Prosecution Insights
Last updated: August 17, 2026
Application No. 19/424,359

DEVICE AND METHOD FOR MANAGING ACCESS RIGHTS AND AUTHORIZATIONS

Non-Final OA §101§103§112
Filed
Dec 18, 2025
Priority
Dec 19, 2024 — FR 2414740
Examiner
ZHANG, DUAN
Art Unit
3699
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Commissariat à l'Énergie Atomique et aux Énergies Alternatives
OA Round
1 (Non-Final)
61%
Grant Probability
Moderate
1-2
OA Rounds
2y 4m
Est. Remaining
78%
With Interview

Examiner Intelligence

Grants 61% of resolved cases
61%
Career Allowance Rate
111 granted / 181 resolved
+9.3% vs TC avg
Strong +17% interview lift
Without
With
+16.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
28 currently pending
Career history
203
Total Applications
across all art units

Statute-Specific Performance

§101
27.8%
-12.2% vs TC avg
§103
48.6%
+8.6% vs TC avg
§102
6.1%
-33.9% vs TC avg
§112
14.4%
-25.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 181 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Acknowledgements This Office Action is in response to Applicant’s response/application filed on 12/18/2025. The Examiner notes that citations to United States Patent Application Publication paragraphs are formatted as [####], #### representing the paragraph number. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims Claims 1-16 are currently pending and have been examined. Claim Rejections - 35 USC § 112(b) The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim(s) 1-16 is/are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 recites limitations: “the access to the use of an automaton”, “the supply of…”, “the generation, by…”, “the sending…”, “the validation”, “the authorizing, by… for the use to access the use of the automation”. There is insufficient antecedent basis for these limitations in the claim. For examination purposes examiner has interpreted “the access to the use of an automaton” to be “an access to an automaton”, “the supply of…” to be “supplying…”, “the generation, by…” to be “generating…”, “the sending…” to be “sending…”, “the validation” to be “validating…”, “the authorizing, by… for the use to access the use of the automation” to be “authorizing, by…, to access the automaton”. Dependent claims are also rejected since they inherit this deficiency. Claim 5 recites limitations: “the derivation”, “the Bitcoin Improvement Proposal 32”, “the elliptic curve”, “the cryptographic system”. There is insufficient antecedent basis for this limitation in the claim. For examination purposes examiner has interpreted “the derivation” to be “a derivation”, “the Bitcoin Improvement Proposal 32” to be “a Bitcoin Improvement Proposal 32”, “the elliptic curve” to be “an elliptic curve”, “the cryptographic system” to be “a cryptographic system”. Dependent claims are also rejected since they inherit this deficiency. Claim 6 recites limitations: “the application”. There is insufficient antecedent basis for this limitation in the claim. For examination purposes examiner has interpreted “the application” to be “applying”. Dependent claims are also rejected since they inherit this deficiency. Claim 11 recites limitations: “the access to the use of an automaton”, “the supply…”, “the generation, …”, “the provision…”. There is insufficient antecedent basis for these limitations in the claim. For examination purposes examiner has interpreted “the supply…” to be “supplying…”, “the generation…” to be “generating…”, “the provision…” to be “provisioning…”. Dependent claims are also rejected since they inherit this deficiency. Claim 12 recites limitations: “the first index value”. There is insufficient antecedent basis for these limitations in the claims. For examination purposes examiner has interpreted “the first index value” to be “a first index value…”. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103(a) are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1, 2, 3, 4, 9, 10, 11, 13, 14, 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Galvez (US 20200066072), in view of Zhang (CN 111986764 A), further in view of Higgins (US 20210012331). Regarding claim(s) 1, Galvez discloses: by a first device, of the access to the use of an automaton by a user, the method comprising: - the supply of an identification value, associated with the user, to the first device (By disclosing, “The door controllers 130 are positioned throughout the building 103 at particular access points 120 and control access through the access points 120 based on input such as identification information received from occupants 150 of the building 103 seeking access to the restricted areas. The door controllers 130 receive the identification information, for example, from the occupants 150 engaging with user interface elements of the door controllers 130 (e.g. entering passcodes, swiping keycards, or bringing user devices 152 such as identification badges, contactless smart cards and/or mobile computing devices within range of wireless receivers of the door controllers 130).” ([0033] of Galvez)); and - if the