Prosecution Insights
Last updated: August 07, 2026
Application No. 18/601,482

APPARATUSES AND COMMUNICATION METHODS OF KEY GENERATION

Non-Final OA §101§103§112
Filed
Mar 11, 2024
Priority
Mar 24, 2023 — provisional 63/454,585
Examiner
CAREY, FORREST L
Art Unit
2491
Tech Center
2400 — Computer Networks
Assignee
Innopeak Technology Inc.
OA Round
3 (Non-Final)
57%
Grant Probability
Moderate
3-4
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 57% of resolved cases
57%
Career Allowance Rate
151 granted / 267 resolved
-1.4% vs TC avg
Strong +54% interview lift
Without
With
+54.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
19 currently pending
Career history
293
Total Applications
across all art units

Statute-Specific Performance

§101
9.7%
-30.3% vs TC avg
§103
59.5%
+19.5% vs TC avg
§102
15.1%
-24.9% vs TC avg
§112
12.4%
-27.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 267 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 5/26/2026 has been entered. Status of Claims Claims 1-2, 4-10, 12-22 are pending. Claims 3, 11 are cancelled. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-2, 4-10, 12-22 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claim 1 recites “wherein obtaining… the second physical layer key comprises performing a randomization operation, a quantization operation, a reconciliation operation, and a shared key stream operation on the first physical layer key”. Each of these operations is recited in the claim at a high level of generality, so as to be unclear to a person of ordinary skill in the art which operations are actually intended, and the specification does not resolve the manner and process of making and using. A review of the specification finds the following: [0070] Any of the well-known randomization, quantization, and reconciliation techniques can be used in this loop feedback physical layer shared key generation mechanism. This is the nearest paragraph to a definition for each of the three “operations” in the disclosure. A “shared key stream operation” is never defined at all; it is unclear if the “shared key stream operation” relates to the frequent “key stream” references throughout the specification (e.g. [0071], [0073], [0074], [0076], [0077]). As applicant has provided no clear definitions of each of the “operations”, applicant essentially provides no description or limitation of the claims. The broadest reasonable interpretation of “randomization operation” includes almost limitless variations of mathematical functions over many different fields of endeavor; the same is true of “quantization operations”, “reconciliation operations”, and “shared key stream operations”. For instance, the quantization operations are frequently used in quantum key distribution techniques. While applicant claims a method for key distribution, it does not appear to include elements related to quantum key distribution. Therefore, it is unclear if such a “well-known” quantization technique would apply. Therefore, the specification does not support the scope of the various claimed “operations” as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor had possession of the claimed invention; See MPEP § 2161.01(I). None of claims 2, 4-8 fix this and are therefore rejected for the same reasons. Independent claims 9 and 17 contain corresponding subject matter, and are therefore rejected for corresponding reasons, as well as each of their respective dependent claims 10, 12-16, 18-22. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-2, 4-10, 12-16, 18 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim(s) recite(s) obtaining a physical layer key, using the key as input of a physical layer key generator, and obtaining a second… key as an output of the generator, which falls under mathematical concepts related to cryptography. This judicial exception is not integrated into a practical application because the additional recited elements as part of the method, e.g. “ambient internet-of-things (AIoT) device”, because they amount to simply implementing the abstract idea on a computer; as the generated key is never used for any purpose, the claim merely recites performing mathematical key generation steps, resulting in a mathematical result, i.e. the “second physical layer key”. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the claimed AIoT device merely acts as the device which acts as the vehicle for the mathematical steps. None of claims 2, 4-8 fix this and are therefore rejected for the same reasons. Claims 9-10, 12-16, 18 contain similar subject matter to claims 1-2, 4-8, but from the perspective of a node comprising a UE or base station, instead of an AIoT device, and are therefore rejected for similar reasons. Claims 17, 19-22 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim(s) recite(s) obtaining a physical layer key, using the key as input of a physical layer key generator, and obtaining a second… key as an output of the generator, which falls under mathematical concepts related to cryptography. This judicial exception is not integrated into a practical application because the additional recited elements as part of the method, e.g. “ambient internet-of-things (AIoT) device”, because they amount to simply implementing the abstract idea on a computer; as the generated key is never used for any purpose, the claim merely recites performing mathematical key generation steps, resulting in a mathematical result, i.e. the “second physical layer key”. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the claimed AIoT device merely acts as the device which acts as the vehicle for the mathematical steps, and the claimed memory, transceiver, and processor are well-understood, routine, conventional computer elements of which the AIoT device merely comprises. None of claims 19-22 fix this and are therefore rejected for the same reasons. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-2, 6-10, 14-19, 22 is/are rejected under 35 U.S.C. 103 as being unpatentable over Win et al (WO 2021/091615), and further in view of Salkintzis et al (WO 2024/088582), Pointcheval et al (PGPUB 2021/0083862), and Dandekar et al (PGPUB 2024/0214803). Regarding Claim 1: Win teaches a wireless communication method of key generation (abstract, physical layer key generation), comprising (page 3 line 13-22, internet of things devices): obtaining, by an internet-of-things (IoT) device, a first physical layer key used in at least one previous communication with a node (page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600, a transmitting device performs the encryption steps 610, and the receiving device performs the decrypting steps 622; during key generation 600, a key generation module 606 takes as input a previous encryption key 602); using, by the IoT device, the first physical layer key as an input of a physical layer key generator (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602); and obtaining, by the IoT device, a second physical layer key generated based on at least a part of the first physical layer key, wherein the second physical layer key is an output of the physical layer key generator (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602 and a current key derived from currently correlated phase-related channel state information 604; the current key may include, but need not be limited to, the quantity; in general any key derived from current phase-related channel state information that is correlated between sender and receiver may be used; the key generation module 606 combines the two keys 602 and 604 to produce a current encryption key 608); wherein obtaining, by the IoT device, the second physical layer key comprises performing a randomization operation, a quantization operation, and a shared key stream operation on the first physical layer key (page 2 line 12-21, key generation from the physical layer of a channel, such as wireless radio frequency channels, linking communication nodes has attracted interest in recent years; since multipath environments generally cause time-varying and location-sensitive fading effects on the wireless signals, the wireless channel parameters (e.g., path delays and path amplitudes) are regarded as a proper random source to generate secret keys; page 9 line 14-17, key extraction begins by converting the analog signal to a digital signal; to that end, we implement a quantization scheme for transforming the complex values to binary values for key generation; page 13 line 14-20, we introduce the cross-layer design by combining a recently-computed raw key and the old encryption key together to obtain the new encryption key using XOR (i.e. “shared key stream operation”); page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600; key derived from currently correlated phase-related channel state information 604); wherein when the key generation is put into use a first time, in a case where the IoT device is pre-configured with a shared key, the shared key is input into the key generation (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602 and a current key derived from currently correlated phase-related channel state information 604; the current key may include, but need not be limited to, the quantity; in general any key derived from current phase-related channel state information that is correlated between sender and receiver may be used; the key generation module 606 combines the two keys 602 and 604 to produce a current encryption key 608). Win does not explicitly teach wherein the internet-of-things device is an ambient internet-of-things (AIoT) device. However, Salkintzis teaches the concept wherein an internet-of-things device is an ambient internet-of-things (AIoT) device ([0002] ambient IoT devices; [0091] AIoT security key, part of security information). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the ambient internet of things device teachings of Salkintzis with the key generation of an internet of things device teachings of Win, with the benefit of incorporating secure low-overhead key generation methods into a larger variety of devices which would benefit from such reduced computation methods to conserve power, such as ambient devices, which typically rely on miniscule amounts of environmental power to function, thereby improving the security of such device types. Neither Win nor Salkintzis explicitly teaches wherein obtaining the second physical layer key comprises performing a reconciliation operation on the first physical layer key. However, Pointcheval teaches the concept wherein obtaining a second physical layer key comprises performing a reconciliation operation on a first physical layer key ([0039] when generating the session key used to communicate with the second device, the second device generates the session key used to communicate with the first device, based on one or more of the following parameters: the original key; [0112] it should be understood that b.sup.Tt and s.sup.Tc can be very approximate provided that a related parameter and vector are properly selected; during decapsulation, the device A needs to perform proper reconciliation on the ciphertext and the decrypted original key, in other words, some approximate and encoding operations need to be performed). