DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
Claims 13, 14, and 15 have been amended by Applicant. Claims 1-12 have been cancelled and new claims 16-32 have been added. Claims 13-32 are currently pending.
Response to Arguments
Requirement of Substitution of Title of the Invention
The requirement of substitution of the title of the invention as not being descriptive was not addressed in Applicant’s response to the Non-Final Office Action dated 04/01/2026. Hence, the requirement has been maintained. If a satisfactory title is not supplied by the applicant, the examiner may, at the time of allowance, change the title by an examiner’s amendment. (See MPEP 1302.04).
Claim Rejections under 35 U.S.C. 101
The rejection of claims 1-12 under 35 U.S.C. 101 because the claimed invention was directed to non-statutory subject matter has been rendered moot in view of Applicant’s cancellation of said claims.
The rejection of claims 13-15 under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea, without significantly more has been withdrawn in view of Applicant’s amendments to the claims. However, upon further consideration and in view of said amendments a new grounds of rejection under 35 U.S.C. 101 has been made herein.
The rejection of claims 1-12 under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea, without significantly more has been rendered moot in view of Applicant’s cancellation of said claims.
Applicant's arguments filed 07/14/2026 regarding the rejection of claim 13 (as amended) under 35 U.S.C. 101 (i.e., abstract idea) have been fully considered but they are not persuasive.
Applicant argues (in page 6 of Applicant’s remarks) that Applicant’s specification provides sufficient details such that one of ordinary skill in the art would recognize the claimed invention as an improvement in terms of security of computing devices that use a neural network. To this effect, Applicant maintains that the amended claim 13 (and analogous claims 19 and 26) stating “executing, by the processor of the computing device, the neural network to generate the encrypted output data based on the encrypted input data without exposing the decrypted input data or the decrypted output data to other components of the computing device.”, is sufficient to demonstrate this improvement according to the MPEP.
Examiner respectfully disagrees with Applicant’s argument above. As to the amended limitation, the instant rejection of claims 13, 19, and 26 show that this limitation merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)). Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Furthermore, considering the claim as a whole, Applicant has not shown the sufficient level of detail in the claim required by MPEP 2106.04(d) to reflect the improvements to the state of technology in view of the Specification. Hence, the claims have been rejected under 35 U.S.C. 101 as directed to an abstract idea without significantly more. (See Rejection of claims under 35 U.S.C. 101 for further analysis under Step 2A, Prong 1 and Step 2A, Prong 2, and Step 2B).
For at least the same reasons stated for claims 13, 19, and 26, the dependent claims have also been rejected under 35 U.S.C. 101.
Claim Rejections under 35 U.S.C. 103
The rejection of claims 1-12 under 35 U.S.C. 103 have been rendered moot in view of Applicant’s cancellation of said claims.
The rejection of claims 13-15 (as amended) have been withdrawn in view of Applicant’s amendment to said claims. However, upon further consideration and in view of said amendments a new grounds of rejection has been made herein. ‘
Applicant’s arguments (in page 8-9) as to the rejection of claims 13, 19, and 26 under 35 U.S.C. 103 (as amended) have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefore, subject to the conditions and requirements of this title.
Claims 13-32 (as amended) are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (abstract idea) without significantly more.
Regarding claim 13 (as amended),
Step 1: Claim 13 is directed to a method.
Step 2A, Prong 1: Claim 13 recites the following limitations:
…and generate decrypted input data based on the encrypted input data; (i.e., a person can mentally and/or with the aid of pen and paper generate decrypted data based on encrypted input data by means of a cryptographic operation.)
…and perform an inference operation on the decrypted input data to generate decrypted output data; (i.e., a person can mentally and/or with the aid of pen and paper perform an inference on decrypted data to generate a decrypted output)
…and generate encrypted output data based on the decrypted output data; (i.e., a person can mentally and/or with the aid of pen and paper generate and encrypted output of data based on the preceding decrypted output data.)
Hence, the claim recites an abstract idea.
