Prosecution Insights
Last updated: October 02, 2026
Application No. 18/779,981

DATABASE PROCESSING METHOD, DEVICE, EQUIPMENT AND MEDIUM

Non-Final OA §101§102§112
Filed
Jul 22, 2024
Priority
Aug 07, 2023 — CN 202310988636.0
Examiner
BECHTEL, KEVIN M
Art Unit
2491
Tech Center
2400 — Computer Networks
Assignee
Beijing Volcano Engine Technology Co., Ltd.
OA Round
3 (Non-Final)
70%
Grant Probability
Favorable
3-4
OA Rounds
12m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
330 granted / 468 resolved
+12.5% vs TC avg
Strong +61% interview lift
Without
With
+61.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
27 currently pending
Career history
490
Total Applications
across all art units

Statute-Specific Performance

§101
16.7%
-23.3% vs TC avg
§103
35.1%
-4.9% vs TC avg
§102
18.5%
-21.5% vs TC avg
§112
23.8%
-16.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 468 resolved cases

Office Action

§101 §102 §112
DETAILED ACTION Notice of AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant’s submission filed on 2026-03-30 has been entered. Response to Amendment The amendment filed 2026-03-30 has been entered and fully considered. Response to Arguments Applicant’s arguments, see page 9, filed 2026-03-20, with respect to the rejection of claims 1-7, 10-16, and 19-20 under 35 U.S.C. § 101 have been fully considered but they are not persuasive. In particular, Applicant argues that the claims have been amended to add “an execution subject, i.e., a database processing apparatus” and thus cannot be performed in the human mind because the claims require the steps to be performed “in the trusted execution environment”. The Examiner respectfully submits, however, that merely adding computing hardware or trusted execution environment to perform the claims steps is insufficient to make the claims patent eligible; See MPEP § 2106.04(a)(2)(III)(C). Thus, the Examiner respectfully submits that the rejection is proper. Applicant’s arguments, see page 8, filed 2026-03-20, with respect to the rejection of claims 1-7, 10-16, and 19-20 under 35 U.S.C. § 112(a) have been fully considered but they are not persuasive. In particular, Applicant argues that the amended claims comply with the written description requirement under 35 U.S.C. § 112(a) because paragraph [0053] of the specification as originally filed recites that “the encrypted data is only fed back to the authorized user, thereby ensuring the security and reliability of data processing”, thereby making evident that returning the encrypted data is an integral part of the inventive concept of the present application, and this technical feature in the claims is sufficiently supported by the specification. First, the Examiner notes that paragraph [0053] and the specific line noted by Applicant was explicitly addressed in the §112(a) rejection. Applicant states this line is “evident that returning the encrypted data”; however, the Examiner respectfully disagrees. Setting aside the issues Examiner raised in the rejection with this particular disclosure, the Examiner notes that the line cited by Applicant is both taken out of context and is insufficient to provide adequate written description. The full sentence in [0053] is as follows: Therefore, for the specified data corresponding to the data processing instruction in the access request sent by the access party, in response to determining that the specified data is encrypted data processed by the TEE, permission authorization for indicating whether the user is authorized is performed based on the user identifier of the access party and the authorization information table, multiple encryption and decryption processes between the client and the database are avoided by the permission authorization, for example, there is no need to perform the following: the acquired target data is encrypted and then transmitted to the database, and the database encrypts the target data and then sends the same to the client where the access party is located, thereby improving the efficiency of data processing, and the encrypted data is only fed back to the authorized user, thereby ensuring the security and reliability of data processing. The Examiner notes that this is a giant run-on sentence that’s replete with grammatical errors and ambiguous modifiers. For example, the sentence reads in-part “there is no need to perform the following:”, but it’s unclear where “the following” ends. Further, even if assuming arguendo that the phrase “the encrypted data is only fed back to the authorized user” is not part of “there is no need to perform the following” (as in, the invention requires that the encrypted data is only fed back to the authorized user, such as argued by Applicant), the Examiner notes that this is similar to the act of “the database encrypts the target data and then sends the same to the client” which the sentence clearly indicates there “is no need to perform” (which is contrary to it being performed as argued). Thus, the sentence is far too unclear and inexact to provide any enabling disclosure to one of ordinary skill in the art to make or use whatever it is that Applicant is attempting to convey. The Examiner additionally notes that the interpretation of [0053] that Applicant proffers, i.e. “returning the encrypted data”, is the more problematic interpretation. As the Examiner noted in the rejection, “if the target data is encrypted, there’s no disclosure of what type of data processing instruction is performed and how such instruction is performed (e.g. is it decrypted for a simple query, homomorphically operated upon in an encrypted state, etc)” and that “if the data is encrypted (as