Prosecution Insights
Last updated: October 02, 2026
Application No. 17/715,835

Secure Artificial Neural Network Models in Outsourcing Deep Learning Computation

Non-Final OA §101§103
Filed
Apr 07, 2022
Examiner
KIM, HARRISON CHAN YOUNG
Art Unit
2145
Tech Center
2100 — Computer Architecture & Software
Assignee
Micron Technology Inc.
OA Round
3 (Non-Final)
56%
Grant Probability
Moderate
3-4
OA Rounds
0m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 56% of resolved cases
56%
Career Allowance Rate
9 granted / 16 resolved
+1.3% vs TC avg
Strong +38% interview lift
Without
With
+37.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
13 currently pending
Career history
43
Total Applications
across all art units

Statute-Specific Performance

§101
37.9%
-2.1% vs TC avg
§103
48.5%
+8.5% vs TC avg
§102
4.7%
-35.3% vs TC avg
§112
8.3%
-31.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 16 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is made non-final. Claims 1-20 are pending. Claims 1, 14 and 19 are independent claims. Response to Arguments Applicant's arguments filed on 1/12/2026, regarding 35 U.S.C. 103 rejections, have been fully considered but are not persuasive. However, applicant’s amendments necessitate new grounds of rejection – see the updated 103 rejections below. Applicant's arguments filed on 1/12/2026, regarding 35 U.S.C. 101 rejections, have been fully considered but are not persuasive. Applicant argues that the claimed inventions are directed to a certain technology and the abstract idea limitations are only a “small part” of the invention. Examiner argues that the degree of importance of a specific limitation does not influence the step 2A prong 1 analysis, which is based on determining if a judicial exception is recited. The evaluation of whether or not the judicial exception is integrated into a practical application occurs in the Step 2A prong 2 section of the 101 analysis. The applicant also argues that a person is not capable of performing computations of an artificial neural network model in the human mind. The examiner argues that given parts of a neural network model and inputs to those parts, a human is capable of performing the necessary mathematical calculations to determine the outputs mentally or with the aid of pen and paper. The examiner further argues that the division of a model into parts (the interpretation of “parts” encompasses simple linear operations, layers, as well as more narrow interpretations that include processes like additive splitting) can be performed mentally. In the process of setting up a neural network to be run on a computer, a human must consider the model parts (i.e., layer weights) and configure them properly. The examiner also notes that, as stated in MPEP 2106.05(a) ¶6, the improvement cannot be provided by the judicial exception alone. See the updated 101 rejection below. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Regarding claims 1-18: Step 1: This part of the eligibility analysis evaluates whether the claim falls within any statutory category. See MPEP 2106.03. Claim 1 recites: A method, comprising... Claim 1 is directed to a process (Step 1: YES). Step 2A prong 1: Does the claim recite a judicial exception? Claim 1 recites: generating… a plurality of first model parts to represent an artificial neural network model (generating model parts to represent an neural network is a mentally performable process that involves mathematical calculations, i.e., defining layer wise connections, activation functions); generating… a plurality of computing tasks, each of the computing tasks including performing a computation of a model part responsive to an input, the computing tasks including performing computations of the first model parts (generating computing tasks is interpreted to mean linking model parts with corresponding inputs, i.e., a mathematical calculation); shuffling… the computing tasks to obscure the artificial neural network model (shuffling can be performed with a mathematical algorithm or is a mental process based on the broadest reasonable interpretation (BRI) of shuffling – reordering in an unpredictable or chaotic way) and randomize the first model parts in distribution of the computing tasks to external entities (randomizing model parts, interpreted to be a an splitting operation involving random numbers or encryption)… and obtaining… a result of a computation of the artificial neural network model (obtaining a result of a computation is a mathematical calculation or a series of calculations). These steps recite mathematical calculations and/or mental processes (Step 2A prong 1: YES). Step 2A prong 2: Does the claim recite additional elements? Do those additional elements, considered individually and in combination, integrate the judicial exception into a practical application? Claim 1 recites: by a computing device... by the computing device… by the computing device… receiving, by the computing device and from the external entities, results of performing the computing tasks… by the computing device based on the results received from the external entities… Transmitting and receiving calculations and calculation results is well-understood, routine and conventional activity as described in MPEP 