Prosecution Insights
Last updated: October 01, 2026
Application No. 19/213,640

PRIVATE DATA SET INTERSECTION WITH MUTUAL DEVICE ANONYMITY

Final Rejection §101§112
Filed
May 20, 2025
Priority
Jul 25, 2023 — continuation of 12/326,849
Examiner
WEHOVZ, OSCAR
Art Unit
2161
Tech Center
2100 — Computer Architecture & Software
Assignee
CrowdStrike Inc.
OA Round
2 (Final)
65%
Grant Probability
Moderate
3-4
OA Rounds
1y 2m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 65% of resolved cases
65%
Career Allowance Rate
72 granted / 111 resolved
+9.9% vs TC avg
Strong +29% interview lift
Without
With
+29.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
15 currently pending
Career history
133
Total Applications
across all art units

Statute-Specific Performance

§101
9.1%
-30.9% vs TC avg
§103
69.8%
+29.8% vs TC avg
§102
4.3%
-35.7% vs TC avg
§112
12.5%
-27.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 111 resolved cases

Office Action

§101 §112
DETAILED ACTION This action is responsive to Applicant Arguments and Remarks filed on August 06, 2026. The terminal disclaimer filed on August 06, 2026, has been acknowledged and considered. The amendments filed on August 06, 2026, have been acknowledged and considered. Claims 1-2, 8 and 15 have been amended. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment Applicant's Remarks, filed August 06, 2026, has been fully considered and entered. Accordingly, Claims 1-20 are pending in this application. Claims 1-2, 8 and 15 have been amended. Claims 1, 8 and 15 are independent claim. In light of Applicant’s amendments the 112(b) rejection of claim 2 and the Statutory double patenting rejection of claims 1, 6-8, 13-15 and 19 have been withdrawn. Response to Arguments Applicant’s arguments, see pages 11-16, filed August 06, 2026, with respect to the rejection of claims 1-20, have been fully considered, but they are not persuasive. Argument 1: Applicant argues on pages 12-13 of the Applicant Arguments and Remarks that “Applicant has amended claim 1 to recite additional limitations that are not abstract and cannot be performed in the human mind or with pen and paper” and that the “Hash structures are specialized data structures that organize data for rapid computational lookup. They are not analogous to any mental process—a human cannot instantiate a hash structure, insert transformed data elements into it, or perform hash-based comparisons mentally. These are inherently computational operations tied to the architecture of the computing device's memory and processing capabilities. Accordingly, the amended claim does not recite a mental process or any other judicial exception under Step 2A, Prong One.” Response to Argument 1: Examiner respectfully disagrees. The argument is not commensurate with the scope of the claim. Amended claim 1 recites determining the subset “by comparing elements of the first hash structure against elements of the second hash structure.” The claim does not recite a lookup, does not recite computing an index or address from a transformed data element, and does not recite any operation that depends upon the internal organization of either structure. The Specification describes the use of a hash filter for fast searching at [0070], but states that “the hash structure 452 may instantiate a hash filter” and at [0078] explicitly states that “the embodiments of the present disclosure are not limited to this configuration” and that “Other types of hash structures 452 may be possible without deviating from the scope of the present disclosure”. The Specification further refers at [0019] to a “hash table (e.g., a Cuckoo hash)” which is not a filter. Limitations from the specification are not read into the claims. See MPEP 2111.01(II). Applicant’s argument is further not persuasive because the claim recites no number of transformed data elements, no size of either plurality, no number of participating computing devices beyond two, and no requirement as to the speed or time within which the comparison is to be completed. The claim reads upon a first plurality and a second plurality each consisting of a single transformed data element. Whether a recited operation can practically be performed in the human mind is determined from the claim, not from the embodiments the Specification prefers. Applicant’s argument that the recited operations are “inherently computational operations tied to the architecture of the computing device's memory and processing capabilities” is unsupported. Therefore, the Examiner has determined that this argument is not persuasive. Argument 2: Applicant argues on page 13 of the Applicant Arguments and Remarks that “The Office Action noted that the anonymity limitation recites a “desired result” rather than a “technical step for achieving the result.” The amended claim directly addresses this concern by reciting the concrete mechanism through which anonymity is achieved. Specifically, by (1) storing each device's transformed data in a separate hash structure, (2) determining the intersection by comparing elements across those separate structures, and (3) transmitting to each computing device an indication of which of that device's own transformed data elements are present in the other hash structure, the third computing device structurally excludes source-device identity from the results. This is not a mere recitation of a desired outcome, but rather a