Prosecution Insights
Last updated: October 04, 2026
Application No. 18/981,948

MACSEC-LIKE ENCRYPTION FOR BLANKET OBFUSCATION AND ENHANCED PRIVACY CONTENT

Final Rejection §101§102§103§112
Filed
Dec 16, 2024
Priority
Jan 09, 2024 — provisional 63/618,965
Examiner
ALI, AFAQ
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
2 (Final)
90%
Grant Probability
Favorable
3-4
OA Rounds
7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
128 granted / 143 resolved
+31.5% vs TC avg
Moderate +12% lift
Without
With
+11.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
27 currently pending
Career history
177
Total Applications
across all art units

Statute-Specific Performance

§101
9.7%
-30.3% vs TC avg
§103
51.5%
+11.5% vs TC avg
§102
4.5%
-35.5% vs TC avg
§112
22.1%
-17.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 143 resolved cases

Office Action

§101 §102 §103 §112
CTNF 18/981,948 CTNF 96641 Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Detailed Action Claims 1-20 are pending. Priority This application claims priority to U.S. Application No. 63/618,965, filed Jan. 9, 2024. Therefore, the effective filing date of this application is Jan. 9, 2024. Drawings Applicants’ drawings filed on 12/16/2024 has been inspected and it is in compliance with MPEP 608.02. Specification The specification filed on 12/16/2024 is acceptable for examination proceedings. Information Disclosure Statement 06-52 The information disclosure statements (IDS) submitted on 12/16/2024 and 04/03/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements have been considered by the examiner. Double Patenting No double patenting rejection required at the time of this office action. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. 07-34-01 Claims 5, 9-12, 14, and 19 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 5, 12, and 19 recite the limitation “randomly generated values for a source address and a destination address”. However, claim 4 already recites of “MACsec header including an over-the-air MAC (otaMAC) address of a wireless client device as a destination address and an otaMAC address of a wireless access point device as a source address”. It is unclear if the source address and destination address of claim 5 are the same as the one being recited in claim 4. For the purpose of examination Examiner is interpreting this limitation as “randomly generated values for the source address and the destination address”. Appropriate correction is required. Claims 9 and 10 recite the limitation of “wherein the operation of performing the encryption operation comprises”. The recitation of the limitation “the operation” renders the claim unclear. The limitation makes it seem there is an operation within an operation. As if operation of performing is then leading to the encryption operation. For the purpose of examination Examiner is interpreting this limitation as “wherein the encryption operation comprises …”. Appropriate correction is required. Claims 11 and 12 depend on claim 10. Therefore, claims 11 and 12 also inherit the rejection. Claim 14 recites the limitation "the operation ". There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination Examiner is interpreting this limitation as “wherein wirelessly transmitting comprises …”. Similar to claim 7. Appropriate correction is required. Claim Rejections - 35 USC § 101 07-04-01 AIA 07-04 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because they directed to an abstract idea. Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim recites of a method comprising: obtaining a data unit that includes a header and a data payload; performing an encryption operation on the data unit to encapsulate the data payload and at least a portion of the header in an encrypted payload; and wirelessly transmitting a frame that includes the encrypted payload. The limitation of obtaining a data unit that includes a header and a data payload, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually obtain data unit that includes a header and a data payload. The limitation of performing an encryption operation on the data unit to encapsulate the data payload and at least a portion of the header in an encrypted payload, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually perform an encryption operation on the data unit. The limitation of wirelessly transmitting a frame that includes the encrypted payload, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually transmit wirelessly the encrypted payload. This judicial exception is not integrated into a practical application. The claim recites of a limitation of “wirelessly transmitting a frame that includes the encrypted payload”. This limitation is used to generally transmit the encrypted payload. The limitation does not place any limit on what is the purpose or outcome of transmitting the encrypted payload. Merely transmitting data wirelessly does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. The claim is not patent eligible. Claim 2 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein performing the encryption operation includes encapsulating a source address and a destination address associated with the data unit in the encrypted payload. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually encapsulate a source address and a destination address associated with the data unit in the encrypted payload. Claim 3 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the data unit is a Media Access Control (MAC) protocol data unit (MPDU) and wherein performing the encryption operation comprises performing a MAC security (MACsec) operation on the MPDU to encapsulate the MPDU within a MACsec payload. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually perform MACsec operation on the MPDU to encapsulate the MPDU within a MACsec payload. Claim 4 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein performing the MACsec operation on the MPDU includes adding a MACsec header to the MACsec payload, the MACsec header including an over-the-air MAC (otaMAC) address of a wireless client device as a destination address and an otaMAC address of a wireless access point device as a source address. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually add a MACsec header to the MACsec payload, the MACsec header including an over-the-air MAC (otaMAC) address of a wireless client device as a destination address and an otaMAC address of a wireless access point device as a source address. Claim 5 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the MACsec header includes randomly generated values for a source address and a destination address. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine the MACsec header includes randomly generated values for a source address and a destination address. Claim 6 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein padding is added to the data payload so that a size of the data unit is a predetermined size, wherein the predetermined size is determined by an access point and wherein the padding is added by a wireless client device that is a source of the data unit. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine padding to be added to the data payload. Furthermore, the recitation of wireless client device amounts to no more than mere instructions to apply the exception using a generic device. Mere instructions to apply an exception using a generic device cannot provide an inventive concept. Claim 7 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein wirelessly transmitting comprises wirelessly transmitting the frame according to an IEEE 802.11 wireless networking protocol. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually transmit data in accordance to IEEE 802.11 wireless networking protocol. Claim 8 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Furthermore, this claim recites of an apparatus comprising a processor that perform the features of method claim 1. Therefore, claim 8 is rejected in a similar manner as in the rejection of claim 1. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. In particular, the claim only recites one additional element of “a processor, wherein the processor is configured to perform operations comprising” recited at a high-level of generality (i.e., as a generic processor implementing the apparatus) such that it amounts no more than mere instructions to apply the exception using a generic processor. Mere instructions to apply an exception using a generic processor cannot provide an inventive concept. The claim is not patent eligible. Claim 15 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Furthermore, this claim recites of one or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to execute the method of claim 1. Therefore, claim 15 is rejected in a similar manner as in the rejection of claim 1. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. In particular, the claim only recites one additional element of “one or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to execute” recited at a high-level of generality (i.e., as a generic processor implementing the system) such that it amounts no more than mere instructions to apply the exception using a generic processor. Mere instructions to apply an exception using a generic processor cannot provide an inventive concept. The claim is not patent eligible. Claims 9-14, and 16-20 are parallel claims to claims 2-7. Therefore, claims 9-14, and 16-20 are rejected in a similar manner as in the rejection of claims 2-7. The dependent claims 2-7, 9-14, and 16-20 are directed to abstract ideas and do not include additional elements that are sufficient to amount to significantly more than the judicial exception. This judicial exception is not integrated into a practical application. Therefore, the claims are not patent eligible. Claim Rejections - 35 USC § 102 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-07-aia AIA 07-07 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – 07-08-aia AIA (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. 