suggested by the last line of [0053]), the specification does not describe how the operation is performed on encrypted data (which, without some other mitigating modification, should not be possible)” (underlining and italics added for emphasis). Applicant has completely ignored the most concerning deficiencies in the claimed invention as used in the basis of the rejection. Thus, based on the above, the Examiner respectfully submits that the rejection is proper. Applicant’s arguments, see pages 8-9, filed 2026-03-20, with respect to the rejection of claims 1-7, 10-16, and 19-20 under 35 U.S.C. § 112(b) have been fully considered but they are not persuasive. In particular, Applicant generally alleges that the amendment traverses the grounds of rejection; however, it does not appear to resolve the ambiguity as to whether or not the “target data” is encrypted. Thus, the Examiner respectfully submits that the rejection is proper. Applicant’s arguments, see page 9, filed 2026-03-20, with respect to the rejection of claims 10-16 under 35 U.S.C. § 102(a)(1) have been fully considered but they are not persuasive. In particular, the Examiner notes that the amendment does not address the merits of the §102(a)(1) rejection, nor does applicant provide argument as to how the amendment addresses it. Thus, the Examiner respectfully submits that the rejection is proper. Applicant’s arguments, see pages 9-12, filed 2026-03-20, with respect to the rejection o of claims 1-7, 10-16, and 19-20 under 35 U.S.C. § 102(a)(2) have been fully considered but they are not persuasive. In response to applicant’s argument that Zaharia fails to disclose or suggest anything about: (1) an authorization information table that, like the database, is packaged in the trusted execution environment; (2) a data processing instruction for instructing to select target data from encrypted data based on a data filtering condition; and (3) returning the selected encrypted data and thus fails to disclose “querying an authorization information table packaged in the trusted execution environment based on the user identifier of the access party, wherein the authorization information table is used for recording authorized user information configured by a data party for the encrypted data” and “executing the data processing instruction to select the target data from the encrypted data based on the data filtering condition, and returning the target data in response to the access request,” as recited in claim 1, the Examiner respectfully disagrees. The Examiner first notes that claim provides no structure or function of the “trusted execution environment” that distinguishes from a general-purpose computer. That is, general-purpose computers provide an execution environment by definition – it’s what they do. Further, there is some inherent level of “trust” that a user has in using a computer, otherwise, they wouldn’t use it. Thus, the broadest reasonable interpretation of “trusted execution environment” encompasses a general-purpose computer. As for “returning the selected encrypted data”, the Examiner notes that the data that is returned being “encrypted” is not recited in the rejected claims – the actual claim language is “the target data” and the claim is silent regarding its cryptographic state. Further, aside from the fact that limitations from the specification are not read into the claims (See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993)), it’s unclear as to what the Specification is attempting to convey, as noted in the § 112(a) rejection. Further, Applicant argues that “multiple encryption and decryption processes between the client and the database are avoided”; however, there is nothing in the claims explicating requiring the exclusion of such multiple encryption and decryption processes. Moreso, there is no evidence addressing how the claims as recited avoid the citations to Zaharia. Mere intended benefit recited in the Specification does not limit the claims – and that ignores that, again, [0053] has significant deficiencies as noted in the § 112(a) rejection. Thus, based on the above, the Examiner respectfully submits that the rejection is proper. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-7, 10-16, and 19-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea (35 U.S.C. 101 Judicial Exception) without significantly more. The claims recite executing data processing instructions of authorized users, a form of observation, evaluation, and/or judgment, which is a concept performed in the human mind and thus grouped as Mental processes. This judicial exception is not integrated into a practical application because the generically recited computer elements do not add a meaningful limitation to the abstract idea because they amount to simply implementing the abstract idea on a computer. