Prosecution Insights
Last updated: August 18, 2026
Application No. 18/894,278

METHOD FOR SIGNING OR DECRYPTING DATA WITH A CRYPTOGRAPHIC KEY AS WELL AS COMPUTER PROGRAM PRODUCT AND DEVICE THEREFOR

Final Rejection §103
Filed
Sep 24, 2024
Examiner
LE, CANH
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
TrustNXT GmbH
OA Round
2 (Final)
73%
Grant Probability
Favorable
3-4
OA Rounds
1y 10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
310 granted / 423 resolved
+15.3% vs TC avg
Strong +72% interview lift
Without
With
+72.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
20 currently pending
Career history
452
Total Applications
across all art units

Statute-Specific Performance

§101
13.5%
-26.5% vs TC avg
§103
56.1%
+16.1% vs TC avg
§102
9.3%
-30.7% vs TC avg
§112
13.7%
-26.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 423 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This Office Action is in response to the communication and claim amendment filed on 04/16/2026; Claim 1 has been amended; Claims 1, 14, and 15 are independent claims. Claims 1-15 have been examined and are pending. This Action is made FINAL. Response to Arguments The objection to the drawing of figures 1-7 is withdrawn as replacement drawing sheets has been submitted. Applicants’ arguments in the instant Amendment, filed on 04/16/2026, with respect to limitations listed below, have been fully considered but they are not persuasive. a. Applicants argue: Koeberl is the wrong kind of mechanism. LR-PUF reconfigures a single PUF internally - it changes the output for a given challenge - and does not select among different physical-property sources (Applicant Remarks/Arguments, pages 8–9). The Examiner respectfully disagrees with the Applicants. This argument attacks Koeberl individually and does not address the rejection as formulated. Nonobviousness cannot be established by attacking references individually where the rejection is based on a combination (In re Keller, 642 F.2d 413 (CCPA 1981); In re Merck & Co., 800 F.2d 1091 (Fed. Cir. 1986); MPEP 2145.IV). The selection limitations — (b), (c), (f), and (g) — are mapped to Guo, not to Koeberl. Koeberl is relied upon for steps (a), (d), and (e), and its [0037] is cited only as a suggestion that reconfigurable, state-dependent PUF behavior is desirable ("by updating the state of a reconfigurable PUF, its challenge/response behavior can be dynamically changed"), supplying motivation. Further, the distinction Applicant draws — “selecting among different physical properties” versus “reconfiguring internally” — is met by Guo: Guo's switches "select a single RO from among the plurality of Ros” ( [0006]), each ring oscillator being a distinct physical component having a distinct “resonating frequency” arising from “manufacturing variations at the semiconductor level.” Guo therefore teaches selection among different physical-property sources. b. Applicants argue: Guo's challenge is transient, not persistent. It's an external per-query input, “not a persistent state that remains constant when the method is repeated and that is deliberately changed.” No concept of "remaining constant on repeat” or “changing the indicator”; challenges are “simply different inputs to the same selection circuit, not a controlled switching mechanism” (Applicant Remarks/Arguments, pages 9-10). The Examiner respectfully disagrees with the Applicants. Claim 1 does not recite a “persistent state,” a stored indicator, an indicator “held constant,” a “deliberate” change, or a “controlled switching mechanism.” These features do not recite in the independent claim 1.. Under the broadest reasonable interpretation, Guo's challenge — received as “an input to the switches 106, 108” ([0006]) — reads on “detecting an indicator” (1b). Applicant's own admission that “each PUF query receives its own independent challenge” confirms the rejection: an indicator independently suppliable each query is exactly a “changeable” indicator (1g), and re-presenting the same challenge necessarily selects the same ring oscillator (1f). Claim 1(f) requires only that an unchanged indicator cause selection of the same physical property — the necessary, inherent result of Guo's deterministic selection, in which the challenge “causes each switch … to then select a single RO” ([0006]) (MPEP 2112). Claim 1(g) requires only that the indicator be changeable so as to cause a differing selection — expressly taught by Guo's disclosure that a challenge “is designed such that each switch … selects a different RO” ([0006]). Whether the challenge is “transient” or “persistent” is therefore immaterial to what claim 1 actually recites. c. Applicants argue: Neither Koeberl nor Guo reference teaches “f) wherein, upon repeating steps a) to e), the indicator remains unchanged and thereby causes selection of the same at least one physical property as in a preceding execution of step c), and g) wherein the indicator is changeable so as to cause, in step c), selection of at least one physical property that differs from the physical property selected in the preceding execution of step c).” (Applicant Remarks/Arguments, page 10). The Examiner respectfully disagrees with the Applicants. This conclusion restates the claim language and rests entirely on the individual-mechanism contentions addressed above, which are unpersuasive. The rejection is based on the combination, not on either reference alone: Koeberl supplies steps (a), (d), (e) and the motivation for reconfigurable, state-dependent PUF behavior ([0037]); Guo supplies steps (b), (c), (f), (g) through its deterministic, challenge-controlled selection of a single ring oscillator from a plurality of ring oscillators ([0006]). Nonobviousness cannot be shown