Prosecution Insights
Last updated: October 02, 2026
Application No. 18/973,204

INFORMATION PROCESSING APPARATUS, INFORMATION PROCESSING METHOD, AND COMPUTER READABLE MEDIUM

Final Rejection §101§103
Filed
Dec 09, 2024
Priority
Dec 21, 2023 — JP 2023-215540
Examiner
FARAMARZI, GITA
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
NEC Corporation
OA Round
2 (Final)
51%
Grant Probability
Moderate
3-4
OA Rounds
1y 9m
Est. Remaining
70%
With Interview

Examiner Intelligence

Grants 51% of resolved cases
51%
Career Allowance Rate
41 granted / 80 resolved
-6.7% vs TC avg
Strong +19% interview lift
Without
With
+18.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
24 currently pending
Career history
122
Total Applications
across all art units

Statute-Specific Performance

§101
8.3%
-31.7% vs TC avg
§103
57.4%
+17.4% vs TC avg
§102
4.9%
-35.1% vs TC avg
§112
28.4%
-11.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 80 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims The following is a Final Office Action in response to applicant’s filing on July 03, 2026. Claim 2 was canceled. Claims 11-19 were newly added. Claims 1, 3-19 are pending, of which claims 1, 9, and 10 are in independent form. Response to Amendment The amendment filed on July 03, 2026, has been entered. Amendments to the claims obviate the previous § 112(b) rejection. Therefore, the 112(b) rejection is withdrawn. The amendments to the claims do not obviate the previous § 101 issue as found in non-Final Office Action. Thus, the examiner maintains the 101 rejection. Response to Arguments Applicant's arguments filed on 07/03/2026, have been fully considered but they are not persuasive. 35 USC § 101 Rejection Applicant’s arguments see pages 7-10 of remarks, filed on 07/03/2026, with respect to claims 9 and 14-16 rejection under U.S.C. 101, have been fully considered, however, they are not persuasive. Applicant amendment to claim is not sufficient to amount to significantly more than the judicial exception because the limitations are merely generating a first random number key, outputting the first random number key, and recording the first random number key in an external apparatus and the memory; encrypting, with the first random number key recorded in the memory, a second random number key used to encrypt first data to be uploaded to a server, to thereby generate second data, recording the second data in the memory, and erasing the second random number key and the first random number key recorded in the memory; and decrypting the second random number key that decrypts the first data to be downloaded from the server based on the acquired first random number key from the external apparatus and the second data recorded in the memory. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because the limitations are merely instructions to implement the abstract idea on a computer and require no more than a generic computer to perform generic computer functions that are well-understood, routine and conventional activities previously known to the industry. The mechanisms used are generic computing operations that do not enhance the functionality of the computer. Further, the claim does not recite an improvement to another technology or technical field, an improvement to the functioning of the computer itself, or meaningful limitations beyond generally linking the use of an abstract idea to a particular technological environment. The additional elements when considered both individually and as a combination do not amount to significantly more than the abstract idea. So, the amendment limitations are not tied to a particular, special-purpose machine nor does it improve the functionality of the machine. A generic computer used to implement an abstract idea does not render the claim to significantly more that the abstract idea. The examiner suggest that additional limitations are necessary to recite steps (generate key, encrypt key with another key, store ciphertext, erase keys, later decrypt based on acquired key and stored ciphertext) are standard cryptographic/key‑management practices. Implementing these practices on a generic processor and memory is a conventional application of known cryptographic techniques. Therefore, the Examiner maintains the 35 USC 101 abstract rejection for claims 9 and 13-16. 35 USC § 103 Rejection On pages 10-13 of remarks, Applicant argues that the applied references, alone or in combination, fail to teach or suggest the recited claim language “wherein following the erasing the information processing apparatus is unable to perform decryption of the second random number key based on information in the at least one memory; and decrypt the second random number key that decrypts the first data to be downloaded from the server based on the acquired first random number key from the external apparatus and the second data recorded in the memory.” in claim 1. The examiner respectfully disagrees. The rejection is revised to remove Bergum and to rely on Miranda Gavillan in view of Denning. Miranda Gavillan teaches the underlying architecture in which a data key is encrypted or wrapped, the encrypted data key is retained and local copies of keys are discarded. Denning further teaches the disputed limitation that, after the locally available key information is discarded, the apparatus cannot recover the encrypted data key based on the information remaining in its memory. Denning explains that, if the key value associated with a key ID change, the cipher key must be unlocked using the old value and relocked with the new value before the old value is discarded, “otherwise the data would become undecipherable”, see Denning, Paragraph [0127]. Accordingly, after