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements, when considered separately and in combination, do not add significantly more to the abstract idea, as they are well-understood, routine, conventional computer functions as recognized by the courts. Based upon consideration of all the relevant factors with respect to the claimed invention as a whole, the claims are determined to be directed to an abstract idea without significantly more. The rationale for this determination is explained infra: The following are Principles of Law: A patent may be obtained for “any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof”; 35 U.S.C. § 101. The Supreme Court has consistently held that this provision contains an important implicit exception: laws of nature, natural phenomena, and abstract ideas are not patentable; See Alice Corp. v. CLS Bank Int’l, 134 S. Ct. 2347, 2354 (2014); Gottschalk v. Benson, 409 U.S. 63, 67 (1972) (“Phenomena of nature, though just discovered, mental processes, and abstract intellectual concepts are not patentable, as they are the basic tools of scientific and technological work.”). Notwithstanding that a law of nature or an abstract idea, by itself, is not patentable, an application of these concepts may be deserving of patent protection; See Mayo Collaborative Servs. v. Prometheus Labs., Inc., 132 S. Ct. 1289, 1293–94 (2012). In Mayo, the Court stated that “to transform an unpatentable law of nature into a patent-eligible application of such a law, one must do more than simply state the law of nature while adding the words ‘apply it.’” Mayo, 132 S. Ct. at 1294 (citation omitted). In Alice, the Court reaffirmed the framework set forth previously in Mayo “for distinguishing patents that claim laws of nature, natural phenomena, and abstract ideas from those that claim patent-eligible applications of these concepts.” Alice, 134 S. Ct. at 2355. The test for determining subject matter eligibility requires a first step of determining whether the claims are directed to a process, machine, manufacture, or composition of matter. If the claims are directed to one of the four patent-eligible subject matter categories, then the Examiner must perform a two-part analysis to determine whether a claim that is directed to a judicial exception recites additional elements that amount to significantly more than the exception. The first part of the second step in the analysis is to “determine whether the claims at issue are directed to one of those patent-ineligible concepts.” Id. If the claims are directed to a patent-ineligible concept, then the second part of the second step in the analysis is to consider the elements of the claims “individually and ‘as an ordered combination”’ to determine whether there are additional elements that “‘transform the nature of the claim’ into a patent-eligible application.” Id. (quoting Mayo, 132 S. Ct. at 1298, 1297). In other words, the second step in the analysis is to “search for an ‘inventive concept’‒ i.e., an element or combination of elements that is ‘sufficient to ensure that the patent in practice amounts to significantly more than a patent on the [ineligible concept] itself.’” Id. (brackets in original) (quoting Mayo, 132 S. Ct. at 1294). The prohibition against patenting an abstract idea “cannot be circumvented by attempting to limit the use of the formula to a particular technological environment or adding insignificant post-solution activity.” Bilski v. Kappos, 561 U.S. 593, 610–11 (2010) (citation and internal quotation marks omitted). The Court in Alice noted that “[s]imply appending conventional steps, specified at a high level of generality,” was not “enough” [in Mayo] to supply an “‘inventive concept.’” Alice, 134 S. Ct. at 2357 (quoting Mayo, 132 S. Ct. at 1300, 1297, 1294). In the “2019 Revised Patent Subject Matter Eligibility Guidance” (2019 PEG), the USPTO has prepared revised guidance for use by USPTO personnel in evaluating subject matter eligibility based upon rulings by the courts. The Examiner is bound by and applies the framework as set forth by the Court in Mayo and reaffirmed by the Court in Alice and follows the 2019 PEG for determining whether the claims are directed to patent-eligible subject matter. Step 1: Are the claims at issue directed to a process, machine, manufacture, or composition of matter? The Examiner finds that the claims are directed to one of the four statutory categories. Step 2A – Prong One: Does the claim recite an abstract idea, law of nature, or natural phenomenon? The Examiner finds that the claims are directed to the abstract idea of executing data processing instructions of authorized users, a form of observation, evaluation, and/or judgment, which is a concept performed in the human mind and thus grouped as Mental processes. Step 2A – Prong Two: Does the claim recite additional elements that integrate the Judicial Exception into a practical application? The abstract idea is not integrated into a practical application because the generically recited computer elements do not add a meaningful limitation to the abstract idea because they amount to simply implementing the abstract idea on a computer. In determining whether the abstract idea was integrated into a practical application, the Examiner has considered whether there were any limitations indicative of integration into a practical application, such as: (1) Improvements to the functioning of a computer, or to any other technology or technical field; See MPEP § 2106.05(a) (2) Applying or using a judicial exception to effect a particular treatment or prophylaxis for a disease or medical condition; See Vanda Memo (Recent Subject Matter Eligibility Decision: Vanda Pharmaceuticals Inc. v. West-Ward Pharmaceuticals) (3) Applying the judicial exception with, or by use of, a particular machine; See MPEP § 2106.05(b) (4) Effecting a transformation or reduction of a particular article to a different state or thing; See MPEP § 2106.05(c) (5) Applying or using the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technological environment, such that the claim as a whole is more than a drafting effort designed to monopolize the exception; See MPEP § 2106.05(e) and Vanda Memo The Examiner notes that clam features of: executing data processing instructions of authorized users do not improve the functioning of a computer or technical field, do not effect a particular treatment or prophylaxis for a disease or medical condition, do not apply or use a