Prosecution Insights
Last updated: October 01, 2026
Application No. 18/948,291

Asynchronous Cryptographic Key Caching and Generation

Final Rejection §103
Filed
Nov 14, 2024
Examiner
WRIGHT, BRYAN F
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
Google LLC
OA Round
2 (Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
641 granted / 820 resolved
+20.2% vs TC avg
Strong +24% interview lift
Without
With
+24.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
20 currently pending
Career history
847
Total Applications
across all art units

Statute-Specific Performance

§101
13.4%
-26.6% vs TC avg
§103
56.5%
+16.5% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
9.0%
-31.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 820 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. FINAL ACTION This action is in response to applicant’s claim amendment(s) submitted on 06/05/2026. Claims 1-20 are pending. Response to Arguments Examiner’s Remarks – Specification Objection (Title) The examiner withdraws the objection in view of applicant’s title amendment. Examiner’s Remarks - 35 U.S.C. §103 Applicant argues: “The PTO cites BanerJee in view of Kang as disclosing re-using the ephemeral key set. However, Banerjee teaches away from re-using the ephemeral key set.”. The examiner respectfully disagrees. First, the examiner notes that applicant’s current independent claim 1 claim structure does not quantify the value of applicant’s “re-use period” (i.e., 1 time, 2 time, … etc) nor qualify (i.e., how explicitly the “re-used period” is implemented). As such, there are a number of reasonable interpretations/implementations that the current claim 1 claim structure affords the examiner. For example, it is certainly reasonable for the examiner, based on the current independent claim 1 claim structure, to interpret the re-use period to be 1 or 2 or 3 or 4 times. Again, the current claim 1 claim structure does not limit the value nor implementation of said “re-use period”. The examiner draws attention to BanerJee teachings in par. 0056 where the following is disclosed: “It is noted that unlike the UE, the home network does not need to perform a fresh ephemeral key pair generation for each decryption.”. The examiner notes that Banerjee tells us in this instance that the ephemeral key pair is not freshly generated for “each” decryption. The examiner respectfully notes that ordinary meaning of the term “each” affords use to reasonably conclude that at the very minimum that it will be at least several or more decryption operations taking place in the communication process. As such, the examiner can reasonably conclude that the ephemeral keys pair will be used multiple times (i.e., re-used) given the fact that BanerJee explicitly tells us that the ephemeral key pair will not be freshly generated for each decryption. Moreover, Banerjee tells us that ephemeral key set is a base for the encryption key in figure 1B, the decryption key in par. 0056, the AEAD in fig. 4., and public and private keys respectively of the ephemeral key set are used to determine the SUPI and SUCI as noted in pars. 0096 and 0105. These noted usages are reasonable examples of the ephemeral key set being reused. BanerJee teaches in par. 0096 the following: “[0096] As illustrated in FIG. 5, at steps 1a and 2a, the network device 202 may determine a ECC ephemeral shared key based on the ECC ephemeral public key (‘A’) and a private key of the HPLMN or the SNPN. For example, at SIDF side, the received UE ephemeral public key (‘A’) and the private key of home network may be used to generate the ephemeral shared key.”. Banerjee teaches in par. 0105 the following: “[0105] In some embodiments, the terminal device may determine the SUCI by: determining an ECC ephemeral shared key based on an ECC ephemeral private key and a public key of the HPLMN or the SNPN; d”. Applicant argues: “Furthermore, Kang does not teach that an ephemeral key set is re-used.”. The examiner notes that by definition, the examiner notes that ephemeral keys are “short live”. As such the examiner notes that Kang teaches in par. 0040 the following: “impose a restriction on the number of times the pair of public and private keys is allowed to be reused,”. As such, Kang’s system can provide “short live” keys by imposing restrictions on the number of times that the keys are made available. Applicant argues: “Banerjee teaches away from re-using the ephemeral keyset. Banerjee states that "without the presence of ephemeral keys (whenever traditional keys are broken) one can re-use the PQC KEM keys." (emphasis added, Banerjee para. [0088]). Applicant's claim 1, by contrast, teaches re-using the ephemeral keyset during a key re-use period. Therefore, Banerjee's teachings of a key re-use period directly contradict and teach away from Applicant's claim 1.”