Prosecution Insights
Last updated: August 17, 2026
Application No. 19/240,354

SECURE SMART CARD SIGNING DIGITAL DOCUMENTS AND VALIDATION

Non-Final OA §101§103
Filed
Jun 17, 2025
Priority
Mar 03, 2022 — continuation of 12/368,593
Examiner
SHEHNI, GHAZAL B
Art Unit
Tech Center
Assignee
Capital One Services LLC
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
943 granted / 1082 resolved
+27.2% vs TC avg
Moderate +13% lift
Without
With
+12.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
20 currently pending
Career history
1103
Total Applications
across all art units

Statute-Specific Performance

§101
13.9%
-26.1% vs TC avg
§103
39.9%
-0.1% vs TC avg
§102
20.1%
-19.9% vs TC avg
§112
11.2%
-28.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1082 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12368593. Although the claims at issue are not identical, they are not patentably distinct from each other because Claims of patent application contain every element of claims above instant application or vice versa, and as such they anticipate or anticipated by Instant Application. As to Claims 1, 8, 14, of the Pat. *593 anticipates the claims of the instant application. By way of illustration, consider the respective claim 1 from each disclosure: Claim 1 of the instant application Claim 1 of the *593 Patent 1. A smart card, comprising: a memory configured to store private key information related to a private key; a communication interface; and a processor coupled to the memory and the communication interface, and configured to: receive a first hash value through the communication interface, wherein the first hash value is generated for an information source based on a first hash function; determine the private key based on the private key information; sign the first hash value by generating a second hash value based on the first hash value using a second hash function, wherein the second hash value is to authenticate that the second hash value is generated by the smart card based on the first hash value and the private key; and assemble a signature package including the second hash value. 5. The smart card of claim 1, wherein: the private key information includes an identifier, a unique derivation key (UDK) associated with a master key, and a counter; the private key is a session key generated based on the UDK, the identifier, and the counter; the second hash value includes a message authentication code (MAC) generated by applying the session key and the second hash function to the first hash value; and the signature package includes the MAC, the identifier, and the counter. 6. The smart card of claim 5, wherein the UDK is generated based on the master key and the identifier that uniquely identifies the smart card. 7. The smart card of claim 5, wherein the session key is generated based on the UDK and the counter. 1. A smart card, comprising: a memory configured to store private key information related to a private key, wherein the private key information comprises a counter indicative of a number of transactions served by the smart card, an identifier that uniquely identifies the smart card, and a unique derivation key (UDK); a communication interface configured to operatively couple the smart card with a computing device; and a processor coupled to the memory and the communication interface, and configured to: receive, from the computing device, a first hash value through the communication interface, wherein the first hash value is generated for an information source based on a first hash function of the computing device; dynamically generate the private key based on the counter, the identifier, and the UDK in response to receiving the first hash value; sign the first hash value by generating a second hash value based on the first hash value using a second hash function of the smart card, wherein the second hash function is to authenticate that the second hash value is generated by the smart card based on the first hash value and the private key; and assemble a signature package including the second hash value. Independent claims 1, 10, 15 of the instant application are substantially similar to independent claims 1, 8, 14, of the Pat. *593 and are rejected for substantially similar reasons as discussed supra. Likewise, dependent claims 2-9, 11-14, 16-20 of the instant application are substantially similar to dependent claims 2-7, 9-13, 15-20 (respectively) of the Pat. *593 and are rejected for substantially similar reasons as discussed supra. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1, 10, 15 recites in part process steps which, receive a first hash value through the communication interface, wherein the first hash value is generated for an information source based on a first hash function; determine the private key based on the private key information; sign the first hash value by generating a second hash value based on the first hash value using a second hash function, wherein the second hash value is to authenticate that the second hash value is generated by the smart card based on the first hash value and the private key; and assemble a signature package including the second hash value, as drafted, under the broadest reasonable interpretation, are a series of mental processes including an observation, evaluation, judgment or opinion that could be performed in the human mind or with the aid of pencil and paper. If a claim, under its broadest reasonable interpretation, covers a mental process or a mathematical concept but for the recitation of generic computer components, then it falls within the "Mental Process" grouping of abstract ideas. Dependent claims 2-9, 11-14, 16-20 also recite an abstract idea. This judicial exception is not integrated into a practical application. In particular, the claim recites – a memory configured to…; a communication interface…, and a processor…. A memory configured to…; a communication interface…, and a processor are recited at a high-level of generality, such that it amounts no more than mere instructions to apply the exception using a generic computer component. As described in MPEP 2106.0S(g), limitations that amount to merely adding insignificant extra-solution activity to a judicial exception cannot integrate a judicial exception into a practical application. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Dependent claims 2-9, 11-14, 16-20 are also directed to a judicial exception. Claims 1-20 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above, determine the private key based on the private key information; sign the first hash value by generating a second hash value based on the first hash value using a second hash function, wherein the second hash value is to authenticate that the second hash value is generated by the smart card based on the first hash value and the private key; and assemble a signature package including the second hash value to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. Claims 1-20 are not patent eligible. Examiner’s note Claims 5-8 (claims 6-8 are depended on claim 5), 14, 18-20 (claims 19-20 are depended on claim 18) are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-4, 9-13, 15-17 are rejected under 35 U.S.C. 103 as being unpatentable over Vilmos (Pub. No. US 2020/0274866) in view of Heimlicher et al (Pub. No. US 2018/0302226). As per claim 1, Vilmos discloses a smart card, comprising: a memory configured to store private key information related to a private key; a communication interface; and a processor coupled to the memory and the communication interface (…the secure storage device is a smart card…comprises a process, a storage unit and a communication interface…the private key is stored in the secure storage unit…see fig.2a, 2b, par. 54-55), and configured to: receive a first hash value through the communication interface, wherein the first hash value is generated for an information source based on a first hash function (…the user authentication data and the data are transmitted to the smart card that is connected to the user device via the smart card interface of the client device…the first hash of the command is generated by the program using a hash algorithm…see par. 54, 88-89); determine the private key based on the private key information (…the user is assigned the smart card which is registered in the user database of the gateway…the asymmetric cryptography key pair is preferably generated in the smart card and the private key is stored in the secure storage of the smart card while the public key may be transmitted to the gateway…see par. 65). Vilmos does not explicitly disclose sign the first hash value by generating a second hash value based on the first hash value using a second hash function, wherein the second hash value is to authenticate that the second hash value is generated by the smart card based on the first hash value and the private key; and assemble a signature package including the second hash value. However Heimlicher discloses sign the first hash value by generating a second hash value based on the first hash value using a second hash function, wherein the second hash value is to authenticate that the second hash value is generated by the smart card based on the first hash value and the private key (…the message of the first certificate may be provided as an input to a particular hash function to generate a fist hash of the first certificate’s message, the first hash may be encrypted using the private key, and the encrypted first hash may be combined with other information to generate the digital signature of the first certificate…the message of the second certificate may be provided as an input to the same hash function to generate a second hash of the second certificate’s message, the second hash may be encrypted sing the private key, and the encrypted second hash may be combined with other information to generate the digital signature of the second certificate…each of the digital signatures may be verified by the computer system using the same public key…see par. 70); and assemble a signature package including the second hash value (…each of the digital signatures may be verified by the computer system using the same public key…with respect to each certificate, the message of the certificate may be provided as input to the same hash function to generate a hash for verification, and the encrypted ash of the certificate may be decrypted using the same public key…if the verification hash matches the decrypted hash, the digital signature may be determined to be valid…see par. 70, 73). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Heimlicher in Vilmos for including the above limitations because one ordinary skill in the art would recognize it would further allows the system to authenticate the multiple hash values …to further facilitate computer assisted authentication of information obtained via one or more connections…see Heimlicher, par. 3-5. As per claim 10, Vilmos discloses a computer-implemented method for a computing device, the method comprising: receiving, from another computing device, a document (…user authentication standard, as FIDO also users asymmetric key encryption, also places the sensitive identifier-the user’s private key, which needs protection, to the client side instead of server side storage…see par. 12); generating a first hash value for the document based on a first hash function; sending the first hash value to a smart card operatively coupled to the computing device (…the user authentication data and the data are transmitted to