Prosecution Insights
Last updated: October 04, 2026
Application No. 19/298,964

AUTHENTICATION SYSTEM AND METHOD FOR WINDOWS SYSTEMS

Non-Final OA §103
Filed
Aug 13, 2025
Priority
Feb 14, 2023 — provisional 63/485,002 +1 more
Examiner
RASHID, HARUNUR
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
L'Garde Inc.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
2y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
479 granted / 631 resolved
+17.9% vs TC avg
Strong +36% interview lift
Without
With
+36.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
18 currently pending
Career history
657
Total Applications
across all art units

Statute-Specific Performance

§101
13.3%
-26.7% vs TC avg
§103
61.1%
+21.1% vs TC avg
§102
5.3%
-34.7% vs TC avg
§112
7.4%
-32.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 631 resolved cases

Office Action

§103
DETAILED ACTION 1. Claims 1-23 are pending in this examination. Notice of Pre-AIA or AIA Status 2.1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 2.2. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Specification 3. The Title is objected to because title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed. Claim Objections 4.1. Claims 2-23 are objected to because of the following informalities: 4.2. Each claim begins with a capital letter and ends with a period. Periods may not be used elsewhere in the claims except for abbreviations. Claims contained capital letters (i.e. claim 2, line 1 recites " the method of Claim...). 4.3. Claims 3-23 contains similar language found in claim 2. Appropriate correction is required. Claim Rejections - 35 USC § 103 5.1. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5.2. Claims 1-5, 8-9, 11, 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over US Patent Application No. 20220131857 to Nolte et al (“Nolte”) in view of US Patent Application No. 20140149746 to Yau et al (“Yau”). As per claim 1, Nolte discloses method of accessing an electronic device that is not connected to an authentication server by a user authentication by a multi-factor authentication using a mobile device as one factor and by either authenticating to the mobile device with a biometric or with knowledge as the second factor, the method comprising ([0009] "...method for multi-factor authentication conducted at a software application executing on a user device associated with a user and connected to a server computer..."): transferring an encrypted code to the mobile device from the electronic device without using an authentication server ([0098] "...the software application instance (118A) may receive a challenge from the server computer (102). The challenge may for example be a cryptographic nonce for signing or encryption and returning to the server computer by the software application instance as a challenge-response..."). Nolte does not explicitly disclose however in the same field of endeavor, Yau discloses decrypting by the mobile device the encrypted code to create a decrypted code ([0038]-[0040] "...on the token, decrypting the encrypted authorization and generating at least partially therefrom an unlock response; securely transmitting the unlock response to the mobile device; and unlocking the resource if the received unlock response is valid."), transferring the decrypted code from the mobile device to the electronic device ([0038]-[0040]), using the decrypted code to decrypt an encrypted credential on the electronic device to create a decrypted credential ([0130] "When access is required, the registered App requests the password via the Hoverkey App, which in turns requests the password pe decrypted by the Applet."),; using the decrypted code to decrypt an encrypted credential on the electronic device to create a decrypted credential ([0130] "When access is required, the registered App requests the password via the Hoverkey App, which in turns requests the password pe decrypted by the Applet."); and allowing access to the electronic device by the user with the decrypted credential ([0130]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Nolte with the teaching of Yau by including the feature of code, in order for Nolte’s system to providing data protection and secure access to applications and stored data on a mobile device (such as a phone or tablet) using a near-field communication (NFC) hardware token. User credentials are stored on the token in the form of private keys, and encrypted data and passwords are stored on the device. When application user requires access to the resource an encrypted password is transmitted to and decrypted on the token using a stored private key. An unencrypted data encryption key or password is then transmitted back to the device under the protection of a cryptographic session key which is generated as a result of strong mutual authentication between the device and the token (Yau, abstract). As per claim 2, the combination of Nolte and Yau discloses the method of Claim 1, where a symmetric key is used to encrypt the credential such as a pin or password on the electronic device used to authenticate to the electronic device (Yau, [0058] "The encryption, decryption and/or the mutual authentication may be provided by symmetric key cryptography..."). The motivation regarding the obviousness of claim 1 is also applied to claim 2. As per claim 3, the combination of Nolte and Yau discloses the method of Claim 2, wherein a segment of the symmetric key is encrypted on the electronic device using a public key transmitted from the user's mobile device (Nolte, [0117] "...only the software application instance could have signed/encrypted the challenge in the manner verifiably by the server using the corresponding cryptographic key (public key, in this embodiment) stored in or in association with the user record. Thus, receipt and validation of the challenge-response by the server computer establishes that the user is in possession of the user device on which the software application instance is installed..."). As