. The examiner respectfully notes that applicant’s above assertion is simply not true. Again, the examiner notes that applicant’s current independent claim 1 claim structure does not quantify the value of applicant’s “re-use period” (i.e., 1 time, 2 time, … etc) nor qualify (i.e., how explicitly the “re-used period” is implemented). As such, there are a number of reasonable interpretations/implementations that the current claim 1 claim structure affords the examiner. For example, it is certainly reasonable for the examiner, based on the current independent claim 1 claim structure, to interpret the re-use period to be 1 or 2 or 3 or 4 times. Again, the current claim 1 claim structure does not limit the value nor implementation of said “re-use period”. The examiner draws attention to BanerJee teachings in par. 0056 where the following is disclosed: “It is noted that unlike the UE, the home network does not need to perform a fresh ephemeral key pair generation for each decryption.”. The examiner notes that Banerjee tells us in this instance that the ephemeral key pair is not freshly generated for “each” decryption. The examiner respectfully notes that ordinary meaning of the term “each” affords use to reasonably conclude that at the very minimum that it will be at least several or more decryption operations taking place in the communication process. As such, the examiner can reasonably conclude that the ephemeral keys pair will be used multiple times (i.e., re-used) given the fact that BanerJee explicitly tells us that the ephemeral key pair will not be freshly generated for each decryption. Moreover, Banerjee tells us that ephemeral key set is a base for the encryption key in figure 1B, the decryption key in par. 0056, the AEAD in fig. 4., and public and private keys respectively of the ephemeral key set are used to determine the SUPI and SUCI as noted in pars. 0096 and 0105. These noted usages are reasonable examples of the ephemeral key set being reused. BanerJee teaches in par. 0096 the following: “[0096] As illustrated in FIG. 5, at steps 1a and 2a, the network device 202 may determine a ECC ephemeral shared key based on the ECC ephemeral public key (‘A’) and a private key of the HPLMN or the SNPN. For example, at SIDF side, the received UE ephemeral public key (‘A’) and the private key of home network may be used to generate the ephemeral shared key.”. Banerjee teaches in par. 0105 the following: “[0105] In some embodiments, the terminal device may determine the SUCI by: determining an ECC ephemeral shared key based on an ECC ephemeral private key and a public key of the HPLMN or the SNPN; d”. Applicant argues: “Kang does not teach re-using ephemeral keys. Instead, Kang teaches that "the pair of Diffie-Hellman keys are determined as being reusable." (Kang para. [0014]). At no point does Kang discuss ephemeral keys, let alone ephemeral keys being re-usable. Thus, Kang fails to teach the limitations of Applicant's claim 1.”. The examiner respectfully notes that applicant’s above assertion is a miss-characterization of the teachings of Kang. The examiner notes that by definition, the examiner notes that ephemeral keys are “short live”. As such the examiner notes that Kang teaches in par. 0040 the following: “impose a restriction on the number of times the pair of public and private keys is allowed to be reused,”. As such, Kang’s system can provide “short live” keys by imposing restrictions on the number of times that the keys are made available. Applicant argues: “Finally, the PTO relies on Balar for the limitation "storing, by the first computing system, the current ephemeral keyset in a memory cache." (Subject Office Action, page 5). However, Balar does not cure the above-noted deficiencies of BanerJee and Kang. Specifically, Balar does not teach or suggest the re-use of an ephemeral keyset to initiate or resume multiple communication sessions, nor does Balar overcome Banerjee's explicit teaching away from such re-use. Therefore, the combination of Baneriee, Kang, and Balar fails to teach or suggest all the limitations of Applicant's Claim 1, and the rejection under 35 U.S.C. § 103 should be withdrawn.”. The examiner notes that the teachings of Balar discloses in par. 0049 the following: “using ephemeral asymmetric key pairs (e.g., RSA keys)”. The examiner respectfully notes that the teachings of Balar, per the office action, where cited to teach applicant’s claim limitation(s) of, “storing, by the first computing system, the current ephemeral keyset in a memory cache”. The examiner notes that applicant has not contested Balar’s teachings as cited in the office action. Applicant argues: “B. Independent Claim 16 … For at least the reasons discussed above with respect to claim 1, Applicant submits that claim 16 is not obvious over the materials cited in the Office Action. Applicant requests withdrawal of the rejection of claim 16 under § 103.”. The examiner notes that applicant’s independent claim 16 recites similar feature(s) to those recited in applicant’s independent claim 1. As such, the examiner notes that the examiner’s remarks noted above for applicant’s independent 1 are applicable for applicant’s independent 16. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over BANERJEE et al. (US Patent Publication No. 2025/0048113 and BANERJEE hereinafter) in view of Kang (US Patent Publication No. 2005/0058295) and further in view of Balar et al. (US Patent Publication No. 2015/0134441 and Balar hereinafter). As to claims 1 and 16, BANERJEE teaches a computer-implemented method to perform periodic generation and caching of cryptographic keys for re-use with multiple communication sessions, the method comprising: for each of a plurality of key re-use periods (i.e.., …teaches in par. 0091 the following: “re-used for a number of times depending on some upper bound level”): a current ephemeral keyset comprising an ephemeral public key and an ephemeral private key (i.e., …teaches in par. 0088 the following: “generate a key pair (ECC ephemeral public key (‘A’) and private key)”); and using, by the first computing system (i.e., …teaches in par. 0055 the following: “The UE may use the provisioned public key of the home network and a freshly generated ECC ephemeral public/private key pair according to the ECIES parameters provisioned by the home network.”), and until an expiration of the key re-use period (i.e., …teaches in par. 0091 the following: “one can re-use the PQC KEM keys for a number of times less than a predetermined threshold number (but not recommended).” …teaches in par. 0055 the following: “The UE may use the provisioned public key of the home network and a freshly generated ECC ephemeral public/private key pair according to the ECIES parameters provisioned by the home network …”). The system of BANERJEE does not expressly teach: generating, by a first computing system, and in response to an initiation of the key re-use period, the current ephemeral keyset to initiate or resume one or more secure communication sessions with one or more other computing systems. In this instance the examiner notes the teachings of prior art reference Kang. With regards to applicant’s claim limitation element of, “generating, by a first computing system, and in response to an initiation of the key re-use period”, Kang teaches par. 0046 the following: “When a request for a pair of public and private keys is received to the public/private key request receiver 11, the reused times checking unit 121 checks whether the number of times the pair of public and private keys stored in the public/private key storage unit 15 has been reused exceeds a predetermined maximum.”. With regards to applicant’s claim limitation element of, “the current ephemeral keyset to initiate or resume one or more secure communication sessions with one or more other computing systems”, teaches in par. 0047 the following: “If the pair of public and private keys, which has been used a number of times less than the predetermined maximum, has not yet been used to connect the two hosts, the public/private key reader 13 reads the pair of public and private keys.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE with the teachings of Kang by having their system comprise an enhanced key generation process. One would have been motivated to do so to provide a simple and effective means for the management of keys within a network environment, wherein the enhanced key generation process helps facilitate proper key security and makes it easier to track key distribution. The system of BANERJEE and Kang does not expressly teach: storing, by the first computing system, the current ephemeral keyset in a memory cache. In this instance the examiner notes the teachings of prior art reference Balar. With regards to applicant’s claim limitation element of, “storing, by the first computing system, the current ephemeral keyset in a memory cache”, Balar teaches in par. 0049 the following: “The unit stores (in non-persistent data storage) the challenge hash, generated agent RSA public key, and the caller MAC address.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE and Kang with the teachings of Balar by having their system comprise an enhanced key storage process. One would have been motivated to do so to provide a simple and effective means to secure key data, wherein the enhanced key storage process helps facilitate proper key management and makes it easier to provide key reusability. As to claims 2 and 17, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE teaches a computer-implemented method of claim 1, wherein each of the number of key re-use periods has a pre-defined temporal length (i.e., …teaches in par. 0108 the following: “the PQC KEM public key may re-used for a number of times less than a predetermined threshold number.”). As to claims 3 and 18, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE does not expressly teach a computer-implemented method of claim 1, wherein a length of each key re-use period is dynamically determined. In this instance the examiner notes the teachings of prior art reference Kang. Kang teaches par. 0046 the following: “the reused times checking unit 121 checks whether the number of times the pair of public and private keys stored in the public/private key storage unit 15 has been reused exceeds a predetermined maximum. The predetermined maximum may be set by a user or may be set at a default value by a system.