the smart card that is connected to the user device via the smart card interface of the client device…the client device communicates with the smart card over the smart card interface…see par. 54, 88-89). Vilmos does not explicitly disclose receiving, from the smart card, a signature package, the signature package including a second hash value generated based on the first hash value using a second hash function, the second hash value being used to authenticate that the second hash value is generated by the smart card based on the first hash value and a private key related to private key information stored on the smart card; and assembling a validation package including the signature package to validate that the second hash value is generated by the smart card based on the first hash value and the private key. However Heimlicher discloses receiving, from the smart card, a signature package, the signature package including a second hash value generated based on the first hash value using a second hash function, the second hash value being used to authenticate that the second hash value is generated by the smart card based on the first hash value and a private key related to private key information stored on the smart card (…the message of the first certificate may be provided as an input to a particular hash function to generate a fist hash of the first certificate’s message, the first hash may be encrypted using the private key, and the encrypted first hash may be combined with other information to generate the digital signature of the first certificate…the message of the second certificate may be provided as an input to the same hash function to generate a second hash of the second certificate’s message, the second hash may be encrypted sing the private key, and the encrypted second hash may be combined with other information to generate the digital signature of the second certificate…each of the digital signatures may be verified by the computer system using the same public key…see par. 70); and assembling a validation package including the signature package to validate that the second hash value is generated by the smart card based on the first hash value and the private key (…each of the digital signatures may be verified by the computer system using the same public key…with respect to each certificate, the message of the certificate may be provided as input to the same hash function to generate a hash for verification, and the encrypted ash of the certificate may be decrypted using the same public key…if the verification hash matches the decrypted hash, the digital signature may be determined to be valid…see par. 70, 73). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Heimlicher in Vilmos for including the above limitations because one ordinary skill in the art would recognize it would further allows the system to authenticate the multiple hash values …to further facilitate computer assisted authentication of information obtained via one or more connections…see Heimlicher, par. 3-5. As per claim 15, Vilmos discloses a non-transitory computer-readable medium storing instructions, the instructions, when executed by a processor, cause the processor to perform operations comprising: receiving a first hash value through a communication interface of a smart card, wherein the first hash value is generated for an information source based on a first hash function (…the user authentication data and the data are transmitted to the smart card that is connected to the user device via the smart card interface of the client device…the first hash of the command is generated by the program using a hash algorithm…see par. 54, 88-89); determining a private key based on private key information stored in memory of the smart card (…the user is assigned the smart card which is registered in the user database of the gateway…the asymmetric cryptography key pair is preferably generated in the smart card and the private key is stored in the secure storage of the smart card while the public key may be transmitted to the gateway…see par. 65). Vilmos does not explicitly disclose signing the first hash value by generating a second hash value based on the first hash value using a second hash function, wherein the second hash value is to authenticate that the second hash value is generated by the smart card based on the first hash value and the private key; and assembling a signature package including the second hash value. However Heimlicher discloses signing the first hash value by generating a second hash value based on the first hash value using a second hash function, wherein the second hash value is to authenticate that the second hash value is generated by the smart card based on the first hash value and the private key (…the message of the first certificate may be provided as an input to a particular hash function to generate a fist hash of the first certificate’s message, the first hash may be encrypted using the private key, and the encrypted first hash may be combined with other information to generate the digital signature of the first certificate…the message of the second certificate may be provided as an input to the same hash function to generate a second hash of the second certificate’s message, the second hash may be encrypted using the private key, and the encrypted second hash may be combined with other information to generate the digital signature of the second certificate…each of the digital signatures may be verified by the computer system using the same public key…see par. 70); and assembling a signature package including the second hash value (…each of the digital signatures may be verified by the computer system using the same public key…with respect to each certificate, the message of the certificate may be provided as input to the same hash function to generate a hash for verification, and the encrypted ash of the certificate may be decrypted using the same public key…if the verification hash matches the decrypted hash, the digital signature may be determined to be valid…see par. 70, 73). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Heimlicher in Vilmos for including the above limitations because one ordinary skill in the art would recognize it would further allows the system to authenticate the multiple hash values …to further facilitate computer assisted authentication of information obtained via one or more connections…see Heimlicher, par. 3-5. As per claim 2, the combination of Vilmos and Heimlicher discloses wherein the processor is further configured to: transmit the signature package through the communication interface to a computing device (Heimlicher: see par. 73). The motivation for claim 2 is the same motivation as in claim 1 above. As per claim 3, the combination of Vilmos and Heimlicher discloses wherein the communication interface is operatively coupled to the computing device through a card reader (Vilmos: see par. 126). As per claim 4, the combination of Vilmos and Heimlicher discloses wherein: the private key information includes the private key and a public key corresponding to the private key; the second hash value includes a digital signature generated by applying the private key and the second hash function to the first hash value; and the signature package includes the digital signature and the public key to be used to validate the digital signature (Heimlicher: see par. 70). The motivation for claim 4 is the same motivation as in claim 1 above. As per claim 9, the combination of Vilmos and Heimlicher discloses wherein the communication interface includes a remote radio frequency interface configured to contactlessly read the first hash value (Vilmos: see generating the associated command code and requests the smart card to be touched to the NFC antenna of the mobile device…when the user touches the smart card to the NFC antenna of the mobile phone it will request the PIN of the user…par. 126). As per claim 11, the combination of Vilmos and Heimlicher discloses wherein the sending the first hash value to the smart card comprises: sending the first hash value through a card reader to the smart card (Vilmos: see par. 126). As per claim 12, the combination of Vilmos and Heimlicher discloses transmitting, to another computing device, the validation package for another computing device to validate that the second hash value is generated by the smart card based on the first hash value and the private key (Heimlicher: see par. 70). The motivation for claim 12 is the same motivation as in claim 10 above. As per claim 13, the combination of Vilmos and Heimlicher discloses identifying, in the second hash value, a digital signature generated by applying the private key related to the private key information and the second hash function to the first hash value; and identifying, in the signature package, the digital signature and a public key included in the private key information corresponding to the private key to be used to validate the digital signature (Heimlicher: see par. 70). The motivation for claim 13 is the same motivation as in claim 10 above. As per claim 16, the combination of Vilmos and Heimlicher discloses transmitting the signature package through the communication interface to a computing device (Heimlicher: see par. 73). The motivation for claim 16 is the same motivation as in claim 10 above. As per claim 17, the combination of Vilmos and Heimlicher discloses storing the private key and a public key corresponding to the private key as the private key information; generating a digital signature as the second hash value by applying the private key and the second hash function to the first hash value; and assembling the signature package that includes the digital signature and the public key to be used to validate the digital signature (Heimlicher: see par. 70). The motivation for claim 17 is the same motivation as in claim 10 above. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-form 892). The following Patents and Papers are cited to further show the state of the art at the time of Applicant’s invention with respect to trusted electronic or digital signing of online documents to generate a digital signature. Newman et al (Pub. No. US 2020/0234295); “Systems and Methods for Cryptographic Authentication of Contactless Cards”; -Teaches the private key can be mathematically related to the cryptocurrency address, and is designed so that the cryptocurrency address can be calculated from the private key, par. 198. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GHAZAL B SHEHNI whose telephone number is (571)270-7479. The examiner can normally be reached Mon-Fri 9am-5pm PCT. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GHAZAL B SHEHNI/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Jun 17, 2025
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705405
Read-Only Memory (ROM) Security
2y 10m to grant Granted Aug 11, 2026
Patent 12706737
METHOD FOR ROLE-BASED DATA TRANSMISSION USING PHYSICALLY UNCLONABLE FUNCTION (PUF)-BASED KEYS
2y 0m to grant Granted Aug 11, 2026
Patent 12699773
METHOD AND APPARATUS FOR CLONE SEARCH
2y 10m to grant Granted Aug 04, 2026
Patent 12694157
TERMINAL CHIP AND MEASUREMENT METHOD THEREOF
3y 0m to grant Granted Jul 28, 2026
Patent 12694093
FLEXIBLE AND REUSABLE RULE EVALUATION FOR SECURE EXECUTION OF EXTERNAL COMMANDS
2y 4m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
99%
With Interview (+12.7%)
2y 5m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1082 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month