Prosecution Insights
Last updated: August 17, 2026
Application No. 18/905,205

SYSTEMS AND METHODS FOR DECRYPTING HYPERTEXT MARKUP LANGUAGE (HTML)

Final Rejection §102§103§112
Filed
Oct 03, 2024
Priority
Oct 04, 2023 — provisional 63/587,891 +2 more
Examiner
SAVENKOV, VADIM
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
Capital One Services LLC
OA Round
2 (Final)
61%
Grant Probability
Moderate
3-4
OA Rounds
1y 6m
Est. Remaining
82%
With Interview

Examiner Intelligence

Grants 61% of resolved cases
61%
Career Allowance Rate
193 granted / 316 resolved
+3.1% vs TC avg
Strong +21% interview lift
Without
With
+20.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
29 currently pending
Career history
371
Total Applications
across all art units

Statute-Specific Performance

§101
10.7%
-29.3% vs TC avg
§103
53.4%
+13.4% vs TC avg
§102
8.9%
-31.1% vs TC avg
§112
17.4%
-22.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 316 resolved cases

Office Action

§102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The 4/9/2026 IDS document has been considered by the examiner. Response to Amendment / Arguments Regarding claims objected to for minor informalities: Applicant’s amendment is considered to have overcome the applied objections. As such, they have been withdrawn. Regarding claims rejected under 35 USC 103: Applicant’s arguments, sin view of the amended claim language, have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Dorwin (US 8,891,765 B1). Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Independent claim 1 recites “wherein the encrypted HTML element has been determined to satisfy the at least one rule of the license,” which renders the claim indefinite because it is not clear whether the determination in “has been determined” is part of the claim scope. For instance, the determination may have taken place in the past tense before the claim scope, and by an entity outside of the claim scope. Independent claims 11 and 20 recite the same limitation, and are therefore rejected under the same analysis. The dependent claims do not rectify this issue, and are therefore likewise rejected with their respective independent claims. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claim(s) 1 and 11 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Dorwin (US 8,891,765 B1). Regarding claim 1, Dorwin discloses: A method for decrypting a HyperText Markup Language (HTML) (e.g., the background and Col. 7, Ll. 35-44 of Dorwin concerning HTML), the method comprising: obtaining, via a browser module associated with a first user device (e.g., Col. 7, Ll. 42-45 and Col. 12, Ll. 38-41 of Dorwin concerning a browser user agent), an encrypted HTML element (e.g., Col. 13, Ll. 5-10 and Col. 14, Ll. 60-Col. 15, Ll. 9 of Dorwin concerning an HTML media element); Refer to at least Col. 13, LL. 22-35 of Dorwin with respect to the browser obtaining encrypted HTML media associated with a media tag and instructing playback. generating, via the browser module a license request including a request to determine whether at least one rule of a license is satisfied; Refer to at least Col. 13, Ll. 36-43 and Col. 9, Ll. 39-53 of Dorwin with respect to requesting a license for the encrypted media. Refer to at least Col. 14, Ll. 60-Col. 15, Ll. 46 and Col. 16, Ll. 19-31 of Dorwin with respect to content control data. obtaining, via the browser module, the license for the encrypted HTML element, wherein the license includes a decryption key and the at least one rule, and wherein the encrypted HTML element has been determined to satisfy the at least one rule of the license; Refer to at least Col. 7, Ll. 49-53 and Col. 16, LL. 27-36 of Dorwin with respect to providing the license following successful authorization, where the license includes a decryption key. upon receiving an indication that the encrypted HTML element satisfies the at least one rule of the license, transmitting the encrypted HTML element and the license to a Content Decryption Model (CDM); and Refer to at least Col. 10, Ll. 15-34 and Col. 13, Ll. 44-55 of Dorwin with respect to the license and encrypted media being provided to a CDM following successful authorization. causing to output, via a first graphical user interface (GUI) associated with the first user device, a decrypted HTML element having been decrypted via the CDM based on the decryption key included with the license. Refer to at least the abstract, 798-799 in FIG. 7, Col. 13, LL. 55-Col. 14, Ll. 10, and Col. 3, Ll. 19-34 of Dorwin with respect to the CDM decrypting the encrypted media using the license key. The decrypted media is then rendered. Regarding independent claim 11, it is substantially similar to independent claim 1 above, and is therefore likewise rejected (i.e., the citations). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 2-3, 7, 12-13, 16, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Dorwin as applied to claims 1 and 11 above, and further in view of Loeb (US 2017/0249394 A1). Regarding claim 2, Dorwin does not disclose: receiving, via the browser module, a first user request to access an HTML element from a first user associated with the first user device; and based on the first user request, transmitting instructions via the browser module to an application server for: tagging the HTML element; and encrypting the tagged HTML element based on the at least one rule and session data to generate the encrypted HTML element. However, Dorwin in view of Loeb discloses: receiving, via the browser module, a first user request to access an HTML element from a first user associated with the first user device; and based on the first user request, transmitting instructions via the browser module to an application server for: tagging the HTML element; and encrypting the tagged HTML element based on the at least one rule and session data to generate the encrypted HTML element. Refer to at least the abstract, FIG. 3, [0091], [0098], [0109]-[0110], and [0127] of Loeb with respect to a primary user tagging HTML elements for privacy protection, including encryption. Refer to at least FIG. 2 and [0077] with respect to the service server. The teachings of Dorwin and Loeb both concern securing HTML content based on access rights, and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Dorwin to further implement scalable privacy protected web content as in Loeb for at least the purpose of allowing protected sharing between users who don’t fully trust each other (e.g., [0002] of Loeb). Regarding claim 3, Dorwin-Loeb discloses: The method of claim 2, wherein the session data includes hardware data associated with the first user device. Refer to at least [0063], [0076], and [0098] of Loeb with respect to data for privacy protection, including browser details and cookies. This claim would have been obvious for substantially the same reasons as claim 2 above (e.g., protected sharing without disclosing sensitive hardware information in cookies). Regarding claim 7, Dorwin-Loeb discloses: The method of claim 1, further comprising: obtaining a second user request from a second user associated with a second user device to decrypt the encrypted HTML element; obtaining permission from a first user associated with the first user device to decrypt the encrypted HTML element based on the second user request; and upon obtaining the permission from the first user, generating the license request. Refer to at least the abstract, FIG. 6, and [0115]-[0117] of Loeb with respect to a secondary user asking for permission to load the shared session with the protected HTML elements. This claim would have been obvious for substantially the same reasons as claim 2 above. Regarding claims 12-13 and 16, they are substantially similar to claims 2-3 and 7 above, and are therefore likewise rejected. Regarding independent claim 20, it is substantially similar to elements of independent claim 1 and claims 2-3 and 7 above. As such, it is therefore likewise rejected (i.e., the citations and obviousness rationales). Claim(s) 4 is/are rejected under 35 U.S.C. 103 as being unpatentable over Dorwin-Loeb as applied to claims 2-3, 7, 12-13, 16, and 20 above, and further in view of Shank (US 2022/0358234 A1). Regarding claim 4, Dorwin-Loeb does not specify: wherein the instructions for tagging the HTML element include adding one or both of an HTML tag or Cascading Style Sheets (CSS). However, Dorwin-Loeb in view of Shank discloses: wherein the instructions for tagging the HTML element include adding one or both of an HTML tag or Cascading Style Sheets (CSS). Refer to at least 190 in FIG.2, [0021], [0023], and [0043]-[0044] of Shank with respect to using CSS selectors to identify HTML elements that contain sensitive information for masking. The teachings of Shank likewise concern access control for sensitive information, as well as HTML and streaming media sessions. As such, they are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Dorwin-Loeb to further implement support for using CSS selectors to identify sensitive HTML elements because the particular known technique was recognized as part of the ordinary capabilities of one skilled in the art. Claim(s) 5-6 and 14-15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Dorwin as applied to claims 1 and 11 above, and further in view of Baker (US 2022/0278992 A1). Regarding claim 5, Dorwin does not specify: upon determining the encrypted HTML element does not satisfy the at least one rule of the license, generating a first alert associated with a first user; and causing to output, via the first GUI the first alert. However, Dorwin in view of Baker discloses: upon determining the encrypted HTML element does not satisfy the at least one rule of the license, generating a first alert associated with a first user; and causing to output, via the first GUI the first alert. Refer to at least [0086], [0091], [0094], and [0096] of Baker with respect to policy checks associated with sharing HTML5 content. Refer to at least [0016] and [0088] of Baker with respect to a dialog presented to users based on the policy checks. The teachings of Baker likewise concern