transaction is validated by the blockchain, the authorizing, by the first device, for the user to access the use of the automaton (By disclosing, “Door controllers receive identification information from user devices (e.g. identification badges, mobile computing devices) and send the identification information to the validation network. A predetermined number of responding nodes generate verification information based on authorization information in the transaction ledger. If a predetermined proportion of the responding nodes indicate that the occupant is authorized, access is granted by the door controller.” (Abstract of Galvez)). Galvez does not disclose, but Zhang teaches: - the generation, by a secure circuit of the first device, of an account address based on a master key associated with the first device, on the identification value, and on a context value (By disclosing, “S14 further comprises: receiving the first public key from the user terminal 3; performing hash algorithm to the identity information, signature, the authorization time limit and the first public key to generate an authorized hash [(account address)]; the identity information, signature, the authorization time limit and the authorization hash as the authorization information packet into block, and writing the second blockchain In at least one embodiment of the present invention, the authorization time limit may be one day, from the authorization code to the query end 4 starts timing.” ([0082] of Zhang)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Galvez in view of Zhang to include generation, by a secure circuit of the first device, of an account address based on a master key associated with the first device, on the identification value, and on a context value. Doing so would result in an improved invention because this would allow the transaction information to include more data for the access, such as a validity period for the access. Galvez does not disclose, but Higgins teaches: - the sending of a transaction, comprising a cost value, to the account address in a blockchain; - the validation or invalidation of the transaction by the blockchain based on the balance associated with the account address in the blockchain and on the cost value (By disclosing, “the transaction may also include one or more blockchain addresses of the sender where blockchain currency is currently stored (e.g., where the digital signature proves their access to such currency), as well as an address generated using the sender's public key for any change that is to be retained by the sender. Addresses to which cryptographic currency has been sent that can be used in future transactions are referred to as “output” addresses, as each address was previously used to capture output of a prior blockchain transaction, also referred to as “unspent transactions,” due to there being currency sent to the address in a prior transaction where that currency is still unspent.” ([0022] of Higgins); and “The processing of a blockchain transaction requires a connection to a node in a blockchain network for the proposed transaction to be verified (e.g., to ensure that the payer has enough currency to cover the transaction amount and has the right to use the provided unspent transaction outputs).” ([0004] of Higgins)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Galvez and Zhang, in view of Higgins to include sending of a transaction, comprising a cost value, to the account address in a blockchain; and validation or invalidation of the transaction by the blockchain based on the balance associated with the account address in the blockchain and on the cost value. Doing so would result in an improved invention because this would allow the system to perform a payment transaction for the access. Additionally, regarding claim 14, Galvez does not disclose, but Zhang teaches: a first device comprising a secure circuit having a seed value (SEED) stored therein (By disclosing, “performing hash algorithm to the index data of the user and the first public key to generate a first hash value” ([0019] of Zhang)). Regarding claim(s) 2, Galvez discloses: wherein the authorizing of the access to the use of the automaton comprises the activation of the automaton by the first device (By disclosing, “If the individuals are authorized to enter the restricted areas, then the access control readers allow access to the restricted areas by unlocking locked doors, signaling that doors should be unlocked, and activating elevators. Alarms can be generated upon unauthorized entry.” ([0003] of Galvez)). Regarding claim(s) 3, Galvez does not disclose, but Higgins teaches: wherein the transaction is validated by the blockchain when the account balance associated with the account address is greater than or equal to the cost value (By disclosing, “The processing of a blockchain transaction requires a connection to a node in a blockchain network for the proposed transaction to be verified (e.g., to ensure that the payer has enough currency to cover the transaction amount and has the