specific, ordered sequence of data-architecture steps that produces the outcome. The anonymity is an inherent consequence of how the data is stored, compared, and reported, not a separate condition layered on top of generic processing.” Therefore, the Examiner has determined that this argument is not persuasive. Response to Argument 2: Examiner respectfully disagrees. Claim 1 recites no such exclusion. Claim 1 does not recite that any information is withheld from either computing device, does not recite that either hash structure excludes information pertaining to its source, and does not recite that the third computing device avoids from retaining or associating information identifying the source of either plurality. Also, claim 1 cannot be interpreted as excluding source-device identity because claim 6, which depends from claim 1, recites inserting both pluralities “into a common hash structure” and determining the subset “by analyzing the common hash structure.” The Specification describes that architecture at [0066] as one in which “the values of the transformed sets 152 may be inserted into the common hash structure along with an identifier of the client computing device 120 from which the values of the transformed sets were received.” Thus, Applicant’s own dependent claim encompasses an architecture that the Specification describes as retaining and using source-device identifiers. Further, each of the two recited indications identifies the same collection of values (the elements common to the first plurality and the second plurality). An element of the first plurality that is present in the second hash structure is an element present in both pluralities, and an element of the second plurality that is present in the first hash structure is likewise an element present in both. The amended transmitting limitation therefore transmit the same information as the limitation it replaced, and recites no withholding of information from either computing device. Therefore, the Examiner has determined that this argument is not persuasive. Argument 3: Applicant argues on page 14 of the Applicant Arguments and Remarks that “This approach is analogous to the claims found eligible in Finjan, Inc. v. Blue Coat Systems, Inc., 879 F.3d 1299 (Fed. Cir. 2018), where the court found patent eligibility because the claims recited a specific technical means (a behavior-based virus scan producing a security profile) rather than a mere desired result (virus detection). Here, the claims recite a specific data architecture and reporting mechanism (separate hash structures with element-level cross-comparison and per-device result transmission) rather than a mere desired result (identity concealment).” Response to Argument 3: Examiner respectfully disagrees. In Finjan the claimed behavior-based scan generated a new and identified a security profile (data structure) enumerating the detected potentially hostile operations, and the claims recited the means by which the asserted new capability was achieved. The eligibility determination was based upon the claims reciting how the improvement was accomplished. Here, the recited means which are the storing of received values in two structures and the comparison of the stored values, does not produce the argued concealment of device identity, for the reasons set forth in the response to Argument 2 above. The claim recites the desired outcome without reciting the operations to achieve it, which is not the case in Finjan. Therefore, the Examiner has determined that this argument is not persuasive. Argument 4: Applicant argues on page 14 of the Applicant Arguments and Remarks that “Furthermore, the specification confirms that this architecture provides a concrete improvement to computer security technology (¶ [0020], describing “improvements both to the operations of the respective computing devices implementing the protocol, and to the technology associated with computer security”). The claimed method solves a problem rooted in computer technology—namely, how to determine intersections among private data sets of multiple networked devices without exposing which devices share common data—and does so through a solution that is similarly rooted in computer technology, not human cognition.” Response to Argument 4: Examiner respectfully disagrees. The Specification’s paragraph [0020] has been fully considered. An improvement described in the specification supports eligibility only to the extent that the improvement is reflected in the claimed subject matter. See MPEP 2106.04(d)(1). As set forth at Prong Two above, the Specification disclose improvements to two things, and claim 1 reflects neither. The efficiency improvement at [0020] is a function of the number of computing devices whose sets are compared, based from the replacement of “a pairwise comparison of sets between a large number of computing devices” with a single centralized comparison of “the sets of large numbers of computing devices (e.g., thousands and/or millions).” Applicant argues that the problem solved refers to “private data sets of multiple networked devices.” Claim 1 recites two computing devices that supply data elements, recites no plurality of computing devices, recites no number of computing devices, and recites no operation whose cost varies with that number. The security improvement at [0020-0021] “by allowing for the private and secure