Prosecution Insights
Last updated: August 17, 2026
Application No. 18/915,419

SYSTEMS AND METHODS FOR OUT-OF-BAND AUTHENTICITY VERIFICATION OF MOBILE APPLICATIONS

Final Rejection §112
Filed
Oct 15, 2024
Priority
Nov 05, 2019 — continuation of 10/985,921 +2 more
Examiner
LWIN, MAUNG T
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Capital One Services LLC
OA Round
2 (Final)
89%
Grant Probability
Favorable
3-4
OA Rounds
4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
550 granted / 619 resolved
+30.9% vs TC avg
Strong +22% interview lift
Without
With
+21.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 2m
Avg Prosecution
21 currently pending
Career history
629
Total Applications
across all art units

Statute-Specific Performance

§101
12.5%
-27.5% vs TC avg
§103
31.7%
-8.3% vs TC avg
§102
13.4%
-26.6% vs TC avg
§112
35.5%
-4.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 619 resolved cases

Office Action

§112
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to the amendment filed on 06/09/2026. Claims 1-20 are currently pending in this application. Claims 1, 8, 9, 16 and 17 have been amended. No new IDS has been filed. Response to Arguments Regarding the 112(b) rejections, applicants have amended the claims 1, 9 and 17 and have, in page 6 of the remarks, argued that “… to clarify that the encrypted cryptographic key is received ‘from a client application’ … also add ‘network’ before ‘channel’ to clarify that out-of-band channel is a network communication channel for transmitting data to an external client application, not an internal processor-memory bus … specification [0026]- [0028] …”. The applicants’ these arguments are not persuasive. As amended, the claim 1 includes “… a processor in communication with the memory … is configured: to receive, from a client application, an encrypted cryptographic key … transmit, to the client application, the encrypted authorization token via an out-of-band network channel …”. As claimed, the processor has the communication with (only) the memory, and any communication (e.g., receiving or transmission) of the processor is performed with the memory. Therefore, the receiving communication from the client application makes unclear as whether the client application is stored in the memory or not. Moreover, the term, “out-of-band channel” is defined as “a separate, independent communication pathway used to transmit information or manage systems outside of a primary, everyday network” or “communication by any channel other than the primary channel”. However, the amended limitation, “an out-of-band network channel”, defining for “transmitting data to an external client application, not an internal processor-memory bus” (see page 6 of the remarks) makes unclear as whether the applicants act as own lexicographer to define a term, “an out-of-band network channel” or not. It is noted that the features upon which applicants argue (e.g., … the specification, which describes that [s]erver 120 may be configured … through the second channel 114 … Specification, [0026], [0028] …”) is NOT recited in the claims. Although the claims are interpreted in light of the specification, limitations for the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). See the 112-rejection section below for detail. The applicants, in page 7 of the remarks, further argued that “… would understand that ‘applying a key’ to encrypted data means using the key as an input to a decryption algorithm …”. Examiner respectfully disagrees with the argument. First of all, using the Broadest Reasonable Interpretation (BRI), the term, “apply”, means to put something into practical use. Therefore, the claimed limitations, “apply each of the plurality of stored keys to the encrypted cryptographic key …”, are not clear whether the stored key is practically used (e.g., added, subtracted, multiplied, etc.) to the encrypted cryptographic key or not. Secondly, there is not any “decryption algorithm” in the claim. Therefore, the rejection is maintained. Regarding the 112(b) rejections to the claims 2, 10 and 18, the applicants, in page 7 of the remarks, have argued that “… would understand that ‘a limited duration token’ refers to a token that is valid only for a limited period of time, such as OAuth tokens with expiration times or session tokens with timeouts …”. The applicants’ this argument is not persuasive. As the applicants’ noted, different types of tokens define different time information (e.g., the expiration time for the OAuth tokens, timeouts for the session tokens, etc.). However, the claimed token is not defined as “OAuth token” or “session token”, and it is not clear whether the claimed “limited duration token” can have any time duration (e.g., 100ms, 15 minutes, 10 years, etc.) or not. The applicants’ argument of difference between “duration token” and “limited duration token” is not clear. Regarding the 112(b) rejections to the claims 8 and 16, the applicants, in pages 6-7 of