Prosecution Insights
Last updated: October 02, 2026
Application No. 18/980,178

SIGNATURE AUTHENTICATION METHODS AND APPARATUSES

Final Rejection §103
Filed
Dec 13, 2024
Priority
Dec 26, 2022 — CN 202211673945.0 +1 more
Examiner
NGUYEN, ANH
Art Unit
2458
Tech Center
2400 — Computer Networks
Assignee
Alipay.com Co., Ltd.
OA Round
2 (Final)
79%
Grant Probability
Favorable
3-4
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
297 granted / 376 resolved
+21.0% vs TC avg
Strong +25% interview lift
Without
With
+25.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
21 currently pending
Career history
400
Total Applications
across all art units

Statute-Specific Performance

§101
14.4%
-25.6% vs TC avg
§103
61.9%
+21.9% vs TC avg
§102
7.8%
-32.2% vs TC avg
§112
10.2%
-29.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 376 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This communication is in response to the amendment filed on 07/21/2026. Claims 1-20 are pending and rejected. Claims 1, 4-6, 8, 11-15, and 18-19 have been amended. Response to Arguments Applicants’ arguments with respect to claims 1, 8, and 15 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Further, the process of generating key/ID associated with a user request corresponds to a dynamic signature. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Wang (US 20240364523 A1) in view of Okuyama (US 20230164142 A1). Regarding claim 1, Wang teaches a method comprising: receiving, by a server configured to perform signature authentication on a terminal device, a signature authentication request sent by the terminal device ([0072] The web end sends, to an application server, a key request used to request a key needed for enabling TOTP ;[0099] The authentication server receives an enabling confirmation request that is sent by a business application end and that includes a second signature, where the second signature is obtained after the business application end signs, by using a second private key in a second public-private key pair, the device information of a terminal device that the business application end is located); determining whether the terminal device that sends the signature authentication request is a contaminated device ([0103] The authentication server can store a blacklist, including devices with a low security level. The authentication server can identify the device model in the blacklist through searching. If the device type can be identified, it is considered that the security level of the terminal device does not satisfy the enabling need (contaminated device)); in response to determining that the terminal device that sends the signature authentication request is a contaminated device, determining a dynamic signature parameter that needs to be used for the signature authentication ([0104] The authentication server queries the second public key in the second public-private key pair based on the obtained device model); re-authorizing the terminal device to enable verification permissions ([0117] The authentication server obtains, based on the received enabling confirmation request, a device model of the terminal device that the business application end is located; determines, based on the obtained device model, whether a security level of the terminal device satisfies an enabling need); notifying the terminal device to collect the dynamic signature parameter ([0123] The business application end performs token calculation based on the secretKey by using the TA application in the TEE, and provides a calculated token to a user); receiving a value of the dynamic signature parameter that is sent by the terminal device ([0126] The application server performs token calculation based on the secretKey stored by the application server, and determines whether a calculated token is consistent with the token included in the identity verification request, where if the calculated token is consistent with the token included in the identity verification request, the identity verification is “legal”; otherwise, the identity verification is “illegal”.); and performing a second signature authentication based on the value of the dynamic signature parameter [0064] the authentication server receives the enabling confirmation request that is sent by the business application end and that includes the second signature, and the authentication server performs signature verification on the second signature by using the foregoing second public key). Wang does not explicitly teach wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication. Okuyama teaches wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication ([0120] The authentication unit 205 determines whether, among the plurality of sets of feature values registered in the database, there is at least one set of feature values whose similarity to the set of matching target feature values is a predetermined value or more; [0133], fig. 2, fig. 12, the service registration request unit 303 selects the user ID and the password from the above three items of information (the personal information, the user ID, and the password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID and password and the corresponding service provider ID to the authentication server 10). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, select dynamic signature from database, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information. Regarding claims 2, 9, and 16, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15, wherein Wang further teaches a service private key required for signature authentication is embedded in a trusted execution environment (TEE) of the terminal device ([0061] The second private key in the second public-private key pair can be stored in the TEE of the terminal device), and a signature required by the signature authentication request is completed by the TEE after a biological feature entered by a user is successfully verified ([0062] performed by the TA in the TEE of the terminal device that the business application end is located, that is, the TA signs, in the TEE by using the second private key stored in the TEE, the device information of the terminal device that the business application end is located, to obtain the second signature). Regarding claims 3, 10, and 17, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15, wherein the determining whether the terminal device that sends the signature authentication request is a contaminated device comprises: obtaining model information of the terminal device or version information that is carried in the signature authentication request ([0103] the authentication server can identify the device model the blacklist through searching); and determining that the model information of the terminal device or the version information is in a pre-obtained blacklist, and in response, determining that the terminal device that sends the signature authentication request is a contaminated device ([0103] The authentication server can store a blacklist, including devices with a low security level. If the device type can be identified, it is considered that the security level of the terminal device does not satisfy the enabling need). Regarding claims 4, 11, 18, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15, wherein Okuyama further teaches the selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from the dynamic signature parameter library by using a random selection method or a one-by-one selection method, the dynamic signature parameter that needs to be used for the signature authentication ([0133], fig. 2, fig. 12, the service registration request unit 303 selects the user ID and the password from the above three items of information (the personal information, the user ID, and the password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID and password and the corresponding service provider ID to the authentication server 10). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, select dynamic signature from database, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information. Regarding claims 5, 12, and 19, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15 wherein Okuyama further teaches the dynamic signature parameter library comprises: a fingerprint ID, a device ID, an application APP package name, a service scenario, and a user ID ([0048] a fingerprint, [0010] first ID that uniquely determines a user in a system, [0064] a user ID, [0130] a terminal 40 may download an application provided by the service provider). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, a user ID, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information. Regarding claims 6 and 13, Wang and Okuyama teach all limitations of parent claims 1 and 8, wherein Wang further teaches the dynamic signature parameter library comprises a parameter associated with a service ([0036] The application server that supports TOTP is disposed in a server that provides a corresponding business service for a business application). Regarding claims 7, 14, and 20, Wang and Okuyama teach all limitations of parent claims 1, 8, and 15, wherein the method further comprises: setting a corresponding parameter sequence number for each parameter in a dynamic signature parameter library ([0008] A first TA application in a TEE of the terminal device performs the step of performing signature verification on the first signature by using a first public key in the first public-private key pair obtained in advance; and/or a second TA application in the TEE of the terminal device performs the step of performing token calculation based on the key); and the notifying the terminal device to collect the dynamic signature parameter comprises: sending a notification message to the terminal device, wherein a first field in the notification message comprises a parameter sequence number corresponding to the dynamic signature parameter that needs to be used for the signature authentication, and a second field in the notification message indicates a length of the first field ([0009] receiving the key and a first signature sent by the application server, where the first signature is obtained after an authentication server signs the key by using a first private key in a first public-private key pair; generating a two-dimensional code by using the received key and the received first signature, and sending the two-dimensional code to a business application end; receiving a token input by a user, and adding the token to an identity verification request and sending the identity verification request to the application server; and receiving an identity verification result sent by the application server). Regarding claim 8, Wang teaches a computer-implemented device comprising: one or more processors ([0139] a memory and a processor); and one or more tangible, non-transitory, machine-readable media storing one or more instructions that ([00138] The computer-readable storage medium stores a computer program), when executed by the one or more processors, perform one or more operations comprising: receiving, by the computer-implemented device configured to perform signature authentication on a terminal device, a signature authentication request sent by the terminal device ([0072] The web end sends, to an application server, a key request used to request a key needed for enabling TOTP; [0099] The authentication server receives an enabling confirmation request that is sent by a business application end and that includes a second signature, where the second signature is obtained after the business application end signs, by using a second private key in a second public-private key pair, the device information of a terminal device that the business application end is located); determining whether the terminal device that sends the signature authentication request is a contaminated device ([0103] The authentication server can store a blacklist, including devices with a low security level. The authentication server can identify the device model in the blacklist through searching. If the device type can be identified, it is considered that the security level of the terminal device does not satisfy the enabling need (contaminated device)); in response to determining that the terminal device that sends the signature authentication request is a contaminated device, determining a dynamic signature parameter that needs to be used for the signature authentication ([0104] The authentication server queries the second public key in the second public-private key pair based on the obtained device model); re-authorizing the terminal device to enable verification permissions ([0117] The authentication server obtains, based on the received enabling confirmation request, a device model of the terminal device that the business application end is located; determines, based on the obtained device model, whether a security level of the terminal device satisfies an enabling need); notifying the terminal device to collect the dynamic signature parameter ([0123] The business application end performs token calculation based on the secretKey by using the TA application in the TEE, and provides a calculated token to a user); receiving a value of the dynamic signature parameter that is sent by the terminal device ([0126]: The application server performs token calculation based on the secretKey stored by the application server, and determines whether a calculated token is consistent with the token included in the identity verification request, where if the calculated token is consistent with the token included in the identity verification request, the identity verification is “legal”; otherwise, the identity verification is “illegal”); and performing a second signature authentication based on the value of the dynamic signature parameter ([0064] the authentication server receives the enabling confirmation request that is sent by the business application end and that includes the second signature, and the authentication server performs signature verification on the second signature by using the foregoing second public key). Wang does not explicitly teach the term “dynamic signature” in the limitation “determining a dynamic signature parameter that needs to be used for the signature authentication”. Wang does not explicitly teach wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication. Okuyama teaches wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication ([0120] The authentication unit 205 determines whether, among the plurality of sets of feature values registered in the database, there is at least one set of feature values whose similarity to the set of matching target feature values is a predetermined value or more; [0133], fig. 2, fig. 12, the service registration request unit 303 selects the user ID and the password from the above three items of information (the personal information, the user ID, and the password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID and password and the corresponding service provider ID to the authentication server 10). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, select dynamic signature from database, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information. Regarding claim 15, Wang teaches a non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising ([0138] The computer-readable storage medium stores a computer program): receiving, by a server configured to perform signature authentication on a terminal device, a signature authentication request sent by the terminal device ([0072] The web end sends, to an application server, a key request used to request a key needed for enabling TOTP ;[0099] The authentication server receives an enabling confirmation request that is sent by a business application end and that includes a second signature, where the second signature is obtained after the business application end signs, by using a second private key in a second public-private key pair, the device information of a terminal device that the business application end is located); determining whether the terminal device that sends the signature authentication request is a contaminated device ([0103] The authentication server can store a blacklist, including devices with a low security level. The authentication server can identify the device model in the blacklist through searching. If the device type can be identified, it is considered that the security level of the terminal device does not satisfy the enabling need (contaminated device)); in response to determining that the terminal device that sends the signature authentication request is a contaminated device, determining a dynamic signature parameter that needs to be used for the signature authentication ([0104] The authentication server queries the second public key in the second public-private key pair based on the obtained device model), re-authorizing the terminal device to enable verification permissions ([0117] The authentication server obtains, based on the received enabling confirmation request, a device model of the terminal device that the business application end is located; determines, based on the obtained device model, whether a security level of the terminal device satisfies an enabling need); notifying the terminal device to collect the dynamic signature parameter ([0123] The business application end performs token calculation based on the secretKey by using the TA application in the TEE, and provides a calculated token to a user); receiving a value of the dynamic signature parameter that is sent by the terminal device ([0126]: The application server performs token calculation based on the secretKey stored by the application server, and determines whether a calculated token is consistent with the token included in the identity verification request, where if the calculated token is consistent with the token included in the identity verification request, the identity verification is “legal”; otherwise, the identity verification is “illegal”); and performing a second signature authentication based on the value of the dynamic signature parameter [0064] the authentication server receives the enabling confirmation request that is sent by the business application end and that includes the second signature, and the authentication server performs signature verification on the second signature by using the foregoing second public key). Wang does not explicitly teach wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication. Okuyama teaches wherein the determining a dynamic signature parameter that needs to be used for the signature authentication comprises: selecting, by the server from a dynamic signature parameter library, the dynamic signature parameter that needs to be used for the signature authentication ([0120] The authentication unit 205 determines whether, among the plurality of sets of feature values registered in the database, there is at least one set of feature values whose similarity to the set of matching target feature values is a predetermined value or more; [0133], fig. 2, fig. 12, the service registration request unit 303 selects the user ID and the password from the above three items of information (the personal information, the user ID, and the password) acquired from the personal information acquisition unit 302. The service registration request unit 303 transmits a service registration request including the selected user ID and password and the corresponding service provider ID to the authentication server 10). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Wang disclosure, select dynamic signature from database, as taught by Okuyama. One would be motivated to do so to enable more secure authentication using biological information. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANH NGUYEN whose telephone number is (571)270-0657. The examiner can normally be reached M-F. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached at 5712703037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ANH NGUYEN/Primary Examiner, Art Unit 2458
Read full office action

Prosecution Timeline

Dec 13, 2024
Application Filed
Apr 21, 2026
Non-Final Rejection mailed — §103
Jul 21, 2026
Response Filed
Sep 11, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750237
METHOD AND SYSTEM FOR PROTECTING DIGITAL SIGNATURES
2y 5m to grant Granted Sep 29, 2026
Patent 12750353
DISPOSABLE BROWSERS AND AUTHENTICATION TECHNIQUES FOR A SECURE ONLINE USER ENVIRONMENT
1y 9m to grant Granted Sep 29, 2026
Patent 12744805
SYSTEMS AND METHODS FOR MONITORING NETWORK TRAFFIC TO IDENTIFY CYBERATTACKS
2y 3m to grant Granted Sep 22, 2026
Patent 12744754
SYSTEM AND METHOD FOR MULTIVARIATE TESTING OF MESSAGES TO SUBGROUP IN A ONE-TO-MANY MESSAGING PLATFORM
2y 2m to grant Granted Sep 22, 2026
Patent 12739229
ONE-TIME VIRTUAL PRIVATE NETWORK
2y 2m to grant Granted Sep 15, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+25.0%)
2y 9m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 376 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month