comparison of set members, while hiding the identity of the owners of the sets and the set contents themselves”, to ensure that the transformation engine 130 and the evaluation engine 140 are unable to collude with one another ([0036]). Thus, the technological improvement described in the specification is not captured in claim 1 as written. See response to argument 2 above. Therefore, the Examiner has determined that this argument is not persuasive. Argument 5: Applicant argues on pages 14-15 of the Applicant Arguments and Remarks that “The specific combination of (1) receiving transformed data from anonymous sources, (2) segregating that data into separate hash structures, (3) performing cross-structure comparison, and (4) reporting to each device which of its own elements appear in another structure—without identifying the other structure's source device—is not well-understood, routine, or conventional. The Office Action has not cited, and Applicant is not aware of, any prior art reference establishing that this specific combination of steps was routine or conventional. Indeed, the Office Action has already indicated that the claims are allowable over the prior art, confirming the novelty and non-obviousness of the claimed approach.” Response to Argument 5: Examiner respectfully disagrees. This argument conflates the requirements under 35 U.S.C. 101 with the requirements under 35 U.S.C. 102 and 103. A claim may be novel and nonobvious and nonetheless fail to recite significantly more than a judicial exception. See MPEP 2106.05(d)(I) “The question of whether a particular claimed invention is novel or obvious is "fully apart" from the question of whether it is eligible.” The absence of a prior art rejection is not evidence that the additional elements, individually or as an ordered combination, are other than well-understood, routine and conventional. Applicant’s characterization of the combination as “reporting to each device which of its own elements appear in another structure—without identifying the other structure's source device” is not supported by the claim language, for the reasons set forth in the response to Argument 2 above. The ordered combination has been separately considered at Step 2B below. Therefore, the Examiner has determined that this argument is not persuasive. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 recites “determining, by the third computing device, a subset of transformed data elements by comparing elements of the first hash structure against elements of the second hash structure; and transmitting, by a processing device executing on the third computing device to the first computing device, an indication identifying which of the first plurality of transformed data elements are present in the second hash structure, and to the second computing device, an indication identifying which of the second plurality of transformed data elements are present in the first hash structure.” These limitations are unclear for the following reasons: The recitation “a subset of transformed data elements” does not identify the collection from which the subset is determined. The previous version of claim 1 recited “a subset of transformed data elements that are present in both the first plurality of transformed data elements and the second plurality of transformed data elements,” which identified that collection. Applicant’s amendment deleted that language. As amended, the claim does not state whether the recited subset is a subset of the first plurality, of the second plurality, of the union of the two, or of some other collection of transformed data elements. The metes and bounds of “a subset of transformed data elements” are therefore unclear. Further, the determining step and the transmitting step are not related to one another in the claim. The determining step produces “a subset of transformed data elements” but the transmitting step does not transmit that subset, does not reference that subset, and does not recite that either transmitted indication is based upon, derived from, or otherwise a function of that subset. Instead, the transmitting step independently recites indications of which elements of each plurality “are present in” the other hash structure. It is therefore unclear whether the claim requires the transmitted indications to be the result of the recited determining step, or whether the determining step and the transmitting step recite two independent operations. Because this ambiguity determines whether the determining step imposes any limitation upon what is transmitted, the scope cannot be ascertained. It is unclear what is meant by “elements of the first hash structure” and “elements of the second hash structure”. The claim does not state whether these “elements” are the transformed data elements recited earlier in the claim as having been stored in those structures, or whether they are the contents of the structures themselves. The Specification describes that the hash structure may be instantiated as a hash filter. At paragraph [0070] the Specification states that “the hash structure 452 may instantiate a hash filter,” and that “a hash filter may allow for a given value to be quickly tested to determine if it is in the hash filter, without requiring that every member of the data of the hash filter be individually compared.” At paragraph [0074] the Specification describes a Cuckoo hash filter