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the key reconciliation techniques of Pointcheval with the key generation of an internet of things device teachings of Win in view of Salkintzis, in order to improve performance and reliability of the key sharing by using methods which ensure that each party to the key sharing operation can generate functionally equivalent session keys using properly reconciled values. Neither Win nor Salkintzis nor Pointcheval explicitly teaches wherein when the key generation is put into use a first time, in a case where there is not a key generated from prior iteration, the first physical layer key is initialized to be all 0’s. However, Dandekar teaches the concept wherein when a key generation is put into use a first time, in a case where there is not a key generated from prior iteration, the first physical layer key is initialized to be all 0’s ([0031] the state is used to generate bits based on the channel symmetry that form the key, which are continuously placed into a shift register 210 as shown in FIG. 2; the bits may be continuously updated until a system specified event occurs, upon which the current key value may be transferred from the shift registers into memory 211; the system event may be either time-triggered based on an interrupt or event-triggered based on the number of packets successfully transmitted or received; at this point, the key is (1) used on its own, (2) mixed with a software encryption key from the application layer, or (3) mixed with the previously valid physical encryption key to generate a more secure key; the key mixing function 220 shown in FIG. 2 is applied with XORs; [0039] the key policy discussed in Section 3.1 is adapted to an FPGA fabric; to implement the key policy on an FPGA, the bits generated from the real-time algorithm described in Section 2.2 may be placed into a shift register capable of storing N bits, where N is the size of the key; the content stored in memory may serve as the key for the software layer for the current time session; the current session key applied within the software layer may be XORed with the physical layer key, which was initialized to all zeros, to create a new temporally dependent key). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the key initialized to zero teachings of Dandekar with the key generation of an internet of things device teachings of Win in view of Salkintzis and Pointcheval; a person of ordinary skill in the art, faced with the problem of initializing the state of a key generation algorithm, must choose from a limited pool of available options for the initial values of the input parameters. It would therefore be obvious to choose to zero out the initial physical layer key parameter in order to reset the system and generate a predictable outcome. Regarding Claim 2: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 1. In addition, Win teaches wherein the physical layer key generator is a loop feedback physical layer key generation (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602, i.e. “loop feedback”). Regarding Claim 6: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 1. In addition, Win teaches the method, further comprising generating an encrypted message based on the second physical layer key (page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600, a transmitting device performs the encryption steps 610, and the receiving device performs the decrypting steps 622; during the encrypting phase 610, an encryption module 618 receives as input a plaintext message 612, as well as a current encryption key 614 and a counter value 616; the encryption module 618 then encrypts the plaintext to produce ciphertext 620 as described above; the ciphertext may be transmitted by the transmitting device). Regarding Claim 7: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 6. In addition, Win teaches the method further comprising sending the encrypted message to the node (page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600, a transmitting device performs the encryption steps 610, and the receiving device performs the decrypting steps 622; during the encrypting phase 610, an encryption module 618 receives as input a plaintext message 612, as well as a current encryption key 614 and a counter value 616; the encryption module 618 then encrypts the plaintext to produce ciphertext 620 as described above; the ciphertext may be transmitted by the transmitting device). Regarding Claim 8: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 1. In addition, Win teaches wherein the node is a user equipment (UE) or a base station (page 3 line 13-22, devices in an “internet of things” setting, such as connected appliances, smart speakers, connected vehicles, etc., i.e. “user equipment”). Regarding Claim 9: Win teaches a wireless communication method of key generation, (abstract, physical layer key generation) comprising: obtaining, by a node, a first physical layer key used in at least one previous communication with an internet-of-things (IoT) device (page 3 line 13-22, internet of things devices; page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600, a transmitting device performs the encryption steps 610, and the receiving device performs the decrypting steps 622; during key generation 600, a key generation module 606 takes as input a previous encryption key 602); using, by the node, the first physical layer key as an input of a physical layer key generator (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602); and obtaining, by the node, a second physical layer key generated based on at least a part of the first physical layer key, wherein the second physical layer key is an output of the physical layer key generator (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602 and a current key derived from currently correlated phase-related channel state information 604; the current key may include, but need not be limited to, the quantity; in general any key derived from current phase-related channel state information that is correlated between sender and receiver may be used; the key generation module 606 combines the two keys 602 and 604 to produce a current encryption key 608); wherein obtaining, by the node, the second physical layer key comprises performing a randomization operation, a quantization operation, and a shared key stream operation on the first physical layer key (page 2 line 12-21, key generation from the physical layer of a channel, such as wireless radio frequency channels, linking communication nodes has attracted interest in recent years; since multipath environments generally cause time-varying and location-sensitive fading effects on the wireless signals, the wireless channel parameters (e.g., path delays and path amplitudes) are regarded as a proper random source to generate secret