Prosecution Insights
Last updated: October 02, 2026
Application No. 19/048,689

METHOD AND SYSTEM FOR ENHANCING SECURITY OF A SYSTEM

Final Rejection §101§103
Filed
Feb 07, 2025
Examiner
VU, TAYLOR P
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Marvell Asia Pte. Ltd.
OA Round
2 (Final)
69%
Grant Probability
Favorable
3-4
OA Rounds
1y 8m
Est. Remaining
78%
With Interview

Examiner Intelligence

Grants 69% — above average
69%
Career Allowance Rate
25 granted / 36 resolved
+11.4% vs TC avg
Moderate +8% lift
Without
With
+8.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
25 currently pending
Career history
66
Total Applications
across all art units

Statute-Specific Performance

§101
11.8%
-28.2% vs TC avg
§103
71.5%
+31.5% vs TC avg
§102
1.5%
-38.5% vs TC avg
§112
15.0%
-25.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 36 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments The present office action is responsive to communication filed on 07/16/2026. Claims 1-43 are currently pending. Applicant’s arguments filed on 07/16/2026 have been fully considered but they are not fully persuasive. On page 7 of the Remarks, Applicant’s amendment with regards to the claim objection to claim 29 has been considered and fully persuasive. Therefore, the claim objection has been withdrawn. On page 8 of the Remarks, Applicant’s arguments with regards to the claim interpretation with regards to 35 USC 112(f) pertaining to the key provisioning and management unit have been fully considered and are persuasive. Therefore, the claim interpretation in view of 35 USC 112(f) with regards to the key provisioning and management unit has been withdrawn, but the claim interpretation for claim 43 will still be ascertained. Claim 43 recites, “A system comprising: a means for managing one or more cryptographical keys associated with one or more cryptographical operations by a hardware component; a means for generating a cryptographic key within an internal environment; and a means for transmitting the generated cryptographic key…” will be under 35 USC 112(f) because the term the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function. On pages 8-9 of the Remarks, Applicant contends: “ Claims 1-43 are allegedly rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The Office concludes that claim 1 recites the abstract idea of a mental process, characterizing, for example, "managing cryptographic keys," "generating cryptographic keys," and "transmitting generated cryptographic keys" as acts capable of being performed in the human mind. Applicant respectfully disagrees. The Federal Circuit has explained that a claim recites a mental process only when the claimed steps can practically be performed in the human mind or by a human using pen and paper. CyberSource Corp. v. Retail Decisions, Inc., 654 F.3d 1366, 1372-73 (Fed. Cir. 2011). Conversely, claims that require technological operations that cannot practically be performed mentally do not recite a mental process. See, SiRF Tech., Inc. v. Int'l Trade Comm'n, 601 F.3d 1319, 1333 (Fed. Cir. 2010) (claims patent eligible because they "could not, as a practical matter, be performed entirely in a human's mind"); SRIInt'l, Inc. v. Cisco Sys., Inc., 930 F.3d 1295, 1304 (Fed. Cir. 2019) (claims not directed to a mental process because "the human mind is not equipped to detect suspicious activity by using network monitors and analyzing network packets as recited by the claims"). Claim 1 recites generating a cryptographic key within a key provisioning and management unit, transmitting the generated cryptographic key to a hardware component, and doing so without exposing the generated cryptographic key in plaintext format to an application. These are technological cryptographic operations performed by specialized computing hardware. They cannot practically be performed in the human mind or with pen and paper. Accordingly, claim 1 does not recite a mental process under the standard set forth in CyberSource, SiRF, and SRI. Because claim 1 does not recite a mental process, the Office has not established that claim 1 recites an abstract idea under Step 2A, Prong One of the 2019 Revised Patent Subject Matter Eligibility Guidance. The rejection should therefore be withdrawn. Independent claims 15, 29, and 42 recite substantially similar features, including managing cryptographic keys, generating cryptographic keys, and transmitting generated cryptographic keys to hardware components without exposing the generated cryptographic keys in plaintext format to applications. Accordingly, for at least the reasons discussed above with respect to claim 1, those claims likewise do not recite mental processes and are not directed to an abstract idea under Step 2A, Prong One. The rejection of independent claims 15, 29, and 42 under 35 U.S.C. § 101 should therefore likewise be withdrawn. The remaining claims recite patent eligible subject matter in view of their dependencies and further in view of the features recited therein.” Examiner disagrees. Applicant’s contention that the independent claims are not directed to a judicial exception is not persuasive because under the broadest reasonable interpretation and in view of the 2019 Revised Patent Subject Matter Eligibility Guidance. While the applicant asserts the elements of cryptographic operations which constitutes no more than invocation of conventional components of a computer performing their ordinary functions. First, the claims fail to specify how the alleged additional elements of managing, generating, transmitting of cryptographic keys achieve any asserted improvement to the computer functionality itself. The recited components are described as result-oriented without reciting any non-generic or nonconventional technical means for accomplishing these operations. Under Alice Corp. v. CLS Bank, 573 U.S. 208 (2014), and In re TLI Communications LLC is 823 F.3d 607 (Fed. Cir. 2016), merely applying technological cryptographic operations performed by specialized computing hardware to a cryptographic key does not transform an abstract idea into patent-eligible subject matter. Further, the claims do not recite any particular structure that departs from well-known practices in hardware, software, and computer application. Similar claim formulation – using HSM (e.g., a key provisioning and management unit), transmission of a cryptographic key, and the generation of a cryptographic key – have been consistently found abstract where they apply known computer techniques to achieve results. Nor the applicant’s arguments to Step 2A because there is no particular machine beyond generic computer is claimed, no transformation of an article to a different state or this is affected beyond the transmission of information and management of keys, are merely data gathering and post-solution activity. Further the claimed specialized computing hardware and technological does not represent an improvement to the functioning of a computer itself or to another technology in a sense contemplated by MPEP 2106.05(a). Thus, the elements do not meaningfully limit the abstract idea so as to integrate it into a practical application. In the absence of concrete, non-generic implementation details in the claim that change the way the computer performs these operations to a technical level, the additional elements, individually and in combination, are well-understood routine, and conventional activities in the field. Accordingly, the claims remain directed to an abstract idea under Step 2A and the rejection 35 USC 101 is reasserted. On pages 10-12, Applicant contends with respect to claims 1-5, 13-19, 27-32, and 40-43 are rejected under 35 U.S.C. 103 as being unpatentable over Kushtagi et al. (US PGPub No. 20230177171-A1 ) in view of Pecoraro et al. (US Pat No. 12425191-B1) and Buonora et al. (US Pat No. 11475140-B1) does not disclose the limitation “wherein transmit the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to the application”. Examiner respectfully disagrees. Buonora does discloses the transmission of generated cryptographic key as seen in paragraph [0034] – [0035] and in combination of Figure 1,” In some embodiments, a request indicates one or more identifiers of keys, in which cryptography service 102 obtain one or more keys from one or more secure devices, such as HSM 104” shows generation the cryptographic key, and one in the ordinary skill in the art could come to that conclusion that the ability to obtain the key would be through a transmission of a cryptographic key. Further, Buonora discloses, “In at least one embodiment, a cryptography service 102 obtains one or more encrypted keys out-of-band or separate from the provisioning request—for example, an edge device may create, select, or otherwise determine one or more keys to be supported by a cryptography service instance, encrypt the one or more keys using a secret that is accessible to the cryptography service 102, and then transmit the encrypted one or more keys to the cryptography service 102” which shows the cryptographic key being transmitted to a hardware component. Therefore, based on at least the above paragraphs, Examiner respectfully discloses that Buonora teaches the limitation. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: A system comprising: a means for managing one or more cryptographical keys associated with one or more cryptographical operations by a hardware component; a means for generating a cryptographic key within an internal environment; and a means for transmitting the generated cryptographic key… in claim 43. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-43 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claim 1 recites a system which appears to be a ‘machine’ and one of the four statutory subject matter categories of invention (Step 1 of the Subject Matter Eligibility Test). However, the claim appears to not qualify for a streamlined analysis thus a full eligibility and thus a fully eligibility analysis is necessary (Step 2A and Step 2B of the Subject Matter Eligibility Test). In Step 2A, Prong One, examiners evaluate whether the claim recites a judicial i.e., whether a law of nature, natural phenomenon, or abstract idea is set forth or described in the claims. The claim recites the steps of: “…manage one or more cryptographic keys…” “…generate a cryptographic key…” “…transmit the generated cryptographic key…” (data gathering) The steps performing amount to an abstract idea which falls under a judicial exception (Step 2A, Prong 1, of Subject Matter Eligibility). Abstract ideas falls in the category. The abstract idea falls in the categories of a mental process, for evaluation, judgments, and opinions, and mathematical concepts (MPEP 2106.04(a)(2) & MPEP 2106.06) such as managing, generation, and the transmission of generated cryptographic key. For example, the courts found that the claim “related to system to monitor access to protected health information in which a rule is created, an audit log is compared with the rule, and a notification is provided if rule is fulfilled”, was directed to an abstract idea of detecting misuse in a computer environment based on analysis log files, while also finding that the claims simply automated a process that was commonly performed without computers in the past. Furthermore, the court found that the claims simply related to the collection and analysis of data is an abstract idea in which there is not inventive concept, and there are no details in the claim that describe an improvement to existing computer technology, Fairwarning IP, LLC v. Iatric Sys, Inc., No. 15-1985 (Fed. Cir. 2016). In Step 2A, Prong Two, examiner determine whether the claim as a whole integrates the judicial exception into a practical application to disqualify abstract as a judicial exception. However, the judicial exception in claim 1 is not integrated into practical because the generically recited elements: …a hardware component… …a key provisioning and management unit… do not add meaningful limitation to an abstract idea because they amount to simply implementing the abstract idea on a computer. The implementation of the hardware component and key provision and management unit enabling human decision making without using the cryptographic key in any meaningful to improve the functioning of a computer or another technology without reference to what is well-understood, routine, and conventional activity. The claim do not include additional elements that are sufficient to amount to significantly more than the judicial exception because simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, e.g., a claim to an abstract idea requiring no more than a generic computer to perform generic computer function that are well-understood, routine and conventional activities previously