in which “Tags are small bit strings obtained by hashing items” and at paragraph [0078] the Specification states that “the hash structure 452 may be another type of hash filter, such as a bloom filter”. In such structures, what is stored is a tag or a set of bit positions derived from an item, and not the item itself. Under those embodiments the “elements” of a hash structure are not the transformed data elements, and a comparison of the elements of one such structure against the elements of another would not identify transformed data elements common to the two pluralities. And, at paragraph [0019] the Specification refers to storing each set “into a hash table (e.g., a Cuckoo hash)” which is a different structure that does hold the values. One of ordinary skill in the art would not be reasonably apprised of which of these the claim requires, and therefore would not be apprised of what is compared or of what the comparison yields. The operation recited in the claim does not correspond to any operation described in the Specification. The claim recites a comparison of elements of one hash structure against elements of another hash structure. The Specification instead describes testing the values of a received set against a stored structure. At paragraph [0073] the Specification states that “the evaluation engine 140 may compare each data value of the received transformed set 152 with each of the separate hash structures 452” and that “each data value of the received transformed set 152 may be tested against the first hash structure 452A of the first client computing device 120”. At paragraph [0075] the Specification states that “To check whether an item is contained in the Cuckoo filter, one computes its tag and both possible bucket locations and compares the tags stored there for equality”. At paragraph [0089] the Specification refers to “determining the subset… by analyzing the first and second hash structures.” The Specification therefore does not describe comparing the elements of one hash structure against the elements of another, and provides no standard for ascertaining what such a comparison requires. Claims 8 and 15 recite corresponding limitations and are rejected for the same reasons. Claims 2-7, 9-14 and 16-20 are rejected under 35 U.S.C. 112(b) as depending from a rejected base claim. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-21 are rejected under 35 U.S.C. 101 because claimed invention is directed to an abstract idea without significantly more. Step 1 analysis: In the instant case, claims 1-7 are directed to a method, claims 8-14 are directed to a system, and claims 15-20 are directed to a computer-readable medium. Thus, each of the claims falls within one of the four statutory categories. Step2A analysis: Based on determining the claim fall within or can be amended to fall within a statutory category (Step 1), it must be determined if the claims are directed to a judicial exception (i.e., law of nature, natural phenomenon, and abstract idea), in this case the claims fall within the judicial exception of an abstract idea. Specifically, the abstract ideas of mental processes and mathematical concepts. Step 2A: Prong One: The claim(s) recite(s): Claim 1 (Similarly in claims 8 and 15) : “determining, by the third computing device, a subset of transformed data elements by comparing elements of the first hash structure against elements of the second hash structure” recites an abstract idea as a mental process in the form of an observation, evaluation or judgement, by comparing two collections of items and identifying common members, which can be performed in the human mind or with pen and paper. Examiner notes that the Specification does not define the term “hash structure.” The Specification states at [0070] that “the hash structure 452 may instantiate a hash filter” and at [0078] that “the embodiments of the present disclosure are not limited to this configuration” and that “Other types of hash structures 452 may be possible without deviating from the scope of the present disclosure” and refers at [0019] to a “hash table (e.g., a Cuckoo hash).” The Specification therefore provides examples of hash structures rather than a definition, and does not limit the term to a hash filter. Thus, consistent with the Specification, a person can observe values on two tables and evaluate common members. Step 2A: Prong Two: The claim(s) recites the following additional elements: “a third computing device”, “a first computing device”, “a second computing device”, “a processing device executing on the third computing device” are a high-level recitation of generic computer components and represents mere instructions to apply the exception on a computer as in MPEP 2106.05(f), which does not provide integration into a practical application. This is consistent with the Specification paragraph [0027] “computing devices 120 may comprise any suitable type of computing device or machine”. “receiving, at a third computing device, a first plurality of transformed data elements from a first computing device;” represents insignificant extra-solution activity as mere data gathering for the abstract idea and/or selecting a particular data source or type of data to be manipulated as identified in MPEP 2106.05(g) and does not provide integration into a practical application. “receiving, at the third computing device, a second plurality of