Prosecution Insights
Last updated: August 15, 2026
Application No. 18/839,090

Protecting Software

Non-Final OA §101§103§112
Filed
Aug 16, 2024
Priority
Feb 18, 2022 — GB 2202209.9 +1 more
Examiner
HURUY, FEVEN HABTEMARIAM
Art Unit
Tech Center
Assignee
Promon AS
OA Round
1 (Non-Final)
67%
Grant Probability
Favorable
1-2
OA Rounds
9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 67% — above average
67%
Career Allowance Rate
2 granted / 3 resolved
+6.7% vs TC avg
Strong +50% interview lift
Without
With
+50.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
18 currently pending
Career history
22
Total Applications
across all art units

Statute-Specific Performance

§101
20.5%
-19.5% vs TC avg
§103
49.4%
+9.4% vs TC avg
§102
3.6%
-36.4% vs TC avg
§112
24.1%
-15.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 3 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION This is the initial Office action based on the preliminary amendment filed on August 16, 2024. Claims 1-3, 6-8, 10-12, 15, 18-19, 21-23, and 26-30 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Drawings The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they include the following reference character(s) not mentioned in the description: reference character 110 in Figure 2. Corrected drawing sheets in compliance with 37 CFR 1.121(d), or amendment to the specification to add the reference character(s) in the description in compliance with 37 CFR 1.121(b) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Specification The disclosure is objected to because of the following informalities: Page 11, line 14, recites “radio 2.” It should read – radio 4 --. Page 11, line 16, recites “(CPU) 4.” It should read – (CPU) 2--. Appropriate correction is required. Claim Objections Claims 1, 8, 11, 19, 21, 26, and 28-29 are objected to because of the following informalities: Claims 1, 28, and 29, in line 3, line 7, & line 6 respectively, recite “receiving a source software application.” It should read -- receiving the source software application --. Claims 1, 28, and 29, in line 7, line 11, & line 10 respectively, recite “the respective set of source instructions.” It should read -- a respective set of source instructions --. Claims 1, 28, and 29, in line 8, line 12, and line 11 respectively, recite “generating a secured software application.” It should read -- generating the secured software application --. Claims 1, 28, and 29, in line 16, line 20, & line 19 respectively, recite “writing the runtime instructions.” It should read -- writing the respective set of runtime instructions --. Claims 8 and 11, line 2 & line 2 respectively, recite “the runtime instructions.” It should read – the respective set of runtime instructions --. Claim 19, in lines 2-3, recites “represents the source instructions.” It should read -- represents the sets of source instructions --. Claim 19, in line 6, recites “the plurality of generations of each set of runtime instructions.” It should read -- a plurality of generations of each set of runtime instructions --. Claim 21, in line 4, recites “writing the runtime instructions.” It should read -- writing the respective set of runtime instructions --. Claim 26, in lines 2-3 and line 4, recites “the set of runtime instructions.” It should read – the respective set of runtime instructions --. Claim 26, in line 5, recites “executions of the runtime instructions.” It should read -- executions of the respective set of runtime instructions --. Claim 28, in line 21, recites “a memory of a processing system.” It should read – the memory of the processing system --. Claim 29, in line 20, recites “a memory of a processing system.” It should read – the memory of the processing system --. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(d): (d) REFERENCE IN DEPENDENT FORMS.—Subject to subsection (e), a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. Claim 26 is rejected under 35 U.S.C. 112(d), as being of improper dependent form for failing to further limit the subject matter of the claim upon which it depends, or for failing to include all the limitations of the claim upon which it depends. Claim 26 depends on Claim 24 which is a cancelled claim and, therefore, fails to include all the limitations of the claim upon which it depends. Applicant may cancel the claim(s), amend the claim(s) to place the claim(s) in proper dependent form, rewrite the claim(s) in independent form, or present a sufficient showing that the dependent claim(s) complies with the statutory requirements. In the interest of compact prosecution and for the purpose of further examination, the Examiner interprets Claim 26 as depending on Claim 1. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-3, 6-8, 10-12, 15, 18-19, 21-23, and 26-30 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Claim Interpretation: Under the broadest reasonable interpretation (BRI), the limitations of Claim 1 are presumed to have their plain meaning consistent with the specification as it would be interpreted by one of ordinary skill in the art. See MPEP § 2111. Step 1: Claim 1 is directed to a method, which is a process (a series of steps or acts), and falls within one of the statutory categories of invention. Step 2A, Prong One: Claim 1 recites the limitations: identifying one or more sets of source instructions within the source software application; for each of the sets of source instructions, generating respective data representative of the respective set of source instructions; and generating a secured software application comprising the data and comprising a runtime engine, wherein the runtime engine comprises code for processing the data, during a runtime of the secured software application, to generate, for each of the sets of source instructions, a respective plurality of generations of a respective set of runtime instructions, for execution during the runtime, wherein each generation of the respective set of runtime instructions is functionally equivalent to the respective set of source instructions, and wherein at least two of the generations of the respective set of runtime instructions differ from each other; and wherein the runtime engine comprises code for writing the runtime instructions generated by the runtime engine at each generation to a memory of a processing system executing the secured software application, and for causing the generated runtime instructions to be executed directly from the memory. These recited steps, under the broadest reasonable interpretation (BRI), cover performance of the steps in the human mind alone or with the aid of pen and paper. Nothing in the claim precludes the steps from practically being performed in the human mind alone using observation, evaluation, judgment, and opinion or with the aid of pen and paper. For example, the limitation (a) in the context of the claim encompasses a human observing a source application using observation, evaluation, judgment, and opinion to mentally identify source instructions. The limitation (b) in the context of the claim encompasses a human observing sets of source instructions using observation, evaluation, judgment, and opinion to mentally generate data representative of the source instructions with the aid of pen and paper. The limitation (c) in the context of the claim encompasses a human using observation, evaluation, judgment, and opinion to mentally generate a secured software application, comprising data and a runtime engine with the features listed in limitation (c), with the aid of pen and paper by writing code that generates the application. The limitation (c) includes the description of features of the runtime engine which is part of the generation of the secured software application. See MPEP § 2106.04(a)(2)(III). If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the human mind alone or with the aid of pen and paper but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea. Step 2A, Prong Two: This judicial exception is not integrated into a practical application. In particular, the claim recites the additional element: receiving a source software application. The additional element (1) is mere data transmitting recited at a high level of generality, and thus is an insignificant extra-solution activity. See MPEP § 2106.05(g). Furthermore, all uses of the recited judicial exception require such data transmitting, and, as such, the additional element does not impose any meaningful limits on the claim. The additional element amounts to necessary data transmitting. See MPEP § 2106.05. Accordingly, even when viewed in combination, the additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. Step 2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as a combination do not amount to significantly more than the abstract idea. As discussed above with respect to integration of the abstract idea into a practical application, the claim recites the additional element: receiving a source software application. The additional element (1) simply appends well-understood, routine, and conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception is not indicative of an inventive concept. MPEP § 2106.05(d)(II) expressly states that the courts have recognized the computer function of receiving or transmitting data over a network, e.g., using the Internet to gather data as a well‐understood, routine, and conventional computer function when it is claimed in a merely generic manner (e.g., at a high level of generality) or as insignificant extra-solution activities. Thus, a person of ordinary skill in the art would readily comprehend that it is well-understood, routine, and conventional in the computing art to receive an application (data). Therefore, the limitation remains an insignificant extra-solution activity even upon reconsideration and does not amount to significantly more. Thus, taken alone, the additional element does not amount to significantly more than the above-identified judicial exception (the abstract idea). Looking at the additional element as a combination adds nothing that is not already present when looking at the additional element taken individually. Even when considered in combination, the additional element represents insignificant extra-solution activities, and therefore does not provide an inventive concept. The claim is not patent eligible. Claims 2-3, 6-8, 10-12, 15, 18-19, 21-23, 26-27, and 30 are rejected under 35 U.S.C. 101 as directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more for at least the reasons stated above. Claim 2 recites the limitations: wherein the data representative of the sets of source instructions is obfuscated and the secured software application comprises code for deobfuscating the data. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 3 recites the limitations: wherein the data representative of the sets of source instructions is encrypted and the secured software application encodes one or more cryptographic keys for decrypting the encrypted data. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 6 recites the limitation: wherein every instruction of the source software application is included in at least one of the identified sets of source instructions <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 7 recites the limitation: wherein the source software application is received as a binary application. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 8 recites the limitations: wherein the runtime instructions generated by the runtime engine are native instructions. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 10 recites the limitations: wherein the runtime engine comprises code for generating the sets of runtime instructions such that a call from a set of runtime instructions is received by the runtime engine, and further comprises code for redirecting the call to a further set of runtime instructions. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 11 recites the limitations: wherein the runtime instructions generated by the runtime engine are ephemeral and are transiently stored in the memory of the processing system executing the secured software application. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 12 recites the limitations: wherein the runtime engine comprises code for removing a latest generation of a set of runtime instructions from the memory of the processing system executing the secured software application when an expiry condition is met. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 15 recites the limitations: wherein the runtime engine comprises code for creating a next generation of a set of runtime instructions before clearing a preceding generation of the set of runtime instructions from the memory of the processing system executing the secured software application. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 18 recites the limitations: wherein the runtime engine comprises code for introducing differences between two generations of a set of runtime instructions such that each of the two generations uses memory differently, or has the same runtime instructions in a different order, or contains a different number of runtime instructions, or contains one or more different runtime instructions, or has any combination of these differences. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 19 recites the limitations: wherein the data in the secured software application represents the source instructions using virtual machine instructions, wherein each virtual machine instruction represent one or a plurality of source instructions, and wherein the runtime engine comprises code implementing a virtual machine for interpreting the virtual machine instructions to create the plurality of generations of each set of runtime instructions. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 21 recites the limitations: wherein the secured software application comprises one or more templates and wherein the runtime engine comprises code for resolving one or more of the templates when writing the runtime instructions to the memory of the processing system executing the secured software application such that at least some of the generated runtime instructions comprise one or more resolved templates. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 22 recites the limitations: wherein a first template of the one or more templates comprises one or more unallocated elements, and wherein the secured software application comprises code for resolving the first template by allocating a respective value to each of the unallocated elements of the first template. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 23 recites the limitations: wherein at least one of the unallocated elements is suitable for receiving a register address, or a memory address, or a constant. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 26 recites the limitations: wherein the runtime engine comprises code for creating a new generation of the set of runtime instructions when a predetermined time interval has elapsed since generating an immediately preceding generation of the set of runtime instructions; or after a predetermined number of executions of the runtime instructions. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 27 recites the limitations: wherein the runtime engine comprises code for: clearing one generation of a set of runtime instructions from the memory of the processing system executing the secured software application when generating a next generation of the set of runtime instructions; or creating a next generation of a set of runtime instructions and subsequently clearing a preceding generation from the memory, such that two generations exist in the memory simultaneously. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim 30 recites the limitation: A non-transitory computer-readable medium storing a secured software application generated by the method of claim 1. These claims are dependent on Claim 1, but do not add any feature or subject matter that would solve the judicial exception deficiencies of Claim 1. Claims 2-3, 6, 8, 10-12, 15, 18-19, 21-23, and 26-27 recite limitations that further limit the mental processes recited in Claim 1 directed toward “generating respective data” and “generating a secured software application comprising the data and comprising a runtime engine, wherein the runtime engine comprises code for […]” and thus, fail to make the claim any less abstract (can be practically performed in the human mind alone using observation, evaluation, judgment, and opinion or with the aid of pen and paper) (see MPEP § 2106.04(a)(2)(III)). Claims 7 and 30 recite further additional elements that do not integrate the judicial exception into a practical application of the judicial exception. Specifically, the additional element (a) recited in Claim 30 fails to meaningfully limit the claim because it amounts to no more than mere instructions to apply the judicial exception using generic computer components. See MPEP § 2106.05(f). The additional element (a) recited in Claim 7 fails to meaningfully limit the claim because it is mere data gathering/transmitting recited at a high level of generality, and thus is an insignificant extra-solution activity. See MPEP § 2106.05(g). Therefore, Claims 2-3, 6-8, 10-12, 15, 18-19, 21-23, 26-27, and 30 when considered both individually and as a combination fail to integrate the abstract idea into a practical application. The additional elements recited in Claims 2-3, 6-8, 10-12, 15, 18-19, 21-23, 26-27, and 30 are also not sufficient to amount to significantly more than the judicial exception. Specifically, Claims 2-3, 6, 8, 10-12, 15, 18-19, 21-23, and 26-27 do not amount to significantly more than the abstract idea because they recite additional elements that further limit the mental processes recited in Claim 1 and thus, fail to make the claim any less abstract. The additional element (a) recited in Claim 30 does not amount to significantly more than the abstract idea because it amounts to no more than mere instructions to apply the judicial exception using generic computer components which cannot provide an inventive concept. See MPEP § 2106.05(f). The additional element (a) recited in Claim 7 does not amount to significantly more because it is mere data gathering/transmitting recited at a high level of generality, and thus is an insignificant extra-solution activity which simply appends well-understood, routine, and conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception is not indicative of an inventive concept. MPEP § 2106.05(d)(II) expressly states that the courts have recognized the computer function of receiving or transmitting data over a network, e.g., using the Internet to gather data as a well‐understood, routine, and conventional computer function when it is claimed in a merely generic manner (e.g., at a high level of generality) or as insignificant extra-solution activities. Thus, a person of ordinary skill in the art would readily comprehend that it is well-understood, routine, and conventional in the computing art to receive a binary application (data). Therefore, Claims 2-3, 6-8, 10-12, 15, 18-19, 21-23, 26-27, and 30 do not add any steps or additional elements, when considered both individually and as a combination, that amount to significantly more than the above-identified judicial exception that would convert Claim 1 into patent-eligible subject matter. Claims 1-3, 6-8, 10-12, 15, 18-19, 21-23, 26-27, and 30 are therefore not drawn to patent-eligible subject matter as they are directed to an abstract idea without significantly more. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim Interpretation: Under the broadest reasonable interpretation (BRI), the limitations of Claim 28 are presumed to have their plain meaning consistent with the specification as it would be interpreted by one of ordinary skill in the art. See MPEP § 2111. Step 1: Claim 28 is directed to a computer-readable medium, which is an article of manufacture, and falls within one of the statutory categories of invention. Step 2A, Prong One: Claim 28 recites the limitations: identifying one or more sets of source instructions within the source software application; for each of the sets of source instructions, generating respective data representative of the respective set of source instructions; and generating a secured software application comprising the data and comprising a runtime engine, wherein the runtime engine comprises code for processing the data, during a runtime of the secured software application, to generate, for each of the sets of source instructions, a respective plurality of generations of a respective set of runtime instructions, for execution during the runtime, wherein each generation of the respective set of runtime instructions is functionally equivalent to the respective set of source instructions, and wherein at least two of the generations of the respective set of runtime instructions differ from each other; and wherein the runtime engine comprises code for writing the runtime instructions generated by the runtime engine at each generation to a memory of a processing system executing the secured software application, and for causing the generated runtime instructions to be executed directly from the memory. These recited steps, under the broadest reasonable interpretation (BRI), cover performance of the steps in the human mind alone or with the aid of pen and paper. That is, other than reciting: A non-transitory computer-readable medium storing instructions which, when executed on a processing system, cause the processing system to carry out a method for generating a secured software application from a source software application, the method comprising. Nothing in the claim precludes the steps from practically being performed in the human mind alone using observation, evaluation, judgment, and opinion or with the aid of pen and paper. For example, the limitation (a) in the context of the claim encompasses a human observing a source application using observation, evaluation, judgment, and opinion to mentally identify source instructions. The limitation (b) in the context of the claim encompasses a human observing sets of source instructions using observation, evaluation, judgment, and opinion to mentally generate data representative of the source instructions with the aid of pen and paper. The limitation (c) in the context of the claim encompasses a human using observation, evaluation, judgment, and opinion to mentally generate a secured software application, comprising data and a runtime engine with the features listed in limitation (c), with the aid of pen and paper by writing code to generate the application. The limitation (c) includes the description of features of the runtime engine which is part of the generation of the secured software application. See MPEP § 2106.04(a)(2)(III). If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the human mind alone or with the aid of pen and paper but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea. Step 2A, Prong Two: This judicial exception is not integrated into a practical application. In particular, the claim recites the additional element: A non-transitory computer-readable medium storing instructions which, when executed on a processing system, cause the processing system to carry out a method for generating a secured software application from a source software application, the method comprising. The additional element (1) is recited at a high-level of generality such that it amounts to no more than mere instructions to apply the judicial exception using generic computer components. The non-transitory computer-readable medium and processing system are used as tools to perform the receiving, identifying, and generating steps of the claim. See MPEP § 2106.05(f). Also, the claim recites the additional element: receiving a source software application. The additional element (2) is mere data transmitting recited at a high level of generality, and thus is an insignificant extra-solution activity. See MPEP § 2106.05(g). Furthermore, all uses of the recited judicial exception require such data transmitting, and, as such, the additional element does not impose any meaningful limits on the claim. The additional element amounts to necessary data transmitting. See MPEP § 2106.05. Accordingly, even when viewed in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. Step 2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as a combination do not amount to significantly more than the abstract idea. As discussed above with respect to integration of the abstract idea into a practical application, the claim recites the additional element: A non-transitory computer-readable medium storing instructions which, when executed on a processing system, cause the processing system to carry out a method for generating a secured software application from a source software application, the method comprising. The additional element (1) amounts to no more than mere instructions to apply the judicial exception using generic computer components. Mere instructions to apply a judicial exception using generic computer components cannot provide an inventive concept. Also, the claim recites the additional element: receiving a source software application. The additional element (2) simply appends well-understood, routine, and conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception is not indicative of an inventive concept. MPEP § 2106.05(d)(II) expressly states that the courts have recognized the computer function of receiving or transmitting data over a network, e.g., using the Internet to gather data as a well‐understood, routine, and conventional computer function when it is claimed in a merely generic manner (e.g., at a high level of generality) or as insignificant extra-solution activities. Thus, a person of ordinary skill in the art would readily comprehend that it is well-understood, routine, and conventional in the computing art to receive an application (data). Therefore, the limitation remains an insignificant extra-solution activity even upon reconsideration and does not amount to significantly more. Thus, taken alone, the additional elements do not amount to significantly more than the above-identified judicial exception (the abstract idea). Looking at the additional elements as a combination adds nothing that is not already present when looking at the additional elements taken individually. Even when considered in combination, the additional elements represent mere instructions to apply a judicial exception using generic computer components and insignificant extra-solution activities, and therefore do not provide an inventive concept. The claim is not patent eligible. <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> + <<>> Claim Interpretation: Under the broadest reasonable interpretation (BRI), the limitations of Claim 29 are presumed to have their plain meaning consistent with the specification as it would be interpreted by one of ordinary skill in the art. See MPEP § 2111. Step 1: Claim 29 is directed to a system, which is a machine, and falls within one of the statutory categories of invention. Step 2A, Prong One: Claim 29 recites the limitations: identifying one or more sets of source instructions within the source software application; for each of the sets of source instructions, generating respective data representative of the respective set of source instructions; and generating a secured software application comprising the data and comprising a runtime engine, wherein the runtime engine comprises code for processing the data, during a runtime of the secured software application, to generate, for each of the sets of source instructions, a respective plurality of generations of a respective set of runtime instructions, for execution during the runtime, wherein each generation of the respective set of runtime instructions is functionally equivalent to the respective set of source instructions, and wherein at least two of the generations of the respective set of runtime instructions differ from each other; and wherein the runtime engine comprises code for writing the runtime instructions generated by the runtime engine at each generation to a memory of a processing system executing the secured software application, and for causing the generated runtime instructions to be executed directly from the memory. These recited steps, under the broadest reasonable interpretation (BRI), cover performance of the steps in the human mind alone or with the aid of pen and paper. That is, other than reciting: the processing system comprising a memory and one or more processors, wherein the memory stores software which, when executed by the one or more processors causes the processing system to carry out a method comprising. Nothing in the claim precludes the steps from practically being performed in the human mind alone using observation, evaluation, judgment, and opinion or with the aid of pen and paper. For example, the limitation (a) in the context of the claim encompasses a human observing a source application using observation, evaluation, judgment, and opinion to mentally identify source instructions. The limitation (b) in the context of the claim encompasses a human observing sets of source instructions using observation, evaluation, judgment, and opinion to mentally generate data representative of the source instructions with the aid of pen and paper. The limitation (c) in the context of the claim encompasses a human using observation, evaluation, judgment, and opinion to mentally generate a secured software application, comprising data and a runtime engine with the features listed in limitation (c), with the aid of pen and paper by writing code to generate the application. The limitation (c) includes the description of features of the runtime engine which is part of the generation of the secured software application. See MPEP § 2106.04(a)(2)(III). If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the human mind alone or with the aid of pen and paper but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea. Step 2A, Prong Two: This judicial exception is not integrated into a practical application. In particular, the claim recites the additional element: the processing system comprising a memory and one or more processors, wherein the memory stores software which, when executed by the one or more processors causes the processing system to carry out a method comprising. The additional element (1) is recited at a high-level of generality such that it amounts to no more than mere instructions to apply the judicial exception using generic computer components. The processor and memory are used as tools to perform the receiving, identifying, and generating steps of the claim. See MPEP § 2106.05(f). Also, the claim recites the additional element: receiving a source software application. The additional element (2) is mere data transmitting recited at a high level of generality, and thus is an insignificant extra-solution activity. See MPEP § 