Prosecution Insights
Last updated: October 04, 2026
Application No. 18/361,643

SYSTEM AND METHOD FOR GENERATING A CRYPTOGRAPHIC KEY

Non-Final OA §103§112
Filed
Jul 28, 2023
Priority
Nov 13, 2014 — provisional 62/079,031 +3 more
Examiner
GRACIA, GARY S
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Chol Inc.
OA Round
5 (Non-Final)
72%
Grant Probability
Favorable
5-6
OA Rounds
2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
408 granted / 571 resolved
+13.5% vs TC avg
Strong +48% interview lift
Without
With
+48.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
24 currently pending
Career history
590
Total Applications
across all art units

Statute-Specific Performance

§101
11.9%
-28.1% vs TC avg
§103
65.8%
+25.8% vs TC avg
§102
11.2%
-28.8% vs TC avg
§112
5.8%
-34.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 571 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 2. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04/24/2026 has been entered. Response to Arguments 3. Applicant’s arguments filed on 04/24/2026, with respect to the rejection(s) of claim(s) Claim 2, 4, 5, 7-12, 14-17 and 19- 21 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Publication No. 20130268775 hereinafter Hawkins and further in view of U.S. Publication No. 20140372754 hereinafter Aissi, and further in view of U.S. Publication No. 20140201644 hereinafter Williams, and further in view of U.S. Publication No. 20040010721 hereinafter Kirovski have been fully considered but are not are persuasive. Examiner admits that not rejecting claim 22 in err without malicious intent. However, after further review, the language of claim 22 does not seem to be obvious over the cited rejection. Applicant’s specification on paragraph 0068 and 0074 both discloses “FIG. 3C shows the image resource of FIG. 3B presented in selectable segments with the same quantity of data in each segment. Each segment of the map can represent any amount of raw data.” The Applicant’s specification only states quantity two times and the specification fails to states “ wherein each of the plurality of selectable segments include a same quantity of raw data. The independent claims contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. There is not discussion as to how the selectable segments include the same quantity of raw data but merely the selectable segments include the quantity of data and the raw data can represent any amount of data. Application does not make any reference to the drawings 1-6c. Therefore, the specification is not enabling and consequently raises doubt as to enablement of the invention due to the essential component(s) or step(s) of the invention not being recited in the claims. For the reasons above, the rejection is maintained. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. 4. Claims 2 and 12 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Applicant’s specification on paragraph 0068 and 0074 both discloses “FIG. 3C shows the image resource of FIG. 3B presented in selectable segments with the same quantity of data in each segment. Each segment of the map can represent any amount of raw data.” The Applicant’s specification only states quantity two times and the specification fails to states “ wherein each of the plurality of selectable segments include a same quantity of raw data. The independent claims contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. There is not discussion as to how the selectable segments include the same quantity of raw data but merely the selectable segments include the quantity of data and the raw data can represent any amount of data. Application does not make any reference to the drawings 1-6c. Therefore, the specification is not enabling and consequently raises doubt as to enablement of the invention due to the essential component(s) or step(s) of the invention not being recited in the claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 5. Claim 2, 4, 5, 7-12, 14-17 and 19- 21 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Publication No. 20130268775 hereinafter Hawkins and further in view of U.S. Publication No. 20140372754 hereinafter Aissi, and further in view of U.S. Publication No. 20140201644 hereinafter Williams. As per claim 1, Hawkins discloses: A computer-implemented method for generating a cryptographic key for encrypting data (para 0032 "In some embodiments, the method comprises using the security code to generate an encryption key that may be used to decrypt stored data to be displayed on said display or on a further, different, display."), comprising: under control of a computing system comprising one or more computing devices configured to execute specific instructions, receiving, via a user interface, selection of one or more data resources from a plurality of data resources (Fig. 3, para 0085 "At step S300, the computing device 100 receives user input to select one or more images. The computing device 100 then displays the selected images on the display 116 at step S302. The image or images may occupy the whole of the display 116, or may only occupy a portion of the display 116. In some embodiments, the image or images may be displayed in a window environment that the user may be able to move within the display. In some embodiments, several images may be displayed in a timed sequence, or in a video sequence that appears to the user as a continuously moving scene.") wherein a single image of the gallery of images is presented with a