DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 07/14/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1: Statutory Category
The claims fall within a statutory category. Claims 1-8 and 15-20 are considered “machines” based claims and claims 9-14 are considered “processes”. Both machines and processes are members of the statutory categories. Thus, the analysis moves towards step 2A, prong one of the subject matter eligibility test.
Step 2A, Prong One: Judicial Exception
In Step 2A, Prong One, examiners evaluate whether the claim recites a judicial i.e., whether a law of nature, natural phenomenon, or abstract idea is set forth or described in the claims. The claim recites the steps of:
“obtain a request to perform a cryptographic operation …” (data gathering)
“select at least one compute region from the one or more compute regions …” (mental processes -concepts performed in the human mind (including observation, evaluation, judgement, opinion))
“provide at least one encrypted cryptographic key of the one or more encrypted cryptographic keys to the selected at least one compute region …” (mental processes -concepts performed in the human mind (including observation, evaluation, judgement, opinion))
The steps performing amount to an abstract idea which falls under a judicial exception (Step 2A, Prong 1, of Subject Matter Eligibility). Abstract ideas falls in the category. The abstract idea falls in the categories of a mental process, for evaluation, judgments, and opinions (MPEP 2106.04(a)(2) & MPEP 2106.06). For example, the courts found that the claim “related to system to monitor access to protected health information in which a rule is created, an audit log is compared with the rule, and a notification is provided if rule is fulfilled”, was directed to an abstract idea of detecting misuse in a computer environment based on analysis log files, while also finding that the claims simply automated a process that was commonly performed without computers in the past. Furthermore, the court found that the claims simply related to the collection and analysis of data is an abstract idea in which there is not inventive concept, and there are no details in the claim that describe an improvement to existing computer technology, Fairwarning IP, LLC v. Iatric Sys, Inc., No. 15-1985 (Fed. Cir. 2016).
Step 2A, Prong Two: Integration into a Practical Application
In Step 2A, Prong Two, examiner determine whether the claim as a whole integrates the judicial exception into a practical application to disqualify abstract as a judicial exception. However, the judicial exception in claim 1 is not integrated into practical because the generically recited elements:
… one or more processors …
… memory storing computer-executable instructions …
do not add meaningful limitation to an abstract idea because they amount to simply implementing the abstract idea on a computer. The additional elements do not improve the functioning of a computer or another technology without reference to what is well-understood, routine, and conventional activity. The claim do not include additional elements that are sufficient to amount to significantly more than the judicial exception because simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception, e.g., a claim to an abstract idea requiring no more than a generic computer to perform generic computer function that are well-understood, routine and conventional activities previously known to the industry, as discussed in Alice Corp., 573 U.S. at 225, 110 USPQ2d at 1984.
Step 2B: Inventive concept
Finally, the claims do not recite an inventive concept that transforms the abstract idea into a patent-eligible application. The use of well-understood, routine, and conventional (WURC) implementations of computer, executing the action. In Berkheimer, 224 F.Supp.3d at 647-48 (quoting Content Extraction, 776 F.3d at 1348), claims that “describe "steps that employ only `well-understood, routine, and conventional' computer functions" and are claimed "at a relatively high level of generality.” were held ineligible.
Thus, the analysis concludes is ineligible under 35 U.S.C. § 101 as it is directed to a judicial exception.
Claims 2-9 and 12-19 merely add details to the generic off-shelf components that were already disclosed in claims 1 and 11, but do not alter the outcome of the analysis above.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1-20 are rejected on the ground of nonstatutory Obviousness-Type double patenting as being unpatentable over claims 1-20 of Patent No. 12,367,293. Although the claims at issue are not identical, they are not patentably distinct from each other because the subject matter claimed in the claim(s) of the instant application is fully disclosed and covered by the Application 17/112,540.
“A later patent claim is not patentably distinct from an earlier patent claim if the later claim is obvious over, or anticipated by, the earlier claim. In re Longi, 759 F.2d at 896, 225 USPQ at 651 (affirming a holding of obviousness-type double patenting because the claims at issue were obvious over claims in four prior art patents); In re Berg, 140 F.3d at 1437, 46 USPQ2d at 1233 (Fed. Cir. 1998) (affirming a holding of obviousness-type double patenting where a patent application claim to a genus is anticipated by a patent claim to a species within that genus). “ELI LILLY AND COMPANY v BARR LABORATORIES, INC., United States Court of Appeals for the Federal Circuit, ON PETITION FOR REHEARING EN BANC (DECIDED: May 30, 2001).
19/251465
12,367,293 (17/112540)
1. A system, comprising:
one or more processors; and
memory storing computer-executable instructions that, when executed by the one or more processors, cause the system to:
obtain a request to perform a cryptographic operation, wherein the request comprises one or more encrypted cryptographic keys, identifiers for one or more compute regions associated with the one or more encrypted cryptographic keys, at least one of the compute regions corresponding to a geographic location or region, and one or more
preferences indicating one or more criteria for selecting at least one compute region;
select at least one compute region from the one or more compute regions based at least in part on the one or more preferences and an availability of the at least one compute region; and
provide at least one encrypted cryptographic key of the one or more encrypted cryptographic keys to the selected at least one compute region to perform the cryptographic operation, wherein the provided at least one encrypted cryptographic key is associated with the selected at least one compute region.