known to the industry, as discussed in Alice Corp., 573 U.S. at 225, 110 USPQ2d at 1984. Thus, the analysis concludes is ineligible under 35 U.S.C. § 101 as it is directed to a judicial exception. Regarding to claim 2-14: Claims 2-14 do not add any additional elements than those already disclosed in claim 1, and merely adds further abstract ideas. Furthermore, none of the claims integrate the judicial exception into a practical application. Claim 15 recites a system which appears to be a ‘machine’ and one of the four statutory subject matter categories of invention (Step 1 of the Subject Matter Eligibility Test). However, the claim appears to not qualify for a streamlined analysis thus a full eligibility and thus a fully eligibility analysis is necessary (Step 2A and Step 2B of the Subject Matter Eligibility Test). In Step 2A, Prong One, examiners evaluate whether the claim recites a judicial i.e., whether a law of nature, natural phenomenon, or abstract idea is set forth or described in the claims. The claim recites the steps of: “…manage one or more cryptographic keys…” “…generate a cryptographic key…” “…transmit the generated cryptographic key…” (data gathering) The steps performing amount to an abstract idea which falls under a judicial exception (Step 2A, Prong 1, of Subject Matter Eligibility). Abstract ideas falls in the category. The abstract idea falls in the categories of a mental process, for evaluation, judgments, and opinions, and mathematical concepts (MPEP 2106.04(a)(2) & MPEP 2106.06) such as managing, generation, and the transmission of generated cryptographic key. For example, the courts found that the claim “related to system to monitor access to protected health information in which a rule is created, an audit log is compared with the rule, and a notification is provided if rule is fulfilled”, was directed to an abstract idea of detecting misuse in a computer environment based on analysis log files, while also finding that the claims simply automated a process that was commonly performed without computers in the past. Furthermore, the court found that the claims simply related to the collection and analysis of data is an abstract idea in which there is not inventive concept, and there are no details in the claim that describe an improvement to existing computer technology, Fairwarning IP, LLC v. Iatric Sys, Inc., No. 15-1985 (Fed. Cir. 2016). In Step 2A, Prong Two, examiner determine whether the claim as a whole integrates the judicial exception into a practical application to disqualify abstract as a judicial exception. However, the judicial exception in claim 15 is not integrated into practical because the generically recited elements: …a plurality of hardware components and plurality of software components … …a hardware security module (HSM)… do not add meaningful limitation to an abstract idea because they amount to simply implementing the abstract idea on a computer. The implementation of hardware security module enabling human decision making without using the cryptographic key in any meaningful to improve the functioning of a computer or another technology without reference to what is well-understood, routine, and conventional activity. The claim do not include additional elements that are sufficient to amount to significantly more than the judicial exception because simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, e.g., a claim to an abstract idea requiring no more than a generic computer to perform generic computer function that are well-understood, routine and conventional activities previously known to the industry, as discussed in Alice Corp., 573 U.S. at 225, 110 USPQ2d at 1984. Thus, the analysis concludes is ineligible under 35 U.S.C. § 101 as it is directed to a judicial exception. Regarding to claim 15-28: Claims 15-28 do not add any additional elements than those already disclosed in claim 15, and merely adds further abstract ideas. Furthermore, none of the claims integrate the judicial exception into a practical application. Claim 29 recites a hardware security module which appears to be a ‘machine’ and one of the four statutory subject matter categories of invention (Step 1 of the Subject Matter Eligibility Test). However, the claim appears to not qualify for a streamlined analysis thus a full eligibility and thus a fully eligibility analysis is necessary (Step 2A and Step 2B of the Subject Matter Eligibility Test). In Step 2A, Prong One, examiners evaluate whether the claim recites a judicial i.e., whether a law of nature, natural phenomenon, or abstract idea is set forth or described in the claims. The claim recites the steps of: “…manage one or more cryptographic keys…” “…generate a cryptographic key…” “…transmit the generated cryptographic key…” (data gathering) The steps performing amount to an abstract idea which falls under a judicial exception (Step 2A, Prong 1, of Subject Matter Eligibility). Abstract ideas falls in the category. The abstract idea falls in the categories of a mental process, for evaluation, judgments, and opinions, and mathematical concepts (MPEP 2106.04(a)(2) & MPEP 2106.06) such as managing, generation, and the transmission of generated cryptographic key. For example, the courts found that the claim “related to system to monitor access to protected health information in which a rule is created, an audit log is compared with the rule, and a notification is provided if rule is fulfilled”, was directed to an abstract idea of detecting misuse in a computer environment based on analysis log files, while also finding that the claims simply automated a process that was commonly performed without computers in the past. Furthermore, the court found that the claims simply related to the collection and analysis of data is an abstract idea in which there is not inventive concept, and there are no details in the claim that describe an improvement to existing computer technology, Fairwarning IP, LLC v. Iatric Sys, Inc., No. 15-1985 (Fed. Cir. 2016). In Step 2A, Prong Two, examiner determine whether the claim as a whole integrates the judicial exception into a practical application to disqualify abstract as a judicial exception. However, the judicial exception in claim 29 is not integrated into practical because the generically recited elements: …a hardware security module… …an internal memory component … …an interface… do not add meaningful limitation to an abstract idea because they amount to simply implementing the abstract idea on a computer. The implementation of the hardware security module enabling human decision making without using the cryptographic key and hardware security module in any meaningful to improve the functioning of a computer or another technology without reference to what is well-understood, routine, and conventional activity. The claim do not include additional elements that are sufficient to amount to significantly more than the judicial exception because simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, e.g., a claim to an abstract idea requiring no more than a generic computer to perform generic computer function that are well-understood, routine and conventional activities previously known to the industry, as discussed in Alice Corp., 573 U.S. at 225, 110 USPQ2d at 1984. Thus, the analysis concludes is ineligible under 35 U.S.C. § 101 as it is directed to a judicial exception. Regarding to claim 30-41: Claims 30-41 do not add any additional elements than those already disclosed in claim 29, and merely adds further abstract ideas. Furthermore, none of the claims integrate the judicial exception into a practical application. Claim 42 recites a method which appears to be a ‘process’ and one of the four statutory subject matter categories of invention (Step 1 of the Subject Matter Eligibility Test). However, the claim appears to not qualify for a streamlined analysis thus a full eligibility and thus a fully eligibility analysis is necessary (Step 2A and Step 2B of the Subject Matter Eligibility Test). In Step 2A, Prong One, examiners evaluate whether the claim recites a judicial i.e., whether a law of nature, natural phenomenon, or abstract idea is set forth or described in the claims. The claim recites the steps of: “…managing one or more cryptographic keys…” (mental processes -concepts performed in the human mind (including observation, evaluation, judgement, opinion)) “…generating a cryptographic key…” (mental processes -concepts performed in the human mind (including observation, evaluation, judgement, opinion)) “…transmitting the generated cryptographic key…” (data gathering) The steps performing amount to an abstract idea which falls under a judicial exception (Step 2A, Prong 1, of Subject Matter Eligibility). Abstract ideas falls in the category. The abstract idea falls in the categories of a mental process, for evaluation, judgments, and opinions, and mathematical concepts (MPEP 2106.04(a)(2) & MPEP 2106.06) such as managing, generation, and the transmission of generated cryptographic key. For example, the courts found that the claim “related to system to monitor access to protected health information in which a rule is created, an audit log is compared with the rule, and a notification is provided if rule is fulfilled”, was directed to an abstract idea of detecting misuse in a computer environment based on analysis log files, while also finding that the claims simply automated a process that was commonly performed without computers in the past. Furthermore, the court found that the claims simply related to the collection and analysis of data is an abstract idea in which there is not inventive concept, and there are no details in the claim that describe an improvement to existing computer technology, Fairwarning IP, LLC v. Iatric Sys, Inc., No. 15-1985 (Fed. Cir. 2016). In Step 2A, Prong Two, examiner determine whether the claim as a whole integrates the judicial exception into a practical application to disqualify abstract as a judicial exception. However, the judicial exception in claim 42 is not integrated into practical because the generically recited elements: …hardware component… …internal environment… do not add meaningful limitation to an abstract idea because they amount to simply implementing the abstract idea on a computer. The implementation of the hardware component enabling human decision making without using the cryptographic key in any meaningful to improve the functioning of a computer or another technology without reference to what is well-understood, routine, and conventional activity. The claim do not include additional elements that are sufficient to amount to significantly more than the judicial exception because simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, e.g., a claim to an abstract idea requiring no more than a generic computer to perform generic computer function that are well-understood, routine and conventional activities previously known to the industry, as discussed in Alice Corp., 573 U.S. at 225, 110 USPQ2d at 1984. Thus, the analysis concludes is ineligible under 35 U.S.C. § 101 as it is directed to a judicial exception. Claim 43 recites a system which appears to be a ‘machine’ and one of the four statutory subject matter categories of invention (Step 1 of the Subject Matter Eligibility Test). However, the claim appears to not qualify for a streamlined analysis thus a full eligibility and thus a fully eligibility analysis is necessary (Step 2A and Step 2B of the Subject Matter Eligibility Test). In Step 2A, Prong One, examiners evaluate whether the claim recites a judicial i.e., whether a law of nature, natural phenomenon, or abstract idea is set forth or described in the claims. The claim recites the steps of: “…managing one or more cryptographic keys…” (mental processes -concepts performed in the human mind (including observation, evaluation, judgement, opinion)) “…generating a cryptographic key…” (mental processes -concepts performed in the human mind (including observation, evaluation, judgement, opinion)) “…transmitting the generated cryptographic key…” (data gathering) The steps performing amount to an abstract idea which falls under a judicial exception (Step 2A, Prong 1, of Subject Matter Eligibility). Abstract ideas falls in the category. The abstract idea falls in the categories of a mental process, for evaluation, judgments, and opinions, and mathematical concepts (MPEP 2106.04(a)(2) & MPEP 2106.06) such as managing, generation, and the transmission of generated cryptographic key. For example, the courts found that the claim “related to system to monitor access to protected health information in which a rule is created, an audit log is compared with the rule, and a notification is provided if rule is fulfilled”, was directed to an abstract idea of detecting misuse in a computer environment based on analysis log files, while also finding that the claims simply automated a process that was commonly performed without computers in the past. Furthermore, the court found that the claims simply related to the collection and analysis of data is an abstract idea in which there is not inventive concept, and there are no details in the claim that describe an improvement to existing computer technology, Fairwarning IP, LLC v. Iatric Sys, Inc., No. 15-1985 (Fed. Cir. 2016). In Step 2A, Prong Two, examiner determine whether the claim as a whole integrates the judicial exception into a practical application to disqualify abstract as a judicial exception. However, the judicial exception in claim 43 is not integrated into practical because the generically recited elements: …hardware component… do not add meaningful limitation to an abstract idea because they amount to simply implementing the abstract idea on a computer. The implementation of the hardware component enabling human decision making without using the cryptographic key in any meaningful to improve the functioning of a computer or another technology without reference to what is well-understood, routine, and conventional activity. The claim do not include additional elements that are sufficient to amount to significantly more than the judicial exception because simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, e.g., a claim to an abstract idea requiring no more than a generic computer to perform generic computer function that are well-understood, routine and conventional activities previously known to the industry, as discussed in Alice Corp., 573 U.S. at 225, 110 USPQ2d at 1984. Thus, the analysis concludes is ineligible under 35 U.S.C. § 101 as it is directed to a judicial exception. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claims 1-5, 13-19, 27-32, and 40-43 are rejected under 35 U.S.C. 103 as being unpatentable over Kushtagi et al. (US PGPub No. 20230177171-A1 ) in view of Pecoraro et al. (US Pat No. 12425191-B1) and Buonora et al. (US Pat No. 11475140-B1 ). With respect to claim 1, Kushtagi teaches a system comprising: a hardware component for running an application supported by the hardware component; and ( Abstract: A cryptography agent is implemented serve as an intermediary for a client executing on an unsecure portion of a machine to bring greater hardware-based security the client application.) a key provisioning and management unit configured to manage one or more cryptographical keys associated with one or more cryptographical operations by the hardware component; ( ¶0017: As seen in Figure 2, the server side 10B includes a key management system (KMS), which is (or includes) a secure server. The KMS 20 may be used a vault to store confidential information, such as digital keys, authentication credentials, certificates personal identification information (PII), etc., in a centralized repository. The security of the KMS 20 is enhanced through a hardware security module (HSM) 24. In that regard, the HSM 24 includes a physical hardware device (e.g., a computing device) that safeguards and manages the confidential information (e.g., digital keys, authentication credentials, certificates, PII) at least in part via encryption and decryption and/or other forms of cryptography. Further in ¶0033 wherein , even though cryptography agent 14 receives the confidential information from the KMS 20, the cryptographic agent 14 still does not direct access to the contents of the confidential information, since it is application 12 to use the encrypted confidential information, for example using the cryptographic operations, the encrypted confidential information must first be decrypted from the inside the enclave 16.); Kushtagi does not disclose: cryptographical keys associated with one or more cryptographical operations by the hardware component; However, Pecoraro teaches cryptographical keys associated with one or more cryptographical operations by the hardware component; ( ¶0039: An HSM, or Hardware Security Module, is a specialized and tamper-resistant hardware device designed to securely store and manage cryptographic keys and perform cryptographic operations. HSMs are used to enhance the security of sensitive data by ensuring that keys are protected from physical attacks and unauthorized access. They are commonly employed in applications requiring high levels of security, such as secure communications, digital signatures, and data encryption.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Pecoraro with regards to the cryptographic keys to the method of Kushtagi in order to protect the keys from physical attacks and unauthorized access (Pecoraro : ¶0039 ). Kushtagi in view of Pecoraro does not disclose: generate a cryptographic key within an internal environment of the key provisioning and management unit; and transmit the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to the application. However, Buonora teaches generate a cryptographic key within an internal environment of the key provisioning and management unit; and ( ¶0037: A hardware security module, such as HSM 104 illustrated in Figure 1, may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. ); transmit the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to the application. ( ¶0032-0033: Upon receipt of a request, a cryptography service 102 may generate a key and encrypt the generated key using a key specified by the KeyID. In some embodiments, the request may generate a plaintext data key and the corresponding ciphertext copy of the data key, encrypted by the key identified by the KeyID. In at least one embodiment, cryptography service 102 is utilized to provision an edge device with cryptographic keys that can be used to fulfill client requests to perform cryptographic operations. In at least one embodiment, cryptography service 102 receives a provisioning request from a client to establish itself as a cryptography service instance.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 2, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), wherein the key provisioning and management unit is a hardware security module (HSM). (Kushtagi ¶0017: As seen in Figure 1, the HSM 24 includes a physical hardware device (e.g., a computing device) that safeguards and manages the confidential information (e.g., digital keys, authentication credentials, certificates, PII) at least in part via encryption and decryption and/or other forms of cryptography. In some embodiments, the HSM 24 may include a plug-in card or another suitable external device that attaches directly into the KMS 20. ); With respect to claim 3, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), wherein the cryptographic key is generated by another hardware component within the key provisioning and management unit. ( Buonora ¶0022: Figure 1 shows an illustrative example of computing environment 100 in which a device obtains code to provision a protected execution environment comprising a cryptography service instance. A cryptography service 102 may include a network of one or more devices, such as a hardware security module (HSM) 104, a trusted platform module (TPM), a cryptographic processor, and/or variations thereof.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 4, the combination of Kushtagi in view of Pecoraro Buonora teaches the system of claim 1 (see rejection of claim 1 above), wherein the cryptographic key is generated by a software component within the internal environment of the key provisioning and management unit. ( Buonora ¶0022-0024: In an embodiment, a cryptography service 102 is a collection of computing resources collectively configured to manage and use cryptographic keys for clients of the computing resource service provider 126. Clients may communicate to cryptography service 102 via application programming interface (API) requests, which may be web service API requests.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the cryptographic key being generated by software component within the internal environment of the key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect aspects of data, such as by providing cryptographically verifiable assurances of confidentiality, integrity, and/or authenticity of the data (Buonora : ¶0023 ). With respect to claim 5, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), wherein the generated cryptographic key is encrypted by the key provisioning and management unit before being sent to the hardware component. ( Buonora ¶0023: Cryptography service 102 may provide encryption keys, such as a data key (DK), which may be encrypted using a managed key (MK), contained within the cryptography service 102. Authenticity may refer to cryptographically verifiable assurances that a message was created by a party purporting to be the author of the message. Integrity may refer to cryptographically verifiable assurances that a received message was not modified either intentionally (e.g., by a malicious party) or unintentionally (e.g., as a result of signal loss during transmission) from its original form when the message was transmitted. Confidentiality may refer to cryptographically verifiable assurances that the message may only be understood by the recipient and/or other intended parties (e.g., by transmitting an encrypted message that may only be decrypted using a secret key that is accessible to recipient). ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to encryption of the generated cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect aspects of data, such as by providing cryptographically verifiable assurances of confidentiality, integrity, and/or authenticity of the data (Buonora : ¶0023 ). With respect to claim 13 , the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), wherein the key provisioning and management unit managing one or more cryptographic keys includes one or more of key generation, key export, key deletion, and secured key storage. (Buonora ¶0037-0038: In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. An HSM may delete cryptographic keys stored in the HSM upon detection of tampering of or unauthorized access to data of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 14, the combination of Kushtagi in view of Pecoraro Buonora teaches the system of claim 1 (see rejection of claim 1 above), wherein the key provisioning and management unit is further configured to store the generated cryptographic key within an internal hardware component within the key provisioning and management unit. (Buonora ¶0037-0038: In at least some embodiment, a protected execution environment can be executed within the context of a security module such as a hardware security module (HSM). An HSM may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. HSMs provide cryptographic key generation and storage, and perform cryptographic operations for authorized clients of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 15, Kushtagi teaches a system comprising: a plurality of hardware components and a plurality of software components running on the plurality of hardware components, ( Abstract: A cryptography agent is implemented serve as an intermediary for a client executing on an unsecure portion of a machine to bring greater hardware-based security the client application.) a hardware security module (HSM) configured to manage one or more cryptographical keys associated with one or more cryptographical operations by the plurality of hardware components; (¶0017: As seen in Figure 1, the HSM 24 includes a physical hardware device (e.g., a computing device) that safeguards and manages the confidential information (e.g., digital keys, authentication credentials, certificates, PII) at least in part via encryption and decryption and/or other forms of cryptography. In some embodiments, the HSM 24 may include a plug-in card or another suitable external device that attaches directly into the KMS 20. ); Kushtagi does not disclose: cryptographical keys associated with one or more cryptographical operations by the plurality of hardware components; However, Pecoraro teaches cryptographical keys associated with one or more cryptographical operations by the hardware component; ( ¶0039: An HSM, or Hardware Security Module, is a specialized and tamper-resistant hardware device designed to securely store and manage cryptographic keys and perform cryptographic operations. HSMs are used to enhance the security of sensitive data by ensuring that keys are protected from physical attacks and unauthorized access. They are commonly employed in applications requiring high levels of security, such as secure communications, digital signatures, and data encryption.