per claim 4, the combination of Nolte and Yau discloses the method of Claim 3, wherein the public key is transmitted from the user's mobile device through an authentication server during an online authentication session (Nolte, [0087] "...may be configured to generate or obtain its own cryptographic key(s) (such as a public-private keypair, or a symmetric key) and/or a digital certificate (116). This may occur the first time the software application is installed on the user device (104) or the first time the software application instance (118A) connects to the server computer..."). As per claim 5, the combination of Nolte and Yau discloses the method of Claim 3, where the public key of the mobile device is transmitted to the electronic device via Bluetooth, near field technology or manual entry (Nolte, [0088] "...the software application instance transmitting a certificate signing request and associated data elements (including the public key) to the CA..."; [0171] "The external communications interface (830) may further include a contactless element (850), which is typically implemented in the form of a semiconductor chip (or other data storage element) with an associated wireless transfer element..."). As per claim 8, the combination of Nolte and Yau discloses the method of Claim 1, wherein the key pair for creating the shared secret is from a key pair securely stored on the electronic device (Nolte, [0090] "The private key may be stored with configuration for use in signing operations such that data elements can be signed using the private key without the private key actually being retrieved or revealed. The public key may be stored configured for use in verifying operations."). As per claim 9, the combination of Nolte and Yau discloses the method of Claim 1, wherein the encrypted code is decrypted using a private key stored securely on the user mobile device (Nolte, [0202] "When the password is required, the PEK stored in the NFC token is used to verify decrypt the protected passwords."; [0089] "...user credentials stored on the token may comprise a private cryptographic key."). As per claim 11, the combination of Nolte and Yau discloses the method of Claim 1, wherein the encrypted code is transferred to the user mobile device electronically (Nolte, [0098]). As per claim 14, the combination of Nolte and Yau discloses the method of Claim 1, wherein the encrypted code is decrypted on the user's mobile device and electronically transferred to the electronic device (Yau, [0038]-[0040]). The motivation regarding the obviousness of claim 1 is also applied to claim 14. As per claim 15, the combination of Nolte and Yau discloses the method of Claim 14, wherein Bluetooth or near field technology are used to transfer the encrypted code (Nolte, [0098], [0171]). 5.3. Claims 6-7, 12, 21 are rejected under 35 U.S.C. 103 as being unpatentable over Nolte and Yau as applied to claim above, and in view of US Patent Application No. 20130013931 to O'Hare et al (“O'Hare”). As per claim 6, the combination of Nolte and Yau discloses the invention as described above, including where the encrypted code is created using ECEIS and symmetric cryptography (Yau, [0058]). The motivation regarding the obviousness of claim 1 is also applied to claim 6. Nolte and Yau do not explicitly disclose however, In the same field of endeavor, O'Hare discloses using a shared secret key created by using the private key of a key pair created on the electronic device (O'Hare, [0513] "...the adversary still cannot learn anything about the shared secret if it lacks the secret key."). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Nolte with the teaching of Yau/ O'Hare by including the feature of code, in order for Nolte’s system for securely sharing data and accessing securely shared data. In some aspects, a method for securely sharing data is provided, the method steps implemented by a programmed computer system. Two or more shares of an encrypted data set are formed. The encrypted data set is representative of a data set associated with a first user device and is encrypted with a symmetric key. Each encrypted data set share includes a portion of data from the encrypted data set, and the two or more encrypted data set shares are caused to be stored separately from each other in at least one storage location. The at least one storage location may include a cloud computing storage location. A first encrypted key is generated by encrypting data indicative of the symmetric key with a first asymmetric key of a first asymmetric key pair associated with the first user device. A second encrypted key is generated by encrypting data indicative of the symmetric key with a first asymmetric key of a second asymmetric key pair associated with a second user device. In some implementations, the method includes accessing the first asymmetric key of the second asymmetric key pair from a registration server prior to generating the second encrypted key. The first and second encrypted keys are caused to be stored in the at least one storage location, which is remote to both the first and second user devices. To restore the data set, a predetermined number of the two or more encrypted data set shares and at least one of a second asymmetric key of the first asymmetric key pair and a second asymmetric key of the second asymmetric key pair are needed. (O'Hare, [0002]). As per claim 7, the combination of Nolte and Yau and O'Hare disclose the method of Claim 6, wherein the key pair for creating the shared secret is created at the time of the offline authentication request (Nolte, [0087]). As per claim 12, the combination of Nolte, Yau and O'Hare discloses the method of Claim 7, wherein Bluetooth or near field technology are used to transfer the encrypted code (O'Hare, [0098], [0171]). The motivation regarding the obviousness of claim 6 is also applied to claim 12. As per claim 21, the combination of Nolte, Yau and O'Hare discloses the method of Claim 1 where before encrypting the string