Prosecution Insights
Last updated: October 04, 2026
Application No. 18/759,321

DISTRIBUTED MESSAGE AUTHENTICATION CODES FOR MULTIPLE PARTIES

Final Rejection §101§103
Filed
Jun 28, 2024
Priority
Sep 14, 2023 — provisional 63/582,736
Examiner
ULLAH, SHARIF E
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Seagate Technology LLC
OA Round
2 (Final)
85%
Grant Probability
Favorable
3-4
OA Rounds
3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
393 granted / 464 resolved
+26.7% vs TC avg
Strong +22% interview lift
Without
With
+21.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
23 currently pending
Career history
481
Total Applications
across all art units

Statute-Specific Performance

§101
13.6%
-26.4% vs TC avg
§103
60.4%
+20.4% vs TC avg
§102
6.8%
-33.2% vs TC avg
§112
11.9%
-28.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 464 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed have been fully considered but they are not persuasive. The applicant argues that neither Shaw et al. (US 2013/0044876), hereon referred to as Shaw, nor Durham et al. (US 2022/0222158), hereon referred to as Durham, alone or in combination teach/suggest all of the limitations of the independent claim(s). The applicant argues that Shaw fails to teach multi-party, independent cryptographic generation and coordination among independently keyed parties producing intermediate authentication values for later aggregation. The applicant also mentions that Durham teaches aggregation that occurs in a memory/cache-line integrity context, not in a distributed, multi-party authentication system. The described technology independently generates intermediate message authentication codes across multiple independently-acting parties, whereas the Durham aggregation is intra-system and data-block oriented by a single system. However, the Examiner respectfully disagrees. As currently presented the, the claim language mentions "cryptographically generating an intermediate message authentication code as a function of the message and a cryptographic key assigned to a first party" and "generating a first instance of an aggregate message authentication code corresponding to the message by combining the intermediate message authentication code with one or more other intermediate message authentication codes of one or more second parties, wherein each code of the one or more other intermediate message authentication codes is cryptographically generated as a function of the message and individual cryptographic key assigned to each of the one or more second parties". There is no mention, currently of "distributed" coordination, "independently-acting" parties, a "signing workflow," and "preserving cryptographic independence. Specification embodiments are not imported into the claims. In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). Additionally, the prior art is used in combination, in view of each other. Shaw teaches multiple parties, each with a party-specific key, generating MACs from the message (Paragraphs 0073-0075), where Durham teaches aggregating multiple authentication values into one MAC by mathematical combination (Paragraphs 0034; 0094). The applicant also argues that the references fail to teach a system with distributed, multi-party cryptographic coordination where multiple independent parties, including each cryptographically generate an intermediate authentication value, using distinct, party-specific keys, and do so as part of a coordinated, distributed signing workflow, and aggregation of authentication codes of multiple parties that preserves cryptographic independence of the parties. However, the Examiner respectfully disagrees. As currently presented, the claim language states, "generating a first instance of an aggregate message authentication code corresponding to the message by combining the intermediate message authentication code with one or more other intermediate message authentication codes of one or more second parties". The claim(s) does not require "distributed" coordination, a "signing workflow," or "preserving cryptographic independence." Specification limitations are not read into the claims. In re Van Geuns, 988 F.2d 1181 (Fed. Cir. 1993). Additionally, the applicant argues that the official notice is improper and unsupported. The applicant mentions that the office action relies on official notice to assert that claim limitations involving Carter-Wegman authentication and key-homomorphic cryptographic functions are "commonly known" and mere "design choices," without citing any documentary evidence. Under the MPEP, official notice is limited to indisputable, well-known facts, not to non-trivial technical or cryptographic constructs that are central to patentability. Here, the noticed features relate to specialized cryptographic mechanisms and their application in a distributed, multi-party aggregation architecture, which are neither self-evident nor universally accepted as routine. Because the noticed facts are material to the section 103 rejection and are reasonably traversed, the Examiner must provide