keys; page 9 line 14-17, key extraction begins by converting the analog signal to a digital signal; to that end, we implement a quantization scheme for transforming the complex values to binary values for key generation; page 13 line 14-20, we introduce the cross-layer design by combining a recently-computed raw key and the old encryption key together to obtain the new encryption key using XOR (i.e. “shared key stream operation”); page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600; key derived from currently correlated phase-related channel state information 604); wherein when the key generation is put into use a first time, in a case where the IoT device is pre-configured with a shared key, the shared key is input into the key generation (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602 and a current key derived from currently correlated phase-related channel state information 604; the current key may include, but need not be limited to, the quantity; in general any key derived from current phase-related channel state information that is correlated between sender and receiver may be used; the key generation module 606 combines the two keys 602 and 604 to produce a current encryption key 608); wherein the node comprises a UE or base station (page 3 line 13-22, internet of things devices). Win does not explicitly teach wherein the internet-of-things device is an ambient internet-of-things (AIoT) device. However, Salkintzis teaches the concept wherein an internet-of-things device is an ambient internet-of-things (AIoT) device ([0002] ambient IoT devices; [0091] AIoT security key, part of security information). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the ambient internet of things device teachings of Salkintzis with the key generation of an internet of things device teachings of Win, with the benefit of incorporating secure low-overhead key generation methods into a larger variety of devices which would benefit from such reduced computation methods to conserve power, such as ambient devices, which typically rely on miniscule amounts of environmental power to function, thereby improving the security of such device types. Neither Win nor Salkintzis explicitly teaches wherein obtaining the second physical layer key comprises performing a reconciliation operation on the first physical layer key. However, Pointcheval teaches the concept wherein obtaining a second physical layer key comprises performing a reconciliation operation on a first physical layer key ([0039] when generating the session key used to communicate with the second device, the second device generates the session key used to communicate with the first device, based on one or more of the following parameters: the original key; [0112] it should be understood that b.sup.Tt and s.sup.Tc can be very approximate provided that a related parameter and vector are properly selected; during decapsulation, the device A needs to perform proper reconciliation on the ciphertext and the decrypted original key, in other words, some approximate and encoding operations need to be performed). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the key reconciliation techniques of Pointcheval with the key generation of an internet of things device teachings of Win in view of Salkintzis, in order to improve performance and reliability of the key sharing by using methods which ensure that each party to the key sharing operation can generate functionally equivalent session keys using properly reconciled values. Neither Win nor Salkintzis nor Pointcheval explicitly teaches wherein when the key generation is put into use a first time, in a case where there is not a key generated from prior iteration, the first physical layer key is initialized to be all 0’s. However, Dandekar teaches the concept wherein when a key generation is put into use a first time, in a case where there is not a key generated from prior iteration, the first physical layer key is initialized to be all 0’s ([0031] the state is used to generate bits based on the channel symmetry that form the key, which are continuously placed into a shift register 210 as shown in FIG. 2; the bits may be continuously updated until a system specified event occurs, upon which the current key value may be transferred from the shift registers into memory 211; the system event may be either time-triggered based on an interrupt or event-triggered based on the number of packets successfully transmitted or received; at this point, the key is (1) used on its own, (2) mixed with a software encryption key from the application layer, or (3) mixed with the previously valid physical encryption key to generate a more secure key; the key mixing function 220 shown in FIG. 2 is applied with XORs; [0039] the key policy discussed in Section 3.1 is adapted to an FPGA fabric; to implement the key policy on an FPGA, the bits generated from the real-time algorithm described in Section 2.2 may be placed into a shift register capable of storing N bits, where N is the size of the key; the content stored in memory may serve as the key for the software layer for the current time session; the current session key applied within the software layer may be XORed with the physical layer key, which was initialized to all zeros, to create a new temporally dependent key). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the key initialized to zero teachings of Dandekar with the key generation of an internet of things device teachings of Win in view of Salkintzis and Pointcheval; a person of ordinary skill in the art, faced with the problem of initializing the state of a key generation algorithm, must choose from a limited pool of available options for the initial values of the input parameters. It would therefore be obvious to choose to zero out the initial physical layer key parameter in order to reset the system and generate a predictable outcome. Regarding Claim 10: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 9. In addition, Win teaches wherein the physical layer key generator is a loop feedback physical layer key generation (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602, i.e. “loop feedback”). Regarding Claim 14: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 9. In addition, Win teaches the method further comprising receiving an encrypted message from the IoT device (page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600, a transmitting device performs the encryption steps 610, and the receiving device performs the decrypting steps 622; during the encrypting phase 610, an encryption module 618 receives as input a plaintext message 612, as well as a current encryption key 614 and a counter value 616; the encryption module 618 then encrypts the plaintext to produce ciphertext 620 as described above; the ciphertext may be transmitted by the transmitting device); and Salkintzis teaches wherein the IoT device is an AIoT device ([0002] ambient IoT devices). The rationale to combine Win and Salkintzis is the same as provided for claim 9 due to the overlapping subject matter between claims 9 and 14. Regarding Claim 15: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 14. In addition, Win teaches the method further comprising decrypting the encrypted message based on the second physical layer key (page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600, a transmitting device performs the encryption steps 610, and the receiving device performs the decrypting steps 622; during the encrypting phase 610, an encryption module 618 receives as input a plaintext message 612, as well as a current encryption key 614 and a counter value 616; the encryption module 618 then encrypts the plaintext to produce ciphertext 620 as described above; the ciphertext may be transmitted by the transmitting device). Regarding Claim 16: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 9. In addition, Win teaches wherein the node is a user equipment (UE) or a base station (page 3 line 13-22, devices in an “internet of things” setting, such as connected appliances, smart speakers, connected vehicles, etc., i.e. “user equipment”). Regarding Claim 17: Win teaches an internet-of-things (IoT) device (abstract, physical layer key generation; page 3 line 13-22, internet of things devices), comprising: a memory (page 17 line 17-page 18 line 13, software may include instructions stored on a non-transitory machine-readable medium); a transceiver (page 17 line 17-page 18 line 13, hardware may further include WiFi-equipped devices such as WiFi cards, chips, etc.; the hardware may further any components capable of wireless communication, e.g. those embedded in mobile devices, “smart” appliances, switches, vehicles, measurement instruments, or the like); and a processor coupled to the memory and the transceiver (page 17 line 17-page 18 line 13, general-purpose or a special-purpose processor); wherein the IoT device is configured to: obtain a first physical layer key used in at least one previous communication with an ambient internet-of-things (IoT) device (page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600, a transmitting device performs the encryption steps 610, and the receiving device performs the decrypting steps 622; during key generation 600, a key generation module 606 takes as input a previous encryption key 602); use the first physical layer key as an input of a physical layer key generator (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602); and obtain a second physical layer key generated based on at least a part of the first physical layer key, wherein the second physical layer key is an output of the physical layer key generator (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602 and a current key derived from currently correlated phase-related channel state information 604; the current key may include, but need not be limited to, the quantity; in general any key derived from current phase-related channel state information that is correlated between sender and receiver may be used; the key generation module 606 combines the two keys 602 and 604 to produce a current encryption key 608); wherein obtaining the second physical layer key comprises performing a randomization operation, a quantization operation, and a shared key stream operation on the first physical layer key (page 2 line 12-21, key generation from the physical layer of a channel, such as wireless radio frequency channels, linking communication nodes has attracted interest in recent years; since multipath environments generally cause time-varying and location-sensitive fading effects on the wireless signals, the wireless channel parameters (e.g., path delays and path amplitudes) are regarded as a proper random source to generate secret keys; page 9 line 14-17, key extraction begins by converting the analog signal to a digital signal; to that end, we implement a quantization scheme for transforming the complex values to binary values for key generation; page 13 line 14-20, we introduce the cross-layer design by combining a recently-computed raw key and the old encryption key together to obtain the new encryption key using XOR (i.e. “shared key stream operation”); page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600; key derived from currently correlated phase-related channel state information 604); wherein when the key generation is put into use a first time, in a case where the AIoT device is pre-configured with a shared key, the shared key is input into the key generation (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602 and a current key derived from currently correlated phase-related channel state information 604; the current key may include, but need not be limited to, the quantity; in general any key derived from current phase-related channel state information that is correlated between sender and receiver may be used; the key generation module 606 combines the two keys 602 and 604 to produce a current encryption key 608). Win does not explicitly teach wherein the internet-of-things device is an ambient internet-of-things (AIoT) device. However, Salkintzis teaches the concept wherein an internet-of-things device is an ambient internet-of-things (AIoT) device ([0002] ambient IoT devices; [0091] AIoT security key, part of security information). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the ambient internet of things device teachings of Salkintzis with the key generation of an internet of things device teachings of Win, with the benefit of incorporating secure low-overhead key generation methods into a larger variety of devices which would benefit from such reduced computation methods to conserve power, such as ambient devices, which typically rely on miniscule amounts of environmental power to function, thereby improving the security of such device types. Neither Win nor Salkintzis explicitly teaches wherein obtaining the second physical layer key comprises performing a reconciliation operation on the first physical layer key. However, Pointcheval teaches the concept wherein obtaining a second physical layer key comprises performing a reconciliation operation on a first physical layer key ([0039] when generating the session key used to communicate with the second device, the second device generates the session key used to communicate with the first device, based on one or more of the following parameters: the original key; [0112] it should be understood that b.sup.Tt and s.sup.Tc can be very approximate provided that a related parameter and vector are properly selected; during decapsulation, the device A needs to perform proper reconciliation on the ciphertext and the decrypted original key, in other words, some approximate and encoding operations need to be performed). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the key reconciliation techniques of Pointcheval with the key generation of an internet of things device teachings of Win in view of Salkintzis, in order to improve performance and reliability of the key sharing by using methods which ensure that each party to the key sharing operation can generate functionally equivalent session keys using properly reconciled values. Neither Win nor Salkintzis nor Pointcheval explicitly teaches wherein when the key generation is put into use a first time, in a case where there is not a key generated from prior iteration, the first physical layer key is initialized to be all 0’s. However, Dandekar teaches the concept wherein when a key generation is put into use a first time, in a case where there is not a key generated from prior iteration, the first physical layer key is initialized to be all 0’s ([0031] the state is used to generate bits based on the channel symmetry that form the key, which are continuously placed into a shift register 210 as shown in FIG. 2; the bits may be continuously updated until a system specified event occurs, upon which the current key value may be transferred from the shift registers into memory 211; the system event may be either time-triggered based on an interrupt or event-triggered based on the number of packets successfully transmitted or received; at this point, the key is (1) used on its own, (2) mixed with a software encryption key from the application layer, or (3) mixed with the previously valid physical encryption key to generate a more secure key; the key mixing function 220 shown in FIG. 2 is applied with XORs; [0039] the key policy discussed in Section 3.1 is adapted to an FPGA fabric; to implement the key policy on an FPGA, the bits generated from the real-time algorithm described in Section 2.2 may be placed into a shift register capable of storing N bits, where N is the size of the key; the content stored in memory may serve as the key for the software layer for the current time session; the current session key applied within the software layer may be XORed with the physical layer key, which was initialized to all zeros, to create a new temporally dependent key). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the key initialized to zero teachings of Dandekar with the key generation of an internet of things device teachings of Win in view of Salkintzis and Pointcheval; a person of ordinary skill in the art, faced with the problem of initializing the state of a key generation algorithm, must choose from a limited pool of available options for the initial values of the input parameters. It would therefore be obvious to choose to zero out the initial physical layer key parameter in order to reset the system and generate a predictable outcome. Regarding Claim 18: Win in view of Salkintzis, Pointcheval, and Dandekar teaches a node (abstract, physical layer key generation; page 3 line 13-22, internet of things devices), comprising: a memory (page 17 line 17-page 18 line 13, software may include instructions stored on a non-transitory machine-readable medium); a transceiver (page 17 line 17-page 18 line 13, hardware may further include WiFi-equipped devices such as WiFi cards, chips, etc.; the hardware may further any components capable of wireless communication, e.g. those embedded in mobile devices, “smart” appliances, switches, vehicles, measurement instruments, or the like); and a processor coupled to the memory and the transceiver (page 17 line 17-page 18 line 13, general-purpose or a special-purpose processor); wherein the processor is configured to perform the method of claim 9 (see claim 9, above) Regarding Claim 19: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the ambient internet-of-things (AIoT) device of claim 17. In addition, Win teaches wherein the physical layer key generator is a loop feedback physical layer key generation (page 14 line 1-10, during key generation 600, a key generation module 606 takes as input a previous encryption key 602, i.e. “loop feedback”). Regarding Claim 22: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the ambient internet-of-things (AIoT) device of claim 17. In addition, Win teaches wherein the AIoT device is further configured to generate an encrypted message based on the second physical