Prosecution Insights
Last updated: September 17, 2026
Application No. 18/556,022

PROTECTING SECRET PROCESSING, SECRET INPUT DATA, AND SECRET OUTPUT DATA USING ENCLAVES

Non-Final OA §103§112
Filed
Oct 18, 2023
Priority
Sep 23, 2021 — nonprovisional of PCTCN2021119882
Examiner
KHAN, MOEEN
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Yiqi Chen
OA Round
3 (Non-Final)
69%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 69% — above average
69%
Career Allowance Rate
168 granted / 242 resolved
+11.4% vs TC avg
Strong +61% interview lift
Without
With
+60.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
21 currently pending
Career history
268
Total Applications
across all art units

Statute-Specific Performance

§101
9.9%
-30.1% vs TC avg
§103
69.5%
+29.5% vs TC avg
§102
6.5%
-33.5% vs TC avg
§112
7.5%
-32.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 242 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 06/10/2026 has been entered. Claims 21-35 are being considered. Claims 21-23, 26-28 and 31-34 have been amended. Examiner Note: The examiner notes that the term “at least one computer readable medium” recited in claim 31 excludes propagating signals and to exclude transmission media in view [0063] of spec. Response to 103 Applicant’s arguments filed on 11/06/2025 have been fully considered and are persuasive but are moot in view of new grounds of rejections. The arguments do not apply to the current art being used. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 21, 26 and 31 recites the limitation "the encrypted persistent key". There is insufficient antecedent basis for this limitation in the claim. Claims 22, 27 and 32 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. The claims recite” downloading the encrypted persistent key and the encrypted secret output data from the TTP to the signed manager enclave” is unclear when this downloading occurs during the encryption and decryption of secret data. In, other words the sequence encryption/decryption operation is ambiguous. For example, independent claim 21 recites “decrypting the encrypted persistent key…..” claim 22 further 1st limitation recites “downloading the encrypted persistent key” and claim 22 last limitation recites “encrypting the persistent key and the uploading the encrypted persistent key…..” its unclear how the persistent key is being decrypted by the signed manager enclave before the encrypted persistent key is downloaded by the signed manager enclave. Furthermore, the last limitation of claim 22 recites encrypting and uploading the persistent key and 1st limitation of claim 22 recites downloading the encrypted persistent key. Please clarify the sequence of each operation when and how it is performed. Dependent claims are also rejected under the same rationales due to inheriting the deficiency of corresponding independent claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 21-24, 26-29 and 31-34 are rejected under 35 U.S.C. 103 as being unpatentable over Leiserson (US 20210111886) in view of Watson (US 20200274699) and further in view of SRIVASTAVA et al (hereinafter SRIVASTAVA) (US 20200311808). Regarding claim 21 Leiserson teaches a method comprising: (Leiserson on [0016] teaches a method); receiving, by processing circuitry of a computing device, a signed private enclave from a secret processing owner (Leiserson Fig 1 block 110 and text on [0015 and 0023] teaches receiving first and second secure enclave from first and second node respectively, wherein the first and the second secure enclave are signed i.e., second secret enclave as signed private enclave); receiving a signed manager enclave from a trusted third party (TTP) (Leiserson Fig 1 block 110 and text on [0015] teaches receiving first and second secure enclave from first and second node respectively, wherein one or more users associated with first and second node i.e., first enclave as signed manager enclave); receiving a key encrypted with an encryption public key of the signed manager enclave from the secret processing owner (Leiserson on [0012 and 0019] teaches the processing logic may encrypt the file system key based on a first enclave key (i.e., encryption public key) to generate an encrypted file system key, wherein first enclave key is associated with first enclave); running secret processing in the signed private enclave with secret input data to generate secret output data (Leiserson on [0023] teaches a key file that has been signed by the second secure enclave. The key file may be received by the enclave manager from the second secure enclave i.e., Note that signing operation on the key file within the second secure enclave is the secret processing of secret input data to generate secret output. Further teaches the application key wrapping certificate may be signed by the second application within the second secure enclave). Leiserson teaches deploying plurality of signed enclave to facilitated by enclave manager to perform operation in each of the plurality of signed enclave, but fails to explicitly teach encrypting the secret output data in the signed private enclave using an ephemeral key, however Watson from analogous art teaches encrypting the secret output data in the signed private enclave using an ephemeral key (Watson on [0056] teaches the software configuration system 128 encrypts the data package 102 with the temporary symmetric key using the second send TPM 126b thereby generating an encrypted data package). Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of Watson into the teaching of Leiserson by encrypting the data using temporary key and then encrypting the temporary key to be transmitted to the signed manager enclave. One would be motivated to do so in order to reduce risk of data and temporary encryption key being compromised, thus increase security of data and key (Watson [0012]). Although the combination teaches decrypting the encrypted key at secure enclave but fails to teach decrypting the encrypted persistent key inside the signed manager enclave using the encryption private key of the signed manager enclave and decrypting the encrypted secret output data inside the signed manager enclave using the persistent key, however SRIVASTAVA from analogous art teaches and decrypting the encrypted persistent key inside the signed manager enclave using the encryption private key of the signed manager enclave and decrypting the encrypted secret output data inside the signed manager enclave using the persistent key (SRIVASTAVA on [0067] teaches the second secure enclave 154b decrypts the encrypted symmetric key (i.e., encrypted persistent key) with its own private key, uses this symmetric key to decrypt the encrypted transaction (i.e., output data), and returns the decrypted transaction to the second transaction manager 152b). Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of SRIVASTAVA into the combined teaching of Leiserson and Watson by decrypting the encrypted key inside secure enclave and decrypting the data using the decrypted key. One would be motivated to do so in order to protect the sensitive data from being exposed to an unauthorized access (SRIVASTAVA on [0004]). Regarding claims 26 and 31, Claims 26 and 31 recite commensurate subject matter as claim 21. Therefore, they are rejected for the same reasons. Except additional elements: An apparatus comprising: a processing circuitry coupled to a memory, the processor circuitry to: (Leiserson on [0036-0042] computer system comprising executable instruction stored in memory executed by a processor). At least one non-transitory machine-readable storage medium comprising instructions that, when executed, cause aa computing device to perform operation: (Leiserson on [0037-0042] executable instruction stored in memory executed by a processor); Regarding claim 22, 27 and 32 the combinations of Leiserson, Watson and SRIVASTAVA teach all the limitations of claim 21, 26 and 31 respectively, Leiserson further teaches further comprising: deploying the signed manager enclave (Leiserson Fig 1 block 110 and text on [0015] teaches deploying a first secure enclave. See on [0023-0024] teaches verifying signature of first secure enclave and second secure enclave i.e., indicating signed enclave); deploying the signed private enclave (Leiserson Fig 1 block 110 and text on [0015] teaches deploying a second secure enclave. See on [0023-0024] teaches verifying signature of first secure enclave and second secure enclave i.e., indicating signed enclave). (Leiserson on [0019] teaches the processing logic may encrypt the file system key (i.e., PCL key) based on a first enclave key (i.e., encryption public key) to generate an encrypted file system key); and when the secret output data is valid, encrypting the secret output data in the signed manager enclave using a persistent key, encrypting the persistent key in the signed manager enclave using the encryption public key of the signed manager enclave, and uploading the encrypted persistent key and the encrypted secret output data to the TTP (Leiserson on [0030] teaches at operation 420, the processing logic may verify a signature of the enclave manager. For example, the file system key file may be signed by the enclave manager. The secure enclave that has received the file system key file may have previously received a digital certificate in response to an attestation operation as previously described. The signature of the enclave manager may be verified by a public key that is included in the digital certificate. At operation 430, the processing logic may decrypt an encrypted file system key from the file system key file in response to verifying the signature of the enclave manager. For example, the encrypted file system key may be identified from the file system key file. The encrypted file system key may be decrypted by using the private key that corresponds to the public key from the application key wrapping certificate from an application of the secure enclave. At operation 440, the processing logic may encrypt the file system key by using a private enclave key (i.e., a sealing key) of the secure enclave. The encrypted file system key may then be stored at the secure enclave and used to decrypt and encrypt a file system to be used by an application at the secure enclave. The private enclave key can be an internal cryptographic key of a processor providing the secure enclave or can be derived based on the internal cryptographic key of the processor