transformed data elements from a second computing device, wherein an identity of the first computing device is unknown to the second computing device and an identity of the second computing device is unknown to the first computing device;” represents insignificant extra-solution activity as mere data gathering as identified in MPEP 2106.05(g). The limitation “wherein an identity of the first computing device is unknown to the second computing device and an identity of the second computing device is unknown to the first computing device” continues to recite a desired result regarding information disclosure rather than a technical step for achieving that result. The claim recites no communication of any kind between the first computing device and the second computing device, and recites no step or structure by which the identity of either device is withheld from the other. The result is stated as a condition of the environment in which the method is performed, not as something the claimed steps bring about. Therefore, it does not provide integration into a practical application. “storing, by the third computing device, the first plurality of transformed data elements in a first hash structure separate from the second plurality of transformed data elements in a second hash structure;” represents insignificant extra-solution activity as identified in MPEP 2106.05(g), and constitutes storing information in memory. The recitation specifies that two structures are used, which is a selection of how received data is arranged in memory. The claim places no requirement upon the content of either structure. The claim does not recite that either hash structure excludes any information, does not recite that either structure stores anything other than the transformed data elements themselves, and does not recite that the third computing device refrains from retaining or associating information identifying the source of either plurality. Therefore, it does not provide integration into a practical application. “transmitting, by a processing device executing on the third computing device to the first computing device, an indication identifying which of the first plurality of transformed data elements are present in the second hash structure, and to the second computing device, an indication identifying which of the second plurality of transformed data elements are present in the first hash structure.” represents insignificant extra-solution activity as mere post-solution output of the result of the abstract idea as identified in MPEP 2106.05(g) and does not provide integration into a practical application. Further with respect to this limitation, each of the two recited indications identifies the same collection of values. An element of the first plurality that is present in the second hash structure is necessarily an element present in both the first plurality and the second plurality, and an element of the second plurality that is present in the first hash structure is likewise an element present in both. The amendment therefore changes the frame of reference in which the result of the comparison is expressed, but does not change the information that is transmitted to either computing device, and does not recite that any information is withheld from either computing device. The Specification at [0020] states that “The embodiments described herein provide improvements both to the operations of the respective computing devices implementing the protocol, and to the technology associated with computer security,” and attributes those improvements to two things. At [0020], to offloading the intersection calculation to a centralized server, such that “the determination of the intersection of the sets of large numbers of computing devices (e.g., thousands and/or millions) may be more efficiently processed” in place of “a pairwise comparison of sets between a large number of computing devices.” Second, at [0020-0021] to “the private and secure comparison of set members, while hiding the identity of the owners of the sets and the set contents themselves,” which the Specification at [0018] attributes to the use of “two non-colluding entities”, a transformation engine that holds a key and applies a PRF or OPRF, and a separate evaluation engine that never receives that key, and at [0037] to the isolation of those two entities from one another by containers and/or virtual machines “to ensure that the transformation engine 130 and the evaluation engine 140 are unable to collude with one another.” An improvement described in the specification supports eligibility only to the extent that the improvement is reflected in the claimed subject matter. See MPEP 2106.04(d)(1). Neither disclosed improvement is reflected in claim 1. The efficiency improvement described at [0020] is a function of the number of computing devices whose sets are compared, in that it arises from replacing pairwise comparison among a large number of computing devices with a single centralized comparison. Claim 1 recites two computing devices that supply data elements, a first computing device and a second computing device. Claim 1 does not recite a plurality of computing devices, does not recite any number of computing devices, and does not recite any operation whose cost varies with that number. The asserted efficiency improvement is therefore not commensurate with the scope of claim 1. The security