Prosecution Insights
Last updated: October 04, 2026
Application No. 18/934,695

SERVER DEVICE FOR PROVIDING HOMOMORPHIC ENCRYPTION AI MODEL AND METHOD THEREOF

Final Rejection §103
Filed
Nov 01, 2024
Priority
Nov 02, 2023 — RE 10-2023-0150206 +1 more
Examiner
LEMMA, SAMSON B
Art Unit
2498
Tech Center
2400 — Computer Networks
Assignee
Crypto Lab Inc.
OA Round
2 (Final)
88%
Grant Probability
Favorable
3-4
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
809 granted / 917 resolved
+30.2% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
25 currently pending
Career history
936
Total Applications
across all art units

Statute-Specific Performance

§101
20.5%
-19.5% vs TC avg
§103
40.8%
+0.8% vs TC avg
§102
19.4%
-20.6% vs TC avg
§112
12.1%
-27.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 917 resolved cases

Office Action

§103
DETAILED ACTION 1. This office action is in response to an amendment filed on 07/16/2026. Claims 1-8 are pending. Claims 1 and 5 are independent. Each independent claim is amended. Notice of Pre-AIA or AIA Status 2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments 3. Applicant’s arguments filed on July 16, 2026, with regarding to: a. the claim objections made to claim 3 and 7 is persuasive. The amendment made to claims 3 and 7 overcomes this objection. Thus, the objection is withdrawn. b. the 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph rejection made to claims 1 and 5 is also persuasive. The amendment made to claims 1 and 5 overcomes the 35 U.S.C. 112(b) rejection. Thus, this rejection is also withdrawn. However, c. the 35 U.S.C. 103 rejection directed to the independent claims 1 and 5 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. 4. Thus, in response to the 35 U.S.C. 103 rejections set forth in the previous office action, applicant amended at least each independent claim 1 and 5, presumably to overcome the 35 U.S.C. 103 rejections set forth in the previous office action. Since the newly amended claims changed the scope and necessitated new grounds of rejection, applicant’s arguments are moot. The analysis of the claims under consideration, as amended, follows in the corresponding section below. Claim Rejections - 35 USC § 103 5. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or non-obviousness. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 6. Independent claims 1 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over Sarpatwar et al (Sarpatwar), (US Publication No. 2021/0397988 A1, Pub. Date: Dec. 23, 2021) in view of Desai et al (Desai)(US Publication No. 2020/0311573 A1, Pub. Date: Oct. 1, 2020) and in further view of Ran Gilad-Bachrach et al (Gilad-Bachrach) (US Publication No. 20160350648, A1, Pub. Date: Dec. 1, 2016 ) The following is referring to independent claims 1 and 5: As per independent claim 1, Sarpatwar discloses a server device [Figure 1, ref. 104, “Server” and figure 2, ref. data processing system 200, para. 0023, With reference now to FIG. 2, a block diagram of a data processing system is shown in which illustrative embodiments may be implemented. Data processing system 200 is an example of a computer, such as server 104] comprising: a communicator [Para. 0023-0024, Figure 2, ref. 210, “Communications unit 210” and a communication fabric 202]; a memory [Figure 2, ref. 206, “memory 206”]; and a processor [Figure 2, ref. 204, “Processor unit 204”, Para. 0023-0024, “data processing system 200 includes communications fabric 202, which provides communications between processor unit 204, memory 206, persistent storage 208, communications unit 210, input/output (I/O) unit 212, and display 214”] wherein the processor is configured to receive a reference artificial intelligence (AI) model [Para. 0006, a method to create a full homomorphic encryption (FHE)-compatible machine learning model begins by obtaining a first (teacher) machine learning model, the first machine learning model having been pre-trained using first training data. The “teacher machine learning model” that is obtained or received corresponds to the limitation, “a reference artificial intelligence (AI) model” and see also claim 8, ‘an apparatus comprising processor, … obtain a first machine learning model, the first machine learning model having been pre-trained using first training data;] and , acquire a plaintext AI model to be converted into a homomorphic encryption [Abstract, “create a full homomorphic encryption (FHE)-friendly machine learning model FHE-friendly model”, The full homomorphic encryption (FHE)-friendly machine learning model corresponds to the claim limitation, “a plaintext AI model friendly to homomorphic encryption”] by performing a knowledge distillation task based on the reference AI model [Abstract, knowledge distillation framework wherein the FHE-friendly (student) ML model closely mimics the predictions of a more complex (teacher) model, wherein the teacher model is one that, relative to the student model, is more complex and that is pre-trained on large datasets. In the approach herein, the distillation framework uses the