particular machine, do not effect a transformation or reduction of a particular article to a different state or thing, and do not apply or use the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technological environment, such that the claim as a whole is more than a drafting effort designed to monopolize the exception. Instead of a practical application, the claim features of executing data processing instructions of authorized users merely use a general-purpose computer as a tool to perform the abstract idea (See MPEP § 2106.05(f)) and merely generally link the use of the abstract idea to a field of use (See MPEP § 2106.05(h)). Thus, the Examiner finds that the claimed invention does not recite additional elements that integrate the Judicial Exception into a practical application. Step 2B: Is there something else in the claims that ensures that they are directed to significantly more than a patent-ineligible concept? The claims, as a whole, require nothing significantly more than generic computer implementation or can be performed entirely by a human. The additional element(s) or combination of element(s) in the claims other than the abstract idea per se amount to no more than recitation of generic computer structure (e.g. electronic device, processor, and memory) that serves to perform generic computer functions (e.g. receiving an access request, querying a table, detecting if a party is authorized, executing a processing instruction, ...) that are well-understood, routine, and conventional activities previously known to the pertinent industry. The claimed database, access request, user identifier, data processing instruction, encrypted data, target data, execution environment, encrypted data, authorization information table, and authorized user information are all numbers, data structures, or datum. Each of these elements are individually dispositive of patent eligibility because of the following legal holdings: “Data in its ethereal, non-physical form is simply information that does not fall under any of the categories of eligible subject matter under section 101.” Digitech Image Techs., LLC v. Electronics for Imaging, Inc., 758 F.3d 1344, 1350 (Fed. Cir. 2014). The Supreme Court has also explained that “[a]bstract software code is an idea without physical embodiment,” i.e., an abstraction. Microsoft Corp. v. AT&T Corp., 550 U.S. 437, 449 (2007). A claim that recites no more than software, logic, or a data structure (i.e., an abstract idea) – with no structural tie or functional interrelationship to an article of manufacture, machine, process or composition of matter does not fall within any statutory category and is not patentable subject matter; data structures in ethereal, non-physical form are non-statutory subject matter. In re Warmerdam, 33 F.3d 1354, 1361 (Fed. Cir. 1994); see Nuijten, 500 F.3d at 1357. Furthermore, the claimed invention does not have a specific asserted improvement in computer capabilities, nor is it a specific implementation of a solution to a problem in the software arts; See Enfish, LLC v. Microsoft Corp., 822 F.3d 1327 (Fed. Cir. 2016). Rather, the claims are merely directed towards executing data processing instructions of authorized users, which is similar to ideas that the courts have found to be abstract, as noted supra, and the claims are without a “practical application” or anything “significantly more”. Considering each of the claim elements in turn, the function performed by the computer system at each step of the process does no more than require a generic computer to perform a well-understood, routine, and conventional activity at a high level of generality. For example, “receiving an access request” and “returning the target data” are merely forms of receiving or transmitting data over a network, which has been found by the courts to be a well-understood, routine, conventional activity in computers; See e.g. Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information); TLI Communications LLC v. AV Auto. LLC, 823 F.3d 607, 610, 118 USPQ2d 1744, 1745 (Fed. Cir. 2016) (using a telephone for image transmission); OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1093 (Fed. Cir. 2015) (sending messages over a network); buySAFE, Inc. v. Google, Inc., 765 F.3d 1350, 1355, 112 USPQ2d 1093, 1096 (Fed. Cir. 2014) (computer receives and sends information over a network). Further “querying … an authorization information table”, “detecting … whether the access party is an authorized user”, and “executing … the data processing instruction” are merely forms of performing repetitive calculations, which has been found by the courts to be a well-understood, routine, conventional activity in computers; See e.g. Flook, 437 U.S. at 594, 198 USPQ2d at 199 (recomputing or readjusting alarm limit values); Bancorp Services v. Sun Life, 687 F.3d 1266, 1278, 103 USPQ2d 1425, 1433 (Fed. Cir. 2012) (“The computer required by some of Bancorp’s claims is employed only for its most basic function, the performance of repetitive calculations, and as such does not impose meaningful limits on the scope of those claims”). Further note that the abstract idea of executing data processing instructions of authorized users to which the claimed invention is directed has a prior art basis outside of a computing environment, e.g. banks verifying transactions before executing them. The prohibition against patenting an abstract idea “cannot be circumvented by attempting to limit the use of the formula to a particular technological environment or adding insignificant post-solution activity.” Bilski v. Kappos, 561 U.S. 593, 610–11 (2010) (citation and internal quotation