Step 2A, Prong 2: Claim 13 recites the additional elements of “providing, by a processor of a computing device, encrypted input data to a neural network, the neural network comprising:”, “a first portion comprising at least a first neural network layer to receive the encrypted input data”, “a second portion comprising at least a second neural network layer to receive the decrypted input data from the first portion”, “a third portion comprising at least a third neural network layer to receive the decrypted output data from the second portion”. These additional elements are considered insignificant extra-solution activity consisting of mere data transmission. (See MPEP 2106.05(g)). Furthermore, the claim recites the additional element of “executing, by the processor of the computing device, the neural network to generate the encrypted output data based on the encrypted input data without exposing the decrypted input data or the decrypted output data to other components of the computing device.” This limitation merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)). Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 13 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element of “executing, by the processor of the computing device, the neural network to generate the encrypted output data based on the encrypted input data without exposing the decrypted input data or the decrypted output data to other components of the computing device.” merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)). Furthermore, the additional elements of “providing, by a processor of a computing device, encrypted input data to a neural network, the neural network comprising:”, “a first portion comprising at least a first neural network layer to receive the encrypted input data”, “a second portion comprising at least a second neural network layer to receive the decrypted input data from the first portion”, “a third portion comprising at least a third neural network layer to receive the decrypted output data from the second portion”, were considered insignificant extra-solution activity consisting of mere data transmission. (See MPEP 2106.05(g)). As such, they must be reevaluated under Step 2B to determine if they are more than what the courts have considered well-understood, routine, and conventional activity in the field. The court decisions cited in MPEP 2106.05(d)(II) have held that mere data transmission over a network is a well-understood, routine, and conventional activity in the field supported by Berkheimer. (see also, i. Receiving or transmitting data over a network, e.g., using the Internet to gather data, Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information); Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 14 (as amended),
Step 2A, Prong 1: Claim 14 recites an abstract idea as inherited from claim 13.
Step 2A, Prong 2: Claim 14 recites the additional element of “wherein the encrypted input data comprises ciphertext data and the decrypted input data comprises plaintext.” This limitation merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)). Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 14 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element of “wherein the encrypted input data comprises ciphertext data and the decrypted input data comprises plaintext.” merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)). Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 15 (as amended),
Step 2A, Prong 1: Claim 15 recites an abstract idea as inherited from claim 13.
Step 2A, Prong 2: Claim 15 recites the additional element of “wherein the third portion of the neural network is to generate the encrypted output data according to Advanced Encryption Standard (AES)”. This limitation is recited at a high-level of generality such that it amounts to no more than mere instructions to apply the exception using generic computer components. (See MPEP 2106.05(f)) Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 15 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element of “wherein the third portion of the neural network is to generate the encrypted output data according to Advanced Encryption Standard (AES)” is recited at a high-level of generality such that it amounts to no more than mere instructions to apply the exception using generic computer components. (See MPEP 2106.05(f)) Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 16,
Step 2A, Prong 1: Claim 16 recites an abstract idea as inherited from claim 13.
Step 2A, Prong 2: Claim 16 recites the additional element of “wherein the processor comprises a specialized accelerator provided on the computing device.” This limitation merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)). Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 16 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element of “wherein the processor comprises a specialized accelerator provided on the computing device.” merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)). Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 17,
Step 2A, Prong 1: Claim 17 recites an abstract idea as inherited from claim 13. Claim 17 further recites the following limitation:
…implement a decryption operation to generate the decrypted input data based on the encrypted input data… (i.e., a person can mentally and/or with the aid of pen and paper implement a decryption operation to generate decrypted input data based on encrypted input data)
Hence, the claim further recites an abstract idea.
Step 2A, Prong 2: Claim 17 recites the additional elements of “wherein the first portion of the neural network is to…” and “using neural network computations”. These additional elements to perform the steps above are recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception using generic computer components. (See MPEP 2106.05(f)) Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 17 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional elements of “wherein the first portion of the neural network is to…”and “using neural network computations” elements to perform the steps above are recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception using generic computer components. (See MPEP 2106.05(f)) Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 18,
Step 2A, Prong 1: Claim 18 recites an abstract idea as inherited from claim 13. Claim 18 further recites the following limitations:
…implement an encryption operation to generate the encrypted output data based on the decrypted output data… (i.e., a person can mentally and/or with the aid of pen and paper implement an encryption operation to generate an encrypted output data based on a preceding decrypted output data)
Hence, the claim further recites an abstract idea.
Step 2A, Prong 2: Claim 18 recites the additional elements of “wherein the third portion of the neural network is to” and “using neural network operations.” These additional elements to perform the steps above are recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception using generic computer components. (See MPEP 2106.05(f)) Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 18 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional elements of “wherein the third portion of the neural network is to” and “using neural network operations.” to perform the steps above are recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception using generic computer components. (See MPEP 2106.05(f)) Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 19,
Step 1: Claim 19 is directed to a device.
Step 2A, Prong 1: Claim 19 recites the same and/or analogous limitations as claim 13. Therefore, it is rejected under the same rationale as claim 13.