07-15 AIA Claim s 1, 2, 8, 9, 15, and 16 are rejected under 35 U.S.C. 102( a)(1 ) as being anticipated by KNECKT (US-20230232218-A1) . Regarding claim 1 , KNECKT teaches “A method comprising: obtaining a data unit that includes a header and a data payload; ([KNECKT, para.0004] “Some embodiments include an apparatus, method, and computer program product for encrypting media access control (MAC) Header fields for Wireless LAN (WLAN) privacy enhancement.”) ([KNECKT, para. 0063] “FIG. 8 illustrates example 800 of transmitter 820 and receiver 830 supporting encryption of MAC header fields for WLAN privacy enhancement, according to some embodiments of the disclosure … Example 800 includes transmitter 820 that receives one or more A-MPDU frames from internet/application 810, supports encryption of MAC header fields for WLAN privacy enhancement, and transmits the one or more A-MPDUs OTA with encrypted MAC header bits 330 of FIG. 3A to receiver 830. Receiver 830 supports decryption of MAC header fields for WLAN privacy enhancement”) ([KNECKT, para. 0039] “FIG. 3A illustrates MAC frame 300 supporting encryption of MAC header fields for WLAN privacy enhancement”) ([KNECKT, para.0040] “To improve privacy, some embodiments include identifying those certain MAC header fields, inserting the actual values of those certain MAC header fields in MAC header bits 330 as part of payload 340 that is then encrypted as shown in FIG. 3A.”) performing an encryption operation on the data unit to encapsulate the data payload and at least a portion of the header in an encrypted payload; and ([KNECKT, para. 0043] “For example, a transmitter can encrypt static MAC header bits 332 along with payload 340 of MAC frame 300. A receiver can receive an A-MPDU subframe including MAC frame 300 and BA may be transmitted before decryption of payload 340 (and hence before the decryption of static MAC header bits 332).”) ([KNECKT, para. 0038] “One or more processors 265 can execute the instructions stored in memory 285 to perform operations enabling wireless system 200 to transmit and receive wireless communications, including the functions for encryption of MAC header fields for WLAN privacy enhancement herein.”) wirelessly transmitting a frame that includes the encrypted payload. ([KNECKT, para. 0038] “Transceiver(s) 270 transmits and receives wireless communications signals including wireless communications supporting encryption of MAC header fields for WLAN privacy enhancement according to some embodiments, and may be coupled to one or more antennas 290 (e.g. 290a, 290b)”) ([KNECKT, para.0106] “At 1160, system 200 can transmit the A-MPDU subframe over the air.”) Regarding claim 8 , this claim recites of a apparatus comprising: a memory; a network interface configured to enable network communication; and a processor, wherein the processor is configured to perform operations of method claim 1. Therefore, claim 8 is rejected in a similar manner as in the rejection of claim 1. KNECKT further teaches of “… a network interface configured to enable network communication; and a processor …” ([KNECKT, para.0038] “System 200 includes one or more processors 265, transceiver(s) 270, communication interface 275, communication infrastructure 280, memory 285, and antenna 290. Memory 285 may include random access memory (RAM) and/or cache, and may include control logic (e.g., computer instructions) and/or data. One or more processors 265 can execute the instructions stored in memory 285 to perform operations enabling wireless system 200 to transmit and receive wireless communications, including the functions for encryption of MAC header fields for WLAN privacy enhancement herein.”) Regarding claim 15 , this claim recites of one or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to execute the method of claim 1. Therefore, claim 15 is rejected in a similar manner as in the rejection of claim 1. KNECKT further teaches of “one or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to” ([KNECKT, para. 0038] “System 200 includes one or more processors 265, transceiver(s) 270, communication interface 275, communication infrastructure 280, memory 285, and antenna 290. Memory 285 may include random access memory (RAM) and/or cache, and may include control logic (e.g., computer instructions) and/or data. One or more processors 265 can execute the instructions stored in memory 285 to perform operations enabling wireless system 200 to transmit and receive wireless communications, including the functions for encryption of MAC header fields for WLAN privacy enhancement herein.”) Regarding claims 2, 9, and 16 , KNECKT teaches all limitations of claims 1, 8, and 15. KNECKT further teaches “wherein performing the encryption operation includes encapsulating a source address and a destination address associated with the data unit in the encrypted payload. ([KNECKT, para. 0067] “At 826, transmitter 820 randomizes fields in Frame Control field 310 and/or QoS Control field 320 that correspond to MAC header bits 330. Namely, the following fields may be populated with corresponding OTA values and/or patterns: … Other fields in the MAC header that can be randomized and replaced with an OTA value include transmitter address (TA), receiver address (RA)”) ([KNECKT, para. 0034] “Some embodiments include encrypting actual values of the MAC header fields (e.g., PM, MD, EOSP) in the encrypted payload of a MAC frame. The MAC header fields that previously contained the actual values can be set to all zeroes (e.g., zeroed out), include a dummy value (e.g., a predetermined value), and/or include a randomized value.”) Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim s 3-5, 10-12, and 17-19 are rejected under 35 U.S.C. 103 as being unpatentable over KNECKT (US-20230232218-A1) in view of SANKARAN (US-20190173860-A1), hereinafter KNECKT-SANKARAN . Regarding claims 3, 10, and 17 , KNECKT teaches all limitations of claims 1, 8, and 15. KNECKT further teaches “wherein the data unit is a Media Access Control (MAC) protocol data unit (MPDU) ([KNECKT, para. 0047] “MAC frame 300 can be included in an aggregated MAC protocol data unit (A-MPDU) subframe, and can then be transmitted OTA to a receiver. Since the actual values of those certain MAC header fields in MAC header bits 330 are encrypted in payload 340 when MAC frame 300 is transmitted OTA, even if MAC frame 300 is intercepted (e.g., by an attacker), only the OTA values within header 315 can be obtained.”) ([KNECKT, para. 0005] “The processor of the STA and/or the AP can be configured to set a bit of real time Media Access Control (MAC) header in a payload of an aggregated MAC Protocol Data Unit (A-MPDU) subframe to an actual value associated with a power management (PM) field of a header of the A-MPDU subframe, and then encrypt the payload. After encrypting the payload, the processor can set the PM field in the header to an over the air (OTA) PM value, and transmit the A-MPDU subframe (e.g., over the air.)”) However, KNECKT does not teach “… and wherein performing the encryption operation comprises performing a MAC security (MACsec) operation on the MPDU to encapsulate the MPDU within a MACsec payload.”. In analogous teaching SANKARAN teaches “… and wherein performing the encryption operation comprises performing a MAC security (MACsec) operation on the MPDU to encapsulate the MPDU within a MACsec payload. ([SANKARAN, para. 0014] “To address these issues, the present disclosure describes various examples for using MACsec to encrypt tunnel data packets. In an example, a Media Access Control (MAC) Security (MACsec) capable device may receive a data packet from a host device for tunneling to a controller in a network. The MACsec capable device may encapsulate the data packet with an encapsulation header to generate an encapsulated data packet.”) ([SANKARAN, para. 0026] “An example encapsulation header 200 along with a data packet 220 is illustrated in FIG. 2. The encapsulation header 200 may comprise a destination address field 202 that may include a destination MAC address, a source address field 204 that may include a source MAC address of the port on MACsec capable device 104 that receives the data packet, an Encaps length or type field 206 which may identify, for example, the protocol contained in the payload (for example, IPv4), a pad field 208 for byte alignment, a VLAN tag field 210, and a control byte field 212.”). Thus, given the teaching of SANKARAN, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of MACsec by SANKARAN into the teaching of a method of obtaining a data packet unit, encrypting the date packet unit, and wirelessly transmitting the data packet unit by KNECKT. One of ordinary skill in the art would have been motivated to do so because SANKARAN recognizes the benefits of MACsec ([SANKARAN, para. 0011] “Enterprises are increasingly focusing on securing networks from the inside, and MACsec as layer 2 security protocol may help fill this gap. To ensure the security of wired networks, it may be desirable to implement the MACsec functionality on newer generation of network infrastructure switches.”) Regarding claims 4, 11, and 18 , KNECKT-SANKARAN teaches all limitations of claims 3, 10, and 17. KNECKT further teaches “wherein performing the … operation on the MPDU includes adding a … header to the … payload, the … header including an over-the-air MAC (otaMAC) address of a wireless client device as a destination address and an otaMAC address of a wireless access point device as a source address. ([KNECKT, para. 0005] “The processor of the STA and/or the AP can be configured to set a bit of real time Media Access Control (MAC) header in a payload of an aggregated MAC Protocol Data Unit (A-MPDU) subframe to an actual value associated with a power management (PM) field of a header of the A-MPDU subframe, and then encrypt the payload. After encrypting the payload, the processor can set the PM field in the header to an over the air (OTA) PM value, and transmit the A-MPDU subframe (e.g., over the air.) ”) ([KNECKT, para. 0067] “Namely, the following fields may be populated with corresponding OTA values and/or patterns: TID field 452, A-MSDU present field 458, retry field 412, PM field 414, MD field 416, EOSP field 454, ACK policy indicator 456, and/or +HTC field 418. Other fields in the MAC header