marks omitted). The Court in Alice noted that “[s]imply appending conventional steps, specified at a high level of generality,” was not “enough” [in Mayo] to supply an “‘inventive concept.’” Alice, 134 S. Ct. at 2357 (quoting Mayo, 132 S. Ct. at 1300, 1297, 1294). Viewed as a whole, the claims simply recite the steps of using generic computer components. The claims do not purport, for example, to improve the functioning of the computer system itself. Nor does it effect an improvement in any other technology or technical field. Instead, the claims amount to nothing significantly more than an instruction to implement the abstract idea using generic computer components. This is insufficient to transform an abstract idea into a patent-eligible invention. The dependent claims likewise incorporate the deficiencies of a claim upon which they ultimately depend and are also directed to non-patent-eligible subject matter. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1-7, 10-16, and 19-20 are rejected under 35 U.S.C. 112(a) as failing to comply with the written description requirement. The claims contain subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor at the time the application was filed, had possession of the claimed invention. In particular, claim 1 recites the limitations “executing … the data processing instruction to select the target data from the specified data from the encrypted data” and “returning … the target data”, and the specification lacks the “full, clear, concise, and exact” written description such that one skilled in the art can reasonably conclude that the inventor had possession of the claimed invention at the time of filing. Deficiency 1: Neither the claims nor the specification resolves the cryptographic state of the returned “target data” as claimed. It is first noted that if an application as filed does not disclose the complete structure (or acts of a process) of the claimed invention as a whole, it should be determined whether the specification discloses other relevant identifying characteristics sufficient to describe the claimed invention in such full, clear, concise, and exact terms that a skilled artisan would recognize inventor was in possession of the claimed invention, and that original claims may lack adequate written description if the specification does not have such a full, clear, concise, and exact written description; See MPEP § 2163(II)(A)(3)(a). In this instance, the claim recites “returning … the target data in response to the access request” after “executing … the data processing instruction to select the target data from the specified data from the encrypted data”; however, neither the claims nor specification is “full” and “clear” as to whether the returned target data is encrypted. The specification only provides antecedent support for the claimed feature (e.g. [0053]) without further description or resolution. However, this supporting paragraph in the specification has significant deficiencies. In particular, the most relevant supporting sentence in [0053] is as follows: Therefore, for the specified data corresponding to the data processing instruction in the access request sent by the access party, in response to determining that the specified data is encrypted data processed by the TEE, permission authorization for indicating whether the user is authorized is performed based on the user identifier of the access party and the authorization information table, multiple encryption and decryption processes between the client and the database are avoided by the permission authorization, for example, there is no need to perform the following: the acquired target data is encrypted and then transmitted to the database, and the database encrypts the target data and then sends the same to the client where the access party is located, thereby improving the efficiency of data processing, and the encrypted data is only fed back to the authorized user, thereby ensuring the security and reliability of data processing. The Examiner notes that this is a giant run-on sentence that’s replete with grammatical errors and ambiguous modifiers. For example, the sentence reads in-part “there is no need to perform the following:”, but it’s unclear where “the following” ends. Further, even if assuming arguendo that the phrase “the encrypted data is only fed back to the authorized user” is not part of “there is no need to perform the following” (as in, the invention requires the encrypted data is only fed back to the authorized user, such as argued by Applicant in the response of 2026-03-30), the Examiner notes that this is similar to the act of “the database encrypts the target data and then sends the same to the client” which the sentence clearly indicates there “is no need to perform” (which is contrary to it being performed as argued). Thus, the sentence is far too unclear to provide any enabling disclosure to one of ordinary skill in the art to make or use whatever it is that Applicant is attempting to convey. Deficiency 2: No description as to how operations are performed on encrypted data. It is also noted that original claims lack adequate written description when the claims define the invention in functional language specifying a desired result but the specification does not sufficiently describe how the function is performed or the result is achieved; See MPEP § 2161.01(I). That is, “the algorithm or steps/procedure taken to perform the function must be described with sufficient detail so that one of ordinary skill in the art would understand how the inventor intended the function to be performed”. In this instance, the claims generally