Prosecution Insights
Last updated: August 17, 2026
Application No. 19/045,877

PROVIDING QUANTUM-SAFE COMMUNICATIONS SECURITY OVER AN INSECURE NETWORK

Non-Final OA §103§112
Filed
Feb 05, 2025
Examiner
VU, TAYLOR P
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
73%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
86%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
24 granted / 33 resolved
+14.7% vs TC avg
Moderate +14% lift
Without
With
+13.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
20 currently pending
Career history
62
Total Applications
across all art units

Statute-Specific Performance

§101
12.9%
-27.1% vs TC avg
§103
69.3%
+29.3% vs TC avg
§102
1.8%
-38.2% vs TC avg
§112
15.7%
-24.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 33 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Regarding claims 1, 16, and 20: “…providing a system request to an entropy service…” is indefinite because the “entropy service” are coined terms whose scope is not defined in the claims and is not given any clear, objective meaning in the specification. A person having ordinary skill in the art would not be able to determine, with reasonable certainty, which specific service or operations are encompassed by the entropy service. Regarding claims 2-15 and 17-19: Claims 2-15 and 17-19 do not add any additional elements than those already disclosed in the claims 1 and 15 merely adds further abstract ideas. Furthermore, none of the claims integrate the judicial exception into a practical application. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claims 1, 7, 16, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1) and Sethi et al. (US PGPub No. 20200145236-A1). With respect to claim 1, Goncalves teaches a method, comprising: (¶0009: Accordingly, the embodiments described herein provide a system and method that solve this issue, by permitting incorporation of the most current and strongest encryption schemes in a hybrid secure encryption scheme. ) generating an initial true random number; generating a hybrid key pair based on the initial true random number, (¶0028: Figure 3 illustrates select functional modules of the security module 170 that carries out the functions of the hybrid secure encryption scheme. The sender device 100 then begins the hybrid encryption process. At 355, the sender device 100 generates, for example using the random generator 210 (generating an initial random number as seen in ¶0010: wherein, while both “random” and “pseudo-random” elements or values are mentioned above, for brevity in the following description reference only the term “random” is used, and should be considered as encompassing both true random and pseudo-random elements, values, and generators unless the person skilled in the art would understand from the context that only one or the other is intended. ) and key derivation module 220, a random value ∂ of length L and a symmetric key K. At 365, the encapsulation/decapsulation module 240 then encapsulates both the symmetric key K and the intermediate ciphertext C, using the recipient's public keys, while adding distinct randomness generated from ∂ to each encapsulation (basing off an initial random number). ) wherein the hybrid key pair includes a first key pair generated by a quantum-safe cryptographic algorithm and a second key pair generated by a cryptographic algorithm; (¶0026: Figure 4 depicts an overview of initialization or registration process tat may be followed by each device 100 utilizing the hybrid encryption scheme. At 300, a device 100, such as the sender device, establishes security policies for implementing the scheme. Establishing security policies may establishment of asymmetric and symmetric encryption, key derivation functions, and hash functions, defining length L if L is defined in advance, and key lengths, and identifying information that must be shared among participating devices. The device 100 then generates two asymmetric key pairs 305, 310 (two key pairs). These key pairs may be generated in accordance with the hybrid secure encryption scheme depicted in Table 1. Thus, a first public-secret key pair (pK, sK) may be generated using a selected PKE key generation algorithm Π.sup.asym.KeyGen (cryptographic algorithm) and a second public-secret key pair (eK, dK) may be generated using a selected key encapsulation algorithm K.KeyGen (further in ¶0030: In some implementations, a selected key encapsulation method (e.g., the quantum-resistant algorithm, FrodoKEM) (quantum-safe cryptographic algorithm)) , given appropriate initialization vectors generated at the device 100 (quantum-safe cryptographic algorithm).); Goncalves does not disclose: providing a system request to an entropy service, wherein the system request includes the hybrid key pair; decrypting encrypted quantum entropy data included in a response received from the entropy service, wherein the response includes a public key associated with the entropy service; and utilizing the decrypted encrypted quantum entropy data for cryptographic operations. However, Cap teaches providing a system request to an entropy service, (¶0038-0039: Authentication of clients and establishing a connection through cryptography. KEM (Key Encapsulation Mechanism) utilization. Entropy Refill Figure 1B 107b is used during high volume communications to replenish the clients 120a or 120b entropy pool to continue the post-quantum server communication or Data at Rest process. The Entropy Refill Service offloads symmetric encryption/decryption to the HSM. The Entropy Refill Service provides bulk entropy from the QRNG to the client to maintain the Client’s entropy pool, the advantage allows offline