5. A system, comprising:
one or more processors; and
memory that stores computer-executable instructions that are executable by the one or more processors to cause the system to:
obtain a request to perform a cryptographic operation, wherein the request comprises an encrypted cryptographic key data structure, and further wherein the encrypted cryptographic key data structure comprises:
a plurality of encrypted cryptographic keys;
identifiers for a plurality of compute regions corresponding to the plurality of encrypted cryptographic keys; and
preferences indicating how to determine which compute region of the plurality of compute regions to use to perform cryptographic operations;
select a compute region of the plurality of compute regions based at least in part on the preferences and the selected compute region being available; and
provide at least an encrypted cryptographic key to the selected compute region to perform the cryptographic operation, wherein the encrypted cryptographic key is from the plurality of encrypted cryptographic keys and is associated with the selected compute region.
2. The system of claim 1, wherein the one or more preferences indicate an order of compute regions of a plurality of compute regions to use to perform the cryptographic operation.
6. The system of claim 5, wherein the preferences indicate an order of compute regions of the plurality of compute regions to use to perform the cryptographic operations.
3. The system of claim 1, wherein the request to perform the cryptographic operation is a request to obtain a plaintext cryptographic key.
8. The system of claim 5, wherein the request to perform the cryptographic operation is a request to obtain a plaintext cryptographic key …
4. The system of claim 1, wherein selecting the at least one compute region comprises transmitting a message to the at least one compute region to determine the availability of the at least one compute region.
9. The system of claim 5, wherein the instructions to select the compute region of the plurality of compute regions include instructions that, as a result of execution by the one or more processors, cause the system to determine availability of compute regions of the plurality of compute regions …
5. The system of claim 1, wherein the request is associated with an application programming interface of a cryptography service.
1. … obtaining an application programming interface request …
6. The system of claim 1, wherein the instructions further include instructions that, as a result of execution by the one or more processors, cause the system to:
generate another request based at least in part on the request, wherein the other request includes an identifier of a managed key from the selected at least one compute region and the at least one encrypted cryptographic key; and
submit the other request to a cryptography service instance of the selected at least one compute region to cause the cryptography service instance to decrypt the at least one encrypted cryptographic key using the managed key from the selected at least one compute region.
10. The system of claim 5, wherein the instructions further include instructions that, as a result of execution by the one or more processors, cause the system to:
generate a second request based at least in part on the request, wherein the second request includes an identifier of a managed key from the selected compute region and the encrypted cryptographic key; and
submit the second request to a cryptography service instance of the selected compute region to cause the cryptography service instance to decrypt the encrypted cryptographic key using the managed key from the selected compute region.
7. The system of claim 6, wherein the at least one encrypted cryptographic key is encrypted with the managed key from the selected at least one compute region.
11. The system of claim 10, wherein the encrypted cryptographic key is encrypted with the managed key from the selected compute region.
8. The system of claim 1, wherein the at least one encrypted cryptographic key is provided to a cryptography service instance of the selected at least one compute region.
12. The system of claim 5, wherein the encrypted cryptographic key is provided to a cryptography service instance of the selected compute region.
9-13 – method claims of claims 1-6
Claims 1-2 and 4-6
14. The computer-implemented method of claim 9, further comprising:
obtaining another request to decrypt the at least one encrypted cryptographic key;
determining the at least one encrypted cryptographic key corresponds to a managed key;
decrypting the at least one encrypted cryptographic key using the managed key to determine a plaintext of the at least one encrypted cryptographic key; and
providing a response to the other request that comprises the plaintext of the at least one encrypted cryptographic key.
3. The computer-implemented method of claim 1, further comprising:
obtaining a second application programming interface request to decrypt the data key, the second application programming interface request comprising the data structure;
inspecting the data structure to determine a first encrypted data key of the set of encrypted data keys corresponding to a managed key;
decrypting the first encrypted data key using the managed key to determine a plaintext of the data key; and
providing a second response to the second application programming interface request that comprises the plaintext of the data key.
15 and 17-20– computer-readable storage medium of claims 1-6
Claims 1-2 and 4-6
Claim 16
Rejected for the same reason as claim 14
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Regarding claim 1, Limitations, “identifiers for one or more compute regions associated with the one or more encrypted cryptographic keys" and “at least one encrypted cryptographic key is associated with the selected at least one compute region” are indefinite because the claim does not provide objective boundaries or mappings by which a person having an ordinary skill in the art can determine how the identifiers of one or more compute regions are associated with the one or more encrypted cryptographic keys. It’s not clear if the association is one-to-one mapping or one-to-many mappings.
Claim 1 is further rejected because of limitation “one or more compute regions”, “at least one of the compute regions corresponding to a geographic location or region” and “availability of the at least one compute region”. It’s not clear if a compute region is “a geographic location or region” or including other computer components. It’s also indefinite regarding the meaning of availability of at least one compute region. Does it mean the geographic location connected to internet or the computer components are idle for use.
Independent 9 and 15 are also rejected for the same rational as claim 1.
Dependent claims 2-8, 10-14 and 16-20 are also rejected for inheriting the deficiencies of the independent claims from which they depend on.
Allowable Subject Matter
Claims 1-20 would be allowable if the 101, 112b and double patenting rejection, set forth in this Office action, are overcome.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Roth et al. US 2014/0230007A1 - Requests submitted to a computer system are evaluated for compliance with policy to ensure data security. Plaintext and associated data are used as inputs into a cipher to produce ciphertext. Whether a result of decrypting the ciphertext can be provided in response to a request is determined based at least in part on evaluation of a policy that itself is based at least in part on the associated data
NAKATSURU et al. US 2021/0050997 - where a reading request including a data reading command and information indicating a region of a recording medium from which data is read is acquired, encrypts data corresponding to the region indicated by the reading request by using an encryption key corresponding to the region indicated by the reading request and transmits the encrypted data.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MENG LI whose telephone number is (571)272-8729. The examiner can normally be reached M-F 8:30-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MENG LI/
Primary Examiner, Art Unit 2437