2106.05(g). Furthermore, all uses of the recited judicial exception require such data transmitting, and, as such, the additional element does not impose any meaningful limits on the claim. The additional element amounts to necessary data transmitting. See MPEP § 2106.05. Accordingly, even when viewed in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. Step 2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as a combination do not amount to significantly more than the abstract idea. As discussed above with respect to integration of the abstract idea into a practical application, the claim recites the additional element: the processing system comprising a memory and one or more processors, wherein the memory stores software which, when executed by the one or more processors causes the processing system to carry out a method comprising. The additional element (1) amounts to no more than mere instructions to apply the judicial exception using generic computer components. Mere instructions to apply a judicial exception using generic computer components cannot provide an inventive concept. Also, the claim recites the additional element: receiving a source software application. The additional element (2) simply appends well-understood, routine, and conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception is not indicative of an inventive concept. MPEP § 2106.05(d)(II) expressly states that the courts have recognized the computer function of receiving or transmitting data over a network, e.g., using the Internet to gather data as a well‐understood, routine, and conventional computer function when it is claimed in a merely generic manner (e.g., at a high level of generality) or as insignificant extra-solution activities. Thus, a person of ordinary skill in the art would readily comprehend that it is well-understood, routine, and conventional in the computing art to receive an application (data). Therefore, the limitation remains an insignificant extra-solution activity even upon reconsideration and does not amount to significantly more. Thus, taken alone, the additional elements do not amount to significantly more than the above-identified judicial exception (the abstract idea). Looking at the additional elements as a combination adds nothing that is not already present when looking at the additional elements taken individually. Even when considered in combination, the additional elements represent mere instructions to apply a judicial exception using generic computer components and insignificant extra-solution activities, and therefore do not provide an inventive concept. The claim is not patent eligible. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 3, 6-7, 18, 21-23, and 28-30 are rejected under 35 U.S.C. 103 as being unpatentable over US 2019/0286818 (Provided by Applicant’s IDS, hereinafter “Friedman”) in view of US 2004/0015710 (hereinafter “Rhodes”). As per Claim 1, Friedman discloses: A computer-implemented method for generating a secured software application from a source software application (paragraph [0012], “Various embodiments provide methods, systems, and computer-readable storage medium including a computer program product for defending against cyber-attacks are provided.”; paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique.”), the method comprising: receiving a source software application (paragraph [0012], “One method comprises receiving, by a processor, program code and automatically generating a chronomorphic binary (e.g., a binary the changes throughout execution time) for the program code (emphasis added).”); identifying one or more sets of source instructions within the source software application (paragraph [0040], “With the SMC binary created, offline portion 2215 analyzes the target program for potentially exploitable sequences of instructions or gadgets (emphasis added).”; paragraphs [0031-0033], “2) Analyzing the SMC binary to identify potentially exploitable sequences of instructions (e.g., gadgets) (see block 320 in FIG. 3); 3) Identifying relocatable gadgets and transform the SMC binary to make those gadgets relocatable (see block 330 in FIG. 3); 4) Computing instruction-level, semantics-preserving transforms that make non-relocatable gadgets and surrounding program code of no use to attackers (see blocks 342 and 344 in FIG. 3) (emphasis added).”) [Examiner’s Remarks: Friedman discloses analyzing the program (source application) to identify potentially exploitable sequences of instructions or gadgets and computing transforms for non-relocatable gadgets. One of ordinary skill in the art would readily comprehend that the computing transforms for the non-relocatable gadgets include identifying the non-relocatable gadgets (one or more sets of source instructions) within the program (source application).]; generating a secured software application comprising a runtime engine (paragraph [0040], “Each of these three embodiments inject the chronomorph SMC runtime into the target program to produce a SMC binary (emphasis added).”; paragraph [0079], “At least in the illustrated embodiment, method 600 begins offline by injecting a chronomorph SMC runtime into the binary of a target program binary to produce a SMC binary with SMC functions that are disconnected from the target program's normal control flow (block 605).”), wherein the runtime engine comprises code for processing [data], during a runtime of the secured software application, to generate, for each of the sets of source instructions, a respective plurality of generations of a respective set of runtime instructions, for execution during the runtime (paragraph [0033], “Computing instruction-level, semantics-preserving transforms that make non-relocatable gadgets and surrounding program code of no use to attackers (see blocks 342 and 344 in FIG. 3) (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code (block 625). The relocations and transforms are written to a morph table outside the chronomorphic binary (block 630) and morph triggers are injected into the SMC binary so that the program will morph itself periodically (block 635), which produces a chronomorphic binary (emphasis added).”; paragraphs [0064-0066], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences. A first IPC strategy to compute transformations comprises instruction substitution (IS), which substitutes a single instruction for one or more alternatives […] Another IPCR strategy comprises register preservation code reordering (RPCR), which reorders the pop instructions before every “ret” instruction of a function and also reorders the corresponding push instructions at the function head to maintain symmetry (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”; paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique (emphasis added).”), wherein each generation of the respective set of runtime instructions is functionally equivalent to the respective set of source instructions (paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique. Using the SMC technique, the chronomorphic preserves the functionality of the underlying program (i.e., maintains the program semantics), maximizes diversity over time, and minimize performance costs (emphasis added).”; paragraph [0033], “Computing instruction-level, semantics-preserving transforms that make non-relocatable gadgets and surrounding program code of no use to attackers (see blocks 342 and 344 in FIG. 3) (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code (block 625) (emphasis added).”), and wherein at least two of the generations of the respective set of runtime instructions differ from each other (paragraph [0064], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions (emphasis added).”; paragraph [0077], “Each MorphPoint is traversed and a corresponding MorphOption is chosen at random and written. Each operation is surrounded by mprotect calls to make the corresponding page writable and then executable (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code […] are written to a morph table outside the chronomorphic binary […] (emphasis added).”; paragraph [0069], “Each morph table binary represents packed structs (e.g., MorphPoint structs with internal MorphOption byte sequences). Each MorphPoint represents a decision point (i.e., an IS or RPCR opportunity) where any of the associated MorphOption structs will suffice. Each MorphPoint is stateless (e.g., does not depend on the last choice made for the MorphPoint) and independent of any other MorphPoint so that random choices are safe and ordering of the morph table is not important.”); and wherein the runtime engine comprises code for writing the runtime instructions generated by the runtime engine at each generation to a memory of a processing system executing the secured software application, and for causing the generated runtime instructions to be executed directly from the memory (paragraph [0077], “Each MorphPoint is traversed and a corresponding MorphOption is chosen at random and written. Each operation is surrounded by mprotect calls to make the corresponding page writable and then executable (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code […] are written to a morph table outside the chronomorphic binary […].”; paragraph [0069], “Each morph table binary represents packed structs (e.g., MorphPoint structs with internal MorphOption byte sequences).”) [Examiner’s Remarks: Note that Friedman discloses computing semantics-preserving transforms that denature non-relocatable gadgets written to a morph table that includes MorphPoints and MorphOptions. Friedman discloses a MorphOption being written and each operation being surrounded by mprotect calls to make a corresponding page writable and executable. Friedman also discloses the chronomorphic binary connecting to the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime. One of ordinary skill in the art would readily comprehend that the MorphOption (runtime instructions) is written to a memory page which is then executed in order to induce diversification of executable memory during runtime.]