Prosecution Insights
Last updated: October 02, 2026
Application No. 19/251,721

DATA MANAGEMENT SYSTEMS AND METHODS USING EXPLICIT PRIVATE NETWORKING TECHNIQUES

Non-Final OA §101§102§103§112§DP
Filed
Jun 26, 2025
Priority
Nov 24, 2021 — provisional 63/283,099 +1 more
Examiner
SHAIFER HARRIMAN, DANT B
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Intertrust Technologies Corporation
OA Round
1 (Non-Final)
81%
Grant Probability
Favorable
1-2
OA Rounds
1y 8m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
640 granted / 790 resolved
+23.0% vs TC avg
Strong +18% interview lift
Without
With
+17.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
13 currently pending
Career history
810
Total Applications
across all art units

Statute-Specific Performance

§101
13.7%
-26.3% vs TC avg
§103
59.9%
+19.9% vs TC avg
§102
14.7%
-25.3% vs TC avg
§112
5.7%
-34.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 790 resolved cases

Office Action

§101 §102 §103 §112 §DP
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Election/Restrictions NO restrictions warranted at applicant’s time of filing for CONtinuation. Priority This application claims domestic priority under 35 USC 120 to non – provisional application # 17/993321, filed on 11/23/2022, now US PAT # 12381854; further claims domestic priority under 35 USC 119e to provisional application # 63/283099, filed on 11/24/2021. Information Disclosure Statement Applicant filed NO information disclosure statements (IDS) time of filing for CONtinuation. Drawings Applicant’s drawings filed on 06/26/2025 have been inspected and are in compliance with MPEP 608.02. Specification Applicant’s specification filed on 06/26/2025 has been inspected and is in compliance with MPEP 608.01. Claim Objections NO claim objections warranted at applicant’s time of filing for CONtinuation. Claim Interpretation – 35 USC 112th f It is in the examiner’s opinion that claim[s] 1 – 20 do not invoke means for or step plus functional claim language under the meaning of the statute. Claim Rejections - 35 USC § 112 NO rejections warranted at applicant’s time of filing for CONtinuation. Claim Rejections - 35 USC § 101 NO rejections warranted at applicant’s time of filing for CONtinuation. Double Patenting The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on non-statutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based e-Terminal Disclaimer may be filled out completely online using web-screens. An e-Terminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about e-Terminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claim[s] 1, 6 - 20 are rejected on the ground of non-statutory double patenting as being unpatentable over claim[s] 1 - 16 of U.S. Patent No. 12381854. Although the claims at issue are not identical, they are not patentably distinct from each other because the subject matter of the pending application and the subject matter of the patented application are the same or similar in subject matter and are not distinct in the following manner: Systems, services, and devices manage communication between each other using explicit private networking [EPN] operations. EPN provides a relatively robust end-to-end security. EPN operations protect data in transit, at rest, and in use while hosted in hostile environments. EPN architecture protects connected device data where and when it is generated by encrypting it and maintaining protection over the data until it is consumed by a trusted information platform or trusted information service, where the trusted platform or service resides in a trusted or secure environment. The trusted platform or service uses the EPN protected/secured data for identity and access management services that facilitate identification, authentication, authorizations, and grant permissions to read, modify, and collaborate with that EPN protected/secured data for use with control devices and associated device commands. Also, see the table below for a claim-by-claim comparison. Pending US Application # 19/251721 US PAT # 12381854 1. A method for managing data performed by a cloud service system comprising a processor and a non-transitory computer-readable storage medium storing instructions that, when executed by the processor, cause the cloud service system to perform the method, the method comprising: receiving, from an application associated with a user over a first trusted network connection, a device command request, the device command request comprising requestor identification information, connected device identification information, and an indication of a requested device action; issuing an access authorization query to an identity and access management service, the access authorization query comprising the requestor identification information; receiving, from the identity and access management service in response to the access authorization query, a response validating the requestor identification information and providing at least one privilege associated with controlling at least one operation of a connected device associated with the connected device identification information; determining, based on the at least one privilege and the indication of the requested device action, that an account associated with the requestor identification information is permitted to perform the requested device action; issuing, to an explicit private network service via a second trusted network connection, an explicit private network key query, the explicit private network key query comprising the connected device identification information; receiving, from the explicit private network service in response to the explicit private network key query, a session key associated with the connected device identification information; generating a connected device command, wherein generating the connected device command comprises performing at least one cryptographic operation using the session key; and transmitting, to a digital twin associated with the connected device, the connected device command, the digital twin comprising a virtual executable representation of the connected device. 