the applicable key value is discarded, the apparatus cannot recover the data encrypting key from the Cipher Key using information remaining in its memory. This teaches the limitation “wherein following the erasing the information processing apparatus is unable to perform decryption of the second random number key based on information in the at least one memory”. Also Denning teaches storing the Cipher Key and Ciphertext in a ciphertext file and later performing Geo-Decrypt using those stored values, see paragraphs [0103]-[0105] and [0126]. Thus, Denning teaches both the inability to decrypt after the required local key has been discarded and the restoration of decryption capability by importing key information from another device. A person of ordinary skill would have been motivated to apply Denning’s external key-management and recovery technique to Miranda Gavillian’s wrapped-data-key stream to reduce the risk that compromise of the local apparatus and its memory would expose the data encryption key, while maintaining authorized recovery through a separately maintained key source. Accordingly, Miranda Gavillan in view of Denning teaches the disputed limitations of amended claim 1. Therefore, the rejection of claims 1, 3-19 under 103 is maintained. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1 and 3-19 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly mare. Analysis Step 1 (Statutory Categories) — 2019 PEG pq. 53 Claim 9 is directed to the statutory categories of invention. Step 2A, Prong 1 (Do the claims recite an abstract idea?) — 2019 PEG pq. 54 Claim 9 recites the following types of subject matter that are judicial exceptions: Abstract idea — mental processes and data manipulation/analysis: “An information processing method performed by an information processing apparatus comprising a memory, the information processing method comprising: generating a first random number key, outputting the first random number key, and recording the first random number key in an external apparatus and the memory; encrypting, with the first random number key recorded in the memory, a second random number key used to encrypt first data to be uploaded to a server, to thereby generate second data, recording the second data in the memory, and erasing the second random number key and the first random number key recorded in the memory; and decrypting the second random number key that decrypts the first data to be downloaded from the server based on the acquired first random number key from the external apparatus and the second data recorded in the memory”. The claim is directed to the abstract concept of cryptographic key management and basic mathematical operations (generation, encryption, decryption, storage, and erasure of keys). At a high level the claim describes generating keys, using one key to encrypt another, storing encrypted keys, erasing keys from memory, and later recovering keys to decrypt data. These are fundamental practices of cryptography and information processing—i.e., mathematical concepts and data‑processing operations. The steps of generating numbers, recording data, performing mathematical encryption or decryption operations, and erasing data are concepts that can be performed in the human mind or by a human using a pen and paper. A human can mentally generate a random number, use it to mathematically encode (encrypt), write down the result (record), cross out the original numbers (erase), and later reverse the encryption (decryption). Thus, claim 9 recites a “mental process”, which falls within the abstract idea grouping. Step 2A, Prong 2 (Does the claim recite additional elements that integrate the judicial exception into a practical application?) - 2019 PEG pq. 54 Claim 9 does not integrate the abstract idea into a practical application. Although the claim recites a “information processing apparatus comprising a memory”, “following the erasing the information processing apparatus is unable to perform decryption of the second random number key based on information in the at least one memory”, these elements merely represent generic computer components performing generic computer functions. These additional elements are invoked merely as a toll to perform the abstract idea. The claim does not affect an improvement in the functioning of a computer or technical field. Further, the steps of generating, encrypting, recording, erasing and decrypting are recited at a high level of generality. Furthermore, the data being manipulated (such as keys, first data, second data, a server, an external apparatus) remains abstract information. Therefore, claim 9 is directed to an abstract idea and is not integrated into a practical application under Step 2A. Step 2B (Does the claim recite additional elements that amount to significantly more than the judicial exception?) - 2019 PEG pq. 56 Claim 9 does not include an inventive concept. The additional elements of the claim, do not amount to significantly more than the abstract idea itself. The claim recites a “information processing apparatus …a memory, keys, first data, second data, a server, and an external apparatus”, these components perform routine computer functions and conventional to use a processor to execute instructions, and to use a memory to store data and instruction. The claim does not recite any specialized hardware. The ordered combination of generating keys, encrypting, recording, erasing, and decrypting using generic memory and processors is a conventional sequence of steps in the field of basic cryptography and data security. The recited steps (generate key, encrypt key with another key, store ciphertext, erase keys, later decrypt based on acquired key and stored