Prosecution Insights
Last updated: October 01, 2026
Application No. 17/878,478

ULTRA-WIDEBAND SESSION KEY SHARING SCHEME

Final Rejection §103
Filed
Aug 01, 2022
Priority
Jun 13, 2022 — provisional 63/351,758
Examiner
COLIN, CARL G
Art Unit
2400
Tech Center
2400 — Computer Networks
Assignee
Apple Inc.
OA Round
4 (Final)
48%
Grant Probability
Moderate
5-6
OA Rounds
2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 48% of resolved cases
48%
Career Allowance Rate
65 granted / 136 resolved
-10.2% vs TC avg
Strong +54% interview lift
Without
With
+54.1%
Interview Lift
resolved cases with interview
Typical timeline
4y 4m
Avg Prosecution
6 currently pending
Career history
145
Total Applications
across all art units

Statute-Specific Performance

§101
12.7%
-27.3% vs TC avg
§103
47.7%
+7.7% vs TC avg
§102
17.2%
-22.8% vs TC avg
§112
16.9%
-23.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 136 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-20 are pending. Applicant’s response filed on 1/25/2026 was received and considered. Response to Arguments Applicant's arguments filed on 1/26/2026 have been fully considered but they are not persuasive. Applicant states that the cited art does not teach or suggest the claimed limitations. Claim 1 recites “implementing, by a first device, at least a portion of a single round=trip communication between the first device and a second device, the single round-trip communication comprising” and “receiving by the first device, a message from the second device via the secure session, the message being encrypted by a second session key locally generated by the second device for use in the single round-trip communication, the generated first session key being a duplicate of the second session key." Examiner respectfully disagrees as Sullivan discloses a single round-trip communication as claimed by applicant. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1-2, 6-9, 13-16, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Sullivan et at. (US-11785449-B2) in view of Fadaie et al. (US-20150358158-A1). In regards to claim 1, Sullivan teaches a method, comprising: implementing, by a first device, at least a portion of a single round-trip communication between the first device and a second device, the single round-trip communication comprising (Sullivan: Col 1. lines 35 – 67, forming a communication channel between a user device (second device) and an access device (first device)). retrieving, by the first device, a public key of the second device (Sullivan: Col 12. lines 32 – 37, the communication channel securing module 208B of the access device (fig. 2b) can generate a primary communication channel session key using a received user device public key). and generating, by the first device, a first session key, by applying a key derivation function to the public key of the second device (Sullivan: For example, the communication channel securing module 208B, in conjunction with the processor 204, can generate a primary communication channel session key using a received user device public key and the access device ephemeral private key (which can be generated by the access device 200). [Col 12, lines 26-37]. establishing, by the first device, a secure session with the second device based at least in part on generating the generated first session key (Sullivan: Col 12, lines 37 – 43, the primary communication channel session key can be utilized to encrypt messages that are to be sent to the user device); receiving, by the first device, a message from the second device via the secure session, the message being encrypted by a second session key locally generated by the second device for use in the single round-trip communication, the generated first session key being a duplicate of the second session key (Sullivan: Col 14. Lines 48 – 54, The primary communication channel session key can be utilized to encrypt messages that are to be sent to the access device, where the access device can decrypt the messages using the same primary communication channel session key that is derived by the access device based on the access device ephemeral private key and the user device public key); and decrypting, by the first device, the message using the generated first session key (Sullivan: Col 14. Lines 48 – 54, The primary communication channel session key can be utilized to encrypt messages that are to be sent to the access device, where the access device can decrypt the messages using the same primary communication channel session key). But, Sullivan does not explicitly disclose that the public key of the second device is retrieved from a third device. However, Fadaie in a similar field of endeavor, teaches a method for securely sharing information between client devices that discloses retrieving, by the first device, a public key of the second device from a third device (Fadaie: In one embodiment, the client device 110a obtains the public key by searching the directory service or the database for the user-friendly contact information in order to find the public key for the client device 110b [Fig Fig1; Para 32].) Therefore, it would have been obvious to one of ordinary skill int the art, before the effective filing date of the claimed invention, to substitute the public key retrieved from the user device as taught by Sullivan with the public key retrieved from the database as taught by Fadaie. The motivation to do so would be to yield the predictable results of generating a session key. One of ordinary skill in the art would have been motivated to do so to apply another layer of security by including a third party for providing the public key. In regards to claim 2, the combination of Sullivan and Fadaie teach the method of claim 1, wherein the method further comprises: receiving an identifier of the second device over a non-secure channel (Sullivan: Col 16. lines 