Prosecution Insights
Last updated: October 02, 2026
Application No. 19/066,145

Unlocking a Data Storage Device Using a Web Application

Non-Final OA §112
Filed
Feb 27, 2025
Priority
Oct 23, 2024 — CIP of 18/924,819
Examiner
ELAHIAN, DANIEL
Art Unit
2407
Tech Center
2400 — Computer Networks
Assignee
SanDisk Technologies Inc.
OA Round
1 (Non-Final)
74%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
32 granted / 43 resolved
+16.4% vs TC avg
Strong +52% interview lift
Without
With
+52.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
15 currently pending
Career history
61
Total Applications
across all art units

Statute-Specific Performance

§101
5.5%
-34.5% vs TC avg
§103
76.7%
+36.7% vs TC avg
§102
9.4%
-30.6% vs TC avg
§112
7.9%
-32.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 43 resolved cases

Office Action

§112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The present Office Action is responsive to communication received 2/27/2025. Claims 1-20 are pending. Information Disclosure Statement The information disclosure statements (IDS) submitted on 5/1/2026 was filed after the mailing date of the application no. 19/066,145 on 2/27/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. This application includes one or more claim limitations that use the word “means,” and are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses “means” that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “means for verifying the authentication data” and “ means for unlock the data storage device” in claim 20. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 112 (d) The following is a quotation of 35 U.S.C. 112(d): (d) REFERENCE IN DEPENDENT FORMS.—Subject to subsection (e), a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. The following is a quotation of pre-AIA 35 U.S.C. 112, fourth paragraph: Subject to the following paragraph [i.e., the fifth paragraph of pre-AIA 35 U.S.C. 112], a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. Claims 18 and 19 are rejected under 35 U.S.C. 112(d) or pre-AIA 35 U.S.C. 112, 4th paragraph, as being of improper dependent form for failing to further limit the subject matter of the claim upon which it depends, or for failing to include all the limitations of the claim upon which it depends. Applicant may cancel the claim(s), amend the claim(s) to place the claim(s) in proper dependent form, rewrite the claim(s) in independent form, or present a sufficient showing that the dependent claim(s) complies with the statutory requirements. Claim 18 recites the method of claim 13, but claim 13 is a device- claims 18 could also depend from claim 15 or 16 or 17. Claim 19 recites the method of claim 13, but claim 13 is a device- claims 19 could also depend from claim 15 or 16 or 17. Allowable subject matter Claims 1-20 recite allowable subject matter. The following is a statement of reasons for the indication of allowable subject matter: The closest prior arts are Zimmerman et al. (US 20220086928), Newman et al., (US 20170063877), Abad et al., (US 10805083) and Johnson et al., (US 9727490). Regarding claims 1, 15, and 20, Zimmerman et al. (US 20220086928), discloses a data storage device, comprising: a storage medium comprising: [an example of a data storage device 1 including a communication interface 3, storage medium 19, and at least one processor 7. (Zimmerman et al., paragraph 39)] a secured partition configured to store user data under the mass storage device protocol, [an example of a data storage device 1 including a communication interface 3, storage medium 19, and at least one processor 7. (Zimmerman et al., paragraph 39)] a communication interface configured to communicate with the host device; and at least one processor configured, individually or in combination, to: [an example of a data storage device 1 including a communication interface 3, storage medium 19, and at least one processor 7. (Zimmerman et al., paragraph 39)] communicatively couple with the host device, via at least one control communication channel, wherein the at least one processor is configured to emulate a network adapter to the host device, [the at least one processor 7 emulating a Wi-Fi adapter sends 103, via the communication interface 3, (Zimmerman et al., paragraph 41)] wherein the at least one control communication channel is enabled by an Ethernet over USB (Universal Serial Bus) protocol driver, [a USB (universal serial bus) bridge to enumerate with the host device 5. (Zimmerman et al., paragraph 48)] verify that the received authentication data corresponds to a record in an authentication data set configured by the first web application; [The at least one processor 7 then verifies 109 that the received authentication data 61 corresponds to a record 63 in an authentication data set 65. (Zimmerman et al., paragraph 83)] and in response to verifying the received authentication data, unlock the data storage device to enable access between the host device and the secured partition via a data communication channel, [device authorizes 111 additional function(s) 67 of the data storage device 1. In this example, the additional function(s) includes selectively enabling access 113 to at least part of the storage medium 19 (that is authorized for the corresponding authentication data) (Zimmerman et al., paragraph 85)] wherein the data communication channel is enabled by a USB mass storage driver. [That is, the communication interface 3 can function as a USB hub. One peripheral device is as a mass data storage device, whereby the host uses the storage medium 19 to store, read, and write, user content data. (Zimmerman et al., paragraph 49)] Newman et al., (US 20170063877) discloses a protected partition inaccessible through a mass storage device protocol, wherein the protected partition stores program code, [ First partition 100 is protected from any malicious computer executable stored on secondary partition 200, because CPU 104 can execute only computer executable code stored on the program code address range of memory 106 and data store 107 (Newman et al., paragraph 20)] Abad et al., (US 10805083) discloses and an unsecured partition readable by the host device, wherein the unsecured partition stores at least a second web application, [For example, public data and generic functionalities of the application may be stored in the unsecured memory 215, and private customer data and security and authentication functionalities may be stored in the secured memory 215S. (Abad et al., column 8, 37-41)] Johnson et al., (US 9727490) discloses to receive, via the at least one control communication channel, authentication data to unlock the data storage device, wherein the authentication data is received from the second web application instantiated at the browser of the host device; [Read/write operations to the storage media 104 are blocked until the self-locking mass-storage system 100 receives an authentication 404 such as a password entered through the software application 302, which sets the self-locking mass-storage system 100 into an unlocked state 406. In alternate embodiments of