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE with the teachings of Kang by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means for managing keys within a network environment, wherein the enhanced key management process helps facilitate proper key security and makes it easier to track key distribution. As to claims 4 and 19, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE does not expressly teach a computer-implemented method of claim 1, wherein, for each of the plurality of key re-use periods, the method further comprises: in response to expiration of the current key re-use period, deleting, by the first computing system, the current ephemeral keyset from the memory cache. In this instance the examiner notes the teachings of prior art reference Kang. With regards to applicant’s claim limitation element of, “in response to expiration of the current key re-use period”, Kang teaches par. 0046 the following: “When a request for a pair of public and private keys is received to the public/private key request receiver 11, the reused times checking unit 121 checks whether the number of times the pair of public and private keys stored in the public/private key storage unit 15 has been reused exceeds a predetermined maximum.”. With regards to applicant’s claim limitation element of, “deleting, by the first computing system, the current ephemeral keyset from the memory cache”, Kang teaches par. 0052 the following: “Therefore, the first, second, and fifth pairs of public and private keys cannot be reused any more. In order to more efficiently use the storage capacity of the public/private key storage unit 15, any of the first, second, and fifth pairs of public and private keys is deleted”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE with the teachings of Kang by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means for managing keys within a network environment, wherein the enhanced key management process helps facilitate proper key security and makes it easier to track key distribution. As to claims 5 and 20, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE teaches a computer-implemented method of claim 1, wherein using, by the first computing system, and until the expiration of the current key re-use period (i.e., …teaches in par. 0091 the following: “keys may be re-used for a number of times depending on some upper bound level. The upper bound level will be defined on how many times the KEM public key can be used”). The system of BANERJEE does not expressly teach: the current ephemeral keyset comprises re-using, by the first computing system, and until the expiration of the current key re-use period, the current ephemeral keyset to initiate or resume multiple different secure communication sessions. In this instance the examiner notes the teachings of prior art reference Kang. With regards to applicant’s claim limitation element of, “the current ephemeral keyset comprises re-using, by the first computing system, and until the expiration of the current key re-use period, the current ephemeral keyset to initiate or resume multiple different secure communication sessions”, Kang teaches par. 0047 the following: “once a pair of public and private keys is used to connect two hosts, the pair of public and private keys can only be used for connecting hosts other than the two hosts or connecting one of the two hosts to another host. If the pair of public and private keys, which has been used a number of times less than the predetermined maximum, has not yet been used to connect the two hosts, the public/private key reader 13 reads the pair of public and private keys.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE with the teachings of Kang by having their system comprise an enhanced key management process. One would have been motivated to do so to provide a simple and effective means for managing keys within a network environment, wherein the enhanced key management process helps facilitate proper key security and makes it easier to track key distribution. As to claim 6, the system of BANERJEE, Kang and Balar as applied to claim 5 teaches key re-use, specifically BANERJEE teaches a computer-implemented method of claim 5, wherein re-using, by the first computing system, and until the expiration of the current key re-use period (i.e., …teaches in par. 0091 the following: “keys may be re-used for a number of times depending on some upper bound level. The upper bound level will be defined on how many times the KEM public key can be used”). The system of BANERJEE does not expressly teach: the current ephemeral keyset to initiate or resume multiple different secure communication sessions comprises re-using, by the first computing system, and until the expiration of the current key re-use period, the current ephemeral keyset to initiate or resume multiple different secure communication sessions conducted with multiple different computing systems. In this instance the examiner notes the teachings of prior art reference Kang. With regards to applicant’s claim limitation element of, “the current ephemeral keyset to initiate or resume multiple different secure communication sessions”, Kang teaches par. 0047 the following: “once a pair of public and private keys is used to connect two hosts, the pair of public and private keys can only be used for connecting hosts other than the two hosts or connecting one of the two hosts to another host. If the pair of public and private keys, which has been used a number of times less than the predetermined maximum, has not yet been used to connect the two hosts, the public/private key reader 13 reads the pair of public and private keys.”