2106.05(d)(II)(i). Performing limitations that have a BRI that encompasses mathematical calculations or mental processes on a generic computing device is recited at a high level of generality and does not amount to significantly more than the abstract idea – similar to adding the words “apply it” to the recited judicial exception (see MPEP 2106.05(f)) (Step 2A prong 2: NO). Step 2B: These tasks are recited at such a high level of generality that they fail to integrate the abstract idea into a practical application, since they only amount to well-understood, routine and conventional (WURC) activity (MPEP 2106.05(d)) or mere application of the judicial exception using generic computer components (MPEP 2106.05(f)). These limitations, taken either alone or in combination, fail to provide an inventive concept (Step 2B: NO). Thus, the claim is not patent eligible. Further, claims 2-13 recite limitations which further narrow the abstract idea by specifying more details of the mental/mathematical process that occurs (Claim 2, identifying a subset of computation results is a mental process; Claim 3, generating random numbers involves a mathematical algorithm, and subtracting random numbers from model parts is a mathematical calculation; Claim 4, excluding the external entities from receiving one or more model parts is a mental process; Claim 5, having the sum of a subset of results be equivalent to the original neural network is still a mental process, Claim 6, generating another set of model parts by offsetting is still a mental or mathematical process; Claim 7, bitwise shifting, addition and multiplication are mathematical formulas; Claim 8, reversing the offsetting is using mathematical formulas; Claim 9, encrypting data is organizing it using mathematical correlations; Claim 10, decrypting data would also involve the use of mathematical correlations; Claim 11, splitting data samples into parts is a mental or mathematical process; Claim 12, preventing external entities from receiving at least one model and sample part is a mental process; Claim 13, generating and transforming sample parts consists of mathematical calculations). Regarding claim 14, Step 1: This part of the eligibility analysis evaluates whether the claim falls within any statutory category. See MPEP 2106.03. Claim 14 recites: A computing device, comprising: memory; and at least one microprocessor coupled to the memory and configured via instructions to… Claim 14 is directed to an apparatus (Step 1: YES). Step 2A prong 1: Does the claim recite a judicial exception? Claim 14 recites: generate a plurality of first model parts to represent an artificial neural network model (generating model parts to represent an neural network is a mentally performable process that involves mathematical calculations, i.e., defining layer wise connections, activation functions); generate a plurality of computing tasks, each of the computing tasks including performing a computation of a model part responsive to an input, the computing tasks including performing computations of the first model parts (generating computing tasks is interpreted to mean linking model parts with corresponding inputs, i.e., a mathematical calculation); and obscure the artificial neural network model via shuffling the computing tasks… to randomize the first model parts received by the external entities (shuffling can be performed with a mathematical algorithm or is a mental process based on the BRI of shuffling – shuffling naturally leads to entities receiving random parts, analogous to shuffling and dealing a deck of cards). These limitations can be performed mentally or are mathematical calculations (Step 2A prong 1: YES). Step 2A prong 2: Does the claim recite additional elements? Do those additional elements, considered individually and in combination, integrate the judicial exception into a practical application? Claim 14 recites: in distribution of the computing tasks to external entities… Transmitting and receiving data by a computer is well-understood, routine and conventional activity as described in MPEP 2106.05(d)(II)(i) (Step 2A prong 2: NO). Step 2B: These tasks are recited at such a high level of generality that they fail to integrate the abstract idea into a practical application, since they only amount to since they only amount to well-understood, routine and conventional (WURC) computer activity (MPEP 2106.05(d)). This limitation fails to provide an inventive concept (Step 2B: NO). Thus, the claim is not patent eligible. Further, claims 15-18 recite limitations which further narrow the abstract idea by specifying more details of the mental/mathematical process that occurs (Claim 15, receiving results of computation and identifying a relevant subset is a mental process, while aggregating them is a mathematical calculation; Claim 16, preventing external entities from receiving one or more model parts is a mental process; Claim 17, splitting data into parts is a mental or mathematical process; Claim 18, preventing external entities from receiving one or more sample parts is a mental process). Regarding claim 19, Step 1: This part of the eligibility analysis evaluates whether the claim falls within any statutory category. See MPEP 2106.03. Claim 19 recites: A non-transitory