grid overlay that segments the single image into a plurality of selectable segments (Fig. 4, para 0109 “FIG. 4 also shows an exemplary user input pattern that the user has entered over the displayed image to select points within the image. These include three individual points 410, 420, 430, defined by selecting non-adjacent imaging elements, and four straight lines which form a four sided polygon 440, which defines the perimeter of an area. The straight lines, and therefore the polygon 440, are formed by selecting a continuous sequence of mutually adjacent individual elements.”) extracting raw data from a plurality of segments selected from at least the plurality of selectable segments (Figs. 4 and 5, Para 0094 “At step S308, the security application 140 determines values derived from display parameters associated with the defined set of locations defined at step S306. The display parameters may include color or intensity values or other display values associated with the display state of a given imaging element. The display parameters may be derived from values defined in the imaging or video file for the pixel or pixels that the imaging element or elements at that location are responsible for displaying. The values may be derived by transforming the display parameters, or performing a mathematical operation on the display parameters, or the display parameters could be used directly as the determined values. By determining values derived from the display parameters, the security application 140 has access to a large amount of raw data from which to generate a security code. Further, since display parameter values, such as color values, typically exhibit a high degree of variation across an image, security codes generated based on these values have a high degree of entropy.”) wherein each of the plurality of selectable segments include a same quantity of raw data (para 0019 “In some embodiments, the user input comprises user input to select locations at the perimeter of said area. The user input may comprise user input to select a continuous sequence of points enclosing said area. This enables relatively large amounts of raw data to be available for generating a security code even when the user input is relatively simple.” Para 0094 “At step S308, the security application 140 determines values derived from display parameters associated with the defined set of locations defined at step S306. The display parameters may include color or intensity values or other display values associated with the display state of a given imaging element. The display parameters may be derived from values defined in the imaging or video file for the pixel or pixels that the imaging element or elements at that location are responsible for displaying. The values may be derived by transforming the display parameters, or performing a mathematical operation on the display parameters, or the display parameters could be used directly as the determined values. By determining values derived from the display parameters, the security application 140 has access to a large amount of raw data from which to generate a security code. Further, since display parameter values, such as color values, typically exhibit a high degree of variation across an image, security codes generated based on these values have a high degree of entropy.”) and creating a cryptographic key (para 0094 "By determining values derived from the display parameters, the security application 140 has access to a large amount of raw data from which to generate a security code. Further, since display parameter values, such as color values, typically exhibit a high degree of variation across an image, security codes generated based on these values have a high degree of entropy." Para 0095 "Finally, at step S310, the computing device generates a security code based on the defined set of locations. The generation of the security code is described in greater detail below. The security code maybe used by the security application 140 to generate an encryption key, or may use directly as an encryption key.") Hawkin does not disclose: wherein one or more data resources are presented as a gallery of images; wherein the raw data is data stored within a computer- readable memory prior to generation of images of the gallery of images modifying the raw data extracted from the plurality of segments to generate a plurality a modified data segments storing the plurality of modified data segments in a storage sequence corresponding to a selection sequence in which the plurality of segments are selected by a user and creating a cryptographic key the plurality of modified data segments for use in encrypting plaintext data using the cryptographic key, and storing the cryptographic key in a computer- readable memory Aissi discloses: wherein one or more data resources are presented as a gallery of images (Fig. 6, para 0021 "In some embodiments, a user may select a subset of images from a plurality of images presented to the user. The user's selection of authentication images may be used to generate an image-based derived key using an image-based key derivation function." Para 0051 " At step 401, server computer 104 provides a plurality of authentication images to client computer 102. The plurality of authentication images may be selected by server computer 104 using image selection module 105(E), and may comprise any suitable set of images (e.g., a set of images stored in image database 