by attacking the references individually where the rejection rests on their combination (In re Keller, 642 F.2d 413 (CCPA 1981); In re Merck, 800 F.2d 1091 (Fed. Cir. 1986); MPEP 2145.IV). As shown above, 1(f) is the inherent result of Guo's deterministic selection ([0006]; MPEP 2112) and 1(g) is expressly taught by Guo ([0006]); both are further not accorded patentable weight as a result clause and a capability clause (MPEP 2111.04). The combination of Koeberl and Guo teaches claim 1 as a whole. d. Applicants argue: Guo recognizes RO aging ([0048]–[0049]) but responds by “detect-and-suspend” ([0041] mismatch → error → suspend operability), not by switching physical property to keep operating. A POSITA "would be led toward monitoring and suspension," so Guo "teaches away" (Applicant Remarks/Arguments, pages 9-11). The Examiner respectfully disagrees with the Applicants. This argument is not persuasive for three independent reasons. First, the teaching-away is directed to subject matter not recited in claim 1. Claim 1 recites neither aging, degradation, a criterion, nor "continued operability"; claim 1(g) recites only that the indicator “is changeable so as to cause” selection of a differing physical property, with no recited reason for the change. An argument premised on a limitation absent from the claim does not show nonobviousness Second, Guo does not teach away as a matter of law. A reference teaches away only where it criticizes, discredits, or otherwise discourages the claimed approach (In re Gurley, 27 F.3d 551 (Fed. Cir. 1994)). Disclosure of an alternative or even preferred approach is not a teaching away (In re Fulton, 391 F.3d 1195 (Fed. Cir. 2004); MPEP 2123, 2145.X.D). Guo's description of one response to degradation (suspension, [0041]) nowhere criticizes or discourages selecting a different ring oscillator; it therefore does not discourage the claimed selection. Third, the rejection relies on Guo [0006] (challenge-based selection of different ring oscillators), not on Guo [0041] (the degradation response). Guo's suspend-on-mismatch teaching does not negate its separate [0006] selection teaching, which satisfies (f) and (g). Indeed, Guo [0048]–[0049] expressly recognizes that different ring oscillators age differently and that health monitoring can identify which have degraded; combined with Guo's [0006] capability to select any ring oscillator by challenge, this recognition would have led a person of ordinary skill toward selecting a different ring oscillator by changing the challenge, reinforcing rather than discouraging the "changeable" indicator of claim 1(g). e. Applicants argue: Secondaries don't cure (Roth / Oberheide / Cambou / Pitsos / Denny) (Applicant Remarks/Arguments, pages 10-12). The Examiner respectfully disagrees with the Applicants. Roth, Oberheide, Cambou, Pitsos, and Denny are relied upon only in the rejections of the dependent claims to which they are applied. They are not relied upon in the rejection of claim 1, which stands over Koeberl in view of Guo. Applicant's assertion that these references do not cure a deficiency in claim 1 is therefore moot, no such deficiency having been shown. The dependent-claim rejections are maintained for the reasons stated in each respective rejection. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-5, 9, 11, and 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over Koeberl, Patrick (“Koeberl,” WO 2014/105310) in view of Guo et al. (“Guo,” US 2014/0225639). Regarding claim 1, Koeberl teaches a method for signing and/or decrypting data with a cryptographic key, comprising steps: a) receiving a request for generating at least one key for signing or for decrypting data (Koeberl: par. 0025, During an enrollment phase of authentication system 100, a large number of keys (e.g., 1000 keys, etc.) are generated as the intrinsic hardware identifier of the hardware device.”, “Authentication can be performed by generating the same keys. from the hardware device to verify the device identifier”, “manufacturing public key to verify the signature”; See also par. 0019, A PUF is a physical system that, when measured or challenged, provides unique, repeatable and unpredictable responses.), d) generating at least one key as a function of the selected physical property (Koeberl: par. [0036], "PUF based key generation system uses PUFs as an underlying static entropy source from which to generate one or more PUF root keys." , par. [0036] "[t]he underlying static entropy source is platform-unique and externally-unknown" and "more keys can be derived from the PUF root keys using cryptographic key derivation functions." ; See also [0037], which discloses "challenge/response behavior that depends on both the physical properties of the PUF" and "multiple outputted keys to be cryptographically derived from the PUF value."), and e) signing and/or decrypting the data as a function of the at least one key (Koeberl: par. [0043] discloses "[t]he private key, which may be known only to the sender, can be used to encrypt the data, or a portion thereof, to generate the digital signature." [0043] further discloses "[i]n authentication system 100, the device identifier (idD) can be the data that is encrypted to create the digital signature (σ)."), Koeberl suggests the concept of state-dependent PUF behavior with multiple physical properties (Koeberl: par. [0037], which discloses "Logically Reconfigurable PUF (LR-PUF)" where "challenge/response behavior... depends on both the physical properties of the PUF and on the logical state maintained by control logic" and "by updating the state of a reconfigurable PUF, its challenge/response behavior can be dynamically changed.") but does not explicitly disclose (b) detecting an