Prosecution Insights
Last updated: October 04, 2026
Application No. 18/573,374

VERIFIABLE SECURE DATASET OPERATIONS WITH PRIVATE JOIN KEYS

Non-Final OA §103
Filed
Dec 21, 2023
Priority
Jul 24, 2022 — provisional 63/391,794 +1 more
Examiner
SHEHNI, GHAZAL B
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Google LLC
OA Round
3 (Non-Final)
87%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
946 granted / 1085 resolved
+29.2% vs TC avg
Moderate +13% lift
Without
With
+12.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
21 currently pending
Career history
1107
Total Applications
across all art units

Statute-Specific Performance

§101
13.8%
-26.2% vs TC avg
§103
40.2%
+0.2% vs TC avg
§102
20.0%
-20.0% vs TC avg
§112
11.1%
-28.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1085 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 05/22/2026 has been entered. The following is a non-final action in response to communications received 05/22/2026. Claims 1, 15 have been amended. Claims 4, 13, 18 have been cancelled. Claims 21-22 have been added. Therefore claims 1-3, 5-12, 14-17, 19-22 are pending and addressed below. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 5-12, 14-17, 21-22 are rejected under 35 U.S.C. 103 as being unpatentable over Arasu et al (Pub. No. US 20160306995) in view of Ortiz et al (Pub. No. US 2022/0108026). As per claim 1, Arasu discloses a method in one or more servers for performing a join operation (…a semantically secure join operator joins two input tables into one resulting table…see par. 45), the method comprising: receiving, at a module executing in a trusted execution environment (TEE) from a first party (1P) data source, a first dataset including personal identifiable information (PII) data and non-PII data (…(table 4 and table 5: see Ailment (encrypted) and Ailment (original))…EDBMS TM framework that can be stored on a trusted machine such as computing device…an EDBMS TM framework can contain a query processor configured for receiving a query having encrypted contents and one or more encrypted records from a data store…the query processor can coordinate the execution of the query on a trusted machine and can return a query result…the query received by the query processor is a complete query, while in others, it can be an intermediate query…an intermediate query can be one of several query operations needed to process a complete query according to a query plan…when the query processor coordinates the execution of an intermediate query, the query result that is returned can be an intermediate query result…see par. 33, 35); matching, in the TEE, the first formatted PII data to second formatted PII data included in a second dataset; performing a join operation between the first dataset and the second dataset based on the matching, to generate a joined dataset (…after the encrypted records and the encrypted query contents have been decrypted, the query processor can process the query by utilizing semantically secure query operators…a semantically secure query operator can be used to execute an associated query operation on decrypted data derived from the encrypted records…semantically secure query operators remove information that can be used to identify correlations between a query parameter and a query result… a semantically secure join operator joins two input tables into one resulting table…see par. 38, 45). Arasu does not explicitly disclose pre-processing the PII data to generate first formatted PII data, the first formatted PII data conforming to a defined format; providing, to a data service operating independently of the 1P data source, the joined dataset wherein: the module implements a secure connector configured to use credentials associated with the 1P data source; and the matching is implemented in a secure join module which is prevented from accessing the credentials associated with the 1P data source. However Ortiz discloses pre-processing the PII data to generate first formatted PII data, the first formatted PII data conforming to a defined format (he data encryption technology can include, for example, SQL databases and SQL servers, among others, that are configured to protect sensitive data at rest on the server, during movement between client and server and while the data is in use to ensure that sensitive data never appears as plaintext inside the database system, par. 159, data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 157-158); providing, to a data service operating independently of the 1P data source, the joined dataset (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, par. 157, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 158), wherein: the module implements a secure connector configured to use credentials associated with the 1P data source (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, par. 157, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 158, differing levels of protection can be established through the use of multiple or separate keys that can be established for each (e.g., a database level key, a table level key, a row/column level key, keys for individual fields), which can then be exposed accordingly so that the secure enclave only receives a minimum level of access required for processing the query or machine learning activities, par. 160); and the matching is implemented in a secure join module which is prevented from accessing the credentials associated with the 1P data source (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements, par. 157, differing levels of protection can be established through the use of multiple or separate keys that can be established for each (e.g., a database level key, a table level key, a row/column level key, keys for individual fields), which can then be exposed accordingly so that the secure enclave only receives a minimum level of access required for processing the query or machine learning activities, par. 158-160). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Ortiz in Arasu for including the above limitations because one ordinary skill in the art would recognize it would further improve a secure computing infrastructure that utilizes secure computing and cryptographic approaches to store sensitive information that can only be access with one or more automatically enforced data custodian policies for conducting analytics while preserving privacy and confidentiality, par. 13-14. As per claim 15, Arasu discloses a system comprising: one or more servers including processing hardware (see fig.1) and configured to; receive, at a module executing in a trusted execution environment (TEE) from a first party (1P) data source, a first dataset including personal identifiable information (PII) data and non-PII data (…(table 4 and table 5: see Ailment (encrypted) and Ailment (original))…EDBMS TM framework that can be stored on a trusted machine such as computing device…an EDBMS TM framework can contain a query processor configured for receiving a query having encrypted contents and one or more encrypted records from a data store…the query processor can coordinate the execution of the query on a trusted machine and can return a query result…the query received by the query processor is a complete query, while in others, it can be an intermediate query…an intermediate query can be one of several query operations needed to process a complete query according to a query plan…when the query processor coordinates the execution of an intermediate query, the query result that is returned can be an intermediate query result…see par. 33, 35); match, in the TEE, the first formatted PII data to second formatted PII data included in a second dataset; perform a join operation between the first dataset and the second dataset based on the matching, to generate a joined dataset (…after the encrypted records and the encrypted query contents have been decrypted, the query processor can process the query by utilizing semantically secure query operators…a semantically secure query operator can be used to execute an associated query operation on decrypted data derived from the encrypted records…semantically secure query operators remove information that can be used to identify correlations between a query parameter and a query result… a semantically secure join operator joins two input tables into one resulting table…see par. 38, 45). Arasu does not explicitly disclose pre-processing the PII data to generate first formatted PII data, the first formatted PII data conforming to a defined format; provide, to a data service operating independently of the 1P data source, the joined dataset wherein: the module implements a secure connector configured to use credentials associated with the 1P data source; and the matching is implemented in a secure join module which is prevented from accessing the credentials associated with the 1P data source. However Ortiz discloses pre-processing the PII data to generate first formatted PII data, the first formatted PII data conforming to a defined format (he data encryption technology can include, for example, SQL databases and SQL servers, among others, that are configured to protect sensitive data at rest on the server, during movement between client and server and while the data is in use to ensure that sensitive data never appears as plaintext inside the database system, par. 159, data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 157-158); provide, to a data service operating independently of the 1P data source, the joined dataset (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, par. 157, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 158), wherein: the module implements a secure connector configured to use credentials associated with the 1P data source (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, par. 157, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 158, differing levels of protection can be established through the use of multiple or separate keys that can be established for each (e.g., a database level key, a table level key, a row/column level key, keys for individual fields), which can then be exposed accordingly so that the secure enclave only receives a minimum level of access required for processing the query or machine learning activities, par. 160); and the matching is implemented in a secure join module which is prevented from accessing the credentials associated with the 1P data source (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements, par. 157, differing levels of protection can be established through the use of multiple or separate keys that can be established for each (e.g., a database level key, a table level key, a row/column level key, keys for individual fields), which can then be exposed accordingly so that the secure enclave only receives a minimum level of access required for processing the query or machine learning activities, par. 158-160). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Ortiz in Arasu for including the above limitations because one ordinary skill in the art would recognize it would further improve a secure computing infrastructure that utilizes secure computing and cryptographic approaches to store sensitive information that can only be access with one or more automatically enforced data custodian policies for conducting analytics while preserving privacy and confidentiality, par. 13-14. As per claim 2, the combination of Arasu and Ortiz disclose performing, by the module and prior to the receiving of the first dataset, authentication with the 1P data source (Ortiz: par. 196). The motivation for claim 2 is the same motivation as in claim 1 above. As per claim 3, the combination of Arasu and Ortiz disclose wherein the performing of the authentication includes performing a decryption operation using credentials