105). In some embodiments, user 101 may select a category or theme for the set of images, such as bodies of water, United States presidents, etc. In other embodiments, the images may be randomly selected from all images maintained by server computer 104."); modifying the raw data extracted from the plurality of segments to generate a plurality a modified data segments (para 0060 "In some cases, a hash or other function may be applied to an image, and the resulting value may be used as an input to the IBKDF. In some cases, the some or all of the image data (e.g., pixel properties of some or all of the pixels in the image) of the image itself may be used as input to the IBKD." para 0065 "For the selection shown in grid 600, in one embodiment, the soccer player image may be numbered 523, the basketball player may be numbered 135, and the house may be numbered 878. Thus, an image value of 523135878 may be used as an input to the IBKDF.") storing the plurality of modified data segments in a storage sequence corresponding to a selection sequence in which the plurality of segments are selected by a user (Para 0061 "At step 406, server computer 104 stores the image-based derived key in user database 106. Typically, the image- based derived key is associated with an entry in user database 106 corresponding to user 101. In addition, in some embodiments, hashes and/or image identifiers corresponding to the selected authentication images may also be stored in user database 106.") and creating a cryptographic key the plurality of modified data segments for use in encrypting plaintext data using the cryptographic key, and storing the cryptographic key in a computer- readable memory (para 0021 "The image- based derived key may be used by a client computer to encrypt data sent toa server, or decrypt data received from the server. In addition, the image- based derived key may be used by a server computer to encrypt data sent to the user, or decrypt data received from the user. Furthermore, an image- based derived key may be used to authenticate the user by comparing the key to a previous key stored for the user." Para 0061 "At step 406, server computer 104 stores the image-based derived key in user database 106. Typically, the image- based derived key is associated with an entry in user database 106 corresponding to user 101. In addition, in some embodiments, hashes and/or image identifiers corresponding to the selected authentication images may also be stored in user database 106."), Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method comprises using the security code to generate an encryption key of Hawkins to include wherein one or more data resources are presented as a gallery of images, extracting raw data from a plurality of segments selected from the one or more data resources, wherein the raw data is data stored within a computer- readable memory prior to generation of images of the gallery of images and modifying the raw data extracted from the plurality of segments to generate a plurality a modified data segments, as taught by Aissi. The motivation would have been to generate, store and using an image- based derived key based on raw data. Hawkins in view of Aissi does not disclose: wherein raw data is data stored within a computer-readable memory prior to generation of images of the gallery of images Williams discloses: wherein raw data is data stored within a computer-readable memory prior to generation of images of the gallery of images (para 0026-0030 "[0026] According to a further aspect of the invention there is provided an apparatus for producing a result digital image from a selection of a plurality of digital images, the apparatus comprising: [0027] a remote computing device having an image management module; the remote computing device being capable to a data network; wherein the image management module accesses a plurality of original (or raw) digital images and generates a respective plurality of preview digital images; [0028] a remote database server for storing the respective preview digital image; the plurality of preview digital images being associated with a job record; [0029] a remote user interface server for presenting a user interface indicative of a job record and enabling viewing of the plurality of preview digital images; [0030] wherein the user interface enables selection of one or more preview digital images, which causes only the respective one or more original (or raw) digital images to be transferred from the remote computing device for access by a photo editing studio.") Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the method comprises using the security code to generate an encryption key of Hawkins in view of Aissi to include wherein one or more data resources are presented as a gallery of images and wherein raw data is data stored within a computer- readable memory prior to generation of images of the gallery of images, as taught by Williams. The motivation would have been to generate and store raw data for selection in order to create a secure method of image selection. As per claim 4, Hawkins in view of Aissi and Williams discloses: The computer-implemented method of claim 3, wherein the raw data extracted from the plurality of segments is modified by encrypting the raw data. (Hawkins para 0032, 0080, and 0081) and (Aissi para 0060). As per claim 5, Hawkins in view of Aissi and Williams discloses: The computer-implemented method of claim 4, wherein the