recite “executing … the data processing instruction to select the target data from the specified data from the encrypted data”; however, operations relying on the underlying plaintext of encrypted data should not by possible without some enabling modification, e.g. decryption or homomorphism. If the target data is encrypted (such as argued by Applicant in the remarks filed 2026-03-30), there’s no disclosure of what type of data processing instruction is performed and how such instruction is performed (e.g. is it decrypted for a simple query, homomorphically operated upon in an encrypted state, etc). At best, the specification merely states “multiple encryption and decryption processes between the client and the database are avoided by the permission authorization, for example, there is no need to perform the following: the acquired target data is encrypted and then transmitted to the database, and the database encrypts the target data and then sends the same to the client where the access party is located, thereby improving the efficiency of data processing”, but does not actually describe what is performed and how it avoids the need to perform the acts allegedly not needed (or even why they would be needed). Further, if the data is encrypted (as suggested by the last line of [0053]), the specification does not describe how the operation is performed on encrypted data (which, without some other mitigating modification, should not be possible). However, for adequate written description, “the algorithm or steps/procedure taken to perform the function must be described with sufficient detail so that one of ordinary skill in the art would understand how the inventor intended the function to be performed”; See MPEP § 2161.01(I). Claims 10 and 19 are rejected under a similar rationale. The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above. Claims 1-7, 10-16, and 19-20 are rejected under 35 U.S.C. 112(a) as failing to comply with the written description requirement. The claims contain subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor at the time the application was filed, had possession of the claimed invention. In particular, claim 1 recites the limitation “select target data from encrypted data stored in the database in an encrypted form”, and it is new matter. That is, the specification does not provide support for the “target data” to be “in an encrypted form”; See §112(a) rejection supra at ¶10 (deficiency 1). Note that this rejection depends on how the ambiguity of the limitation is resolved in the §112(b) rejection infra at ¶13. Claims 10 and 19 are rejected under a similar rationale. The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above. Claims 1-7, 10-16, and 19-20 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention. Specifically, claim 1 recites the limitations “executing … the data processing instruction to select the target data from the specified data from the encrypted data” and “returning … the target data”, and the limitations are unclear as to the cryptographic state of the “target data” and the nature of the “data processing” as noted in the §112(a) rejection supra at ¶10. Claims 10 and 19 are rejected under a similar rationale. The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above. Claims 1-7, 10-16, and 19-20 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention. Specifically, claim 1 recites the limitation “select target data from encrypted data stored in the database in an encrypted form”, and it is unclear as to what “in an encrypted form” modifies. That is, it is ambiguous as to whether it is modifying the “encrypted data stored in the database” or the “target data” that is selected. Claims 10 and 19 are rejected under a similar rationale. The dependent claims included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 10-16 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by a general-purpose computer. The Examiner notes that the United States Patent and Trademark Office (USPTO) is obliged to give claims their broadest reasonable interpretation consistent with the specification during proceedings before the USPTO; See In re ZIetz, 893 F.2d 319 (Fed. Cir. 1989) (during patent examination the pending claims must be interpreted as broadly as their terms reasonably allow); See also MPEP 2111.01. It is noted that claims are directed towards an apparatus comprising a processor and “memory, configured to store an executable instruction for the processor” that, when executed, perform the recited acts. As opposed to, e.g., a processor and memory with executable instructions that, when executed by the processor, causes the processor to perform acts, the instant claim merely recites a memory “configured to store” the executable instructions (i.e. an intended use). That is, the claim does not require that the computer be programmed to perform the steps that follow (i.e., the claim does not require that the memory actually store the instructions that when executed perform the steps; instead, the claim encompasses embodiments such as a generic, non-programmed computer that could be programmed to perform the steps. Thus, the claim is met by any general-purpose computer with sufficient hardware and instruction set that could be operable to perform the claimed acts vs a computer programmed to perform the recited acts. Therefore, the claims are clearly anticipated by any general-purpose computing machine with sufficient hardware and instruction set that is operable to perform the claimed steps. Claims 1-7, 10-16, and 19-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Zaharia et al. (US Pre-Grant Publication No. 20250131118-A1, hereinafter “Zaharia”). With respect to independent claim 1, Zaharia discloses a database processing method, comprising: receiving, by a database processing apparatus, an access request for a database packaged in a trusted execution environment {paras. 