Prosecution Insights
Last updated: October 02, 2026
Application No. 18/854,924

STATEFUL SIGNATURES

Non-Final OA §101§102§103
Filed
Oct 07, 2024
Priority
Apr 28, 2022 — nonprovisional of PCTUS2022071976
Examiner
LIN, AMIE CHINYU
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Hewlett-Packard Development Company, L.P.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
260 granted / 308 resolved
+26.4% vs TC avg
Strong +31% interview lift
Without
With
+30.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
12 currently pending
Career history
319
Total Applications
across all art units

Statute-Specific Performance

§101
14.8%
-25.2% vs TC avg
§103
46.8%
+6.8% vs TC avg
§102
15.3%
-24.7% vs TC avg
§112
17.9%
-22.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 308 resolved cases

Office Action

§101 §102 §103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Applicant's election, without traverse, Group I encompassed by claims 1-5 in the reply filed on 08/21/2026 is acknowledged. Claims 6-15 have been canceled. New claims 16-25 have been added. Claims 1-5, and 16-25 are pending. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-5, and 16-25 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claim 1 recites the step of identifying a partition in a state space of a stateful signature scheme for implementation by a cryptoprocessor. The limitation, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting a processor performing the step, nothing in the claim element precludes the step from practically being performed in the mind. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the Mental Processes grouping of abstract ideas. Accordingly, the claim recites an abstract idea. This judicial exception is not integrated into a practical application. In particular, the additional element of providing, to the cryptoprocessor, an indication of the partition is merely an insignificant extra-solution activity, e.g., pre or post solution activities. In addition, the claim recites the additional element of the processor performing the steps. This additional element is recited at a high level of generality such that it amounts to no more than mere instructions to apply the exception using a generic computer component. Accordingly, the combination of the above additional elements does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of the processor amounts to no more than mere instructions to apply the exception using a generic computer component; mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. In addition, the addition element of providing to the cryptoprocessor an indication of the partition is an insignificant extra-solution activity that cannot provide an inventive concept. The claim is not patent eligible. Dependent claims 2-5 further clarify the concept recited in claim 1 that is directed to an abstract idea. However, these clarifications still fall under the concept recited in claim 1 that is directed to an abstract idea and do not amount to significantly more than the judicial exception. The addition element of transmitting to the second computing device an indication of the second partition in claim 2 is an insignificant extra-solution and does not integrate the abstract idea into a practical application and cannot provide an inventive concept. Claim 16, although not using the exact claim language, contains similar elements as recited in claim 1 and is also rejected for similar reasons. Dependent claims 17-20 further clarify the concept recited in claim 16 that is directed to an abstract idea; however, the clarifications still fall under the concept recited in claim 16 that is directed to an abstract idea and do not amount to significantly more than the judicial exception. The additional element as explained above does not integrate the abstract idea into a practical application and cannot provide an inventive concept. Claim 21, although not using the exact claim language, contains similar elements as recited in claim 1 and is also rejected for similar reasons. Dependent claims 22-25 further clarify the concept recited in claim 21 that is directed to an abstract idea, but the clarifications still fall under the concept recited in claim 21 that is directed to an abstract idea and do not amount to significantly more than the judicial exception. The additional element as explained above does not integrate the abstract idea into a practical application and cannot provide an inventive concept. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1, 5, 16, 20-21, and 25 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Sastry et al. (US 2021/0306155). Claim 1, Sastry teaches: A computing device comprising: a processor to: identify a partition in a state space of a stateful signature scheme for implementation by a cryptoprocessor; and (e.g., [0057], “FIG. 7 is a schematic illustration of compute blocks in an architecture to implement robust state synchronization for stateful hash-based signatures…signing facility 700 may comprise a computer readable memory block (or register file) 710 which may be used to store signature operation inputs and intermediate results for the signature operations, a state synchronization manager 720, a load balancer 722, a plurality of hardware security modules 730A, 730B, . . . 730N, (collectively referred to herein by reference numeral 730) which are configured to compute signatures using a common XMSS key pair 740” [0060], “the state synchronization manager 720 may maintain a listing of the hardware security modules 730 in the signing facility that are operational and available to perform a digital signature process…one or more signature operations are received in the signing facility” [0061], “a set of hardware security modules 730 is selected to perform the digital signature operations received…In some examples the state synchronization manager 720 may selected a subset comprising two or more hardware security modules 730 from the plurality of hardware security modules that are operational and available to execute digital signature operations” [0066], “The state synchronization manager 722 retains a database of encrypted state in the memory 710. Only the HSMs can decrypt the state. When a signing operation is requested…selects an available HSM 730 and the state synchronization manager 720 retrieves the encrypted state from memory 710 based on the requested signing key and sends the encrypted state to the selected HSM”) provide, to the cryptoprocessor, an indication of the partition. (e.g., [0066], “The state synchronization manager 722 retains a database of encrypted state in the memory 710. Only the HSMs can decrypt the state. When a signing operation is requested…selects an available HSM 730 and the state synchronization manager 720 retrieves the encrypted state from memory 710 based on the requested signing key and sends the encrypted state to the selected HSM” [0067], “The HSM decrypts the state which includes the next available counter, signs the message, updates the counter and other state information, re-encrypts the state information and sends