and identification information of the secure enclave). Watson teaches encrypting the ephemeral key in the signed private enclave based on the encryption public key of the signed manager enclave (Watson on [0056] teaches at step 212, the software configuration system 128 encrypts the temporary symmetric key with the public key of the asymmetric key pair generated by the sender TPM 126a, thereby generating an encrypted temporary symmetric key); sending the encrypted secret output data and the encrypted ephemeral key to the signed manager enclave, (Watson on [0056] teaches the encrypted data package, the encrypted temporary symmetric key, and the encrypted private key (collectively, the encrypted payload package 136) are transferred from the software configuration system 128 to the sender ground unit 13, the sender ground unit 134 transfers the encrypted payload package 136 to each of the LRUs 106a, 106b). decrypting the encrypted ephemeral key in the signed manager enclave using an encryption private key of the signed manage enclave and decrypting the encrypted secret output data in the signed manager enclave using the ephemeral key (Watson teaches on [0058] teaches each LRU 106 decrypting the encrypted data package so that the LRU can utilize the decrypted data package. At step 220, the LRU 106 decrypts the encrypted private key with the shared symmetric key using the LRU TPM 127, thereby generating a decrypted private key. At step 222, the LRU 106 then decrypts the encrypted temporary symmetric key using the decrypted private key using the LRU TPM thereby generating a decrypted temporary symmetric key. At step 224, the LRU TPM 127 decrypts the encrypted data package with the decrypted temporary symmetric key using the LRU TPM 127). Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of Watson into the teaching of Leiserson by encrypting the data using temporary key and then encrypting the temporary key to be transmitted to the signed manager enclave. One would be motivated to do so in order to reduce risk of data and temporary encryption key being compromised, thus increase security of data and key (Watson [0012]). SRIVASTAVA teaches downloading the encrypted persistent key and the encrypted secret output data from the TTP to the signed manager enclave (SRIVASTAVA on [0065-0067] teaches retrieving the encrypted symmetric key from first secure enclave vi transaction manager). Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of SRIVASTAVA into the combined teaching of Leiserson and Watson by decrypting the encrypted key inside secure enclave and decrypting the data using the decrypted key. One would be motivated to do so in order to protect the sensitive data from being exposed to an unauthorized access (SRIVASTAVA on [0004]). Regarding claim 23, 28 and 33 the combinations of Leiserson, Watson and SRIVASTAVA teaches all the limitations of claim 22, 27 and 32 respectively, Watson further teaches encrypting the secret output data using an encryption public key of a public enclave and sending the encrypted randomly generated deployment session key and the encrypted secret output data to the public enclave (Watson on [0056-0058] teaches the software configuration system 128 generates a random, temporary symmetric key using the second sender TPM 126b. The temporary symmetric key may be an AES cryptosystem key, such as a 256-bit AES encryption key, or other suitable symmetric encryption key. The software configuration system 128 encrypts the data package 102 with the temporary symmetric key using the second send TPM 126b thereby generating an encrypted data package. At step 212, the software configuration system 128 encrypts the temporary symmetric key with the public key of the asymmetric key pair generated by the sender TPM 126a, thereby generating an encrypted temporary symmetric key. At step 214, the encrypted data package, the encrypted temporary symmetric key, and the encrypted private key (collectively, the encrypted payload package 136) are transferred from the software configuration system 128 to the sender ground unit 134. The encrypted payload package 136 is stored in the storage device 122c of the sender ground unit. At step 216, the sender ground unit 134 transfers the encrypted payload package 136 to each of the LRUs 106a, 106b. The LRUs store the encrypted payload package 136 in the storage devices 122d, 122e). SRIVASTAVA teaches encrypting the secret output data inside the signed manager enclave using a (SRIVASTAVA on [0065-0067] teaches the first transaction manager passes the private transaction to the first secure enclave 154a. The first secure enclave generates a symmetric key, encrypts the private transaction, determines a hash of the transaction, and encrypts the symmetric key with the public key of the recipient of the private transaction (in this case, the buyer blockchain server 120). The first secure enclave then returns the encrypted transaction, the hash of the transaction, and the encrypted symmetric key. The first transaction manager 152a sends the encrypted transaction, the hash of the transaction, and the encrypted symmetric key to the second transaction manager). Regarding claim 24, 29 and 34 the combinations of Leiserson, Watson and