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Pecoraro with regards to the cryptographic keys to the method of Kushtagi in order to protect the keys from physical attacks and unauthorized access (Pecoraro : ¶0039 ). Kushtagi in view of Pecoraro does not disclose: wherein each software component of the plurality of software components is associated with a respective hardware component of the plurality of hardware components; and generate a cryptographic key within an internal environment of the HSM; and transmit the generated cryptographic key to one hardware component of the plurality of hardware components without exposing the generated cryptographic key in plaintext format to the plurality of software components. However, Buonora teaches wherein each software component of the plurality of software components is associated with a respective hardware component of the plurality of hardware components; and ( ¶0022-0024: In an embodiment, a cryptography service 102 is a collection of computing resources collectively configured to manage and use cryptographic keys for clients of the computing resource service provider 126. Clients may communicate to cryptography service 102 via application programming interface (API) requests, which may be web service API requests.); generate a cryptographic key within an internal environment of the HSM; and ( ¶0037: A hardware security module, such as HSM 104 illustrated in Figure 1, may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. ); transmit the generated cryptographic key to one hardware component of the plurality of hardware components without exposing the generated cryptographic key in plaintext format to the plurality of software components. ( ¶0032-0035: As seen in Figure 1, a cryptography service 102 may generate executable code based at least in part on one or more keys. A cryptography service 102 may obtain one or more keys and generate code for an enclave that stores the one or more keys as enclave data within the enclave. Code for an enclave may be generated such that keys resident to the enclave may be protected by the enclave and never exported from the enclave in plaintext format. Data, such as executable code or keys, stored within an enclave may be inaccessible outside of the enclave environment within an edge device, including to privileged components of the edge device such as VMMs, kernels, BIOS firmware, and OS software (without exposing the generated cryptographic key in plaintext format to plurality of software components). Further in ¶0037 explicitly discloses cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the software component and the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 16, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the generated cryptographic key is not exposed to hardware components of the plurality of hardware components other than the one hardware component. ( Buonora ¶0015 A cryptography service can provide executable code to an edge device that, when executed by the edge device, causes the edge device to provision a cryptography service instance within a protected execution environment. A protected execution environment may be implemented as an enclave that protects access to cryptographic keys such that cryptographic keys resident to the enclave are designed to never be exposed outside of the enclave in a plaintext format.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the software component and the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 ). With respect to claim 17, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the cryptographic key is generated by a software component within an internal environment of the HSM. ( Buonora ¶0022-0024: In an embodiment, a cryptography service 102 is a collection of computing resources collectively configured to manage and use cryptographic keys for clients of the computing resource service provider 126. Clients may communicate to cryptography service 102 via application programming interface (API) requests, which may be web service API requests.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the cryptographic key being generated by software component within the internal environment of the key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect aspects of data, such as by providing cryptographically verifiable assurances of confidentiality, integrity, and/or authenticity of the data (Buonora : ¶0023 ). With respect to claim 18, the combination of Kushtagi in view of Pecoraro Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the cryptographic key is generated by another hardware component within an internal environment of the HSM. ( Buonora ¶0022: Figure 1 shows an illustrative example of computing environment 100 in which a device obtains code to provision a protected execution environment comprising a cryptography service instance. A cryptography service 102 may include a network of one or more devices, such as a hardware security module (HSM) 104, a trusted platform module (TPM), a cryptographic processor, and/or variations thereof.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 19, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the generated cryptographic key is encrypted by the HSM before being sent to the one hardware component. ( Buonora ¶0023: Cryptography service 102 may provide encryption keys, such as a data key (DK), which may be encrypted using a managed key (MK), contained within the cryptography service 102. Authenticity may refer to cryptographically verifiable assurances that a message was created by a party purporting to be the author of the message. Integrity may refer to cryptographically verifiable assurances that a received message was not modified either intentionally (e.g., by a malicious party) or unintentionally (e.g., as a result of signal loss during transmission) from its original form when the message was transmitted. Confidentiality may refer to cryptographically verifiable assurances that the message may only be understood by the recipient and/or other intended parties (e.g., by transmitting an encrypted message that may only be decrypted using a secret key that is accessible to recipient). ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to encryption of the generated cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect aspects of data, such as by providing cryptographically verifiable assurances of confidentiality, integrity, and/or authenticity of the data (Buonora : ¶0023 ). With respect to claim 13 , the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), wherein the key provisioning and management unit managing one or more cryptographic keys includes one or more of key generation, key export, key deletion, and secured key storage. (Buonora ¶0037-0038: In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. An HSM may delete cryptographic keys stored in the HSM upon detection of tampering of or unauthorized access to data of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 14, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), wherein the key provisioning and management unit is further configured to store the generated cryptographic key within an internal hardware component within the key provisioning and management unit. (Buonora ¶0037-0038: In at least some embodiment, a protected execution environment can be executed within the context of a security module such as a hardware security module (HSM). An HSM may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. HSMs provide cryptographic key generation and storage, and perform cryptographic operations for authorized clients of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 15, Kushtagi teaches a system comprising: a plurality of hardware components and a plurality of software components running on the plurality of hardware components, ( Abstract: A cryptography agent is implemented serve as an intermediary for a client executing on an unsecure portion of a machine to bring greater hardware-based security the client application.) a hardware security module (HSM) configured to manage one or more cryptographical keys associated with one or more cryptographical operations by the plurality of hardware components; (¶0017: As seen in Figure 1, the HSM 24 includes a physical hardware device (e.g., a computing device) that safeguards and manages the confidential information (e.g., digital keys, authentication credentials, certificates, PII) at least in part via encryption and decryption and/or other forms of cryptography. In some embodiments, the HSM 24 may include a plug-in card or another suitable external device that attaches directly into the KMS 20. ); Kushtagi does not disclose: However, Pecoraro teaches cryptographical keys associated with one or more cryptographical operations by the hardware component; ( ¶0039: An HSM, or Hardware Security Module, is a specialized and tamper-resistant hardware device designed to securely store and manage cryptographic keys and perform cryptographic operations. HSMs are used to enhance the security of sensitive data by ensuring that keys are protected from physical attacks and unauthorized access. They are commonly employed in applications requiring high levels of security, such as secure communications, digital signatures, and data encryption.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Pecoraro with regards to the cryptographic keys to the method of Kushtagi in order to protect the keys from physical attacks and unauthorized access (Pecoraro : ¶0039 ). Kushtagi in view of Pecoraro does not disclose: wherein each software component of the plurality of software components is associated with a respective hardware component of the plurality of hardware components; and generate a cryptographic key within an internal environment of the HSM; and transmit the generated cryptographic key to one hardware component of the plurality of hardware components without exposing the generated cryptographic key in plaintext format to the plurality of software components. However, Buonora teaches wherein each software component of the plurality of software components is associated with a respective hardware component of the plurality of hardware components; and ( ¶0022-0024: In an embodiment, a cryptography service 102 is a collection of computing resources collectively configured to manage and use cryptographic keys for clients of the computing resource service provider 126. Clients may communicate to cryptography service 102 via application programming interface (API) requests, which may be web service API requests.); generate a cryptographic key within an internal environment of the HSM; and ( ¶0037: A hardware security module, such as HSM 104 illustrated in Figure 1, may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. ); transmit the generated cryptographic key to one hardware component of the plurality of hardware components without exposing the generated cryptographic key in plaintext format to the plurality of software components. ( ¶0032-0035: As seen in Figure 1, a cryptography service 102 may generate executable code based at least in part on one or more keys. A cryptography service 102 may obtain one or more keys and generate code for an enclave that stores the one or more keys as enclave data within the enclave. Code for an enclave may be generated such that keys resident to the enclave may be protected by the enclave and never exported from the enclave in plaintext format. Data, such as executable code or keys, stored within an enclave may be inaccessible outside of the enclave environment within an edge device, including to privileged components of the edge device such as VMMs, kernels, BIOS firmware, and OS software (without exposing the generated cryptographic key in plaintext format to plurality of software components). Further in ¶0037 explicitly discloses cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the software component and the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 16, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the generated cryptographic key is not exposed to hardware components of the plurality of hardware components other than the one hardware component. ( Buonora ¶0015 A cryptography service can provide executable code to an edge device that, when executed by the edge device, causes the edge device to provision a cryptography service instance within a protected execution environment. A protected execution environment may be implemented as an enclave that protects access to cryptographic keys such that cryptographic keys resident to the enclave are designed to never be exposed outside of the enclave in a plaintext format.