DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This action is response to communication: response to election filed on 08/19/2026.
Claims 1-20 are currently pending in this application. Applicants have elected Group I (Claims 1-11 and 19-20) without traverse.
The IDS filed on 03/20/2025 has been accepted.
Election/Restrictions
Claims 12-18 are withdrawn from further consideration pursuant to 37 CFR 1.142(b) as being drawn to a nonelected group, there being no allowable generic or linking claim. Election was made without traverse in the reply filed on 08/19/2026.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 USC 101 because the clamed invention is directed toward an abstract idea without significantly more. The claims require receiving a key, establishing a communication channel, receiving key material, and determining a session key. These limitations merely cover mental processes, but for the recitation of generic computing components.
Next, the judicial exception is not integrated into a practical application. Other elements in the claim include a processor and a sniffer device. These additional elements do not improve the functioning of a computer or other technology, are not applied with any particular machine (except for generic computing elements), do not effect a transformation of a particular article to a different state, and are not applied in any meaningful way beyond generally linking the use of the judicial exception to a particular technological environment, such that the claim as a whole is more than a drafting effort designed to monopolize the exception. Using a generic computing device to receive and process data amounts to merely applying the judicial exception using a generic computing component. Moreover, the “determine, by the client, a session key” amount to insignificant extra-solution activity that is insufficient to integrate the abstract idea into a practical application. Since the claims do not recite an improvement to the functioning of the computer system or other computer related products, nor do the claims recite an improvement to a technical field, the claims do not integrate the abstract idea into a practical application and are thus directed toward an abstract mental process.
Further, the claims do not include additional elements that are sufficient to amount to significantly more than a judicial exception. The present claims do not recite specific limitations that are not well understood, routine, and conventional. Limitations including receiving a key, establishing a secure communication channel, receiving key material generating data, and determining a session key amount to no more than applying the exception using generic computer components.
Therefore, the claims are not patent eligible as the claims are directed toward a judicial exception that do not amount to significantly more. The dependent claims do not cure the deficiencies.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-11, 19, and 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
As per claims 1-11, 19, and 20, the independent claim recites “establish … a secure communication channel .. responsive to the public key.” It is unclear what it means to perform an action responsive to an item. Does this mean that a secure communication channel is established based on the reception of a key, or does this mean a secure communication channel is established using the key?
As per claims 1-11, 19, and 20 the claims recite multiple steps including determining a session key. There seem to be essential steps missing as it is unclear how the claim limitations relate to one another. For example, in the independent claim, the claim recites establishing a secure communication channel between a sniffer and a first wireless device. It is unclear how the secure communication channel relates to the claim limitations as this channel is not used in other limitations of the claims. The independent claim also ends with determining a session key. However, it is unclear what this session key is used for. Is the key to be used to establish a secure channel? And if it is, what communication/devices is it used for? In general, the claism recite limitations that do not seem to relate to one another, nor do they perform any useful steps to perform any secure functions.
As per claims 8-9, claim 8 recites wherein “the client receives the key material via an OOB channel; a shared secret secures the OOB channel.” However, the independent claims already teach such communications, and such channels are presumed to be the primary modes of communication. If such channels are out of band, it is unclear what channels are actually in-band, and what types of communication channels would be used in-band if such communication channels are considered out of band.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-5, 11, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Soriente et al. US Patent Application Publication 2021/0377224 (Soriente), in view of Devarajan et al. US Patent Application Publication 2021/0344511 (Dev).
As per claim 1, Soriente teaches a non-transitory computer-readable medium comprsiign instructions that are executable by a processor of a sniffer device to cause the sniffer device to: receive, by a client of the sniffer device a public key; establish, by the client, a secure communication channel between the sniffer device and a first wireless device responsive to the public key (paragraphs 34-35 with establishing a secure communication between client and proxy utilizing public key; see also Figure 1); receive, by the client, key material after establishing the secure communication channel (paragraph 37, with proxy receiving signed fetching request from client; see also Figure 1), wherein the key material is related to a communication session between the first wireless device and a second wireless device (see paragraph 37, wherein the fetching request is signed).
Although Soriente teaches a communication session between a first wireless device and a second wireless device, Soriente does not explicitly teach wherein the communications session is established ushing a shared password, and determine, by the client, a session key responsive to the key material and the public key. However, this would have been obvious. For example, see Dev (password (paragraph 89, 90 with snooping proxy snooping keys between handshake between two devices; see paragarph78 wherein connection between the devices are secured via shared key/password; paragraph 90 with determining keys for session after snooping; see paragraph 49 wherein the handshake includes public key).
