Prosecution Insights
Last updated: August 14, 2026
Application No. 19/107,153

ENCLAVE ARCHITECTURE

Non-Final OA §103
Filed
Feb 27, 2025
Priority
Sep 06, 2022 — GB 2213012.4 +1 more
Examiner
FAROOQUI, QUAZI
Art Unit
Tech Center
Assignee
The Blockhouse Technology Limited
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
384 granted / 463 resolved
+22.9% vs TC avg
Moderate +15% lift
Without
With
+14.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
10 currently pending
Career history
467
Total Applications
across all art units

Statute-Specific Performance

§101
11.1%
-28.9% vs TC avg
§103
62.8%
+22.8% vs TC avg
§102
15.7%
-24.3% vs TC avg
§112
6.1%
-33.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 463 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detail Action This office action is response to the application 19/107,153 filed on 02/27/2025. Claims 1-3, 5-11, 13-17, 19-21, 24 & 25 are pending in this communication. Claims 4, 12, 18, 22 & 23 have been cancelled. Priority This application claims priority UNITED KINGDOM 2213012.4 09/06/2022. Priority date has been accepted. Claim Rejections - 35 USC § 103 The following is a quotation of AIA 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 5, 7, 16, 17, 19-21 & 25 are rejected under AIA 35 U.S.C. 103 as being unpatentable over XU; Emily Hong et al. (US 2021/0314312 A1) in view of BEN-ARI; Adi (2023/0269093). Regarding Claim 1, XU discloses a method of operating a computing system to manage a set of enrolled service enclaves {ABSTRACT}, wherein the system comprises: a network of computing devices; a plurality of service enclaves hosted on one or more of the computing devices of the network {Fig. 2 element 112 & [0016], “The management service 154 can manage and oversee the operation of one or more client devices 112”. Examiner’s note: cited client devices represent claimed ‘service enclaves’ in for example a multi-tenant service provider like AWS}; and an authority service hosted on a first computing device of the network {Fig. 2 element 154 & [0016], “The management service 154 can manage access to resources for a user account from various client devices 112. That is, the management service 154 can determine whether a user, a device, or a pairing of a user and a device are authorized to access resources based on access rights”. Examiner’s note: a management/authority service provider 154 is functioning as claimed ‘first computing device’}; the method comprising enrolling a new service enclave of the plurality of service enclaves, hosted on a second computing device of the network, into the set of enrolled service enclaves {[0063], “when a user signs onto a new client device 112 for a first time, the management component 179 can send an enrollment request to the management service 154”. Examiner’s note: the client device(s) 112 is functioning as claimed ‘second computing device’} by: the authority service receiving an identifier of the second computing device hosting the new service enclave {claim 1, “transmit, by the management service, a key generation request that instructs a certificate authority service to generate a public key that includes the unique device identifier and a private key for the client device”}; … in response to receiving the attestation, the authority service generating a certificate that associates the identifier of the second computing device with a public key of the new service enclave {claim 1: “wherein the device-identifying certificate provides secure authentication chaining of the unique device identifier in association with the certificate authority service; and transmit, by the management service, the device-identifying certificate and the private key to the client device”}; and the authority service providing the certificate to an already-enrolled service enclave of the plurality of service enclaves {ABSTRACT, “The management service instructs a certificate authority service to generate a public key that includes the unique device identifier and a private key for the client device, and provides the device-identifying certificate and the private key to the client device”}. XU, however, does not explicitly disclose the authority service using the identifier of the second computing device to receive, from the second computing device, an attestation of software code stored in the new service enclave; In an analogous reference BEN-ARI discloses the authority service using the identifier of the second computing device to receive, from the second computing device, an attestation of software code stored in the new service enclave {[0135] … [0148], “The invention combines aspects of the TLS protocol with a secure enclave attestation capability. A valid secure enclave attestation is an attestation that the secure enclave module 120 is genuine and secure and running the expected software (TCB), assuring that the private data is processed in secret and that the expected code is executed”}; Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to modify XU’s technique of ‘providing secured multi-tenant hosting service to client enclaves’ for ‘attesting software/code stored in a new tenancy or enrolled client’, as taught by BEN-ARI, in order to eliminate unauthorized software code storage that may be malicious. The motivation is - an authority service secures multi-tenant environments by verifying a new enclave's identity and software code to issue a digital certificate. This certificate allows the cloud provider to prove the enclave's legitimacy to the rest of the network. All references are inventions in analogous area but each invention teaches specific claimed limitation specifically and other references mutually cure each other’s deficiencies. When all claimed techniques are combined, they teach claimed invention. The