Prosecution Insights
Last updated: October 01, 2026
Application No. 19/202,993

Secure Supplemental Large Language Model (LLM) Processing

Non-Final OA §103
Filed
May 08, 2025
Priority
May 13, 2024 — provisional 63/646,686 +4 more
Examiner
NIPA, WASIKA
Art Unit
Tech Center
Assignee
Apple Inc.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
1y 5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
237 granted / 314 resolved
+15.5% vs TC avg
Strong +30% interview lift
Without
With
+30.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
9 currently pending
Career history
325
Total Applications
across all art units

Statute-Specific Performance

§101
14.2%
-25.8% vs TC avg
§103
55.8%
+15.8% vs TC avg
§102
2.5%
-37.5% vs TC avg
§112
15.1%
-24.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 314 resolved cases

Office Action

§103
Detailed Action The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is the initial office action that has been issued in response to patent application, 19/202,993 filed on 05/08/2025. Claims 1-20 are currently pending and have been considered below. Claim 1, 11 and 16 are independent claims. Information Disclosure Statement The information disclosure statements (IDS's) submitted on 05/08/2025 and 12/08/2025 are in compliance with provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Priority This application has PRO 63/657,852 filed on 06/08/2024. This application has PRO 63/657,849 06/08/2024. This application has PRO 63/657,853 06/08/2024. This application has PRO 63/647,451 05/14/2024. This application has PRO 63/646,686 05/13/2024. Drawings The drawings filed on 05/08/2025 are accepted by the examiner. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Yang (Foreign Application No CN118013563 A1) in view of Momchilov (US Patent Application Publication No 2020/0374274 A1). Regarding Claim 1, Yang discloses a non-transitory computer readable medium having program instructions stored therein that are executable by a device to perform operations, comprising: processing a query using a locally stored large language model (LLM) operable to use supplemental data provided by one of a plurality of assisting server systems (Yang, page-6, S110, the large model is split into LLM0 and LLM1. First sub-model LLM0 of the client only needs limited resource to complete forward calculation. Page-8, Fig-7, the original data of the client is calculated in the first sub-model to obtain the confusion intermediate data output by the first sub-model); sending, based on the verifying, a request for the supplemental data to the assisting server systems, wherein the request includes intermediary data produced by the processing and encrypted using the attested-to public keys (Yang, page-9, establishing a trusted channel between the client and the server through remote authentication and receiving the HE public key sent by the server. Page-10, the client uses the pre-constructed mutual information privacy protection model to convert the intermediate data into the confused intermediate data protected by the mutual information. Sending the confusion intermediate data protected by the mutual information. Sending the confusion intermediate data and the second confusion data group to a server); and processing the received supplemental data using the LLM to produce a result of the query (Yang, page-11, splitting the LLM0 model parameter to the server terminal, the server terminal converts the LLM0 model parameter into shares (L1 and L2) through MPC protocol and transmits the L2 to the client terminal. The client terminal performs integrated calculation with L2 and the result is sent to the server). Yang does not explicitly teach the following limitation that Momchilov teaches: verifying a set of public-key attestations, each attesting to a public key of a respective one of the assisting server systems (Momchilov, ¶[0007], generate the gateway connection ticket including a payload encrypted with a symmetric encryption key and a plurality of different versions of the symmetric key encrypted with different public encryption keys of the PoP computing devices. Fig-8, ¶[0088], having the public key signed by the RoT is significant because the gateway , the virtual delivery appliances and broker also trust the RoT and can therefore use its signature to authenticate the client device public key); Yang in view of Momchilov are analogous art because they are from the “same field of endeavor” and are from the same “problem solving area”. Namely, they pertain to the field of “network connection and client server communication”. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the invention of Yang in view of Momchilov to include the idea of routing client device communication through a plurality of point of presence (PoP) computing devices (Momchilov, ¶[0004]). Regarding Claim 2, Yang in view of Momchilov discloses the computer readable medium of claim 1, wherein the sending includes: encrypting the intermediary data with a symmetric key (Momchilov, ¶[0008], gateway connection tickets including a payload encrypted with a symmetric encryption key, and a plurality of different versions of the symmetric key encrypted with different public encryption keys of the PoP computing devices so that the PoP computing devices may use their private encryption keys to decrypt the version of the symmetric key encrypted with their public encryption keys); and encrypting a respective instance of the symmetric key with each of the attested-to public keys, wherein the request includes the encrypted instances of the symmetric key (Momchilov, ¶[0008], gateway connection tickets including a payload encrypted with a symmetric encryption key, and a plurality of different versions of the symmetric key encrypted with different public encryption keys of the PoP computing devices so that the PoP computing devices may use their private encryption keys to decrypt the version of the symmetric key encrypted with their public encryption keys). Regarding