computer storage medium storing instructions which, when executed in a computing device, cause the computing device to perform a method, comprising… Claim 19 is directed to an apparatus (Step 1: YES). Step 2A prong 1: Does the claim recite a judicial exception? Claim 19 recites: each of the computing tasks including performing a computation of a model part responsive to an input, the computing tasks including performing first computations of a plurality of first model parts derived from an artificial neural network model and second computations of second model parts; and obtaining… a result of a computation of the artificial neural network model. These limitations can be performed mentally or are mathematical calculations (Step 2A prong 1: YES). Step 2A prong 2: Does the claim recite additional elements? Do those additional elements, considered individually and in combination, integrate the judicial exception into a practical application? Claim 19 recites receiving, by the computing device and from external entities, results of performing computing tasks… by the computing device based on the results received from the external entities. Transmitting and receiving data by a computer is well-understood, routine and conventional activity as described in MPEP 2106.05(d)(II)(i) (Step 2A prong 2: NO). Step 2B: These tasks are recited at such a high level of generality that they fail to integrate the abstract idea into a practical application, since they only amount to since they only amount to well-understood, routine and conventional (WURC) computer activity (MPEP 2106.05(d)). This limitation fails to provide an inventive concept (Step 2B: NO). Thus, the claim is not patent eligible. Further, claim 20 recites limitations which further narrow the abstract idea by specifying more details of the mental/mathematical process that occurs – splitting the neural network into parts and distributing the parts are mental processes and aggregating the subset of results is a mathematical calculation. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, 3, 6, 7, 8, 14, 15, 19 and 20 are rejected under 35 U.S.C. 103 as being unpatentable Chen et al. (US 20220114014 A1), herein Chen in view of Pham et al. (US 20230133800 A1), herein Pham. Regarding claim 1, Chen teaches: A method, comprising: generating, by a computing device, a plurality of first model parts to represent an artificial neural network model (fig. 6, 608 discusses splitting of weights, an example of which is shown in fig. 7, 400); generating, by the computing device, a plurality of computing tasks, each of the computing tasks including performing a computation of a model part responsive to an input, the computing tasks including performing computations of the first model parts (¶81, As shown in FIG. 7, this example of additive splitting thus creates two matrices W1 and W2 that can both be passed to the non-TEE 404 for heavier computations, such as for use by the accelerator 410. In some embodiments, the accelerator 410 can perform heavier computations such as matrix multiplications by multiplying both W1 and W2 separately with an input vector X – note: TEE stands for “trusted execution environment”)… and randomize the first model parts in distribution of the computing tasks to external entities (¶81, For example, to perform additive splitting, the processor within the TEE 402, for each entry w in the weight matrix or vector, randomly splits each entry w into two or more parts whose sum is w – ¶39, The memory 130 can also include a secure storage area used by a TEE that is inaccessible to entities operating in the non-TEE – the non-trusted execution environment that receives obfuscated data is described as involving multiple entities); receiving, by the computing device and from the external entities, results of performing the computing tasks (¶83, The non-TEE 404 passes Z′ and Z″ to the TEE 402 to perform recovery of the real output Z); and obtaining, by the computing device based on the results received from the external entities, a result of a computation of the artificial neural network model (fig. 7, item labeled recovery, involving the aggregation of the additive parts). Chen fails to teach: shuffling, by the computing device, the computing tasks to obscure the artificial neural network model… However, in the same field of endeavor, Pham teaches: shuffling, by the computing device, the computing tasks to obscure the artificial neural network model (¶44, For example, by randomizing the order, data received from the two data sources 102, 103 may be mixed together in such a way that it may be more difficult to determine which source sent a particular piece of data)… Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to shuffle computing tasks as disclosed by Pham in the method disclosed by Chen to improve privacy (¶44, The randomization of the order in which the rows or columns are included as part of the example aggregation data 205 may improve data privacy). Regarding claim 2, Chen further teaches: The method of claim 1, further comprising: identifying, by the computing device, a subset of the results corresponding to the computations of the first model parts, wherein the result of the computation of the artificial neural network model