Prosecution Insights
Last updated: October 01, 2026
Application No. 19/195,728

HOSTED DEVICE PROVISIONING PROTOCOL WITH SERVERS AND A NETWORKED INITIATOR

Non-Final OA §112§DP
Filed
Apr 30, 2025
Priority
Apr 27, 2018 — provisional 62/664,057 +4 more
Examiner
SIMITOSKI, MICHAEL J
Art Unit
Tech Center
Assignee
Meta Platforms Inc.
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
630 granted / 785 resolved
+20.3% vs TC avg
Strong +28% interview lift
Without
With
+28.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
19 currently pending
Career history
802
Total Applications
across all art units

Statute-Specific Performance

§101
10.7%
-29.3% vs TC avg
§103
45.2%
+5.2% vs TC avg
§102
13.9%
-26.1% vs TC avg
§112
21.1%
-18.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 785 resolved cases

Office Action

§112 §DP
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-20 are pending. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 13 and 16 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Regarding claim 13, the limitation “the configuration attribute” lacks sufficient antecedent basis. Regarding claim 16, the limitation “the second device” lacks sufficient antecedent basis. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims of U.S. Patent No. 12,306,976, per the correspondence table. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims of U.S. Patent No. 11,409,896, per the correspondence table. Claims 8-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims of U.S. Patent No. 10,621,352, per the correspondence table. Although the claims at issue are not identical, they are not patentably distinct from each other because the patent claims the patent claims anticipate the instant claims. 19/195,728 12,306,976 11,409,896 10,621,352 1 1 1 2 2 2 3 3 3 4 4 5 5 5 6 6 6 7 7 7 8 8 8 9 8 9 9 10 9 10 10 11 10 11 11 12 11 12 12 13 12 13 13 14 13 14 8 9 13 15 15 15 14 16 16 16 15 17 17 17 16 18 18 18 17 19 19 19 18 20 14 20 19 Allowable Subject Matter Claims 1-20 are allowable with respect to the prior art. Regarding independent claims 1, 8 and 15, the prior art: US 20180109418 A1 (Cammarota; Rosario et al.) teaches a method for supporting a device provisioning protocol (DPP), the method comprising: receiving, by a server (configurator) from a first computing device (enrollee), (i) at least a portion of a tag value (enrollee bootstrapping data can be read from machine-readable for a second computing device (configurator receives bootstrap public key and other bootstrapping information, obtained from the enrollee, from intermediary, ¶50) and (ii) a networks available list (the enrollee bootstrapping data also may include a Global Operating Class and a Channel Number list, ¶40); selecting a responder bootstrap public key using the portion of the tag value (configurator receives bootstrap public key, ¶50); receiving, by the server from the first computing device, a responder ephemeral public key (enrollee device places its public protocol key in a DPP Authentication Response message, ¶43). “Device Provisioning Protocol Specification Version 1.0” (DPP) (Wi-Fi Alliance) teaches conducting, by the server (configurator), an elliptic curve point addition with the responder bootstrap public key (BR) and the responder ephemeral public key (PR) to derive a point (L, p. 49); conducting, by the server (configurator, acting as initiator), an elliptic curve Diffie-Hellman key exchange (devices perform ECDH operations, p. 27, §3.2.1) using the point and an initiator bootstrap private key (calculation of shared key ke uses L, p. 49 and the exchange uses SHA256(BI), p. 49 “R-auth’ = H(I-nonce | R-nonce |PI.x | PR.x | [ BI.x | ] BR.x | 0)” in order to derive a shared secret (ke, where ke = HKDF(I-nonce | R-nonce, “DPP Key”, M.x | N.x [ | L.x ])). The DPP specification lacks third-party support, as claimed. US 20180248694 A1 (Benoit; Olivier Jean et al.) teaches device provisioning utilizing a third device, a configurator device (Fig. 2, ¶¶90+), including sending the responder public key to a server (Fig. 3, Fig. 4), but lacks at least receiving, by the server and from the first computing device, (i) at least a portion of a tag value for a second computing device and (ii) a networks available list, as claimed. US 20170295448 A1 (McCann; Stephen et al.) teaches provisioning a headless device using a server and mediator device by exchanging the public key of a configurator device. US 20170257819 A1 (McCann; Stephen et al.) teaches the device provisioning protocol (¶¶20-23) and similar subject matter to ‘448. US 20170331679 A1 (Whittaker; Colin John) teaches assisted device provisioning. US 20170237571 A1 (Pahl; Sébastien Andreas Henry et al.) teaches a system where a secure-session server sends request to key server to generate a premaster secret, where the request includes public value received from client (operations 935-945). However, regarding claim 1, the prior art – individually, or in a reasonable combination – fails to teach the combination of method for supporting a device provisioning protocol (DPP) comprising: receiving, by a server from a first computing device, (i) at least a portion of a tag value for a second computing device and (ii) a networks available list; selecting a responder bootstrap public key using the portion of the tag value; receiving, by the server from the first computing device, a responder