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the software component and the generation of the cryptographic key to the method of Kushtagi in view Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 ). With respect to claim 17, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the cryptographic key is generated by a software component within an internal environment of the HSM. ( Buonora ¶0022-0024: In an embodiment, a cryptography service 102 is a collection of computing resources collectively configured to manage and use cryptographic keys for clients of the computing resource service provider 126. Clients may communicate to cryptography service 102 via application programming interface (API) requests, which may be web service API requests.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the cryptographic key being generated by software component within the internal environment of the key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect aspects of data, such as by providing cryptographically verifiable assurances of confidentiality, integrity, and/or authenticity of the data (Buonora : ¶0023 ). With respect to claim 18, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the cryptographic key is generated by another hardware component within an internal environment of the HSM. ( Buonora ¶0022: Figure 1 shows an illustrative example of computing environment 100 in which a device obtains code to provision a protected execution environment comprising a cryptography service instance. A cryptography service 102 may include a network of one or more devices, such as a hardware security module (HSM) 104, a trusted platform module (TPM), a cryptographic processor, and/or variations thereof.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 19, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the generated cryptographic key is encrypted by the HSM before being sent to the one hardware component. ( Buonora ¶0023: Cryptography service 102 may provide encryption keys, such as a data key (DK), which may be encrypted using a managed key (MK), contained within the cryptography service 102. Authenticity may refer to cryptographically verifiable assurances that a message was created by a party purporting to be the author of the message. Integrity may refer to cryptographically verifiable assurances that a received message was not modified either intentionally (e.g., by a malicious party) or unintentionally (e.g., as a result of signal loss during transmission) from its original form when the message was transmitted. Confidentiality may refer to cryptographically verifiable assurances that the message may only be understood by the recipient and/or other intended parties (e.g., by transmitting an encrypted message that may only be decrypted using a secret key that is accessible to recipient). ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to encryption of the generated cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect aspects of data, such as by providing cryptographically verifiable assurances of confidentiality, integrity, and/or authenticity of the data (Buonora : ¶0023 ). With respect to claim 27, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the HSM managing one or more cryptographic keys includes one or more of key generation, key export, key deletion, and secured key storage. (Buonora ¶0037-0038: In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. An HSM may delete cryptographic keys stored in the HSM upon detection of tampering of or unauthorized access to data of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 28, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), wherein the HSM is further configured to store the generated cryptographic key within the HSM without exposing the generated cryptographic key to an environment outside of the HSM. (Buonora ¶0037-0038: In at least some embodiment, a protected execution environment can be executed within the context of a security module such as a hardware security module (HSM). An HSM may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. HSMs provide cryptographic key generation and storage, and perform cryptographic operations for authorized clients of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to key provisioning and management unit to the method of Kushtagi in view Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 29, Kushtagi teaches a hardware security module (HSM) comprising: an internal memory component configured to store data internal to the HSM and prevent external components to the HSM from accessing the stored data; ( ¶0017: In some embodiments, the HSM 24 may include a plug-in card or another suitable external device that attaches directly into the KMS 20. In some embodiments, the HSM 24 may include one or more secure crypto-processor chips, which may also be protected by tamper-evident or tamper-resistant packaging.); wherein the HSM is configured to: manage one or more cryptographical keys associated with one or more cryptographical operations by the hardware component, (¶0017: The security of the KMS 20 is enhanced through a hardware security module (HSM) 24. In that regard, the HSM 24 includes a physical hardware device (e.g., a computing device) that safeguards and manages the confidential information (e.g., digital keys, authentication credentials, certificates, PII) at least in part via encryption and decryption and/or other forms of cryptography. ); Kushtagi does not disclose: cryptographical keys associated with one or more cryptographical operations by the hardware component, However, Pecoraro cryptographical keys associated with one or more cryptographical operations by the hardware component; ( ¶0039: An HSM, or Hardware Security Module, is a specialized and tamper-resistant hardware device designed to securely store and manage cryptographic keys and perform cryptographic operations. HSMs are used to enhance the security of sensitive data by ensuring that keys are protected from physical attacks and unauthorized access. They are commonly employed in applications requiring high levels of security, such as secure communications, digital signatures, and data encryption.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Pecoraro with regards to the cryptographic keys to the method of Kushtagi in order to protect the keys from physical attacks and unauthorized access (Pecoraro : ¶0039 ). Kushtagi in view of Pecoraro does not disclose: and an interface configured to couple the HSM to a hardware component for running an application supported by the hardware component, generate a cryptographic key within an internal environment of the HSM, and transmit the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to the application. However, Buonora teaches an interface configured to couple the HSM to a hardware component for running an application supported by the hardware component, ( ¶0015: Cryptography services can be utilized to provide web service interfaces to which requests can be submitted by clients via client computing devices to cause cryptographic operations to be performed. ¶0044: As seen in Figure 1, the cryptographic material may verify the authenticity of the provisioning data 112 and the executable code 114. Edge device 110 may obtain cryptographic material and perform one or more processes to verify the authenticity of the provisioning data 112 and ensure the provisioning data 112 has not been modified or otherwise altered in transmission from a cryptography service 102 of the computing resource service provider 126 (interface coupled to the HSM to the hardware component). ); generate a cryptographic key within an internal environment of the HSM, and ( ¶0037: A hardware security module, such as HSM 104 illustrated in Figure 1, may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. ); transmit the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to the application. ( ¶0032-0035: As seen in Figure 1, a cryptography service 102 may generate executable code based at least in part on one or more keys. A cryptography service 102 may obtain one or more keys and generate code for an enclave that stores the one or more keys as enclave data within the enclave. Code for an enclave may be generated such that keys resident to the enclave may be protected by the enclave and never exported from the enclave in plaintext format. Data, such as executable code or keys, stored within an enclave may be inaccessible outside of the enclave environment within an edge device, including to privileged components of the edge device such as VMMs, kernels, BIOS firmware, and OS software (without exposing the generated cryptographic key in plaintext format to plurality of software components). Further in ¶0037 explicitly discloses cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the interface and generation of the cryptographic key to the method of Kushtagi in view Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 30, the combination of Kushtagi in view of Pecoraro and Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), wherein the cryptographic key is generated by another hardware component within the HSM. ( Buonora ¶0022: Figure 1 shows an illustrative example of computing environment 100 in which a device obtains code to provision a protected execution environment comprising a cryptography service instance. A cryptography service 102 may include a network of one or more devices, such as a hardware security module (HSM) 104, a trusted platform module (TPM), a cryptographic processor, and/or variations thereof.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 31, the combination of Kushtagi in view of Pecoraro Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), wherein the cryptographic key is generated by a software component within the internal environment of the HSM. ( Buonora ¶0022-0024: In an embodiment, a cryptography service 102 is a collection of computing resources collectively configured to manage and use cryptographic keys for clients of the computing resource service provider 126. Clients may communicate to cryptography service 102 via application programming interface (API) requests, which may be web service API requests.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the cryptographic key being generated by software component within the internal environment of the key provisioning and management unit to the method of Kushtagi in order to protect aspects of data, such as by providing cryptographically verifiable assurances of confidentiality, integrity, and/or authenticity of the data (Buonora : ¶0023 ). With respect to claim 32, the combination of Kushtagi in view of Pecoraro and Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), wherein the generated cryptographic key is encrypted by the HSM before transmitting the generated cryptographic key to the hardware component. ( Buonora ¶0023: Cryptography service 102 may provide encryption keys, such as a data key (DK), which may be encrypted using a managed key (MK), contained within the cryptography service 102. Authenticity may refer to cryptographically verifiable assurances that a message was created by a party purporting to be the author of the message. Integrity may refer to cryptographically verifiable assurances that a received message was not modified either intentionally (e.g., by a malicious party) or unintentionally (e.g., as a result of signal loss during transmission) from its original form when the message was transmitted. Confidentiality may refer to cryptographically verifiable assurances that the message may only be understood by the recipient and/or other intended parties (e.g., by transmitting an encrypted message that may only be decrypted using a secret key that is accessible to recipient). ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to encryption of the generated cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect aspects of data, such as by providing cryptographically verifiable assurances of confidentiality, integrity, and/or authenticity of the data (Buonora : ¶0023 ). With respect to claim 40, the combination of Kushtagi in view of Pecoraro Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), wherein the HSM managing one or more cryptographic keys includes one or more of key generation, key export, key deletion, and secured key storage. (Buonora ¶0037-0038: In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. An HSM may delete cryptographic keys stored in the HSM upon detection of tampering of or unauthorized access to data of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 41, the combination of Kushtagi in view of Pecoraro and Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), wherein the HSM is further configured to store the generated cryptographic key within the internal memory component. (Buonora ¶0037-0038: In at least some embodiment, a protected execution environment can be executed within the context of a security module such as a hardware security module (HSM). An HSM may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. HSMs provide cryptographic key generation and storage, and perform cryptographic operations for authorized clients of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to key provisioning and management unit to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 42, Kushtagi teaches a method comprising: managing one or more cryptographical keys associated with one or more cryptographical operations by a hardware component; (Abstract: A cryptography agent is implemented serve as an intermediary for a client executing on an unsecure portion of a machine to bring greater hardware-based security the client application. The client application sends commands to the cryptography agent, which performs operations within the enclave according to the commands once the client application is validated. ¶0017: The security of the KMS 20 is enhanced through a hardware security module (HSM) 24. In that regard, the HSM 24 includes a physical hardware device (e.g., a computing device) that safeguards and manages the confidential information (e.g., digital keys, authentication credentials, certificates, PII) at least in part via encryption and decryption and/or other forms of cryptography.); Kushtagi does not disclose: Kushtagi does not disclose: cryptographical keys associated with one or more cryptographical operations by the hardware component, However, Pecoraro cryptographical keys associated with one or more cryptographical operations by the hardware component; ( ¶0039: An HSM, or Hardware Security Module, is a specialized and tamper-resistant hardware device designed to securely store and manage cryptographic keys and perform cryptographic operations. HSMs are used to enhance the security of sensitive data by ensuring that keys are protected from physical attacks and unauthorized access. They are commonly employed in applications requiring high levels of security, such as secure communications, digital signatures, and data encryption.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Pecoraro with regards to the cryptographic keys to the method of Kushtagi in order to protect the keys from physical attacks and unauthorized access (Pecoraro : ¶0039 ). Kushtagi in view of Pecoraro does not disclose: generating a cryptographic key within an internal environment; and transmitting the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to an application running on the hardware component. However, Buonora teaches generating a cryptographic key within an internal environment; ( ¶0037: A hardware security module, such as HSM 104 illustrated in Figure 1, may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. ); and transmitting the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to an application running on the hardware component. ( ¶0032-0035: As seen in Figure 1, a cryptography service 102 may generate executable code based at least in part on one or more keys. A cryptography service 102 may obtain one or more keys and generate code for an enclave that stores the one or more keys as enclave data within the enclave. Code for an enclave may be generated such that keys resident to the enclave may be protected by the enclave and never exported from the enclave in plaintext format. Data, such as executable code or keys, stored within an enclave may be inaccessible outside of the enclave environment within an edge device, including to privileged components of the edge device such as VMMs, kernels, BIOS firmware, and OS software (without exposing the generated cryptographic key in plaintext format to plurality of software components). Further in ¶0037 explicitly discloses cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). With respect to claim 43, Kushtagi teaches a system comprising: a means for managing one or more cryptographical keys associated with one or more cryptographical operations by a hardware component; (Abstract: A cryptography agent is implemented serve as an intermediary for a client executing on an unsecure portion of a machine to bring greater hardware-based security the client application. The client application sends commands to the cryptography agent, which performs operations within the enclave according to the commands once the client application is validated. ¶0017: The security of the KMS 20 is enhanced through a hardware security module (HSM) 24. In that regard, the HSM 24 includes a physical hardware device (e.g., a computing device) that safeguards and manages the confidential information (e.g., digital keys, authentication credentials, certificates, PII) at least in part via encryption and decryption and/or other forms of cryptography.); Kushtagi does not disclose: cryptographical keys associated with one or more cryptographical operations by the hardware component, However, Pecoraro cryptographical keys associated with one or more cryptographical operations by the hardware component; ( ¶0039: An HSM, or Hardware Security Module, is a specialized and tamper-resistant hardware device designed to securely store and manage cryptographic keys and perform cryptographic operations. HSMs are used to enhance the security of sensitive data by ensuring that keys are protected from physical attacks and unauthorized access. They are commonly employed in applications requiring high levels of security, such as secure communications, digital signatures, and data encryption.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Pecoraro with regards to the cryptographic keys to the method of Kushtagi in order to protect the keys from physical attacks and unauthorized access (Pecoraro : ¶0039 ). Kushtagi in view of Pecoraro does not disclose: a means for generating a cryptographic key within an internal environment; and means for transmitting the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to an application running on the hardware component. However, Buonora teaches a means for generating a cryptographic key within an internal environment; ( ¶0037: A hardware security module, such as HSM 104 illustrated in Figure 1, may refer to a physical computing device that safeguards cryptographic keys by storing them within a tamper-resistant physical device. In some examples, an HSM provides cryptographic key generation and storage, and performs cryptographic operations for authorized clients of the HSM. In some embodiments, cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM. An HSM may comprise one or more processors that may prevent tampering and unauthorized access to data of the HSM. ); and means for transmitting the generated cryptographic key to the hardware component without exposing the generated cryptographic key in plaintext format to an application running on the hardware component. ( ¶0032-0035: As seen in Figure 1, a cryptography service 102 may generate executable code based at least in part on one or more keys. A cryptography service 102 may obtain one or more keys and generate code for an enclave that stores the one or more keys as enclave data within the enclave. Code for an enclave may be generated such that keys resident to the enclave may be protected by the enclave and never exported from the enclave in plaintext format. Data, such as executable code or keys, stored within an enclave may be inaccessible outside of the enclave environment within an edge device, including to privileged components of the edge device such as VMMs, kernels, BIOS firmware, and OS software (without exposing the generated cryptographic key in plaintext format to plurality of software components). Further in ¶0037 explicitly discloses cryptographic keys that are stored in a HSM are not exposed in a plaintext format outside of the HSM.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Buonora with regards to the generation of the cryptographic key to the method of Kushtagi in view of Pecoraro in order to protect access to cryptographic key and prevent tampering and unauthorized access to data of the HSM (Buonora : ¶0015 & ¶0037 ). Claims 6, 7, 20, 21, 33, and 34 are rejected under 35 U.S.C. 103 as being unpatentable over Kushtagi et al. (US PGPub No. 20230177171-A1 ) in view of Pecoraro et al. (US Pat No.12425191-B1), Buonora et al. (US Pat No. 11475140-B1 ) and Krahn et al. (US PGPub No. 20240187260-A1 ). With respect to claim 6, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), but does not disclose wherein the key provisioning and management unit is coupled to the hardware component through a secure physical channel. However, Krahn teaches wherein the key provisioning and management unit is coupled to the hardware component through a secure physical channel. (¶0032-0033: In some embodiments, DPE 105 can receive from client computing device 110 and via secure communication channel 115, context data 150 associated with a cryptographic subtask of the task. For example, DPE 105 can perform operations related to hashing, pairing cryptographic keys, encrypting and/or decrypting data, and so forth. In some embodiments, the cryptographic subtask may relate to a generation of an attestation certificate for a software application of a plurality of software applications on the computing device. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Krahn with regards to the secure physical channel to the method of Kushtagi in view of Pecoraro and Buonora in order to enable mitigation of real and or potential security threats (Krahn : ¶0016 ). With respect to claim 7, the combination of Kushtagi in view of Pecoraro, Buonora, and Krahn teaches the system of claim 6 (see rejection of claim 6 above), wherein the key provisioning and management unit is configured to identify and authenticate the hardware component using a device identifier composition engine (DICE). (Krahn ¶0022-0022 Figure 1 is a diagram illustrating an example architecture 100 for DICE protection environment (DPE) 105. Some embodiments involve receiving, by a secure component (e.g., DPE 105) and from client computing device 110 via a secure communication channel 115, input data for a task associated with the client computing device 110, wherein the task is based on a device identifier composition engine (DICE) protocol 105A, and wherein the secure component 120 is to perform a cryptographic subtask of the task. In some embodiments, DICE 105A may be a component that performs authentication related operations in client computing device 110. Such operations may be performed during a transition from hardware to software during a boot process, or during transfer from a software code to another. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Krahn with regards to using a device identifier composition engine to the method of Kushtagi in view of Pecoraro and Buonora in order to enable mitigation of real and or potential security threats (Krahn : ¶0016 ). With respect to claim 20, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), but does not disclose wherein the HSM is coupled to the one hardware component through a secure physical channel. However, Krahn teaches wherein the HSM is coupled to the one hardware component through a secure physical channel. (¶0032-0033: In some embodiments, DPE 105 can receive from client computing device 110 and via secure communication channel 115, context data 150 associated with a cryptographic subtask of the task. For example, DPE 105 can perform operations related to hashing, pairing cryptographic keys, encrypting and/or decrypting data, and so forth. In some embodiments, the cryptographic subtask may relate to a generation of an attestation certificate for a software application of a plurality of software applications on the computing device. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Krahn with regards to the secure physical channel to the method of Kushtagi in view of Pecoraro and Buonora in order to enable mitigation of real and or potential security threats (Krahn : ¶0016 ). With respect to claim 21, the combination of Kushtagi in view of Pecoraro, Buonora, and Krahn teaches the system of claim 20 (see rejection of claim 20 above), wherein the HSM is configured to identify and authenticate the one hardware component using a device identifier composition engine (DICE). (Krahn ¶0022-0022 Figure 1 is a diagram illustrating an example architecture 100 for DICE protection environment (DPE) 105. Some embodiments involve receiving, by a secure component (e.g., DPE 105) and from client computing device 110 via a secure communication channel 115, input data for a task associated with the client computing device 110, wherein the task is based on a device identifier composition engine (DICE) protocol 105A, and wherein the secure component 120 is to perform a cryptographic subtask of the task. In some embodiments, DICE 105A may be a component that performs authentication related operations in client computing device 110. Such operations may be performed during a transition from hardware to software during a boot process, or during transfer from a software code to another. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Krahn with regards to using a device identifier composition engine to the method of Kushtagi in view of Pecoraro and Buonora in order to enable mitigation of real and or potential security threats (Krahn : ¶0016 ). With respect to claim 33, the combination of Kushtagi in view of Pecoraro and Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), but does not disclose wherein the interface couples the HSM to the hardware component through a secure physical channel. However, Krahn teaches wherein the interface couples the HSM to the hardware component through a secure physical channel. (¶0032-0033: In some embodiments, DPE 105 can receive from client computing device 110 and via secure communication channel 115, context data 150 associated with a cryptographic subtask of the task. For example, DPE 105 can perform operations related to hashing, pairing cryptographic keys, encrypting and/or decrypting data, and so forth. In some embodiments, the cryptographic subtask may relate to a generation of an attestation certificate for a software application of a plurality of software applications on the computing device. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Krahn with regards to the secure physical channel to the method of Kushtagi in view of Pecoraro and Buonora in order to enable mitigation of real and or potential security threats (Krahn : ¶0016 ). With respect to claim 34, the combination of Kushtagi in view of Pecoraro, Buonora, and Krahn teaches the HSM of claim 33 (see rejection of claim 33 above), wherein the HSM is configured to identify and authenticate the hardware component using a device identifier composition engine (DICE). (Krahn ¶0022-0022 Figure 1 is a diagram illustrating an example architecture 100 for DICE protection environment (DPE) 105. Some embodiments involve receiving, by a secure component (e.g., DPE 105) and from client computing device 110 via a secure communication channel 115, input data for a task associated with the client computing device 110, wherein the task is based on a device identifier composition engine (DICE) protocol 105A, and wherein the secure component 120 is to perform a cryptographic subtask of the task. In some embodiments, DICE 105A may be a component that performs authentication related operations in client computing device 110. Such operations may be performed during a transition from hardware to software during a boot process, or during transfer from a software code to another. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Krahn with regards to using a device identifier composition engine to the method of Kushtagi in view of Pecoraro and Buonora in order to enable mitigation of real and or potential security threats (Krahn : ¶0016 ). Claims 8, 9, 22, 23, 35, and 36 are rejected under 35 U.S.C. 103 as being unpatentable over Kushtagi et al. (US PGPub No. 20230177171-A1 ) in view of Pecoraro et al. (US Pat No.12425191-B1), Buonora et al. (US Pat No. 11475140-B1 ), and Griffin et al. (US Pat No. 10615969-B1). With respect to claim 8, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), but does not disclose wherein the key provisioning and management unit is coupled to the hardware component through a secure logical channel. However, Griffin teaches wherein the key provisioning and management unit is coupled to the hardware component through a secure logical channel. (¶0023-0024: The database server 116 is communicatively coupled to the key manager circuit 114 via secure connection 150. n some embodiments, the secure connection 150 is a Transport Layer Security (TLS) protocol-based electronic connection. In some embodiments, the secure connection 150 is a Transport Layer Security (TLS) protocol-based electronic connection. In other embodiments, the secure connection 150 is an Internet Protocol Security (IPsec)-based connection. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Griffin with regards to the secure logical channel to the method of Kushtagi in view of Buonora in view of Pecoraro in order to external attacks and likelihood that the stored data would be compromised (Griffin : ¶0018 ). With respect to claim 9, the combination of Kushtagi in view of Pecoraro, Buonora, and Griffin teaches the system of claim 8 (see rejection of claim 8 above),wherein the logical channel is formed by performing mutual authentication by the key provisioning and management unit and the hardware component. (Griffin ¶0023-0024: Additionally or alternatively, the secure connection 150 may be established using a mutual authentication algorithm comprising digital certificates.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Griffin with regards to the mutual authentication to the method of Kushtagi in view of Pecoraro and Buonora in order to external attacks and likelihood that the stored data would be compromised (Griffin : ¶0013 & ¶0018 ). With respect to claim 22, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above),but does not disclose wherein the HSM is coupled to the one hardware component through a secure logical channel. However, Griffin teaches wherein the HSM is coupled to the one hardware component through a secure logical channel. (¶0023-0024: The database server 116 is communicatively coupled to the key manager circuit 114 via secure connection 150. n some embodiments, the secure connection 150 is a Transport Layer Security (TLS) protocol-based electronic connection. In some embodiments, the secure connection 150 is a Transport Layer Security (TLS) protocol-based electronic connection. In other embodiments, the secure connection 150 is an Internet Protocol Security (IPsec)-based connection. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Griffin with regards to the secure logical channel to the method of Kushtagi in view of Pecoraro and Buonora in order to external attacks and likelihood that the stored data would be compromised (Griffin : ¶0018 ). With respect to claim 23, the combination of Kushtagi in view of Pecoraro, Buonora, and Griffin teaches the system of claim 22 (see rejection of claim 22 above), wherein the logical channel is formed by performing mutual authentication by the HSM and the one hardware component. (Griffin ¶0023-0024: Additionally or alternatively, the secure connection 150 may be established using a mutual authentication algorithm comprising digital certificates.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Griffin with regards to the mutual authentication to the method of Kushtagi in view of Pecoraro and Buonora in order to external attacks and likelihood that the stored data would be compromised (Griffin : ¶0013 & ¶0018 ). With respect to claim 35, the combination of Kushtagi in view of Pecoraro and Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), but does not disclose wherein the interface couple is coupled to the hardware component through a secure logical channel. However, Griffin teaches wherein the interface couple is coupled to the hardware component through a secure logical channel. (¶0023-0024: The database server 116 is communicatively coupled to the key manager circuit 114 via secure connection 150. n some embodiments, the secure connection 150 is a Transport Layer Security (TLS) protocol-based electronic connection. In some embodiments, the secure connection 150 is a Transport Layer Security (TLS) protocol-based electronic connection. In other embodiments, the secure connection 150 is an Internet Protocol Security (IPsec)-based connection. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Griffin with regards to the secure logical channel to the method of Kushtagi in view of Pecoraro and Buonora in order to external attacks and likelihood that the stored data would be compromised (Griffin : ¶0018 ). With respect to claim 36, the combination of Kushtagi in view of Pecoraro, Buonora, and Griffin teaches the HSM of claim 35 (see rejection of claim 35 above), wherein the logical channel is formed by performing mutual authentication by the HSM and the hardware component. (Griffin ¶0023-0024: Additionally or alternatively, the secure connection 150 may be established using a mutual authentication algorithm comprising digital certificates.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Griffin with regards to the mutual authentication to the method of Kushtagi in view of Pecoraro and Buonora in order to external attacks and likelihood that the stored data would be compromised (Griffin : ¶0013 & ¶0018 ). Claims 10 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Kushtagi et al. (US PGPub No. 20230177171-A1 ) in view of Pecoraro et al. (US Pat No.12425191-B1), Buonora et al. (US Pat No. 11475140-B1 ), Nedgundi et al. (US Pat No. 20230231842-A1), and Cho et al. (Post-quantum MACsec key agreement for ethernet networks, Proceedings of the 15th International Conference on Availability, Reliability and Security (ARES '20). Association for Computing Machinery, New York, NY, USA, Article 107, 1-6). With respect to claim 10, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), but does not disclose wherein the hardware component is an Ethernet medium access control (MAC), and wherein the key provisioning and management unit is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. However, Nedungadi teaches wherein the hardware component is an Ethernet medium access control (MAC), and (¶0043 In some embodiments, the TPM is replaced by a hardware security module (HSM). In some embodiments, the identify certificate 378 stored in the TPM 370 of a network device is unique to the network device and is, for example, tied to the serial number and other unique identity of the network device, such as the Ethernet MAC address of the network device. Impersonating a network device typically requires an attacker to gain access the identify certificate 378.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Nedungadi with regards to the Ethernet medium access control (MAC) to the method of Kushtagi in view of Pecoraro and Buonora in order to make external attacks more difficult or even infeasible (Nedungadi : ¶0043 ). Kushtagi in view of Pecoraro, Buonora, Nedugadi does not disclose: wherein the key provisioning and management unit is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. However, Cho wherein the key provisioning and management unit is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. (Page 2: 2.2 MACsec Key Agreement : MKA is a companion protocol of MACsec that provides methods of the cryptographic key establishment for MACsec [20]. MKA is based on a hierarchical key derivation structure. A CAK is a root of the key hierarchy. Each payload of an Ethernet frame is encrypted by a SAK(Secure Association Key) which is derived from a CAK during a key lifetime.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Cho with regards using a secure association key to the method of Kushtagi in view of Pecoraro, Buonora, and Nedugadi in order to ensure integrity, confidentiality, and authenticity (Cho : Page 1, 1 Introduction). With respect to claim 24, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), but does not disclose wherein the one hardware component is an Ethernet medium access control (MAC), and wherein the HSM is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. However, Nedungadi teaches wherein the one hardware component is an Ethernet medium access control (MAC), and (¶0043 In some embodiments, the TPM is replaced by a hardware security module (HSM). In some embodiments, the identify certificate 378 stored in the TPM 370 of a network device is unique to the network device and is, for example, tied to the serial number and other unique identity of the network device, such as the Ethernet MAC address of the network device. Impersonating a network device typically requires an attacker to gain access the identify certificate 378.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Nedungadi with regards to the Ethernet medium access control (MAC) to the method of Kushtagi in view of Pecoraro and Buonora in order to make external attacks more difficult or even infeasible (Nedungadi : ¶0043 ). Kushtagi in view of Pecoraro , Buonora, and Nedugadi does not disclose: wherein the HSM is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. However, Cho teaches wherein the HSM is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. (Page 2: 2.2 MACsec Key Agreement : MKA is a companion protocol of MACsec that provides methods of the cryptographic key establishment for MACsec [20]. MKA is based on a hierarchical key derivation structure. A CAK is a root of the key hierarchy. Each payload of an Ethernet frame is encrypted by a SAK(Secure Association Key) which is derived from a CAK during a key lifetime.