24 – 38, One device, either access device or user device, can send an inquiry to the other device containing its address. The responding device replies with a name, address, and or other information to form a primary communication channel. After forming the primary communication channel, the user device and the access device can secure the channel. Since the primary communication channel is secured by both devices after an initial connection setup, and the connection set up is based on the capability of both devices sending and receiving identifiers such as an address or a name/other data if it is the responding device, then it is reasonable to conclude that an identifier of the second device is received over a non-secure channel.); and retrieving the public key based at least in part on the identifier (Fadaie: In one embodiment, the client device 110a obtains the public key by searching the directory service or the database for the user-friendly contact information in order to find the public key for the client device 110b. (Paragraph 32).). This claim is rejected based on the same rationale as claim 1 above. In regards to claim 6, the combination of Sullivan and Fadaie teach the method of claim 1, wherein the method further comprises transmitting an identifier to the second device (Sullivan: Col 16. lines 14-34, i.e., one device, either access device or user device, can send an inquiry to the other device containing its address. The responding device replies with a name, address, and or other information to form a primary communication channel. Since both devices are capable of sending and receiving identifiers such as an address, then it is reasonable to conclude that an identifier is transmitted to the second device). In regards to claim 7, the combination of Sullivan and Fadaie teach the method of claim 1, wherein the generated first session key is symmetric with the second session key (Sullivan: Col 17. lines 32 – 36, “The shared secrets held by the access device and user device can be used as symmetric keys to secure the primary communication channel”, wherein the session key was generated a private key of the access device and public key of the user device (Col 7.Lines 65-67 – Col8.Lines 1-6 ). In regards to claim 8, Sullivan teaches a first device, comprising: a processor; and a computer-readable medium including instructions that, when executed by the processor, cause the processor to perform operations comprising: implementing, at least a portion of a single round-trip communication between the first device and a second device, the single round-trip communication comprising (Sullivan: Col 1. lines 35 – 67, forming a communication channel between a user device (second device) and an access device (first device)). retrieving a public key of the second device (Sullivan: Col 12. lines 32 – 37, the communication channel securing module 208B of the access device (fig. 2b) can generate a primary communication channel session key using a received user device public key). and generating, a first session key, by applying a key derivation function to the public key of the second device (Sullivan: For example, the communication channel securing module 208B, in conjunction with the processor 204, can generate a primary communication channel session key using a received user device public key and the access device ephemeral private key (which can be generated by the access device 200). [Col 12, lines 26-37]. establishing a secure session with the second device based at least in part on generating the generated first session key (Sullivan: Col 12, lines 37 – 43, the primary communication channel session key can be utilized to encrypt messages that are to be sent to the user device); receiving, a message from the second device via the secure session, the message being encrypted by a second session key locally generated by the second device for use in the single round-trip communication, the generated first session key being a duplicate of the second session key (Sullivan: Col 14. Lines 48 – 54, The primary communication channel session key can be utilized to encrypt messages that are to be sent to the access device, where the access device can decrypt the messages using the same primary communication channel session key that is derived by the access device based on the access device ephemeral private key and the user device public key); and decrypting the message using the generated first session key (Sullivan: Col 14. Lines 48 – 54, The primary communication channel session key can be utilized to encrypt messages that are to be sent to the access device, where the access device can decrypt the messages using the same primary communication channel session key). But, Sullivan does not explicitly disclose that the public key of the second device is retrieved from a third device. However, Fadaie in a similar field of endeavor, teaches a method for securely sharing information between client devices that discloses retrieving, by the first device, a public key of the second device from a third device (Fadaie: In one embodiment, the client device 110a obtains the public key by searching the directory service or the database for the user-friendly contact information in order to find the public key for the client device 110b [Fig Fig1; Para 32].) Therefore, it would have been obvious to one of ordinary skill int the art, before the effective filing date of the claimed invention, to substitute the public key retrieved from the user device as taught by Sullivan with the public key retrieved from the database as taught by Fadaie. The motivation to do so would be to yield the predictable results of generating a session key. One of ordinary skill in the art would have been motivated to do so to apply another layer of security by including a third party for providing the public key. In regards to