. With regards to applicant’s claim limitation element of, “re-using, by the first computing system, and until the expiration of the current key re-use period, the current ephemeral keyset to initiate or resume multiple different secure communication sessions conducted with multiple different computing systems”, Kang teaches par. 0047 the following: “once a pair of public and private keys is used to connect two hosts, the pair of public and private keys can only be used for connecting hosts other than the two hosts or connecting one of the two hosts to another host. If the pair of public and private keys, which has been used a number of times less than the predetermined maximum, has not yet been used to connect the two hosts, the public/private key reader 13 reads the pair of public and private keys.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE with the teachings of Kang by having their system comprise an enhanced key exchange process. One would have been motivated to do so to provide a simple and effective means the management of keys with in a network environment, wherein the enhanced key exchange process helps facilitate proper key security and makes it easier to track key distribution. As to claim 7, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE expressly teaches a computer-implemented method of claim 1, wherein the one or more other computing systems are configured to generate and re-use their own ephemeral keysets over their own respective key re-use periods (i.e., …teaches in par. 0091 the following: “one can re-use the PQC KEM keys for a number of times less than a predetermined threshold number (but not recommended).” …teaches in par. 0055 the following: “The UE may use the provisioned public key of the home network and a freshly generated ECC ephemeral public/private key pair according to the ECIES parameters provisioned by the home network …”). As to claim 8, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE expressly teaches a computer-implemented method of claim 1, wherein the respective key re-use periods of the one or more other computing systems are asynchronous with the key re-use periods of the first computing system (i.e., …teaches in par. 0091 the following: “keys may be re-used for a number of times depending on some upper bound level. The upper bound level will be defined on how many times the KEM public key can be used…”). As to claim 9, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE expressly teaches a computer-implemented method of claim 1, wherein: for each of the plurality of key re-use periods (i.e., …teaches in par. 0091 the following: “keys may be re-used for a number of times depending on some upper bound level. The upper bound level will be defined on how many times the KEM public key can be used…”), the method further comprises serializing, by the first computing system, the ephemeral public key to generate a serialized public key (i.e., …teaches in par. 0088 the following: “generate a key pair (ECC ephemeral public key (‘A’) and private key)”); and using, by the first computing system, and until the expiration of the key re-use period (i.e., …teaches in par. 0091 the following: “keys may be re-used for a number of times depending on some upper bound level.”). The system of BANERJEE does not expressly teach: the current ephemeral keyset to initiate or resume one or more secure communication sessions with the one or more other computing systems comprises transmitting, by the first computing system, the serialized public key to the one or more other computing systems. In this instance the examiner notes the teachings of prior art reference Kang. With regards to applicant’s claim limitation element of “the current ephemeral keyset to initiate or resume one or more secure communication sessions with the one or more other computing systems”, Kang teaches par. 0047 the following: “once a pair of public and private keys is used to connect two hosts, the pair of public and private keys can only be used for connecting hosts other than the two hosts or connecting one of the two hosts to another host. If the pair of public and private keys, which has been used a number of times less than the predetermined maximum, has not yet been used to connect the two hosts, the public/private key reader 13 reads the pair of public and private keys.”