0038, 0046, and 0052: “database 116 are implemented by a single server or a same set of one or more servers”, the server has “one or more security policies that are to be enforced”, and “database 116 comprises a cloud-based storage system that is distinct from the system that requests the data”}, wherein the access request carries a user identifier of an access party and a data processing instruction, the data processing instruction is used for instructing to select target data from encrypted data stored in the database in an encrypted form based on a data filtering condition {paras. 0021, 0028, and 0031: “receive, by a data manager service from a data requesting service, a request using an identifier for a high-level data object to access a set of data associated with the high-level data object” and/or “in connection with requesting access to a high-level data object, the data requesting service provides authentication information to the data manager service”; note that “the system uses an encryption of a partition of low-level data object(s) corresponding to a high-level data object”, e.g. a “first row of a table can be encrypted”}. querying, by the database processing apparatus, an authorization information table packaged in the trusted execution environment based on the user identifier of the access party, and detecting, by the database processing apparatus, whether the access party is an authorized user of the encrypted data {para. 0028: “the data manager service uses the authentication to authenticate the data requesting service and/or determine access permissions/authorizations for the data requesting service”}, wherein the authorization information table is used for recording authorized user information configured by a data party for the encrypted data {paras. 0028 and 0031: “determine the access permissions for the data requesting service” and “enforce access rights” such as “determination that access to the first file/row/column/section is to be provided and that access to the second file/row/column/section is to be restricted”}. in response to determining that the access party is the authorized user of the encrypted data {note that the broadest reasonable interpretation of the claim does not require the following limitations, as the steps are not required if the contingency is not met; See MPEP §2111.04(II)}, executing, by the database processing apparatus, the data processing instruction to select the target data from the encrypted data based on the data filtering condition, and returning, by the database processing apparatus, the target data in response to the access request {paras. 0031-0032: “the system (e.g., the data manager service) provides access to a set of data (e.g., a set of low-level data objects associated with a high-level data object) by communicating one or more URLs to the data requesting service”}. With respect to dependent claim 2, Zaharia discloses: receiving an authorization configuration instruction sent by the data party, wherein the authorization configuration instruction carries a user identifier of the data party, a data identifier of the encrypted data and a user identifier of the authorized user, and the authorization configuration instruction is used for instructing to configure that the authorized user is authorized and allowed to access to the encrypted data {paras. 0027-0028 and 0034: “an administrator of data sharing system (e.g., an administrator of a dataset) can provide a data requesting service with access to a dataset by adding the data recipient (e.g., the entity associated with the data requesting service) to a policy or account or access control metadata structure”}. in response to the authorization configuration instruction, recording, in the authorization information table, a correspondence among the user identifier of the data party, the data identifier of the encrypted data and the user identifier of the authorized user {paras. 0027-0028 and 0034: “an administrator of data sharing system (e.g., an administrator of a dataset) can provide a data requesting service with access to a dataset by adding the data recipient (e.g., the entity associated with the data requesting service) to a policy or account or access control metadata structure”}. With respect to dependent claim 3, Zaharia discloses wherein the authorization configuration instruction further comprises an authorized access time limit; the authorization information table records a correspondence among the user identifier of the data party, the data identifier of the encrypted data, the user identifier of the authorized user and the authorized access time limit; and the authorized access time limit is used for limiting an access time of the authorized user for the encrypted data {para. 0030: “the URL expires after a predefined period of time (e.g., an amount of time after generation of the URL or an amount of time after sending the URL to the data requesting service or other system associated with the corresponding data access request)”}. With respect to dependent claim 4, Zaharia discloses: receiving an authorization deletion instruction sent by the data party, wherein the authorization deletion instruction carries a user identifier of the data party, a data identifier of the encrypted data and a user identifier of the authorized user, and the authorization deletion instruction is used for instructing to delete configuration information that the authorized user is authorized and allowed to access the encrypted data {paras. 