Prosecution Insights
Last updated: August 17, 2026
Application No. 19/184,561

PARALLEL SECRET SALT GENERATION AND AUTHENTICATION FOR ENCRYPTED COMMUNICATION

Non-Final OA §103
Filed
Apr 21, 2025
Priority
Aug 18, 2022 — continuation of 12/289,396
Examiner
TRAORE, FATOUMATA
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Capital One Services LLC
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
2y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
457 granted / 585 resolved
+20.1% vs TC avg
Strong +35% interview lift
Without
With
+35.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
13 currently pending
Career history
604
Total Applications
across all art units

Statute-Specific Performance

§101
8.6%
-31.4% vs TC avg
§103
55.1%
+15.1% vs TC avg
§102
14.0%
-26.0% vs TC avg
§112
10.8%
-29.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 585 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This is in response to the original filing of 04/21/2025 and preliminary amendments of 07/30/2025. Claims 1-20 have been cancelled. Claims 21-40 have been added. Claims 21-40 are pending and have been considered below. Priority 19184561 filed 04/21/2025 is a Continuation of 17890628 , filed 08/18/2022 ,now U.S. Patent # 12289396 and having 1 RCE-type filing therein. Drawings The drawings filed on 04/21/2025 are accepted. Specification The amendment to the specification filed on 04/21/2025 is accepted. Information Disclosure Statement The information disclosure statement (IDS) submitted on 03/20/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Objections Claim 23 is objected to because of the following informalities: Claim 23 depend on clam 23 for examination purpose only claim 23 will be treated as depending on claim 22. Appropriate correction is required. Double Patenting The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on non-statutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a non-statutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 21-40 are rejected on the ground of non-statutory double patenting as being unpatentable over claims1-20 of U.S. Patent No. 12,289,396 B1. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the present application are anticipated by the claims of the parent patent. Claim 21 is an obvious variant of claim 1 of the parent patent substituting the disclosed shared secret. And “shared authentication key” MAC generation alternative for disclosed “dynamically derived shared secret value alone” alternative. 19/184561 12,289,396 B1 21. A card, comprising: a data processor; a communication interface configured for data communication with an intermediary device; and a card memory storing a shared secret, a shared authentication key, a session key, message content, and a message encryption application comprising instructions for execution by the data processor, wherein, when executed by the data processor, the message encryption application causes the data processor to: generate a message authentication code using the shared secret and the shared authentication key, encrypt at least a portion of the message content and the message authentication code using the session key to generate an encrypted message, and transmit, to the intermediary device, the encrypted message. 33. A method, comprising: generating, by a card comprising a data processor, a communication interface configured for communication with an intermediary device, and a card memory storing a shared secret, a shared authentication key, a session key, message content and a message encryption application comprising instructions for execution by the data processor, a message authentication code using the shared secret and the shared authentication key; encrypting, by the card, at least a portion of the message content and the message authentication code using the session key to generate an encrypted message; and transmitting, by the card to the intermediary device, the encrypted message. 1. A card comprising: a data processor; a communication interface configured for contact or contactless communication with an intermediary processing device; and a card memory having stored therein a shared secret master key and a unique card identifier, and a message encryption application comprising instructions for the data processor to generate a shared secret value using the unique card identifier and the shared secret master key, generate a message authentication code using the shared secret value, encrypt at least a portion of message content using a first session key to produce encrypted message content, encrypt the message authentication code, transmit, to the intermediary processing device for retransmission to a receiving communication processing system, a message comprising the encrypted message content and the encrypted message authentication code. 7. A method of facilitating symmetric encryption communications between a transmitting data processing system having a unique identifier associated therewith and a receiving data processing system, the method comprising: generating, by a key generation data processing system, at least one encryption master key, each encryption master key being configured for use with the unique identifier and a first encryption algorithm to produce a transmitting system-unique encryption key; generating, by the key generation data processing system, a shared secret master key configured for use with the unique identifier and a second encryption algorithm to produce a shared secret value; storing, by the key generation data processing system, the at least one encryption master key and the shared secret master key in association with the unique identifier in an encryption information database; transmitting, by the key generation data processing system, the at least one encryption master key and shared secret information to the transmitting data processing system; and transmitting, by the key generation data processing system, the at least one encryption master key, the shared secret master key, and the unique identifier to the receiving data processing system. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 21-27, 32-34, 38-40 are rejected under 35 U.S.C. 103 as being unpatentable over Lee et al U.S. 6,367,011 B1 in view of Osborn et al U.S. 2020/0111095 A1. Claim 21: Lee et al teaches a card, comprising: a data processor (Lee et al teaches at Fig.6, item 902); a communication interface configured for data communication with an intermediary device (Lee et al teaches at col. 7, ll.48 to col.8, ll.17, -card personalization architecture; a card issued after personalization by an HSM)"); and a card memory storing a shared secret, a shared authentication key, a session key, message content, and a message encryption application comprising instructions for execution by the data processor (Lee et al teaches col.12, ll.26-50 and Fig.5C, data field 620 to be used by a processing module to place the data onto the chip of a smart card. Data 620 may contain data, identifiers, and keys for any number of applications on the card. Application data 620 includes the following information. Application identifier 630 identifies a first application present on the card. Data length 632 indicates the total length of subsequent information for that application including key 634, data 636, a MAC key and the MAC itself. KEK identifier 634 is an identifier for the key encryption key (KEK) used to encrypt any secret data for this first application. In one embodiment, KEK identifier 634 includes an issuer identifier and a version identifier for the KEK. Application data 636 is a variable length field that includes any and all application data needed to personalize a card for a particular application. In one embodiment, a MAC is used along with application data 636. In this embodiment, application data 636 is followed by a key used to compute the MAC. Preferably, this key is encrypted under the KEK. Following this key is the MAC itself which is computed using the fields starting with application identifier 630 up through and including the key used to compute the MAC.Lee et al further teaches col.10, ll.5-15, “secret data includes symmetric keys and representation of the card secret”) wherein, when executed by the data processor, the message encryption application causes the data processor to: generate a message authentication code using the shared secret and the shared authentication key (Lee et al teaches at col.10, ll.5-15, a message authentication code (MAC) is also included along with the MAC key used to compute the MAC, and all secret data (including the MAC key) is encrypted under KEK. In one embodiment, this secret data includes any symmetric keys and a representation of the card secret key), encrypt at least a portion of the message content and the message authentication code using the session key to generate an encrypted message (Lee et al teaches at col.6. ll.10-26, HSM 152 is used to decrypt secret data in output file 160 using a key encryption key, and to encrypt the secret data under a key known to the card (for example, a session key) prior to sending it to the card for personalization. HSM 152 also uses a supplier update key to unlock cards received from the card supplier. Further use of HSM 130 and HSM 152 will be described below), and Lee et al fail to teach, however Osborn et al in the same field of endeavor teaches transmit, to the intermediary device, the encrypted message (Osborn et al teaches at [0063], The transmitting device 205 may then transmit the protected encrypted data, along with the counter value, to the receiving device 210 for processing.). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Lee et al with the additional features of Osborn et al in order to provide techniques for increasing the cryptographic strength of an encryption or message-authentication-code-(MAC) generation technique, as suggested by Osborn et al abstract. Claim 22: the combination teaches wherein the shared secret comprises a shared secret value (Lee et al at col.1, ll.54 to col.2, ll.13). Claim 23: the combination teaches wherein: the card memory further stores a shared secret master key, and the shared secret value is generated using the shared secret master key (Lee et al at col.1, ll.54 to col.2, ll.13). Claim 24: the combination teaches wherein: the card memory further stores a unique card identifier, and the shared secret value is generated using the shared secret master key and the unique card identifier (col.6, ll.56 to col.7, ll.37). Claim 25: the combination teaches wherein: the card memory further stores an account identifier, and the shared secret value is generated using the shared secret master key and the account identifier(Lee et al teaches at col.6. ll.10-26, col.12, ll.27-60). Claim 26: the combination teaches wherein: the card memory further stores a transmission counter, and the shared secret value is generated using the shared secret master key and the transmission counter (Osborn et al teaches at [0105]-[0106]). The same motivation to modify Lee et al in view of Osborn et al applied to claim 23above applies here. Claim 27: the combination teaches wherein the transmission counter is updated for each transmission by the message encryption application (Osborn et al teaches at [0105]-[0106]). The same motivation to modify Lee et al in view of Osborn et al applied to claim 26 above applies here. Claim 32: the combination teaches wherein the communication interface is configured for at least one selected from the group of contact communication with the intermediary device and contactless communication with the intermediary device (Osborn et al teaches at [0042]-[0046]). The same motivation to modify Lee et al in view of Osborn et al applied to claim 31 above applies here. Claim 33: Lee et al teaches a method, comprising: generating, by a card comprising a data processor, a communication interface configured for communication with an intermediary device, and a card memory storing a shared secret, a shared authentication key, a session key, message content and a message encryption application comprising instructions for execution by the data processor, a message authentication code using the shared secret and the shared authentication key (Lee et al teaches at col.10, ll.5-15, a message authentication code (MAC) is also included along with the MAC key used to compute the MAC, and all secret data (including the MAC key) is encrypted under KEK. In one embodiment, this secret data includes any symmetric keys and a representation of the card secret key); encrypting, by the card, at least a portion of the message content and the message authentication code using the session key to generate an encrypted message (Lee et al teaches at col.6. ll.10-26, HSM 152 is used to decrypt secret data in output file 160 using a key encryption key, and to encrypt the secret data under a key known to the card (for example, a session key) prior to sending it to the card for personalization. HSM 152 also uses a supplier update key to unlock cards received from the card supplier. Further use of HSM 130 and HSM 152 will be described below); and Lee et al fail to teach, however Osborn et al in the same field of endeavor teaches transmitting, by the card to the intermediary device, the encrypted message (Osborn et al teaches at [0063], The transmitting device 205 may then transmit the protected encrypted data, along with the counter value, to the receiving device 210 for processing.). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Lee et al with the additional features of Osborn et al in order to provide techniques for increasing the cryptographic strength of an encryption or message-authentication-code-(MAC) generation technique, as suggested by Osborn et al abstract. Claim 34: the combination teaches wherein the shared secret comprises a shared secret master key(Osborn et al teaches at [0094], [0096]-[0097]). The same motivation to modify Lee et al in view of Osborn et al applied to claim 33 above applies here. Claim 38: Lee et al teaches a non-transitory computer readable medium containing instructions for execution by a card, wherein, when executed the instructions cause the card to perform procedures(col.14, ll.17-35, embodiments of the present invention further relate to computer storage products with a computer-readable medium that have computer code thereon for performing various computer-implemented operations) comprising: generating a message authentication code using a shared secret and a shared authentication key(Lee et al teaches at col.10, ll.5-15, a message authentication code (MAC) is also included along with the MAC key used to compute the MAC, and all secret data (including the MAC key) is encrypted under KEK. In one embodiment, this secret data includes any symmetric keys and a representation of the card secret key); encrypting at least a portion of a message content and the message authentication code using a session key to generate an encrypted message (Lee et al teaches at col.6. ll.10-26, HSM 152 is used to decrypt secret data in output file 160 using a key encryption key, and to encrypt the secret data under a key known to the card (for example, a session key) prior to sending it to the card for personalization. HSM 152 also uses a supplier update key to unlock cards received from the card supplier. Further use of HSM 130 and HSM 152 will be described below), and Lee et al fail to teach, however Osborn et al in the same field of endeavor teaches transmitting, to an intermediary device, the encrypted message (Osborn et al teaches at [0063], the transmitting device 205 may then transmit the protected encrypted data, along with the counter value, to the receiving device 210 for processing). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Lee et al with the additional features of Osborn et al in order to provide techniques for increasing the cryptographic strength of an encryption or message-authentication-code-(MAC) generation technique, as suggested by Osborn et al abstract. Claim 39: the combination teaches the procedures further comprising: generating the shared secret value using an encryption counter, a unique card identifier, and the shared secret master key to generate the shared secret value; and incrementing the encryption counter after generating the message authentication code (Osborn et al teaches at [0038], [0043], [0051], [[0106]-[0107]). The same motivation to modify Lee et al in view of Osborn et al applied to claim 38 above applies here. Claim 40: the combination teaches the procedures further comprising: generating a first card-unique encryption key using a unique card identifier and an encryption master key(Osborn et al teaches [0121]); and generating the session key using the first card-unique encryption key (Osborn et al teaches at[0121]). The same motivation to modify Lee et al in view of Osborn et al applied to claim 38 above applies here. Allowable Subject Matter Claims 28-31 and 35-37 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: the prior art or record either alone and in combination fails to the following limitations: “wherein: the card memory further stores a unique card identifier, and the method further comprises: generating, by a key generation data processing system, an encryption master key, the encryption master key being configured for use with the unique card identifier and a first encryption algorithm to produce a transmitting system-unique encryption key; generating, by the key generation data processing system, a shared secret master key configured for use with the unique card identifier and a second encryption algorithm to produce a shared secret value; storing, by the key generation data processing system, the encryption master key and the shared secret master key in association with the unique identifier in an encryption information database; transmitting, by the key generation data processing system, the encryption master key and shared secret information to the card; and transmitting, by the key generation data processing system, the encryption master key, the shared secret master key, and the unique card identifier to the receiving data processing system.” Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to FATOUMATA TRAORE whose telephone number is (571)270-1685. The examiner can normally be reached 6:30-3:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at 5712724219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. Saturday, July 25, 2026 /FATOUMATA TRAORE/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Apr 21, 2025
Application Filed
Jul 29, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706750
KEY STORAGE SYSTEM AND METHOD
1y 10m to grant Granted Aug 11, 2026
Patent 12675578
OPERATIONAL CHARACTERISTIC-BASED CONTAINER MANAGEMENT
3y 0m to grant Granted Jul 07, 2026
Patent 12676741
KEY EXCHANGE SYSTEM, HUB APPARATUS, QKD APPARATUS, METHOD, AND PROGRAM
1y 8m to grant Granted Jul 07, 2026
Patent 12664488
PROVIDING ACCESS TO A PRIVATE RESOURCE IN AN ENTERPRISE SOCIAL NETWORKING SYSTEM
1y 11m to grant Granted Jun 23, 2026
Patent 12641092
METHOD FOR DETERMINING LIKELY MALICIOUS BEHAVIOR BASED ON ABNORMAL BEHAVIOR PATTERN COMPARISON
3y 10m to grant Granted May 26, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+35.2%)
3y 5m (~2y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 585 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month