improvement described at [0021] “by allowing for the private and secure comparison of set members, while hiding the identity of the owners of the sets and the set contents themselves”, is not reflected on claim 1. Claim 1 does not recite the fourth computing device, does not recite a key, does not recite a pseudorandom function or any other particular transformation, and does not recite any isolation between the entity that performs the transformation and the third computing device that performs the comparison. Viewing the additional limitations together and the claim as a whole, nothing provides integration into a practical application. At Step 2B: The conclusions above with respect to the mere implementation of the abstract idea using generic computer components are carried over and do not provide significantly more. With respect to the receiving and transmitting steps identified as insignificant extra-solution activity above, when re-evaluated at Step 2B these elements are well-understood, routine and conventional as in MPEP 2106.05(d)(II), which identifies “receiving or transmitting data over a network”. These elements accordingly remain insignificant extra-solution activity that does not provide significantly more. The ordered combination of the additional elements has also been separately considered. The combination consists of receiving two collections of values over a network, placing each collection in its own structure in memory, comparing the members of the two structures, and transmitting the result of that comparison back over the network to each source. The recited elements are performed in the only sequence in which they could be performed, in that data must be received before it can be stored, stored before it can be compared, and compared before the result of the comparison can be reported. Each element performs its ordinary and expected function, and no element operates differently, or produces any effect in the operation of any computing device, by reason of its combination with the others. The ordered combination therefore adds nothing beyond the sum of the individual elements and does not amount to significantly more than the judicial exception. Therefore, claims 1, 8 and 15 do not recite patent eligible subject matter under 35 U.S.C. § 101. Regarding claim 2 (Similarly in claim 9 and 16), it further recites abstract idea and additional elements as identified in claim 1. Claim 2 further recites further abstract idea at Step 2A Prong One of: “generating, by a fourth computing device, a pseudorandom key;”, “computing, by the fourth computing device, a first pseudorandom function using the pseudorandom key and the set of intermediate values; producing, by the fourth computing device, the first plurality of transformed data elements based on the first pseudorandom function;” This further recites an abstract idea of mathematical concept. Each of these operations is itself a mathematical concept. This is consistent with the Specification [0033] “A PRF is a deterministic function of a key and an input that is indistinguishable from a truly random function of the input.” “receiving, at the fourth computing device, a set of intermediate values from the first computing device, wherein the set of intermediate values represents a transformation of a set of data elements by the first computing device using a first hash function;”, providing, by the fourth computing device, the first plurality of transformed data elements to the first computing device.” These additional limitations represent insignificant extra-solution activity as mere data gathering for the abstract idea and/or selecting a particular data source or type of data to be manipulated as identified in MPEP 2106.05(g) and does not provide integration into a practical application. And when re-evaluated this elements are well-understood, routine, and conventional as in MPEP 2106.05(d) - Receiving or transmitting data over a network, and thus remains insignificant extra-solution activity that does not provide significantly more. Claim 2 does not recite any other additional elements and for the same reasons as above with regard to integration into practical application and whether additional elements amount to significantly more, claim 2 also fails both Step 2A prong 2, thus the claim is directed to the judicial exception as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claim 2 does not recite patent eligible subject matter under 35 U.S.C. § 101. Regarding claim 3 (Similarly in claim 11 and 17), it further recites abstract idea and additional elements as identified in claim 1. Claim 3 further recites further abstract idea at Step 2A Prong One of: “determining, by the third computing device, an intersection of the first hash structure and the second hash structure; and identifying the subset of transformed data elements based in the intersection of the first hash structure and the second hash structure.” This further recites an abstract idea of mental process in the form of an observation, evaluation or judgement, by comparing two collections items and identifying common members, which can be performed in the human mind or with pen and paper. “storing, by the third computing device, the first plurality of transformed data elements in a first hash structure, wherein the first hash structure is devoid of information pertaining to the first computing device; and