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of Soriente with Dev. One of ordinary skill in the art would have been motivated to perform such an addition to create more security by inspecting encrypted traffic in a cloud-based security system (pargraph 3 of Dev).
As per claim 2, the Soriente combination teaches wherein the key material excludes the shared password and the session key that is uniquely related to the communication session (Soriente paragraph 37 wherein key material is a signed request).
As per claim 3, the Soriente combination teaches wherein the instructions are executable by the processor to further cause the sniffer device to: receive, by the client, the shared password from a device that is external to the first wireless device (obvious over the Soriente combination; see Dev paragraphs 89 and 90 wherein the keys are snooped between a host and server; see paragraph 78 wherein the keys are shared keys).
As per claim 4, it would have been obvious over the Soriente combination wherein the instructions are executable by the processor to further cause the sniffer device to: intercept, by the sniffer device, a packet sent in the communication session, wherein the packet includes a payload that is encrypted with forward secrecy using the session key; and decrypt, by the sniffer device, the payload of the packet using the session key (obvious over Dev; see paragraphs 79-83 wherein encrypted packets are intercepted and then analyzed; see Dev paragraphs 56-58 with forward secrecy and decrypting conversations).
As per claim 5, it would have been obvious over the Soriente combination wherein the key material is encrypted using the public key of the sniffer device, and the instructions are executable by the processor to further cause the sniffer device to: decrypt, by the client, the key material using a private key of the sniffer device that forms a key pair with the public key of the sniffer device (obvious over the Soriente combination; see paragraph 79 with the interception proxy forming multiople connections between clieint and server; communication is established using root CA and establishes trust via handshake; see information on handshake in paragraphs 75-78).
As per claim 11, the Soriente combination teaches wherein the client receives the key material via an in-band channel that is secured using the public key of the sniffer device (obvious over Dev; see paragraph 79 with proxy interception and proxy opening SSL connection with client; see paragraphs 75-78 with information on SSL handshake and process).
Claim 19 is rejected using the same basis of arguments used to reject claim 1 above.
Claim(s) 6-10 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over the Soriente combination as applied above, and further in view of Sinha US Patent Application Publication 2011/0231659 (Sinha).
As per claim 6, the Soriente combination does not explicitly teach wherein receiving the public key is performed in an OOB key exchange. However, this would have been obvious. Dev paragraph 53 teaches wherein public keys are made available to the public, and it would have been obvious to one of ordinary skill in the art to use any form of communication retrieve public available information. However, for a more explicit teaching on out of band key exchange, see Sinha (abstract, paragraph 5, and throughout).
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of the Soriente combination with Sinha. One of ordinary skill in the art would have been motivated to perform such an addition to improve efficiency by impoving network performance and efficiency (paragraphs 3-4 of Sinha).
As per claim 7, it would have been obvious over the Soriente combination wherein the OOB key exchange provisions the public key of the sniffer device to the first wireless device (obvious over Sinha; see throughout reference wherein key exchanges are performed out of band).
As per claim 8, it would have obvious over the Soriente combination wherein the client receives the key material via an OOB channel; a shared secret secures the OOB channel; the client generates the shared secret using the public key of the sniffer device and a private key of the first wireless device; and the public key of the first wireless device forms a key pair with the private key of the first wireless device (see throughout Sinha with utilizing OOB channels; see throughout Dev such as in paragarphs 52-55 with utilizing PKI to secure communications/channels).
As per claim 9, it would have been obvious over the Soriente combination wherein the communication session is established between the first wireless device and the second wireless device in a WLAN; and the OOB channel is a communication channel that excludes the WLAN as a transmission medium (obvious over the SOriente combination; see Dev paragraph 39 wherein WLAN can be used for communication; see throughout Sinha wherein communications can be out of band).
As per claim 10, it would have been obvious over the Soriente combination wherein the instructions are executable by the processor to further cause the sniffer device to: generate, by the client, a shared secret using the public key of the first wireless device and a private key of the sniffer device that forms a key pair with the public key of the sniffer device, wherein the OOB exchange provisions the public key of the sniffer device to the first wireless device (see Dev with utilizing DHE and Elliptic Curive DHE; see also paragarphs 52-55 with utilizing PKI to secure communications/channels)
Claim 20 is rejected using the same basis of arguments used to reject claim 6 above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JASON KAI YIN GEE whose telephone number is (571)272-6431. The examiner can normally be reached on Monda-Friday 8:30-5:00 PST Pacific.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on (571) 272-37393739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/JASON K GEE/Primary Examiner, Art Unit 2495