of key segment bytes displayed on the first electronic device, the key segment string is created by concatenating the set of bytes removed from the symmetric key with placeholders inserted to buffer the bytes so that when the key segment string is decrypted and returned to the electronic device it can be properly parsed (O'Hare, [0432] "...parsing and splitting may be randomly or pseudo-randomly processed on a bit by bit basis. A random or pseudo-random value may be used (e.g., session key, cipher feedback session key, etc.) whereby for each bit in the original data, the result of a hash function on corresponding data in the random or pseudo-random value may indicate to which share to append the respective bit. In one suitable approach the random or pseudo-random value may be generated as, or extended to, 8 times the size of the original 'data so that the hash function may be performed on a corresponding byte of the random or pseudo-random value with respect to each bit of the original data..."). It would have been obvious to one of ordinary skill in the art to combine the teachings of Enter, YAU, and O'Hare because original data may be secured by appending randomly generated padding/placeholder data ([0432]). The motivation regarding the obviousness of claim 6 is also applied to claim 21. 5.4. Claims 10, 13, 16-20 and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Nolte and Yau as applied to claim above, and in view of US Patent Application No. 20130185778 to Tamai et al (“Tamai”). As per claim 10, the combination of Nolte and Yau discloses the invention as described above, including the encrypted code is transferred to the mobile device (Nolte, [0098]). Nolte and Yau do not explicitly disclose however, In the same field of endeavor, Tamai discloses by means of a QR code ([0041] "...display a presentation pattern..."). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Nolte with the teaching of Yau/ Tamai by including the feature of code, in order for Nolte’s system to avoid fraudulent authentication using stolen password. Provided is an off-line two-factor user authentication system with a reduced risk of leakage of authentication information. The two-factor user authentication system is designed to use, as a password, a one-time-password derivation rule to be applied to certain pattern elements included in a presentation pattern at specific positions so as to create a one-time password, and further use, as a second authentication factor, information identifying a client to be used by a user. A plurality of pattern seed values each adapted to uniquely specify a presentation pattern in combination with a client ID, and a plurality of verification codes corresponding to respective ones of the pattern seed values, are stored in an off-line two-factor authentication client. A presentation pattern is created based on a selected one of the pattern seed values and a client ID, and an entered one-time password is verified based on a verification code corresponding to the selected pattern seed value. (Tamai, abstract). As per claim 13, the combination of Nolte and Yau discloses the method of Claim 1, wherein the encrypted code is decrypted on the user's mobile device Yau, [0038]-[0040]). The motivation regarding the obviousness of claim 1 is also applied to claim 13. Nolte and Yau do not explicitly disclose however, In the same field of endeavor, Tamai discloses visually displayed on the user's mobile device and transferred to the electronic device by means of a keyboard ([0051] "...verification codes 193 are created in the same number as that of creatable or displayable presentation patterns 191, and pre-stored in the off-line two-factor authentication client 151. During user authentication in the off-line two-factor authentication client 151, a value obtained by subjecting an entered one-time password 192 to the same one-way function algorithm as that used for creating the verification codes 193 is compared with one of the verification codes 191 corresponding to a presented presentation pattern..."). It would have been obvious to one of ordinary skill in the art to combine the teachings of Enter, YAU, and Tamai because scanning a presentation pattern such as a QR code can be used to transfer information between devices ([0003]). The motivation regarding the obviousness of claim 10 is also applied to claim 13. As per claim 16, the combination of Nolte, Yau and Tamai the method of Claim 13 wherein the decrypted code is used on the electronic device to recreate the symmetric key originally used to encrypt the token (Tamai, [0006] "...data indicative of the symmetric key is restored by decrypting the first encrypted key using a second asymmetric key..."). The motivation regarding the obviousness of claim 10 is also applied to claim 16. As per claim 17, the combination of Nolte, Yau and Tamai the method of Claim 16 wherein the encrypted token is decrypted with the symmetric key and used to log into the electronic device (Yau, [0202], [0130]). The motivation regarding the obviousness of claim 1 is also applied to claim 17. As per claim 18, the combination of Nolte, Yau and Tamai discloses the method of Claim 1 wherein the mobile device can detect if the electronic device being accessed is offline based on the data transferred to the mobile device during a login attempt (Tamai, [0087] "...In the network logon authentication for authorizing a user to use the off-line two-factor authentication client 151 in the online state, the requesting-user ID is senfto the verification-data request section 153, and transmitted together with a verification-data request..."). The motivation regarding the obviousness of claim 10 is also applied to claim 18. As per claim 19, the combination of Nolte, Yau and Tamai the method of Claim 18 wherein the mobile device processes the transferred data and determines if it is to be used for online of offline use (Tamai, [0087]). The motivation regarding the obviousness of claim 10 is also applied to claim 19. As per claim 20, the combination of Nolte, Yau and Tamai the method of Claim 1 wherein the mobile device does not have an online connection (Tamai, [0035] "...serving as an off-line two-factor authentication client 151 which is a terminal capable of authenticating each of the users in an off-line state of being not network-connected although being connectable to the off-line authentication support server..."). The motivation regarding the obviousness of claim 10 is also applied to claim 20. As per claim 23, the combination of Nolte, Yau and Tamai the method of Claim 1, wherein the encrypted code is changed after a successful log in to the first electronic device (Tamai, [0055] "...a one-time-password derivation rule 102 bis used as a password of a user subject to authentication..."). The motivation regarding the obviousness of claim 10 is also applied to claim 23. 