storing, by the third computing device, the second plurality of transformed data elements in a second hash structure, wherein the second hash structure is devoid of information pertaining to the second computing device and is separate from the first hash structure;” These additional limitations represent insignificant extra-solution activity as mere data gathering for the abstract idea and/or selecting a particular data source or type of data to be manipulated as identified in MPEP 2106.05(g) and does not provide integration into a practical application. And when re-evaluated this elements are well-understood, routine, and conventional as in MPEP 2106.05(d)(II) - Storing and retrieving information in memory, and thus remains insignificant extra-solution activity that does not provide significantly more. The recitation that each hash structure is devoid of information pertaining to the source device recites a results rather than a technical step for achieving the result. Claim 3 does not recite any other additional elements and for the same reasons as above with regard to integration into practical application and whether additional elements amount to significantly more, claim 3 also fails both Step 2A prong 2, thus the claim is directed to the judicial exception as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claim 3 does not recite patent eligible subject matter under 35 U.S.C. § 101. Regarding claim 4 (Similarly in claim 12 and 18), it further recites abstract idea and additional elements as identified in claim 1. Claim 2 further recites further abstract idea at Step 2A Prong One of: “generating the first plurality of transformed data elements based on a first oblivious pseudorandom function (OPRF) protocol executed between the first computing device and a fourth computing device using a key of the fourth computing device; and generating the second plurality of transformed data elements based on a second OPRF protocol executed between the second computing device and the fourth computing device using the key of the fourth computing device.” This further recites an abstract idea of mathematical concept. Each of these operations is itself a mathematical concept. Claim 4 does not recite any other additional elements and for the same reasons as above with regard to integration into practical application and whether additional elements amount to significantly more, claim 4 also fails both Step 2A prong 2, thus the claim is directed to the judicial exception as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claim 4 does not recite patent eligible subject matter under 35 U.S.C. § 101. Regarding claim 5 (Similarly claim 10), it further recites additional elements for implementing the abstract ideas of claims 1 and 4. Claim 5 further recites: “wherein the third computing device and the fourth computing device are logically isolated on separate virtual machines.” are a high-level recitation of generic computer components and represents mere instructions to apply on a computer as in MPEP 2106.05(f), which does not provide integration into a practical application. The claim does not impose any limit on how the logical isolation operates or what enforces it or how it produces a technical effect beyond merely describing a general property. Claim 5 does not recite any other additional elements and for the same reasons as above with regard to integration into practical application and whether additional elements amount to significantly more, claim 5 also fails both Step 2A prong 2, thus the claim is directed to the judicial exception as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claim 5 does not recite patent eligible subject matter under 35 U.S.C. § 101. Regarding claim 6 (Similarly in claim 13 and 19), it further recites abstract idea and additional elements as identified in claim 1. Claim 6 further recites further abstract idea at Step 2A Prong One of: “determining, by the third computing device, an intersection of the first hash structure and the second hash structure; and identifying the subset of transformed data elements based in the intersection of the first hash structure and the second hash structure.” This further recites an abstract idea of mental process in the form of an observation, evaluation or judgement, by comparing two collections items and identifying common members, which can be performed in the human mind or with pen and paper. “inserting the first plurality of transformed data elements and the second plurality of transformed data elements into a common hash structure;” represent insignificant extra-solution activity as mere data gathering for the abstract idea and/or selecting a particular data source or type of data to be manipulated as identified in MPEP 2106.05(g) and does not provide integration into a practical application. And when re-evaluated this elements are well-understood, routine, and conventional as in MPEP 2106.05(d)(II) - Storing and retrieving information in memory, and thus remains insignificant extra-solution activity that does not provide significantly more. The recitation that each hash structure is devoid of information pertaining to the source device recites a results rather than a technical step for achieving the result. Claim 6 does not recite any other additional elements and for the same reasons as above with regard to integration into practical application and whether