associated with the 1P data source (Ortiz: par. 223-226). The motivation for claim 3 is the same motivation as in claim 1 above. As per claim 14, the combination of Arasu and Ortiz disclose wherein the receiving of the first dataset includes receiving the first dataset in cleartext over an encrypted link (Arasu: see par. 34). As per claim 16, the combination of Arasu and Ortiz disclose wherein the one or more servers are further configured to: perform, by the module and prior to the receiving of the first dataset, authentication with the 1P data source (Ortiz: par. 196). The motivation for claim 16 is the same motivation as in claim 1 above. As per claim 17, the combination of Arasu and Ortiz disclose wherein the one or more servers are configured to perform the authentication by performing a decryption operation using credentials associated with the 1P data source (Ortiz: par. 223-226). The motivation for claim 17 is the same motivation as in claim 1 above. As per claims 21, 22, the combination of Arasu and Ortiz disclose wherein the predefined format includes one or more predefined string formats (Ortiz: par. 177-180). The motivation for claims 21, 22 is the same motivation as in claims 1, 15 above. Claims 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Arasu et al (Pub. No. US 20160306995) in view of Ortiz et al (Pub. No. US 2022/0108026) as applied to claim 15 above, and further in view of Sultan et al (Pub. No. US 2022/0343021). As per claim 19, the combination of Arasu and Ortiz does not explicitly disclose wherein the one or more servers are further configured to: provide the first formatted PII data from the secure connector to the secure join module via an extract-transform-load (ETL) pipeline. However Sultan discloses wherein the one or more servers are further configured to: provide the first formatted PII data from the secure connector to the secure join module via an extract-transform-load (ETL) pipeline (…match different PII data among trading partners using the main tokenizer, and corresponding tokens may be sent back to the trading partners…linking of records may be performed by certain additional special programming and analysis software. For example, record linking fits into a general class of data processing known as data integration, which can be defined as the problem of combining information from multiple heterogeneous data sources. Data integration can include data preparation steps such as parsing, profiling, cleansing, normalization, and parsing and standardization of the raw input data prior to record linkage to improve the quality of the input data and to make the data more consistent and comparable (these data preparation steps are sometimes referred to as ETL or extract, transform, load) …see par. 145, 151). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Sultan in the combination of Arasu and Ortiz for including the above limitations because one ordinary skill in the art would recognize it would further detect and prevent fraud from plurality of PII fields…see Sultan, par. 20-21. As per claim 20, the combination of Arasu, Ortiz and Sultan discloses wherein the ETL pipeline is configured to provide the first formatted PII data to (i) the data service and (ii) a repository for time-deferred consumption of the first formatted PII data (Sultan: par. 150-151). The motivation for claim 20 is the same motivation as in claim 19 above. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-form 892). The following Patents and Papers are cited to further show the state of the art at the time of Applicant’s invention with respect to a secure computing environment…for improving data security and computational efficiency when performing such operations as joining datasets. Gkoulalas-Vivanis (Pub. No. US 2019/0266352); “Coordinated De-Identification of a Dataset Across a Network”; -Teaches data masking and data pseudonymization technology protects direct identifiers in a dataset such as, for example, full names of individuals, social security numbers, medical IDs, phone numbers, credit card numbers, email addresses, etc., which are personal information that is most vulnerable in a person-specific dataset with respect to re-identification of individuals via triangulation attacks with external, publicly available datasets, such as voter registration lists, yellow pages, etc. Protection of direct identifiers in a dataset significantly reduces an overall privacy risk, thereby making the dataset less vulnerable during data transfer, par. 20. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GHAZAL B SHEHNI whose telephone number is (571)270-7479. The examiner can normally be reached Mon-Fri 9am-5pm PCT. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GHAZAL B SHEHNI/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Show 3 earlier events
Oct 02, 2025
Applicant Interview (Telephonic)
Oct 02, 2025
Examiner Interview Summary
Oct 16, 2025
Response Filed
Feb 13, 2026
Final Rejection mailed — §103
May 07, 2026
Response after Non-Final Action
May 22, 2026
Request for Continued Examination
Jun 02, 2026
Response after Non-Final Action
Aug 31, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12724864
REMOTE SECURE BOOT VERIFICATION SERVICE FOR SECURE DEPLOYMENT OF VIRTUAL MACHINES
2y 4m to grant Granted Sep 01, 2026
Patent 12705405
Read-Only Memory (ROM) Security
2y 10m to grant Granted Aug 11, 2026
Patent 12706737
METHOD FOR ROLE-BASED DATA TRANSMISSION USING PHYSICALLY UNCLONABLE FUNCTION (PUF)-BASED KEYS
2y 0m to grant Granted Aug 11, 2026
Patent 12699773
METHOD AND APPARATUS FOR CLONE SEARCH
2y 10m to grant Granted Aug 04, 2026
Patent 12694157
TERMINAL CHIP AND MEASUREMENT METHOD THEREOF
3y 0m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
87%
Grant Probability
99%
With Interview (+12.6%)
2y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 1085 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month