indicator, (c) selecting at least one physical property of at least one component of a device as a function of the indicator, f) wherein, upon repeating steps a) to e), the indicator remains unchanged and thereby causes selection of the same at least one physical property as in a preceding execution of step c), and g) wherein the indicator is changeable so as to cause, in step c), selection of at least one physical property that differs from the physical property selected in the preceding execution of step c). However, in analogous art, Guo teaches (b) detecting an indicator (Guo: par. [0006]. "A challenge serves as an input to the switches 106, 108."); (c) selecting at least one physical property of at least one component of a device as a function of the indicator (Guo: par. [0006], "A challenge serves as an input to the switches 106, 108 which causes each switch 106, 108 to then select a single RO [ring oscillator] from among the plurality of ROs 104." , par. [0006] further discloses "[t]he challenge sent to the switches 106, 108 is designed such that each switch 106, 108 selects a different RO." par. [0006] also discloses "[t]he selected ROs each have a slightly different resonating frequency associated with them due to slight manufacturing variations at the semiconductor level.). f) wherein, upon repeating steps a) to e), the indicator remains unchanged and thereby causes selection of the same at least one physical property as in a preceding execution of step c) ((Guo: par. [0006], "A challenge serves as an input to the switches 106, 108 which causes each switch 106, 108 to then select a single RO from among the plurality of ROs 104," and "[t]he selected ROs each have a slightly different resonating frequency associated with them due to slight manufacturing variations at the semiconductor level.". Note: Guo discloses a deterministic selection — the challenge (indicator) "causes each switch … to then select a single RO." Because the selection is deterministic, presenting the same challenge in a subsequent execution necessarily causes the switches to select the same ring oscillator(s). The physical property relied upon — the RO's resonating frequency — is a fixed characteristic arising from "manufacturing variations at the semiconductor level"; the identity of the selected physical property is therefore fixed and does not vary between executions. Any measurement noise in a PUF affects the derived key value at step (d), not which physical property is selected at step (c). Selection of the same physical property upon an unchanged indicator is thus the necessary and inherent result of Guo's deterministic selection; inherency is established because the result must occur, not merely may occur (MPEP 2112)), and g) wherein the indicator is changeable so as to cause, in step c), selection of at least one physical property that differs from the physical property selected in the preceding execution of step c) (Guo: par. [0006], "A challenge serves as an input to the switches 106, 108 which causes each switch 106, 108 to then select a single RO from among the plurality of ROs 104," "[t]he challenge sent to the switches 106, 108 is designed such that each switch 106, 108 selects a different RO," and "[t]he selected ROs each have a slightly different resonating frequency associated with them due to slight manufacturing variations at the semiconductor level." Note: Guo expressly teaches that a changed indicator causes selection of a different physical property. Guo selects from "a plurality of ROs," and a challenge "is designed such that each switch … selects a different RO"; because each RO possesses "a slightly different resonating frequency," a different challenge value causes selection of a ring oscillator having a different physical property than that selected in a preceding execution. Guo therefore expressly discloses the "changeable" indicator causing selection of a differing physical property recited in 1(g). To the extent inherency is relied upon in the alternative, the differing result also necessarily follows from Guo's deterministic mapping of distinct challenges to distinct ring oscillators (MPEP 2112)) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Guo with the method and system of Koeberl to include (b) detecting an indicator, (c) selecting at least one physical property of at least one component of a device as a function of the indicator, f) wherein, upon repeating steps a) to e), the indicator remains unchanged and thereby causes selection of the same at least one physical property as in a preceding execution of step c), and g) wherein the indicator is changeable so as to cause, in step c), selection of at least one physical property that differs from the physical property selected in the preceding execution of step c). One would have been motivated to provide flexible selection of which physical properties (PUF sources) to use for key generation, as Guo teaches that challenge-based selection of ring oscillators is a known technique for generating PUF responses (Guo: par. 0006, "[t]he PUF output response is generated by a pair-wise comparison 114 of these selected ring oscillators' frequencies"). Furthermore, Koeberl already suggests the desirability of reconfigurable, state-dependent PUF behavior (Koeberl: par. [0037], "by updating the state of a reconfigurable PUF, its challenge/response behavior can be dynamically changed"), and incorporating Guo's explicit selection mechanism would provide a predictable way to implement such dynamic selection of physical properties for key generation, thereby allowing the same hardware to generate different keys based on different indicator values. Regarding claim 2, the combination of Koeberl and Guo teaches the method