ciphertext) are standard cryptographic/key‑management practices. Implementing these practices on a generic processor and memory is a conventional application of known cryptographic techniques. Accordingly, under Step 2B of the PEG, the claim 9 is not patent eligible. Claim 1 includes all the limitations of claim 9. Therefore, claim 1 recites the same abstract idea of claim 9. Claim 1 recites the additional limitations “An information processing apparatus comprising: at least one memory storing instructions; and at least one processor configured to execute the instructions to: generate a first random number key in the memory; encrypt, with the first random number key recorded in the memory, a second random number key used to encrypt first data to be uploaded, to thereby generate second data, record the second data in the memory, and erase the second random number key and the first random number key recorded in the memory; and decrypt the second random number key that decrypts the first data to be downloaded based on the acquired first random number key and the second data recorded in the memory”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 3 is dependent on claim 2 and includes all the limitations of claim 2. Therefore, claim 3 recites the same abstract idea of claim 2. Claim 3 recites additional limitations “wherein the external apparatus is located at a first place where the first random number key is generated, and the first place is different from a second place where the second data is generated…”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 4 is dependent on claim 1 and includes all the limitations of claim 1. Therefore, claim 4 recites the same abstract idea of claim 1. Claim 4 recites additional limitations “wherein the information processing apparatus generates the first random number key at the first place, generates the second data at the second place, and decrypts the second random number key at the first place…”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 5 is dependent on claim 1 and includes all the limitations of claim 1. Therefore, claim 5 recites the same abstract idea of claim 1. Claim 5 recites additional limitations “wherein the at least one processor is configured to execute the instructions to encrypt the second random number key …”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 6 is dependent on claim 1 and includes all the limitations of claim 1. Therefore, claim 6 recites the same abstract idea of claim 1. Claim 6 recites additional limitations “wherein the at least one processor is configured to execute the instructions to: in a case where a data size of the first random number key is equal to or larger than a data size of the second random number key, encrypt the second random number key with the first random number key using a one-time pad; and in a case where a data size of the first random number key is not equal to or larger than a data size of the second random number key, encrypt the second random number key with the first random number key using an encryption method other than a one-time pad”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 7 is dependent on claim 1 and includes all the limitations of claim 1. Therefore, claim 7 recites the same abstract idea of claim 1. Claim 7 recites additional limitations “wherein the at least one processor is configured to execute the instructions to, in a case where information indicating a position at which the second random number key is decrypted satisfies a predetermined condition based on information indicating a position at which the first random number key is generated, decrypt the second random number key”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 8 is dependent on claim 1 and includes all the limitations of claim 1. Therefore, claim 8 recites the same abstract idea of claim 1. Claim 8 recites additional limitations “wherein the at least one processor is configured to execute the instructions to, in a case where information indicating a position at which the second random number key is decrypted satisfies a predetermined condition based on information indicating a position at which the first random number key is generated, decrypt the first random number key from third data in which the first random number key is encrypted”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 10 is dependent on claims 9 and includes all the limitations of claim 9. Therefore, claim 10 recites the same abstract idea of claim 9. Claim 10 recites additional limitations “A non-transitory computer readable medium storing a program for causing a computer comprising a memory to: generate a first random number key, output the first random number key, and record the first random number key in the memory; encrypt, with the first random number key recorded in the memory, a second random number key used to encrypt first data to be uploaded, to thereby generate second data, record the second data in the memory, and erase the second random number key and the first random number key recorded in the memory; and decrypt the second random number key that decrypts the first data to be downloaded based on the acquired first random number key and the second data recorded in the memory.”