additional elements amount to significantly more, claim 6 also fails both Step 2A prong 2, thus the claim is directed to the judicial exception as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claim 6 does not recite patent eligible subject matter under 35 U.S.C. § 101. Regarding claim 7 (Similarly in claim 14 and 20), it further recites additional elements for implementing the abstract ideas of claims 1. Claim 7 further recites: “wherein the first plurality of transformed data elements and the second plurality of transformed data elements correspond to a first and second set of passwords of the first computing device and the second computing device, respectively.” are limiting the abstract idea to a particular filed of use (password comparison). Claim 7 does not recite any other additional elements and for the same reasons as above with regard to integration into practical application and whether additional elements amount to significantly more, claim 7 also fails both Step 2A prong 2, thus the claim is directed to the judicial exception as it has not been integrated into practical application, and fails Step 2B as not amounting to significantly more. Therefore, claim 7 does not recite patent eligible subject matter under 35 U.S.C. § 101. Allowable Subject Matter Claims 1, 8 and 15 would be allowable pending the resolution 112(b) and 101 rejections. After sufficient search and analysis, Examiner concluded that the claimed invention has been recited in such a manner that independent claims 1, 8 and 15 is not taught by any prior reference found through search. The primary reason for allowance of the claim in this case, is the inclusion of the limitations “receiving, at the third computing device, a second plurality of transformed data elements from a second computing device, wherein an identity of the first computing device is unknown to the second computing device and an identity of the second computing device is unknown to the first computing device;” which are not found in the prior art of record. Overcoming the 112(b) and 101 rejections would put claims in condition for allowance. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Amisano et al. (US Pub. No. 20190378599) discloses a method for implementing a secure system to prevent adverse drug interactions and repeat prescriptions, for a patient, in a multi-party computing environment using Oblivious pseudo random function (OPRF) and private set intersection (PSI), receiving an input from a provider that corresponds to a patient identifier, and accessing a database that contains a stored private ID, wherein the stored private ID is a combination of a received patient identifier and a retrieved second patient identifier, and wherein the database includes data relating to the patient, and searching the database to obtain a search result based on the received input from the provider, and transmitting the search result to the provider. Claudio et al. (US. Pub. No. 20190349191) discloses a method for anonymous authentication and key establishment based on passwords, instantiating, by a server, an OPRF scheme and a symmetric encryption scheme, engaging in, by a client and the server, an OPRF Evaluate protocol so that the client learns a decryption key associated with its password while the server learns nothing, securely transferring, by the server, a nonce and a symmetric encryption key to the client if the client holds a valid password, sending, by the client, its nonce encrypted under the symmetric encryption key, using, by the server, the symmetric encryption key to decipher ciphertext received by virtue of the sending, by the client, its nonce encrypted under the symmetric encryption key and to recover the client's nonce, and computing, by the server and the client, a compute key based on the client's nonce and the server's nonce. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to OSCAR WEHOVZ whose telephone number is (571)272-3362. The examiner can normally be reached 8:00am - 5:00pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, APU M MOFIZ can be reached at (571) 272-4080. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /OSCAR WEHOVZ/Examiner, Art Unit 2161 /APU M MOFIZ/Supervisory Patent Examiner, Art Unit 2161
Read full office action

Prosecution Timeline

May 20, 2025
Application Filed
May 06, 2026
Non-Final Rejection mailed — §101, §112
Jul 15, 2026
Applicant Interview (Telephonic)
Jul 15, 2026
Examiner Interview Summary
Aug 06, 2026
Response Filed
Sep 14, 2026
Final Rejection mailed — §101, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12724763
Computer Architecture for Prediction Using Consistency Rules
1y 5m to grant Granted Sep 01, 2026
Patent 12711113
SYSTEM AND METHOD FOR CREATING RELATIONAL AND NON-RELATIONAL DATABASES FROM STRUCTURED AND UNSTRUCTURED DATA SOURCES
4y 3m to grant Granted Aug 18, 2026
Patent 12705247
RESOURCE NAVIGATION USING NEURAL NETWORKS
1y 8m to grant Granted Aug 11, 2026
Patent 12699738
ENHANCED CONCEPTUAL SEARCH BASED ON ENRICHED CATEGORIZATIONS OF ITEM LISTINGS
2y 7m to grant Granted Aug 04, 2026
Patent 12688193
MACHINE LEARNING ENABLED REAL TIME QUERY HANDLING SYSTEM AND METHOD
1y 7m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
65%
Grant Probability
94%
With Interview (+29.2%)
2y 6m (~1y 2m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 111 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month