Step 2A, Prong 2: Claim 19 further recites the additional element of “a computing device comprising memory to store a neural network… and a processor to execute the neural network…”. These additional elements to perform the steps in the claim are recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception using generic computer components. (See MPEP 2106.05(f)) Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 19 is rejected under the same rationale as stated for claim 13 and is incorporated by reference herein. Furthermore, Claim 19 does not further include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional elements of “a computing device comprising memory to store a neural network… and a processor to execute the neural network…” to perform the steps in the claim are recited at a high-level of generality such that they amount to no more than mere instructions to apply the exception using generic computer components. (See MPEP 2106.05(f)) Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 20,
Claim 20 recites the same and/or analogous limitations as claim 16. Therefore, it is rejected under the same as claim 16.
Regarding claim 21,
Claim 21 recites the same and/or analogous limitations as claim 17. Therefore, it is rejected under the same rationale as claim 17.
Regarding claim 22,
Claim 22 recites the same and/or analogous limitations as claim 18. Therefore, it is rejected under the same rationale as claim 18.
Regarding claim 23,
Step 2A, Prong 1: Claim 23 recites an abstract idea as inherited from claim 19.
Step 2A, Prong 2: Claim 23 recites the additional element of “wherein a first set of weights of the first portion of the neural network encodes a decryption key.” This limitation merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)) Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 23 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element of “wherein a first set of weights of the first portion of the neural network encodes a decryption key.” merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)) Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 24,
Step 2A, Prong 1: Claim 24 recites an abstract idea as inherited from claim 19.
Step 2A, Prong 2: Claim 24 recites the additional element of “wherein a third set of weights of the third portion of the neural network encodes an encryption key.” This additional element merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)) Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 15 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element of wherein a third set of weights of the third portion of the neural network encodes an encryption key.” merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)) Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 25,
Step 2A, Prong 1: Claim 25 recites an abstract idea as inherited from claim 19.
Step 2A, Prong 2: Claim 25 recites the additional element of “wherein the processor is to execute the neural network such that the decrypted input data and decrypted output data are not written to memory that is accessible to software executed by the computing device outside of the neural network.” This additional element merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)). Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 25 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element of “wherein the processor is to execute the neural network such that the decrypted input data and decrypted output data are not written to memory that is accessible to software executed by the computing device outside of the neural network.” merely generally links the use of the judicial exception to a particular technological environment or field of use. (See MPEP 2106.05(h)) Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 26,
Step 1: Claim 26 is directed to a non-transitory computer-readable medium.
Step 2A, Prong 1: Claim 26 recites the same and/or analogous limitations as claim 13. Therefore, it is rejected under the same rationale as claim 13.
Step 2A, Prong 2: Claim 26 further recites the additional element of “a non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor of a computing device, cause the processor to:…”. This additional element to perform the steps in the claim is recited at a high-level of generality such that it amounts to no more than mere instructions to apply the exception using a generic computer component. (See MPEP 2106.05(f)) Hence the claim does not recite additional elements that integrate the judicial exception into a practical application. Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is directed to an abstract idea.
Step 2B: Claim 26 is rejected under the same rationale as claim 13 and is incorporated by reference herein. Furthermore, claim 26 does not include further additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to the integration of the abstract idea into a practical application, the additional element of “a non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor of a computing device, cause the processor to:…”. to perform the steps in the claim is recited at a high-level of generality such that it amounts to no more than mere instructions to apply the exception using a generic computer component. (See MPEP 2106.05(f)) Hence the claim lacks limitations which amount to significantly more than the judicial exception or an inventive concept, and is rejected. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 27,
Claim 27 recites the same and/or analogous limitations as claim 16. Therefore, it is rejected under the same rationale as claim 16.
Regarding claim 28,
Claim 28 recites the same and/or analogous limitations as claim 17. Therefore, claim 17 is rejected under the same rationale as claim 17.
Regarding claim 29,
Claim 29 recites the same and/or analogous limitations as claim 18. Therefore, claim 29 is rejected under the same rationale as claim 18.
Regarding claim 30,
Claim 30 recites the same and/or analogous limitations as claim 23. Therefore, claim 30 is rejected under the same rationale as claim 23.
Regarding claim 31,
Claim 31 recites the same and/or analogous limitations as claim 24. Therefore, claim 24 is rejected under the same rationale as claim 24.