. Friedman discloses “the sets of source instructions,” “generating a secured software application comprising a runtime engine,” and “wherein the runtime engine comprises code for processing [data] […],” but does not explicitly disclose: for each of the sets of source instructions, generating respective data representative of the respective set of source instructions; generating a secured software application comprising the data and comprising a runtime engine; wherein the runtime engine comprises code for processing the data […]. However, Rhodes discloses: for each of the sets of [instructions], generating respective data representative of the respective set of [instructions] (paragraph [0009], “The encoding program encrypts the language identifier and the source code instructions, and provides [generates] an encrypted file that includes an encrypted language identifier and an encrypted version of the source code. The encrypted file may then be provided to a licensee without undue risk (emphasis added).”). Friedman is within the same field of endeavor as the claimed invention regarding generation of runtime instructions to protect against software attacks. Rhodes is also within the same field of endeavor as the claimed invention regarding the utilization of encryption to protect against software attacks. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Rhodes into the teaching of Friedman to include “for each of the sets of source instructions, generating respective data representative of the respective set of source instructions; generating a secured software application comprising the data and comprising a runtime engine; wherein the runtime engine comprises code for processing the data […].” The modification would be obvious because one of ordinary skill in the art would be motivated to encrypt code to protect software from being copied, altered, or reverse engineered by unauthorized parties; moreover, utilizing a system that encrypts/decrypts the code without regard to the specific choice of the interpreted language relives licensees from needing to have a multiplicity of language-dependent decoding programs (Rhodes, paragraphs [0001 & 0011]). As per Claim 3, the rejection of Claim 1 is incorporated; and Friedman discloses “the sets of source instructions (paragraph [0040], “With the SMC binary created, offline portion 2215 analyzes the target program for potentially exploitable sequences of instructions or gadgets (emphasis added).”; paragraph [0033], “Computing instruction-level, semantics-preserving transforms that make non-relocatable gadgets and surrounding program code of no use to attackers (see blocks 342 and 344 in FIG. 3).”)” and “the secured software application (paragraph [0079], “At least in the illustrated embodiment, method 600 begins offline by injecting a chronomorph SMC runtime into the binary of a target program binary to produce a SMC binary with SMC functions that are disconnected from the target program's normal control flow (block 605).”),” but does not explicitly disclose: wherein the data representative of the sets of source instructions is encrypted and the secured software application encodes one or more cryptographic keys for decrypting the encrypted data. However, Rhodes discloses: wherein the data representative of the [code] is encrypted and the [program] encodes one or more cryptographic keys for decrypting the encrypted data (paragraph [0009], “The encoding program encrypts the language identifier and the source code instructions, and provides an encrypted file that includes an encrypted language identifier and an encrypted version of the source code. The encrypted file may then be provided to a licensee without undue risk (emphasis added).”; abstract, “The decoder then decrypts an encrypted source code instruction and inputs the result to the interpreter, looping through the instructions until reaching the end of the encrypted file, passing decrypted instructions to the interpreter at a rate suitable for execution by the interpreter substantially in real time.”; paragraph [0020], “In a preferred embodiment of the invention, the decryption key needed by the decryption program is compiled into the decoding program.”; paragraph [0019], “To embody the invention, any suitable encryption and decryption programs may be used. An exemplary embodiment of the invention uses the so-called Tiny Encryption Algorithm (TEA), which is well known to those skilled in the art. The invention is not so limited, however, and a wide variety of other encryption and decryption programs known to those skilled in the art may be used as well, including single-key systems and systems having both public and private keys.”). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Rhodes into the teaching of Friedman to include “wherein the data representative of the sets of source instructions is encrypted and the secured software application encodes one or more cryptographic keys for decrypting the encrypted data.” The modification would be obvious because one of ordinary skill in the art would be motivated to encrypt code and utilize keys to decrypt encrypted data in order to prevent unauthorized access to the code and execute code securely (Rhodes, abstract & paragraph [0020]). As per Claim 6, the rejection of Claim 1 is incorporated; and Friedman discloses “the source application (paragraph [0012], “One method comprises receiving, by a processor, program code and automatically generating a chronomorphic binary (e.g., a binary the changes throughout execution time) for the program code (emphasis added).”)” and “the identified sets of source instructions (paragraph [0040], “With the SMC binary created, offline portion 2215 analyzes the target program for potentially exploitable sequences of instructions or gadgets (emphasis added).”; paragraph [0033], “Computing instruction-level, semantics-preserving transforms that make non-relocatable gadgets and surrounding program code of no use to attackers (see blocks 342 and 344 in FIG. 3) (emphasis added).”),” but does not explicitly disclose: wherein every instruction of the source software application is included in at least one of the identified sets of source instructions. However, Rhodes discloses: wherein every instruction of the [program] is included in at least one of the [encrypted sets of instructions] (abstract, “A language identifier and the source code are input to an encoding program, which provides an encrypted file that includes the language identifier and source code. The encrypted file is input to a decoding program. The decoding program decrypts the language identifier and opens a suitable interpreter. The decoder then decrypts an encrypted source code instruction and inputs the result to the interpreter, looping through the instructions until reaching the end of the encrypted file, passing decrypted instructions to the interpreter at a rate suitable for execution by the interpreter substantially in real time.”). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Rhodes into the teaching of Friedman to include “wherein the data representative of the sets of source instructions is encrypted and the secured software application encodes one or more cryptographic keys for decrypting the encrypted data.” The modification would be obvious because one of ordinary skill in the art would be motivated to encrypt all of the code within the program in order to prevent unauthorized access to any part of the code and protect the program from any copying, altering, and reverse engineering from unauthorized parties (Rhodes, abstract & paragraph [0001]). As per Claim 7, the rejection of Claim 1 is incorporated; and Friedman further discloses: wherein the source software application is received as a binary application (paragraph [0036], “In one various embodiments, before offline analysis tool 2215 can analyze the binary and compute transformations for the third-party program (e.g., a target program), offline analysis tool 2215 injects a chronomorph SMC runtime into the target program [source application].”; paragraph [0039], “In another embodiment in which the source code of the target program is unavailable, the chronomorph SMC runtime is injected by rewriting a dynamically-linked binary by adding chronomorph procedures to an alternative procedure linkage table and adding objects to a global object table. The binary is then extended with a new loadable, executable segment containing the dynamically-linked chronomorph SMC runtime to produce a dynamically-linked SMC executable.”) [Examiner’s Remarks: Note that Friedman discloses injecting the SMC runtime into the target program (source application) and that when the source code of the target program is not available, the SMC runtime is injected by rewriting a dynamically-linked binary and extending the binary with an executable segment containing the dynamically linked SMC runtime. One of ordinary skill in the art would readily comprehend that the target program was received as a binary in order to inject the SMC runtime.]. As per Claim 18, the rejection of Claim 1 is incorporated; and Friedman further discloses: wherein the runtime engine comprises code for introducing differences between two generations of a set of runtime instructions such that each of the two generations uses memory differently, or has the same runtime instructions in a different order, or contains a different number of runtime instructions, or contains one or more different runtime instructions, or has any combination of these differences (paragraphs [0064-0066], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences. A first IPC strategy to compute transformations comprises instruction substitution (IS), which substitutes a single instruction for one or more alternatives […] Another IPCR strategy comprises register preservation code reordering (RPCR), which reorders the pop instructions before every “ret” instruction of a function and also reorders the corresponding push instructions at the function head to maintain symmetry (emphasis added).”). As per Claim 21, the rejection of Claim 1 is incorporated; and Friedman further discloses: wherein the secured software application comprises one or more templates and wherein the runtime engine comprises code for resolving one or more of the templates when writing the runtime instructions to the memory of the processing system executing the secured software application such that at least some of the generated runtime instructions comprise one or more resolved templates (Figure 4; paragraph [0069], “Each morph table binary represents packed structs (e.g., MorphPoint structs with internal MorphOption byte sequences). Each