Prosecution Insights
Last updated: October 02, 2026
Application No. 19/061,805

CONTROL OF MEMORY DEVICES OVER COMPUTER NETWORKS USING DIGITAL SIGNATURES GENERATED BY A SERVER SYSTEM FOR COMMANDS TO BE EXECUTED IN THE MEMORY DEVICES

Non-Final OA §103§DOUBLEPATENT
Filed
Feb 24, 2025
Priority
Jan 15, 2021 — continuation of 12/256,016
Examiner
WRIGHT, BRYAN F
Art Unit
Tech Center
Assignee
Micron Technology Inc.
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
641 granted / 820 resolved
+18.2% vs TC avg
Strong +24% interview lift
Without
With
+24.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
21 currently pending
Career history
847
Total Applications
across all art units

Statute-Specific Performance

§101
13.4%
-26.6% vs TC avg
§103
56.5%
+16.5% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
9.0%
-31.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 820 resolved cases

Office Action

§103 §DOUBLEPATENT
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. DETAILED ACTION This action is in response to applicant’s original submittal made on 02/24/2025. Claims 1-20 are pending. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1, 14 and 19 are rejected on the ground of nonstatutory double patenting as being unpatentable over claim 1 of U.S. Patent No. 12,256,016 and 016’ hereinafter. Although the claims at issue are not identical, they are not patentably distinct from each other because both sets of claims are drawn to the following: (19/061805) 1. A method, comprising: generating, by a server system, a first digital signature for a command using at least a cryptographic key stored in the server system in association with a memory device; and transmitting, from the server system via a connection to a client computer system, the first digital signature, the client computer system to submit the command with the first digital signature to the memory device.; maps to (016’) 1. A method, comprising: establishing, by a server system with a client computer system, a secure authenticated connection; receiving, in the server system over the connection from the client computer system, a request identifying a memory device; determining, based on data stored in the server system, that the client computer system is eligible to control the memory device; generating, by the server system, a first digital signature for a command using at least a cryptographic key stored in the server system in association with the memory device; and transmitting, from the server system via the connection to the client computer system, the first digital signature, the client computer system to submit the command with the first digital signature to the memory device, the memory device to validate the first digital signature prior to execution of the command.. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-3, 6, 7 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Prabhu et al. (US Patent Publication No. 2017/0149569 and Prabhu hereinafter) in view of HONJO (US Patent Publication No. 2011/0085474). As to claims 1 and 19, Prabhu teaches a method, comprising: generating, by a server system, a first digital signature for a command using at least a cryptographic key stored in the server system in association with a memory device (i.e. …teaches in par. 0043 the following: “the web server computing device 112 signs the command using a private signing key” …teaches in par. 0044 the following: “The processor in the embedded computing device 104 only in response to successful verification of the cryptographic signature in the command message (244). Successful verification means that the cryptographic signature in the command message, which can only be generated by the server 112, corresponds to each of the unique command identifier, counter, and the command message data elements of the command message.” …teaches in par. 0043 the following: “The server computing device 112 responds with a command message … The processor in the client computing device 108 receives the command message with the network interface device and forwards the command message to the embedded computing device 104 through the peripheral connection device.”. …teaches in par. 0044 the following: “The processor in the embedded computing device 104 only in response to successful verification of the cryptographic signature in the command message (244). Successful verification means that the cryptographic signature in the command message, which can only be generated by the server 112, corresponds to each of the unique command identifier, counter, and the command message data elements of the command message), the client computer system to submit the command with the first digital signature to the memory device (i.e., …teaches in par. 0043 the following: “The embedded computing device 104 receives the command message from the client computing device 108 via the peripheral connection using the peripheral connection device and the processor in the embedded computing device 104 verifies a cryptographic signature in the command message that corresponds to the unique command identifier, counter, and the command message data using a cryptographic key (240)”). Prabhu does not explicitly teach: and transmitting, from the server system via a connection to a client computer system, the first digital signature. In this instance the examiner notes the teachings of prior art reference HONJO. HONJO teaches in par. 00105 the following: “the signature generation server 200 transmits to the client UI software 104 the generated electronic signature together with the result of the uniqueness check (S124).”