layer key (page 14 line 1-10, both a transmitting device and a receiving device perform the key generation steps 600, a transmitting device performs the encryption steps 610, and the receiving device performs the decrypting steps 622; during the encrypting phase 610, an encryption module 618 receives as input a plaintext message 612, as well as a current encryption key 614 and a counter value 616; the encryption module 618 then encrypts the plaintext to produce ciphertext 620 as described above; the ciphertext may be transmitted by the transmitting device). Claim(s) 4, 12, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Win in view of Salkintzis, Pointcheval, and Dandekar, and further in view of Wang et al (PGPUB 2021/0351936). Regarding Claim 4: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 1. Neither Win nor Salkintzis nor Pointcheval nor Dandekar explicitly teaches wherein the second physical layer key is used as a one-time pad (OTP). However, Wang teaches the concept wherein a physical layer key is used as a one-time pad (OTP) ([0005] keys generated by the physical layer; [0014] one-time pad encryption is achieved); and Win teaches wherein the physical layer key is a second physical layer key (page 14 line 1-10). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the one-time pad encryption teachings of Wang with the key generation of an internet of things device teachings of Win in view of Salkintzis, Pointcheval, and Dandekar; it is well-known in the art that one-time pad is one of the most mathematically secure forms of encryption, and that the difficulty lies in distributing the key material securely without being intercepted by an eavesdropper. Therefore, combining the secure key generation techniques of Win in view of Salkintzis with the one-time pad encryption teachings of Wang would result in an overall improvement to the security environment. Regarding Claim 12: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 9. Neither Win nor Salkintzis nor Pointcheval nor Dandekar explicitly teaches wherein the second physical layer key is used as a one-time pad (OTP). However, Wang teaches the concept wherein a physical layer key is used as a one-time pad (OTP) ([0005] keys generated by the physical layer; [0014] one-time pad encryption is achieved); and Win teaches wherein the physical layer key is a second physical layer key (page 14 line 1-10). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the one-time pad encryption teachings of Wang with the key generation of an internet of things device teachings of Win in view of Salkintzis; it is well-known in the art that one-time pad is one of the most mathematically secure forms of encryption, and that the difficulty lies in distributing the key material securely without being intercepted by an eavesdropper. Therefore, combining the secure key generation techniques of Win in view of Salkintzis, Pointcheval, and Dandekar with the one-time pad encryption teachings of Wang would result in an overall improvement to the security environment. Regarding Claim 20: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the ambient internet-of-things (AIoT) device of claim 17. Neither Win nor Salkintzis nor Pointcheval nor Dandekar explicitly teaches wherein the second physical layer key is used as a one-time pad (OTP). However, Wang teaches the concept wherein a physical layer key is used as a one-time pad (OTP) ([0005] keys generated by the physical layer; [0014] one-time pad encryption is achieved); and Win teaches wherein the physical layer key is a second physical layer key (page 14 line 1-10). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the one-time pad encryption teachings of Wang with the key generation of an internet of things device teachings of Win in view of Salkintzis, Pointcheval, and Dandekar; it is well-known in the art that one-time pad is one of the most mathematically secure forms of encryption, and that the difficulty lies in distributing the key material securely without being intercepted by an eavesdropper. Therefore, combining the secure key generation techniques of Win in view of Salkintzis with the one-time pad encryption teachings of Wang would result in an overall improvement to the security environment. Claim(s) 5, 13, 21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Win in view of Salkintzis, Pointcheval, and Dandekar, and further in view of Bartlett et al (PGPUB 2020/0336895). Regarding Claim 5: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 1. Neither Win nor Salkintzis nor Pointcheval nor Dandekar explicitly teaches the method further comprising performing a channel establishment procedure with the node. However, Bartlett teaches the concept of performing a channel establishment procedure with a node ([0067] local communication interface 303 and antenna 311 establishes local communication channels with each of the IoT devices 101-105). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the channel establishment teachings of Bartlett with the key generation of an internet of things device teachings of Win in view of Salkintzis, Pointcheval, and Dandekar; a person of ordinary skill in the art would have recognized that communicating devices must somehow be configured to establish a channel of some kind prior to/as part of the exchange of security information, in order for that security information to be effectively conveyed. Regarding Claim 13: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the wireless communication method of claim 9. Neither Win nor Salkintzis nor Pointcheval nor Dandekar explicitly teaches the method further comprising performing a channel establishment procedure with the AIoT device. However, Bartlett teaches the concept of performing a channel establishment procedure with an IoT device ([0067] local communication interface 303 and antenna 311 establishes local communication channels with each of the IoT devices 101-105); and Salkintzis teaches wherein the IoT device is an AIoT device ([0002] ambient IoT devices). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the channel establishment teachings of Bartlett with the key generation of an internet of things device teachings of Win in view of Salkintzis, Pointcheval, and Dandekar; a person of ordinary skill in the art would have recognized that communicating devices must somehow be configured to establish a channel of some kind prior to/as part of the exchange of security information, in order for that security information to be effectively conveyed. The rationale to combine Win and Salkintzis is the same as provided for claim 9 due to the overlapping subject matter between claims 9 and 13. Regarding Claim 21: Win in view of Salkintzis, Pointcheval, and Dandekar teaches the ambient internet-of-things (AIoT) device of claim 17. Neither Win nor Salkintzis nor Pointcheval nor Dandekar explicitly teaches the method further comprising performing a channel establishment procedure with the node. However, Bartlett teaches the concept of performing a channel establishment procedure with a node ([0067] local communication interface 303 and antenna 311 establishes local communication channels with each of the IoT devices 101-105). It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the channel establishment teachings of Bartlett with the key generation of an internet of things device teachings of Win in view of Salkintzis, Pointcheval, and Dandekar; a person of ordinary skill in the art would have recognized that communicating devices must somehow be configured to establish a channel of some kind prior to/as part of the exchange of security information, in order for that security information to be effectively conveyed. Response to Arguments Applicant's arguments filed 5/26/2026 have been fully considered but they are not persuasive. Regarding the claim objections: Applicant’s amendments have overcome the previous objections, which are therefore withdrawn. Regarding the rejection of claims under 35 USC 101: Applicant’s amendments have failed to overcome the 35 USC 101 rejection, which is therefore maintained. Upon further consideration, the examiner has concluded that mere generation of a key fails to integrate the mathematical function into a practical application. Further details regarding the analysis are provided above, in the 35 USC 101 rejection. Regarding the rejection of claims under 35 USC 103: Examiner’s response to applicant’s arguments, page 8 paragraph 9-page 9 paragraph 5: Applicant mentions “the specific operation of the quantization”; however, this is the entire issue: there is no specific operation of the quantization. Applicant claims an operation which can be interpreted in myriad ways, across many different technologies, even limiting oneself to key generation techniques generally. If applicant is unwilling to define the scope of what particular “quantization operation” applicant has in mind, then it is up to the examiner to determine the broadest reasonable interpretation. It is the examiner’s view that an “operation” can be a single function, or a process comprising many steps, and that a “quantization operation” can be a process comprising many steps which includes quantization. Therefore, the entire process of quantizing an analog signal and combining it with a previous encryption key can be seen as performing a “quantization operation” on the previous key. Examiner has not shifted the object of the quantization operation; it remains the previous key. However, examiner has interpreted the “quantization operation” to include every step in the process, including the quantization step and the mixing of the quantized value with the previous key. Examiner’s response to applicant’s arguments, page 9 paragraph 5-page 10 paragraph 1: Applicant’s arguments regarding Elshafie are moot, as Elshafie is no longer part of any rejection of the claims. Examiner’s response to applicant’s arguments, page 10 paragraph 2-3: In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., “to provide a new free random number source and to bind the previously used encryption key with a currently generated encryption key, thereby enhancing the security level of the currently generated encryption key”) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Applicant’s arguments with regard to independent claims 9 and 17 are similar to those regarding claim 1 and are therefore responded to in a similar way. Applicant further argues that the dependent claims are allowable due to depending on an allowable independent claim. However, as shown above, the independent claims are not allowable. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to FORREST L CAREY whose telephone number is (571)270-7814. The examiner can normally be reached 9:00AM-5:30PM M-F. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at (571) 272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /FORREST L CAREY/Examiner, Art Unit 2491 /WILLIAM R KORZUCH/Supervisory Patent Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

Mar 11, 2024
Application Filed
Aug 12, 2025
Non-Final Rejection mailed — §101, §103, §112
Oct 22, 2025
Response Filed
Feb 26, 2026
Final Rejection mailed — §101, §103, §112
Apr 23, 2026
Response after Non-Final Action
May 26, 2026
Request for Continued Examination
Jun 02, 2026
Response after Non-Final Action
Jun 17, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12696083
Securing Media Stream Communications
4y 5m to grant Granted Jul 28, 2026
Patent 12683928
Hybrid web application firewall
4y 1m to grant Granted Jul 14, 2026
Patent 12647791
METHOD AND DEVICE FOR AUTHENTICATING A PRIMARY STATION
3y 4m to grant Granted Jun 02, 2026
Patent 12625932
IDENTITY AUTHENTICATION USING BIOMETRICS
4y 1m to grant Granted May 12, 2026
Patent 12625979
ENFORCEMENT OF AUTHORIZATION RULES ACROSS DATA ENVIRONMENTS
4y 0m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
57%
Grant Probability
99%
With Interview (+54.4%)
3y 7m (~1y 3m remaining)
Median Time to Grant
High
PTA Risk
Based on 267 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month