Claim 3, Yang in view of Momchilov discloses the computer readable medium of claim 2, wherein the operations further comprise: prior to processing the received supplemental data, decrypting the received supplemental data using the symmetric key (Momchilov, ¶[0007], generate the gateway connection ticket including a payload encrypted with a symmetric encryption key and a plurality of different versions of the symmetric key encrypted with different public encryption keys of the PoP computing devices. Also Yang, page-7, based on the decrypted model parameter, calculating the confused original data of the client in the first sub-model and encrypting the calculated result to obtain the confused intermediate data). Regarding Claim 4, Yang in view of Momchilov discloses the computer readable medium of claim 1, wherein the set of public-key attestations includes an attestation attesting to a public key shared by a cluster of multiple assisting server systems (Momchilov, ¶[0088], Fig-8, the client device provides its public key to cloud interface. Yang, page-7, the client initializes TEE, performs remote authentication to establish a local trusted channel with the server end to generate a symmetric/public key password and establishes a communication security channel between the two parties); and wherein the sending includes encrypting intermediary data with the public key of the cluster (Momchilov, ¶[0088], Fig-8, the client device provides its public key to cloud interface. Yang, page-7, the client initializes TEE, performs remote authentication to establish a local trusted channel with the server end to generate a symmetric/public key password and establishes a communication security channel between the two parties). Regarding Claim 5, Yang in view of Momchilov discloses the computer readable medium of claim 1, wherein a given one of public-key attestations signed by a secure circuit included in the assisting server system associated with the given attestation (Momchilov, ¶[0088], Fig-8, the client device provides its public key to cloud interface. Yang, page-7, the client initializes TEE, performs remote authentication to establish a local trusted channel with the server end to generate a symmetric/public key password and establishes a communication security channel between the two parties); and wherein the verifying includes verifying an authority attestation issued by a trusted authority for certifying a public key pair including a private key used by the secure circuit to sign the given public key attestation (Momchilov, ¶[0076], PKI and setting up certificate authorities). Regarding Claim 6, Yang in view of Momchilov discloses the computer readable medium of claim 1, wherein the operations further comprise: receiving, from a token service, anonymized one-time token authorizing the device to submit a single request to the assisting server systems (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key); and sending the anonymized one-time token with the sent request for the supplemental data to the assisting server systems (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key). Regarding Claim 7, Yang in view of Momchilov discloses the computer readable medium of claim 6, wherein the operations further comprise: sending a token request that includes a blind version of the one-time token for signing by the token service (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key); and unblinding the signed blind one-time token received from the token service to produce the anonymized one-time token (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key. ¶[0087], a client device that incorporates a hardware-backed key store can create cryptographic keys and encrypt them so that they can only be decrypted by the hardware-backed key store. This process, referred to as wrapping or binding a key. ¶[0105]). Regarding Claim 8, Yang in view of Momchilov discloses the computer readable medium of claim 6, wherein the operations further comprise sending, to authentication service, an authorization request for a token granting token that authorizes the device to receive one-time tokens, wherein the authorization request includes authentication information and a blind version of the token granting token for signing by the authentication service (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key. ¶[0087], a client device that incorporates a hardware-backed key store can create cryptographic keys and encrypt them so that they can only be decrypted by the hardware-backed key store. This process, referred to as wrapping or binding a key. ¶[0105]); in response to the authorization request being granted, unblinding the signed blind token granting token (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key. ¶[0087], a client device that incorporates a hardware-backed key store can create cryptographic keys and encrypt them so that they can only be decrypted by the hardware-backed key store. This process, referred to as wrapping or binding a key. ¶[0105]); and sending the unblind signed token granting token to the token service to receive the one- time token (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key. ¶[0087], a client device that incorporates a hardware-backed key store can create cryptographic keys and encrypt them so that they can only be decrypted by the hardware-backed key store. This process, referred to as wrapping or binding a key. ¶[0105]). Regarding Claim 9, Yang in view of Momchilov discloses the computer readable medium of claim 1, wherein processing the query includes: applying an encoder of the LLM to the query to produce an input for a decoder of the LLM, wherein the encrypted intermediary data includes the input for the decoder of the LLM (Yang, page 6, the mutual information model is composed of an encoder and a decoder). Regarding Claim 10, Yang in view of Momchilov discloses the computer readable medium of claim 1, wherein processing the query includes: applying a tokenization algorithm