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu with the teachings of HONJO by having their system comprise an enhance data management process. One would have been motivated to do so to provide a simple and effective means to manage data, wherein the enhance data management process helps facilitate data integrity within the network and makes it easier to secure data. As to claim 2, the system of Prabhu and HONJO as applied to claim 1 above teaches command verification, specifically Prabhu teaches a method of claim 1, further comprising: receiving, by the server system via the client computer system from the memory device, identity data of the memory device (i.e., …teaches in par. 0041 the following: “The processor in the embedded computing device 104 generates a counter for the access request (224) and sends the counter back to the local client application 264 for the local client application to send a request to the server to get the command for unique counter and unique command identifier (228). In the embedded computing device 104, the processor transmits a second response message including the counter value and the unique command identifier to server computing device 112 via the client computing device 108 through the peripheral connection with the peripheral interface device in the embedded computing device. ”); validating, by the server system, the identity data based on a secret of the memory device stored in the server system (i.e., …teaches in par. 0041 the following: “The server computing device 112 receives the unique command identifier and counter from the client system 108 and verifies (compares) the unique command identifier previously sent in block 212 and the unique command identifier received from the client system 108 (232).”); and establishing a session key known to the server system and the memory device based on validation of the identity data (i.e., ..teaches in par. 0043 the following: “the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108.”). As to claim 3, the system of Prabhu and HONJO as applied to claim 2 above teaches command verification, specifically Prabhu teaches a method of claim 2, wherein when executed in the memory device, the command causes the memory device to activate a security feature of the memory device (i.e., …teaches in par. 0044 the following: “the embedded computing device 104 verifies the counter value received with the command and verifies the digital signature or the command authentication code to ensure that the command is valid prior to execution of the command. The processor in the embedded computing device 104 performs the requested operation in the command message based on the command data in the command message only in response to verification that the cryptographic signature corresponds to the counter value, the unique command identifier, and the command data using the cryptographic key. For example, upon successful verification of the command message the embedded computing device 104, which is operatively connected to an actuator in the power tool 102 in one embodiment, is further configured to perform the requested operation based on the command data to operate the actuator in the power tool 102.”). As to claim 6, the system of Prabhu and HONJO as applied to claim 2 above teaches command verification, specifically Prabhu teaches a method of claim 2, further comprising: encrypting, using the session key, at least a portion of data transmitted from the server system via the client computer system to the memory device for the execution of the command (i.e. …teaches in par. 0043 the following: “, the web server computing device 112 signs the command using a private signing key and the memory 328 in the embedded computing device 104 stores a corresponding public key in an internal memory that the embedded computing device 104 uses to verify the cryptographic signature.”). As to claim 7, the system of Prabhu and HONJO as applied to claim 2 above teaches command verification, specifically Prabhu teaches a method of claim 2, further comprising: decrypting, using the session key, at least a portion of a response transmitted to the server system via the client computer system from the memory device, the response being responsive to the execution of the command (i.e., …teaches in par. 0043 the following: “In one embodiment of the system 100, the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108.” …The examiner notes that all communication between the server and embedded memory device will be cryptographically process using the shared key). Claims 4 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over Prabhu in view of HONJO as applied to claim 1 above and further in view of Kamiya et al. (US Patent Publication No. 2021/0302640 and Kamiya hereinafter). As to claim 4, the system of Prabhu and HONJO as applied to claim 2 above teaches command verification, specifically neither reference expressly teaches a method of claim 2, wherein when executed in the memory device, the command causes the memory device to replace a first cryptographic key with a second cryptographic key. In this instance the examiner notes the teachings of prior art reference Kamiya. Kamiya teaches in par. 0133 the following: “server 240 then instructs the control device 110 to replace the encryption key by a new one.