Regarding claim 32,
Claim 32 recites the same and/or analogous limitations as claim 25. Therefore, claim 32 is rejected under the same rationale as claim 25.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or non-obviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 13, 14, 17, 18, 19, 21, 22, 26, 28, and 29 are rejected under 35 U.S.C. 103 as being unpatentable over Doshi et al. (US 20190044918 A1, filed Mar. 30, 2018 and published Feb. 7, 2019) in view of Abadi et al. (US 20190171929 A1 filed Feb. 4, 2019 and published Jun. 6, 2019)
Regarding claim 13, Doshi teaches:
providing, by a processor of a computing device, encrypted input data to a neural network (Doshi, Abstract, teaches systems and techniques for AI model and data camouflaging techniques for cloud edge are described herein. In an example, a neural network transformation system is adapted to receive, from a client, camouflaged input data, the camouflaged input data resulting from application of a first encoding transformation to raw input data. The neural network transformation system may be further adapted to use the camouflaged input data as input to a neural network model, the neural network model created using a training data set created by applying the first encoding transformation on training data. The neural network transformation system may be further adapted to receive a result from the neural network model and transmit output data to the client, the output data based on the result.), the neural network comprising:
a first portion … to receive the encrypted input data and generate decrypted input data based on the encrypted input data (Doshi, [0042] teaches FIG. 4 illustrates the client 410 and server 405 systems for interfacing with a camouflaged neural network, in accordance with some embodiments. In an embodiment, the client device 410 may have a client application for collecting data, encoding the data, and transmitting it to an AI model on server 405.; Doshi, [0043] further teaches the transformed data [i.e., encrypted input] may be received at transceiver 430 of the server 405.; Doshi, [0043] further teaches the input transcoder 420 may include a transformation to decode the transformation performed by the encoder 440 at the client 410 [i.e., generate decrypted input data based on the encrypted input data]. The input transcoder 420 may then send the second transformed data to the camouflaged model 415.; Doshi, [0010] teaches FIG. 4 illustrates a client and server systems for interfacing with a camouflaged neural network, in accordance with some embodiments.);
a second portion … to receive the decrypted input data from the first portion and perform an inference operation on the decrypted input data to generate decrypted output data (Doshi, [0043] the input transcoder 420 may then send the second transformed data to the camouflaged model 415.; See Fig. 4 – Camouflage model receiving from the input transcoder 420; Doshi, [0043] further teaches The received transformed data may be sent directly to the camouflaged model 415 for training or inference.) and
a third portion … to receive the decrypted output data from the second portion and generate encrypted output data based on the decrypted output data (Doshi, [0043] teaches the inference transcoder 425 may include a transformation to encode the output data corresponding to a decode transformation performed at the client 410. The inference transcoder 425 may send the output data to transceiver 430 to be transmitted to the client 410.); and
executing, by the processor of the computing device, the neural network to generate the encrypted output data based on the encrypted input data without exposing the decrypted input data or the decrypted output data to other components of the computing device (Doshi, [0048] teaches [0048] The described system and methods allow having AI models on the edge such that any outside observation of the training and inferencing data may not be able to derive how the model works and what part of the data used is valid. Thus, for parties using a client of a service provider, which have not established prior trust with the service provider, the service provider may share infrastructure without concern that the intellectual secrets of the model and neural network will be stolen. Another concern may exist if the model owner is different than the edge cloud provider, and thus the model owner is providing the edge cloud provider with access to the model. For example, the model may be uploaded into the edge cloud provider infrastructure. However, the model is guarded from the edge cloud provider, as the owner of the model may protect the server-side transformations and thus hides, even to someone using the model, how the inputs are transformed (camouflaged) and how to recover the transformed (camouflaged) actual outputs. While the described systems and methods are exemplified in the context of edge cloud, usage may also apply in any type of fog or IoT architecture using AI as part of its solution stack.).
However, Doshi does not distinctly disclose the neural network:
…comprising at least a first neural network layer…
…comprising at least a second neural network layer…
… comprising at least a third neural network layer…
Nevertheless, Abadi teaches:
the neural network: …comprising at least a first neural network layer…comprising at least a second neural network layer… comprising at least a third neural network layer… (Abadi, [0018] teaches in some implementations, the encoder neural network can include one or more fully-connected layers followed by one or more convolutional layers. In some implementations, the first decoder neural network can include one or more fully-connected layers followed by one or more convolutional layers. In some implementations, the second decoder neural network can include one or more fully-connected layers followed by one or more convolutional layers.; Abadi, [0040] teaches The encoder neural network 102, trusted decoder neural network 104, and adversary decoder neural network 106 may or may not share a common architecture.)