according to claim 1. The combination of Koeberl and Guo further teaches, wherein, as a function of the indicator in step c), a set with at least two physical properties is selected, wherein in step d), a key is generated as a function of each of the selected physical properties in each case (Guo: par. [0006] discloses "each switch 106, 108 selects a different RO," teaching selection of at least two physical properties (two different ring oscillators; Koeberl: par. [0036] discloses "generate one or more PUF root keys" , par. [0025] discloses "a large number of keys (e.g., 1000 keys, etc.) are generated," teaching the capability to generate multiple keys from PUF physical properties.), and in step e), the data is signed and/or decrypted with each of the generated keys (Koeberl: par. [0043] discloses "a private signing key and a public key, can be used to secure data" and "A digital signature is a mechanism in which the data is proved to have originated from a particular sender."). Regarding claim 3, the combination of Koeberl and Guo teaches the method according to claim 1. The combination of Koeberl and Guo further teaches, wherein in step c), at least three physical properties are selected, wherein a first physical property of the at least three physical properties corresponds to a physical property of at least one first component and of a second component (Koeberl: par. [0037] discloses "challenge /response behavior that depends on both the physical properties of the PUF," wherein "physical properties" is recited in plural, indicating multiple physical properties are available within a single PUF device; Guo: par. [0006], discloses "a plurality of ROs 104" within a single PUF structure, wherein each ring oscillator (RO) constitutes a component of the device, and "each switch 106, 108 selects a different RO." See also par. [0006], which discloses that the selected ROs are compared to produce an output, teaching that a physical property (frequency comparison result) corresponds to both a first component (first selected RO) and a second component (second selected RO)), a second physical property of the at least three physical properties corresponds to a physical property of at least the second component and of a third component (Guo: par. [0006] discloses that the challenge input controls "which causes each switch 106, 108 to then select a single RO from among the plurality of ROs 104," teaching that different challenges can select different pairs of ROs for comparison. A second challenge can select a different pair comprising the second component (second RO) and a third component (third RO), producing a second physical property based on their frequency comparison), and a third physical property of the at least three physical properties corresponds to a physical property of at least the third component and of the at least one first component (Quo: par. [0006] discloses the plurality of ROs and challenge-based selection mechanism. A third challenge can select a pair comprising the third component (third RO) and the first component (first RO), completing a ring/closed-loop topology where each component participates in exactly two physical property measurements). Regarding claim 4, the combination of Koeberl and Guo teaches the method according to claim 1. The combination of Koeberl and Guo further teaches wherein the indicator indicates one set to be selected of several sets which each comprise several physical properties (Guo: par. [0006] discloses "[a] challenge serves as an input to the switches 106, 108 which causes each switch 106, 108 to then select a single RO from among the plurality of ROs 104." See also Guo: par. [0006], which discloses "each switch 106, 108 selects a different RO," teaching that each challenge (indicator) causes selection of a pair of ROs (a set comprising two physical properties, i.e., the oscillation frequencies of the two selected ROs). Different challenge values select different RO pairs, teaching several sets available for selection; Koeberl: par. [0037], discloses "challenge/response behavior that depends on both the physical properties of the PUF," wherein "physical properties" is recited in plural, supporting that each set comprises several physical properties.), wherein at least one physical property of each set differs from a physical property of any other set (Guo: [0006] discloses "[t]he challenge sent to the switches 106, 108 is designed such that each switch 106, 108 selects a different RO." Different challenge values cause selection of different RO pairs. For example, a first challenge may select {RO1, RO2} while a second challenge selects {RO3, RO4}, resulting in sets with completely different physical properties. Even when sets share a common RO (e.g., {RO1, RO2} and {RO1, RO3}), at least one RO (and thus at least one physical property) differs between the sets). Regarding claim 5, the combination of Koeberl and Guo teaches the method according to claim 4. The combination of Koeberl and Guo teaches further teaches, wherein the sets of physical properties have an order (Koeberl: [0037] discloses "Logically Reconfigurable PUF (LR-PUF)" where "by updating the state of a reconfigurable PUF, its challenge/response behavior can be dynamically changed," teaching that PUF behavior changes over time through state updates. This temporal progression suggests an ordered sequence of states/configurations. Guo: [0006] discloses multiple challenges that select different RO combinations, and these challenges can be issued in a defined sequence.) and one or several sets following a previous set in that order each comprise at least one physical property, which is identical to the previous set (Guo: Claim 3 discloses "the first plurality