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu and HONJO with the teachings of KAMIYA by having their system comprise an enhance key management process. One would have been motivated to do so to provide a simple and effective means to control key related data stored in the device, wherein the enhance key management process helps facilitate secure communication within the network and makes it easier to configure the devices for network communication. As to claim 5, the system of Prabhu and HONJO as applied to claim 4 above teaches command verification, specifically Prabhu teaches a method of claim 4, wherein the second cryptographic key is generated in the memory device based on a unique device secret that is stored in the memory device and in the server system (i.e. …teaches in par. 011 the following: “a public cryptographic key stored in the memory, the public cryptographic key corresponding to a private cryptographic key stored in a memory of the server computing device.” …teaches in par. 0043 the following: “the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108.”); and the method further comprises: generating, in the server system and independently from the memory device, the second cryptographic key from the unique device secret stored in the server system (i.e. …teaches in par. 011 the following: “a public cryptographic key stored in the memory, the public cryptographic key corresponding to a private cryptographic key stored in a memory of the server computing device.” ……teaches in par. 0043 the following: “the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108.). Claim(s) 8-13 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Prabhu in view of HONJO as applied to claims 1 and 19 above and further in view of Fava et al. (US Patent Publication No. 2019/0229913 and Fava hereinafter). As to claim 8, the system of Prabhu and HONJO as applied to claim 2 above teaches command verification, specifically Prabhu expressly teaches a method of claim 2, wherein the identity data includes a second message and a second digital signature applied on the second message using a secret cryptographic key of the memory device (i.e., …teaches in par. 0045 the following: “embedded computing device 104 generates a third response message including the unique command identifier, the counter, and the return data generated in response to the requested operation.” …teaches in par. 0043 the following: “he memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device” …The examiner notes that all communication between the embedded memory device and server will be cryptographically processed using the shared key.). The system of Prabhu and HONJO do not expressly teach: and the second message includes an unique identification of the memory device, a value from a counter configured in the memory device, and a second cryptographic nonce. In this instance the examiner notes the teachings of prior art reference Fava. With regards to applicant’s claim limitation element of, “and the second message includes an unique identification of the memory device, a value from a counter configured in the memory device, and a second cryptographic nonce”, Fava teaches in par. 0050 the following: “The UID 212 is provided together with a signature calculated by the boot device 156 using the secret key 214. For example, this calculation may be done as follows: Signature=(Secret Key, UID|Freshness), where Freshness is a field used for anti-replay (e.g., the Freshness can be a monotonic counter, a time stamp, a NONCE, etc.). In this example, the identity is included in the data read by application controller 152 from the boot device 156, and the identity is verified using the following relationship: Identity proof=UID|Freshness|Signature, whereas mentioned above, Freshness is a field used for anti-replay (e.g., the Freshness can be a monotonic counter, a time stamp, a NONCE, etc.)”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu and HONJO with the teachings of Fava by having their system comprise an enhance cryptographic communication process. One would have been motivated to do so to provide a simple and effective means to secure data communication, wherein the enhance cryptographic communication process helps facilitate communication integrity within the network and makes it easier to secure network communication. As to claim 9, the system of Prabhu and HONJO as applied to claim 8 above teaches command verification, specifically Prabhu teaches a method of claim 8, wherein the first digital signature is applied to a first message in a request from the client computer system to the memory device (i.e.., …teaches in par. 0043 the following: “The server computing device 112 responds with a command message including details for a command, such as a machine-readable encoding of the command and parameters for the command, if the verification is successful (236). The processor in the client computing device 108 receives the command message with the network interface device and forwards the command message to the embedded computing device 104 through the peripheral connection device. The embedded computing device 104 receives the command message from