the remarks, have argued that “… to clarify that the unsuccessful decryption scenario occurs ‘upon none of the plurality of stored keys successfully decrypting’ this clarifies the relationship between the interactive decryption process recited in the independent claims …”. The examiner respectfully disagrees with the argument. As rejected in the previous office action, the claim 1 recites to “apply the stored key until successfully decrypts the encrypted key”, which does not include any condition information or the interactive decryption process (e.g., determining whether the decryption is successful or not, etc.). Then, the claim 8 recites “upon none of the stored key successfully decrypting the encrypted key”, which conflicts the limitations of the claim 1. Therefore, the rejection is maintained. The previous double patenting rejections have been withdrawn in response to the applicants’ filing of a terminal disclaimer which is approved on 06/09/2026. Thus, the applicants’ arguments are not persuasive. Please see amended rejections below for the amended claims. This action is final. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(a): (a) IN GENERAL. —The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. Claims 1-20 are rejected under 35 U.S.C. 112(a), as failing to comply with the written description requirements (e.g., the new matter issue). Applicants have amended the claims 1, 9 and 17 to include subject matter “… transmit, to the client application, the encrypted authorization token via an out-of-band network channel …”, however, these amended limitations/terms were not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, at the time the application was filed, had possession of the claimed invention. Examiner noted that the specification describes that “… Server 120 may be configured to transmit the authorization token to client application 105 via the out-of-band channel …” – see par. 0028, but the claimed out-of-band network channel is defined as “transmitting data to an external client application, not an internal processor-memory bus” (see page 6 of the remarks). However, the information of the specification stated above does not provide to support or describe the amended limitations, “… out-of-band network channel” defined as “transmitting data to an external client application, not an internal processor-memory bus”. Claims 2-8, 10-16 and 18-20 depend from the claim 1, 9 or 17, and are analyzed and rejected accordingly. The following is a quotation of 35 U.S.C. 112(b): (B) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which applicant regards as the invention. Claim 1 (claims 9 and 17 include similar limitations) recites: “An authentication server, comprising: a memory storing … a processor in communication with the memory, wherein the processor is configured to: receive, from a client application, an encrypted cryptographic key … transmit, to the client application, the encrypted authorization token … grant access to at least one service …”, however, it is not clear (1) whether the encrypted cryptographic key is received from the memory via the communication or not or whether the client application is a part of the authentication server (e.g., stored/installed in the memory) or not – please note that the processor has the communication with (only) the memory, and any communication (e.g., receiving or transmission) of the processor is performed with the memory; (2) whether the authentication server grants the service of the authentication server or not – it is not clear to define a boundary of the limitations; “… apply each of the plurality of stored keys to the encrypted cryptographic key until one of the stored keys successfully decrypts …”, however, it is not clear (1) how to apply the stored key to the encrypted key (e.g., replacing key, adding the key), please note that using the Broadest Reasonable Interpretation (BRI), the term, “apply”, is interpreted as to put something into practical use, and the stored key and the encrypted key are data/information, NOT a program/function for execution; (2) how applying the stored key to the encrypted key perform decryption a process - omitting necessary step(s)/component(s) which cause the limitations unclear; “… transmit, to a client application … via an out-of-band network channel; grant access to at least one service to the client application …”, however, it is not clear (1) whether the out-of-band network channel is the communication channel other than the communication channel between the processor and the memory stated before or not – please note that the amended limitation, “an out-of-band network channel”, defining for “transmitting data to an external client application, not an internal processor-memory bus” (see page 6 of the remarks) makes unclear as whether the applicants act as own lexicographer to define a term, “an out-of-band network channel” or not; (2) whether the client application is granted to access the service