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 11 is dependent on claim 1 and includes all the limitations of claim 1. Therefore, claim 11 recites the same abstract idea of claim 1. Claim 11 recites additional limitations “wherein the external apparatus is a removable storage medium that is physically separate from the information processing apparatus”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 12 is dependent on claim 1 and includes all the limitations of claim 1. Therefore, claim 12 recites the same abstract idea of claim 1. Claim 12 recites additional limitations “wherein the at least one processor is configured to execute the instructions to generate the first random number key having a data size equal to or larger than a data size of the second random number key”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 13 is dependent on claim 1 and includes all the limitations of claim 1. Therefore, claim 13 recites the same abstract idea of claim 1. Claim 13 recites additional limitations “wherein the external apparatus is kept at a secure location at a first place where the first random number key is generated”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 14 is dependent on claim 9 and includes all the limitations of claim 9. Therefore, claim 14 recites the same abstract idea of claim 9. Claim 14 recites additional limitations “wherein the external apparatus is a removable storage medium that is physically separate from the information processing apparatus”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 15 is dependent on claim 9 and includes all the limitations of claim 9. Therefore, claim 15 recites the same abstract idea of claim 9. Claim 15 recites additional limitations “… generating the first random number key comprises generating the first random number key having a data size equal to or larger than a data size of the second random number key”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 16 is dependent on claim 9 and includes all the limitations of claim 9. Therefore, claim 16 recites the same abstract idea of claim 9. Claim 16 recites additional limitations “… generating the first random number key comprises generating the first random number key having a data size equal to or larger than a data size of the second random number key”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 17 is dependent on claim 10 and includes all the limitations of claim 10. Therefore, claim 17 recites the same abstract idea of claim 10. Claim 17 recites additional limitations “… wherein the external apparatus is a removable storage medium that is physically separate from the computer”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 18 is dependent on claim 10 and includes all the limitations of claim 10. Therefore, claim 18 recites the same abstract idea of claim 10. Claim 18 recites additional limitations “… wherein the program causes the computer to generate the first random number key having a data size equal to or larger than a data size of the second random number key”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Claim 19 is dependent on claim 10 and includes all the limitations of claim 10. Therefore, claim 19 recites the same abstract idea of claim 10. Claim 18 recites additional limitations “… wherein the external apparatus is kept at a secure location at a first place where the first random number key is generated”, which in Step 2A, Prong 2, the limitations are merely elaborating on the abstract idea, by further specifying an additional limitation at a high-level of generality, therefore, does not amount to significantly more than the abstract idea. Therefore, claims 1 and 3-19 are rejected under 35 U.S.C. § 101. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 3-4, and 7-19 are rejected under 35 U.S.C. 103 as being unpatentable over Miranda Gavillan et al. (US 2008/0165973 A1), hereinafter Miranda Gavillan in view of Denning et al. (US 7,143,289 B2), hereinafter Denning. Regarding claim 1, Miranda Gavillan discloses an information processing apparatus comprising: at least one memory storing instructions (Miranda Gavillan, Fig. 2, Paras. 0022-0027); and at least one processor configured to execute the instructions to (Miranda Gavillan, Fig. 2, Paras. 0022-0027): generate a first random number key (Miranda Gavillan, Paras. 0006, a random symmetric data key (DK) is generated by an external key manager (EKM), output the first random number key (Miranda Gavillan, Paras. 0033, The data key DK 206 is then securely wrapped in the tape drive's session key to generate the session encrypted data key SEDK 214 in step 416. Using any desired secure key exchange protocol, the EKM 202 passes the SEDK 214 to the tape drive 218 where it is stored as the SEDK 214 b), and record the first random number key in an external apparatus and the memory (Miranda Gavillan, Paras. 0034, the EEDK(s) 212 b and the SEDK 214 b are stored in the crypto module 226) and (Miranda Gavillan, Fig. 2, tap drive 218, and crypto module 226); Miranda Gavillan does not explicitly disclose encrypt, with the first random number key recorded in the memory, a second random number key used to encrypt first data to be uploaded to server, to thereby generate second data, record the second data in the memory, and erase the second random number key and the first random number key recorded in the memory; wherein following the erasing the information processing apparatus is unable to perform decryption of the second random number key based on information in the at least one memory; and decrypt the second random number key that decrypts the first data to be downloaded from the server based on the acquired first random number key from the external apparatus and the second data recorded in the memory. However, Denning teaches encrypt, with the first random number key recorded in the memory (Denning, Para. 0081, the Geo- Encrypt function 700 generates a Data Encrypting Key 524 using the PRNG sub-function 704… the Data Encrypting Key 524 is locked (i.e., encrypted) using the Geo-Lock Key function 800, using a location value derived from the location identified by the Location ID 140 and from the key