cryptographic key is stored in the computer-readable memory after encrypting the cryptographic key (Hawkins para 0032 and 0082). As per claim 7, Hawkins in view of Aissi and Williams discloses: The computer-implemented method of claim 2, wherein a total number of images in the gallery of images is selected by a user (Williams para 0026-0030, The motivation would have been to generate and store raw data for selection in order to create a secure method of image selection). As per claim 8, Hawkins in view of Aissi and Williams discloses: The computer-implemented method of claim 2, wherein the raw data is data stored within the computer-readable memory prior to generation of the single image (Williams para 0026-0030, The motivation would have been to generate and store raw data for selection in order to create a secure method of image selection). As per claim 9, Hawkins in view of Aissi and Williams discloses: The computer-implemented method of claim 8, wherein a total number of grids and dimensions of each grid in the single image is determined by a user (Hawkins Fig. 5, para 0116 "FIG. 5 show one embodiment in which the relatively higher resolution displayed image 400 is divided into a relatively lower resolution array 500 or grid of selectable elements. The relatively lower array 500 of selectable elements is not visible to the user but the security application 140 uses this array 500 of elements when defining the set of locations. By displaying the relatively higher resolution image 400, rather than the relatively lower resolution array 500, the number of possible locations available to an unauthorized user appears to be much greater, making it more difficult for the unauthorized user to guess which features in the image to select.") As per claim 10, Hawkins in view of Aissi and Williams discloses: The computer-implemented method of claim 9, wherein a data resource of the one or more data resources is presented as the single image (Hawkins Fig. 5, para 0116 "FIG. 5 show one embodiment in which the relatively higher resolution displayed image 400 is divided into a relatively lower resolution array 500 or grid of selectable elements. The relatively lower array 500 of selectable elements is not visible to the user but the security application 140 uses this array 500 of elements when defining the set of locations. By displaying the relatively higher resolution image 400, rather than the relatively lower resolution array 500, the number of possible locations available to an unauthorized user appears to be much greater, making it more difficult for the unauthorized user to guess which features in the image to select."). As per claim 11, Hawkins in view of Aissi and Williams discloses: The computer-implemented method of claim 2, wherein a data resource of the one or more data resources is presented as a video clip divisible into multiple segments each being a plurality of video frames (Hawkins para 0070). As per claim 12, the implementation of the computer-implemented method of claims 1 and 8 will execute the system of claim 12. The claim is analyzed with respect to claim 1. As per claim 14, the claim is analyzed with respect to claim 4. As per claim 15, the claim is analyzed with respect to claim 5. As per claim 16, Hawkins in view of Aissi and Williams discloses: The system of claim 12, wherein the one or more data resources are presented as a gallery of images and the raw data is data stored within the computer- readable memory prior to generation of the images associated with the gallery of images (Williams para 0026-0030, The motivation would have been to generate and store raw data for selection in order to create a secure method of image selection). As per claim 17, the claim is analyzed with respect to claim 7. As per claim 19, the claim is analyzed with respect to claim 9. As per claim 20, the claim is analyzed with respect to claim 10. As per claim 21, the claim is analyzed with respect to claim 11. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to GARY S GRACIA whose telephone number is (571)270-5192. The examiner can normally be reached Monday-Friday 9am-6pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GARY S GRACIA/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Show 4 earlier events
Feb 18, 2025
Request for Continued Examination
Feb 20, 2025
Response after Non-Final Action
Mar 25, 2025
Non-Final Rejection mailed — §103, §112
Sep 18, 2025
Response Filed
Oct 28, 2025
Final Rejection mailed — §103, §112
Apr 24, 2026
Request for Continued Examination
May 01, 2026
Response after Non-Final Action
May 12, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750243
SYSTEMS AND METHODS FOR PRESERVING PRIVACY OF A REGISTRANT IN A DOMAIN NAME SYSTEM ("DNS")
3y 3m to grant Granted Sep 29, 2026
Patent 12748873
SYSTEMS AND METHODS FOR DATA CLASSIFICATION AND GOVERNANCE
3y 5m to grant Granted Sep 29, 2026
Patent 12743501
DEVICE, METHOD, AND SYSTEM TO DETERMINE AN ACCESS TO A TRUSTED EXECUTION ENVIRONMENT
3y 9m to grant Granted Sep 22, 2026
Patent 12737487
METHOD FOR MANAGING ACCESS TO A FILE FOR NON-VOLATILE MEMORY
1y 6m to grant Granted Sep 15, 2026
Patent 12730915
SYSTEM AND METHOD FOR AUTHENTICATION USING TOKENIZATION OF A RESOURCE PRIOR TO RESOURCE ALLOCATION
3y 3m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
72%
Grant Probability
99%
With Interview (+48.0%)
3y 4m (~2m remaining)
Median Time to Grant
High
PTA Risk
Based on 571 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month