. With regards to applicant’s claim limitation element of, “transmitting, by the first computing system, the serialized public key to the one or more other computing systems”, Kang teaches par. 0009 the following: “a public key Y.sub.i or Y.sub.j, which are disclosed in the process of being transmitted”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE with the teachings of Kang by having their system comprise an enhanced key exchange process. One would have been motivated to do so to provide a simple and effective means the management of keys with in a network environment, wherein the enhanced key exchange process helps facilitate proper key security and makes it easier to track key distribution. The system of BANERJEE and Kang does not expressly teach: storing, by the first computing system, the current ephemeral keyset in the memory cache comprises storing, by the first computing system, the serialized public key in the memory cache. In this instance the examiner notes the teachings of prior art reference Balar. Balar teaches in par. 0049 the following: “The unit stores (in non-persistent data storage) the challenge hash, generated agent RSA public key, and the caller MAC address.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE and Kang with the teachings of Balar by having their system comprise an enhanced key storage process. One would have been motivated to do so to provide a simple and effective means to secure key data, wherein the enhanced key storage process helps facilitate proper key management and makes it easier to provide key reusability. As to claim 10, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE expressly teaches a computer-implemented method of claim 1, wherein using, by the first computing system, and until the expiration of the key re-use period (i.e., …teaches in par. 0091 the following: “keys may be re-used for a number of times depending on some upper bound level. The upper bound level will be defined on how many times the KEM public key can be used”). The system of BANERJEE does not expressly teach: the current ephemeral keyset to initiate or resume one or more secure communication sessions comprises using, by the first computing system, and until the expiration of the key re-use period, the current ephemeral keyset to initiate or resume one or more mutual authentication and transport encryption protocols. In this instance the examiner notes the teachings of prior art reference Kang. With regards to applicant’s claim limitation element of, “the current ephemeral keyset to initiate or resume one or more secure communication sessions”, Kang teaches par. 0047 the following: “once a pair of public and private keys is used to connect two hosts, the pair of public and private keys can only be used for connecting hosts other than the two hosts or connecting one of the two hosts to another host. If the pair of public and private keys, which has been used a number of times less than the predetermined maximum, has not yet been used to connect the two hosts, the public/private key reader 13 reads the pair of public and private keys.”. With regards to applicant’s claim limitation element of, “using, by the first computing system, and until the expiration of the key re-use period, the current ephemeral keyset to initiate or resume one or more mutual authentication and transport encryption protocols”, Kang teaches par. 0047 the following: “once a pair of public and private keys is used to connect two hosts, the pair of public and private keys can only be used for connecting hosts other than the two hosts or connecting one of the two hosts to another host. If the pair of public and private keys, which has been used a number of times less than the predetermined maximum, has not yet been used to connect the two hosts, the public/private key reader 13 reads the pair of public and private keys.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE with the teachings of Kang by having their system comprise an enhanced key exchange process. One would have been motivated to do so to provide a simple and effective means the management of keys with in a network environment, wherein the enhanced key exchange process helps facilitate proper key security and makes it easier to track key distribution. As to claim 11, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE teaches a computer-implemented method of claim 1, the current ephemeral keyset comprises a post-quantum cryptographic algorithm to generate a current post-quantum cryptographic keyset (i.e., …teaches in his Abstract the following: “post quantum cryptography (PQC) are used in the generating”). The system of BANERJEE does not expressly teach: wherein generating, by the first computing system, and in response to the initiation of the key re-use period, performing, by the first computing system, and in response to the initiation of the key re-use period. In this instance the examiner notes the teachings of prior art reference Kang. With regards to applicant’s claim limitation element of, “wherein generating, by the first computing system, and in response to the initiation of the key re-use period”, Kang teaches par. 0046 the following: “When a request for a pair of public and private keys is received to the public/private key request receiver 11, the reused times checking unit 121 checks whether the number of times the pair of public and private keys stored in the public/private key storage unit 15 has been reused exceeds a predetermined maximum. The predetermined maximum may be set by a user or may be set at a default value by a system.”