more complex teacher model to facilitate training of the FHE-friendly model, but using synthetically-generated training data in lieu of the original datasets used to train the teacher.] for a lightweight AI model [Para. 0006, “wherein the teacher model is one that, relative to the student model, is more complex and that is pre-trained on large datasets” This indicates that the student model is a lightweight AI model compared to the more complex teacher model] having a reduced number of layers or parameters compared to the reference AI model [[Para. 0006, “The second machine learning model, which is depth-constrained. Para. 0099, “preferably a shallow neural network is employed as the student model architecture”; “the teacher model is one that, relative to the student model, is more complex”, meaning the student model is less complex. Note: This directly corresponds to reduced layer; lower complexity and shallow architecture and Abstract, knowledge distillation framework wherein the FHE-friendly (student) ML model closely mimics the predictions of a more complex (teacher) model, wherein the teacher model is one that, relative to the student model, is more complex and that is pre-trained on large datasets. In the approach herein, the distillation framework uses the more complex teacher model to facilitate training of the FHE-friendly model, but using synthetically-generated training data in lieu of the original datasets used to train the teacher and para. 2 describes the student as having “less model complexity” and at least para. 0006, teaches shallow, depth constrained student and comparatively complex teacher ], and Sarpatwar doesn’t explicitly disclose the following underlined claim limitation: ”receive a reference artificial intelligence (AI) model of an external device through the communicator and store the received reference AI model in the memory” However, Desai explicitly discloses the above underlined claim limitation: “receive a reference artificial intelligence (AI) model of an external device through the communicator [Par. 0030 teaches how a cloud resource predication platform/server receives a model or a training model from another device, “rather than training a model, the cloud resource prediction platform may receive a model from another device (e.g., a server device). For example, a server device may generate a model based on having trained the model in a manner similar to that described above and may provide the model to the cloud resource prediction platform”] and store the received reference AI model in the memory,[Para. 0030, also teaches loading the learning model/AI model into the platform that implies that the received model is retained or stored by the platform, “rather than training a model, the cloud resource prediction platform may receive a model from another device (e.g., a server device). For example, a server device may generate a model based on having trained the model in a manner similar to that described above and may provide the model to the cloud resource prediction platform (e.g., may pre-load the cloud resource prediction platform with the model”] Sarpatwar and Desai are analogous and are in the same field of endeavor as they both are directed to utilizing a machine learning or AI model It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Sarpatwar by implementing a mechanism such as “receive a reference artificial intelligence (AI) model of an external device through the communicator and store the received reference AI model in the memory” as per teachings of Desai for the purpose of training and generating a trained machine learning model, and responding to the customer’s request and performing one or more actions based on the projection. [Para. 0003, Desai, the method may include training a machine learning model…to generate a trained machine learning model, and receiving a request for new resource usage by a customer associated with the cloud computing environment. The method may include processing the request for the new resource usage, with the trained machine learning model, to generate …and performing one or more actions based ..] Furthermore, Sarpatwar discloses how a more complex teacher, reference/plaintext AI model is generally converted into a full homomorphic encryption (FHE)-friendly student machine learning model [Abstract, “to create a full homomorphic encryption (FHE)-friendly machine learning model. The approach herein leverages a knowledge distillation framework wherein the FHE-friendly (student) ML model closely mimics the predictions of a more complex (teacher) model, wherein the teacher model is one that, relative to the student model, is more complex and that is pre-trained on large datasets. In the approach herein, the distillation framework uses the more complex teacher model to facilitate training of the FHE-friendly model”] The combination of Sarpatwar and Desai doesn’t explicitly disclose the following underlined claim limitation: “convert the plaintext Al model into a homomorphic encryption Al model by “approximating a nonlinear operation