that can be randomized and replaced with an OTA value include transmitter address (TA), receiver address (RA), sequence number (SN), packet number (PN), and a Salt.”) ([KNECKT, abstract] “For example, a transceiver of a station (STA) or an access point (AP) can set a real time Media Access Control (MAC) header bit in a payload of an aggregated MAC Protocol Data Unit (A-MPDU) subframe”) ([KNECKT, para. 0057] “For example, a transmitter may be AP MLD 110, AP 112”) ([KNECKT, para. 0063] “For example, receiver 830 can be AP MLD 110, AP 112, AP 114, AP 116, AP 110 that includes a single transceiver, non-AP MLD STA 120, STA 122, STA 124, STA 126, or STA 140 of FIG. 1. Transmitter 820 and/or receiver 830 can be system 200 of FIG. 2.”). SANKARAN teaches of MACsec as seen in the rejection of claim 3. The same rejection and motivation apply. Regarding claims 5, 12, and 19 , KNECKT-SANKARAN teaches all limitations of claims 4, 11, and 18. KNECKT further teaches “wherein the … header includes randomly generated values for a source address and a destination address. ([KNECKT, para. 0054] “AP 510 can determine and set OTA values (e.g., zeroes, dummy value, or randomized value) for EOSP field 454 and/or MD field 416 in header 315 before transmission OTA.”) ([KNECKT, para. 0067] “Other fields in the MAC header that can be randomized and replaced with an OTA value include transmitter address (TA), receiver address (RA), sequence number (SN), packet number (PN), and a Salt.”) SANKARAN teaches of MACsec as seen in the rejection of claim 3. The same rejection and motivation apply . 07-21-aia AIA Claim s 6 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over KNECKT (US-20230232218-A1) in view of SINN (US-10826876-B1) . Regarding claims 6 and 13 , KNECKT teaches all limitations of claims 1 and 8. However, KNECKT does not teach “wherein padding is added to the data payload so that a size of the data unit is a predetermined size, wherein the predetermined size is determined by an access point and wherein the padding is added by a wireless client device that is a source of the data unit.” In analogous teaching SINN teaches “wherein padding is added to the data payload so that a size of the data unit is a predetermined size, wherein the predetermined size is determined by an access point and wherein the padding is added by a wireless client device that is a source of the data unit. ([SINN, col. 5 Lines 25-29] “another example, a packet can be padded out to a Maximum Transmission Unit (MTU) when the packet is followed by a relatively large gap before the next packet. The MTU can be the largest size packet that is allowed for a particular network protocol.”) ([SINN, col. 4 Lines 46-53] “The network devices 110 and 150 can communicate with physical transceiver devices (PHYs) 120 and 140, respectively. As one example, network device 110 can transmit and receive unencrypted link layer packets to and from the PHY 120; and the network device 150 can transmit and receive unencrypted link layer packets to and from the PHY 140”) ([SINN, col. 11 Lines 8-13] “The stream of packets 500 can be processed by the transmit data path of the physical transceiver device to generate the stream of packets 510. The stream of packets 510 has been padded and filled with filler packets so that the link utilization of the stream of packets 510 is closer to 100%”) ([SINN, col. 4 Lines 37-43] “types of network devices 110 and 150 can include … wireless network interface controllers, modems, ISDN terminal adapters, line drivers, wireless access points,”) Thus, given the teaching of SINN, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of padding being added to a data payload by SINN into the teaching of a method of obtaining a data packet unit, encrypting the date packet unit, and wirelessly transmitting the data packet unit by KNECKT. One of ordinary skill in the art would have been motivated to do so because SINN recognizes the need to improve security of computer systems ([SINN, col. 1 Lines 11-15] “As the complexity and ubiquity of distributed computer systems increases, however, maintaining information security can become more challenging even as users of the distributed computer systems place a higher value on the security of their information.”) ([SINN, col. 2 Lines 58-63] “As described herein, the characteristics of network traffic can be encrypted or obscured. In particular, network traffic patterns can be obscured during transmission at the link level by adding padding to frames so that the size of the packets is hidden. The padding can be encrypted so that it appears as random bits to an outside observer.”) 07-21-aia AIA Claim s 7, 14, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over KNECKT (US-20230232218-A1) in view of LEE (US-20160285834-A1) . Regarding claims 7, 14, and 20 , KNECKT teaches all limitations of claims 1, 8, and 15. However, KNECKT does not teach “wherein wirelessly transmitting comprises wirelessly transmitting the frame according to an IEEE 802.11 wireless networking protocol.”