encrypting key identified by the Key ID 505. The Geo-Lock Key function 800 provides as outputs Shape Parameter 509 and Cipher Key 526) and (Denning, Para. 0062, the memory units 304, 314, 324, and 404 are further organized to include key tables 306, 316, 326, and 406 that allow for the storage of a plurality of keys that are used with private-key and public-key cryptography), a second random number key used to encrypt first data to be uploaded to server (Denning, Para. 0081, the Encrypt sub-function 706 then encrypts the Plaintext 518 using both the Data Encrypting Key 524 and the IV 708 to produce a Ciphertext output 520. The Data Encrypting Key 524 is locked (i.e., encrypted) using the Geo-Lock Key function 800, using a location value derived from the location identified by the Location ID 140 and from the key encrypting key identified by the Key ID 505), to thereby generate second data (Denning, Para. 0085, the Geo-Lock Key function 800 is used to encrypt the Data Encrypting Key 524 so that it can be securely distributed to a receiver device 400. The Geo-Lock Key function 800 has three inputs, including: (1) Location ID (Loc ID) 140; (2) Key ID 505; and (3) Data Encrypting Key 524. The Geo-Lock Key function 800 further includes a Mapping Encrypt (Mapping Enc) sub-function 802, a Get Key sub-function 806, and a Key Encrypt sub-function 812. The Geo-Lock Key function generates two outputs, including: (1) Cipher Key 526; and (2) Shape Parm 509), record the second data in the memory (Denning, Para. 0126, this produces the values Shape Parm, Cipher Key, IV, and Ciphertext, which would then be stored in the ciphertext file along with Key ID), and erase the second random number key and the first random number key recorded in the memory (Denning, Para. 0100, for some applications, it may be desirable to provide a Delete Key function that deletes particular keys from a key table of a device. The Delete Key function receives as an input a particular Key ID in order to delete the corresponding key from the key table), wherein following the erasing the information processing apparatus is unable to perform decryption of the second random number key based on information in the at least one memory (Denning, Para. 0127, if the Key Value associated with this particular Key ID ever changes as the result of an Update Key operation, Cipher Key would have to be unlocked with the old value and re-locked with a new value before the old value is discarded. Otherwise, the data would become undecipherable); and decrypt the second random number key that decrypts the first data to be downloaded from the server based on the acquired first random number key from the external apparatus (Denning, Para. 0083, data Encrypting Key 524 is determined by unlocking the Cipher Key using the Geo-Unlock Key function 820) and (Denning, Para. 0014, the encrypted data encrypting key is then transmitted to the receiver along with the ciphertext data) and (Denning, Para. 0083, the Geo-Decrypt function 720 decrypts Ciphertext 520 using Data Encrypting Key 524 and IV 708, and includes sub-function Decrypt 724 and accesses the Geo-Unlock Key function 820 (described below with respect to FIG. 8)) and the second data recorded in the memory (Denning, Para. 0126, at a later time, the provider device 300, 310, 320 decrypts the data by performing the Geo-Decrypt function with inputs Shape Parm, Key ID, Cipher Key, IV, and Ciphertext, using the values obtained from the ciphertext file). Miranda Gavillan and Denning are both considered to be analogous to the claim invention because they are in the same field of a cryptographic processing method where data encrypted and uploaded at a first place is downloaded and decrypted at a second place. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Miranda Gavillan to incorporate the teachings of Denning to include encrypt, with the first random number key recorded in the memory (Denning, Para. 0081) and (Denning, Para. 0062), a second random number key used to encrypt first data to be uploaded to server (Denning, Para. 0081), to thereby generate second data (Denning, Para. 0085), record the second data in the memory (Denning, Para. 0126), and erase the second random number key and the first random number key recorded in the memory (Denning, Para. 0100), wherein following the erasing the information processing apparatus is unable to perform decryption of the second random number key based on information in the at least one memory (Denning, Para. 0127); and decrypt the second random number key that decrypts the first data to be downloaded from the server based on the acquired first random number key from the external apparatus (Denning, Para. 0083) and (Denning, Para. 0014) and (Denning, Para. 0083) and the second data recorded in the memory (Denning, Para. 0126). Doing so would aid to permit decryption anywhere in the world provided the receiver has the key decrypting key needed to decrypt the random data encrypting key. It also should be appreciated that geo-encryption can be used when time is not to be factor in granting access, thereby permitting decryption over an indefinite period of time (Denning, Para. 0021). Regarding claim 3, the combination of Miranda Gavillan in view of Denning teaches the information processing apparatus according to claim 2, wherein the external apparatus is located at a first place where the first random number key is generated (Miranda, Fig. 2, Para. 0006, when a tape drive requests an encryption key, a random symmetric data key (DK) is generated by an external key manager (EKM)), and the first place is different from a second place where the second data is generated (Miranda, Fig. 2, Para. 0006, at the crypto module 