affirmative evidence in the form of prior art or withdraw reliance on official notice. However, the Examiner provides US 2022/0014386 as affirmative evidence in the form of prior art. Applicant’s arguments regarding 35 USC 101 have been considered, and regarding the non-transitory portion have been deemed persuasive, but regarding the abstract idea are not persuasive. The applicant argues that claims are not directed to an abstract idea of generic data processing. At Step 2A, the claims recite a practical application / technological improvement, namely a concrete, distributed cryptographic architecture, coordinated multi-party authentication, and structured aggregation enabling efficient verification. The rejection improperly characterizes the claims as abstract first (without analyzing individual claim elements, identifying a mental process, mathematical concept, or fundamental economic practice), and then seeks "significantly more" under Step 2B. Yet, when viewed as a whole, the claims improve the functioning of distributed authentication systems, not merely the use of a generic computer. However, the Examiner respectfully disagrees. Step 2A, Prong 1 -- The claims recite mathematical concepts. "Cryptographically generating an intermediate message authentication code as a function of the message and a cryptographic key" and "generating a first instance of an aggregate message authentication code... by combining the intermediate message authentication code with one or more other intermediate message authentication codes" are mathematical operations within the "mathematical concepts" grouping. MPEP 2106.04(a)(2)(I). Step 2A, Prong 2 . The claims recite no particular machine, no transformation of a particular article, and no specific technological improvement. The "technological improvement" is drawn from the specification, not the claims. Specification limitations are not imported under BRI. In re Van Geuns, 988 F.2d 1181 (Fed. Cir. 1993). As written, the claims recite mathematical operations performed by a generic processor, not a practical application under Step 2A, Prong 2. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-8, 17-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e. an abstract idea) without significantly more. Claim 1 is directed to a process processing a message on a device. The underlying invention is merely directed towards data processing a message by computing functions and is therefore abstract. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because the limitations are merely instructions to implement the abstract idea on a computer and require no more than a generic computer to perform generic computer functions that are well-understood, routine and conventional activities previously known to the industry (e.g. sending data). The data processing of a message by computing functions does not enhance the functionality of the computer. Further, the claim does not recite an improvement to another technology or technical field, an improvement to the functioning of the computer itself, or meaningful limitations beyond generally linking the use of an abstract idea to a particular technological environment. Dependent claims 2-8 do not cure the deficiency of claim 1, therefore are also rejected 35 USC 101 for they dependency on claim 1. Claim 17 is directed to a process processing a message on a device. The underlying invention is merely directed towards data processing a message by computing functions and is therefore abstract. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because the limitations are merely instructions to implement the abstract idea on a computer and require no more than a generic computer to perform generic computer functions that are well-understood, routine and conventional activities previously known to the industry (e.g. sending data). The data processing of a message by computing functions does not enhance the functionality of the computer. Further, the claim does not recite an improvement to another technology or technical field, an improvement to the functioning of the computer itself, or meaningful limitations beyond generally linking the use of an abstract idea to a particular technological environment. Dependent claims 18-20 do not cure the deficiency of claim 17, therefore are also rejected 35 USC 101 for they dependency on claim 17. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-23 are rejected under 35 U.S.C 103 as being unpatentable over Shaw et al. (US 2013/0044876), hereon referred to as Shaw, in view of Durham et al. (US 2022/0222158), and hereon referred to as Durham. In regards to claims 1, 9 & 17 Shaw discloses cryptographically generating an intermediate message authentication code as a function of the message and a cryptographic key assigned to a first party (The process includes to encode the plaintext message into DNA code 3 words at a time, encryption with a pre-shared secret key; Paragraphs 0073-0090); and wherein each code of the one or more other intermediate message authentication codes is cryptographically generated as a function of the message and individual cryptographic key assigned to each of the one or more second parties (A common genome to use as an HMAC key; a pre-shared secret unique to each party; and HMAC algorithm; Paragraphs 0073-0090). However, Shaw does not disclose generating a first instance of an aggregate message authentication code corresponding to the message by combining the intermediate message authentication code with one or more other intermediate message authentication codes of one or more second parties. In an analogous art Durham discloses generating a first instance of an aggregate message authentication code corresponding to the message by combining the intermediate message authentication code with one or more other intermediate message authentication codes of one or more second parties (Generate an AMAC, each data block in chacheline set is multiplied with a parameter; the resulting products are XORed together to generate GHASH; Paragraphs 0092-0101). At the time before the effective filing date of the invention, it would have been obvious to the one with ordinary skill in the art to combine the teachings disclosed by Shaw, with the teachings disclosed by Durham regarding generating a first instance of an aggregate message authentication code corresponding to the message by combining the intermediate message authentication code with one or more other intermediate message authentication codes of one or more second parties. The suggestion/motivation of the combination would have been to provide aggregate GHASH-based message authentication code (MAC) over multiple cachelines with incremental updates (Durham; Paragraph 0002). In regards to claims 2, 10 & 18, Shaw discloses wherein the first party and the one or more second parties constitute multiple sending parties and further comprising: signing the message with the first instance of the aggregate message authentication code to yield a signed message (The sender encodes the plaintext message and appends the checksum to the message before transmitting; Paragraphs 0080-0090). In regards to claims 3, 10 & 18, Shaw discloses wherein the first party and the one or more second parties constitute multiple sending parties and further comprising: receiving the message and a second instance of the aggregate message authentication code, the second instance of the aggregate message authentication code being generated from intermediate message authentication codes of multiple sending parties; and comparing the first instance of the aggregate message authentication code to the second instance of the aggregate message authentication code, wherein the message is verified when the first instance of the aggregate message authentication code to the second instance of the aggregate message authentication code match within a difference margin (The receiver extracts the checksum from the message…The hash code computed at the receiver must have an exact match of the check sum; Paragraphs 0080-0090). In regards to claims 4 & 12, Shaw discloses wherein a number of sending parties signing the message and a number of verifying parties verifying the message are fixed and the difference margin is zero (The computed has code must have an exact match of the checksum; Paragraphs 0080-0090). In regards to claims 5 & 13, Shaw discloses wherein a number of sending parties signing the message and a number of verifying parties verifying the message are different and the difference margin is dependent on a sum of a number of sending parties signing the message and a number of verifying parties (Three entities possess a pre-shared secret which is unique to each party; Paragraphs 0070-0080). In regards to claims 6, 14 & 20, the combination of Shaw and Durham discloses wherein cryptographically generating comprises: cryptographically generating an intermediate message authentication code as a function of the message and a cryptographic key assigned to a first party using a Carter-Wegman message authentication code generation function (The elements presented in the claim(s) do not contain any additional features, do not present any inventive step or novelty not addressed/presented in the combination of Shaw and Durham. Examiner takes official notice, that these elements are commonly known, minor design details that are derivable from the prior art and are well known, and obvious to an ordinary skill in the art. The additional features of these claims represent normal design options, which the skilled person would implement the combination of Shaw and Durham, depending on the circumstances, without exercising any inventive activity). In regards to claims 7 & 15, the combination of Shaw and Durham discloses wherein a number of sending parties signing the message and a number of verifying parties verifying the message are different and cryptographically generating comprises: cryptographically generating an intermediate message authentication code as a function of the message and a cryptographic key assigned to a first party using a Carter-Wegman message authentication code generation function and a key-homomorphic