1. (Currently amended) A method for managing data performed by a cloud service system comprising a processor and a non-transitory computer-readable storage medium storing instructions that, when executed by the processor, cause the cloud service system to perform the method, the method comprising: receiving, from an application associated with a user over a first trusted network connection, a device command request, the device command request comprising requestor identification information, connected device identification information, and an indication of a requested device action; issuing an access authorization query to an identity and access management service, the access authorization query comprising the requestor identification information; receiving, from the identity and access management service in response to the access authorization query, a response validating the requestor identification information and providing at least one privilege associated with controlling at least one operation of a connected device associated with the connected device identification information; determining, based on the at least one privilege and the indication of the requested device action, that an account associated with the requestor identification information is permitted to perform the requested device action; issuing, to an explicit private network service via a second trusted network connection, an explicit private network key query, the explicit private network key query comprising the connected device identification information; receiving, from the explicit private network service in response to the explicit private network key query, a session key associated with a connected device associated with the connected device identification information; generating a connected device command, wherein generating the connected device command comprises performing at least one cryptographic operation using the session key; and transmitting, via an untrusted network connection to the connected device, the connected device command. 6. The method of claim 1, wherein the requestor identifier comprises identification information associated with the user. 2. (Original) The method of claim 1, wherein the requestor identifier comprises identification information associated with the user. 7. The method of claim 1, wherein the requestor identifier comprises identification information associated with the application. 3. (Original) The method of claim 1, wherein the requestor identifier comprises identification information associated with the application. 8. The method of claim 1, wherein the requestor identifier comprises identification associated with a system executing the application. 4. (Original) The method of claim 1, wherein the requestor identifier comprises identification associated with a system executing the application. 9. The method of claim 1, wherein the requestor identifier comprises an access token. 5. (Original) The method of claim 1, wherein the requestor identifier comprises an access token. 10. The method of claim 9, wherein the requestor identifier is issued by the identity and access management service to a system executing the application. 6. (Original) The method of claim 5, wherein the requestor identifier is issued by the identity and access management service to a system executing the application. 11. The method of claim 1, wherein the session key comprises a device session key. 7. (Currently amended) The method of claim 1, wherein the first-session key comprises a device session key. 12. The method of claim 1, wherein the session key comprises a group session key. 8. (Currently amended) The method of claim 1, wherein the first-session key comprises a group session key. 13. The method of claim 1, wherein the connected device comprises one or more of a computer system, a smartphone, a tablet computing system, a security system, a vehicle infotainment system, a streaming media device, a gaming device, an entertainment system, a networked lock, a connected thermostat, a connected furnace, a connected air conditioning system, an irrigation system, a water control system, a pump system, a utility meter, a network gateway, an activity sensor, a home alarm, a connected appliance, a connected vehicle, a mobile communication device, a wind turbine system, a solar panel system, and an industrial manufacturing control system. 