the client computing device 108 via the peripheral connection using the peripheral connection device and the processor in the embedded computing device 104 verifies a cryptographic signature in the command message that corresponds to the unique command identifier, counter, and the command message data using a cryptographic key”); and the first message includes the command and a first cryptographic nonce (i.e.., …teaches in par. 0043 the following: “The server computing device 112 responds with a command message including details for a command, such as a machine-readable encoding of the command and parameters for the command, if the verification is successful (236). The processor in the client computing device 108 receives the command message with the network interface device and forwards the command message to the embedded computing device 104 through the peripheral connection device. The embedded computing device 104 receives the command message from the client computing device 108 via the peripheral connection using the peripheral connection device and the processor in the embedded computing device 104 verifies a cryptographic signature in the command message that corresponds to the unique command identifier, counter, and the command message data using a cryptographic key” …teaches in par. 0043 the following: “The counter enables the embedded computing device 104 to identify each access request and prevent a so-called “replay attack” where an attacker sends a previously-executed valid command to the embedded computing device 104 without proper authorization after the embedded computing device 104 had already executed the command.”). As to claim 10, the system of Prabhu and HONJO as applied to claim 9 above teaches command verification, specifically Prabhu expressly teaches a method of claim 9, and a cryptographic key that is stored in both the memory device and the server system (i.e., …teaches in par. 0043 the following: “the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108.”.). The system of Prabhu and HONJO does not expressly teach: wherein the first digital signature includes a Hash-based Message Authentication Code (HMAC) generated from the first message. In this instance the examiner notes the teachings of prior art reference Fava. Fava teaches in par. 0077 the following: “a Message and its MAC (signature) calculated by using an algorithm based on a secret KEY (e.g., HMAC-SHA256)”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu and HONJO with the teachings of Fava by having their system comprise an enhance cryptographic communication process. One would have been motivated to do so to provide a simple and effective means to secure data communication, wherein the enhance cryptographic communication process helps facilitate communication integrity within the network and makes it easier to secure network communication. As to claim 11, the system of Prabhu and HONJO as applied to claim 9 above teaches command verification, specifically Prabhu teaches a method of claim 9, wherein the first digital signature is generated using the session key, or a cryptographic key stored in the server system in association with the unique identification of the memory device, or any combination thereof (i.e., the examiner notes that applicant’s usage of the term “or” places the above limitation(s) in alternative form. As such Prabhu teaches in par. 0043 the following: “the web server computing device 112 signs the command using a private signing key and the memory 328 in the embedded computing device 104 stores a corresponding public key in an internal memory that the embedded computing device 104 uses to verify the cryptographic signature.” …teaches in par. 0043 the following: “the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108.”.). As to claim 12, the system of Prabhu and HONJO as applied to claim 11 above teaches command verification, specifically neither reference expressly teaches a method of claim 11, wherein the session key is configured to expire in a time period of a predetermined length from validation of the identity data. In this instance the examiner notes the teachings of prior art reference Fava. Fava teaches in par. 0078 the following: “freshness is included in the calculation: Measure=MAC (Secret_Key, pages_content|freshness).”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu and HONJO with the teachings of Fava by having their system comprise an enhance key management process. One would have been motivated to do so to provide a simple and effective means to control key related data stored in the device, wherein the enhance key management process helps facilitate secure communication within the network and makes it easier to configure the devices for network communication. As to claim 13, the system of Prabhu and HONJO as applied to claim 12 above teaches command verification, specifically Prabhu teaches a method of claim 12, further comprising: generating the first cryptographic nonce for the command (i.e., …teaches in par. 0008 the following: “the command message including command data and a cryptographic signature corresponding to the unique command identifier, the counter, and the command data…”) and the second cryptographic nonce for the identity data (i.e., …teaches in par. 0008 the following: “transmit a second response message including the counter value and the unique command identifier”), wherein the first cryptographic nonce and the second cryptographic nonce are provided to the memory device via the client computer system (i.e., …teaches in par. 0044 the following: “the embedded computing device 104 verifies the counter value received with the command” …teaches in par. 0045 the following: “the counter, and the return data generated in response to the requested operation.”