of ring oscillators and the second plurality of ring oscillators include at least one commonly shared ring oscillator."; par. [0037] discloses "A first grouping of ROs 316 may be associated with a PUF module 318, while a second grouping of ROs 316 may be associated with a chip age sensor module 320. Notably, one or more of the ROs 316 is associated with both the PUF module 318 and the chip age sensor module 320 (as indicated by the overlapping dashed lines of the modules 318, 320 that both encompass the same three ROs)" ). Regarding claim 9, the combination of Koeberl and Guo teaches the method according to claim 1. The combination of Koeberl and Guo further teaches wherein the indicator comprises a command or an order (Guo: par. 0006, discloses "A challenge serves as an input to the switches 106, 108 which causes each switch 106, 108 to then select a single RO from among the plurality of ROs 104; par. 0040, discloses "the processing circuit 304 generates a challenge 328 that serves as an input to the PUF and age sensor circuit 302. Specifically, the challenge 328 contains data that instructs the RO selector circuit 312 which of the two (or more) RO frequency outputs... to select as outputs."; par. [0046] discloses "the circuit 302 may receive a chip identifier or key generation challenge 522 from a processing circuit" which "may cause two PUF ROs out of the plurality of PUF ROs 502, 504, 506 to be selectively activated/enabled.") in order to select in step c) at least one physical property which is a function of the command or order (Guo: par. 00040, discloses "the challenge 328 contains data that instructs the RO selector circuit 312 which of the two (or more) RO frequency outputs 322a, 322b, 322c,... 322n to select as outputs."; par. 0046 , discloses "The challenge 522 will also cause the two switches 512, 514 to select and pass through the two different RO outputs of the plurality of outputs 524, 526, 528 that were selectively activated/enabled."), or a dependent set of physical properties. Regarding claim 11, the combination of Koeberl and Guo teaches the method according to claim 1. The combination of Koeberl and Guo further teaches wherein the at least one key comprises at least one key pair of an asymmetrical encrypting method and in step e), a hash of the data to be signed is signed with a private key of the at least one key pair or each of the private keys of generated key pairs (Koeberl: par. [0043] discloses "[p]ublic key cryptology is a mechanism in which a mathematically linked key pair, including a private signing key and a public key, can be used to secure data being sent from a sender to a receiver and to verify the authenticity of the data. A digital signature is a mechanism in which the data is proved to have originated from a particular sender.”), wherein the results of the signing and a respective public key of the key pairs are displayed as signatures in metadata of the data (Koeberl: [0025] discloses "using the manufacturer public key to verify the signature on the device certificate," teaching that signatures and public keys are associated together for verification purposes). Regarding claim 14, claim 14 is directed to a computer program product comprising a non-transitory computer-readable medium (Koeberl: par. 0079) containing executable instructions, which, when executed by a processor of a processing unit (Koeberl: par. 0079), cause the processor to carry out the method in claim 1; claim 14 is similar in scope to claim 1, and is therefore rejected under similar rationale. Regarding claim 15, claim 15 is directed to a device (Koeberl: pars. 0012, 0034, 0035, 0042, hardware device) for signing and/or encrypting data with a cryptographic key, wherein the device is configured for carrying out the method in claim 1; claim 15 is similar in scope to claim 1, and is therefore rejected under similar rationale. Claims 6 and 8 are rejected under 35 U.S.C. 103 as being unpatentable over Koeberl, Patrick (“Koeberl,” WO 2014/105310) in view of Guo et al. (“Guo,” US 2014/0225639), further in view of Roth et al. (“Roth,” US 10,467,422). Regarding claim 6, the combination of Koeberl and Guo teaches the method according to claim 1. Koeberl and Guo do not explicitly disclose wherein a state or a time indication, comprising a point in time, is monitored or detected, wherein in the event that a stored or storable criterion which is comparable with the time indication or the state remains unmet, an indicator for detecting is specified, which remains constant and which is selected with the same set when repeating the steps a) to e), and wherein in the event that the stored or storable criterion is met, an indicator for detecting is specified, which is changed compared to the constant indicator and with which a set which differs from the previously selected set is selected in step c). However, in an analogous art, Roth discloses wherein a state or a time indication, comprising a point in time, is monitored or detected (Roth: Col. 6, lines 33-34, "a cryptography service or other system utilizing keys may track operations performed with keys"; Col. 6, lines 58-59, teaches that “the service may allocate operations to the security modules and maintain its own counter".), wherein in the event that a stored or storable criterion which is comparable with the time indication or the state remains unmet, an indicator for detecting is specified, which remains constant and which is selected with the same set when repeating the steps a) to e) (Roth: Col. lines , Col. 6, lines 35-36, "When a key identified by a key identifier (KeyID) is used in a threshold number of operations"; Col. 6, lines 36-39 , the key "may be retired... and replaced with a new key to be identified by the KeyID" only after the threshold is met), and wherein in the event that the stored or storable criterion is met, an indicator for detecting is specified, which is changed compared to the constant indicator and with which a set which differs from the previously selected set is selected in step c) (Roth: Col. 6, lines 36-39, the key changes: "the key may be retired (e.g., unusable for future encryption operations, but usable for future decryption operations) and replaced with a new key"; Col. 7, lines 21-24, "the service may cause security modules that redundantly store the key to retire the key and replace the key with a new key, where the new key may be generated or otherwise obtained"). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Roth with the method and system of Koeberl and Guo to include wherein a state or a time indication, comprising a point in time, is monitored or detected, wherein in the event that a stored or storable criterion which is comparable with the time indication or the state remains unmet, an indicator for detecting is specified, which remains constant and which is selected with the same set when repeating the steps a) to e), and wherein in the event that the stored or storable criterion is met, an indicator for detecting is specified, which is changed compared to the constant indicator and with which a set which differs from the previously selected set is selected in step c). One would have been motivated to One would have been motivated to make this combination because Roth teaches that automatic key rotation based on usage thresholds "prevent[s] the keys from being used enough time to enable successful cryptographic attacks that can reveal the keys" (Roth: Col. 6, lines 29-31). Applying this automatic rotation mechanism to PUF-derived keys would enhance security by limiting the exposure of any single key set, which is a well-known security practice in cryptographic key management. Regarding claim 8, the combination Koeberl, Guo, and Roth teaches the method according to claim 6. The combination Koeberl, Guo, and Roth further teaches wherein the indicator and/or the criterion changes in response to each run through of the steps a) to e) (Roth: Col. 6, limes 33-34, "a cryptography service or other system utilizing keys may track operations performed with keys"; Col. 6, lines 58-59, "the service may allocate operations to the security modules and maintain its own counter"; Col. 6, lines 35-36. "When a key identified by a key identifier (KeyID) is used in a threshold number of operations"; Fig. 26, Step 2602: "Receive Request to perform Cryptographic Operation Using Key Identified by KeyID"; Step 2604: "Perform Requested Operation Using Active Key identified by KeyID"; Step 2606: "Update Key Use Counter for Active Key Identified by KeyID"; Step 2608: "Counter Exceeds Threshold?" If No, loop back for next operation; Col. 41, lines 55 to Col. 42, lines 25). Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Koeberl, Patrick (“Koeberl,” WO 2014/105310) in view of Guo et al. (“Guo,” US 2014/0225639), and Roth et al. (“Roth,” US 10,467,422), further in view of Oberheide et al. (“Oberheide,” US 2017/0034141). Regarding claim 7, the combination of Koeberl, Guo, and Roth teaches the method according to claim 6. Koeberl, Guo, and Roth do not explicitly teach, wherein several criteria are stored and after meeting one of the several criteria by the state or the time indication, a set is in each case selected, which differs from one of the sets or all sets which were selected prior to meeting the respective criterion. However, in an analogous art, Oberheide discloses wherein several criteria are stored (Oberheide: claim 6, "initiating key rotation comprises initiating key rotation without receiving an external key rotation request"; Claim 6: Oberheide further teaches "initiating key rotation in response to expiration of a time threshold") and after meeting one of the several criteria by the state or the time indication, a set is in each case selected (Oberheide: claim 6, "initiating key rotation in response to expiration of a time threshold"; Oberheide teaches claim 7, "generating, at the authenticating device, a second asymmetric key set" and "configuring the multi-factor authentication platform and the authenticating device to enable authentication that uses the second asymmetric key set".), which differs from one of the sets or all sets which were selected prior to meeting the respective criterion (Oberheide: claim 7: "configuring the multi-factor authentication platform and the authenticating device to disable authentication that uses the first asymmetric key set" and Claim 7: simultaneously enabling "the second asymmetric key set".) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Oberheide with the method and system of Koeberl, Guo, and Roth to include wherein several criteria are stored and after meeting one of the several criteria by the state or the time indication, a set is in each case selected, which differs from one of the sets or all sets which were selected prior to meeting the respective criterion. One would have been motivated to ensure ensures rotation occurs based on whichever condition is reached first, providing comprehensive key lifecycle management (Roth: Col. 6, lines 29-31; Oberheide: Claims 6-7) Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Koeberl, Patrick (“Koeberl,” WO 2014/105310) in view of Guo et al. (“Guo,” US 2014/0225639), and further in view of Cambou (“Cambou,” US 10,320,573) Regarding claim 10, the combination of Koeberl and Guo teaches the method according to claim 1. Koeberl and Guo do not explicitly disclose wherein the indicator comprises a password or is generated as a function of a