0027-0028 and 0034: “access permissions can be defined in a security policy (e.g., a security policy that is configurable by an administrator of the system, etc.)”, the Examiner submits that removing permissions is “at once envisaged” from the more generic configurable security policy, as configuring permissions only has three species – adding permissions, removing permissions, and modifying permissions; See MPEP § 2131.02(II)}. in response to the authorization deletion instruction, deleting, from the authorization information table, a correspondence among the user identifier of the data party, the data identifier of the encrypted data and the user identifier of the authorized user {paras. 0027-0028 and 0034: “access permissions can be defined in a security policy (e.g., a security policy that is configurable by an administrator of the system, etc.)”, the Examiner submits that removing permissions is “at once envisaged” from the more generic configurable security policy, as configuring permissions only has three species – adding permissions, removing permissions, and modifying permissions; See MPEP § 2131.02(II)}. With respect to dependent claim 5, Zaharia discloses wherein user identifiers of a plurality of authorized users are configured for one piece of encrypted data of the data party in the authorization information table {paras. 0027-0028 and 0034: “access permissions to corresponding low-level data objects to determine one or more low-level objects, if any, to which a user or system (e.g., a data requesting service) associated with a data access request has appropriate permissions to access”}. With respect to dependent claim 6, Zaharia discloses wherein the authorization information table is dynamically updated with the authorization configuration instruction sent by the data party {paras. 0027-0028 and 0034: “an administrator … [performs] adding the data recipient (e.g., the entity associated with the data requesting service) to a policy or account or access control metadata structure”}. With respect to dependent claim 7, Zaharia discloses: wherein the encrypted data is at least one column of encrypted data in at least one data table corresponding to a specified column identifier, or, the encrypted data is at least one row of encrypted data in at least one data table corresponding to a specified row identifier {para. 0031: “any other portions of a table are encrypted using different keys-for example, a column, an area, a volume, a range of rows, a range of columns, a section, etc. In response to receiving a data access request and a determination that access to the first file/row/column/section is to be provided and that access to the second file/row/column/section is to be restricted”}, or the encrypted data is at least one encrypted data element in at least one data table corresponding to the specified column identifier and the specified row identifier {para. 0019: “low-level data object can correspond to a row of a table, a column of a table, a subset of rows and/or columns in a table”}. With respect to claims 10-16, a corresponding reasoning as given earlier in this section with respect to claims 1-7 applies, mutatis mutandis, to the subject matter of claims 10-16; therefore, claims 10-16 are rejected, for similar reasons, under the grounds as set forth for claims 1-7. With respect to claims 19-20, a corresponding reasoning as given earlier in this section with respect to claims 1-2 applies, mutatis mutandis, to the subject matter of claims 19-20; therefore, claims 19-20 are rejected, for similar reasons, under the grounds as set forth for claims 1-2. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. The reference Mattsson et al. (US Pre-Grant Publication No. 20060259950-A2) discloses controlling data access in a data-at-rest system, including storing and retrieving encrypted data in a database based on a user’s ID and authorization. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Kevin Bechtel whose telephone number is 571-270-5436. The examiner can normally be reached Monday - Friday, 09:00 - 17:00 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William (“Bill”) Korzuch can be reached at 571-272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Kevin Bechtel/ Primary Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

Jul 22, 2024
Application Filed
Oct 01, 2025
Non-Final Rejection mailed — §101, §102, §112
Jan 02, 2026
Response Filed
Jan 30, 2026
Final Rejection mailed — §101, §102, §112
Mar 30, 2026
Response after Non-Final Action
Apr 30, 2026
Request for Continued Examination
May 06, 2026
Response after Non-Final Action
Jul 21, 2026
Non-Final Rejection mailed — §101, §102, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748831
SYSTEM AND METHOD EMPLOYING REDUCED TIME DEVICE PROCESSING
2y 0m to grant Granted Sep 29, 2026
Patent 12744781
METHOD AND SYSTEM FOR PERMISSION MANAGEMENT
2y 3m to grant Granted Sep 22, 2026
Patent 12726512
SYSTEMS AND METHODS FOR IDENTIFYING AND ADDRESSING MALICIOUS NETWORK TRAFFIC BASED ON NETWORK TRAFFIC LANE ACTIVITY
2y 4m to grant Granted Sep 01, 2026
Patent 12711276
Integrations Platform with Interaction and Abstraction with a Third Party Platform
1y 8m to grant Granted Aug 18, 2026
Patent 12706907
MANAGEMENT SERVER, MANAGEMENT METHOD, AND STORAGE MEDIUM
2y 0m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
70%
Grant Probability
99%
With Interview (+61.3%)
3y 2m (~12m remaining)
Median Time to Grant
High
PTA Risk
Based on 468 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month