Prosecution Insights
Last updated: October 02, 2026
Application No. 19/288,915

CLOUD-BASED CREATION OF A CUSTOMER-SPECIFIC SYMMETRIC KEY ACTIVATION DATABASE

Non-Final OA §103§DOUBLEPATENT
Filed
Aug 01, 2025
Priority
Sep 08, 2020 — continuation of 11/728,997 +1 more
Examiner
NOAMAN, BASSAM A
Art Unit
Tech Center
Assignee
Micron Technology Inc.
OA Round
1 (Non-Final)
79%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
223 granted / 282 resolved
+19.1% vs TC avg
Strong +46% interview lift
Without
With
+46.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
20 currently pending
Career history
295
Total Applications
across all art units

Statute-Specific Performance

§101
6.3%
-33.7% vs TC avg
§103
60.4%
+20.4% vs TC avg
§102
9.5%
-30.5% vs TC avg
§112
16.7%
-23.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 282 resolved cases

Office Action

§103 §DOUBLEPATENT
DETAILED ACTION This Non-Final Office Action is in response to Application filed on 08/01/2025. Claims 1-20 filed on 08/01/2025 are being considered on the merits. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Drawings The drawings filed on 08/01/2025 are accepted. Information Disclosure Statement The information disclosure statements (IDS) submitted on 08/12/2025 and 07/17/2026 have been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly an initialed and dated copy of Applicant's IDS form 1449 filed 08/12/2025 and 07/17/2026 are attached to the instant Office action. Claim Objections Claim 7 objected to because of the following informalities: claim 7 recites “a a first…”, should be “a first”. Appropriate correction is required. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1-20 rejected on the ground of nonstatutory double patenting as being obvious over claims 1-2, 4-5-6 and 8 of US 11728997 B2, hereinafter 997 in view of Cignetti (US 20190074960 A1). This is a nonstatutory double patenting rejection. Instant Application 19288915 US 11728997 B2 1. A device, comprising: a processor; and a storage medium having stored thereon program logic, wherein the processor is configured to, upon execution of the stored program logic: 1. A method comprising: send, to a key management system, a request for an activation code for a manufactured device, the request comprising at least one parameter; and receiving a request for an activation code database from a remote computing device, the request including at least one parameter comprising at least a device type, a date range, a customer identifier, and a nonce value receive, from the key management system, the activation code in response to the request, wherein the key management system is configured to determine a unique identification of the manufactured device based on the at least one parameter. Similarly in claims 13 and 16 retrieving a plurality of pairs based on the at least one parameter, each of the plurality of pairs including a unique identifier and secret key, wherein the plurality of pairs corresponds to semiconductor devices associated with the customer identifier, wherein the semiconductor devices of the device type indicated in the request, and wherein the semiconductor devices are manufactured within the date range indicated in the request; generating at least a first activation code for a first unique identifier of the plurality of pairs using, at least in part, the nonce value and the customer identifier; and returning the first activation code to the remote computing device. 2. The device of claim 1, wherein the at least one parameter comprises at least a device type, a date range, a customer identifier, and a nonce value. 1…comprising at least a device type 3. The device of claim 1, wherein the key management system is configured to retrieve a plurality of pairs based on the at least one parameter. 1… retrieving a plurality of pairs based on the at least one parameter, each of the plurality of pairs including a unique identifier and secret key 4. The device of claim 3, wherein the plurality of pairs corresponds to manufactured devices associated with a customer identifier. 1…. pairs corresponds to semiconductor devices associated with the customer identifier 5. The device of claim 4, wherein the manufactured devices are of a device type indicated in the request. 1…the request including at least one parameter comprising at least a device type… 6. The device of claim 4, wherein the manufactured devices are manufactured within a date range indicated in the request. 1….wherein the semiconductor devices are manufactured within the date range 7. The device of claim 3, wherein the key management system is configured to generate the activation code for a a first unique identifier of the plurality of pairs using, at least in part, a nonce value of the request and a customer identifier of the request. Similarly claim 17. 