included in the plaintext Al model into a polynomial based on an input distribution of a function corresponding to the nonlinear operation or an approximation error caused by operating the polynomial” However, Gilad-Bachrach discloses the above underlined claim limitation: “convert the plaintext Al model into a homomorphic encryption Al model [Para. 0043, “facilitate computation under homomorphic encryption” and para. 0041-0045 teaches starting with a conventionally trained neural network and replacing its activation functions with polynomial approximations so that resulting network can operate on homomorphically encrypted data. This teaches modifying a conventional/plaintext model into HE-compatible model] by “approximating a nonlinear operation included in the plaintext Al model into a polynomial [Para. 0033, “polynomials to approximate the non-polynomial activation functions” Sigmoid and rectified linear activation functions are nonlinear operations with the neural network. Replacing those functions with polynomial expression corresponds and meets the limitation, approximating a nonlinear model with a polynomial] based on an input distribution of a function corresponding to the nonlinear operation [Para. 0037, “The input of sigmoid function can spread quite a large range”, para. 36-38 compare approximation intervals and teach turning the polynomial-range parameter according to the range of inputs received by the sigmoid function. This application itself treats “input distribution” as an input range] or an approximation error caused by operating the polynomial [Para. 0039, “the best fitting polynomial” Para. 0039 generates input/function-output pairs and performs polynomial regression to select the best fit. Selecting the best-fitting regression polynomial evaluates and minimizes the difference between the nonlinear function and the polynomial. i.e, the polynomial approximation error.] Sarpatwar, Desai and Gilad-Bachrach are analogous and are in the same field of endeavor as they all are directed to utilizing a machine learning or AI model. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify the FHE-friendly, knowledge-distilled model of Sarpatwar and Desai by applying a mechanism such as ““convert the plaintext Al model into a homomorphic encryption Al model by “approximating a nonlinear operation included in the plaintext Al model into a polynomial based on an input distribution of a function corresponding to the nonlinear operation or an approximation error caused by operating the polynomial” as per teachings of Gilad-Bachrach in order to implement nonlinear neural network functions using operations supported by homomorphic encryption and reduce approximation error. [See at least Gilad-Bachrach, abstract and para. 0039, “The approximations of neural network functions can approximate activation functions, where the activation functions are approximated using polynomial expressions”…” To solve this, the second approximation method: polynomial regression can be used. To approximate a function f(x), (x, ƒ(x)) pairs are generated from this function, and polynomials can be utilized to do regression over these points to obtain the best fitting polynomial] As per independent claim 5, independent claim 5 is method version of the device claim 1 and has a similar scope as that of the above independent claim 1. Thus, claim 5 is rejected for the same reason/rationale as that of the above independent claim 1. 7. Claims 2-3 and 6-7 are rejected under 35 U.S.C. 103 as being unpatentable over Sarpatwar et al (Sarpatwar), (US Publication No. 2021/0397988 A1, Pub. Date: Dec. 23, 2021) in view of Desai et al (Desai)(US Publication No. 2020/0311573 A1, Pub. Date: Oct. 1, 2020) and in further view of Ran Gilad-Bachrach et al (Gilad-Bachrach) (US Publication No. 20160350648, A1, Pub. Date: Dec. 1, 2016 )and further in view of Geoffrey Hinton et al (Hinton) (NPL document titled, “Distilling the Knowledge in a Neural Network” , March 9, 2015) The following is referring to dependent claims 2-3 and 6-7: As per dependent claim 2, the combination of Sarpatwar, Desai and Gilad-Bachrach discloses the method or the device as applied to claim 1 above. Furthermore, Sarpatwar discloses the method/device, wherein the processor is configured to input the same learning data to the reference AI model and the lightweight AI model [Figure 5 and para. 0079-0080, “The transfer data set 507 is generated, preferably randomly, using a given input data “and “the student model 504 are learned using, as “synthetic” training data, the transfer data set 507, and predictions of the teacher model 500 on that transfer data set. As shown on figure 5 and para. 0079-0080, the transfer data generated from input distribution. The same transfer data is provided to the teacher model to produce predictions and the same transfer data is provided to the student model during training. This means the same learning data is input during the training]. comparing para. 0080, ” the student model strives to minimize the loss between the predictions of the teacher