via the out-of-band network channel or not – it is not clear to define a boundary of the limitations. Claims 2-8, 10-16 and 18-20 depend from the claim 1, 9 or 17, and are analyzed and rejected accordingly. Claims 2, 10 and 18 recite “… a limited duration token”, however, it is not clear how to define “a duration token”. As the applicants noted in the previous response, different types of tokens define different time information (e.g., the expiration time for the OAuth tokens, timeouts for the session tokens, etc.). However, the claimed token is not defined as “OAuth token” or “session token”, and it is not clear whether the claimed “limited duration token” can have any time duration (e.g., 100ms, 15 minutes, 10 years, etc.) or not. Claim 8 recites “… wherein upon none of the plurality of stored keys successfully decrypting the encrypted cryptographic key, the processor disables communications with a client application”, however, it is not clear (1) how the processing until successfully decryption (see the claim 1) provides “none of the plurality of stored keys successfully decrypting” (e.g., during the decryption process before the successful decryption, etc.) – please note that the claim 1 recites to “apply the stored key until successfully decrypts the encrypted key”, which does not include any condition information or the interactive decryption process (e.g., determining whether the decryption is successful or not, etc.). Then, the claim 8 recites “upon none of the stored key successfully decrypting the encrypted key”, which conflicts the limitations of the claim 1; (2) whether the processor has communications with the client application before the decryption process in order to process “disable” function – it is not clear to define a boundary of the limitations. Examiner’s Note Regarding Prior-art Rejections As explained in the 112 rejections stated above, the current limitations are in a condition of lack of clarity and/or capability (e.g., omitting necessary component/step) for a prior-art examination. However, a potential concept of the application can be found in: US 11,133,934 B2 by Abadir et al. (e.g., performing out-of-band user authentication, by a service electronic device associated with a service for a request to initiate a session of the service; generating an authentication token; encrypting the authentication token to generate an encrypted authentication token, and transmitting the encrypted authentication token to the electronic device, etc.); US 2014/0068244 A1 by Oliver (e.g., enabling a web browser to decrypt and to display encrypted information including attempting to decrypt at least one element using keys, such as key 1, key 2, key 3 until a successful completion, etc.); US 2017/0289197 A1 by Mandyam et al. (e.g., establishing the secure communication session by a client device sending a request to a server for access token with a public key and preventing the access token from exported by a malicious party to obtain access to services, etc.); US 6,681,017 B1 by Matias et al. (e.g., encrypting a shared key of a client using a public key of the server and sending the encrypted shared key to the server and the server sending a message to the client after successful decryption of the shared key, etc.); US 2009/0313705 A1 by Adams et al. (e.g., access restriction after a predetermined limit for decryption attempts exceeded by a user attempting to decrypt a session key with the candidate passphrase, etc.); US 9,026,782 B2 by Ahuja et al. (e.g., sending an authentication request from a device to a session management server to receive a token, etc.); US 2017/0346807 A1 by Blasi (e.g., providing technologies for token-based access authorization to an API for a service request message of a remote computing device, etc.). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MAUNG T LWIN whose telephone number is (571)270-7845. The examiner can normally be reached on Monday - Friday 10:00 am - 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MAUNG T LWIN/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Oct 15, 2024
Application Filed
Mar 19, 2026
Non-Final Rejection mailed — §112
Jun 09, 2026
Response Filed
Jul 07, 2026
Final Rejection mailed — §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706181
PREDICTING OLFACTORY PROPERTIES OF MOLECULES USING MACHINE LEARNING
2y 11m to grant Granted Aug 11, 2026
Patent 12699801
CONSTRUCTING AND ENFORCING ACCESS CONTROL POLICIES
1y 9m to grant Granted Aug 04, 2026
Patent 12695604
METHODS AND SYSTEMS FOR BLOCKCHAIN-IMPLEMENTED EVENT-LOCK ENCRYPTION
1y 8m to grant Granted Jul 28, 2026
Patent 12682103
USER-SPECIFIC ACCESS CONTROL FOR METADATA TABLES
2y 8m to grant Granted Jul 14, 2026
Patent 12682104
EFFICIENT ALLOW LISTING OF SQL INSIDE A DATABASE
2y 4m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+21.8%)
2y 2m (~4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 619 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month