.). As to claim 20, the system of Prabhu and HONJO as applied to claim 19 above teaches command verification, specifically Prabhu expressly teaches a non-transitory computer storage medium of claim 19, wherein the method further comprises: receiving, via the client computer system from the memory device, identity data of the memory device (i.e., …teaches in par. 0041 the following: “The server computing device 112 receives the unique command identifier and counter from the client system 108 and verifies (compares) the unique command identifier previously sent in block 212 and the unique command identifier received from the client system 108 (232).”); validating the identity data based on a secret of the memory device stored in the computing system (i.e., …teaches in par. 0041 the following: “The server computing device 112 receives the unique command identifier and counter from the client system 108 and verifies (compares) the unique command identifier previously sent in block 212 and the unique command identifier received from the client system 108 (232).”); and establishing a session key known between the computing system and the memory device based on validation of the identity data (i.e., …teaches in par. 0043 the following: “the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108. In another embodiment,”); wherein when executed in the memory device, the command causes the memory device to activate a security feature of the memory device, or to replace a first cryptographic key with a second cryptographic key, or any combination thereof (i.e., …the examiner notes that applicant’s usage of the term “or” places the above limitation(s) in alternative form. As such with regards applicant’s alternate form of, “wherein when executed in the memory device, the command causes the memory device to activate a security feature of the memory device”, Prabhu teaches in par. 0044 the following: “the embedded computing device 104 verifies the counter value received with the command and verifies the digital signature or the command authentication code to ensure that the command is valid prior to execution of the command. The processor in the embedded computing device 104 performs the requested operation in the command message based on the command data in the command message only in response to verification that the cryptographic signature corresponds to the counter value, the unique command identifier, and the command data using the cryptographic key. For example, upon successful verification of the command message the embedded computing device 104, which is operatively connected to an actuator in the power tool 102 in one embodiment, is further configured to perform the requested operation based on the command data to operate the actuator in the power tool 102.” ); wherein the identity data includes a second message and a second digital signature applied on the second message using a secret cryptographic key of the memory device (i.e., …teaches in par. 0045 the following: “embedded computing device 104 generates a third response message including the unique command identifier, the counter, and the return data generated in response to the requested operation.” …teaches in par. 0043 the following: “he memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device” …The examiner notes that all communication between the embedded memory device and server will be cryptographically processed using the shared key.); and wherein the first digital signature is applied to a first message in a request from the client computer system to the memory device (i.e., …teaches in par. 0018 the following: “the command message including a cryptographic signature corresponding to the unique command identifier, the counter value, and command data to enable the embedded device to perform the operation in the request message.”); and the first message includes the command and a first cryptographic nonce (i.e., …teaches in par. 0018 the following: “the command message including a cryptographic signature corresponding to the unique command identifier, the counter value, and command data to enable the embedded device to perform the operation in the request message.” …teaches in par. 0042 the following: “The counter enables the embedded computing device 104 to identify each access request and prevent a so-called “replay attack” where an attacker sends a previously-executed valid command to the embedded computing device 104 without proper authorization after the embedded computing device 104 had already executed the command.”). The system of Prabhu and HONJO does not expressly teach: and the second message includes an unique identification of the memory device, a value from a counter configured in the memory device, and a second cryptographic nonce. In this instance the examiner notes the teachings of prior art reference Fava. With regards to applicant’s claim limitation element of, “and the second message includes an unique identification