4. The non-transitory computer-readable storage medium of claim 9, wherein the nonce value is a first nonce value, and wherein generating at least the first activation code comprises: generating a second nonce value using the first nonce value and the customer identifier; generating the first activation code using the second nonce value and the secret key. 8. The device of claim 1, wherein the manufactured device comprises a semiconductor device. 1…. pairs corresponds to semiconductor devices associated with the customer identifier 9. The device of claim 1, wherein the request is sent to the key management system by way of a trusted partner computing device. 2. The method of claim 1, wherein the request is received using a secure communications channel. 10. The device of claim 9, wherein the trusted partner computing device is securely and communicatively coupled to the key management system. 2. The method of claim 1, wherein the request is received using a secure communications channel. 11. The device of claim 1, wherein the processor is configured to, upon execution of the stored program logic, receive, from the manufactured device, the at least one parameter. 1… retrieving a plurality of pairs based on the at least one parameter 12. The device of claim 11, wherein the at least one parameter received from the manufactured device comprises at least one of a customer identifier or a customer authentication key. Similarly claim 14. 1…at least one parameter comprising at least a device type, a date range, a customer identifier, 18. The device of claim 17, wherein generation of the second nonce value comprises computation of a hash of the results of concatenating the first nonce value and the customer identifier. 5. The method of claim 4, wherein generating the second nonce value comprises computing a hash of results of concatenating the first nonce value and the customer identifier. 19. The device of claim 17, wherein generation of the activation code comprises generation of a message authentication code for the secret key. 6. The method of claim 4, wherein generating the first activation code comprises generating a message authentication code for the secret key. 20. The device of claim 16, wherein the return of the activation code to the remote computing device further comprises a return of a customer identifier value and at least one customer authentication key with the activation code. 8. The method of claim 1, wherein returning the first activation code to the remote computing device further comprises returning a customer identifier value and at least one customer authentication key with the activation code. Although the conflicting claims are not identical, they are not patentably distinct from each other because claims 1-2, 4-5-6 and 8 of 997 contains every element of claims 1-20 of the instant application except for the manufactured device and the limitations in claim 15. However, Cignetti discloses manufactured device wherein the customer identifier or the customer authentication key is stored onto a memory of the manufactured device by a manufacturer of the device (Cignetti Col. 5 line 62-65 “ the HSM key may be a cryptographic key stored on the HSM 206 during the manufacturing process by the manufacturer of the HSM.”). Therefore, It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified 997 to incorporate the teaching of Cignetti to utilize the above feature, with the motivation of protecting cryptographic keys, as recognized by (Cignetti Col. 5 line 55-67 and Col. 6 line 1-35). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 3, 8-14, 16, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas. Regarding claim 1, Griffin teaches a device, comprising: a processor; and a storage medium having stored thereon program logic, wherein the processor is configured to, upon execution of the stored program logic (Abstract “Methods and systems are described for enhanced-security database encryption via cryptographic software”, Col. 1 line 40-41 “Various embodiments relate to a method performed by a processor”): send, to a key management system, a request for an activation code for a manufactured device, the request comprising at least one parameter (Griffin Figure 9, Col. 17 line 8-25 “To obtain a seed 132 for the DEK 130, the database server 116 sends a request to the HSM 118 over a secured channel, such as the secure connection 150. At 918, the database server 116 retrieves the HMAC key cryptogram 126 from the local storage 142. At 920, the database server 116 retrieves the unique identifier 128 from the local storage 142. These retrieved values are sent to the HSM 118 through the secure connection 150. The HMAC key cryptogram 126 and the unique identifier 128 are cryptographically protected using the RSA private key that resides (is written to) in the volatile memory of the database server 116 to generate the second item 962. In an example embodiment, the second item 962 is a digital message transmitted from the database server 116 to the HSM 118 through the secure connection 150.”, where the seed 132 generated, based on HMAC in Figure 9 (924), corresponds to the activation code, consistent with the activation code generated based on HMAC in the instant application [0054]); and