right to use the provided unspent transaction outputs).” ([0004] of Higgins)). Regarding claim(s) 4, Galvez does not disclose, but Higgins teaches: wherein the transaction is an account-to-account transaction or a transaction towards a smart contract (By disclosing, “the transaction may also include one or more blockchain addresses of the sender where blockchain currency is currently stored (e.g., where the digital signature proves their access to such currency), as well as an address generated using the sender's public key for any change that is to be retained by the sender. Addresses to which cryptographic currency has been sent that can be used in future transactions are referred to as “output” addresses, as each address was previously used to capture output of a prior blockchain transaction, also referred to as “unspent transactions,” due to there being currency sent to the address in a prior transaction where that currency is still unspent.” ([0022] of Higgins)). Regarding claim(s) 9, Galvez does not disclose, but Zhang teaches: wherein the context value corresponds to an encoding of the date of at least one day on which access to the use of the first device is authorized for the user. (By disclosing, “S14 further comprises: receiving the first public key from the user terminal 3; performing hash algorithm to the identity information, signature, the authorization time limit and the first public key to generate an authorized hash [(account address)]; the identity information, signature, the authorization time limit and the authorization hash as the authorization information packet into block, and writing the second blockchain In at least one embodiment of the present invention, the authorization time limit may be one day, from the authorization code to the query end 4 starts timing.” ([0082] of Zhang)). Regarding claim(s) 10, Galvez does not disclose, but Zhang teaches: wherein the context value further comprises an encoding of a time slot or of a geographic location associated with the first device (By disclosing, “S14 further comprises: receiving the first public key from the user terminal 3; performing hash algorithm to the identity information, signature, the authorization time limit and the first public key to generate an authorized hash [(account address)]; the identity information, signature, the authorization time limit and the authorization hash as the authorization information packet into block, and writing the second blockchain In at least one embodiment of the present invention, the authorization time limit may be one day, from the authorization code to the query end 4 starts timing.” ([0082] of Zhang)). Regarding claim(s) 11, Galvez does not disclose, but Zhang teaches: provision, via an external device, at least one coin on the account address in the blockchain by achieving: - the supply, by the first device, of a second public key and of a chain code associated with the first device; - the generation of the account address, by the external device, based on the second public key and on the chain code (By disclosing, “In such embodiments, the external device 104 may transmit the destination address to the computing device 102, or may transmit the external device's public key to the computing device 102 for use in generating a destination address thereby. In other embodiments, the external device 104 may generate a destination address using its public key after receiving the signed blockchain data value, where the external device 104 may include the destination address when submitting the blockchain transaction for verification once online.” ([0029] of Higgins)); and - the provision of at least one coin on the account address in the blockchain (By disclosing, “The blockchain data value may include the received transaction amount, and enough unspent transaction outputs necessary to cover the transaction amount.” ([0027]-[0028] of Higgins)). Regarding claim(s) 13, Galvez discloses: wherein the supply of the identification value to the first device is performed by the user, by presenting a user device having the identification value stored therein, the supply being achieved by near-field communication between the user device and the first device. (By disclosing, “The door controllers 130 are positioned throughout the building 103 at particular access points 120 and control access through the access points 120 based on input such as identification information received from occupants 150 of the building 103 seeking access to the restricted areas. The door controllers 130 receive the identification information, for example, from the occupants 150 engaging with user interface elements of the door controllers 130 (e.g. entering passcodes, swiping keycards, or bringing user devices 152 such as identification badges, contactless smart cards and/or mobile computing devices within range of wireless receivers of the door controllers 130).” ([0033] of Galvez)). Regarding claim(s) 15, Galvez does not disclose, but Higgins teaches: - a blockchain configured to validate or invalidate the