of the memory device, a value from a counter configured in the memory device, and a second cryptographic nonce”, Fava teaches in par. 0050 the following: “The UID 212 is provided together with a signature calculated by the boot device 156 using the secret key 214. For example, this calculation may be done as follows: Signature=(Secret Key, UID|Freshness), where Freshness is a field used for anti-replay (e.g., the Freshness can be a monotonic counter, a time stamp, a NONCE, etc.). In this example, the identity is included in the data read by application controller 152 from the boot device 156, and the identity is verified using the following relationship: Identity proof=UID|Freshness|Signature, whereas mentioned above, Freshness is a field used for anti-replay (e.g., the Freshness can be a monotonic counter, a time stamp, a NONCE, etc.)”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu and HONJO with the teachings of Fava by having their system comprise an enhance cryptographic communication process. One would have been motivated to do so to provide a simple and effective means to secure data communication, wherein the enhance cryptographic communication process helps facilitate communication integrity within the network and makes it easier to secure network communication. Claim(s) 14 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Prabhu in view of Bhalero (US Patent No. 10,114,939). As to claim 14, Prabhu teaches a computing system, comprising: and at least one processor configured via a set of instructions to: generate a first digital signature for a command using at least a cryptographic key stored in the server system in association with a memory device (i.e. …teaches in par. 0043 the following: “the web server computing device 112 signs the command using a private signing key” …teaches in par. 0044 the following: “The processor in the embedded computing device 104 only in response to successful verification of the cryptographic signature in the command message (244). Successful verification means that the cryptographic signature in the command message, which can only be generated by the server 112, corresponds to each of the unique command identifier, counter, and the command message data elements of the command message.”); and transmit the first digital signature, the client computer system to submit the command with the first digital signature to the memory device (i.e., …teaches in par. 0043 the following: “The server computing device 112 responds with a command message … The processor in the client computing device 108 receives the command message with the network interface device and forwards the command message to the embedded computing device 104 through the peripheral connection device.”. …teaches in par. 0044 the following: “The processor in the embedded computing device 104 only in response to successful verification of the cryptographic signature in the command message (244). Successful verification means that the cryptographic signature in the command message, which can only be generated by the server 112, corresponds to each of the unique command identifier, counter, and the command message data elements of the command message). The system of Prabhu does not expressly teach: memory storing cryptographic keys of memory devices and data indicative privileges of client computer systems to control the memory devices. In this instance the examiner notes the teachings of prior art reference Bhalero. Bhalero teaches in col. 9 lines 5-15 the following: “security certificate 402, which may include authentication information 404. As with security certificate 208, authentication information 404 included in security certificate 402 may include a public encryption key for the smart device. The authentication information may also include an X.509 digital certificate with a digital signature and identification of a public key algorithm that may be used to authenticate the digital signature for the smart device, as well as identification of the certificate authority that issued the security certificate.”. Bhalero teaches in col. 6 lines 65-67 & col. 7 lines 1-5 the following: “privilege information may be included as an extension in an X.509 certificate. In some examples, privilege information may specifically describe the types of interactions the control device may request from the smart device.”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu with the teachings of Bhalero by having their system comprise a enhanced command execution process. One would have been motivated to do so to provide a simple and effective means to control device operations, wherein the enhanced command execution process helps facilitate secure device operation within the network and makes it easier to configure a device. As to claim 15, the system of Prabhu and Bhalerao as applied to claim 14 above teaches command verification, specifically Prabhu expressly teaches a computing system of claim 14, wherein the at least one processor is further configured via the set of instructions to: receive, via the client computer system from the memory device, identity data of the memory device (i.e., …teaches in par. 0041 the following: “The server computing device 112 receives the unique command identifier and counter from the client system 108 and verifies (compares) the unique command identifier previously sent