MorphPoint represents a decision point (i.e., an IS or RPCR opportunity) where any of the associated MorphOption structs will suffice. Each MorphPoint is stateless (e.g., does not depend on the last choice made for the MorphPoint) and independent of any other MorphPoint so that random choices are safe and ordering of the morph table is not important. The relocation data is a separate portion of the morph table and contains the content of relocatable blocks alongside their corresponding jump addresses (emphasis added).”; paragraph [0072], “Online execution tool 2220 comprises computer-executable code for diversifying the executable memory space of the chronomorphic binary during program runtime. Diversification is accomplished by relocating and transforming the instructions of the program code without hindering the performance or functionality of the target program […] For example, when the first morph trigger is invoked, the chronomorph SMC runtime loads the morph table and seeds its random number generator […] In other embodiments, the morph triggers induce a complete SMC diversification of the in-process executable memory according to the IPCR and relocation data in the morph table (emphasis added).”; paragraph [0077], “Each MorphPoint is traversed and a corresponding MorphOption is chosen [resolved] at random and written. Each operation is surrounded by mprotect calls to make the corresponding page writable and then executable (emphasis added).”). As per Claim 22, the rejection of Claim 21 is incorporated; and Friedman further discloses: wherein a first template of the one or more templates comprises one or more unallocated elements, and wherein the secured software application comprises code for resolving the first template by allocating a respective value to each of the unallocated elements of the first template (paragraph [0077], “Each MorphPoint is traversed and a corresponding MorphOption is chosen at random and written. Each operation is surrounded by mprotect calls to make the corresponding page writable and then executable (emphasis added).”; paragraph [0055], “Write the block's byte sequence and the address of the new jump instruction to the morph table.”) [Examiner’s Remarks: Note that Friedman discloses writing values to the morph table and choosing/writing a corresponding MorphOption for each traversed MorphPoint. One of ordinary skill in the art would readily comprehend that there were unallocated elements within the morph table until the corresponding MorphOptions were chosen/written (allocated) for each MorphPoint.]. As per Claim 23, the rejection of Claim 22 is incorporated; and Friedman further discloses: wherein at least one of the unallocated elements is suitable for receiving a register address, or a memory address, or a constant (Figure 4; paragraph [0055], “Write the block's byte sequence and the address of the new jump instruction to the morph table.”). As per Claim 28, Friedman discloses: A non-transitory computer-readable medium storing instructions which, when executed on a processing system, cause the processing system to carry out a method (paragraph [0093], “Any combination of one or more computer-readable medium(s) may be utilized. The computer-readable medium may be […] a non-transitory computer-readable storage medium […] In the context of this document, a computer-readable storage medium may be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.”; abstract, “Methods, systems, and computer-readable storage medium including a computer program product for defending against cyber-attacks are provided.”; paragraph [0040], “Each of these three embodiments inject the chronomorph SMC runtime into the target program to produce a SMC binary.”) for generating a secured software application from a source software application, the method comprising: […]. Claim 28 is a non-transitory computer-readable medium claim corresponding to method Claim 1 and the remainder of Claim 28 is rejected for the same reasons as given in the rejection of Claim 1. As per Claim 29, Friedman discloses: A processing system for generating a secured software application from a source software application, the processing system comprising a memory and one or more processors (paragraph [0013], “A system comprises memory configured for storing a defense module and a processor connected to the memory.”; abstract, “Methods, systems, and computer-readable storage medium including a computer program product for defending against cyber-attacks are provided.”; paragraph [0040], “Each of these three embodiments inject the chronomorph SMC runtime into the target program to produce a SMC binary.”), wherein the memory stores software which, when executed by the one or more processors causes the processing system to carry out a method comprising: […]. Claim 29 is a system claim corresponding to method Claim 1 and the remainder of Claim 29 is rejected for the same reasons as given in the rejection of Claim 1. As per Claim 30, the rejection of Claim 1 is incorporated; and Friedman further discloses: A non-transitory computer-readable medium storing a secured software application generated by the method of claim 1 (paragraph [0093], “Any combination of one or more computer-readable medium(s) may be utilized. The computer-readable medium may be […] a non-transitory computer-readable storage medium […] In the context of this document, a computer-readable storage medium may be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.”; abstract, “Methods, systems, and computer-readable storage medium including a computer program product for defending against cyber-attacks are provided.”; paragraph [0040], “Each of these three embodiments inject the chronomorph SMC runtime into the target program to produce a SMC binary.”). Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Rhodes as applied to Claim 1 above, and further in view of US 11,122,079 (hereinafter “Aloisio”). As per Claim 2, the rejection of Claim 1 is incorporated; and Friedman discloses “the sets of source instructions (paragraph [0040], “With the SMC binary created, offline portion 2215 analyzes the target program for potentially exploitable sequences of instructions or gadgets (emphasis added).”; paragraph [0033], “Computing instruction-level, semantics-preserving transforms that make non-relocatable gadgets and surrounding program code of no use to attackers (see blocks 342 and 344 in FIG. 3).”)” and “the secured software application (paragraph [0079], “At least in the illustrated embodiment, method 600 begins offline by injecting a chronomorph SMC runtime into the binary of a target program binary to produce a SMC binary with SMC functions that are disconnected from the target program's normal control flow (block 605).”),” but the combination of Friedman and Rhodes does not explicitly disclose: wherein the data representative of the sets of source instructions is obfuscated and the secured software application comprises code for deobfuscating the data. However, Aloisio discloses: wherein the data representative of the [code] is obfuscated and the [engine] comprises code for deobfuscating the data (col. 12 lines 24-29, “Upon receiving obfuscated response data from controller node 16 and/or compute nodes 18, obfuscation engine 48 may be configured to deobfuscate the obfuscated code or command, in cases in which obfuscation engine 48 had previously obfuscated the original code or command provided by command processing engine 40.”). Aloisio is within the same field of endeavor as the claimed invention regarding code obfuscation. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Aloisio into the combined teachings of Friedman and Rhodes to include “wherein the data representative of the sets of source instructions is obfuscated and the secured software application comprises code for deobfuscating the data.” The modification would be obvious because one of ordinary skill in the art would be motivated to obfuscate data to improve data security by enforcing data confidentiality (Aloisio, col. 2 lines 1-5 & col. 4 lines 19-23). Claims 8 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Rhodes as applied to Claim 1 above, and further in view of KR 102105020 (Provided by Applicant’s IDS, hereinafter “Kim”). As per Claim 8, the rejection of Claim 1 is incorporated; and the combination of Friedman and Rhodes does not explicitly disclose: wherein the runtime instructions generated by the runtime engine are native instructions. However, Kim discloses: wherein the runtime instructions generated by the runtime engine are native instructions (paragraph [0082], “A new VM section is linked (or inserted) into the target program, and at runtime, the entry point of the protected code region calls the VM to convert bytecode instructions into native machine code and execute the program.”; paragraph [0006], “The substituted virtual instructions are converted into native machine code at runtime to be executed on the underlying hardware platform.”). Kim is within the same field of endeavor as the claimed invention regarding code obfuscation. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Kim into the combined teachings of Friedman and Rhodes to include “wherein the runtime instructions generated by the runtime engine are native instructions.” The modification would be obvious because one of ordinary skill in the art would be motivated to utilize a system that uses native instructions and VM-based code obfuscation techniques in order to effectively execute the program and neutralize attacks by drastically increasing the input of time and resources, making reverse engineering difficult by forcing attackers to interpret unfamiliar virtualized instruction sets from familiar instruction sets (Kim, paragraphs [0082 & 0083]). As per Claim 19, the rejection of Claim 1 is incorporated; and Friedman discloses “wherein the data in the secured software application represents the source instructions (paragraph [0079], “At least in the illustrated embodiment, method 600 begins offline by injecting a chronomorph SMC runtime into the binary of a target program binary to produce a SMC binary with SMC functions that are disconnected from the target program's normal control flow (block 605).”; paragraph [0040], “With the SMC binary created, offline portion 2215 analyzes the target program for potentially exploitable sequences of instructions or gadgets.”)”and “wherein the runtime engine comprises code […] to create the plurality of generations of each set of runtime instructions (paragraph [0033], “Computing instruction-level, semantics-preserving transforms that make non-relocatable gadgets and surrounding program code of no use to attackers (see blocks 342 and 344 in FIG. 3) (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code (block 625). The relocations and transforms are written to a morph table outside the chronomorphic binary (block 630) and morph triggers are injected into the SMC binary so that the program will morph itself periodically (block 635), which produces a chronomorphic binary (emphasis added).”; paragraphs [0064-0066], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences. A first IPC strategy to compute transformations comprises instruction substitution (IS), which substitutes a single instruction for one or more alternatives […] Another IPCR strategy comprises register preservation code reordering (RPCR), which reorders the pop instructions before every “ret” instruction of a function and also reorders the corresponding push instructions at the function head to maintain symmetry (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”; paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique (emphasis added).”),” but the combination of Friedman and Rhodes does not explicitly disclose: wherein the data in the secured software application represents the source instructions using virtual machine instructions, wherein each virtual machine instruction represent one or a plurality of source instructions, and wherein the runtime engine comprises code implementing a virtual machine for interpreting the virtual machine instructions to create the plurality of generations of each set of runtime instructions. However, Kim discloses: represents the [instructions] using virtual machine instructions, wherein each virtual machine instruction represent one or a plurality of [instructions], and wherein the [software] comprises code implementing a virtual machine for interpreting the virtual machine instructions (paragraph [0066], “Another method is to create a virtual machine (VM) directly, similar to the case of JAVA. In other words, it is a method of transforming assembly code into virtual code while ensuring identical behavior by generating virtual instructions corresponding to assembly code instructions and mapping them to a virtual machine handler that guarantees identical execution.”; paragraph [0089], “Accordingly, the embodiment according to the present invention is based on a plurality of virtual machines and attempts to make analysis difficult by arbitrarily creating a plurality of handlers.”). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Kim into the combined teachings of Friedman and Rhodes to include “wherein the data in the secured software application represents the source instructions using virtual machine instructions, wherein each virtual machine instruction represent one or a plurality of source instructions, and wherein the runtime engine comprises code implementing a virtual machine for interpreting the virtual machine instructions to create the plurality of generations of each set of runtime instructions.” The modification would be obvious because one of ordinary skill in the art would be motivated to utilize VM-based obfuscation and virtual instructions because it makes it difficult to guess the original code from the virtual instructions which makes reverse engineering difficult for attackers (Kim, paragraphs [0074 & 0083]). Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Rhodes as applied to Claim 1 above, and further in view of US 2013/0232573 (hereinafter “Saidi”). As per Claim 10, the rejection of Claim 1 is incorporated; and Friedman discloses “wherein the runtime engine comprises code for generating the sets of runtime instructions such that […] (paragraph [0033], “Computing instruction-level, semantics-preserving transforms that make non-relocatable gadgets and surrounding program code of no use to attackers (see blocks 342 and 344 in FIG. 3) (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code (block 625). The relocations and transforms are written to a morph table outside the chronomorphic binary (block 630) and morph triggers are injected into the SMC binary so that the program will morph itself periodically (block 635), which produces a chronomorphic binary (emphasis added).”; paragraphs [0064], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”; paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique (emphasis added).”)” and but the combination of Friedman and Rhodes does not explicitly disclose: wherein the runtime engine comprises code for generating the sets of runtime instructions such that a call from a set of runtime instructions is received by the runtime engine, and further comprises code for redirecting the call to a further set of runtime instructions. However, Saidi discloses: a call from a set of [instructions] is received by the [redirecter], and [the redirecter] further comprises code for redirecting the call to a further set of [instructions] (paragraph [0071], “Referring now to FIG. 3, an illustrative method 300, which may be implemented as one or more computer-executable instructions, routines, or processes by which the MEC redirecter 160 may cause low-level system calls made by the repackaged software application 130 to be redirected to privacy, security, performance and/or other monitoring and enforcement code at runtime, is shown (emphasis added).”; paragraph [0073], “It should be appreciated that in some embodiments, the MEC redirecter 160 and MEC system call intercepter 162 may be configured, e.g., by the application repackager 114 according to the policies 166, so that only certain system calls are intercepted and redirected at runtime, or so that every system call is intercepted and redirected. So as to be able to modify the process memory, the illustrative embodiments of the MEC redirecter 160 are written in a lower-level programming language (such as C++) and compiled to native code.”). Saidi is within the same field of endeavor as the claimed invention regarding the redirection of calls. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Saidi into the combined teachings of Friedman and Rhodes to include “wherein the runtime engine comprises code for generating the sets of runtime instructions such that a call from a set of runtime instructions is received by the runtime engine, and further comprises code for redirecting the call to a further set of runtime instructions.” The modification would be obvious because one of ordinary skill in the art would be motivated to utilize a system that redirects calls to privacy, security, performance and/or other monitoring and enforcement code and monitors a software application in order to help prevent the software application from engaging in potentially unauthorized activities without the user's permission or from engaging in potentially unoptimized program flow and/or other activities that may be desirable to be monitored (Saidi, paragraphs [0037 & 0071]). Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Rhodes as applied to Claim 1 above, and further in view of US 9,483,259 (hereinafter “Lee”). As per Claim 11, the rejection of Claim 1 is incorporated; and Friedman discloses “wherein the runtime instructions generated by the runtime engine are ephemeral and [stored] in the memory of the processing system executing the secured software application (paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code […] are written to a morph table outside the chronomorphic binary […] (emphasis added).”; paragraph [0064], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”),” but the combination of Friedman and Rhodes does not explicitly disclose: wherein the runtime instructions generated by the runtime engine are ephemeral and are transiently stored in the memory of the processing system executing the secured software application. However, Lee discloses: wherein the [instructions] are transiently stored in the memory of the processing system (col. 10 lines 41-45, “In one embodiment, each time user device 160 transmits to collaborative development service 130 an instruction to make a change to a source code file, user device 160 also stores transiently in memory a reverse instruction in a stack data structure.”). Lee is within the same field of endeavor as the claimed invention regarding transiently storing data in memory. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Lee into the combined teachings of Friedman and Rhodes to include “wherein the runtime instructions generated by the runtime engine are ephemeral and are transiently stored in the memory of the processing system executing the secured software application.” The modification would be obvious because one of ordinary skill in the art would be motivated to transiently store data in memory for faster retrieval and reduced latency (Lee, col. 10 lines 41-45). Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Rhodes as applied to Claim 1 above, and further in view of US 2021/0004243 (hereinafter “Shan”). As per Claim 12, the rejection of Claim 1 is incorporated; and Friedman discloses “the runtime engine (paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”)” and “generation of a set of runtime instructions from the memory of the processing system executing the secured software application (paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code […] are written to a morph table outside the chronomorphic binary […] (emphasis added).”; paragraph [0064], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”),” but the combination of Friedman and Rhodes does not explicitly disclose: wherein the runtime engine comprises code for removing a latest generation of a set of runtime instructions from the memory of the processing system executing the secured software application when an expiry condition is met. However, Shan discloses: wherein the [module] comprises code for removing a latest generation of [an object shell] from the memory when an expiry condition is met (paragraph [0083], “Alternatively, after the newly created object shell is used, or after the newly created object shell survives for a specific period/time, the object pool management module may delete the newly created object shell to make room in old generation memory space for creating a new object pool or creating an object shell for another object pool.”). Shan is within the same field of endeavor as the claimed invention regarding the removal of data from memory based on a condition being met. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Lee into the combined teachings of Friedman and Rhodes to include “wherein the runtime engine comprises code for removing a latest generation of a set of runtime instructions from the memory of the processing system executing the secured software application when an expiry condition is met.” The modification would be obvious because one of ordinary skill in the art would be motivated to delete old data to make room for newly generated data in order to avoid storing data that’s no longer needed and prevent problems regarding insufficient space (Shan, paragraph [0083]). Claims 15 and 27 are rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Rhodes as applied to Claim 1 above, and further in view of US 2019/0278665 (hereinafter “Raghuram”). As per Claim 15, the rejection of Claim 1 is incorporated; and Friedman discloses “the runtime engine (paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”)” and “generation of the set of runtime instructions from the memory of the processing system executing the secured software application (paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code […] are written to a morph table outside the chronomorphic binary […] (emphasis added).”; paragraph [0064], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”),” but the combination of Friedman and Rhodes does not explicitly disclose: wherein the runtime engine comprises code for creating a next generation of a set of runtime instructions before clearing a preceding generation of the set of runtime instructions from the memory of the processing system executing the secured software application. However, Raghuram discloses: wherein the [controller] comprises code for creating a next generation of a set of [data] before clearing a preceding generation of the set of [data] from the memory (paragraph [0253], “Again, the latest/current backup, together with its signature may be maintained in memory (such as non-volatile memory) of the system controller (as discussed below, each time the system controller generates another or new backup together with its signature, it may remove or delete the prior backup, along with this prior backup's signature) (emphasis added).”). Raghuram is within the same field of endeavor as the claimed invention regarding the generation of new data before removing old data. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Raghuram into the combined teachings of Friedman and Rhodes to include “wherein the runtime engine comprises code for creating a next generation of a set of runtime instructions before clearing a preceding generation of the set of runtime instructions from the memory of the processing system executing the secured software application.” The modification would be obvious because one of ordinary skill in the art would be motivated to delete old data after generating new data in order to ensure the new data is available before losing access to the old data which helps prevent unintended data loss (Raghuram, paragraph [0253]). As per Claim 27, the rejection of Claim 1 is incorporated; and Friedman discloses “the runtime engine (paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”)” and “generation of a set of runtime instructions from the memory of the processing system executing the secured software application (paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code […] are written to a morph table outside the chronomorphic binary […] (emphasis added).”; paragraph [0064], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”),”, but the combination of Friedman and Rhodes does not explicitly disclose: wherein the runtime engine comprises code for: clearing one generation of a set of runtime instructions from the memory of the processing system executing the secured software application when generating a next generation of the set of runtime instructions; or creating a next generation of a set of runtime instructions and subsequently clearing a preceding generation from the memory, such that two generations exist in the memory simultaneously. However, Raghuram discloses: wherein the [controller] comprises code for: clearing one generation of a set of [data] from the memory of the processing system when generating a next generation of the set of [data] (paragraph [0253], “Again, the latest/current backup, together with its signature may be maintained in memory (such as non-volatile memory) of the system controller (as discussed below, each time the system controller generates another or new backup together with its signature, it may remove or delete the prior backup, along with this prior backup's signature) (emphasis added).”). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Raghuram into the combined teachings of Friedman and Rhodes to include “wherein the runtime engine comprises code for: clearing one generation of a set of runtime instructions from the memory of the processing system executing the secured software application when generating a next generation of the set of runtime instructions; or creating a next generation of a set of runtime instructions and subsequently clearing a preceding generation from the memory, such that two generations exist in the memory simultaneously.” The modification would be obvious because one of ordinary skill in the art would be motivated to delete old data after generating new data in order to ensure the new data is available before losing access to the old data which helps prevent unintended data loss (Raghuram, paragraph [0253]). Claim 26 is rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Rhodes as applied to Claim 1 above, and further in view of US 2023/0106942 (hereinafter “Wong”). As per Claim 26, the rejection of Claim 1 is incorporated [Please note that Claim 26 is interpreted as being dependent on Claim 1 as a result of the 35 U.S.C. 112(d) rejection.]; and Friedman discloses the runtime engine (paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”)” and “the set of runtime instructions (paragraph [0025], “The chronomorph approach described herein changes the machine code at runtime using a self-modifying code (SMC) technique (emphasis added).”; paragraph [0081], “Furthermore, method 600 includes computing instruction-level, semantics-preserving transforms that denature non-relocatable gadgets and the surrounding program code […] are written to a morph table outside the chronomorphic binary […] (emphasis added).”; paragraph [0064], “In various other embodiments, the chronomorphic binary uses in-place code randomization (IPCR) strategies to randomize non-relocated instructions. IPCR strategies perform narrow-scope transformations without changing the byte-length of instruction sequences (emphasis added).”; paragraph [0070], “The chronomorphic binary, in one embodiment, automatically connects the chronomorph SMC runtime into the target program's control flow to induce diversification of executable memory during runtime (emphasis added).”),” but the combination of Friedman and Rhodes does not explicitly disclose: wherein the runtime engine comprises code for creating a new generation of the set of runtime instructions when a predetermined time interval has elapsed since generating an immediately preceding generation of the set of runtime instructions; or after a predetermined number of executions of the runtime instructions. However, Wong discloses: wherein the [software] comprises code for creating a new generation of the set of [code] when a predetermined time interval has elapsed since generating an immediately preceding generation of the set of [code] (paragraph [0063], “In various embodiments, the above-mentioned generating (at 204), at the first functional block, the first code comprises generating a new first code periodically based on a first time interval. In various embodiments, the above-mentioned generating (at 206), at the second functional block, the second code comprises generating a new second code periodically based on a second time interval. Accordingly, the first code generated at the first functional block and the second code generated at the second functional block are each refreshed periodically, such as at the expiry of the respective time interval […] Accordingly, for example, as the first code is refreshed (or re-initialized) periodically, freshness or unpredictability (without knowledge of the first code) of the series of random sequences generated at the first functional block (generated based on the first code) for obfuscating the address (which will be described below) can be achieved.”). Wong is within the same field of endeavor as the claimed invention regarding obfuscation and the generation of data in time intervals. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teaching of Wong into the combined teachings of Friedman and Rhodes to include “wherein the runtime engine comprises code for creating a new generation of the set of runtime instructions when a predetermined time interval has elapsed since generating an immediately preceding generation of the set of runtime instructions; or after a predetermined number of executions of the runtime instructions.” The modification would be obvious because one of ordinary skill in the art would be motivated to generate new data in predetermined time intervals to help ensure fresh and unpredictable data is provided (Wong, paragraph [0063]). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Feven H Huruy whose telephone number is (571) 272-3826. The examiner can normally be reached Mon-Fri. 7:30am-3:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Wei Mui can be reached at (571) 272-3708. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /F.H.H./Examiner, Art Unit 2191 /WEI Y MUI/Supervisory Patent Examiner, Art Unit 2191
Read full office action

Prosecution Timeline

Aug 16, 2024
Application Filed
Jul 29, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
67%
Grant Probability
99%
With Interview (+50.0%)
2y 9m (~9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 3 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month