5.6. Claim 22 is rejected under 35 U.S.C. 103 as being unpatentable over Nolte, Yau and Tamai as applied to claim above, and in view of US Patent Application No. 20130013931 to O'Hare et al (“O'Hare”). As per claim 22, the combination of Nolte, Yau and Tamai discloses the invention as described above. Nolte, Yau and Tamai do not explicitly disclose however, In the same field of endeavor, O'Hare discloses the method of Claim 20 where after the decrypted string is entered into the first electronic device, the buffer placeholders are removed to obtain the original bytes to recreate the symmetric key used to decrypt the encrypted, protected token (O'Har, [0432], [0006]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Nolte with the teaching of Yau/ Tamai/ O'Hare by including the feature of key, in order for Nolte’s system It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Nolte with the teaching of Yau/ O'Hare by including the feature of code, in order for Nolte’s system for securely sharing data and accessing securely shared data and restore the data set, a predetermined number of the two or more encrypted data set shares and a second asymmetric key of at least one of the plurality of asymmetric key pairs are needed to restore the data set.. In some aspects, a method for securely sharing data is provided, the method steps implemented by a programmed computer system. Two or more shares of an encrypted data set are formed. The encrypted data set is representative of a data set associated with a first user device and is encrypted with a symmetric key. Each encrypted data set share includes a portion of data from the encrypted data set, and the two or more encrypted data set shares are caused to be stored separately from each other in at least one storage location. The at least one storage location may include a cloud computing storage location. A first encrypted key is generated by encrypting data indicative of the symmetric key with a first asymmetric key of a first asymmetric key pair associated with the first user device. A second encrypted key is generated by encrypting data indicative of the symmetric key with a first asymmetric key of a second asymmetric key pair associated with a second user device. In some implementations, the method includes accessing the first asymmetric key of the second asymmetric key pair from a registration server prior to generating the second encrypted key. The first and second encrypted keys are caused to be stored in the at least one storage location, which is remote to both the first and second user devices. To restore the data set, a predetermined number of the two or more encrypted data set shares and at least one of a second asymmetric key of the first asymmetric key pair and a second asymmetric key of the second asymmetric key pair are needed. (O'Hare, [0002]). 6..1 The prior art made of record and not relied upon is considered pertinent to applicant's disclosure as the prior art discloses many of the claim features (See PTO-form 892). 6.2. US Patent Application No. 20190124081 to Nowak et al., discloses FIDO (“Fast IDentity Online”) authentication processes and systems are described. In an embodiment, a FIDO information systems (IS) computer system receives a FIDO authentication request for a transaction from a user device, which includes user data and user device authenticator data. The FIDO IS computer system then verifies the user data and user device authenticator data, selects a FIDO-certified server, transmits the FIDO authentication request to the selected FIDO server, and receives a challenge message from the selected FIDO-certified server. The FIDO IS computer system next transmits the challenge message to the user device, receives a FIDO authentication response, transmits the FIDO authentication response to the selected FIDO-certified server, receives an authentication result from the FIDO-certified server, and transmits the authentication result to the user device. Conclusion 7. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARUNUR RASHID whose telephone number is (571)270-7195. The examiner can normally be reached 9 AM to 5PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. HARUNUR . RASHID Primary Examiner Art Unit 2497 /HARUNUR RASHID/Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Aug 13, 2025
Application Filed
Sep 10, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730921
AUTOMATED IDENTIFICATION OF SENSITIVE DATA ACCESS BASED ON SOURCE-CODE ANALYSIS
1y 9m to grant Granted Sep 08, 2026
Patent 12711501
ASSOCIATING MULTIPLE USER ACCOUNTS WITH A CONTENT OUTPUT DEVICE
1y 8m to grant Granted Aug 18, 2026
Patent 12712745
Communication Method and Related Device
1y 6m to grant Granted Aug 18, 2026
Patent 12706945
Network Environment Control Scanning Engine
1y 8m to grant Granted Aug 11, 2026
Patent 12701003
MACHINE LEARNING FOR AUTOMATIC IDENTIFICATION OF POINTS OF INTEREST FOR SIDE CHANNEL LEAKAGE
1y 8m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+36.2%)
3y 4m (~2y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 631 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month