Prosecution Insights
Last updated: August 14, 2026
Application No. 19/076,961

REMOTE ATTESTATION TRANSPORT LAYER SECURITY AND SPLIT TRUST ENCRYPTION

Non-Final OA §103
Filed
Mar 11, 2025
Priority
Jul 19, 2021 — divisional of 11/743,293 +1 more
Examiner
HOLDER, BRADLEY W
Art Unit
Tech Center
Assignee
Google LLC
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
2y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
411 granted / 491 resolved
+23.7% vs TC avg
Strong +62% interview lift
Without
With
+62.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 8m
Avg Prosecution
12 currently pending
Career history
504
Total Applications
across all art units

Statute-Specific Performance

§101
17.8%
-22.2% vs TC avg
§103
51.1%
+11.1% vs TC avg
§102
9.9%
-30.1% vs TC avg
§112
16.0%
-24.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 491 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This is in response to Application #19/076,961 filed on 03/11/2025 in which Claims 1-20 are presented for examination. Status of Claims Claims 1-20 are pending, of which Claims 1, 2, 9, 10, 11, 12, 19, 20 are rejected under 35 U.S.C. 103, dependent Claim(s) 3-8, 13-18, is/are objected to as being allowable as a whole over prior art if rewritten in independent form including all of the limitations of its/their base independent claim and any intervening dependent claims. Applicant’s Most Recent Claim Set of 03/11/2025 Applicant’s most recent claim set of 03/11/2025 is considered to be the latest claim set under consideration by the examiner. Prior Art Rejections - 35 USC § 102 and/or 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claim(s) 1, 2, 11, 12 are rejected under 35 U.S.C. 103 as being unpatentable over Ono et al US Patent Application Publication #2002/0035685 in view of Satpathy US Patent #11,265,721. Regarding Claim 1, Ono et al discloses: A computer-implemented method executed by data processing hardware that causes the data processing hardware to perform operations comprising [(Ono et al. Fig 10 Items 401, 416) where Ono et al teaches a hardware processor and connected memory for storing and executing instructions to perform operations]: establishing, using a cryptographic protocol, a first communication session between a first computing device and an intermediary device, the first communication session encrypted with a first session key; establishing, using the first communication session, a second communication session between the first computing device and a second computing device through the intermediary device, the second communication session encrypted with a second session key different than the first session key [(Ono et al. Par 24 Lines 1-4; Par 25 Lines 1-11; Par 29 Lines 1-9; Par 89 Lines 1-7; Par 98 Lines 4-9; Par 102 Lines 1-3; Par 103 Lines 1-3; Par 104 Lines 1-12; Par 105 Lines 2-19) where Ono et al teaches an intermediary device that bridges communications between a server and a client, with communications between the server and the intermediary device encrypted with a first secret session key and then communications between the intermediary device and the client encrypted with a second different secret session key, the first secret session key being only known to the server and the intermediary device, with the second secret session being only known to the intermediary device and the client device, the session keys would not be secret, if either were both known to the server and known to the client]; Ono et al does not appear to explicitly disclose: receiving, at the first computing device via the second communication session from the second computing device, an attestation request requesting an attestation report from the first computing device; generating the attestation report based on the second session key; and sending, via the second communication session, the attestation report to the second computing device. However, Satpathy discloses: receiving, at the first computing device via the second communication session from the second computing device, an attestation request requesting an attestation report from the first computing device; generating the attestation report based on the second session key; and sending, via the second communication session, the attestation report to the second computing device [(Satpathy Col 23 Lines 9-11, 15-18, 59-67; Col 24 Line 1) where Satpathy teaches a server receiving an encrypted attestation request from a peripheral device over a communications channel or session encrypted with a second session key, then responding with an attestation report encrypted with the second session key back to the peripheral device over the same communications channel or session]. Ono et al and Satpathy are analogous art because they are from the “same field of endeavor” and are from the same “problem-solving area”. Namely, they are both from the field of “information security”. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Ono et al and the teachings of Satpathy by providing a server receiving an encrypted attestation request from a peripheral device over a communications channel or session encrypted with a second session key, then responding with an attestation report encrypted with the second session key back to the peripheral device over the same communications channel or session as taught by Satpathy in the teaching described by Ono et al. The motivation for doing so would be to increase the usability and flexibility of Ono et al by providing a server receiving an encrypted attestation request from a peripheral device over a communications channel or session encrypted with a second session key, then responding with an attestation report encrypted with the second session key back to the peripheral device over the same communications channel or session as taught by Satpathy in the teaching described by Ono et al so as to provide a secure path to respond to an encrypted attestation request over an encrypted communications channel. Regarding Claim 2, most of the limitations of this claim have been noted in the rejection of Claim 1. Applicant is directed to the rejection of Claim 1 above. In addition, the combination of Ono et al and Satpathy discloses: The method of claim 1, wherein the cryptographic protocol comprises a Transport Layer Security (TLS) protocol. [(Ono et al Par 5 Lines 5, 8 where Ono et al defines Transport Layer Security Protocol as TLS for the remainder of Ono et al; Par 89 Lines 1-7) where Ono et al teaches that the TLS Protocol is employed with the communications through the intermediary device]. Regarding Claim 11: It is a system claim corresponding to the method claim of cl1im 1. Therefore, claim 11 is rejected with the same rationale as applied against claim 2 above. Regarding Claim 12: It is a system claim corresponding to the method claim of claim 2. Therefore, claim 12 is rejected with the same rationale as applied against claim 2 above. Claims 9, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Ono et al US Patent Application Publication #2002/0035685 in view of Satpathy US Patent #11,265,721 and further in view of Bysani et al US Patent #10,466,933. Regarding Claim 9: the combination Ono et al and Satpathy discloses: The method of claim 1, The combination of Ono et al and Satpathy does not appear to explicitly disclose: wherein the intermediary device comprises a load balancer. However, Bysani et al discloses: wherein the intermediary device comprises a load balancer [(Bysani et al Col 6 Lines 19-22) where Bysani et al teaches that an intermediary device is a load balancer]. Ono et al and Satpathy, and Bysani et al are analogous art because they are from the “same field of endeavor” and are from the same “problem-solving area,”. Namely, they are both from the field of “information security”. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Ono et al and Satpathy and the teachings of Bysani et al by providing an intermediary device that is a load balancer as taught by Bysani et al in the teaching described by Ono et al and Satpathy. The motivation for doing so would be to increase the usability and flexibility of Ono et al and Satpathy, and Bysani et al by providing an intermediary device that is a load balancer as taught by Bysani et al in the teaching described by Ono et al and Satpathy so as provide a way to balance the load placed on a network. Regarding Claim 19: It is a system claim corresponding to the method claim of claim 9. Therefore, claim 19 is rejected with the same rationale as applied against claim 9 above. Claims 10, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Ono et al US Patent Application Publication #2002/0035685 in view of Satpathy US Patent #11,265,721 and further in view of Hybertson US Patent #10,050,945. Regarding Claim 10: the combination Ono et al and Satpathy discloses: The method of claim 1, The combination of Ono et al and Satpathy does not appear to explicitly disclose: wherein the intermediary device comprises a proxy. However, Hybertson discloses: wherein the intermediary device comprises a proxy [(Hybertson Col 31 Lines 33-34) where Hybertson teaches that an intermediary device is a proxy]. Ono et al and Satpathy, and Hybertson are analogous art because they are from the “same field of endeavor” and are from the same “problem-solving area,”. Namely, they are both from the field of “information security”. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Ono et al and Satpathy and the teachings of Hybertson by providing an intermediary device that is a proxy as taught by Hybertson in the teaching described by Ono et al and Satpathy. The motivation for doing so would be to increase the usability and flexibility of Ono et al and Satpathy, and Hybertson by providing an intermediary device that is a proxy as taught by Hybertson in the teaching described by Ono et al and Satpathy so as provide a substitute device to isolate suspect code for further testing. Regarding Claim 20: It is a system claim corresponding to the method claim of claim 10. Therefore, claim 20 is rejected with the same rationale as applied against claim 10 above. Allowable Subject Matter – Dependent Claim(s) Claim(s) 3-8, 13-18 is/are objected to as being dependent upon a rejected base claim, but would be allowable as a whole over prior art if rewritten in independent form including all of the limitations of its/their base independent claim, and any intervening dependent claims. The following is a statement of reasons for the indication of allowable subject matter. The closest prior art, as recited, Ono et al US Patent Application Publication #2002/0035685 and Satpathy US Patent #11,265,721, are also generally directed to various aspects of providing implementation of remote attestation utilizing transport layer security in establishing a communications session between a first and a second computing device with the communications between the devices occurring through an intermediary device. However, Ono et al or Satpathy does not teach or suggest, either singularly or in combination, the particular combination of steps or elements as recited in the dependent Claim(s) 3-8, 13-18 when also incorporating all of the limitations of its/their base independent claim and any intervening dependent claims. For example, none of the cited prior art teaches or suggests the steps of: where generating the attestation report based on the second session key includes generating, using the second session key, a token and signing the generated token with an attestation key, where authenticity of the attestation key is confirmed by a third party, where the authenticity is confirmed via a certificate issued by the third party, where generating the attestation report based on the second session key includes generating a derived key derived from the second session key, including the derived key within the attestation report, where the operations further comprise, after sending the attestation report to the second computing device, receiving, from the second computing device, a first portion of a data encryption key, and receiving, from a third computing device, a second portion of the data encryption key, the second portion different than the first portion, where the operations further include combining the first portion of the data encryption key and the second portion of the data encryption key, and decrypting data using the combined data encryption key. As recited in dependent Claim(s) 3-8, 13-18, when also incorporating all of the limitations of its/their base independent claim, any intervening dependent claims, and any additional limitations found in dependent Claim(s) 3-8, 13-18. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Soriente et al - US_20190243950: Soriente et al teaches remote attestation in trusted execution environments. Ganesan - US_5535276: Ganesan teaches communications utilizing split private key asymmetric cryptography. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRADLEY HOLDER whose telephone number is 571-270-3789. The examiner can normally be reached on Monday-Friday 10:00AM-7:00PM Eastern Time. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards, can be reached on (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRADLEY W HOLDER/ Primary Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

Mar 11, 2025
Application Filed
Jul 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705328
ACCESS CONTROL FOR CONTENT DELIVERY SERVICES
2y 7m to grant Granted Aug 11, 2026
Patent 12695746
COMPUTING CLUSTER SYSTEM, SECURITY AUTHENTICATION METHOD, NODE DEVICE AND STORAGE MEDIUM
2y 4m to grant Granted Jul 28, 2026
Patent 12689521
CIRCUITRY FOR PROTECTING A COMMUNICATION CHANNEL
2y 3m to grant Granted Jul 21, 2026
Patent 12683809
METHOD AND APPARATUS FOR VERIFYING FIRMWARE
2y 9m to grant Granted Jul 14, 2026
Patent 12632611
SYSTEM AND METHOD FOR SECURE KEY MANAGEMENT FOR ENCRYPTED CORE DUMP
2y 3m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+62.5%)
3y 8m (~2y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 491 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month