in block 212 and the unique command identifier received from the client system 108 (232).”); validate the identity data based on a secret of the memory device stored in the computing system (i.e., …teaches in par. 0041 the following: “The server computing device 112 receives the unique command identifier and counter from the client system 108 and verifies (compares) the unique command identifier previously sent in block 212 and the unique command identifier received from the client system 108 (232).”); and establish a session key known to the computing system and the memory device based on validation of the identity data (i.e., …teaches in par. 0043 the following: “the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108. In another embodiment,”); wherein when executed in the memory device, the command causes the memory device to activate a security feature of the memory device, or to replace a first cryptographic key with a second cryptographic key, or any combination thereof (i.e., …the examiner notes that applicant’s usage of the term “or” places the above limitation(s) in alternative form. As such with regards applicant’s alternate form of, “wherein when executed in the memory device, the command causes the memory device to activate a security feature of the memory device”, Prabhu teaches in par. 0044 the following: “the embedded computing device 104 verifies the counter value received with the command and verifies the digital signature or the command authentication code to ensure that the command is valid prior to execution of the command. The processor in the embedded computing device 104 performs the requested operation in the command message based on the command data in the command message only in response to verification that the cryptographic signature corresponds to the counter value, the unique command identifier, and the command data using the cryptographic key. For example, upon successful verification of the command message the embedded computing device 104, which is operatively connected to an actuator in the power tool 102 in one embodiment, is further configured to perform the requested operation based on the command data to operate the actuator in the power tool 102.” ). Claim(s) 16 - 18 are rejected under 35 U.S.C. 103 as being unpatentable over Prabhu in view of Bhalero as applied to claim 15 above and further in view of Fava. As to claim 16, the system of Prabhu and Bhalerao as applied to claim 15 above teaches command verification, specifically Prabhu expressly teaches a computing system of claim 15, wherein the identity data includes a second message and a second digital signature applied on the second message using a secret cryptographic key of the memory device (i.e., …teaches in par. 0018 the following: “the command message including a cryptographic signature corresponding to the unique command identifier, the counter value, and command data to enable the embedded device to perform the operation in the request message.” …teaches in par. 0042 the following: “The counter enables the embedded computing device 104 to identify each access request and prevent a so-called “replay attack” where an attacker sends a previously-executed valid command to the embedded computing device 104 without proper authorization after the embedded computing device 104 had already executed the command.”); the first digital signature is applied to a first message in a request from the client computer system to the memory device (i.e., …teaches in par. 0018 the following: “the command message including a cryptographic signature corresponding to the unique command identifier, the counter value, and command data to enable the embedded device to perform the operation in the request message.”); and the first message includes the command and a first cryptographic nonce (i.e., …teaches in par. 0018 the following: “the command message including a cryptographic signature corresponding to the unique command identifier, the counter value, and command data to enable the embedded device to perform the operation in the request message.” …teaches in par. 0042 the following: “The counter enables the embedded computing device 104 to identify each access request and prevent a so-called “replay attack” where an attacker sends a previously-executed valid command to the embedded computing device 104 without proper authorization after the embedded computing device 104 had already executed the command.”). The system of Prabhu and Bhalerao do not expressly teach: the second message includes an unique identification of the memory device, a value from a counter configured in the memory device, and a second cryptographic nonce. In this instance the examiner notes the teachings of prior art reference Fava. With regards to applicant’s claim limitation element of, “and the second message includes an unique identification of the memory device, a value from a counter configured in the memory device, and a second cryptographic nonce”, Fava teaches in par. 0050 the following: “The UID 212 is provided together with a signature calculated by the boot device 156 using the secret key 214. For example, this calculation may be done as follows: Signature=(Secret Key, UID|Freshness), where Freshness is a field used for anti-replay (e.g., the Freshness can be a monotonic counter, a time stamp, a NONCE, etc.). In this example, the identity is included in the data read by application controller 152 from the boot device 156, and the identity is verified using the following relationship: Identity proof=UID|Freshness|Signature, whereas mentioned above, Freshness is a field used for anti-replay (e.g., the Freshness can be a monotonic counter, a time stamp, a NONCE, etc.)”