ephemeral public key with the server conducting an elliptic curve point addition with the responder bootstrap public key and the responder ephemeral public key to derive a point and conducting an elliptic curve Diffie-Hellman key exchange using the point and an initiator bootstrap private key in order to derive a shared secret and sending, from the server to the first computing device, the shared secret, in the context of the claims as a whole. Regarding claim 8, the Examiner refers to the above discussion of the references. Further, US 20180109381 A1 (Cammarota; Rosario et al.) (see also WO 2018075135 A1) teaches method for supporting a device provisioning protocol (DPP), the method comprising: receiving, by a network (configurator), a responder bootstrap public key for a responder (obtaining enrollee bootstrapping data, including public bootstrap key, ¶48) via a secure session (visual tag, etc., ¶48); receiving, by the network from a computing device, (i) an initiator bootstrap public key for an initiator bootstrap private key (configurator device comprises a public bootstrapping key, ¶47) and (ii) an initiator configuration (bootstrapping data includes additional data, ¶48); receiving, by the network from the computing device, a responder ephemeral public key (enrollee device places a hash of its public bootstrapping key (and optionally includes a hash of the configurators public bootstrapping key if it is doing mutual authentication), its public protocol key, the wrapped nonces along with its wrapped network public key and the wrapped authentication tag in a DPP Authentication Response message ¶51); conducting, by the network, a key exchange using the responder bootstrap public key, the responder ephemeral public key, and the initiator bootstrap private key in order to derive a shared secret key (generate symmetric key, ¶50). DPP 1.0 discloses ECDH (pp. 27, 49). Cammarota lacks sending, by the network to the computing device, the derived shared secret key via the secure session. DPP teaches conducting, by the network, a first elliptic curve Diffie-Hellman (ECDH) key exchange using the responder bootstrap public key, the responder ephemeral public key, and the initiator bootstrap private key in order to derive a shared secret key (p. 49, §6.2.4, DPP authentication confirm; see also §7.5.2). However, the prior art – individually, or in a reasonable combination – fails to teach a method for supporting a device provisioning protocol (DPP), the method comprising: receiving, by the network from a computing device, (i) an initiator bootstrap public key for an initiator bootstrap private key and (ii) an initiator configuration; receiving, by the network from the computing device, a responder ephemeral public key; conducting, by the network, a first elliptic curve Diffie-Hellman (ECDH) key exchange using the responder bootstrap public key, the responder ephemeral public key, and the initiator bootstrap private key in order to derive a shared secret key; and sending, by the network to the computing device, the derived shared secret key via the secure session, in combination with the remaining limitations of the claims as a whole. Regarding claim 15, the Examiner refers to the above discussion of the references. Further, Benoit et al., and Cammarota et al. teach reading a tag value to obtain bootstrapping parameters for DPP. However, the prior art – individually, or in a reasonable combination – fails to teach a first radio for establishing a secure session with a server, for sending the tag value to the server, for receiving from the server (i) an initiator configuration, (ii) a first hash value of an initiator bootstrap public key, and (iii) a first ciphertext; a second radio for operating with a user configuration before the mobile device reads the tag value, for operating with the initiator configuration after the mobile device reads the tag value, for transmitting a DPP authentication request message with the first ciphertext and the first hash value, a data bus for transferring a third ciphertext with a set of credentials for the first device from the first radio to second radio, in combination with the remaining limitations of the claims as a whole. Claims 2-7, 9-14 and 16-20 inherit allowable subject matter. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL J SIMITOSKI whose telephone number is (571)272-3841. The examiner can normally be reached Monday - Friday, 7:00-3:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Michael Simitoski/ Primary Examiner, Art Unit 2493 September 2, 2026
Read full office action

Prosecution Timeline

Apr 30, 2025
Application Filed
Sep 09, 2026
Non-Final Rejection mailed — §112, §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732808
VEHICLE, IN-VEHICLE DEVICE, AND MANAGEMENT METHOD
5y 0m to grant Granted Sep 08, 2026
Patent 12712747
SECURE CHANNEL INITIATION BETWEEN CARD AND HOST
2y 0m to grant Granted Aug 18, 2026
Patent 12695631
INTERIM ROOT-OF-TRUST ENROLMENT AND DEVICE-BOUND PUBLIC KEY REGISTRATION
2y 10m to grant Granted Jul 28, 2026
Patent 12695722
Network Traffic Control Method and Related System
2y 4m to grant Granted Jul 28, 2026
Patent 12689646
Malicious application detection
3y 7m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+28.4%)
3y 2m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 785 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month