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to have modified the AI model and data camouflaging techniques, as taught by Doshi, with the Systems, methods, devices, and other techniques are described herein for training and using neural networks to encode inputs and to process encoded inputs, as taught by Abadi, in order to obfuscate sensitive information represented in an input so that other systems that process the encoded representation of the input cannot reliably determine the sensitive information without an appropriate key. For example, personal or identifying information about users may be hidden from a portion of the system so that it is prevented from acting on such information. In some implementations, different components of a neural network system can be trained in an adversarial manner so as to protect the confidentiality of information processed by a first portion of the system from a second portion of the system. (Abadi, [0006] and [0028])
Regarding claim 14, the combination of Doshi in view of Abadi teaches all of the limitations of claim 13, and the combination further teaches wherein the encrypted input data comprises ciphertext data and the decrypted input data comprises plaintext data (Abadi, [0038] teaches the encoded representation of the primary neural network input 112 can be ciphertext, i.e., an encrypted version of the primary neural network input 112… the primary neural network input 112 can be a plaintext representation of input data, the neural network input key 110 can be a cryptographic key (e.g., a shared secret key), and the encoded representation of the primary neural network input 112 can be ciphertext, i.e., an encrypted version of the primary neural network input 112.).
Motivation to combine same as stated in claim 13.
Regarding claim 17, the combination of Doshi in view of Abadi teaches all of the limitations of claim 13, and the combination further teaches wherein the first portion of the neural network is to implement a decryption operation to generate the decrypted input data based on the encrypted input data using neural network computations (Doshi, [0042] teaches FIG. 4 illustrates the client 410 and server 405 systems for interfacing with a camouflaged neural network, in accordance with some embodiments. In an embodiment, the client device 410 may have a client application for collecting data, encoding the data, and transmitting it to an AI model on server 405.; Doshi, [0043] further teaches the transformed data [i.e., encrypted input] may be received at the transceiver 430 of the server 405.; Doshi, [0043] further teaches the input transcoder 420 may include a transformation to decode the transformation performed by the encoder 440 at the client 410 [i.e., generate decrypted input data based on the encrypted input data]. The input transcoder 420 may then send the second transformed data to the camouflaged model 415.; Doshi, [0010] teaches FIG. 4 illustrates a client and server systems for interfacing with a camouflaged neural network, in accordance with some embodiments.; Doshi, Abstract, teaches systems and techniques for AI model and data camouflaging techniques for cloud edge are described herein. In an example, a neural network transformation system [i.e., using neural network computations] is adapted to receive, from a client, camouflaged input data, the camouflaged input data resulting from application of a first encoding transformation to raw input data. The neural network transformation system may be further adapted to use the camouflaged input data as input to a neural network model, the neural network model created using a training data set created by applying the first encoding transformation on training data. The neural network transformation system may be further adapted to receive a result from the neural network model and transmit output data to the client, the output data based on the result.).
Regarding claim 18, the combination of Doshi in view of Abadi teaches all of the limitations of claim 13, and the combination further teaches wherein the third portion of the neural network is to implement an encryption operation to generate the encrypted output data based on the decrypted output data using neural network computations (Doshi, [0043] teaches the inference transcoder 425 may include a transformation to encode the output data corresponding to a decode transformation performed at the client 410. The inference transcoder 425 may send the output data to the transceiver 430 to be transmitted to the client 410.; Doshi, Abstract, teaches systems and techniques for AI model and data camouflaging techniques for cloud edge are described herein. In an example, a neural network transformation system [i.e., using neural network computations] is adapted to receive, from a client, camouflaged input data, the camouflaged input data resulting from application of a first encoding transformation to raw input data. The neural network transformation system may be further adapted to use the camouflaged input data as input to a neural network model, the neural network model created using a training data set created by applying the first encoding transformation on training data. The neural network transformation system may be further adapted to receive a result from the neural network model and transmit output data to the client, the output data based on the result.).
Regarding claim 19,
Claim 19 teaches the same and/or analogous limitations as claim 13. Therefore, it is rejected under the same rationale and motivation as claim 13.
Doshi further teaches:
memory to store a neural network… (Doshi, [0070] teaches the storage device 816 may include a machine readable medium 822 on which is stored one or more sets of data structures or instructions 824 (e.g., software) embodying or used by any one or more of the techniques or functions described herein. The instructions 824 may also reside, completely or at least partially, within the main memory 804, within static memory 806, or within the hardware processor 802 during execution thereof by the machine 800. In an example, one or any combination of the hardware processor 802, the main memory 804, the static memory 806, or the storage device 816 may constitute machine readable media.; See also Fig. 4 405 and Camouflaged Model (i.e., Camouflaged Neural Network) 415 – Paragraph [0010])
a processor to execute the neural network… (Doshi, [claim 1] teaches A system for camouflaging data in a cloud computing environment, comprising: at least one processor; and memory including instructions that, when executed by the at least one processor, cause the at least one processor to: receive, from a client, camouflaged input data, the camouflaged input data resulting from application of a first encoding transformation to raw input data; use the camouflaged input data as input to a neural network model, the neural network model created using a training data set created by applying the first encoding transformation on training data; receive a result from the neural network model; and transmit output data to the client, the output data based on the result.)