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu and Bhalero with the teachings of Fava by having their system comprise an enhance cryptographic communication process. One would have been motivated to do so to provide a simple and effective means to secure data communication, wherein the enhance cryptographic communication process helps facilitate communication integrity within the network and makes it easier to secure network communication. As to claim 17, the system of Prabhu and Bhalerao as applied to claim 16 above teaches command verification, specifically Prabhu expressly teaches a computing system of claim 16, wherein the first digital signature is generated using the session key, or a cryptographic key stored in the computing system in association with the unique identification of the memory device, or any combination thereof (i.e., the examiner notes that applicant’s usage of the term “or” places the above limitation(s) in alternative form. As such Prabhu teaches in par. 0043 the following: “the web server computing device 112 signs the command using a private signing key and the memory 328 in the embedded computing device 104 stores a corresponding public key in an internal memory that the embedded computing device 104 uses to verify the cryptographic signature.” …teaches in par. 0043 the following: “the memory 328 in the embedded computing device 104 stores a symmetric cryptographic key that is a unique shared secret key stored in each embedded device and that is shared with the server computing device 112 but not the client computing device 108.”.). The system of Prabhu and Bhalerao do not expressly teach: and the session key is configured to expire in a time period of a predetermined length from validation of the identity data. In this instance the examiner notes the teachings of prior art reference Fava. Fava teaches in par. 0078 the following: “freshness is included in the calculation: Measure=MAC (Secret_Key, pages_content|freshness).”. Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the of the claimed invention was made to implement the teachings of Prabhu and Bhalero with the teachings of Fava by having their system comprise an enhance cryptographic communication process. One would have been motivated to do so to provide a simple and effective means to secure data communication, wherein the enhance cryptographic communication process helps facilitate communication integrity within the network and makes it easier to secure network communication. As to claim 18, the system of Prabhu and Bhalerao as applied to claim 17 above teaches command verification, specifically Prabhu expressly teaches a computing system of claim 17, wherein the at least one processor is further configured via the set of instructions to: generate the first cryptographic nonce for the command (i.e., …teaches in par. 0008 the following: “the command message including command data and a cryptographic signature corresponding to the unique command identifier, the counter, and the command data…”) and the second cryptographic nonce for the identity data (i.e., …teaches in par. 0008 the following: “transmit a second response message including the counter value and the unique command identifier”), wherein the first cryptographic nonce and the second cryptographic nonce are provided to the memory device via the client computer system (i.e., …teaches in par. 0044 the following: “the embedded computing device 104 verifies the counter value received with the command” …teaches in par. 0045 the following: “the counter, and the return data generated in response to the requested operation.”.). Art Made of Record The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Brandwine et al (US Patent No. 9,729,524) and Zhang et al. (US Patent Publication No. 2020/0186342). Contact Information Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRYAN F WRIGHT whose telephone number is (571)270-3826. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni Shiferaw can be reached on (571)272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRYAN F WRIGHT/Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Feb 24, 2025
Application Filed
Aug 25, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744820
HIGHLY SCALABLE FOUR-DIMENSIONAL GEOSPATIAL DATA SYSTEM FOR SIMULATED WORLDS
2y 1m to grant Granted Sep 22, 2026
Patent 12719909
AUTOMATED VULNERABILITY AND THREAT LANDSCAPE ANALYSIS
3y 5m to grant Granted Aug 25, 2026
Patent 12712732
METHOD FOR AUTHENTICATION OF A SERVICE PROVIDER DEVICE TO A USER DEVICE
2y 9m to grant Granted Aug 18, 2026
Patent 12707015
IMAGE FORMING APPARATUS AND USER REGISTRATION METHOD FOR IMAGE FORMING APPARATUS
3y 2m to grant Granted Aug 11, 2026
Patent 12689613
Privileged remote access for Operational Technology (OT)/Internet of Things (IOT)/Industrial IOT (IIOT)/Industrial Control System (ICS)
4y 0m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+24.1%)
3y 2m (~1y 6m remaining)
Median Time to Grant
Low
PTA Risk
Based on 820 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month