transaction sent by the first device, based on the balance associated with the account address in the blockchain and on the cost value (By disclosing, “the transaction may also include one or more blockchain addresses of the sender where blockchain currency is currently stored (e.g., where the digital signature proves their access to such currency), as well as an address generated using the sender's public key for any change that is to be retained by the sender. Addresses to which cryptographic currency has been sent that can be used in future transactions are referred to as “output” addresses, as each address was previously used to capture output of a prior blockchain transaction, also referred to as “unspent transactions,” due to there being currency sent to the address in a prior transaction where that currency is still unspent.” ([0022] of Higgins); and “The processing of a blockchain transaction requires a connection to a node in a blockchain network for the proposed transaction to be verified (e.g., to ensure that the payer has enough currency to cover the transaction amount and has the right to use the provided unspent transaction outputs).” ([0004] of Higgins)); and - an external device configured to generate the account address based on a second public key and on the chain code, supplied by the first device, and to provision at least one coin on the account balance at the account address in the blockchain. (By disclosing, “in step 316, the external device 104 that will be the recipient of the offline blockchain transaction may generate a destination blockchain address using its own public key. In step 318, the external device 104 may transmit its destination address to the computing device 102 using a suitable communication network and method.” ([0050], [0027], [0028] of Higgins)). And Zhang teaches: generate the account address based on the identification value, and on a context value (By disclosing, “S14 further comprises: receiving the first public key from the user terminal 3; performing hash algorithm to the identity information, signature, the authorization time limit and the first public key to generate an authorized hash [(account address)]; the identity information, signature, the authorization time limit and the authorization hash as the authorization information packet into block, and writing the second blockchain In at least one embodiment of the present invention, the authorization time limit may be one day, from the authorization code to the query end 4 starts timing.” ([0082] of Zhang)). Claim(s) 5, 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Galvez (US 20200066072), in view of Zhang (CN 11198764 A), further in view of Higgins (US 20210012331), and Zhou (CN 109067526 A). Regarding claim(s) 5, Galvez does not disclose, but Zhang teaches: - the generation of the account address by applying a hash function to the first public key (By disclosing, “S14 further comprises: receiving the first public key from the user terminal 3; performing hash algorithm to the identity information, signature, the authorization time limit and the first public key to generate an authorized hash [(account address)]; the identity information, signature, the authorization time limit and the authorization hash as the authorization information packet into block, and writing the second blockchain In at least one embodiment of the present invention, the authorization time limit may be one day, from the authorization code to the query end 4 starts timing.” ([0082] of Zhang)). Galvez does not disclose, but Zhou teaches: - the generation of a first key by performing the derivation, by application by the secure circuit of a key derivation function associated with the Bitcoin Improvement Proposal 32 standard, of the master key according to a first index path (PATH1) (By disclosing, using BIP32 to generate a child private key, ([0003], [0019]-[0026] of Zhou)); and - the generation of a first public key (LEAF_PK) by multiplying a first part of the first key with a generator point of the elliptic curve associated with the cryptographic system of the Bitcoin Improvement Proposal 32 standard (By disclosing, generating a child public key by multiplying a child private key and a point of ECC using BIP32 ([0019]-[0026], [0003] of Zhou)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Galvez, Zhang, and Higgins, in view of Zhou to include generation of a first key by performing the derivation, by application by the secure circuit of a key derivation function associated with the Bitcoin Improvement Proposal 32 standard, of the master key according to a first index path (PATH1); and generation of a first public key (LEAF_PK) by multiplying a first part of the first key with a generator point of the elliptic curve associated with the cryptographic system of the Bitcoin Improvement Proposal 32 standard. Doing so would result in an improved invention because this would leverage the advantages of using elliptic curve cryptography (e.g. stronger security with smaller key sizes, higher efficiency and