is based on the subset; wherein a sum of the first model parts is equal to the artificial neural network model (¶81, For example, to perform additive splitting, the processor within the TEE 402, for each entry w in the weight matrix or vector, randomly splits each entry w into two or more parts whose sum is w.). Regarding claim 3, Chen further teaches: The method of claim 2, further comprising: generating, by the computing device, random numbers as numbers in at least one of the first model parts, wherein one of the first model parts is generated from subtracting a sum of a subset of the first model parts from the artificial neural network model (¶81, For example, to perform additive splitting, the processor within the TEE 402, for each entry w in the weight matrix or vector, randomly splits each entry w into two or more parts whose sum is w. For instance, w can be split into two parts such that w=w1+w2. In some embodiments, this can be done once and stored in the secure storage to reduce overhead. In this example, to generate w1, the processor randomly chooses a real number as w1 within a predetermined range). Regarding claim 6, Chen further teaches: The method of claim 1, further comprising: generating, by the computing device, a plurality of second model parts, a sum of the second model parts being equal to the artificial neural network model; and offsetting, by the computing device, at least a portion of the second model parts to generate the first model parts, wherein a sum of the first model parts is not equal to the artificial neural network model (¶84, Turning back to FIG. 6, other example techniques for obfuscating the model parameters or inputs can include multiplicative splitting, individual linear transformation… To perform individual linear transformation, for each entry w of the matrix or vector, the processor changes the entry w into aw+b. Similar to choosing the random values for W1 as in additive or multiplicative splitting, a and b can be chosen such that aw+b is not too big or too small. Special cases can also be used, such as setting a=1 or b=0, so that each entry w is changed into w+b or aw, respectively – offsetting model parts by adding a nonzero value (i.e., b) would result in the additive property of the model parts being broken). Regarding claim 7, Chen further teaches: The method of claim 6, wherein the offsetting includes bit-wise shifting, adding a constant, or multiplying a constant, or any combination thereof (¶84, Turning back to FIG. 6, other example techniques for obfuscating the model parameters or inputs can include multiplicative splitting, individual linear transformation… To perform individual linear transformation, for each entry w of the matrix or vector, the processor changes the entry w into aw+b. Similar to choosing the random values for W.sub.1 as in additive or multiplicative splitting, a and b can be chosen such that aw+b is not too big or too small. Special cases can also be used, such as setting a=1 or b=0, so that each entry w is changed into w+b or aw, respectively). Regarding claim 8, Chen further teaches: The method of claim 7, further comprising: applying, by the computing device, reverse offsetting to results corresponding to the portion of the second model parts in obtaining the result of the computation of the artificial neural network model (¶85, the processor delegates matrix multiplication, convolution, or other computation-heavy operations to the non-TEE, such as the accelerator 410, and provides the obfuscated weights and any obfuscated input data to the non-TEE. In some embodiments, the first layer inputs are not obfuscated. At block 612, the processor receives the computation results from the non-TEE. At block 614, the processor de-noises or recovers the results by recombining the split values and/or reversing the perturbations). Regarding claim 14, Chen teaches: A computing device, comprising: memory; and at least one microprocessor coupled to the memory and configured via instructions to (Abstract, An electronic device includes at least one transceiver, at least one memory, and at least one processor coupled to the at least one transceiver and the at least one memory): generate a plurality of first model parts to represent an artificial neural network model (¶81, For example, to perform additive splitting, the processor within the TEE 402, for each entry w in the weight matrix or vector, randomly splits each entry w into two or more parts whose sum is w); generate a plurality of computing tasks, each of the computing tasks including performing a computation of a model part responsive to an input, the computing tasks including performing computations of the first model parts (¶81, As shown in FIG. 7, this example of additive splitting thus creates two matrices W1 and W2 that can both be passed to the non-TEE 404 for heavier computations, such as for use by the accelerator 410. In some embodiments, the accelerator 410 can perform heavier computations such as matrix multiplications by multiplying both W1 and W2 separately with an input vector X)… Chen fails to explicitly teach: and obscure the artificial neural network model via shuffling the computing tasks in distribution of the computing tasks to external entities to randomize