and student models” This teaches comparison between teacher and student outputs and loss is defined between them] The combination of Sarpatwar, Desai and Gilad-Bachrach doesn’t disclose the following underlined claim limitation, “acquire a distillation loss by comparing at least one of embedding vectors, logits, or class values, respectively output from the reference AI model and the lightweight AI model, and acquire the plaintext AI model by a training process, feeding back the distillation loss to the lightweight AI model multiple times. However, Hinton discloses the above underlined claim limitation: comparing at least one of embedding vectors, logits, or class values, respectively output from the reference AI model and the lightweight AI model, [Page 2, “using the logits (the inputs to the final softmax) …as the targets and ….minimize the squared difference between the logits produced by the cumbersome model and the logits produced by the small model.” And page 2, “use the class probabilities …as “soft targets” for training the small model” This teaches comparing the teacher logits vs student logits] and acquire the plaintext AI model by a training process, feeding back the distillation loss to the lightweight AI model multiple times.[Page 3, “knowledge is transferred to the distilled model by training it/distilled model ….using a soft target distribution”, “The first objective function is the cross entropy with the soft targets”, page 3, 2.1, “Each case in the transfer set contributes a cross-entropy gradient…with respect to each logit…of the distilled model. Note: Cross-entropy gradient with respect to logits is explicit loss feedback used to update the student during training. Training by gradient is iterative across many cases/steps (i.e. the loss is fed back “multiple times” On page 4, “The model is trained with a distributed stochastic gradient descent” This is iterative training or multiple iterations] Furthermore, Hinton discloses “to input the same learning data to the reference AI model and the lightweight AI model” [Abstract, “A very simple way to improve the performance of almost any machine learning algorithm is to train many different models on the same data and then to average their predictions”] Sarpatwar, Desai, Gilad-Bachrach and Hinton are analogous and are in the same field of endeavor as they all are directed to utilizing a machine learning or AI model. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Sarpatwar, Desai and Gilad-Bachrach by adding a mechanism such as “comparing at least one of embedding vectors, logits, or class values, respectively output from the reference AI model and the lightweight AI model, and acquire the plaintext AI model by a training process, feeding back the distillation loss to the lightweight AI model multiple times” as per teachings of Hinton in order to improve the performance of almost any machine learning algorithm and in order to train the model rapidly and in parallel.. [See at least Hinton, abstract, “improve the performance of almost any machine learning algorithm and these specialist models can be trained rapidly and in parallel”] As per dependent claim 6, dependent claim 6 is method version of the device claim 2 and has a similar scope as that of the above dependent claim 2. Thus, claim 6 is rejected for the same reason/rationale as that of the above dependent claim 2. As per dependent claim 3, the combination of Sarpatwar, Desai and Gilad-Bachrach disclose the method or the device as applied to claim 2 above. Furthermore, Sarpatwar discloses the method/device, wherein the reference AI model is the plaintext model that is pre-trained [para. 0006. “the teacher model is one that, relative to the student model, is more complex and that is pre-trained on large datasets”, “by obtaining a first (teacher) machine learning model, the first machine learning model having been pre-trained using first training data”] to perform a task predetermined by the external device, and wherein the lightweight AI model is the plaintext model which includes one of a model having a reduced number of layers or parameters compared to the reference AI model [Para. 0006, “The second machine learning model, which is depth-constrained. Para. 0099, “preferably a shallow neural network is employed as the student model architecture”; “the teacher model is one that, relative to the student model, is more complex”, meaning the student model is less complex. Note: This directly corresponds to reduced layer; lower complexity and shallow architecture]and easily performing an operation in a homomorphic encryption state [Abstract, “ product to create a full homomorphic encryption (FHE)-friendly machine learning model. The approach herein leverages a knowledge distillation framework wherein the FHE-friendly (student) ML model closely mimics the predictions of a more complex (teacher) model, wherein the teacher model is one that, relative to the student model, is more complex and that is pre-trained on large datasetsPara 0082, “Given a multiplicative depth budget, compute the set of configurations of neural networks, along with polynomial activation functions that satisfy the depth budget” and para. 0099, “polynomial approximation of activation functions] . As per dependent claim 7, dependent claim 7 is method version of the device claim 3 and has a similar scope as that of the above dependent claim 3. Thus, claim 7 is rejected for the same reason/rationale as that of the above dependent claim 3. Allowable Subject Matter 8. Claims 4 and 8 are objected to as being dependent upon rejected base claims 3 and 7 respectively, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. 