Examiner notes that this motivation applies to all dependent and/or otherwise subsequently addressed claims unless addressed separately. Regarding Claim 2, XU as modified by BEN-ARI discloses all the features of claim 1. The combination further discloses the already-enrolled service enclave using a public key of the authority service to authenticate the certificate; {XU: [0034], “The certificate authority keys 196 can include a private key and a public key. The certificate authority service 190 can share the pubic key with other network devices, such as the identity provider server 103, management server 106, the key distribution server 109, and one or more client devices 112”} and the already-enrolled service enclave using the public key of the new service enclave to send encrypted data to the new service enclave {XU: [0066], “At step 512, the management service 154 can send the private key and the certificate to the client device 112. The management service 154 can encrypt and transmit the private key and certificate to the client device 112. In one example, the management service 154 manages a secured storage system located on the client device 112. The management service 154 can place the private key and the certificate in a secured storage location of the secured storage system”}. Regarding Claim 3, XU as modified by BEN-ARI discloses all the features of claim 1. The combination further discloses comprising the new service enclave generating an attestation report that includes the public key of the new service enclave and/or a public key of the authority service {XU: [0074], “The key distribution service 166 can use a public key associated with the certificate authority 115 to determine whether the certificate 181 from the management component 179 is a valid certificate”}. Regarding Claim 5, XU as modified by BEN-ARI discloses all the features of claim 1. The combination further discloses wherein the already-enrolled service enclave is permitted to communicate with the new service enclave only after receiving and authenticating the certificate generated by the authority service {XU: [0025], “The management service 154 can permit or deny access to one or more resources depending upon who is seeking to access the resources, what client devices 112 are used to seek access to the resources” … [0026], “The compliance rules 161 include certain profile, credential, compliance, and other parameters or rules associated with access to resources. The compliance rules 161 can define requirements for users of the client device 112, requirements of client device 112, requirements of the network 121, and other device or network operational requirements of factors”}. Regarding Claim 7, XU as modified by BEN-ARI discloses all the features of claim 1. The combination further discloses wherein the authority service is provided by an authority enclave hosted on the first computing device, the method further comprising the new service enclave receiving, from the authority service, an attestation of software code stored in the authority service {BEN-ARI: [0148], “The invention combines aspects of the TLS protocol with a secure enclave attestation capability. A valid secure enclave attestation is an attestation that the secure enclave module 120 is genuine and secure and running the expected software (TCB), assuring that the private data is processed in secret and that the expected code is executed”}. Regarding claim 16, claim 16 is claim to a system using the method of claim 1. Therefore, claim 16 is rejected for the reasons set forth for claim 1. Regarding claim 17, claim 17 is a dependent claim of claim 16, claim 17 is claim to system using the method of claim 2. Therefore, claim 17 is rejected for the reasons set forth for claim 2. Regarding Claim 19, XU as modified by BEN-ARI discloses all the features of claim 16. The combination further discloses a gateway enclave configured to receive, and/or send to a client computing device, an attestation for the authority service and/or each of the set of enrolled service enclaves {BEN-ARI: Fig. 1 & [0135], “In S2, upon a third party’s request to a data attestation server 110 for an attestation, an untrusted host module 115 of the data attestation server 110 summons a secure enclave verification module 125 to verify the security of a secure enclave module 120 of the data attestation server 110”. Examiner’s note: cited ‘secure enclave verification module’ is functioning as ‘gateway enclave’ to police existing service enclaves and new service enclave}. Regarding Claim 20, XU as modified by BEN-ARI discloses all the features of claim 16. The combination further discloses a gateway enclave configured to receive a service request from a client computing device and, in response to receiving said request, to instruct an already-enrolled enclave to perform the requested service {BEN-ARI: Fig. 1 & [0135], “In S2, upon a third party’s request to a data attestation server 110 for an attestation, an untrusted host module 115 of the data attestation server 110 summons a secure enclave verification module 125 to verify the security of a secure enclave module 120 of the data attestation server 110”. Examiner’s note: cited ‘secure enclave verification module’ is functioning as ‘gateway enclave’ to police existing service enclaves and new service enclave}. Regarding Claim 21, XU as modified by BEN-ARI discloses all the features of claim 20. The combination further discloses wherein the gateway enclave is configured to verify an attestation of the client computing device before instructing the already enrolled enclave to perform the requested service {BEN-ARI: Fig. 1 & [0135], “In S2, upon a third party’s request to a data attestation server 110 for an attestation, an untrusted host module 115 of the data