the first model parts received by the external entities. However, in the same field of endeavor, Pham teaches: and obscure the artificial neural network model via shuffling the computing tasks (¶44, For example, by randomizing the order, data received from the two data sources 102, 103 may be mixed together in such a way that it may be more difficult to determine which source sent a particular piece of data) in distribution of the computing tasks to external entities to randomize the first model parts received by the external entities (¶45, The computing platform 110 may determine to send selected data to all or only some of the data sources. For example, as depicted in FIG. 1, both of the two data sources 102, 103 are shown as being sent selected data… The first selected data 113 may be determined by performing the first selecting process 110-2 that, for each cell of the aggregated data 111, determines whether to select or not select that cell for inclusion in the first selected data 113… Determining whether to select or not select a cell for inclusion may be performed in a randomized fashion). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to shuffle computing tasks as disclosed by Pham in the method disclosed by Chen to improve privacy (¶44, The randomization of the order in which the rows or columns are included as part of the example aggregation data 205 may improve data privacy). Regarding claim 15, Chen further teaches: The computing device of claim 14, wherein the at least one microprocessor is further configured via the instructions to: receive, from the external entities, results of performing the computing tasks; identify, by the computing device, a subset of the results corresponding to the computations of the first model parts; and obtain, by the computing device based on operating on the subset, a result of a computation of the artificial neural network model (¶83, The non-TEE 404 passes Z′ and Z″ to the TEE 402 to perform recovery of the real output Z). Regarding claim 19, Chen teaches: A non-transitory computer storage medium storing instructions which, when executed in a computing device, cause the computing device to perform a method, comprising (Abstract, An electronic device includes at least one transceiver, at least one memory, and at least one processor coupled to the at least one transceiver and the at least one memory): receiving, by the computing device and from external entities, results of performing computing tasks, each of the computing tasks including performing a computation of a model part responsive to an input, the computing tasks including performing first computations of a plurality of first model parts derived from an artificial neural network model and second computations of second model parts, wherein the artificial neural network model is obscure to the external entities (¶81, For example, to perform additive splitting, the processor within the TEE 402, for each entry w in the weight matrix or vector, randomly splits each entry w into two or more parts whose sum is w – additive splitting results in an obscure model – the device receives outputs from other entities that are part of the non-trusted execution environment [non-TEE] as described in ¶83, The non-TEE 404 passes Z′ and Z″ to the TEE 402 to perform recovery of the real output Z, the non-TEE being possibly composed of multiple entities as described in ¶39, a secure storage area used by a TEE that is inaccessible to entities operating in the non-TEE)… and obtaining, by the computing device based on the results received from the external entities, a result of a computation of the artificial neural network model. Chen fails to teach: via shuffling the computing tasks communicated to the external entities to randomize the first model parts received by the external entities… However, in the same field of endeavor, Pham teaches: via shuffling the computing tasks communicated to the external entities to randomize the first model parts received by the external entities (¶44, For example, by randomizing the order, data received from the two data sources 102, 103 may be mixed together in such a way that it may be more difficult to determine which source sent a particular piece of data). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to shuffle computing tasks as disclosed by Pham in the method disclosed by Chen to improve privacy (¶44, The randomization of the order in which the rows or columns are included as part of the example aggregation data 205 may improve data privacy). Regarding claim 20, Chen further teaches: The non-transitory computer storage medium of claim 19, wherein the method further comprises: generating, by the computing device via splitting the artificial neural network model, the first model parts (Fig. 6, 608 discusses splitting of weights, an example of which is shown in fig. 7, 400); generating, by the computing device, the computing tasks (¶81, As shown in FIG. 7, this example of additive splitting thus creates two matrices W1 and W2 that can both be passed to the non-TEE 404 for heavier computations, such as for use by the accelerator 410. In some embodiments, the accelerator 410 can perform heavier computations such as matrix multiplications by multiplying both