SRIVASTAVA teaches all the limitations of claim 23, 28 and 33 respectively, Watson further teaches decrypting the encrypted (Watson [0058] teaches the method 200 may also include each LRU 106 decrypting the encrypted data package so that the LRU can utilize the decrypted data package. At step 220, the LRU 106 decrypts the encrypted private key with the shared symmetric key using the LRU TPM 127, thereby generating a decrypted private key. At step 222, the LRU 106 then decrypts the encrypted temporary symmetric key using the decrypted private key using the LRU TPM 127, thereby generating a decrypted temporary symmetric key. At step 224, the LRU TPM 127 decrypts the encrypted data package with the decrypted temporary symmetric key using the LRU TPM 127). SRIVASTAVA teaches decrypting the encrypted (SRIVASTAVA on [0067] teaches the second secure enclave 154b decrypts the encrypted symmetric key (i.e., encrypted persistent key) with its own private key, uses this symmetric key to decrypt the encrypted transaction (i.e., output data), and returns the decrypted transaction to the second transaction manager 152b). Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of SRIVASTAVA into the combined teaching of Leiserson and Watson by decrypting the encrypted key inside secure enclave and decrypting the data using the decrypted key. One would be motivated to do so in order to protect the sensitive data from being exposed to an unauthorized access (SRIVASTAVA on [0004]). Claims 25, 30 and 35 are rejected under 35 U.S.C. 103 as being unpatentable over Leiserson (US 20210111886) in view of Watson (US 20200274699) in view of SRIVASTAVA et al (hereinafter SRIVASTAVA) (US 20200311808) and further in view of Acharya et al (Acharya) (US 11494171). Regarding claim 25, 30 and 35 the combinations of Leiserson, Watson and SRIVASTAVA teach all the limitations of claim 21, 26 and 31 respectively, Leiserson further teaches wherein the processing circuitry is coupled to a memory, the processing circuitry comprising one or more of application processing circuitry or graphics processing circuitry (Leiserson on [0033 and 0041] teaches memory associated with processing device). The combination fails to explicitly teach wherein deploying the private enclave comprises deploying the private enclave within a private network inaccessible to users of the public enclave, wherein the secret processing comprises at least one of machine learning model training, deep learning model training, and artificial intelligence process training, wherein secret processing comprises training scripts, however Acharya from analogous art teaches wherein deploying the private enclave comprises deploying the private enclave within a private network inaccessible to users of the public enclave (Acharya on [col 13 line 1-5] teaches a secure enclave within private network); wherein the secret processing comprises at least one of machine learning model training, deep learning model training, and artificial intelligence process training, wherein secret processing comprises training scripts (Acharya on [col 5 line 35-50, col 7 line 35-65 and col 9 line 20-25] teaches secret processing comprises deploying artificial intelligence model and smart contract is generated based on the AI model. Further teaches a smart-contract that allows a micro-reward to the validator 104 of the AI model, the AI model gradually gets feedback that makes the model publisher 102 fine-tune it appropriately). Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of Acharya into the combined teaching of Leiserson, Watson and SRIVASTAVA by having machine learning model comprising training scripts for training data. One would be motivated to do so in order to enable deployment and scaling of artificial intelligence solutions in an efficient manner without sacrificing security (Acharya [col 2 line 1-20]). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOEEN KHAN whose telephone number is (571)272-3522. The examiner can normally be reached 7AM-5PM EST M-TH Alternate Fridays. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MOEEN KHAN/ Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Show 2 earlier events
Sep 23, 2025
Response after Non-Final Action
Sep 23, 2025
Response Filed
Nov 06, 2025
Response Filed
Dec 23, 2025
Final Rejection mailed — §103, §112
Mar 19, 2026
Response after Non-Final Action
Jun 10, 2026
Request for Continued Examination
Jun 15, 2026
Response after Non-Final Action
Sep 11, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739102
ENCRYPTION DEVICE, KEY GENERATION DEVICE, AND COMPUTER PROGRAM PRODUCT FOR ENCRYPTION
3y 0m to grant Granted Sep 15, 2026
Patent 12732370
METHOD AND SYSTEM FOR PROCESSING PERSONAL DATABASE ON BLOCK CHAIN
5y 8m to grant Granted Sep 08, 2026
Patent 12712722
RATCHET-BASED KEY MANAGEMENT
3y 2m to grant Granted Aug 18, 2026
Patent 12712710
CONFIGURATION PAYLOAD SEPARATION POLICIES
2y 5m to grant Granted Aug 18, 2026
Patent 12706733
Methods and Apparatus for Operating a Constrained Device
5y 0m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
69%
Grant Probability
99%
With Interview (+60.6%)
2y 10m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 242 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month