performance, etc.) Regarding claim(s) 16, Galvez does not disclose, but Zhou teaches: wherein the account address is generated by application of a key derivation function associated with the BitCoin Improvement Proposal 32 standard ([0063] of Zhou). Claim(s) 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Galvez (US 20200066072), in view of Zhang (CN 11198764 A), further in view of Higgins (US 20210012331), Zhou (CN 109067526 A), and Xiaohu (CN 118523904A). Regarding claim(s) 8, Galvez does not disclose, but Xiaohu teaches: wherein the master key is a value over 2N bytes, the first key is a value over 2N bytes, and the first part of the first key corresponds to the first N bytes of the first key, N being an integer (By disclosing, “the process shown in FIG. 7. Illustrative, SM3_T_len is developed as SM3 (pk.seed | toByte (0, 64-n) | wotspkADRS | tmp [i], n). Wherein, "| |" is a spliced symbol, toByte (0, 64-n) means that 0 is denoted as 64-n bytes, and FIG. 7 is only illustrated with 64-n bytes as an example, and is not limited. The first parameter (pk.seed), toByte (0, 64-n), and sequentially splicing the address information wotspkADRS and the second element tmp [i] set by the set function to obtain a third splicing result, calculating the hash value corresponding to the third splicing result, and then taking the first n bytes of the hash value as the leaf key.” ([0129] of Xiaohu)). Therefore, it would have been obvious to one of ordinary skill in the art at the effective filing date of the present application to modify the invention of Galvez, Zhang, Higgins, and of Zhou, in view of Xiaohu to include wherein the master key is a value over 2N bytes, the first key is a value over 2N bytes, and the first part of the first key corresponds to the first N bytes of the first key, N being an integer. Doing so would result in an improved invention because this would improve the security of the cryptographic key generation. Allowable Subject Matter Claim(S) 6, 7, 12 would be allowable if rewritten or amended to overcome the rejection(s) under 35 U.S.C. 101 and 35 U.S.C. 112 set forth in this Office action. As per claims 6, 7, and 12, the closest prior art of record, Galvez (US 20200066072) discloses an invention for activating an automaton after validating a transaction by a blockchain network. In addition, Zhang (CN 11198764 A) discloses an invention for generating an account address based on user identification information, a context value, and a public key, In addition, Higgins (US 20210012331) discloses an invention for validating a transaction by a blockchain network based on verifying whether an account of a first user has enough funds to perform the transaction. In addition, Zhou (CN 109067526 A) discloses an invention for generating keys based on BIP32 protocol and elliptic curve algorithem. The closest prior art of record fail to teach or suggest, in the context of the ordered combination of the claims. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20190295342 to Kagaya for disclosing: A control method of controlling, using a distributed ledger, locking or unlocking of one or more storage units, in each of which an item is storable, includes: operating a first smart contract and one or more second smart contracts by a code, stored in the distributed ledger, being executed by a computer, the first smart contract managing the one or more second smart contracts that are in one-to-one correspondence with the one or more storage units; controlling, by each of the one or more second smart contracts, locking or unlocking of a corresponding one of the one or more storage units, the controlling being performed under the management by the first smart contract; and controlling, by the first smart contract, whether to place each of the one or more second smart contracts under the management. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DUAN ZHANG whose telephone number is (571)272-4642. The examiner can normally be reached Mon - Fri 10 AM-5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha Patel can be reached at 571-270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DUAN ZHANG/Primary Examiner, Art Unit 3699
Read full office action

Prosecution Timeline

Dec 18, 2025
Application Filed
Jul 24, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699987
TRANSACTION SYSTEM WITH ACCOUNT MAPPING
6y 8m to grant Granted Aug 04, 2026
Patent 12699990
AUTOMATED APPLICATION PROGRAMMING INTERFACE (API) SYSTEM AND METHOD
1y 6m to grant Granted Aug 04, 2026
Patent 12688499
DEVICE AND SYSTEMS FOR PROVISIONING AND VERIFYING TOKENS WITH STRONG IDENTITY AND STRONG AUTHENTICATION
2y 11m to grant Granted Jul 21, 2026
Patent 12675789
DESTINATION ADDRESSING ASSOCIATED WITH A DISTRIBUTED LEDGER
4y 8m to grant Granted Jul 07, 2026
Patent 12664545
MULTI-INPUT TRANSACTIONS
2y 1m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
61%
Grant Probability
78%
With Interview (+16.9%)
3y 0m (~2y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 181 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month