and high-volume key availability. ); wherein the system request includes the hybrid key pair; (¶0039-0042: The Entropy Refill Service pulls in the symmetric key(s) and routing address associated with relevant unique identifiers from Unique Identifier Dataset. As further seen in Figure 1A, 1A 115a and Key Get Figure 1B 115b reaches out to HSM to get keys get decrypted key from database.); decrypting encrypted quantum entropy data included in a response received from the entropy service, (¶0047: Decrypt Figure 1B 113c Decrypt (Data-At-Rest) utilizes Key Get 115b to reach out to the Key Management Service 113a, specifically the Key Get Service 115a to get decryption keys. Decrypt decrypts the data using the Moving Target Design to switch between decryption keys. Symmetric decryption (ADAD) is offloaded to S/HSM. Key Get Service 115a reaches out to HSM to get keys get decrypted key from database. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Cap with regards to the entropy service to the method of Goncalves in order to provide secure communication and prevent malicious actions such as stealing from bad actors (Cap ¶0017). Goncalves in view of Cap does not disclose: wherein the response includes a public key associated with the entropy service; and utilizing the decrypted encrypted quantum entropy data for cryptographic operations. Cap does disclose a server using Authenticated Encryption with Associated Data with symmetric key to decrypt the encrypted text by producing the ephemeral Key Encapsulation Mechanism public key, but Cap does not disclose include the response includes a public key associated with the entropy service and utilizing the decrypted encrypted quantum entropy data for cryptographic operations . However, Sethi teaches wherein the response includes a public key associated with the entropy service; and utilizing the decrypted encrypted quantum entropy data for cryptographic operations. (¶0050: Upon receiving a response from entropy server(s) 5a, 5b, 5c, virtual machine 2 may (in case of encrypted reply) decrypt the respective packets with the public key of the entropy server 5a, 5b, 5c, or verify the signature (in case of signed reply) of messages with the public key of entropy server 5a, 5b, 5c. At arrow A5, the virtual machine 2 may thus decrypts each of the response messages, but at least establishes their validity and if valid uses them as entropy sources. It is noted that it is not necessary for the virtual machine 2 to decrypt the received responses, but only verify the signature (i.e. timestamp) thereof. It should be assumed that an attacker has the same public key available, and can decrypt also the responses.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Sethi with regards to the response includes a public key associated with the entropy service and utilizing the decrypted encrypted quantum entropy data for cryptographic operations to the method of Goncalves in view of Cap in order to mitigate certain types of attacks (e.g., cache timing attacks from unprivileged mode) and enable secure communication (Sethi ¶0017). With respect to claim 7, the combination of Goncalves in view of Cap and Sethi teaches the method of claim 1 (see rejection of claim 1 above), wherein the cryptographic operations include evaluating IPSec tunnels, establishing a quantum-safe transport layer security (TLS) tunnel, and/or providing quantum-safe random numbers to another device in a network. (Cap ¶0026-0027: Hardware Security Module (HSM) Figure 1A 108 all KEM and cryptographic operations are controlled though the HSM. This component has all cryptographic algorithms and systems logic to avoid security side channel attacks on key pairs or symmetric keys, not limited to other elements requiring vaulting protection. The Hardware Security Module (HSM) 108 controls but is not limited to key creation and extraction from the Quantum Random Number Generator 109 and associated storage. Quantum Random Number Generator (QRNG) 109 QRNG delivers random numbers to act as cryptographic keys and other security parameters, deterministic RNG seeding, initialization vectors, nonces, random challenges, authentication and DSA signing. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Cap with regards to the cryptographic operation to the method of Goncalves in view of Sethi in order to provide secure communication and prevent malicious actions such as stealing from bad actors (Cap ¶0017). With respect to claim 16, Goncalves teaches a system, (¶0009: Accordingly, the embodiments described herein provide a system and method that solve this issue, by permitting incorporation of the most current and strongest encryption schemes in a hybrid secure encryption scheme.) comprising: a processor configured to: (¶0069: Code adapted to provide the systems and methods described above may be provided on many different types of computer-readable media including computer storage mechanisms (e.g., CD-ROM, diskette, RAM, flash memory, computer hard drive, etc.) that contain instructions for use in execution by one or more processors to perform the operations described herein. ); generate an initial true random number; is generate a hybrid key pair based on the initial true random number, (¶0028: Figure 3 illustrates select functional modules of the security module 170 that carries out the functions of the hybrid secure encryption scheme. The sender device 100 then begins the hybrid encryption process. At 355, the sender device 100 generates, for example using the random generator 210 (generating an initial random number as seen in ¶0010: wherein, while both “random” and “pseudo-random” elements or values are mentioned above, for brevity in