DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This communication is a Non-Final Office Action.
Claims 1-20 have been examined in this application.
The information disclosure statement (IDS) filed on October 8, 2025 has been considered.
Title of the Invention Not Descriptive
The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Drawings
The drawings are objected to because they are pixelated/blurred, making them hard to read and view. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter.
Claims 1-20 fall within at least one of the four categories of patent eligible subject matter (process, machine, manufacture, or composition of matter).
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea of provisioning access or providing access to data to a user without significantly more.
The abstract idea is categorized under mental processes, including concepts performed in the human mind such as observation, evaluation, judgement, opinion, and carrying out these concepts using pen-and-paper. The claims are analyzed under the broadest reasonable interpretation (BRI). Under BRI, the claims are directed to receiving data, generating or encoding the data, generating an identifier associated with the encrypted data, receiving an authentication request, validating the credentials based on stored credentials and the identifier and as a result decrypting the data and provisioning the plaintext data. A human mind, with use of a pen-and-paper, is capable of performing every single operation. The limitations capture broad concepts that a human mind can carry out easily in order to ultimately allow access to data in plaintext form to a user.
Claim 1, in pertinent part, recites:
A method for secure data transmission between user devices, the method comprising:
obtaining… plaintext data for encryption as indicated by an encryption request;
generating… encrypted data from the plaintext data using an encrypting key by executing a cryptographic operation;
generating… a unique encryption identifier associated with the encrypted data, the unique encryption identifier referencing one or more cryptographic keys including the encrypting key;
receiving… an authentication request via a user interface, the authentication request indicating the unique encryption identifier and a set of access credentials;
in response to… validating the set of access credentials against a stored access permission record associated with the unique encryption identifier:
decrypting… the encrypted data to recover the plaintext data by executing the cryptographic operation… using a decrypting key of the one or more cryptographic keys indicated by the unique encryption identifier; and
providing… the plaintext data to the user interface.
The judicial exception is not integrated into a practical application. The claims recite the following additional elements: A processor executing a cryptographic engine and a processor configured to, per claim 12. The additional elements are recited at a high level of generality, wherein the claims merely amount to an abstract idea that is implemented using generic computers, performing generic computer functions such as receiving data, generating data based on encrypting the received data using basic techniques, generating other data based on the encryption keys, receiving a validation request including a portion of the generated data such as a unique encryption identifier that is simply an identifier and access credentials that are also high-level credentials, and based on validating the data decrypting the encrypted data to allow access to it by a user. Each of the additional elements / limitations are no more than mere instructions to apply the exception using generic computer components or a generic device as a tool to perform the abstract idea. Accordingly, even in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Likewise, the claimed scope as a whole, including the above noted additional elements, fail to transform the abstract idea into a practical application because the limitations and additional elements merely add insignificant extra solution activity to the judicial exception.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements amount to merely instructions to apply the exception using generic computer components. The claim limitations do not improve another technology or technical field, improve the functioning of a computer itself, apply the abstract idea with, or by use of, a particular machine (not a generic computer, not adding the words "apply it" or words equivalent to "apply the abstract idea", not mere instructions to implement an abstract idea on a computer, adding insignificant extra solution activity to the judicial exception, generally linking the user of the judicial exception to a particular technological environment or field of use), effects a transformation or reduction of a particular article to a different state or thing, or adds meaningful limitations that amount to more than generally linking the use of the abstract idea to a particular technological environment. Mere instructions to apply an exception using generic computer components cannot provide an inventive concept.