. In analogous teaching LEE teaches “wherein wirelessly transmitting comprises wirelessly transmitting the frame according to an IEEE 802.11 wireless networking protocol. ([LEE, para. 0006] “A wireless network, for example a Wireless Local Area Network (WLAN), such as a Wi-Fi network (IEEE 802.11) may include an access point (AP) that may communicate with at least one station (STA) or mobile device.”) ([LEE, para. 0049] “The wireless stations 115 in these examples may communicate according to the WLAN radio and baseband protocol including physical and MAC layers from IEEE 802.11, and its various versions including, but not limited to, 802.11b, 802.11g, 802.11a, 802.11n, 802.11ac, 802.11ad, 802.11ah, and the like. In other implementations, other peer-to-peer connections and/or ad hoc networks may be implemented within WLAN network 100.”) Thus, given the teaching of LEE, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of IEEE 802.11 wireless networking protocol by LEE into the teaching of a method of obtaining a data packet unit, encrypting the date packet unit, and wirelessly transmitting the data packet unit by KNECKT. One of ordinary skill in the art would have been motivated to do so because LEE recognizes the need to improve wireless systems ([LEE, para. 0008] “The described features generally relate to various improved systems, methods, or apparatuses for wireless communications. Such systems, methods, or apparatuses may provide for hiding source or destination addresses to improve privacy and prevent an observer from determining the source or destination of a data frame.”) Pertinent Art 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. HIDLE (US-8775790-B2): This prior art teaches of method includes receiving a data message, from a first embedded node, in a first end point device. The first data message is addressed to a second embedded node. The method also includes encrypting the first data message to produce an encrypted data message, where the encryption is transparent to the first embedded node. The method further includes transmitting the encrypted data message to a second end point device. An apparatus includes a plurality of embedded node ports each configured to communicate with an embedded node. The apparatus also includes an encrypted communications link port configured to communicate with an end point device. The apparatus further includes a controller connected to communicate with the embedded node ports and the encrypted communications link port. In addition, the apparatus includes a storage connected to be read from and written to by the controller. GUAN (US-8386772-B2): This prior art teaches of method for generating a secure association key (SAK), a method for realizing medium access control security (MACsec) and a network device is provided. The method for generating an SAK includes the following steps. A sending key selection protocol (KSP) instance sends a key selection protocol data unit (KSPDU) to the other KSP instances in the same secure connectivity association (CA). The KSPDU includes a secure connectivity association key identifier (CKI) of the instance and information about a MACsec level that the sending KSP instance belongs to. If the receiving KSP instance and the sending KSP instance belong to the CA with the same MACsec level, an SAK is generated based on the KSPDU. The MACsec of multiple levels in a communication network and the secure MACsec network communication with multiple levels are realized, thus ensuring the confidentiality of the network communication . Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFAQ ALI whose telephone number is (571)272-1571. The examiner can normally be reached Mon - Fri 7:30am - 5:30pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.A./ 03/25/2026 /AFAQ ALI/Examiner, Art Unit 2434 /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434 Application/Control Number: 18/981,948 Page 2 Art Unit: 2434 Application/Control Number: 18/981,948 Page 3 Art Unit: 2434
Read full office action

Prosecution Timeline

Dec 16, 2024
Application Filed
Mar 30, 2026
Non-Final Rejection mailed — §101, §102, §103
Jun 08, 2026
Interview Requested
Jun 25, 2026
Applicant Interview (Telephonic)
Jun 25, 2026
Examiner Interview Summary
Jun 26, 2026
Response Filed
Oct 01, 2026
Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750358
NON-CUSTODIAL TOOL FOR BUILDING DECENTRALIZED COMPUTER APPLICATIONS
2y 1m to grant Granted Sep 29, 2026
Patent 12726508
DYNAMIC INTELLIGENT CYBER PLAYBOOKS
2y 4m to grant Granted Sep 01, 2026
Patent 12689649
DETERMINING ADDITIONAL SIGNALS FOR DETERMINING CYBERSECURITY RISK
1y 12m to grant Granted Jul 21, 2026
Patent 12665926
System And Methods Of Defense Against DDoS Attacks For Applications On A Multi-Substrate Multi-Ingress Shared Infrastructure With Multiple Cloud Architectures
1y 9m to grant Granted Jun 23, 2026
Patent 12639404
Authorization of Access Rights Licenses
2y 2m to grant Granted May 26, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+11.9%)
2y 5m (~7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 143 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month