of the LLM to the query to produce a set of tokens indicative of the query, wherein the encrypted intermediary data includes the set of tokens (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key). Regarding Claim 11, Yang discloses a device, comprising: one or more processors (Yang, Fig-12); and memory having program instructions stored therein that are executable by the one or more processors to cause the device to perform operations including (Yang, Fig-12): processing a query using a locally stored large language model (LLM) operable to use supplemental data provided by one of a plurality of assisting server systems (Yang, page-6, S110, the large model is split into LLM0 and LLM1. First sub-model LLM0 of the client only needs limited resource to complete forward calculation.Page-8, Fig-7, the original data of the client is calculated in the first sub-model to obtain the confusion intermediate data output by the first sub-model); sending, based on the verifying, a request for the supplemental data to the assisting server systems, wherein the request includes intermediary data produced by the processing and encrypted using the attested-to public keys (Yang, page-9, establishing a trusted channel between the client and the server through remote authentication and receiving the HE public key sent by the server. Page-10, the client uses the pre-constructed mutual information privacy protection model to convert the intermediate data into the confused intermediate data protected by the mutual information. Sending the confusion intermediate data protected by the mutual information. Sending the confusion intermediate data and the second confusion data group to a server); and processing the received supplemental data using the LLM to produce a result of the query (Yang, page-11, splitting the LLM0 model parameter to the server terminal, the server terminal converts the LLM0 model parameter into shares (L1 and L2) through MPC protocol and transmits the L2 to the client terminal. The client terminal performs integrated calculation with L2 and the result is sent to the server). Yang does not explicitly teach the following limitation that Momchilov teaches: verifying a set of public-key attestations, each attesting to a public key of a respective one of the assisting server systems (Momchilov, ¶[0007], generate the gateway connection ticket including a payload encrypted with a symmetric encryption key and a plurality of different versions of the symmetric key encrypted with different public encryption keys of the PoP computing devices. Fig-8, ¶[0088], having the public key signed by the RoT is significant because the gateway , the virtual delivery appliances and broker also trust the RoT and can therefore use its signature to authenticate the client device public key). Yang in view of Momchilov are analogous art because they are from the “same field of endeavor” and are from the same “problem solving area”. Namely, they pertain to the field of “network connection and client server communication”. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the invention of Yang in view of Momchilov to include the idea of routing client device communication through a plurality of point of presence (PoP) computing devices (Momchilov, ¶[0004]). Regarding Claim 12, Yang in view of Momchilov discloses the device of claim 11, wherein the sending includes: encrypting the intermediary data with a symmetric key encrypted using the attested-to public keys (Momchilov, ¶[0008], gateway connection tickets including a payload encrypted with a symmetric encryption key, and a plurality of different versions of the symmetric key encrypted with different public encryption keys of the PoP computing devices so that the PoP computing devices may use their private encryption keys to decrypt the version of the symmetric key encrypted with their public encryption keys). Regarding Claim 13, Yang in view of Momchilov discloses the device of claim 11, wherein the sending includes: sending an anonymized one-time token with the sent request for the supplemental data to the assisting server systems (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key). Regarding Claim 14, Yang in view of Momchilov discloses the device of claim 13, wherein the operations further include: sending a token request that includes a blind version of the one-time token for signing by a token service (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key); and unblinding the signed blind one-time token received from the token service to produce the anonymized one-time token (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key. ¶[0087], a client device that incorporates a hardware-backed key store can create cryptographic keys and encrypt them so that they can only be decrypted by the hardware-backed key store. This process, referred to as wrapping or binding a key. ¶[0105]). Regarding Claim 15, Yang in view of Momchilov discloses the device of claim 11, wherein processing the query includes: supplying the query to an encoder of a transformer model to produce an input for a decoder of the transformer model, wherein the encrypted intermediary data includes the input for the decoder of the transformer model (Yang, page 6, the mutual information model is composed of an encoder and a decoder). Regarding Claim 16, Yang discloses a method, comprising: processing, by a device, a query using a locally stored large language model (LLM) operable to use supplemental data provided by one of a plurality of assisting server systems (Yang, page-6, S110, the large model is split into LLM0 and LLM1. First sub-model LLM0 of the client only needs limited resource to complete forward calculation. Page-8, Fig-7, the original data of the client is calculated in the first sub-model to obtain the confusion intermediate data output by the first sub-model); sending, by the device and based on the verifying, a request for the supplemental data to the assisting server systems, wherein the request includes