation phase E3, in which a copy of keys, i.e., a public key and a private key, is generated"). Regarding claim 7, Enrico discloses the method of claim 1, wherein storing the encrypted private key and the seed value further comprises storing the encrypted private key in a first database in association with the public key (¶[0046], "encrypted private key (also called ‘sketch’) that is stored in the memory means", wherein the private key is a counterpart of the public key), and storing the seed value in a second database in association with the public key (¶[0094], "seed kept secret on the device of the user"). Regarding claim 9, Enrico discloses the method of claim 1, further comprising discarding the private key after encrypting the private key with the cipher value (¶[0017], encrypting the private key; ¶[0018], the keys are stored in the user device but can only be used if the fingerprint is available, suggesting the plaintext key is not stored in the apparatus, but since the private key was used to generate the encrypted key at the user device (see Fig. 3), the plain text private key was at some point stored at least in transient memory of the user device, thus it was discarded - see also ¶[0051], recovering the private key from the encrypted key in order to use it, further suggesting the plaintext key is no longer in the user device after encryption). Regarding claim 10, Enrico discloses the method of claim 1, wherein the private key is not stored (¶[0017], encrypting the private key; ¶[0018], the keys are stored in the user device but can only be used if the fingerprint is available, suggesting the plaintext key is not stored in the apparatus, but since the private key was used to generate the encrypted key at the user device (see Fig. 3), the plain text private key was at some point stored at least in transient memory of the user device, thus it was discarded - see also ¶[0051], recovering the private key from the encrypted key in order to use it, further suggesting the plaintext key is no longer in the user device after encryption). Regarding claim 11, Enrico discloses the method of claim 1, wherein the identifier of the user is not stored (¶[0048]-[0050], the fingerprint must be generated again, by the user device, by taking images using the camera in order to decrypt the private key, suggesting the previous images are not available at the user device - see also ¶[0016], "it is necessary to possess the fingerprint of the image sensor that, in order to be determined needs to have access to the user terminal with sufficient access rights to use the image sensor of said user apparatus", if previous images were available it would not be "necessary" to use the image sensor). Regarding claims 12, 29, 31, 33-34, and 36, Enrico discloses a system for non-custodial cryptographic key storage, comprising: a first computing device comprising an input device and a processor (). The remaining limitations of claims 12, 29, 31, 33-34, and 36 are similar in scope to those of claims 1-2, 4, 6-7, and 9. Therefore, claims 12, 29, 31, 33-34, and 36 are rejected for the same reasons as set forth in the rejection of claims 1-2, 4, 6-7, and 9, above. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 3 and 30 is/are rejected under 35 U.S.C. 103 as being unpatentable over Enrico (US 20200382308 A1) in view of ZHOU et al. (CN 110855429 A, hereinafter ZHOU). Regarding claim 3, Enrico discloses the method of claim 1. Enrico does not disclose that the identifier of the user comprises a passphrase. ZHOU discloses that an identifier of a user may comprise a passphrase (page 1, under summary of invention, "When the application software needs to generate a key, first a user is required to input a user password, and the password is remembered, a key seed is generated by using the password and the salt by means of a PBKDF 2 algorithm, a value of the salt is a fixed word "mnemonic", and then a HASH algorithm is used to generate a user key (USERKEY) by using a seed; at this time, a dense user key or a plaintext key is generated; after being encrypted later, the plaintext key needs to be deleted; and the encryption key method is generated by means of the user password, so that the key can be recovered after the key is lost"). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Enrico and ZHOU to arrive at a system in which the identifier of the user comprises a passphrase. One of ordinary skill in the art would have been motivated because it would enhance the system by enabling other identifiers to be used instead of images when a device is not capable of using images, as deciding what to use as identifier is a design choice. Regarding claim 30, Enrico discloses the system of claim 12. The remaining limitations of claim 30 are similar in scope to those of claim 3. Therefore, claim 30 is rejected for the same reasons as set forth in the rejection of claim 3, above. Claim(s) 5 and 32 is/are rejected under 35 U.S.C. 103 as being unpatentable over Enrico (US 20200382308 A1) in view of Agrawal et al. (US 8831228 B1, hereinafter Agrawal). Regarding claim 5, Enrico discloses the method of claim 1. Enrico does not disclose that enciphering the identifier of the user and the seed value further comprises concatenating the first identifier and the seed value. Agrawal discloses that enciphering an identifier of a user and a seed value comprises concatenating a first identifier and the seed value (col. 1, lines 53-54, "an encrypted content encryption key that is encrypted with a packaging key"; col. 12, lines 56-58, "an identifier (e.g., a unique identifier) to each of client systems 600. Such an identifier may be referred to herein as a packaging entity identifier (PEID)"; col. 13, lines 13-22, "a given client system's packaging key may be generated from both the PEID of that client system and a secret root seed 684 […] the key generator may perform an HMAC-SHA1 on the concatenation of the secret root seed and the client system's PEID"). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Enrico and Agrawal to arrive at a system in which enciphering the identifier of the user and the seed value further comprises concatenating the first identifier and the seed value. One of ordinary skill in the art would have been motivated because it would enhance the system by enabling other unique identifiers to be used instead of images when a device is not capable of using images, as deciding what to use as identifier is a design choice. Regarding claim 32, Enrico discloses the system of claim 12. The remaining limitations of claim 32 are similar in scope to those of claim 5. Therefore, claim 32 is rejected for the same reasons as set forth in the rejection of claim 5, above. Claim(s) 8 and 35 is/are rejected under 35 U.S.C. 103 as being unpatentable over Enrico (US 20200382308 A1) in view of Fontaine (US 12483397 B1). Regarding claim 8, Enrico discloses the method of claim 7. Enrico does not disclose that at least one of the first database and the second database is managed by a second computing device; and wherein storing the encrypted private key and the seed value further comprises transmitting at least one of the encrypted private key and the seed value to the second computing device for storage. Fontaine discloses at least one of the first database and the second database is managed by a second computing device (col. 15, lines 6-14, "backup can be implemented as follows in accordance with one embodiment. Upon creation of a new Household Private/Public Key Pair, the Household app creates a Household Private Key Recovery Secret Key (HPKRSKey). The Household app encrypts the Household Private Key with the HPKRSKey, and sends the Encrypted Household Private Key to the Household microservice for backup in the central service"); and wherein storing the encrypted private key and the seed value further comprises transmitting at least one of the encrypted private key and the seed value to the second computing device for storage (col. 15, lines 6-14, "backup can be implemented as follows in accordance with one embodiment. Upon creation of a new Household Private/Public Key Pair, the Household app creates a Household Private Key Recovery Secret Key (HPKRSKey). The Household app encrypts the Household Private Key with the HPKRSKey, and sends the Encrypted Household Private Key to the Household microservice for backup in the central service"). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Enrico and Fontaine to arrive at a system in which at least one of the first database and the second database is managed by a second computing device; and wherein storing the encrypted private key and the seed value further comprises transmitting at least one of the encrypted private key and the seed value to the second computing device for storage. One of ordinary skill in the art would have been motivated because it would provide backup means for the private key. Regarding claim 35, Enrico discloses the system of claim 34. The remaining limitations of claim 35 are similar in scope to those of claim 8. Therefore, claim 35 is rejected for the same reasons as set forth in the rejection of claim 8, above. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 10554401 B1, which discloses "generates private key information (or seeds for private keys) and another, geographically independent, team (e.g., at a second facility) that generates encryption key information (or passphrases) for encrypting private keys" (col. 45, lines 44-48). Any inquiry concerning this communication or earlier communications from the examiner should be directed to BORIS D GRIJALVA LOBOS whose telephone number is (571)272-0767. The examiner can normally be reached M-F 10:30AM to 6:30PM EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L Ortiz-Criado can be reached at 571-272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BORIS D GRIJALVA LOBOS/ Primary Patent Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Mar 07, 2023
Application Filed
Aug 28, 2025
Non-Final Rejection mailed — §102, §103
Nov 27, 2025
Response Filed
Sep 11, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12695955
COMMENT MANAGEMENT METHOD AND SYSTEM FOR DISPLAYING COMMENTS
2y 1m to grant Granted Jul 28, 2026
Patent 12657338
SYSTEMS AND METHODS TO MANAGE DATA SETS WHILE MAINTAINING DATA SET ISOLATION AND INTEGRITY
2y 0m to grant Granted Jun 16, 2026
Patent 12652273
ENCRYPTING DATA GENERATED FROM MEDICAL DEVICES
2y 1m to grant Granted Jun 09, 2026
Patent 12647415
Gesture-Based User Authentication
2y 1m to grant Granted Jun 02, 2026
Patent 12645781
AUTHENTICATION OF MEMORY EXPANSION CAPABILITIES
1y 10m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
82%
Grant Probability
99%
With Interview (+18.6%)
2y 4m (~0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 399 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month