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Cho with regards using a secure association key to the method of Kushtagi in view of Pecoraro, Buonora, and Nedugadi in order to ensure integrity, confidentiality, and authenticity (Cho : Page 1, 1 Introduction). With respect to claim 37, the combination of Kushtagi in view of Pecoraro and Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), but does not disclose wherein the hardware component is an Ethernet medium access control (MAC), and wherein the HSM is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. However, Nedungadi teaches wherein the hardware component is an Ethernet medium access control (MAC), (¶0043 In some embodiments, the TPM is replaced by a hardware security module (HSM). In some embodiments, the identify certificate 378 stored in the TPM 370 of a network device is unique to the network device and is, for example, tied to the serial number and other unique identity of the network device, such as the Ethernet MAC address of the network device. Impersonating a network device typically requires an attacker to gain access the identify certificate 378.); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Nedungadi with regards to the Ethernet medium access control (MAC) to the method of Kushtagi in view of Pecoraro and Buonora in order to make external attacks more difficult or even infeasible (Nedungadi : ¶0043 ). Kushtagi in view of Pecoraro ,Buonora, Nedugadi does not disclose: and wherein the HSM is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. However, Cho teaches wherein the HSM is configured to generate and store a secure association key (SAK) and transmit the SAK as a MAC security (MACSec) to the Ethernet Mac. (Page 2: 2.2 MACsec Key Agreement : MKA is a companion protocol of MACsec that provides methods of the cryptographic key establishment for MACsec [20]. MKA is based on a hierarchical key derivation structure. A CAK is a root of the key hierarchy. Each payload of an Ethernet frame is encrypted by a SAK(Secure Association Key) which is derived from a CAK during a key lifetime.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Cho with regards using a secure association key to the method of Kushtagi in view of Pecoraro, Buonora and Nedugadi in order to ensure integrity, confidentiality, and authenticity (Cho : Page 1, 1 Introduction). Claims 11, 25, and 38 are rejected under 35 U.S.C. 103 as being unpatentable over Kushtagi et al. (US PGPub No. 20230177171-A1 ) in view of Pecoraro et al. (US Pat No. 12425191-B1)Buonora et al. (US Pat No. 11475140-B1 ) and Kornegay et al. (US Pat No. 20180196945-A1). With respect to claim 11, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), but does not disclose wherein communication of the generated cryptographic key between the key provisioning and management unit and the hardware component is without utilizing a configuration bus. However, Kornegay teaches wherein communication of the generated cryptographic key between the key provisioning and management unit and the hardware component is without utilizing a configuration bus. (¶0030: Figure 4 illustrates the data traffic module. More particularly, in this configuration, data traffic module 100 is configured to perform preferably each of the following functions: sealed storage to house cryptographic keys and secrets, remote attestation, which allows a trusted device to present reliable evidence to remote parties about the software it is running, built-in tamper resistance, and public key cryptographic operations and random number generation . In certain configurations, data traffic module 100 may use XILINX Ethernet MAC and PHY layer IP cores to facilitate additional Ethernet connectivity. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kornegay with regards to communication without of the utilization of a configuration bus to the method of Kushtagi in view of Pecoraro and Buonora in order to prevent large scale coordinated attacks (Kornegay : ¶0005-0006 ). With respect to claim 25, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), but does not disclose wherein communication of the generated cryptographic key between the HSM and the one hardware component is without utilizing a configuration bus. However, Kornegay teaches wherein communication of the generated cryptographic key between the HSM and the one hardware component is without utilizing a configuration bus. (¶0030: Figure 4 illustrates the data traffic module. More particularly, in this configuration, data traffic module 100 is configured to perform preferably each of the following functions: sealed storage to house cryptographic keys and secrets, remote attestation, which allows a trusted device to present reliable evidence to remote parties about the software it is running, built-in tamper resistance, and public key cryptographic operations and random number generation . In certain configurations, data traffic module 100 may use XILINX Ethernet MAC and PHY layer IP cores to facilitate additional Ethernet connectivity. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kornegay with regards to communication without of the utilization of a configuration bus to the method of Kushtagi in view of Pecoraro and Buonora in order to prevent large scale coordinated attacks (Kornegay : ¶0005-0006 ). With respect to claim 38, the combination of Kushtagi in view of Pecoraro and Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), but does not disclose wherein communication of the generated cryptographic key between the HSM and the hardware component is without utilizing a configuration bus. However, Kornegay teaches wherein communication of the generated cryptographic key between the HSM and the hardware component is without utilizing a configuration bus. (¶0030: Figure 4 illustrates the data traffic module. More particularly, in this configuration, data traffic module 100 is configured to perform preferably each of the following functions: sealed storage to house cryptographic keys and secrets, remote attestation, which allows a trusted device to present reliable evidence to remote parties about the software it is running, built-in tamper resistance, and public key cryptographic operations and random number generation . In certain configurations, data traffic module 100 may use XILINX Ethernet MAC and PHY layer IP cores to facilitate additional Ethernet connectivity. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Kornegay with regards to communication without of the utilization of a configuration bus to the method of Kushtagi in view of Pecoraro and Buonora in order to prevent large scale coordinated attacks (Kornegay : ¶0005-0006 ). Claims 12, 26, and 39 are rejected under 35 U.S.C. 103 as being unpatentable over Kushtagi et al. (US PGPub No. 20230177171-A1 ) in view of Pecoraro et al. (US Pat No. 12425191-B1), Buonora et al. (US Pat No. 11475140-B1 ) and Swarbrick et al. (US Pat No. 20250139207-A1). With respect to claim 12, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 1 (see rejection of claim 1 above), but does not disclose wherein the hardware component is one of a memory controller, an accelerator, an Ethernet medium access (MAC), hardware debug, peripheral component interconnect (PCI), PCI express (PCIe), storage controller, software integrity, or application security. However, Swarbrick teaches wherein the hardware component is one of a memory controller, an accelerator, an Ethernet medium access (MAC), hardware debug, peripheral component interconnect (PCI), PCI express (PCIe), storage controller, software integrity, or application security. (¶0012-0013: Hardware Security Module (HSM) is configured to be communicatively coupled to a computer or server device in an external system through the Input/Output (IO) connector 1701. For example, the Hardware Security Module (HSM) can be a PCI express card, which can be directly plugged into the computer or server device. In this case the Input/Output (IO) connector is a PCIe connector. In use, the Hardware Security Module (HSM) receives user requests through the Input-Output (IO) connector 1701. The requests may comprise commands to perform certain cryptographic operations. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Swarbrick with regards to communication without of the utilization of a configuration bus to the method of Kushtagi in view of Pecoraro and Buonora in order to prevent tampering (Swarbrick : ¶0002-0004). With respect to claim 26, the combination of Kushtagi in view of Pecoraro and Buonora teaches the system of claim 15 (see rejection of claim 15 above), but does not disclose wherein the one hardware component is one of a memory controller, an accelerator, an Ethernet medium access (MAC), hardware debug, peripheral component interconnect (PCI), PCI express (PCIe), storage controller, software integrity, or application security. However, Swarbrick teaches wherein the one hardware component is one of a memory controller, an accelerator, an Ethernet medium access (MAC), hardware debug, peripheral component interconnect (PCI), PCI express (PCIe), storage controller, software integrity, or application security. (¶0012-0013: Hardware Security Module (HSM) is configured to be communicatively coupled to a computer or server device in an external system through the Input/Output (IO) connector 1701. For example, the Hardware Security Module (HSM) can be a PCI express card, which can be directly plugged into the computer or server device. In this case the Input/Output (IO) connector is a PCIe connector. In use, the Hardware Security Module (HSM) receives user requests through the Input-Output (IO) connector 1701. The requests may comprise commands to perform certain cryptographic operations. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Swarbrick with regards to communication without of the utilization of a configuration bus to the method of Kushtagi in view of Pecoraro and Buonora in order to prevent tampering (Swarbrick : ¶0002-0004). With respect to claim 39, the combination of Kushtagi in view of Pecoraro and Buonora teaches the HSM of claim 29 (see rejection of claim 29 above), but does not disclose wherein the hardware component is one of a memory controller, an accelerator, an Ethernet medium access (MAC), hardware debug, peripheral component interconnect (PCI), PCI express (PCIe), storage controller, software integrity, or application security. However, Swarbrick teaches wherein the hardware component is one of a memory controller, an accelerator, an Ethernet medium access (MAC), hardware debug, peripheral component interconnect (PCI), PCI express (PCIe), storage controller, software integrity, or application security. (¶0012-0013: Hardware Security Module (HSM) is configured to be communicatively coupled to a computer or server device in an external system through the Input/Output (IO) connector 1701. For example, the Hardware Security Module (HSM) can be a PCI express card, which can be directly plugged into the computer or server device. In this case the Input/Output (IO) connector is a PCIe connector. In use, the Hardware Security Module (HSM) receives user requests through the Input-Output (IO) connector 1701. The requests may comprise commands to perform certain cryptographic operations. ); It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Swarbrick with regards to communication without of the utilization of a configuration bus to the method of Kushtagi in view of Pecoraro and Buonora in order to prevent tampering (Swarbrick : ¶0002-0004). Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAYLOR P VU whose telephone number is (703)756-1218. The examiner can normally be reached MON - FRI (7:30 - 5:00). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /T.P.V./Examiner, Art Unit 2437 /MENG LI/Primary Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Feb 07, 2025
Application Filed
May 12, 2026
Non-Final Rejection mailed — §101, §103
Jul 16, 2026
Response Filed
Sep 25, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726815
SECURE MOBILE TRANSACTION APPARATUS AND METHOD
4y 3m to grant Granted Sep 01, 2026
Patent 12717917
PERSISTENT SECURITY CONFIGURATION MONITORING
4y 3m to grant Granted Aug 25, 2026
Patent 12717903
DETECTING UPLOADS OF MALICIOUS FILES TO CLOUD STORAGE
3y 8m to grant Granted Aug 25, 2026
Patent 12717960
METHOD AND DATA PROCESSING SYSTEM FOR EXECUTING AN OBFUSCATED COMPUTER PROGRAM
3y 3m to grant Granted Aug 25, 2026
Patent 12712713
GENERATING SHARED PRIVATE KEYS
3y 7m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
69%
Grant Probability
78%
With Interview (+8.4%)
3y 4m (~1y 8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 36 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month