Regarding claim 21,
Claim 21 recites the same and/or analogous limitations as claim 17. Therefore, it is rejected under the same rationale and motivation as claim 17.
Regarding claim 22,
Claim 22 recites the same and/or analogous limitations as claim 18. Therefore, it is rejected under the same rationale and motivation as claim 18.
Regarding claim 26,
Claim 26 recites the same and/or analogous limitations as claim 13. Therefore, it is rejected under the same rationale and motivation as claim 13.
Doshi further teaches a non-transitory computer-readable storage medium having instructions stored thereon … (Doshi, [0070] The storage device 816 may include a machine readable medium 822 on which is stored one or more sets of data structures or instructions 824 (e.g., software) embodying or used by any one or more of the techniques or functions described herein. The instructions 824 may also reside, completely or at least partially, within the main memory 804, within static memory 806, or within the hardware processor 802 during execution thereof by the machine 800. In an example, one or any combination of the hardware processor 802, the main memory 804, the static memory 806, or the storage device 816 may constitute machine readable media.; Doshi, [0072] The term “machine readable medium” may include any medium that is capable of storing, encoding, or carrying instructions for execution by the machine 800 and that cause the machine 800 to perform any one or more of the techniques of the present disclosure, or that is capable of storing, encoding or carrying data structures used by or associated with such instructions. Non-limiting machine-readable medium examples may include solid-state memories, and optical and magnetic media. In an example, a massed machine-readable medium comprises a machine readable medium with a plurality of particles having invariant (e.g., rest) mass. Accordingly, massed machine-readable media are not transitory propagating signals.)
Regarding claim 28,
Claim 28 recites the same and/or analogous limitations as claim 17. Therefore, claim 17 is rejected under the same rationale and motivation as claim 17.
Regarding claim 29,
Claim 29 recites the same and/or analogous limitations as claim 18. Therefore, claim 29 is rejected under the same rationale and motivation as claim 18.
Claims 15, 16, 20, and 27 are rejected under 35 U.S.C. 103 as being unpatentable over Doshi et al. in view of Abadi et al., as applied to claim 13, and further in view of Choi et al., “CREMON: Cryptography Embedded on Convolutional Neural Network Accelerator” (Feb. 2020)
Regarding claim 15, the combination of Doshi in view of Abadi teaches all of the limitations of claim 13, however the combination does not distinctly disclose wherein the third portion of the neural network is to generate the encrypted output data according to Advanced Encryption Standard (AES).
Nevertheless, Choi teaches wherein the third portion of the neural network is to generate the encrypted output data according to Advanced Encryption Standard (AES) (Choi, pg. 3338, Col. 2 teaches since there is a data dependency between layers, AES processing has to keep pace with convolutions by supporting adequate throughput in each layer. From this point of view, CREMON utilizes convolution cores of a CNN accelerator as a reconfigurable block for both CNN and AES, thereby meeting two crucial conditions: supporting large-scale data ciphers and adjustable AES throughput for diverse CNN environments.)
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to have modified the AI model and data camouflaging techniques, as taught by Doshi in view of Abadi, to further include the reconfigurable core for CNN and AES, as taught by Choi, in order to support large-scale data ciphers and adjustable AES throughput for diverse CNN environments. (Choi, pg. 3338, Col. 2)
Regarding claim 16, the combination the combination of Doshi in view of Abadi teaches all of the limitations of claim 13, however the combination does not distinctly disclose wherein the processor comprises a specialized accelerator provided on the computing device.
Nevertheless, Choi teaches wherein the processor comprises a specialized accelerator provided on the computing device (Choi, pg. 3338, Col. 2 teaches since there is a data dependency between layers, AES processing has to keep pace with convolutions by supporting adequate throughput in each layer. From this point of view, CREMON utilizes convolution cores of a CNN accelerator as a reconfigurable block for both CNN and AES, thereby meeting two crucial conditions: supporting large-scale data ciphers and adjustable AES throughput for diverse CNN environments.)
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to have modified the AI model and data camouflaging techniques, as taught by Doshi in view of Abadi, to further include the reconfigurable core for CNN and AES, as taught by Choi, in order to support large-scale data ciphers and adjustable AES throughput for diverse CNN environments. (Choi, pg. 3338, Col. 2)
Regarding claim 20,
Claim 20 recites the same and/or analogous limitations as claim 16. Therefore, it is rejected under the same rationale and motivation as claim 16.