The dependent claims do not include additional elements that integrate the abstract idea into a practical application or that provide significantly more than the abstract idea. The dependent claims further describe the abstract idea. This is evident by claims 2-10, and 12-20. The dependent claims include a data repository to store and use for retrieval of the decryption key, the keys being either symmetric or asymmetric keys, and use of AES algorithm for encryption, generation of a digital signature for the plain text using a private key and deleting the private key after the digital signature is generated, validating a digital signature using a public key, and a first user device, and transmission of the encrypted data from a first user device to a second user device using a secure communication channel. These additional elements are recited at a high level of generality, wherein the claims merely amount to an abstract idea that is implemented using generic computers, performing generic computer functions such as communication, generating encrypted data, signing data, decrypting data, validating data, and manipulating data in general. Each of the additional elements / limitations are no more than mere instructions to apply the exception using generic computer components or a generic device as a tool to perform the abstract idea. Accordingly, even in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Likewise, claims 2-10 and 12-20 fail to transform the abstract idea into a practical application because the limitations / additional elements as a whole, including when considered in light of claims 1 and 11 merely add insignificant extra solution activity to the judicial exception.
The claims are not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over U.S. Patent Application Publication 2012/0179905 to Ackerly (Acherly), in view of U.S. Patent 11,005,829 to Johnson et al. (Johnson).
Per claims 1 and 11, Ackerly teaches:
A method for secure data transmission between user devices, the method comprising (devices include hardware, software, capable of performing cryptographic operations and use secure communication channels) [Abstract, Paragraph 0005 and Figures 1B and 1C]:
generating, by the processor (secure object information generator including encryption engine and hardware such as a processor-Figures 1B/1C), encrypted data from the plaintext data using an encrypting key by executing a cryptographic operation (data objects are encrypted using cryptographic means such as symmetric/asymmetric signature means) [Paragraphs 0040-0041, and 0038 and Figure 4];
generating, by the processor, a unique encryption identifier associated with the encrypted data, the unique encryption identifier referencing one or more cryptographic keys including the encrypting key (generating “an identifier for the encrypted data object 210 and includes the identifier in the information 208.” Also, “generate an encrypted data object 206 and information 208 associated with the encrypted data object 206. The information 208 may be, for example, a registration payload containing information such as an encryption key used to encrypt the data object 206 and an access control list specifying users who may receive the encryption key to decrypt the data object 206. In one embodiment, the information 208 includes at least one identification of a user authorized to receive the encryption key.” The identifier/information can reference any type of data including machine ID, user ID, access ID linked to the data object and cryptographic keys used to encrypt the data object) [Paragraphs 0040-0041 and 0054];
receiving, by the processor, an authentication request via a user interface, the authentication request indicating the unique encryption identifier and a set of access credentials (user requests to access data object via API/user device interface and includes unique ID and credentials such as a password) [Paragraphs 0049, 0052, 0068];
in response to the processor validating the set of access credentials against a stored access permission record associated with the unique encryption identifier [Paragraph 0076, 0082-0084]:
decrypting, by the processor, the encrypted data to recover the plaintext data by executing the cryptographic operation of the cryptographic engine using a decrypting key of the one or more cryptographic keys indicated by the unique encryption identifier [Paragraphs 0084-0085]; and
providing, by the processor, the plaintext data to the user interface [Paragraphs 0052 and 0072].
Ackerly does not explicitly disclose:
Although Ackerly teaches encrypting a data object using a plurality of encryption techniques, as indicated above, Ackerly does not explicitly disclose that this data is first received/does not explicitly disclose obtaining, by a processor executing a cryptographic engine, plaintext data for encryption as indicated by an encryption request.
Johnson teaches obtaining, by a processor executing a cryptographic engine, plaintext data for encryption as indicated by an encryption request [Col. 1, Ln. 21-40].
It would have been obvious to one of ordinary skill in the art before the effective filing date to combine the teachings of Acherly, which teach encrypting a data object and including other data associated with the object and encryption keys, to include the teachings of Johnson to explicitly disclose that the data encrypted is first received or obtained as unencrypted data. Such a teaching is obvious because the data must be obtain from somewhere before it is encrypted and secured or transmitted. The motivation of obtaining the data is to secure it through encryption and further to include additional information that allows access to the encrypted data object by authorized persons.
