CTNF 19/011,963 CTNF 89584 DETAILED ACTION Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. 12-151 AIA 26-51 12-51 Status of Claims The following is a Non-Final Office Action in response to applicant’s filing on January 07, 2025. Claims 1-20 are pending, of which claims 1, 9 and 1 are in independent form. Drawings 06-22 AIA The drawings are objected to because Fig. 2, steps 240 and 260 are having the same label as " transmit the set of server-encrypted decryption keys ". However, paragraph [0096] of the decryption discloses “ transmits the list of FHE encrypted values to the client 202 (260) ” . Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Specification 07-29 AIA The disclosure is objected to because of the following informalities: The paragraphs need to be renumbered in proper format, such as: [0100], [0101]… Appropriate correction is required. Claim Rejections - 35 USC § 112 07-30-02 AIA The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 07-34-01 Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 recites the limitation “the client encrypted query ” in line 11. There is insufficient antecedent basis for this limitation in the claim, since it is unclear which query was encrypted and there is no antecedent basis for “a client query ”. The examiner suggests to clarify the difference between “the query” and “a client query” to rectify the issue. Claim 1 recites the limitation “converting… into a number within a specific range ”. The term “ specific range ” is a relative term and renders the scope of the claim indefinite, the claim does not specify how the range is determined. Accordingly, the claim fails to set forth a clear boundary of the invention and renders the scope of the claim uncertain. The same reasons apply to independent claims 9 and 17 and their dependent claims. Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA Claim s 1-2, 6, 8-10, 14, and 16-18 are rejected under 35 U.S.C. 103 as being unpatentable over Williams et al. (US 2018/0212751 A1), hereinafter Williams in view of CEBERE et al. (US 2022/0140996 A1), hereinafter CEBERE . Regarding claim 1, Williams disclose s a computer-implemented method, comprising: obtaining, by one or more processors, a server encrypted identifier (Williams, Para. 0028, when data source 322 1 -322 N includes an encrypted “social security number” field, the social security numbers are all encrypted, as opposed to some social security numbers being encrypted and others unencrypted. Data stored in and/or retrieved from target data source 322 1 -322 N can be encrypted and/or decrypted as described in relation to FIG. 1.) ; generating, by the one or more processors and using a hash function on the server encrypted identifier, an unsigned integer (Williams, Para. 0034, the keyed hash function and term generation function can be used to divide data in target data source 322 1 -322 N , so the correct records in target data source 322 1 -322 N are mapped to the correct encrypted query piece, so the operation can be conducted in the right way) and (Williams, Para. 0036, each of one or more servers 320 1 -320 N can extract a set of term components {T} from target data source 322 1 -322 N using the term generation function) ; converting, by the one or more processors, the unsigned integer into a converted number within a specified range (Williams, Para. 0039, the range of keyed hash function H(T) is partitioned into a set of vectors {c_T}. H(T)={H(T): T in {T}} denotes the range of keyed hash function H over the set of term elements {T}. C(H(T))={c_T: c_T is the d-dimensional vector partitioning the range of keyed hash function H(T) into d-many bitwise components, |C(H(T))|=|H(T)|=|{T}|. For example, if d=3 and H(T)=000001001111) ; Williams does not explicitly disclose splitting, by the one or more processors, the converted number into a shard index and a bucket identifier; generating, by the one or more processors, a query using the shard index and the bucket identifier; transmitting, by the one or more processors, the client encrypted query to a server; and receiving, by the one or more processors and from the server, a set of server encrypted results in response to submission of the client encrypted query. However, CEBERE teaches splitting, by the one or more processors, the converted number into a shard index and a bucket identifier (CEBERE, Para. 0047, each table 51 a - c uses a distinct hash function to determine the respective indices. In an exemplary cuckoo hash scheme, records are inserted serially, by computing an index for each record using a first hash function) and (Para. 0044) ; generating, by the one or more processors, a query using the shard index and the bucket identifier (CEBERE, Para. 0006, to formulate a private query comprising an encryption of a hash index indicative of a location of a record within a domain name database, the hash index encrypted according to a homomorphic encryption procedure) ; transmitting, by the one or more processors, the client encrypted query to a server (CEBERE, Para. 0084, when issuing a query, the client may send the bucket/category index in cleartext or ciphertext) ; and receiving, by the one or more processors and from the server, a set of server encrypted results in response to submission of the client encrypted query (CEBERE, Para. 0084, the server then transmits the resulting encrypted vector C back to the client. The homomorphic property ensures that decrypting C produces the same result as applying the function F to the unencrypted bitmap I). Williams and CEBERE are both considered to be analogous to the claim invention because they are in the same field of partitioning the queries based on the provided index that is submitted with each query. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Williams to incorporate the teachings of CEBERE to include splitting, by the one or more processors, the converted number into a shard index and a bucket identifier (CEBERE, Para. 0047) ; generating, by the one or more processors, a query using the shard index and the bucket identifier (CEBERE, Para. 0006) ; transmitting, by the one or more processors, the client encrypted query to a server (CEBERE, Para. 0084) ; and receiving, by the one or more processors and from the server, a set of server encrypted results in response to submission of the client encrypted query (CEBERE, Para. 0084). Doing so would aid to reduce the size of the database and therefore the complexity of the PIR calculations and the size of queries and server replies. Computer experiments have revealed that reducing database size to 65536 records allows keeping the average time required to carry out a DNS lookup at under 1 s, which makes applications of the current systems and methods commercially and technically viable (CEBERE, Para. 0092). Regarding claim 2, the combination of Williams in view of CEBERE teaches the computer-implemented method of claim 1, wherein generating the query comprises: generating an indicator vector, wherein an element having an index equal to the bucket identifier is set to a value of 1, and other elements of the indicator vector are set to a value of 0 (CEBERE, Para. 0044, I={0, 1, 0}. The client may then homomorphically encrypt the respective bitmap and transmit it to the server); encrypting the indicator vector using fully homomorphic encryption (FHE) to obtain a corresponding FHE encrypted bucket vector (CEBERE, Para. 0044, the client may then homomorphically encrypt the respective bitmap and transmit it to the server); and including the corresponding FHE encrypted bucket vector and the shard index in the query (CEBERE, Para. 0045, an index attached to each record may indicate a location of the respective record within the respective data repository). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Williams to incorporate the teachings of CEBERE to include generating an indicator vector, wherein an element having an index equal to the bucket identifier is set to a value of 1, and other elements of the indicator vector are set to a value of 0 (CEBERE, Para. 0044); encrypting the indicator vector using fully homomorphic encryption (FHE) to obtain a corresponding FHE encrypted bucket vector (CEBERE, Para. 0044); and including the corresponding FHE encrypted bucket vector and the shard index in the query (CEBERE, Para. 0045). Doing so would aid to reduce the size of the database and therefore the complexity of the PIR calculations and the size of queries and server replies. Computer experiments have revealed that reducing database size to 65536 records allows keeping the average time required to carry out a DNS lookup at under 1 s, which makes applications of the current systems and methods commercially and technically viable (CEBERE, Para. 0092). Regarding claim 6, the combination of Williams in view of CEBERE teaches the computer-implemented method of claim 1, further comprising generating a decryption key based on the server encrypted identifier (CEBERE, Para. 0074, generate a private-public key pair, or and encryption-decryption key pair using a homomorphic encryption scheme). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Williams to incorporate the teachings of CEBERE to include further comprising generating a decryption key based on the server encrypted identifier (CEBERE, Para. 0074). Doing so would aid to reduce the size of the database and therefore the complexity of the PIR calculations and the size of queries and server replies. Computer experiments have revealed that reducing database size to 65536 records allows keeping the average time required to carry out a DNS lookup at under 1 s, which makes applications of the current systems and methods commercially and technically viable (CEBERE, Para. 0092). Regarding claim 8, the combination of Williams in view of CEBERE teaches the computer-implemented method of claim 6, further comprising decrypting the server encrypted results using the generated decryption key (CEBERE, Para. 0043, wherein decrypting a result of such calculations produces the same output as applying the respective calculations to an unencrypted version of the same data). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Williams to incorporate the teachings of CEBERE to include further comprising decrypting the server encrypted results using the generated decryption key (CEBERE, Para. 0043). Doing so would aid to reduce the size of the database and therefore the complexity of the PIR calculations and the size of queries and server replies. Computer experiments have revealed that reducing database size to 65536 records allows keeping the average time required to carry out a DNS lookup at under 1 s, which makes applications of the current systems and methods commercially and technically viable (CEBERE, Para. 0092). Regarding claim 9, the claim is interpreted and rejected for the same rational set forth in claim 1. Regarding claim 10, the claim is interpreted and rejected for the same rational set forth in claim 2. Regarding claim 14, the claim is interpreted and rejected for the same rational set forth in claim 2. Regarding claim 16, the claim is interpreted and rejected for the same rational set forth in claim 8. Regarding claim 17, the claim is interpreted and rejected for the same rational set forth in claim 1 and 9. Regarding claim 18, the claim is interpreted and rejected for the same rational set forth in claim 2 and 10 . 07-21-aia AIA Claim s 3-4, 5, 11-13, 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Williams et al. (US 2018/0212751 A1), hereinafter Williams in view of CEBERE et al. (US 2022/0140996 A1), hereinafter CEBERE and further in view of Laine et al. (US 2019/0325082 A1), hereinafter Laine . Regarding claim 3, the combination of Williams in view of CEBERE does not explicitly teach the computer-implemented method of claim 2, wherein generating the indicator vector comprises generating the indicator vector to have a length based on a number (P) of database shards in a results database. However, Laine teaches wherein generating the indicator vector comprises generating the indicator vector to have a length based on a number (P) of database shards in a results database (Laine, Para. 0054, the number of buckets b, as a function of the database size (n)) . Williams, CEBERE and Laine are all considered to be analogous to the claim invention because they are in the same field of partitioning the queries based on the provided index that is submitted with each query. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Williams and CEBERE to incorporate the teachings of Laine to include wherein generating the indicator vector comprises generating the indicator vector to have a length based on a number (P) of database shards in a results database (Laine, Para. 0054). Doing so would aid to put the benefits and costs in context, the multi-query PIR scheme found in Pung was evaluated. Pung's protocol, like PBCs, was probabilistic and significantly improved over existing batch codes in terms of costs (Laine, Para. 0099). Regarding claim 4, the combination of Williams and CEBERE in view of Laine teaches the computer-implemented method of claim 3, wherein generating the indicator vector comprises generating the indicator vector to have a length based on the number of database shards in the results database and a largest possible value (n) of the converted number (Laine, Para. 0061, using w hash functions to hash a key to w candidate buckets approximates an independent and uniform random assignment of a ball to w bins). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Williams and CEBERE to incorporate the teachings of Laine to wherein generating the indicator vector comprises generating the indicator vector to have a length based on the number of database shards in the results database and a largest possible value (n) of the converted number (Laine, Para. 0061). Doing so would aid to put the benefits and costs in context, the multi-query PIR scheme found in Pung was evaluated. Pung's protocol, like PBCs, was probabilistic and significantly improved over existing batch codes in terms of costs (Laine, Para. 0099). Regarding claim 5, the combination of Williams and CEBERE in view of Laine teaches the computer-implemented method of claim 4, wherein generating the indicator vector comprises generating the indicator vector to have a length of n/P (Laine, Para. 0061, the max load is n/w where all balls map to the same w candidate buckets, but there are useful bounds that hold with high probability). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Williams and CEBERE to incorporate the teachings of Laine to wherein generating the indicator vector comprises generating the indicator vector to have a length of n/P (Laine, Para. 0061). Doing so would aid to put the benefits and costs in context, the multi-query PIR scheme found in Pung was evaluated. Pung's protocol, like PBCs, was probabilistic and significantly improved over existing batch codes in terms of costs (Laine, Para. 0099). Regarding claim 11, the claim is interpreted and rejected for the same rational set forth in claim 3. Regarding claim 12, the claim is interpreted and rejected for the same rational set forth in claim 4. Regarding claim 13, the claim is interpreted and rejected for the same rational set forth in claim 5. Regarding claim 19, the claim is interpreted and rejected for the same rational set forth in claim 3 and 11. Regarding claim 20, the claim is interpreted and rejected for the same rational set forth in claim 4 and 12 . 07-21-aia AIA Claim s 7 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Williams et al. (US 2018/0212751 A1), hereinafter Williams in view of CEBERE et al. (US 2022/0140996 A1), hereinafter CEBERE and further in view of the article entitled “HMAC-based Extract-and-Expand Key Derivation Function (HKDF)” by Krawczyk . Regarding claim 7, the combination of Williams in view of CEBERE does not explicitly teach the computer-implemented method of claim 6, wherein generating the decryption key comprises implementing a hash-based message authentication code cryptographic key derivation function that results into at least one secret key. However, Krawczyk teaches wherein generating the decryption key comprises implementing a hash-based message authentication code cryptographic key derivation function that results into at least one secret key (Krawczyk, Page 5, A major goal of key derivation functions is to ensure that, when applying the KDF to any two values IKM and IKM' sampled from the (same) source distribution, the resultant keys OKM and OKM' are essentially independent of each other (in a statistical or computational sense)). Williams, CEBERE and Krawczyk are all considered to be analogous to the claim invention because they are in the same field of partitioning the queries based on the provided index that is submitted with each query. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Williams and CEBERE to incorporate the teachings of Krawczyk to include wherein generating the decryption key comprises implementing a hash-based message authentication code cryptographic key derivation function that results into at least one secret key (Krawczyk, Page 5). Doing so would aid to accommodate a wide range of KDF requirements while minimizing the assumptions about the underlying hash function (Krawczyk, Page. 1). Regarding claim 15, the claim is interpreted and rejected for the same rational set forth in claim 7 . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892 . Any inquiry concerning this communication or earlier communications from the examiner should be directed to GITA FARAMARZI whose telephone number is (571)272-0248. The examiner can normally be reached Monday- Friday 9:00 am- 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GITA FARAMARZI/Examiner, Art Unit 2496 /JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496 Application/Control Number: 19/011,963 Page 2 Art Unit: 2496 Application/Control Number: 19/011,963 Page 3 Art Unit: 2496 Application/Control Number: 19/011,963 Page 4 Art Unit: 2496