attestation server 110 summons a secure enclave verification module 125 to verify the security of a secure enclave module 120 of the data attestation server 110”. Examiner’s note: cited ‘secure enclave verification module’ is functioning as ‘gateway enclave’ to police existing service enclaves and new service enclave}. Regarding claim 25, claim 16 is claim to a non-transitory computer-readable medium using the method of claim 1. Therefore, claim 25 is rejected for the reasons set forth for claim 1. Claims 6, 8-11 & 13 are rejected under AIA 35 U.S.C. 103 as being unpatentable over XU; Emily Hong et al. (US 2021/0314312 A1) in view of BEN-ARI; Manuel et al. (US 2023/0269093-A1) and further in view of BATTLE; Robert et al. (US 11,372,654 B1). Regarding Claim 6, XU as modified by BEN-ARI discloses all the features of claim 1. However, the combination does not explicitly disclose comprising the authority service providing the certificate to only a subset of the plurality of service enclaves. In an analogous reference BATTLE discloses comprising the authority service providing the certificate to only a subset of the plurality of service enclaves {col. 12 lines 47-49, “The security certificate may be signed by a public certificate authority or a private certificate authority (e.g., established by the service provider environment 120)” … col. 46 lines 6-9, “the management and deployment service 130 selects group identifiers (or “GIDs”) for permissions groups to be used to control access to data resources”. Examiner’s note: cited ‘permission’ of accessing resources per group basis is functioning as claimed ‘certificate’ of accessing resources per group basis}. Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to further modify XU’s technique as modified by BEN-ARI of ‘providing secured multi-tenant hosting service to client enclaves for attesting software/code stored in a new tenancy or enrolled client’ for providing resource access permission/ certificates per group basis, as taught by BATTLE, in order to compartmentalize access permission. The motivation is - combining multi-tenant attestation with group-based certification creates a scalable, zero-trust ecosystem enforced at the hardware level. Cryptographically verifying tenant code before issuing group-specific permissions ensures that resources are accessible only to authenticated, untampered services. This automates security audits and prevents cross-tenant breaches, allowing the provider to manage thousands of clients with the same rigorous isolation as dedicated private servers. All references are inventions in analogous area but each invention teaches specific claimed limitation specifically and other references mutually cure each other’s deficiencies. When all claimed techniques are combined, they teach claimed invention. The Examiner notes that this motivation applies to all dependent and/or otherwise subsequently addressed claims unless addressed separately. Regarding Claim 8, XU as modified by BEN-ARI discloses all the features of claim 1. However, the combination does not explicitly disclose the already-enrolled service enclave storing configuration data; and the authority service providing the configuration data to the new service enclave. BATTLE further discloses the already-enrolled service enclave storing configuration data; and the authority service providing the configuration data to the new service enclave {col. 14 lines 55-60, “ As shown in FIG. 1, the management and deployment service 130 includes a client and data interface 132 and a configuration data store 134 that may operate collectively to enable registration of a coordinator 114 with the management and deployment service 130, generation of configurations for the coordinator 114, and transmission of configuration data”. Examiner’s note: cited ‘coordinator’ is functioning as a tenant/enclave in a multi-tenant service provider}. Regarding Claim 9, XU as modified by BEN-ARI & BATTLE discloses all the features of claim 8. The combination further discloses wherein the configuration data comprises a respective identifier for each of the plurality of service enclaves {BATTLE: col. 23 lines 41-49, “An illustrative table of the contents of a configuration is shown in FIG. 5 as table 502. As shown in the table 502, the configuration may include an environment identifier (e.g., an identifier of a coordinated environment 110 in which the coordinator 114 is intended to operate), a coordinator identifier (e.g., an identifier of the coordinator 114, such as a serial number), a device list (a list of coordinated devices 112 to be managed by the coordinator 114, including identifying information, such as serial numbers, of the devices 112)”}. Regarding Claim 10, XU as modified by BEN-ARI & BATTLE discloses all the features of claim 8. The combination further discloses wherein the configuration data indicates whether a first type of service enclave is authorised to communicate with a second type of service enclave, and the method further comprises the already-enrolled service enclave using the configuration data to determine whether to receive and process a communication from another service enclave {col. 12 lines 47-49, “The security certificate may be signed by a public certificate authority or a private certificate authority (e.g., established by the service provider environment 120)” … col. 46 lines 6-9, “the management and deployment service 130 selects group identifiers (or “GIDs”) for permissions groups to be used to control access to data resources”. Examiner’s note: cited ‘permission’ of accessing resources/configuration per group}. Regarding Claim 11, XU as modified by BEN-ARI & BATTLE discloses all the features of claim 8. The combination further discloses wherein the configuration data comprises