the following description reference only the term “random” is used, and should be considered as encompassing both true random and pseudo-random elements, values, and generators unless the person skilled in the art would understand from the context that only one or the other is intended. ) and key derivation module 220, a random value ∂ of length L and a symmetric key K. At 365, the encapsulation/decapsulation module 240 then encapsulates both the symmetric key K and the intermediate ciphertext C, using the recipient's public keys, while adding distinct randomness generated from ∂ to each encapsulation (basing off an initial random number). ); wherein the hybrid key pair includes a first key pair generated by a quantum-safe cryptographic algorithm and a second key pair generated by a cryptographic algorithm; (¶0026: Figure 4 depicts an overview of initialization or registration process tat may be followed by each device 100 utilizing the hybrid encryption scheme. At 300, a device 100, such as the sender device, establishes security policies for implementing the scheme. Establishing security policies may establishment of asymmetric and symmetric encryption, key derivation functions, and hash functions, defining length L if L is defined in advance, and key lengths, and identifying information that must be shared among participating devices. The device 100 then generates two asymmetric key pairs 305, 310 (two key pairs). These key pairs may be generated in accordance with the hybrid secure encryption scheme depicted in Table 1. Thus, a first public-secret key pair (pK, sK) may be generated using a selected PKE key generation algorithm Π.sup.asym.KeyGen (cryptographic algorithm) and a second public-secret key pair (eK, dK) may be generated using a selected key encapsulation algorithm K.KeyGen (further in ¶0030: In some implementations, a selected key encapsulation method (e.g., the quantum-resistant algorithm, FrodoKEM) (quantum-safe cryptographic algorithm)) , given appropriate initialization vectors generated at the device 100 (quantum-safe cryptographic algorithm).); and a memory coupled to the processor and configured to provide the processor with instructions. (¶0070: Functional units may also be implemented as combinations of software and hardware, such as a processor operating on a set of operational data or instructions. ); Goncalves does not disclose: provide a system request to an entropy service, wherein the system request includes the hybrid key pair; decrypt encrypted quantum entropy data included in a response received from the entropy service, However, Cap teaches provide a system request to an entropy service, (¶0038-0039: Authentication of clients and establishing a connection through cryptography. KEM (Key Encapsulation Mechanism) utilization. Entropy Refill Figure 1B 107b is used during high volume communications to replenish the clients 120a or 120b entropy pool to continue the post-quantum server communication or Data at Rest process. The Entropy Refill Service offloads symmetric encryption/decryption to the HSM. The Entropy Refill Service provides bulk entropy from the QRNG to the client to maintain the Client’s entropy pool, the advantage allows offline and high-volume key availability. ); wherein the system request includes the hybrid key pair; (¶0039-0042: The Entropy Refill Service pulls in the symmetric key(s) and routing address associated with relevant unique identifiers from Unique Identifier Dataset. As further seen in Figure 1A, 1A 115a and Key Get Figure 1B 115b reaches out to HSM to get keys get decrypted key from database.); decrypt encrypted quantum entropy data included in a response received from the entropy service, (¶0047: Decrypt Figure 1B 113c Decrypt (Data-At-Rest) utilizes Key Get 115b to reach out to the Key Management Service 113a, specifically the Key Get Service 115a to get decryption keys. Decrypt decrypts the data using the Moving Target Design to switch between decryption keys. Symmetric decryption (ADAD) is offloaded to S/HSM. Key Get Service 115a reaches out to HSM to get keys get decrypted key from database. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Cap with regards to the entropy service to the method of Goncalves in order to provide secure communication and prevent malicious actions such as stealing from bad actors (Cap ¶0017). Goncalves in view of Cap does not disclose: wherein the response includes a public key associated with the entropy service; and utilize the decrypted encrypted quantum entropy data for cryptographic operations; Cap does disclose a server using Authenticated Encryption with Associated Data with symmetric key to decrypt the encrypted text by producing the ephemeral Key Encapsulation Mechanism public key, but Cap does not disclose include the response includes a public key associated with the entropy service and utilizing the decrypted encrypted quantum entropy data for cryptographic operations . However, Sethi teaches wherein the response includes a public key associated with the entropy service; and utilize the decrypted encrypted quantum entropy data for cryptographic operations; (¶0050: Upon receiving a response from entropy server(s) 5a, 5b, 5c, virtual machine 2 may (in case of encrypted reply) decrypt the respective packets with the public key of the entropy server 5a, 5b, 5c, or verify the signature (in case of signed reply) of messages with the public key of entropy server 5a, 5b, 5c. At arrow A5, the virtual machine 2 may thus decrypts each of the response messages, but at least establishes their validity and if valid uses them as entropy sources. It is noted that it is not necessary for the virtual machine 2 to decrypt the received responses, but only verify the signature (i.e. timestamp) thereof. It should be assumed that an attacker has the same public key available, and can decrypt also the responses.