. With regards to applicant’s claim limitation element of, “performing, by the first computing system, and in response to the initiation of the key re-use period”, Kang teaches par. 0046 the following: “When a request for a pair of public and private keys is received to the public/private key request receiver 11, the reused times checking unit 121 checks whether the number of times the pair of public and private keys stored in the public/private key storage unit 15 has been reused exceeds a predetermined maximum. The predetermined maximum may be set by a user or may be set at a default value by a system.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE with the teachings of Kang by having their system comprise an enhanced key generation process. One would have been motivated to do so to provide a simple and effective means the management of keys with in a network environment, wherein the enhanced key generation process helps facilitate proper key security and makes it easier to track key distribution. As to claim 12, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE expressly teaches a computer-implemented method of claim 1, wherein the plurality of key re-use periods are sequential and non-overlapping (i.e., ...teaches in par. 0091 the following: “The PQC KEM keys may be re-used for a number of times depending on some upper bound level. The upper bound level will be defined on how many times the KEM public key can be used”). As to claim 13, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically neither BANERJEE nor Kang expressly teaches a computer-implemented method of claim 1, wherein storing, by the first computing system, the current ephemeral keyset in the memory cache comprises storing, by the first computing system, the current ephemeral keyset in only a non-persistent memory cache. In this instance the examiner notes the teachings of prior art reference Balar. Balar teaches in par. 0049 the following: “The unit stores (in non-persistent data storage) the challenge hash, generated agent RSA public key, and the caller MAC address.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of BANERJEE and Kang with the teachings of Balar by having their system comprise an enhanced key storage process. One would have been motivated to do so to provide a simple and effective means to secure key data, wherein the enhanced key storage process helps facilitate proper key management and makes it easier to provide key reusability. As to claim 14, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE teaches a computer-implemented method of claim 1, wherein, for each of the plurality of key re-use periods, the method further comprises denying, by the first computing system, any attempts to initiate or resume a secure communication session that use prior ephemeral keysets associated with prior, expired key re-use periods (i.e., …teaches in par. 0091 the following: “keys may be re-used for a number of times depending on some upper bound level. The upper bound level will be defined on how many times the KEM public key”). As to claim 15, the system of BANERJEE, Kang and Balar as applied to claim 1 teaches key re-use, specifically BANERJEE expressly teaches a computer-implemented method of claim 1, wherein the ephemeral keyset comprises a Elliptic Curve Digital Signature Algorithm (ECDSA) keyset (i.e., …teaches in his Abstract the following: “elliptic curve cryptography”). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRYAN F WRIGHT whose telephone number is (571)270-3826. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRYAN F WRIGHT/Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Nov 14, 2024
Application Filed
Mar 05, 2026
Non-Final Rejection mailed — §103
Jun 05, 2026
Response Filed
Aug 13, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744820
HIGHLY SCALABLE FOUR-DIMENSIONAL GEOSPATIAL DATA SYSTEM FOR SIMULATED WORLDS
2y 1m to grant Granted Sep 22, 2026
Patent 12719909
AUTOMATED VULNERABILITY AND THREAT LANDSCAPE ANALYSIS
3y 5m to grant Granted Aug 25, 2026
Patent 12712732
METHOD FOR AUTHENTICATION OF A SERVICE PROVIDER DEVICE TO A USER DEVICE
2y 9m to grant Granted Aug 18, 2026
Patent 12707015
IMAGE FORMING APPARATUS AND USER REGISTRATION METHOD FOR IMAGE FORMING APPARATUS
3y 2m to grant Granted Aug 11, 2026
Patent 12689613
Privileged remote access for Operational Technology (OT)/Internet of Things (IOT)/Industrial IOT (IIOT)/Industrial Control System (ICS)
4y 0m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+24.1%)
3y 2m (~1y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 820 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month