password, and one of several sets is selected as a function of the password or at least one physical property is predefined and/or selected as a function of the password. However, in an analogous art, Cambou discloses wherein the indicator comprises a password or is generated as a function of a password (Cambou: Col. 2, lines 19-22, discloses "An input to a hash function may be generated using the user identification and the random number... The hash function may generate a hash digest based on the input to the hash function, wherein the hash digest identifies the particular location within the array of PUFs"; Cambou: Col. 8, 34-39, "The hash function 510 preferably generates fixed size data streams... The hash function 510 is preferably 'image resistant', which means that any small change in the input to the hash function 510 creates a new hash digest that is totally different than the original digest.") and one of several sets is selected as a function of the password or at least one physical property is predefined and/or selected as a function of the password (Cambou: Col. 1, lines 46-49, The hash function may generate a hash digest based on the input to the has function, wherein the hash digest identifies a location (a particular cell or group of cells) in the array of PUFs; Col. 2, lines 19-22, discloses ".. The hash function may generate a hash digest based on the input to the hash function, wherein the hash digest identifies the particular location within the array of PUFs"; Col. 2, lines 25-27, discloses "A PUF controller may generate a challenge from the PUF at the selected location using the instruction."; Col. 8, lines 43-49, lines discloses The hash digest can directly point to an address {X, Y, θ} in the memory array for the PUF controller... it is shown how the memory array can have respective locations {X, Y, θ} that are randomly spread for the users A, B, C, . . . , N.",). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Cambou with the method and system of Koeberl and Guo to include wherein the indicator comprises a password or is generated as a function of a password, and one of several sets is selected as a function of the password or at least one physical property is predefined and/or selected as a function of the password. One would have been motivated to provide two-factor authentication - Combining PUF-based hardware authentication (something you have) with password-based authentication (something you know) enhances security through multi-factor authentication (Cambou: Col. 11, lines 55-58), enable database-free authentication - Using a hash of password to select PUF locations eliminates the need to store passwords in a central database, improving security against database hacking attacks (Cambou: Abstract; Col. 2, lines 25-27) Claim 12 are rejected under 35 U.S.C. 103 as being unpatentable over Koeberl, Patrick (“Koeberl,” WO 2014/105310) in view of Guo et al. (“Guo,” US 2014/0225639), further in view of Pitsos (“Pitsos,” US 7,051,204). Regarding claim 12, the combination of Koeberl and Guo teaches the method according to claim 11. The combination of Koeberl and Guo further teaches wherein the at least one private key of the further key pair is a private key of a key pair which can be generated identically from a current set and a set which differs from the current set (Guo: Claim 3 discloses "the first plurality of ring oscillators and the second plurality of ring oscillators include at least one commonly shared ring oscillator."; par. 0012, par. 0037, "A first grouping of ROs 316 may be associated with a PUF module 318, while a second grouping of ROs 316 may be associated with a chip age sensor module 320. Notably, one or more of the ROs 316 is associated with both the PUF module 318 and the chip age sensor module 320 (as indicated by the overlapping dashed lines of the modules 318, 320 that both encompass the same three ROs)."; par. 0046, In one mode of operation, the circuit 302 may utilize its PUF capabilities to generate a key or identifier … the circuit 302 may receive a chip identifier or key generation challenge 522 … challenge "may cause two PUF ROs out of the plurality of PUF ROs 502, 504, 506 to be selectively activated/enabled" ….This process continues “until an identifier or key of sufficient length ( e.g., bit string) is generated.”). Koeberl and Guo do not explicitly disclose wherein at least one or all of the public keys of a key pair in the metadata is additionally signed with at least one private key of a further key pair and is stored in the metadata after the signing. However, in an analogous art, Pitsos discloses wherein at least one or all of the public keys of a key pair in the metadata is additionally signed with at least one private key of a further key pair and is stored in the metadata after the signing (Pitsos: Col. 1, lines 23-26, discloses "there are various sorts of certification authorities that sign public keys with their private key. With that signature they proclaim authenticity of some information in the key, like the name and address."), Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Pitsos with the method and system of Koeberl and Guo to include wherein at least one or all of the public keys of a key pair in the metadata is additionally signed with at least one private key of a further key pair and is stored in the metadata after the signing. One would have been motivated to apply standard PKI certificate signing practices to PUF-generated keys to establish a chain of trust and enable third-party verification of key authenticity without requiring direct access to the PUF device (Pitsos: Col. 1, lines 23-26). Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Koeberl, Patrick (“Koeberl,” WO 2014/105310) in view of Guo et al. (“Guo,” US 2014/0225639), and Roth et al. (“Roth,” US 10,467,422), further in view of Denny (“Denny,” 4,817,092). Regarding claim 13, the combination of Koeberl and Guo teaches the method according to claim 1. The combination of Koeberl and Guo further disclose explicitly disclose wherein in step c) a plurality of physical properties are selected and in step d) a plurality of keys are generated from the plurality of physical properties (Koerberl: par. 0045, teaches generating a plurality of keys, specifically "in the range of 500 to 5000 keys" [0035] or "n=512, n=1024, or n=2048"; Guo: par. 0006, "a plurality of ring oscillators (ROs) may be concurrently enabled" and "a challenge serves as an input to the switches which causes each switch to then select a single RO from among the plurality of ROs"; par., 0006, “selected ROs each have a slightly different resonating frequency associated with them due to slight manufacturing variations" and "the PUF output response is generated by a pair-wise comparison of these selected ring oscillators' frequencies"). Koeber and Guo do not explicitly disclose wherein a state represents a monitoring of validity and invalidity of the plurality of keys. However, in an analogous art, Roth wherein a state represents a monitoring of validity and invalidity of the plurality of keys (Roth: Col. 6, lines 33-34, "a cryptography service or other system utilizing keys may track operations performed with keys"; Col. 6, lines 62-63, "the service may check whether the key is still usable or whether the key should be retired"; Col. 6, lines 35- 39, "when a key... is used in a threshold number of operations, the key may be retired (e.g., unusable for future encryption operations, but usable for future decryption operations) and replaced with a new key".). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Roth with the method and system of Koeberl and Guo to include wherein a state represents a monitoring of validity and invalidity of the plurality of keys. One would have been motivated to One would have been motivated to make this combination because Roth teaches that automatic key rotation based on usage thresholds "prevent[s] the keys from being used enough time to enable successful cryptographic attacks that can reveal the keys" (Roth: Col. 6, lines 29-31). Applying this automatic rotation mechanism to PUF-derived keys would enhance security by limiting the exposure of any single key set, which is a well-known security practice in cryptographic key management. Koeber, Guo, and Roth do not explicitly disclose “wherein a criterion is met when a predefined percentage of the plurality of keys is recognized as being invalid and the criterion otherwise remains unmet.” However, in an analogous art, Denny discloses using a percentage-based threshold to determine when corrective action should be triggered: "the percentage and physical number of available resources that rely on the field replaceable unit are checked to determine if they have exceeded their system thresholds. If the threshold has not been exceeded, the replaceable unit is taken out of operation." (Denny: Col. 3, lines 14-18). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Denny with the method and system of Koeberl, Guo, and Roth to include wherein a criterion is met when a predefined percentage of the plurality of keys is recognized as being invalid and the criterion otherwise remains unmet. One would have been motivated to provide "a user selectable threshold of system resource that is allowable for each resource in the system" and allow the user to "dynamically change the selectable threshold of system resource as the needs of the system change" (Col. 2, lines 63-65), Denny further teaches that using "the percentage of a particular resource that is available for use" enables intelligent decisions about when to take corrective action (Col. 3, lines 1-3). One of ordinary skill in the art would recognize that these same advantages - configurable thresholds and percentage-based resource monitoring - apply directly to key management systems. Additionally, to the extent that the claim recites a specific percentage value, determining the optimal percentage threshold is a matter of routine optimization (MPEP 2144.05(II)(B). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CANH LE whose telephone number is (571)270-1380. The examiner can normally be reached on Monday to Friday 6:00AM to 3:30PM other Friday off. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham, can be reached at telephone number 571-270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated- interview-request-air-form. /Canh Le/ Examiner, Art Unit 2439 July 1st, 2026 /LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Sep 24, 2024
Application Filed
Jan 22, 2026
Non-Final Rejection mailed — §103
Apr 16, 2026
Response Filed
Jul 07, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12683779
CALCULATION SYSTEM, CALCULATION METHOD, AND INFORMATION STORAGE MEDIUM
3y 2m to grant Granted Jul 14, 2026
Patent 12683971
MONITORING APPARATUS AND CONTROL METHOD THEREOF
2y 8m to grant Granted Jul 14, 2026
Patent 12626227
DYNAMIC MEETING SPACE CONFIGURATION BASED ON CONTENT
3y 1m to grant Granted May 12, 2026
Patent 12627651
SECURE PASSWORD LESS CRITICAL COMPUTING INFRASTRUCTURE ACCESS COMMUNICATION NETWORK PROTOCOL
2y 2m to grant Granted May 12, 2026
Patent 12621301
SCALABLE ARCHITECTURE OF SERVERS PROVIDING ACCESS TO DATA CONTENT
5y 4m to grant Granted May 05, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
73%
Grant Probability
99%
With Interview (+72.4%)
3y 9m (~1y 10m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 423 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month