Per claims 2, and 12, Ackerly teaches further comprising storing, by the processor, the unique encryption identifier and the encrypting key in a data repository [Paragraphs 0057, 0073 and claim 2].
Per claims 3, and 13, Ackerly teaches further comprising retrieving, by the processor, the decrypting key from a data repository based on the unique encryption identifier as indicated by the authentication request [Paragraph 0063 and 0073].
Per claims 4, and 14, Ackerly teaches wherein the encrypting key and the decrypting key are a same symmetric key [Paragraphs 0004 and 0038].
Per claims 5, and 15, Ackerly teaches wherein the cryptographic operation comprises an Advanced Encryption Standard (AES) algorithm [Paragraphs 0004 and 0038].
Per claims 6, and 16, Ackerly teaches wherein the encrypting key is a private key of an asymmetric key pair and the decrypting key is a public key of the asymmetric key pair [Paragraphs 0004, and 0073].
Per claims 7 and 17, Ackerly teaches… and deleting, by the processor, the private key after the digital signature is generated (using SAML, the private key is never reused) [Paragraph 0048].
Although Ackerly teaches using well-settled encryption techniques including asymmetric and symmetric encryption along with signatures, as indicated above, Acherly does not explicitly disclose further comprising generating, by the processor, a digital signature for the plaintext data using a private key.
Johnson teaches generating, by the processor, a digital signature for the plaintext data using a private key; and deleting, by the processor, the private key after the digital signature is generated [Col. 11, Ln. 30-43].
It would have been obvious to one of ordinary skill in the art before the effective filing date to combine the teachings of Ackerly, which teaches use of AES encryption and signatures to secure data and its access, to include the teachings of Johnson to explicitly disclose that a signature of the plain-text is generated using private key and allowing access to the data via the public key in motivation of enhancing security measures through securing the data by allowing only the designated persons access to the data.
Per claims 8, and 18, Although Ackerly teaches using well-settled encryption techniques including asymmetric and symmetric encryption along with signatures, as indicated above, Acherly does not explicitly disclose wherein the authentication request includes a digital signature, and wherein validating the set of access credentials includes verifying, by the processor, the digital signature of the authentication request using a public key associated with a private key.
Johnson teaches wherein the authentication request includes a digital signature, and wherein validating the set of access credentials includes verifying, by the processor, the digital signature of the authentication request using a public key associated with a private key [Col. 11, Ln. 30-43].
It would have been obvious to one of ordinary skill in the art before the effective filing date to combine the teachings of Ackerly, which teaches use of AES encryption and signatures to secure data and its access, to include the teachings of Johnson to explicitly disclose that a signature of the plain-text is generated using private key and allowing access to the data via the public key in motivation of enhancing security measures through securing the data by allowing only the designated persons access to the data.
Per claims 9, and 19, Ackerly teaches wherein the processor executing the cryptographic engine is executed on a first user device [Paragraphs 0052, and 0088].
Per claims 10, and 20, Ackerly teaches wherein the encrypted data is transmitted from a first user device to a second user device via a secure communication channel [Paragraph 0057].
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure is listed on for PTO-892.
WO 2022/212396 to Quinlan teaches the Applicant’s claimed scope: “The method involves receiving an encrypted data encryption key encrypted by the remote entity (170). The encrypted data encryption key is encrypted with a encryption key unavailable to the data processing hardware (114). An operation request (162) requesting a cryptographic operation on data is received, after receiving the encrypted data encryption key. A decryption request requesting decryption of the encrypted data encryption key is transmitted in response to receiving the operation request to the remote entity. The decryption request includes an authentication request based on contextual information associated with a client, and the client is associated with the encryption key.”
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EL MEHDI OUSSIR whose telephone number is (571)270-0191. The examiner can normally be reached M-F 9AM - 5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Neha W. Patel can be reached on 571-270-1492. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Sincerely,
/EL MEHDI OUSSIR/Primary Examiner, Art Unit 3699