W1 and W2 separately with an input vector X)… and identifying, by the computing device, a subset of the results corresponding to the first computations of the first model parts, wherein the result of the computation of the artificial neural network model is based on the subset (¶83, The non-TEE 404 passes Z′ and Z″ to the TEE 402 to perform recovery of the real output Z). Chen fails to explicitly teach: shuffling, by the computing device, the computing tasks in distribution of the computing tasks to the external entities… However, in the same field of endeavor, Pham teaches: shuffling, by the computing device, the computing tasks in distribution of the computing tasks to the external entities (¶44, For example, by randomizing the order, data received from the two data sources 102, 103 may be mixed together in such a way that it may be more difficult to determine which source sent a particular piece of data)… Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to shuffle computing tasks as disclosed by Pham in the method disclosed by Chen to improve privacy (¶44, The randomization of the order in which the rows or columns are included as part of the example aggregation data 205 may improve data privacy). Claims 4, 5 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Pham as applied to claims 3 and 15 above, and further in view of Ge et al. (“Practical Two-party Privacy-preserving Neural Network Based on Secret Sharing”, 2021), herein Ge. Regarding claim 4, Chen in view of Pham fails to teach: The method of claim 3, wherein the distribution is configured to exclude each of the external entities from receiving at least one of the first model parts. However, in the same field of endeavor, Ge teaches: wherein the distribution is configured to exclude each of the external entities from receiving at least one of the first model parts (pg. 6, 3.2.1 Secret Sharing, In our whole protocol, all intermediate data are shared between the two computing servers in the form of arithmetic sharing, and ⟨◦⟩ represents the secret form of a number. Assuming that the data owner holds the data a, in order to share a, it randomly generates a0 ∈ Z2l, computes and gets a1 = a − a0 mod 2l. Then, it can send ⟨a⟩0 and ⟨a⟩1 to the two servers P0 and P1 separately for specific computation). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to exclude models from receiving multiple parts as disclosed by Ge in the method disclosed by Chen in view of Pham to improve data privacy (pg. 6, 3.2.1 Secret Sharing, Because a0 and a1 are random relative to the original a, the privacy of the data will not be leaked to the two actual computing servers, and secret sharing addition and multiplication will become relatively easy). Regarding claim 5, Chen further teaches: The method of claim 4, wherein the result of the computation of the artificial neural network model is equal to a sum of the subset (¶81, For example, to perform additive splitting, the processor within the TEE 402, for each entry w in the weight matrix or vector, randomly splits each entry w into two or more parts whose sum is w – see fig. 7, box labeled recovery, for recombination of a subset of results). Regarding claim 16, it recites similar limitations to claim 4 and is rejected on the same grounds – see above. Claims 9 and 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Pham as applied to claim 1 above, and further in view of Sav et al. (US 20230325529 A1), herein Sav. Regarding claim 9, Chen in view of Pham fails to explicitly teach: The method of claim 1, further comprising: generating, by the computing device, a plurality of second model parts, a sum of the second model parts being equal to the artificial neural network model; and encrypting, by the computing device using an encryption key, at least a portion of the second model parts to generate the first model parts, wherein a sum of the first model parts is not equal to the artificial neural network model. However, in the same field of endeavor, Sav teaches: further comprising: generating, by the computing device, a plurality of second model parts, a sum of the second model parts being equal to the artificial neural network model; and encrypting, by the computing device using an encryption key, at least a portion of the second model parts to generate the first model parts, wherein a sum of the first model parts is not equal to the artificial neural network model (¶43, In response to the input data, each data provider can now obtain one or more corresponding encrypted prediction values by applying the encrypted global model to the encrypted input data – and – ¶44, the plurality of data providers being in possession of one or more destination public keys of one or more respective destination entities can collectively switch the global model (encrypted with the collective public key) to the one or more destination public keys and then provide the resulting one or more switched global models to the respective destination entities. Each destination entity can decrypt the received global model with the secret-key related to its own destination public key and thus obtain the corresponding decrypted global model). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to encrypt the model parts as disclosed by Sav in the method of Chen in view of Pham to maintain model confidentiality (¶11, In other words, the parties' and querier's data confidentiality, as well as the trained model confidentiality are to be protected). Regarding claim 10, Chen in view of Pham fails to teach: The method of claim 9, further comprising: decrypting, by the computing device, results corresponding to the portion of the second model parts in obtaining the result of the computation of the artificial neural network model. However, in the same field of endeavor, Sav teaches: further comprising: decrypting, by the computing device, results corresponding to the portion of the second model parts in obtaining the result of the computation of the artificial neural network model ¶42, Further, the request includes a destination public key of a destination entity. The destination entity is the recipient of a prediction result to be provided by the global model in response to the input data. The destination entity is a computing device which can be the querying entity or it can be different from the querying entity – and – ¶43, The one or more encrypted prediction values are then switched to the destination public key. This guarantees that only the destination entity can decrypt the one or more encrypted prediction values. The switched one or more encrypted prediction values are then provided to the querying entity. Key switching in the context of fully homomorphic encryption is well known to a person skilled in the art). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to decrypt the results as disclosed by Sav in the method disclosed by Chen in view of Pham in order to give a trusted entity access to computation results (¶42, The destination entity is the recipient of a prediction result to be provided by the global model in response to the input data). Claim 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Pham as applied to claim 1 above, and further in view of Zhu et al. (US 20220114475 A1), herein Zhu. Regarding claim 11, Chen in view of Pham fails to teach: The method of claim 1, further comprising: generating, by the computing device via splitting a data sample as input to the artificial neural network model, a plurality of first sample parts to represent the data sample; wherein the computing tasks include performing computations of the first model parts responsive to each of the first sample parts. However, in the same field of endeavor, Zhu teaches: further comprising: generating, by the computing device via splitting a data sample as input to the artificial neural network model, a plurality of first sample parts to represent the data sample; wherein the computing tasks include performing computations of the first model parts responsive to each of the first sample parts (¶41, A known approach to train a machine learning model related to a task from a large dataset is to split the dataset into several parts and build a distributed cluster of client computing systems). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to add the splitting of a training dataset into sample parts as disclosed by Zhu to the method disclosed by Chen in view of Pham to maintain data privacy (¶7, enable preservation of data privacy). Claims 12 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Pham as applied to claim 1 above, and further in view of Ge and Miller (US 20210273948 A1). Regarding claim 12, Chen in view of Pham fails to explicitly teach: The method of claim 11, wherein the distribution is configured to exclude each of the external entities from receiving at least one of the first model parts… However, in the same field of endeavor, Ge teaches: wherein the distribution is configured to exclude each of the external entities from receiving at least one of the first model parts (pg. 6, 3.2.1 Secret Sharing, In our whole protocol, all intermediate data are shared between the two computing servers in the form of arithmetic sharing, and ⟨◦⟩ represents the secret form of a number. Assuming that the data owner holds the data a, in order to share a, it randomly generates a0 ∈ Z2l, computes and gets a1 = a − a0 mod 2l. Then, it can send ⟨a⟩0 and ⟨a⟩1 to the two servers P0 and P1 separately for specific computation)… Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to exclude models from receiving multiple parts as disclosed by Ge in the method disclosed by Chen in view of Pham to improve data privacy (pg. 6, 3.2.1 Secret Sharing, Because a0 and a1 are random relative to the original a, the privacy of the data will not be leaked to the two actual computing servers, and secret sharing addition and multiplication will become relatively easy) Chen in view of Pham and Ge fails to explicitly teach: and at least one of the first sample parts. However, in the same field of endeavor, Miller teaches: and at least one of the first sample parts (¶98, In preferred embodiments, only one portion of the local data set (partial local datasets 121, 122, 123, 124, 125, 126) may be provided to each client device 402 in step 902). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to ensure data samples are not distributed in their entirety as disclosed by Miller in the method disclosed by Chen in view of Pham and Ge to increase security (¶98, to provide data security in the case of a client device 402 being compromised because only a part of the local dataset 120 may be distributed to the client device 402). Regarding claim 13, Chen further teaches: The method of claim 12, further comprising: generating, by the computing device, a plurality of second sample parts, a sum of the second sample parts being equal to the data sample; and transforming, by the computing device, at least a portion of the second sample parts to generate the first sample parts, wherein a sum of the first sample parts is not equal to the data sample (¶84, Turning back to FIG. 6, other example techniques for obfuscating the model parameters or inputs can include multiplicative splitting, individual linear transformation, batch linear transformation, or sparse randomization… To perform individual linear transformation, for each entry w of the matrix or vector, the processor changes the entry w into aw+b. Similar to choosing the random values for W1 as in additive or multiplicative splitting, a and b can be chosen such that aw+b is not too big or too small. Special cases can also be used, such as setting a=1 or b=0, so that each entry w is changed into w+b or aw, respectively). Claim 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Pham and Ge as applied to claim 16 above, and further in view of Zhu et al. (US 20220114475 A1), herein Zhu. Regarding claim 17, Chen further teaches: The computing device of claim 16, wherein the at least one microprocessor is further configured via the instructions to: generate… a plurality of first sample parts to represent the data sample; wherein the computing tasks include performing computations of the first model parts responsive to each of the first sample parts (¶81, As shown in FIG. 7, this example of additive splitting thus creates two matrices W1 and W2 that can both be passed to the non-TEE 404 for… heavier computations such as matrix multiplications by multiplying both W1 and W2 separately with an input vector X). Chen in view of Pham and Ge fails to teach: via splitting a data sample as input to the artificial neural network model… However, in the same field of endeavor, Zhu teaches: via splitting a data sample as input to the artificial neural network model (¶41, A known approach to train a machine learning model related to a task from a large dataset is to split the dataset into several parts and build a distributed cluster of client computing systems)… Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to add the splitting of a training dataset into sample parts as disclosed by Zhu to the method disclosed by Chen in view of Pham and Ge to maintain data privacy (¶7, enable preservation of data privacy). Claim 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Pham, Ge and Zhu as applied to claim 17 above, and further in view of Miller. Regarding claim 18, Chen in view of Pham, Ge and Zhu fails to teach: The computing device of claim 17, wherein the distribution is further configured to exclude each of the external entities from receiving at least one of the first sample parts. However, in the same field of endeavor, Miller teaches: wherein the distribution is further configured to exclude each of the external entities from receiving at least one of the first sample parts (¶98, In preferred embodiments, only one portion of the local data set (partial local datasets 121, 122, 123, 124, 125, 126) may be provided to each client device 402 in step 902). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to ensure data samples are not distributed in their entirety as disclosed by Miller in the method disclosed by Chen in view of Pham, Ge and Zhu to increase security (¶98, to provide data security in the case of a client device 402 being compromised because only a part of the local dataset 120 may be distributed to the client device 402). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARRISON CHAN YOUNG KIM whose telephone number is (571)272-0713. The examiner can normally be reached Monday - Friday 10:00 am - 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Cesar Paula can be reached at (571) 272-4128. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HARRISON C KIM/Examiner, Art Unit 2145 /CESAR B PAULA/Supervisory Patent Examiner, Art Unit 2145
Read full office action

Prosecution Timeline

Apr 07, 2022
Application Filed
May 09, 2025
Non-Final Rejection mailed — §101, §103
Aug 08, 2025
Response Filed
Oct 10, 2025
Final Rejection mailed — §101, §103
Dec 10, 2025
Response after Non-Final Action
Jan 12, 2026
Request for Continued Examination
Jan 23, 2026
Response after Non-Final Action
Aug 19, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12711372
TRAINING GIANT NEURAL NETWORKS USING PIPELINE PARALLELISM
4y 7m to grant Granted Aug 18, 2026
Patent 12674702
SOUND EVENT EARLY DETECTION
3y 10m to grant Granted Jul 07, 2026
Patent 12608607
METHOD FOR PREDICTING REMAINING USEFUL LIFE OF RAILWAY TRAIN BEARING BASED ON CAN-LSTM
3y 5m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 3 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
56%
Grant Probability
94%
With Interview (+37.5%)
3y 11m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 16 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month