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Sethi with regards to the response includes a public key associated with the entropy service and utilizing the decrypted encrypted quantum entropy data for cryptographic operations to the method of Goncalves in view of Cap in order to mitigate certain types of attacks (e.g., cache timing attacks from unprivileged mode) and enable secure communication (Sethi ¶0017). With respect to claim 20, Goncalves teaches a computer program product embodied in a non-transitory and comprising computer instructions for: (¶0068-0069: Further, there is also provided a non-transitory computer-readable medium storing code which, when executed by one or more processors of a computing system, causes the system to implement one or more of the aspects described above. The data employed by the systems, devices, and methods described herein may be stored in one or more data stores. The media on which the code may be provided is generally considered to be non-transitory or physical. Code executable to configure the systems or devices to perform the methods described above may be downloaded to the memory of a device over a network, such as the Internet.) generating an initial true random number; generating a hybrid key pair based on the initial true random number, (¶0028: Figure 3 illustrates select functional modules of the security module 170 that carries out the functions of the hybrid secure encryption scheme. The sender device 100 then begins the hybrid encryption process. At 355, the sender device 100 generates, for example using the random generator 210 (generating an initial random number as seen in ¶0010: wherein, while both “random” and “pseudo-random” elements or values are mentioned above, for brevity in the following description reference only the term “random” is used, and should be considered as encompassing both true random and pseudo-random elements, values, and generators unless the person skilled in the art would understand from the context that only one or the other is intended. ) and key derivation module 220, a random value ∂ of length L and a symmetric key K. At 365, the encapsulation/decapsulation module 240 then encapsulates both the symmetric key K and the intermediate ciphertext C, using the recipient's public keys, while adding distinct randomness generated from ∂ to each encapsulation (basing off an initial random number). ) wherein the hybrid key pair includes a first key pair generated by a quantum-safe cryptographic algorithm and a second key pair generated by a cryptographic algorithm; (¶0026: Figure 4 depicts an overview of initialization or registration process tat may be followed by each device 100 utilizing the hybrid encryption scheme. At 300, a device 100, such as the sender device, establishes security policies for implementing the scheme. Establishing security policies may establishment of asymmetric and symmetric encryption, key derivation functions, and hash functions, defining length L if L is defined in advance, and key lengths, and identifying information that must be shared among participating devices. The device 100 then generates two asymmetric key pairs 305, 310 (two key pairs). These key pairs may be generated in accordance with the hybrid secure encryption scheme depicted in Table 1. Thus, a first public-secret key pair (pK, sK) may be generated using a selected PKE key generation algorithm Π.sup.asym.KeyGen (cryptographic algorithm) and a second public-secret key pair (eK, dK) may be generated using a selected key encapsulation algorithm K.KeyGen (further in ¶0030: In some implementations, a selected key encapsulation method (e.g., the quantum-resistant algorithm, FrodoKEM) (quantum-safe cryptographic algorithm)) , given appropriate initialization vectors generated at the device 100 (quantum-safe cryptographic algorithm).); Goncalves does not disclose: providing a system request to an entropy service, wherein the system request includes the hybrid key pair; decrypting encrypted quantum entropy data included in a response received from the entropy service, However, Cap teaches providing a system request to an entropy service, (¶0038-0039: Authentication of clients and establishing a connection through cryptography. KEM (Key Encapsulation Mechanism) utilization. Entropy Refill Figure 1B 107b is used during high volume communications to replenish the clients 120a or 120b entropy pool to continue the post-quantum server communication or Data at Rest process. The Entropy Refill Service offloads symmetric encryption/decryption to the HSM. The Entropy Refill Service provides bulk entropy from the QRNG to the client to maintain the Client’s entropy pool, the advantage allows offline and high-volume key availability. ); wherein the system request includes the hybrid key pair; (¶0039-0042: The Entropy Refill Service pulls in the symmetric key(s) and routing address associated with relevant unique identifiers from Unique Identifier Dataset. As further seen in Figure 1A, 1A 115a and Key Get Figure 1B 115b reaches out to HSM to get keys get decrypted key from database.); decrypting encrypted quantum entropy data included in a response received from the entropy service, (¶0047: Decrypt Figure 1B 113c Decrypt (Data-At-Rest) utilizes Key Get 115b to reach out to the Key Management Service 113a, specifically the Key Get Service 115a to get decryption keys. Decrypt decrypts the data using the Moving Target Design to switch between decryption keys. Symmetric decryption (ADAD) is offloaded to S/HSM. Key Get Service 115a reaches out to HSM to get keys get decrypted key from database. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Cap with regards to the entropy service to the method of Goncalves in order to provide secure communication and prevent malicious actions such as stealing from bad actors (Cap ¶0017). Goncalves in view of Cap does not disclose: wherein the response includes a public key associated with the entropy service; and utilizing the decrypted encrypted quantum entropy data for cryptographic operations. Cap does disclose a server using Authenticated Encryption with Associated Data with symmetric key to decrypt the encrypted text by producing the ephemeral Key Encapsulation Mechanism public key, but Cap does not disclose include the response includes a public key associated with the entropy service and utilizing the decrypted encrypted quantum entropy data for cryptographic operations . However, Sethi teaches wherein the response includes a public key associated with the entropy service; and utilizing the decrypted encrypted quantum entropy data for cryptographic operations. (¶0050: Upon receiving a response from entropy server(s) 5a, 5b, 5c, virtual machine 2 may (in case of encrypted reply) decrypt the respective packets with the public key of the entropy server 5a, 5b, 5c, or verify the signature (in case of signed reply) of messages with the public key of entropy server 5a, 5b, 5c. At arrow A5, the virtual machine 2 may thus decrypts each of the response messages, but at least establishes their validity and if valid uses them as entropy sources. It is noted that it is not necessary for the virtual machine 2 to decrypt the received responses, but only verify the signature (i.e. timestamp) thereof. It should be assumed that an attacker has the same public key available, and can decrypt also the responses.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Sethi with regards to the response includes a public key associated with the entropy service and utilizing the decrypted encrypted quantum entropy data for cryptographic operations to the method of Goncalves in view of Cap in order to mitigate certain types of attacks (e.g., cache timing attacks from unprivileged mode) and enable secure communication (Sethi ¶0017). Claims 2, 3, 17, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), and Pabijanskas et al. (US Pat No. 12010102-B1). With respect to claim 2, the combination of Goncalves in view of Cap and Sethi teaches the method of claim 1 (see rejection of claim 1 above), but does not disclose wherein the quantum-safe cryptographic algorithm is Kyber768. However, Pabijanskas teaches wherein the quantum-safe cryptographic algorithm is Kyber768. (¶0050: The second pair of keys (referred to herein as a short-term Kyber key pair or, more broadly, as short-term high-security key pair or as quantum-resistant key pair) can be generated using Kyber-512, Kyber-768, or any other Kyber key sizes.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Pabijanskas with regards to the quantum-safe cryptographic algorithm is Kyber768 to the method of Goncalves in view of Cap, and Sethi in order to ensure long-term security in the evolving landscape of information technology (e.g., securing against future quantum threats) while providing efficiency and low computational overhead (Pabijanskas ¶0017). With respect to claim 3, the combination of Goncalves in view of Cap and Sethi teaches the method of claim 1 (see rejection of claim 1 above), but does not disclose wherein the cryptographic algorithm is X25519. However, Pabijanskas teaches wherein the cryptographic algorithm is X25519. (¶0045-0046: The second pair of keys (referred to herein as a short-term Kyber key pair or, more broadly, as short-term high-security key pair or as quantum-resistant key pair) can be generated using Kyber-512, Kyber-768, or any other Kyber key sizes.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Pabijanskas with regards to the cryptographic algorithm is X25519 to the method of Goncalves in view of Cap, and Sethi in order to enable to an key exchange (Pabijanskas ¶0045-0046). With respect to claim 17, the combination of Goncalves in view of Cap and Sethi teaches the system of claim 16 (see rejection of claim 16 above), but does not disclose wherein the quantum-safe cryptographic algorithm is Kyber768. However, Pabijanskas teaches wherein the quantum-safe cryptographic algorithm is Kyber768. (¶0050: The second pair of keys (referred to herein as a short-term Kyber key pair or, more broadly, as short-term high-security key pair or as quantum-resistant key pair) can be generated using Kyber-512, Kyber-768, or any other Kyber key sizes.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Pabijanskas with regards to the quantum-safe cryptographic algorithm is Kyber768 to the method of Goncalves in view of Cap and Sethi in order to ensure long-term security in the evolving landscape of information technology (e.g., securing against future quantum threats) while providing efficiency and low computational overhead (Pabijanskas ¶0017). With respect to claim 18, the combination of Goncalves in view of Cap and Sethi teaches the system of claim 16 (see rejection of claim 16 above), but does not disclose wherein the cryptographic algorithm is X25519. However, Pabijanskas teaches wherein the cryptographic algorithm is X25519. (¶0045-0046: The second pair of keys (referred to herein as a short-term Kyber key pair or, more broadly, as short-term high-security key pair or as quantum-resistant key pair) can be generated using Kyber-512, Kyber-768, or any other Kyber key sizes.