the signed message and updated and re-encrypted state back to the state synchronization manager 720. The manager 720 updates the state in the database in memory 710 and returns the signed message to the requestor” [0068], “Disaster recovery may be performed and only lose a single key…The synchronization manager 720 sends the encrypted state from the database in memory 710 to a working HSM 730C and commands the working HSM 730C to increment the state by one to recover from a lost signing operation. The commanded HSM 730C decrypts the state, increments the counter, re-encrypts the state and returns the re-encrypted state to the synchronization manager 720. The synchronization manager 720 updates the new state in the database in memory 710, and resubmits the lost signing request with the updated state to an available HSM. In this failure case only a single signing key is lost” [0069], “In other renditions, all HSMs 730 have a copy of a database for all keys in the NVM memory. All HSMs 730 can communicate to the synchronization manager 720 (as well as to each other). For example, HSM 730A can send messages and receive messages from HSM 730B and 730C. The synchronization manager 720 sends a signing request to an HSM (example e.g., HSM 730A) for a specific signing key (e.g., signing key #23) to perform signing. In response, the synchronization manager 720 marks HSM 730A as having a lock on signing key #23. HSM 730A sends a message to all other HSMs in the facility that it is going to be signing with signing key #23, and waits until all HSMs acknowledge this action. Each other HSM, when receiving the message from HSM 730A, marks singing key #23 as locked by HSM 730A, and sends a message to HSM 730A that they acknowledge and accept the lock request” [0070], “When HSM 730A receives a lock acknowledge from all other HSMs, it performs the signing operation, increments the counter for signing key #23 in its internal state”) Claim 5, Sastry teaches: wherein the indication comprises a rule executable by the cryptoprocessor to allow the cryptoprocessor to determine an unused private key for signing data, wherein the unused private key is derivable from a state of the partition (e.g., [0077]) Claim 16, this claim is directed to a method containing similar limitations as recited in claim 1 and is rejected for similar rationale. Claim 20, this claim is directed to a method containing similar limitations as recited in claim 5 and is rejected for similar rationale. Claim 21, this claim is directed to a non-transitory machine-readable medium containing similar limitations as recited in claim 1 and is rejected for similar rationale. Claim 25, this claim is directed to a non-transitory machine-readable medium containing similar limitations as recited in claim 5 and is rejected for similar rationale. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 2-3, 17-18, and 22-23 are rejected under 35 U.S.C. 103 as being unpatentable over Sastry et al. (US 2021/0306155) in view of Stapleton et al. (US 11,601,266). Claim 2, Sastry teaches identify a second partition in the state space for implementation by a second cryptoprocessor and transmit an indication of the second partition (e.g., [0066]-[0068]) and does not appear to explicitly teach but Stapleton teaches: a second cryptoprocessor of a second computing device; and transmit, to the second computing device, an indication. (e.g., col. 85 ll. 20-67) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Stapleton into the invention of Sastry, and the motivation for such an implementation would be for the purpose of securing communications between two devices (Stapleton col. 1 ll. 12-14). Claim 3, Sastry-Stapleton teaches: the state space is indicative of a set of one-time use private keys for signing data; the partition is associated with a first subset of the set; the second partition is associated with a second subset of the set; and the second subset is distinct from the first subset. (e.g., Sastry [0066]-[0067], [0069], [0077]) Claim 17, this claim is directed to a method containing similar limitations as recited in claim 2 and is rejected using the same rationale to combine the references. Claim 18, this claim is directed to a method containing similar limitations as recited in claim 3 and is rejected using the same rationale to combine the references. Claim 22, this claim is directed to a non-transitory machine-readable medium containing similar limitations as recited in claim 2 and is rejected using the same rationale to combine the references. Claim 23, this claim is directed to a non-transitory machine-readable medium containing similar limitations as recited in claim 3 and is rejected using the same rationale to combine the references. Claims 4, 19, and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Sastry et al. (US 2021/0306155) in view of Buonora (US 11,475,140). Claim 4, Sastry teaches wherein the cryptoprocessor comprises a hardware security module (HSM), and wherein the HSM is to protect keying material stored therein in response to detecting an unauthorized attempt to access the HSM (e.g., [0055], [0073]-[0074], [0076]) and does not appear to explicitly teach but Buonora teaches: destroy keying material stored therein in response to detecting an unauthorized attempt to access an HSM. (e.g., col. 8 ll. 23-36) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Buonora into the invention of Sastry, and the motivation for such an implementation would be for the purpose of ensuring the security of cryptographic material (Buonora col. 1 ll. 22-23). Claim 19, this claim is directed to a method containing similar limitations as recited in claim 4 and is rejected using the same rationale to combine the references. Claim 24, this claim is directed to a non-transitory machine-readable medium containing similar limitations as recited in claim 4 and is rejected using the same rationale to combine the references. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 12,388,653 teaches stateful hash-based signatures. Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIE C LIN whose telephone number is (571)272-7752. The examiner can normally be reached M-F 9:00AM -5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, GELAGAY SHEWAYE can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AMIE C. LIN/ Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Oct 07, 2024
Application Filed
Sep 09, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737504
Access Control System and a Data Storage Device
3y 1m to grant Granted Sep 15, 2026
Patent 12739135
METHOD FOR AUTHENTICATING DATA
1y 6m to grant Granted Sep 15, 2026
Patent 12725106
ENDPOINT WITH REMOTELY PROGRAMMABLE DATA RECORDER
2y 0m to grant Granted Sep 01, 2026
Patent 12699764
CERTIFICATE RESILIENCY VALIDATION USING CHAOS ENGINEERING
3y 4m to grant Granted Aug 04, 2026
Patent 12665894
SYSTEMS AND METHODS FOR AUTHENTICATION BROKERING
2y 9m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+30.9%)
2y 8m (~8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 308 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month