pseudo-random function (The elements presented in the claim(s) do not contain any additional features, do not present any inventive step or novelty not addressed/presented in the combination of Shaw and Durham. Examiner takes official notice, that these elements are commonly known, minor design details that are derivable from the prior art and are well known, and obvious to an ordinary skill in the art. The additional features of these claims represent normal design options, which the skilled person would implement the combination of Shaw and Durham, depending on the circumstances, without exercising any inventive activity). In regards to claims 8 & 16, Durham discloses wherein combining comprises: performing an XOR operation on the intermediate message authentication code and the one or more other intermediate message authentication codes (The resulting products are XORed together; Paragraphs 0090-0095). In regards to claim 21, Shaw wherein the first party and the one or more second parties are associated with respective separate computing devices communicatively coupled over a network, wherein the one or more other intermediate message authentication codes are received from the respective separate computing devices of the one or more second parties, and further comprising communicating the message and the first instance of the aggregate message authentication code via at least one of a storage system or a communication channel over the network (as well as Mobile Ad hoc Network (MANET) situations that lack the standard network security infrastructure; if X and Y wish to substitute a new message with a valid hash code, or forward the message and have the message accepted by the network members, X and Y have to create a valid hash code and checksum, which requires knowledge of the chromosome sequence and valid pre-shared secrets known to the other MANET nodes. The MANET members may change their pre-shared secrets on a pre-established basis to thwart a brute force attack to derive the pre-shared secret from the hash code; Paragraphs 0040-0045; 0070-0075). In regards to claim 22, Shaw discloses wherein the intermediate message authentication code is generated without knowledge of individual cryptographic keys assigned to the one or more second parties, and wherein each of the one or more other intermediate message authentication codes is generated without knowledge of the cryptographic key assigned to the first party and without knowledge of the individual cryptographic keys assigned to any other of the one or more second parties ((1) a common genome, C, to use as an HMAC key; (2) a pre-shared secret (pss) unique to each party; and (3) the DNA-based HMAC algorithm.; X and Y have to create a valid hash code and checksum, which requires knowledge of the chromosome sequence and valid pre-shared secrets known to the other MANET nodes. The MANET members may change their pre-shared secrets on a pre-established basis to thwart a brute force attack to derive the pre-shared secret from the hash code; Paragraphs 0070-0075). In regards to claim 23, Shaw discloses wherein the cryptographic key assigned to the first party and individual cryptographic keys assigned to each of the one or more second parties are distributed by a dealer, and wherein the aggregate message authentication code cannot be forged by any proper subset of the first party and the one or more second parties (If Y can recover the original cryptographic sequence, or determine the genome and genome location that a cryptographic key was taken from, Y may be able to forge a valid hash code. This could be problematic for a cryptographic sequence due to the high degree of redundancy in all genomes. For this application, the hash code should be evaluated against the cryptographic key to ensure the hash code has the proper characteristics of diffusion and confusion; Paragraphs 0070-0075; 0095-0100). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHARIF E ULLAH whose telephone number is (571)272-5453. The examiner can normally be reached Mon-Fri 7:00-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHARIF E ULLAH/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Jun 28, 2024
Application Filed
Feb 20, 2026
Non-Final Rejection mailed — §101, §103
Apr 27, 2026
Interview Requested
May 14, 2026
Response Filed
Sep 02, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739108
BYPASSING TECHNIQUE TO ENABLE DIRECT ACCESS TO SNAPSHOT DATA IN OBJECT STORE
3y 0m to grant Granted Sep 15, 2026
Patent 12739111
KEY UPDATE METHOD, NETWORK ELEMENT, USER EQUIPMENT, AND STORAGE MEDIUM
2y 7m to grant Granted Sep 15, 2026
Patent 12711254
SECURE COMPUTING SYSTEM
1y 7m to grant Granted Aug 18, 2026
Patent 12695928
VIDEO TRANSMISSION METHOD, VIDEO TRANSMISSION APPARATUS, ELECTRONIC DEVICE AND READABLE MEDIUM
3y 3m to grant Granted Jul 28, 2026
Patent 12695605
METHOD AND APPARATUS FOR A SOFTWARE DEFINED NETWORK
2y 11m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+21.5%)
2y 6m (~3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 464 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month