Regarding claim 27,
Claim 27 recites the same and/or analogous limitations as claim 16. Therefore, it is rejected under the same rationale and motivation as claim 16.
Claims 23, 24, 25, 30, 31, and 32 are rejected under 35 U.S.C. 103 as being unpatentable over Doshi et al. in view of Abadi et al, as applied to claim 19, and further in view of Modi et al. (US 20190005375 A1, filed Oct. 11, 2017 and published Jan. 3, 2019)
Regarding claim 23, the combination of Doshi in view of Abadi teaches all of the limitations of claim 19, however the combination does not distinctly disclose wherein a first set of weights of the first portion of the neural network encodes a decryption key.
Nevertheless, Modi teaches wherein a first set of weights of the first portion of the neural network encodes a decryption key (Modi, Abstract teaches A CNN based-signal processing includes receiving of an encrypted output from a first layer of a multi-layer CNN data. The received encrypted output is subsequently decrypted to form a decrypted input to a second layer of the multi-layer CNN data. A convolution of the decrypted input with a corresponding decrypted weight may generate a second layer output, which may be encrypted and used as an encrypted input to a third layer of the multi-layer CNN data.; Modi, [0015] teaches for the decryption of inputs and/or weights, and the encryption of the output, a particular key may be stored and used for the decryptions and encryptions as described herein.; Modi, [0023] teaches during the signal processing of a particular layer, an encrypted input, which may be an encrypted output of a previously processed layer, may be decrypted on-the-fly by the secure IP block 202. Similarly, the corresponding encrypted weight stored from the external memory may be decrypted on-the-fly and convolved with the decrypted input to generate an unencrypted output. Thereafter, the unencrypted output may be encrypted at the secure IP block 202 and used as another encrypted input to a subsequent layer.; Modi, [0024] further teaches for these decryptions and encryptions, the secure IP block 202 may include a key features block (further described below in FIG. 3 as key features block 316) that are accessible by hardware and invisible from software side. As further discussed below, the key features block may provide different keys for each layer during the signal processing. The different keys may be used for the on-the-fly decryption of the input and weights, and the on-the-fly encryption of the output. The decryption keys for the weights may be fixed for each layer. In other words, for frame to frame processing, keys used for decryption of weights for each layer are fix.).
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to have modified the AI model and data camouflaging techniques, as taught by Doshi in view of Abadi, to further include the secure convolutional neural network accelerator, as taught by Mody, in order to prevent malicious attempts to provide a fixed pattern input to a given layer and allow the ability to decode the output and determine the weight of the given layer (and other layers), since output=weight*input. (Mody, [0025])
Regarding claim 24, the combination of Doshi in view of Abadi teaches all of the limitations of claim 19, however the combination does not distinctly disclose wherein a third set of weights of the third portion of the neural network encodes an encryption key.
Nevertheless, Modi teaches wherein a third set of weights of the third portion of the neural network encodes an encryption key (Modi, Abstract teaches A CNN based-signal processing includes receiving of an encrypted output from a first layer of a multi-layer CNN data. The received encrypted output is subsequently decrypted to form a decrypted input to a second layer of the multi-layer CNN data. A convolution of the decrypted input with a corresponding decrypted weight may generate a second layer output, which may be encrypted and used as an encrypted input to a third layer of the multi-layer CNN data.; Modi, [0015] teaches for the decryption of inputs and/or weights, and the encryption of the output, a particular key may be stored and used for the decryptions and encryptions as described herein.; Modi, [0023] teaches during the signal processing of a particular layer, an encrypted input, which may be an encrypted output of a previously processed layer, may be decrypted on-the-fly by the secure IP block 202. Similarly, the corresponding encrypted weight stored from the external memory may be decrypted on-the-fly and convolved with the decrypted input to generate an unencrypted output. Thereafter, the unencrypted output may be encrypted at the secure IP block 202 and used as another encrypted input to a subsequent layer.; Modi, [0024] further teaches for these decryptions and encryptions, the secure IP block 202 may include a key features block (further described below in FIG. 3 as key features block 316) that are accessible by hardware and invisible from software side. As further discussed below, the key features block may provide different keys for each layer during the signal processing. The different keys may be used for the on-the-fly decryption of the input and weights, and the on-the-fly encryption of the output. The decryption keys for the weights may be fixed for each layer. In other words, for frame to frame processing, keys used for decryption of weights for each layer are fix.).