expected measurement data for verifying an attestation of one or more already-enrolled enclaves of the network {BEN-ARI: [0035], “checking that the secure enclave attestation verification report is valid and the report was signed by a private key corresponding to the public key certificate chain (a list of certificates where the parent certificate signs the child certificate) and ultimately signed by the root certificate authority of the hardware manufacturer; and [0036], “checking that the public keys reported in the secure enclave attestation packet matches the secure enclave public keys and contains the unique measurement”}. Regarding Claim 13, XU as modified by BEN-ARI & BATTLE discloses all the features of claim 11. The combination further discloses new service enclave using the expected measurement data to attest one or more already-enrolled enclaves of the network {BEN-ARI: [0035], “checking that the secure enclave attestation verification report is valid and the report was signed by a private key corresponding to the public key certificate chain (a list of certificates where the parent certificate signs the child certificate) and ultimately signed by the root certificate authority of the hardware manufacturer; and [0036], “checking that the public keys reported in the secure enclave attestation packet matches the secure enclave public keys and contains the unique measurement”. Examiner’s note: attestation verification report is validated for new or existing enclave}. Claim 24 is rejected under AIA 35 U.S.C. 103 as being unpatentable over XU; Emily Hong et al. (US 2021/0314312 A1) in view of BEN-ARI; Manuel et al. (US 2023/0269093-A1) and further in view of GROETZNER; Michael et al. (US 2022/0188004 A1). Regarding Claim 24, XU as modified by BEN-ARI discloses all the features of claim 16. However, the combination does not explicitly disclose further comprising at least two computing devices configured to host the plurality of service enclaves, wherein the at least two In an analogous reference GROETZNER discloses further comprising at least two computing devices configured to host the plurality of service enclaves, wherein the at least two {[0035], “The method 100 includes moving, 104, the logical I/O configuration settings—e.g., stored in a configuration database (e.g., CMDB) or alternatively, as a flat file—from the source system to a remote multi-tenant target environment including a plurality of target systems. The target systems may have a different architecture and/or may belong to a different generation of the computer system types of the source system”}. Before the effective filing date of the claimed invention, it would have been obvious to one with ordinary skill in the art to further modify XU’s technique as modified by BEN-ARI of ‘providing secured multi-tenant hosting service to client enclaves for attesting software/code stored in a new tenancy or enrolled client’ for/to using distinct different computer architecture in another configuration of computer, as taught by GROETZNER. The motivation is – illegal data intrusion attack is reduced of computers have different architecture, like windows to Linux or Apple. Allowable subject matter Claims 14 & 15 will be allowable if written in independent form with base method claim 1. For allowability, the independent claims 16 & 25 are required to be in same scope with equivalent limitations of claim 15 as proposed for amended claim 1. Reasons of allowance: what is missing from the prior arts is: comprising an already-enrolled service enclave of the plurality of service enclaves receiving new software code and using a public key of an off-line certifying authority to authenticate the new software code before executing the new software code in the already-enrolled service enclave. Therefore, claims 14 & 15 are objected. Conclusion Following prior art has been consulted but is not applied: SONEDA; Takuya (US 12,149,536 B2) – Service providing system … and use permission assigning: “In the service providing system of the present embodiment, following configurations are adopted: —Create a group in the tenant and assign license use permission on a group-by-group basis, —Create a group in the tenant and limit the license usage range within the group.” Any inquiry concerning this communication or earlier communications from the examiner should be directed to QUAZI FAROOQUI whose telephone number is (571) 270-1034 or Quazi.farooqui@USPTO.GOV. The examiner can normally be reached on Monday-Friday 9:00 am to 5:30 pm, EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bill Korzuch can be reached on (571) 272-7589 or William.Korzuch@USPTO.GOV. The fax phone number for Examiner Farooqui assigned is 571-270-2034. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-flee). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /QUAZI FAROOQUI/ Primary Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

Feb 27, 2025
Application Filed
Jul 15, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706921
SECURING BORDER GATEWAY PROTOCOL ROUTE PROPAGATION AND UPDATING
2y 1m to grant Granted Aug 11, 2026
Patent 12700989
CRYPTOGRAPHIC PROCESSOR FOR FULLY HOMOMORPHIC ENCRYPTION (FHE) APPLICATIONS
2y 1m to grant Granted Aug 04, 2026
Patent 12695630
METHOD FOR REMOTELY PROGRAMMING A PROGRAMMABLE DEVICE
3y 6m to grant Granted Jul 28, 2026
Patent 12689902
AUTHENTICATION METHODS FOR A SATELLITE-BASED NAVIGATION SYSTEM, DEVICES FOR AUTHENTICATING MESSAGES AND AUTHENTICATION SYSTEM
3y 7m to grant Granted Jul 21, 2026
Patent 12689502
METHOD BY WHICH DEVICE SHARES DIGITAL KEY
1y 10m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
98%
With Interview (+14.8%)
2y 7m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 463 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month