intermediary data produced by the processing and encrypted using the attested-to public keys (Yang, page-9, establishing a trusted channel between the client and the server through remote authentication and receiving the HE public key sent by the server. Page-10, the client uses the pre-constructed mutual information privacy protection model to convert the intermediate data into the confused intermediate data protected by the mutual information. Sending the confusion intermediate data protected by the mutual information. Sending the confusion intermediate data and the second confusion data group to a server); and processing, by the device, the received supplemental data using the LLM to produce a result of the query (Yang, page-11, splitting the LLM0 model parameter to the server terminal, the server terminal converts the LLM0 model parameter into shares (L1 and L2) through MPC protocol and transmits the L2 to the client terminal. The client terminal performs integrated calculation with L2 and the result is sent to the server). Yang does not explicitly teach the following limitation that Momchilov teaches: verifying, by the device, a set of public-key attestations, each attesting to a public key of a respective one of the assisting server systems (Momchilov, ¶[0007], generate the gateway connection ticket including a payload encrypted with a symmetric encryption key and a plurality of different versions of the symmetric key encrypted with different public encryption keys of the PoP computing devices. Fig-8, ¶[0088], having the public key signed by the RoT is significant because the gateway , the virtual delivery appliances and broker also trust the RoT and can therefore use its signature to authenticate the client device public key). Yang in view of Momchilov are analogous art because they are from the “same field of endeavor” and are from the same “problem solving area”. Namely, they pertain to the field of “network connection and client server communication”. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the invention of Yang in view of Momchilov to include the idea of routing client device communication through a plurality of point of presence (PoP) computing devices (Momchilov, ¶[0004]). Regarding Claim 17, Yang in view of Momchilov discloses the method of claim 16, wherein the sending includes: encrypting the intermediary data with a symmetric key accessible using the attested-to public keys (Momchilov, ¶[0008], gateway connection tickets including a payload encrypted with a symmetric encryption key, and a plurality of different versions of the symmetric key encrypted with different public encryption keys of the PoP computing devices so that the PoP computing devices may use their private encryption keys to decrypt the version of the symmetric key encrypted with their public encryption keys). Regarding Claim 18, Yang in view of Momchilov discloses the method of claim 16, wherein the sending includes: providing an anonymized authorization token with the sent request for the supplemental data to the assisting server systems (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key). Regarding Claim 19, Yang in view of Momchilov discloses the method of claim 18, further comprising: sending, by the device to authentication service, an authorization request for a token granting token that authorizes the device to receive authorization tokens, wherein the authorization request includes authentication information and a blind version of the token granting token for signing by the authentication service (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key); in response to the authorization request being granted, unblinding, by the device, the signed blind token granting token (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key. ¶[0087], a client device that incorporates a hardware-backed key store can create cryptographic keys and encrypt them so that they can only be decrypted by the hardware-backed key store. This process, referred to as wrapping or binding a key. ¶[0105]); and sending, by the device, the unblind signed token granting token to a token service to receive the anonymized authorization token (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key). Regarding Claim 20, Yang in view of Momchilov discloses the method of claim 16, wherein processing the query includes: tokenizing the query to produce a set of tokens indicative of the query, wherein the encrypted intermediary data includes the set of tokens (Momchilov, ¶[0072], the gateway service initiates a secure session to the appropriate resource feed and presents the identity token to seamlessly authenticates the user. ¶[00798], the client device first encrypts an authorization token with an authorization token symmetric key). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-Form 892). Any inquiry concerning this communication or earlier communications from the examiner should be directed to WASIKA NIPA whose telephone number is (571)272-8923. The examiner can normally be reached on M-F, 8 am to 5 pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on 571-272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /WASIKA NIPA/ Primary Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

May 08, 2025
Application Filed
Sep 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744818
IDENTIFYING SERVERLESS FUNCTIONS WITH OVER-PERMISSIVE ROLES
2y 4m to grant Granted Sep 22, 2026
Patent 12732819
DETECTING CELL SITE SIMULATOR
2y 9m to grant Granted Sep 08, 2026
Patent 12726359
SYSTEM AND METHOD FOR PROVIDING INFORMATION USABLE TO IDENTIFY TRUST IN DATA
3y 4m to grant Granted Sep 01, 2026
Patent 12712863
SYSTEM FOR SECURE DATA TRANSMISSION
1y 12m to grant Granted Aug 18, 2026
Patent 12707266
PROTECTION OF A WIRELESS ACCESS POINT (AP) FROM REPEATED ATTACKS
3y 4m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+30.0%)
2y 10m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 314 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month