9 The following is an examiner’s statements of reasons for allowance: The above prior arts of record including the rest of the cited prior arts neither anticipates nor renders obvious the claimed subject matter of the instant application that is taken as a whole including the following specific claim limitation recited in dependent claim 4 and a similar claim recited in dependent claim 8: “wherein the processor is configured to convert the plaintext AI model into the homomorphic encryption AI model by performing: a task of defining at least one parameter used by the homomorphic encryption AI model, a packing task of merging the data used by the plaintext AI model into an encrypted form, a task of determining the type, order, number of times, and structure of an operation performed by the homomorphic encryption AI model, a task of securing a storage for storing at least one key used for the homomorphic encryption and ciphertext, a polynomial approximation task of approximating a nonlinear operation into a polynomial, a task of adjusting a trade-off relationship between the degree and precision of each polynomial used in the polynomial approximation task, a task of adjusting an input distribution of a function used in the polynomial approximation task, a task of adjusting an approximation error in a process of operating the polynomial, and a task of adjusting a homomorphic encryption operation to be performed by a graphic processing unit (GPU)” For this reason, the specific claim limitations recited in the dependent claims 4 and 8 taken as whole would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion 10. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. A. US Patent No. 11757618 B2 Cheon et al discloses a method of operating a homomorphic ciphertext is disclosed. The method of operating a homomorphic ciphertext includes receiving a non-polynomial operation command with respect to a homomorphic ciphertext, computing an approximate polynomial function corresponding to the non-polynomial operation, performing an operation of the homomorphic ciphertext using the computed polynomial function, and outputting the operated homomorphic ciphertext, wherein the approximate polynomial function is a second approximate polynomial function which is obtained by extending a first approximate polynomial function to have a second range wider than the first range having a preset accuracy with the non-polynomial operation within a first range. B. US Patent No. 12260313B2 B2 Tiku et al discloses artificial neural network bypass. C. US Publication No. 20200242466 A1 to Mohassel et al discloses privacy preserving machine learning where a neural network trained on plaintext data can make predication on encrypted data using fully homomorphic encryption with the model held by one party and evaluated on another party’s private inputs. D. US Publication No. 20210081203 A1 to Vald et al discloses homomorphic encryption (FHE) ciphertext processing using approximate polynomials (e.g., for modulus reduction/bootstrapping), including calculating error and adjusting polynomial degree/samples to improve the approximation used during homomorphic encryption (HE) evaluation. E. See other cited prior arts. 11. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMSON B LEMMA whose telephone number is 571-272-3806. The examiner can normally be reached on M-F 8am-10pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor Yin-Chen Shaw can be reached on 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /SAMSON B LEMMA/ Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Nov 01, 2024
Application Filed
Feb 21, 2026
Non-Final Rejection (signed) — §103
Apr 17, 2026
Non-Final Rejection mailed — §103
Jul 16, 2026
Response Filed
Sep 22, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748896
PHYSICAL UNCLONABLE FUNCTION DEVICE AND METHOD
2y 4m to grant Granted Sep 29, 2026
Patent 12732520
GENERATION DEVICE, GENERATION METHOD, AND GENERATION PROGRAM
2y 0m to grant Granted Sep 08, 2026
Patent 12719874
SECURITY MANAGEMENT OF TRUSTED NETWORK FUNCTIONS
1y 8m to grant Granted Aug 25, 2026
Patent 12712643
SYSTEM AND METHOD FOR NETWORK DISTRIBUTION OF QUANTUM ENTANGLEMENT
1y 11m to grant Granted Aug 18, 2026
Patent 12694098
SYSTEMS AND METHODS FOR MANAGING STATE
1y 8m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+11.2%)
2y 9m (~10m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 917 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month