the invention, the authentication 404 may be a Personal Identification Number (PIN) entered through an input device, or a biometric signature or pattern entered through a biometric reader (Johnson et al., column 3, lines 52-61)] For independent claims 1, 15, and 20, the prior arts of record, alone or in combination, fail to teach the claims limitations as a whole, and particularly fails to explicitly disclose the claim in relation to: “when executed, to emulate at least a webserver configured to provide a first web application to a browser of a host device to configure the data storage device, wherein the second web application is different from the first web application and is executable through the browser of the host device to unlock the data storage device; wherein the second web application is configured to specify an IP (Internet Protocol) address associated with the data storage device to unlock the data storage device via the at least one control communication channel”. Therefore claims 1-20 recite allowable subject matter. Other pertinent prior arts disclose: Tazume et al., (US 20220075851) – discloses The authentication of a user based on the authentication information received, in advance, from the central server and the authentication information input from the user and further, when the user is authenticated, the key controller may be controlled so that the reception control unit unlocks the storage compartment that stores the package addressed to the user. White et al. (US 9935767) discloses activating and configuring the secure storage associated with the second application in the non-volatile memory on the second computing device managing the secure storage by the second application, wherein managing the secure storage comprises locking and unlocking the secure storage to control accessibility of the application data associated with executing of the second application by a runtime process running on the second computing device. Wilkins et al. (US 20210097791) discloses an electronic lock which ensures that only an authorized user can unlock the secure storage container to access the products inside. To unlock the secure storage container, the mobile application at the mobile device must authenticate the user, present the user with a user interface for unlocking, receive a user unlocking request, and then transmit an unlocking message from a local wireless transceiver or communication unit of the mobile device to a local wireless transceiver or communication unit of the secure storage container, and the secure storage container may activate the locking mechanism from a locked to an unlocked position. Shan et al. (CN 121525067) discloses a system which comprises a host terminal and a mobile storage device terminal. the host terminal is equipped with a special device driver for transmitting the generated authentication data and the storage access instruction to the mobile storage device terminal via the virtual storage front terminal device created by the special device driver. the mobile storage device end is deployed with an operation system based on micro-kernel architecture, and establishes a virtual storage back end device corresponding to the virtual storage front end device, for performing host identity and right energy verification on the authentication data received by the virtual storage back end device, and after the verification is passed, A storage access instruction from the host is received and executed. the virtual storage front-end device and the virtual storage back-end device establish communication connection through USB bus. Shukla et al. (WO 2022245414) discloses storing, by the data storage device, device credentials for authenticating access to the network storage system; storing, by the data storage device, encryption credentials for establishing the secure data transfer connection; reading, by the data storage device, the encryption credentials; initiating, by the data storage device and using the encryption credentials, the secure data transfer connection with the network storage system; reading, by the data storage device, the device credentials; and sending, by the data storage device, the device credentials to the network storage system to authenticate access to the target data unit stored in the network storage system. Dou et al. (CN 114978689) discloses The remote management device 20 establishing a communication connection with the storage device 10 to send an unlocking instruction to the storage device 10; the storage device 10 receives the remote management device 20 sends the unlocking instruction to generate and store an identity credential, using the storage device private key to sign the identity credential to obtain the first signature value; the remote management device 20 receives the identity credentials and the first signature value, using the stored storage device public key to the first signature value for the first signature authentication to obtain the first authentication information, namely checking the identity credential and the first signature value, when the signature is passed, then the storage device 10 directly unlocking or remote management device 20 sends unlocking credentials to the storage device 10 so that the storage device 10 for unlocking operation. Choi et al. (US 20240184931) discloses receiving an unlock request for each storage device from the host device, and each of the plurality of storage devices, including the second storage device, may determine whether to unlock the corresponding storage device. Here, the unlock request for the storage device may include a password input from the user of the application. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANIEL ELAHIAN whose telephone number is (703) 756-1284. The examiner can normally be reached on Monday – Friday from 7:30am to 5pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at telephone number 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /D.E./ DANIEL ELAHIAN, Examiner, Art Unit 2407 /Catherine Thiaw/Supervisory Patent Examiner, Art Unit 2407 6/28/2026
Read full office action

Prosecution Timeline

Feb 27, 2025
Application Filed
Jul 01, 2026
Non-Final Rejection mailed — §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748854
SYSTEM AND METHOD FOR DETECTING ADVERSARIAL INTERFERENCE WITH DATA PROCESSING SYSTEMS
3y 5m to grant Granted Sep 29, 2026
Patent 12737454
SYSTEMS AND METHODS FOR ENCODING BEHAVIORAL INFORMATION INTO AN IMAGE DOMAIN FOR PROCESSING
4y 3m to grant Granted Sep 15, 2026
Patent 12724900
DEVICE RISK-BASED TRUSTED DEVICE VERIFICATION AND REMOTE ACCESS PROCESSING SYSTEM
3y 2m to grant Granted Sep 01, 2026
Patent 12724901
Real-Time Tamper-Detection Protection for Source Code Using LSTM and QLSTM with Quantum Cache
2y 7m to grant Granted Sep 01, 2026
Patent 12699802
OBSCURING ELEMENTS BASED ON USER INPUT
4y 1m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
74%
Grant Probability
99%
With Interview (+52.4%)
2y 11m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 43 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month