226, the DK 206 b is extracted from the SEDK 214 b, and is sent to the data encryption/decryption module 230 where it is used to encode/decode the input data stream). Regarding claim 4, the combination of Miranda Gavillan in view of Denning teaches the information processing apparatus according to claim 1, wherein the information processing apparatus generates the first random number key at the first place (Miranda Gavillan, Fig. 2, Para. 0006, when a tape drive requests an encryption key, a random symmetric data key (DK) is generated by an external key manager (EKM)), generates the second data at the second place (Miranda Gavillan, Fig. 2, Para. 0006, at the crypto module 226, the DK 206 b is extracted from the SEDK 214 b, and is sent to the data encryption/decryption module 230 where it is used to encode/decode the input data stream), and decrypts the second random number key at the first place (Miranda Gavillan, Para. 0027, the crypto module 226 controls the data encryption/decryption module 230 by securely exchanging data key (DK) 206 b and its associated key label 208 b using the SEDK 214 b which is received from the EKM 202 (where it is originally generated as SEDK 214). At the crypto module 226, the DK 206 b is extracted from the SEDK 214 b, and is sent to the data encryption/decryption module 230 where it is used to encode/decode the input data stream). Regarding claim 7, the combination of Miranda Gavillan in view of Denning teaches the information processing apparatus according to claim 1, wherein the at least one processor is configured to execute the instructions to, in a case where information indicating a position at which the second random number key is decrypted satisfies a predetermined condition based on information indicating a position at which the first random number key is generated (Denning, Para. 0073, at step 514, the process generates a random data encrypting key 524. This data encrypting key 524 is used to encrypt the plaintext digital information 518 at step 516 to produce geo-encrypted digital information 520. The data encrypting key 524 is then encrypted at step 522 using the location value 507 and the key encrypting key 307 a. The geo-encrypted digital information 520, the encrypted data encrypting key 526 (also referred to below as a cipher key), the shape parameter 509, and the key ID 505 are then communicated to the receiver device 400. Attempts to decrypt the geo-encrypted information 520 by a receiver device 400 will be denied unless the location of the receiver device 400 matches the location specified by the location identity attribute 140 and the receiver device 400 has the correct key decrypting key identified by the key ID 505), decrypt the second random number key (Denning, Para. 0073, Attempts to decrypt the geo-encrypted information 520 by a receiver device 400 will be denied unless the location of the receiver device 400 matches the location specified by the location identity attribute 140 and the receiver device 400 has the correct key decrypting key identified by the key ID 505). Miranda Gavillan and Denning are all considered to be analogous to the claim invention because they are in the same field of a cryptographic processing method where data encrypted and uploaded at a first place is downloaded and decrypted at a second place. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Miranda Gavillan to incorporate the teachings of Denning to include wherein the at least one processor is configured to execute the instructions to, in a case where information indicating a position at which the second random number key is decrypted satisfies a predetermined condition based on information indicating a position at which the first random number key is generated (Denning, Para. 0073,), decrypt the second random number key (Denning, Para. 0073,). Doing so would aid to permit decryption anywhere in the world provided the receiver has the key decrypting key needed to decrypt the random data encrypting key. It also should be appreciated that geo-encryption can be used when time is not to be factor in granting access, thereby permitting decryption over an indefinite period of time (Denning, Para. 0021). Regarding claim 8, the combination of Miranda Gavillan in view of Denning teaches the information processing apparatus according to claim 1, wherein the at least one processor is configured to execute the instructions to, in a case where information indicating a position at which the second random number key is decrypted satisfies a predetermined condition based on information indicating a position at which the first random number key is generated (Denning, Para. 0073, at step 514, the process generates a random data encrypting key 524. This data encrypting key 524 is used to encrypt the plaintext digital information 518 at step 516 to produce geo-encrypted digital information 520. The data encrypting key 524 is then encrypted at step 522 using the location value 507 and the key encrypting key 307 a. The geo-encrypted digital information 520, the encrypted data encrypting key 526 (also referred to below as a cipher key), the shape parameter 509, and the key ID 505 are then communicated to the receiver device 400. Attempts to decrypt the geo-encrypted information 520 by a receiver device 400 will be denied unless the location of the receiver device 400 matches the location specified by the location identity attribute 140 and the receiver device 400 has the correct key decrypting key identified by the key ID 505), Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Miranda Gavillan to incorporate the teachings of Denning to include wherein the at least one processor is configured to execute the instructions