protecting content during content sharing (e.g., screen sharing), and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Dorwin to further implement the policy checks and notifications of Baker (e.g., having the correct viewer application; being associated with the correct users) for at least the purpose of preventing accidental instances of insecure sharing (e.g., using an insecure viewer; choosing to share elements that should not be seen by certain participants). Regarding claim 6, it is rejected for substantially the same reasons as claim 5 above (e.g., 325 in FIG. 3A and [0094]-[0096] of Baker). Claim(s) 8-10 and 17-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Dorwin-Loeb as applied to claims 2-3, 7, 12-13, 16, and 20 above, and further in view of Baker (US 2022/0278992 A1) and Seo (US 2014/0240440 A1). Regarding claim 8, Darwin-Loeb does not specify: upon determining the encrypted HTML element does not satisfy the at least one rule of the license, generating a second alert associated with the second user; and causing to output, via a second GUI associated with the second user device, the second alert. However, Darwin-Loeb in view of Baker discloses: upon determining the encrypted HTML element does not satisfy the at least one rule of the license, generating a second alert; Refer to at least [0086] and [0094]-[0096] of Baker with respect to evaluating content to be shared against policy and providing notification of failure. The teachings of Baker likewise concern protecting content during content sharing (e.g., screen sharing), and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Dorwin-Loeb to further implement the policy checks and notifications of Baker (e.g., having the correct viewer application; being associated with the correct users) for at least the purpose of preventing accidental instances of insecure sharing (e.g., using an insecure viewer; choosing to share elements that should not be seen by certain participants). Dorwin-Loeb-Baker does not specify: the second alert further being associated with the second user; and causing to output, via a second GUI associated with the second user device, the second alert. However, Dorwin-Loeb-Baker in voew of Seo discloses: the second alert further being associated with the second user; and causing to output, via a second GUI associated with the second user device, the second alert. Refer to at least FIG. 11 and [0243]-[0245] of Seo with respect to a screen sharing refusal popup window in response to a screen sharing request. The teachings of Seo likewise concern screen sharing, and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Dorwin-Loeb-Baker to further implement a refusal popup window because particular known technique was recognized as part of the ordinary capabilities of one skilled in the art, and for the purpose of letting requestors know the result of their request. Regarding claim 9, it is rejected for substantially the same reasons as claim 8 above (i.e., the citations and obviousness rationale). Regarding claim 10, Dorwin-Loeb-Baker-Seo discloses: The method of claim 8, further comprising: upon determining the encrypted HTML element does not satisfy the at least one rule of the license, generating a user interface, wherein the user interface include one or more of the second alert, a blank screen, or a watermark; and causing to output, via the GUI associated with the first user device, the user interface. Refer to at least 320 in FIG. 3A, 1445 in FIG. 14, and [0096] of Baker with respect to the case where the content is not shared. This claim would have been obvious for substantially the same reasons as claim 5 above. Regarding claims 17-19, they are substantially similar to claims 8-10 above, and are therefore likewise rejected. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to VADIM SAVENKOV whose telephone number is (571)270-5751. The examiner can normally be reached 12PM-8PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432 /V.S/Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Oct 03, 2024
Application Filed
Jan 02, 2026
Non-Final Rejection mailed — §102, §103, §112
Apr 01, 2026
Applicant Interview (Telephonic)
Apr 02, 2026
Response Filed
Apr 04, 2026
Examiner Interview Summary
Jul 07, 2026
Final Rejection mailed — §102, §103, §112
Jul 21, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12639449
SYSTEM AND METHOD FOR SCANNING CONTAINERS FOR VULNERABILITIES
2y 4m to grant Granted May 26, 2026
Patent 12632534
ACCESSING SECURE SYSTEM RESOURCES BY LOW PRIVILEGE PROCESSES
7y 12m to grant Granted May 19, 2026
Patent 12613999
DETECTING ELECTRONIC SYSTEM MODIFICATION
6y 10m to grant Granted Apr 28, 2026
Patent 12608482
DETERMINING A SECURITY SCORE IN BINARY SOFTWARE CODE
6y 5m to grant Granted Apr 21, 2026
Patent 12608501
Privacy-Preserving Log Analysis
5y 11m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
61%
Grant Probability
82%
With Interview (+20.8%)
3y 5m (~1y 6m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 316 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month