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Pabijanskas with regards to the cryptographic algorithm is X25519 to the method of Goncalves in view of Cap, and Sethi in order to enable to an key exchange (Pabijanskas ¶0045-0046). Claims 4 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), and Fang et al. (US PGPub No. 20160315816-A1). With respect to claim 4, the combination of Goncalves in view of Cap and Sethi teaches the method of claim 1 (see rejection of claim 1 above), but does not disclose wherein the system request is an HTTP GET request. However, Fang teaches wherein the system request is an HTTP GET request. (¶0010: Another side, the system uses web service to take Hyper Transfer Protocol (HTTP) get request from the Internet based Application in which the UID of the device instruction set is placed. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Fang with regards to the system request being an HTTP GET request to the method of Goncalves in view of Cap and Sethi in order to enable secure communication and idempotence (Fang ¶0006). With respect to claim 5, the combination of Goncalves in view of Cap, Sethi, and Fang teaches the method of claim 4 (see rejection of claim 4 above),wherein the HTTP GET request is in JSON format. (Fang ¶0048: Within the Function, System will deploy web services to obtain HTTP get request from the Application as XML/JSON format in which IoT device UID is included. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Fang with regards to the HTTP GET request being in JSON format to the method of Goncalves in view of Cap, and Sethi in order to enable secure communication and idempotence (Fang ¶0006). Claim 6 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), and Rule et al. (US PG Pub No. 20250132916-A1). With respect to claim 6, the combination of Goncalves in view of Cap and Sethi teaches the method of claim 1 (see rejection of claim 1 above), but does not disclose wherein the system request includes an applications programming interface (API) endpoint associated with the entropy service, a request size, and public keys associated with the hybrid key pair. However, Rule teaches wherein the system request includes an applications programming interface (API) endpoint associated with the entropy service, a request size, and public keys associated with the hybrid key pair. (¶0138: In step 913, the client application prepares a header including the pubic key and a payload. In step 914, the client application signs the header using the private key. In step 916, the client application creates and transmits an API call request to an API endpoint administered by a resource server for accessing resources. The payload herein in the header corresponds to the API call request. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Rule with regards to the system request including an application programming interface (API) endpoint to the method of Goncalves in view of Cap and Sethi in order to increase security (Rule ¶0003-0005). With respect to claim 19, the combination of Goncalves in view of Cap and Sethi teaches the system of claim 16 (see rejection of claim 16 above), but does not disclose wherein the system request includes an applications programming interface (API) endpoint associated with the entropy service, a request size, and public keys associated with the hybrid key pair. However, Rule teaches wherein the system request includes an applications programming interface (API) endpoint associated with the entropy service, a request size, and public keys associated with the hybrid key pair. (¶0138: In step 913, the client application prepares a header including the pubic key and a payload. In step 914, the client application signs the header using the private key. In step 916, the client application creates and transmits an API call request to an API endpoint administered by a resource server for accessing resources. The payload herein in the header corresponds to the API call request. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Rule with regards to the system request including an application programming interface (API) endpoint to the method of Goncalves in view of Cap and Sethi in order to increase security (Rule ¶0003-0005). Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), and Schmatz et al. (US PG Pub No. 20210126781-A1). With respect to claim 8, the combination of Goncalves in view of Cap and Sethi teaches the method of claim 1 (see rejection of claim 1 above), but does not disclose wherein the entropy service generates a plurality of quantum random numbers and generates a key pair using one of the quantum random numbers. However, Schmatz teaches wherein the entropy service generates a plurality of quantum random numbers and generates a key pair using one of the quantum random numbers. (¶0093: For example, preferred embodiments aim at using a known (but cryptographically non-secure) entropy to securely derive a key on a HSM, and using the result to seed a random number generator, which is then used to generate a PQS key pair. The PQS key pair is used for a cryptographic operation (e.g., for signature or key encapsulation) and then deleted. Whenever the key pair is needed again, one recreates the key pair by retrieving the stored entropy and deriving a key using the on-HSM key.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Schmatz with regards to the entropy service generating a plurality of quantum random numbers and a key pair to the method of Goncalves in view of Cap and Sethi in order to protect against attack by a sufficiently powerful quantum computer running a Shor algorithm or Grover algorithm and enable secure communications (Schmatz ¶0012). Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), Schmatz et al. (US PG Pub No. 20210126781-A1), and Nix et al. (US Pat No. 9351162-B2). With respect to claim 9, the combination of Goncalves in view of Cap, Sethi, and Schmatz teaches the method of claim 8 (see rejection of claim 8 above), but does not disclose wherein the key pair generated by the entropy service is generated by a cryptographic algorithm. However, Nix teaches wherein the key pair generated by the entropy service is generated by a cryptographic algorithm. (¶0137: As seen in Figure 1c, the module 101 could derive the PKI key pair using a set of cryptographic algorithms and a key pair generation algorithm. The module 101 could derive the PKI key pair using a random number generator 128 and a set of cryptographic algorithms 141, where the random number generator 128 uses input from a sensor 101f and/or a clock 160 in order to obtain a random number with a high degree of information entropy. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Schmatz with regards to the key pair to the method of Goncalves in view of Cap, Sethi, and Schmatz in order to enable secure communication (Nix ¶0015). Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), Schmatz et al. (US PG Pub No. 20210126781-A1), and Pabijanskas et al. (US Pat No. 12010102-B1). With respect to claim 10, the combination of Goncalves in view of Stapleton, Cap, Sethi, Schmatz, and Nix teaches the method of claim 9 (see rejection of claim 9 above), but does not disclose wherein the cryptographic algorithm is X25519. However, Pabijanskas teaches wherein the cryptographic algorithm is X25519. (¶0045-0046: The second pair of keys (referred to herein as a short-term Kyber key pair or, more broadly, as short-term high-security key pair or as quantum-resistant key pair) can be generated using Kyber-512, Kyber-768, or any other Kyber key sizes.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Pabijanskas with regards to the cryptographic algorithm is X25519 to the method of Goncalves in view of Cap, Sethi, Schmatz, and Nix in order to enable to an key exchange (Pabijanskas ¶0045-0046). Claim 11 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), Schmatz et al. (US PG Pub No. 20210126781-A1), and Bisheh Niasar et al. (US PGPub No. 20240413995-A1). With respect to claim 11, the combination of Goncalves in view of Cap, Sethi, and Schmatz teaches the method of claim 8 (see rejection of claim 8 above), but does not disclose wherein the entropy service generates a public key and a shared secret. However, Bisheh Nisar teaches wherein the entropy service generates a public key and a shared secret. (¶0081: As seen in Figure 8, the architecture 800 can be implemented using HLS. The Kyber architecture 800 shows a data flow indicated by arrows. Typically, a first device, such as the device 880 performs key generation to generate a secret key (sk) 898 and a public key (pk) 812, using keygen circuit 884. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Bisheh Niasar with regards to the entropy service to the method of Goncalves in view of Cap, Sethi, and Schmatz in order to enable confidential communication and prevent malicious attacks via classical and quantum computers (Bisheh ¶0001). With respect to claim 12, the combination of Goncalves in view of Cap, Sethi, Schmatz, and Bisheh Niasar teaches the method of claim 11 (see rejection of claim 11 above), wherein the public key is generated using a quantum-safe cryptographic algorithm with one of the quantum random numbers as a seed. (Bisheh Niasar ¶0084: The keygen circuit 884 receives a seed 889, n 890, q 892, and k 894. The seed 889 is a random number (sometimes called a pseudorandom number). The seed 889 can be generated using a random number generator. The seed 889 can be generated by sampling a uniform distribution. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Bisheh Niasar with regards to the public key to the method of Goncalves in view of Cap, Sethi, and Schmatz in order to enable confidential communication and prevent malicious attacks via classical and quantum computers (Bisheh Niasar ¶0001). Claim 13 is rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), Schmatz et al. (US PG Pub No. 20210126781-A1), Bisheh Niasar et al. (US PGPub No. 20240413995-A1), and Pabijanskas et al. (US Pat No. 12010102-B1). With respect to claim 13, the combination of Goncalves in view of Cap, Sethi, Schmatz, and Bisheh Niasar teaches the method of claim 11 (see rejection of claim 11 above), but does not disclose wherein the shared secret is generated using a private key of the key pair generated by the entropy service and a public key provided in the system request. However, Pabijanskas teaches wherein the shared secret is generated using a private key of the key pair generated by the entropy service and a public key provided in the system request. (¶0045: The first pair of keys (referred to herein as a short-term x25519 key pair) can be a pair of cryptographic keys used in the x25519 key exchange algorithm, which is an elliptic curve Diffie-Hellman (ECDH) algorithm that provides a secure method for two parties to establish a shared secret key over an insecure channel. Thus, in this case, the short-term key pair can be referred to as a Curve25519 key pair. The x25519 key pair includes a private key (short-term private x25519 key) and a public key (short-term public x25519 key). The short-term private x25519 key is a randomly generated secret that is kept confidential at the VPN client 302.