to, in a case where information indicating a position at which the second random number key is decrypted satisfies a predetermined condition based on information indicating a position at which the first random number key is generated (Denning, Para. 0073,), decrypt the first random number key from third data in which the first random number key is encrypted (Denning, Para. 0103). Doing so would aid to permit decryption anywhere in the world provided the receiver has the key decrypting key needed to decrypt the random data encrypting key. It also should be appreciated that geo-encryption can be used when time is not to be factor in granting access, thereby permitting decryption over an indefinite period of time (Denning, Para. 0021). Regarding claim 9, the claim is interpreted and rejected for the same rational set forth in claim 1. Regarding claim 10, the claim is interpreted and rejected for the same rational set forth in claim 1 and 9. Regarding claim 11, the combination of Miranda Gavillan in view of Denning teaches the information processing apparatus according to claim 1, wherein the external apparatus is a removable storage medium that is physically separate from the information processing apparatus (Miranda, Para. 0007, A method, system and program are disclosed for the retrieval of key label codes enabling tamper resistant access to encrypted data in a removable storage medium, such as single tape storage cartridge). Regarding claim 12, the combination of Miranda Gavillan in view of Denning teaches the information processing apparatus according to claim 1, wherein the at least one processor is configured to execute the instructions to generate the first random number key having a data size equal to or larger than a data size of the second random number key (Miranda Gavillan, Para. 0027, the data encryption/decryption module 230 performs the actual data encryption and decryption (such as by using the Advanced Encryption Standard encryption algorithm) using a data key having any desired key length (e.g., 128 or 256-bit data key length)) and (Miranda Gavillan, Para. 0032, In a selected embodiment, the EEDK 212 creation process in the EKM 202 uses asymmetric encryption by performing RSA 2048-bit encryption of the DK 206 with the public part of a public/private key pair to render the data key 206 within the EEDK 212 completely secure to any entity who does not possess the private part of the key pair) and (Miranda Gavillan, Para. 0032, in certain implementations, the host 602 obtains the public key from a third party, or alternatively, the host 602 can generate the public/private key pair itself). Regarding claim 13, the combination of Miranda Gavillan in view of Denning teaches the information processing apparatus according to claim 1, wherein the external apparatus is kept at a secure location at a first place where the first random number key is generated (Denning, Para. 0100, the PRNG sub-function may be used to generate a random Key Value. Then, a Key Record is created using the Key Id and the randomly generated Key Value. This newly created Key Record is then added to the key table of the device) and (Denning, Para. 0063, The preferred embodiment is a tamperproof hardware device that would protect both the secrecy of keys and the integrity of the functions performed by the devices). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Miranda Gavillan to incorporate the teachings of Denning to include wherein the external apparatus is kept at a secure location at a first place where the first random number key is generated (Denning, Para. 0100) and (Denning, Para. 0063). Doing so would aid to permit decryption anywhere in the world provided the receiver has the key decrypting key needed to decrypt the random data encrypting key. It also should be appreciated that geo-encryption can be used when time is not to be factor in granting access, thereby permitting decryption over an indefinite period of time (Denning, Para. 0021). Regarding claim 14, the claim is interpreted and rejected for the same rational set forth in claim 11. Regarding claim 15, the claim is interpreted and rejected for the same rational set forth in claim 12. Regarding claim 16, the claim is interpreted and rejected for the same rational set forth in claim 13. Regarding claim 17, the claim is interpreted and rejected for the same rational set forth in claims 11 and 14. Regarding claim 18, the claim is interpreted and rejected for the same rational set forth in claims 12 and 15. Regarding claim 19, the claim is interpreted and rejected for the same rational set forth in claims 13 and 16. Claims 5-6 are rejected under 35 U.S.C. 103 as being unpatentable over Miranda Gavillan et al. (US 2008/0165973 A1), hereinafter Miranda Gavillan in view of Denning et al. (US 7,143,289 B2), hereinafter Denning further in view of Hammersmith (US 8.467,533 B2), hereinafter Hammersmith. Regarding claim 5, the combination of Miranda Gavillan in view of Denning does not explicitly teach the information processing apparatus according to claim 1, wherein the at least one processor is configured to execute the instructions to encrypt the second random number key with the first random number key using a one-time pad. However, Hammersmith teaches the information processing apparatus according to claim 1, wherein the at least one processor is configured to execute the instructions to encrypt the second random number key with the first random number key using a one-time pad (Hammersmith, Col. 1, Lines 23-25, if the key used for encryption and decryption is as long as the message, it is referred to as a “one-time-pad” (OTP) encryption method). Miranda Gavillan, Denning and Hammersmith are all considered to be analogous to the claim invention because they are in the same field of a cryptographic processing method where data encrypted and uploaded at a first place is downloaded and decrypted at a second place. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Miranda Gavillan and Denning to incorporate the teachings of Hammersmith to include the information processing apparatus according to claim 1, wherein the at least one processor is configured to execute the instructions to encrypt the second random number key with the first random number key using a one-time pad (Hammersmith, Col. 1, Lines 23-25). Doing so would allow bulky one-time-pad (OTP) keys to be distributed to a computer connected to a network such as the Internet. So that a one-time-pad key distributed on a network cannot be intercepted and then used to decrypt a message, the one-time-pad communications key is itself encrypted with a key encryption key (Hammersmith, Col. 2, Lines 13-18). Regarding claim 6, the combination of Miranda Gavillan in view of Denning does not explicitly teach the information processing apparatus according to claim 1, wherein the at least one processor is configured to execute the instructions to: in a case where a data size of the first random number key is equal to or larger than a data size of the second random number key, encrypt the second random number key with the first random number key using a one-time pad; and in a case where a data size of the first random number key is not equal to or larger than a data size of the second random number key, encrypt the second random number key with the first random number key using an encryption method other than a one-time pad. However, Hammersmith teaches in a case where a data size of the first random number key is equal to or larger than a data size of the second random number key, encrypt the second random number key with the first random number key using a one-time pad (Hammersmith, Col. 1, Lines 23-25, if the key used for encryption and decryption is as long as the message, it is referred to as a “one-time-pad” (OTP) encryption method) and (Hammersmith, Col. 1, Lines 39-44, fast enough computer with a large enough memory, any repeating key encryption can be broken. With the recent increases in computer speed and memory size, repeating key encryption methods previously thought to provide adequate security have been broken. The only known encryption method that is provably unbreakable is one-time-pad); and in a case where a data size of the first random number key is not equal to or larger than a data size of the second random number key, encrypt the second random number key with the first random number key using an encryption method other than a one-time pad (Hammersmith, Col. 1, Lines 23-25, if the key is shorter than the message, such that the key, or a derivative of the key, must be used two or more times, it is referred to as a “repeating key encryption method). Miranda Gavillan, Denning and Hammersmith are all considered to be analogous to the claim invention because they are in the same field of a cryptographic processing method where data encrypted and uploaded at a first place is downloaded and decrypted at a second place. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Miranda Gavillan and Denning to incorporate the teachings of Hammersmith to include in a case where a data size of the first random number key is equal to or larger than a data size of the second random number key, encrypt the second random number key with the first random number key using a one-time pad (Hammersmith, Col. 1, Lines 23-25) and (Hammersmith, Col. 1, Lines 39-44); and in a case where a data size of the first random number key is not equal to or larger than a data size of the second random number key, encrypt the second random number key with the first random number key using an encryption method other than a one-time pad (Hammersmith, Col. 1, Lines 23-25). Doing so would allow bulky one-time-pad (OTP) keys to be distributed to a computer connected to a network such as the Internet. So that a one-time-pad key distributed on a network cannot be intercepted and then used to decrypt a message, the one-time-pad communications key is itself encrypted with a key encryption key (Hammersmith, Col. 2, Lines 13-18). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTOL-892. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GITA FARAMARZI whose telephone number is (571)272-0248. The examiner can normally be reached Monday- Friday 9:00 am- 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GITA FARAMARZI/Examiner, Art Unit 2496 /JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Dec 09, 2024
Application Filed
Apr 08, 2026
Non-Final Rejection mailed — §101, §103
Jun 03, 2026
Interview Requested
Jun 18, 2026
Applicant Interview (Telephonic)
Jun 27, 2026
Examiner Interview Summary
Jul 03, 2026
Response Filed
Sep 11, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12627633
SYSTEM AND METHOD FOR APPLICATION TRAFFIC AND RUNTIME BEHAVIOR LEARNING AND ENFORCEMENT
5y 9m to grant Granted May 12, 2026
Patent 12339997
ENTITY FOCUSED NATURAL LANGUAGE GENERATION
2y 1m to grant Granted Jun 24, 2025
Patent 12316648
Data value classifier
5y 10m to grant Granted May 27, 2025
Patent 12301564
VIRTUAL SESSION ACCESS MANAGEMENT
4y 3m to grant Granted May 13, 2025
Patent 12256022
BLOCKCHAIN TRANSACTION COMPRISING RUNNABLE CODE FOR HASH-BASED VERIFICATION
3y 3m to grant Granted Mar 18, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
51%
Grant Probability
70%
With Interview (+18.9%)
3y 7m (~1y 9m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 80 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month