9. (Original) The method of claim 1, wherein the connected device comprises one or more of a computer system, a smartphone, a tablet computing system, a security system, a vehicle infotainment system, a streaming media device, a gaming device, an entertainment system, a networked lock, a connected thermostat, a connected furnace, a connected air conditioning system, an irrigation system, a water control system, a pump system, a utility meter, a network gateway, an activity sensor, a home alarm, a connected appliance, a connected vehicle, a mobile communication device, a wind turbine system, a solar panel system, and an industrial manufacturing control system. 14. The method of claim 1, wherein the cryptographic operation comprises encrypting the connected device command with the session key. 10. (Currently amended) The method of claim 1, wherein the cryptographic operation comprises encrypting the connected device command with the session key. 15. The method of claim 1, wherein the cryptographic operation comprises cryptographically signing at least a portion of the connected device command with the session key. 11. (Currently amended) The method of claim 1, wherein the cryptographic operation comprises cryptographically signing at least a portion of the connected device command with the session key. 16. The method of claim 1, wherein the method further comprises receiving, from the connected device via an untrusted network connection, a command acknowledgement indicating that the connected device performed the requested device action. 12. (Original) The method of claim 1, wherein the method further comprises receiving, from the connected device via an untrusted network connection, a command acknowledgement indicating that the connected device performed the requested device action. 17. The method of claim 16, wherein the method further comprises issuing, to the explicit private network service via the second trusted network connection, a subsequent explicit private network key query, the subsequent explicit private network key query comprising the connected device identification information. 13. (Currently amended) The method of claim 12, wherein the method further comprises issuing, to the explicit private network service via the second trusted network connection, a subsequent explicit private network key query, the subsequent explicit private network key query comprising the connected device identification information. 18. The method of claim 17, wherein the method further comprises receiving, from the explicit private network service in response to the subsequent explicit private network key query, a subsequent session key associated with the connected device identification information. 14. (Currently amended) The method of claim 13, wherein the method further comprises receiving, from the explicit private network service in response to the subsequent explicit private network key query, a subsequent session key associated with the connected device associated with the connected device identification information. 19. The method of claim 18, wherein the first session key and the subsequent session key are the same session key. 15. (Currently amended) The method of claim 14, wherein the first session key and the subsequent session key are the same session key. 20. The method of claim 19, wherein the method further comprises validating the command acknowledgement using the subsequent session key. 16. (Currently amended) The method of claim 15, wherein the method further comprises validating the command acknowledgement using the subsequent session key. Claim Rejections - 35 USC § 102 NO rejections warranted at applicant’s time of filing for CONtinuation. Claim Rejections - 35 USC § 103 NO rejections warranted at applicant’s time of filing for CONtinuation. Allowable Subject Matter Claim[s] 1 – 20 contain allowable subject matter, but as allowable subject matter has been indicated, applicant's reply must either comply with all formal requirements or specifically traverse each requirement not complied with. See 37 CFR 1.111(b) and MPEP § 707.07(a). ***The examiner notes that a reason’s for allowance can be written in the next subsequent office action, once all formal requirements as identified above have been overcome. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to DANT SHAIFER - HARRIMAN whose telephone number is (571)272-7910. The examiner can normally be reached M - F: 9am to 5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at 571 – 270 - 1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DANT B SHAIFER HARRIMAN/ Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Jun 26, 2025
Application Filed
Aug 12, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750661
Secured data derivation for user devices
3y 3m to grant Granted Sep 29, 2026
Patent 12737496
ARTIFICIAL INTELLIGENCE BASED SERVICE PROVIDING METHOD WITHOUT LEAKING PRIVATE INFORMATION AND CLIENT APPARATUS
1y 11m to grant Granted Sep 15, 2026
Patent 12724856
SECURED ACCELERATED UNIT PROCESSING IN A DISTRIBUTED PROCCESING SYSTEM
3y 3m to grant Granted Sep 01, 2026
Patent 12726331
METHOD OF MANAGING CARBON DATA USING BLOCKCHAIN NETWORK AND SYSTEM FOR THE SAME
1y 9m to grant Granted Sep 01, 2026
Patent 12726525
LARGE LANGUAGE MODEL TRIGGERED EPHEMERAL DIRECTIVE
9m to grant Granted Sep 01, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
81%
Grant Probability
98%
With Interview (+17.5%)
2y 11m (~1y 8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 790 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month