claim 9, the subject matter of the claim is analogous to claim 2. Therefore this claim is rejected based on the same rationale cited for claim 2 above. In regards to claim 13, the subject matter of the claim is analogous to claim 6. Therefore this claim is rejected based on the same rationale cited for claim 6 above. In regards to claim 14, the subject matter of the claim is analogous to claim 7. Therefore this claim is rejected based on the same rationale cited for claim 7 above. In regards to claim 15, Sullivan teaches a non-transitory computer-readable storage media comprising computer-executable instructions that, when executed by a processor of a first device, cause the processor to perform operations comprising: implementing, at least a portion of a single round-trip communication between the first device and a second device, the single round-trip communication comprising (Sullivan: Col 1. lines 35 – 67, forming a communication channel between a user device (second device) and an access device (first device)). retrieving a public key of the second device (Sullivan: Col 12. lines 32 – 37, the communication channel securing module 208B of the access device (fig. 2b) can generate a primary communication channel session key using a received user device public key). and generating, a first session key, by applying a key derivation function to the public key of the second device (Sullivan: For example, the communication channel securing module 208B, in conjunction with the processor 204, can generate a primary communication channel session key using a received user device public key and the access device ephemeral private key (which can be generated by the access device 200). [Col 12, lines 26-37]. establishing a secure session with the second device based at least in part on generating the generated first session key (Sullivan: Col 12, lines 37 – 43, the primary communication channel session key can be utilized to encrypt messages that are to be sent to the user device); receiving, a message from the second device via the secure session, the message being encrypted by a second session key locally generated by the second device for use in the single round-trip communication, the generated first session key being a duplicate of the second session key (Sullivan: Col 14. Lines 48 – 54, The primary communication channel session key can be utilized to encrypt messages that are to be sent to the access device, where the access device can decrypt the messages using the same primary communication channel session key that is derived by the access device based on the access device ephemeral private key and the user device public key); and decrypting the message using the generated first session key (Sullivan: Col 14. Lines 48 – 54, The primary communication channel session key can be utilized to encrypt messages that are to be sent to the access device, where the access device can decrypt the messages using the same primary communication channel session key). But, Sullivan does not explicitly disclose that the public key of the second device is retrieved from a third device. However, Fadaie in a similar field of endeavor, teaches a method for securely sharing information between client devices that discloses retrieving, by the first device, a public key of the second device from a third device (Fadaie: In one embodiment, the client device 110a obtains the public key by searching the directory service or the database for the user-friendly contact information in order to find the public key for the client device 110b [Fig Fig1; Para 32].) Therefore, it would have been obvious to one of ordinary skill int the art, before the effective filing date of the claimed invention, to substitute the public key retrieved from the user device as taught by Sullivan with the public key retrieved from the database as taught by Fadaie. The motivation to do so would be to yield the predictable results of generating a session key. One of ordinary skill in the art would have been motivated to do so to apply another layer of security by including a third party for providing the public key. In regards to claim 16, the subject matter of the claim is analogous to claim 2. Therefore this claim is rejected based on the same rationale cited for claim 2 above. In regards to claim 20, the subject matter of the claim is analogous to claim 6. Therefore this claim is rejected based on the same rationale cited for claim 6 above. Claim(s) 3,10, and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Sullivan et at. (US-11785449-B2) in view of Fadaie et al. (US-20150358158-A1) as applied to claims 1-2,6-9,13-16, and 20 above, and further in view of Ho et al (KR-102032210-B1). In regards to claim 3, the combination of Sullivan and Fadaie teach the method of claim 1, wherein the generated first session key is generated based on (Sullivan: Col 5. lines 56 – 66, a session key can be derived by a first device using the private key of the 1st device and the public key of the 2nd device and the session key can be generated by any suitable manner that allows two devices to communicate over a secure channel). However, the combination of Sullivan and Fadaie does not explicitly teach that the first session key is generated is based on a hash of the of the public key of the second device and the private key of the first device. Ho, in the same field of endeavor, teaches a first session key is generated based on a hash of the of the public key of the second device and the private (Ho: Paragraph 10 of the Detailed Description: the client terminal may generate the first session key by applying the first seed value generated by the client terminal and the second seed value received from the user authentication processing apparatus to the hash function for generating the session key). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention, to modify generating a session key taught by Sullivan to include a hash function as taught by Ho, in order to increase user convenience and strengthen the security of device authentication to facilitate transmitting secured data between them (Ho: Abstract, thereby increasing user convenience and providing a high level of security at the same time in a user authentication process. ). In regards to claim 10, the subject matter of the claim is analogous to claim 3. Therefore this claim is rejected based on the same rationale cited for claim 3 above. In regards to claim 17, the subject matter of the claim is analogous to claim 3. Therefore this claim is rejected based on the same rationale cited for claim 3 above. Claim(s) 4,11, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Sullivan et at. (US-11785449-B2) in view of Fadaie et al. (US-20150358158-A1) as applied to claims 1-2,6-9,13-16, and 20 above, and further in view of Coskun et al. (“NFC Essentials”; hereinafter Coskun). In regards to claim 4, The combination of Sullivan and Fadaie teach the method of claim 1, wherein the first device comprises a near field communication (NFC) reader and (Col 10. lines 49-53, “the user may tap the user device 102 against an NFC reader in the access device 104.”). However, the combination of Sullivan and Fadaie does not explicitly disclose the second device comprises an NFC tag. Coskun, in the same field of endeavor, teaches the second device comprises an NFC tag (Coskun: Page 75, 1st paragraph of section ii, i.e., that an NFC tag needs to touch an NFC reader to receive power). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention, to add to the system of Sullivan an NFC tag of a second device as disclosed by Coskun. Doing so would allow one to conclude that an NFC tag is embodied in the user device that taps the NFC reader in the access device disclosed by Sullivan, so that the NFC tag can power on and facilitate NFC communication between the access device and user device (Page 75, 1st paragraph of section ii, i.e., that an NFC tag needs to touch an NFC reader to receive power). In regards to claim 11, the subject matter of the claim is analogous to claim 4. Therefore this claim is rejected based on the same rationale cited for claim 4 above. In regards to claim 18, the subject matter of the claim is analogous to claim 4. Therefore this claim is rejected based on the same rationale cited for claim 4 above. Claim(s) 5, 12, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Sullivan et at. (US-11785449-B2) in view of Fadaie et al. (US-20150358158-A1) as applied to claims 1-2,6-9,13-16, and 20 above, and further in view of Muthineni et al (US-11838403-B2). In regards to claim 5, the combination of Sullivan and Fadaie teach the method of claim 1, However, the combination of Sullivan and Fadaie does not specify the message comprising a maximum of sixteen bytes. Muthineni, in the same field of endeavor, teaches a message comprising a maximum of sixteen bytes (Muthineni: Col 5. lines 41 -50, Electronic Code Book mode for encrypting large messages using AES encryption, wherein the large message is broken up into 128-bit blocks, equivalent to 16-byte blocks, for encryption and decryption processes). Therefore, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention, to have the messages sent over the secure channel in Sullivan to adhere to size limitations of 128 bits taught by Muthineni, in order to use the known technique of AES encryption for securing the data exchanged between both devices (Muthineni: Col 4. lines 43 – 45, Advanced Encryption Standard (AES), also known as Rijndael, is the most widely used encryption standard for security of data transmissions), and optimize the power consumption of both devices (Muthineni: Col 1. Lines 38 – 39, Ultra-low implementations of the AES algorithm have become important for a range of devices.). In regards to claim 12, the subject matter of the claim is analogous to claim 5. Therefore this claim is rejected based on the same rationale cited for claim 5 above. In regards to claim 19, the subject matter of the claim is analogous to claim 5. Therefore this claim is rejected based on the same rationale cited for claim 5 above. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Carl G Colin whose telephone number is (571) 272-3862. The examiner can normally be reached Monday-Thursday 8:00-5:00 PM, Friday 8-12 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amy Cohen Johnson can be reached at 571-272-2238. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CARL G COLIN/Supervisory Patent Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Show 9 earlier events
Apr 07, 2025
Applicant Interview (Telephonic)
Apr 07, 2025
Examiner Interview Summary
Jul 25, 2025
Request for Continued Examination
Jul 29, 2025
Response after Non-Final Action
Sep 24, 2025
Non-Final Rejection mailed — §103
Dec 05, 2025
Examiner Interview Summary
Jan 26, 2026
Response Filed
Sep 22, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12634114
RECURRENT NEURAL NETWORK-BASED USER IDENTITY MISAPPROPRIATION PREVENTION FROM PUBLIC DOMAINS AND CONNECTIONS
2y 1m to grant Granted May 19, 2026
Patent 12608469
SYSTEMS AND METHODS FOR STORAGE SYSTEM ATTACK DETECTION AND RESPONSE
3y 1m to grant Granted Apr 21, 2026
Patent 12592963
DETECTION DEVICE, DETECTION METHOD, AND DETECTION PROGRAM
2y 11m to grant Granted Mar 31, 2026
Patent 12554808
PUBLIC KEY EMBEDDED IN CONTENT FOR VERIFICATION OF AUTHORSHIP
2y 3m to grant Granted Feb 17, 2026
Patent 12547704
AUTOMATED DEPLOYMENT OF RELOCATABLE CODE BLOCKS AS AN ATTACK COUNTERMEASURE IN SOFTWARE
2y 9m to grant Granted Feb 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
48%
Grant Probability
99%
With Interview (+54.1%)
4y 4m (~2m remaining)
Median Time to Grant
High
PTA Risk
Based on 136 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month