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to have modified the AI model and data camouflaging techniques, as taught by Doshi in view of Abadi, to further include the secure convolutional neural network accelerator, as taught by Mody, in order to prevent malicious attempts to provide a fixed pattern input to a given layer and allow the ability to decode the output and determine the weight of the given layer (and other layers), since output=weight*input. (Mody, [0025])
Regarding claim 25, the combination of Doshi in view of Abadi teaches all of the limitations of claim 19, however, the combination does not distinctly disclose wherein the processor is to execute the neural network such that the decrypted input data and decrypted output data are not written to memory that is accessible to software executed by the computing device outside of the neural network.
Nevertheless, Modi teaches wherein the processor is to execute the neural network such that the decrypted input data and decrypted output data are not written to memory that is accessible to software executed by the computing device outside of the neural network (Modi, [0025] teaches at any time during the signal processing, the decrypted weights, the decrypted inputs, and the encrypted outputs may not be available to the external memories (i.e., external flash 208 and external memory 210) in order to prevent exposure to malicious attacks. Storing of the decrypted weights and input, and the encrypted output may be stored at the internal memory 206. Encrypting the output is implemented to prevent malicious attempts to provide a fixed pattern input to a given layer and allow the ability to decode the output and determine the weight of the given layer (and other layers), since output=weight*input.; Mody, [0026] furthermore, the decrypted weights and the decrypted input may be directly provided to other blocks within the secure IP block 202 without software intervention. That is, the CNN HW engine 200 may be configured to retrieve and use directly the decrypted weights and decrypted input through a hardware concurrent parallel execution of security engines for hidden layers during the signal processing. The CNN HW engine 200, for example, may implement parallel execution of convolutions of the decrypted inputs and weights, and to supply the output back to the secure IP block 202 to form an encrypted output.; Modi, [0054] further teaches As described herein, the AES channels 504 may implement secure decryption and encryption of the input, weights, and layer output by using hardware functionalities such as the CNN HW core 410. That is, the input, weight, and output that are being utilized in the AES channels 504 and the CNN HW core 410 are not visible to software i.e., not accessible through software from outside of the SoC device 104.; Modi, [0046] teaches In certain implementations, on-the-fly allows for inputs or weights after decryption to directly pass to the CNN HW core 410 without storing in any internal or external memory (e.g., memory 206, memory 210). In any event, content is not readable (compromised) by software during on-the-fly.).
[EXAMINER NOTE: Examiner notes that Doshi teaches without exposing the decrypted input data or the decrypted output data to other components of the computing device (Doshi, [0048] teaches [0048] The described system and methods allow having AI models on the edge such that any outside observation of the training and inferencing data may not be able to derive how the model works and what part of the data used is valid. Thus, for parties using a client of a service provider, which have not established prior trust with the service provider, the service provider may share infrastructure without concern that the intellectual secrets of the model and neural network will be stolen. Another concern may exist if the model owner is different than the edge cloud provider, and thus the model owner is providing the edge cloud provider with access to the model. For example, the model may be uploaded into the edge cloud provider infrastructure. However, the model is guarded from the edge cloud provider, as the owner of the model may protect the server-side transformations and thus hides, even to someone using the model, how the inputs are transformed (camouflaged) and how to recover the transformed (camouflaged) actual outputs. While the described systems and methods are exemplified in the context of edge cloud, usage may also apply in any type of fog or IoT architecture using AI as part of its solution stack.) However, Doshi does not explicitly or clearly disclose decrypted input data and decrypted output data are not written to memory that is accessible to software executed by the computing device outside of the neural network, as presently claimed].
Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to have modified the AI model and data camouflaging techniques, as taught by Doshi in view of Abadi, to further include the secure convolutional neural network accelerator, as taught by Mody, in order to prevent malicious attempts to provide a fixed pattern input to a given layer and allow the ability to decode the output and determine the weight of the given layer (and other layers), since output=weight*input. (Mody, [0025])
Regarding claim 30,
Claim 30 recites the same and/or analogous limitations as claim 23. Therefore, claim 30 is rejected under the same rationale and motivation as claim 23.
Regarding claim 31,
Claim 31 recites the same and/or analogous limitations as claim 24. Therefore, claim 24 is rejected under the same rationale and motivation as claim 24.
Regarding claim 32,
Claim 32 recites the same and/or analogous limitations as claim 25. Therefore, claim 32 is rejected under the same rationale and motivation as claim 25.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BEATRIZ RAMIREZ BRAVO whose telephone number is 571-272-2156. The examiner can normally be reached Mon. - Fri. 7:30a.m.-5:00p.m..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, USMAAN SAEED can be reached at 571-272-4046. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/B.R.B./Examiner, Art Unit 2146
/USMAAN SAEED/Supervisory Patent Examiner, Art Unit 2146