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Pabijanskas with regards to the cryptographic algorithm is X25519 to the method of Goncalves in view of Cap, Sethi, Schmatz, and Bisheh Niasar in order to enable to an key exchange (Pabijanskas ¶0045). Claim 14 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Goncalves et al. (US Pat No.11431498-B2) in view of Cap et al. (US PGPub No. 20230353349-A1), Sethi et al. (US PGPub No. 20200145236-A1), Schmatz et al. (US PG Pub No. 20210126781-A1), Bisheh Niasar et al. (US PGPub No. 20240413995-A1), and Wu et al. (US PG Pub No. 20180337782-A1). With respect to claim 14, the combination of Goncalves in view of Cap, Sethi, Schmatz, and Bisheh Niasar teaches the method of claim 11 (see rejection of claim 11 above), but does not disclose wherein the entropy service encrypts quantum entropy data using the shared secret and a cryptographic algorithm. However, Wu teaches wherein the entropy service encrypts quantum entropy data using the shared secret and a cryptographic algorithm. (¶0094-0096: As seen in Figure 8C, provides an illustrative diagram 831, used to explain optional encryption function used in avatarization. the encryption software typically uses a shared secret key of the device (e.g., key.sub.Bob, 841), once again, optionally stored in protected memory 815. The encryption software also in this example generates a secondary key 843, comprising a nonce such as a time stamp and also identifies a session key (PSK) 845, which it will use in a high entropy format preserving (FP) encryption process 846.To prepare the use By “format preserving,” it is meant that in association with this encryption methodology, the encryption output will represent the same number space as the input and thus also in this example be represented as a 64-character string. By “high entropy,” it is meant that the encryption process is robust in generating outputs which differ widely in value in the encrypted number space, and are capable of producing values distributed throughout the encrypted number space, based on variation in the input values. As noted by numeral 865, the encryption process is advantageously a completely reversible process such that, given knowledge of the keys used to perform encryption (e.g., the shared secret key, secondary key, PSK and so forth, as appropriate), it is possible to completely recover the input string from cipher text 851 output by the encryption process. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Wu with regards to the entropy service to the method of Goncalves in view of Cap, Sethi, Schmatz, and Bisheh Niasar in order to heighten the source entropy and tamper/forgery-resistance (Wu ¶0095). With respect to claim 15, the combination of Goncalves in view of Cap, Sethi, Schmatz, Bisheh Niasar, and Wu teaches the method of claim 14 (see rejection of claim 14 above), wherein the entropy service generates the response that includes io the encrypted quantum entropy data, the public key generated by the entropy service, an initialization vector, a nonce, and an encryption tag. (Wu ¶0094: As seen in Figure 8C, provides an illustrative diagram 831, used to explain optional encryption function used in avatarization. the encryption software typically uses a shared secret key of the device (e.g., key.sub.Bob, 841), once again, optionally stored in protected memory 815. The encryption software also in this example generates a secondary key 843, comprising a nonce such as a time stamp and also identifies a session key (PSK) 845, which it will use in a high entropy format preserving (FP) encryption process 846); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Wu with regards to the entropy service to the method of Goncalves in view of Cap, Sethi, Schmatz, and Bisheh Niasar in order to heighten the source entropy and tamper/forgery-resistance (Wu ¶0095). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Kisley et al. (US PGPub No. 20220321331-A1) discloses method that includes encrypting an authenticated random value retrieved from a trusted source using a cipher key QSA (Quantum Safe Algorithm) public key. Further shown in Figure 6, the method includes creating, at a first computer, first public and private quantum safe algorithm (QSA) keys and first public and private elliptic curve cryptography (ECC) keys (601), receiving, at a second computer, authenticated forms of the first public QSA and ECC keys (602) and creating, at the second computer, a cipher key and second public and private ECC keys (603). Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAYLOR P VU whose telephone number is (703)756-1218. The examiner can normally be reached MON - FRI (7:30 - 5:00). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /T.P.V./Examiner, Art Unit 2437 /MENG LI/Primary Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Feb 05, 2025
Application Filed
Jun 10, 2026
Non-Final Rejection (signed) — §103, §112
Aug 03, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12652530
SECURE TRANSACTION USING POINT-OF-USER-INTERACTION APPARATUS AND METHOD THEREOF
3y 11m to grant Granted Jun 09, 2026
Patent 12652301
MULTI-PROCESS SHARED-MEMORY MESSAGE COMMUNICATION
3y 4m to grant Granted Jun 09, 2026
Patent 12639425
THWARTING CONTROL PLANE ATTACKS WITH DISPLACED AND DILATED ADDRESS SPACES
4y 3m to grant Granted May 26, 2026
Patent 12632540
SECURITY DEFENDING METHOD AND ELECTRONIC APPARATUS
3y 4m to grant Granted May 19, 2026
Patent 12619737
A METHOD AND SYSTEM FOR SECURITY RISK IDENTIFICATION AND CONTROLLING RELEASE MANAGEMENT OF SOFTWARE APPLICATION WITH VULNERABLE CODES
2y 11m to grant Granted May 05, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
73%
Grant Probability
86%
With Interview (+13.6%)
3y 3m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 33 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month