receive, from the key management system, the activation code in response to the request, wherein the key management system is configured to [[determine a unique identification of the manufactured device based on the at least one parameter]] (Griffin Figure 9 (924, 928, 958) Col. 17 line 38-40 and 48-59 “At 922, the HMAC key cryptogram 126 is decrypted by the key manager circuit 114 using the master key encryption key 122 to obtain the HMAC key 124…At 924, a seed 132 is generated by the key manager circuit 114 using the HMAC key 124 and the unique identifier 128. The seed 132 is generated by calling an HMAC function, the executable file for which may be, for example, installed on the HSM 118, and transmitted to the database server 116 through the secure connection 150. The purpose of the seed 132 is to securely generate a secret value that serves as an input to a key derivation function (KDF) executed on the database server 116 to generate the DEK 130. Advantageously, at 928 and 930, respectively, the HMAC key 124 and the unique identifier 128 are deleted from the HSM 118 to reduce security vulnerabilities.”, Figure 4, where a plurality of pairs, e.g. (412-414) and (426-428) are retrieved from server storage 142, where each pair is utilized to generate and return seed 1 (418) and seed 2 (432), corresponding to first and second activation codes, respectively, as disclosed in Col. 9 line 48-67 and Col. 10 line 1-36). Griffin discloses determining and retrieving the seed, i.e. activation code at 928, and further determining and retrieving a signature, however, Griffin does not explicitly disclose determining a unique value associated with the device based on the received parameter. Thomas discloses determine a unique identification of the manufactured device based on the at least one parameter (Thomas [0013] “The processing circuit may send a pairing request message including an identification of a device type of the host device to an accessory device, and may receive an encrypted key generator and a random number from the accessory device in response.”, where the key generator and the random number are subsequently used for deriving a unique device key used only for the device as disclosed in [0014]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin to incorporate the teaching of Thomas to utilize the above feature, with the motivation of establishing trust and secure delivery of content between the communicating devices, as recognized by (Thomas [0013]). Regarding claim 3, Griffin in view of Thomas teaches the device of claim 1. Griffin discloses determining and retrieving the seed, i.e. activation code at 928, and further determining and retrieving a signature, however, Griffin does not explicitly disclose determining a unique value associated with the device based on the received parameter. Thomas discloses wherein the key management system is configured to retrieve a plurality of pairs based on the at least one parameter (Thomas [0013] “The processing circuit may send a pairing request message including an identification of a device type of the host device to an accessory device, and may receive an encrypted key generator and a random number from the accessory device in response.”, where the key generator and the random number are subsequently used for deriving a unique device key used only for the device as disclosed in [0014], , further in [0047] Figure 3A 318 disclosing retrieving different information). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin to incorporate the teaching of Thomas to utilize the above feature, with the motivation of establishing trust and secure delivery of content between the communicating devices, as recognized by (Thomas [0013]). Regarding claim 8, Griffin in view of Thomas teaches the device of claim 1, wherein the manufactured device comprises a semiconductor device (Griffin discloses elements of the sever 116 in Figure 1 utilizing IC as disclosed in Col. 18 line 43-47). Regarding claim 9, Griffin in view of Thomas teaches the device of claim 1, wherein the request is sent to the key management system by way of a trusted partner computing device (Griffin Figure 9, Col. 17 line 8-25 “To obtain a seed 132 for the DEK 130, the database server 116 sends a request to the HSM 118 over a secured channel, such as the secure connection 150.”). Regarding claim 10, Griffin in view of Thomas teaches the device of claim 9, wherein the trusted partner computing device is securely and communicatively coupled to the key management system (Griffin Figure 9, Col. 17 line 8-25 “To obtain a seed 132 for the DEK 130, the database server 116 sends a request to the HSM 118 over a secured channel, such as the secure connection 150.”, 150 is further disclosed in Col. 5 line 45-65). Regarding claim 11, Griffin in view of Thomas teaches the device of claim 1, wherein the processor is configured to, upon execution of the stored program logic, receive, from the manufactured device, the at least one parameter (Griffin discloses Griffin Figure 9, Col. 17 line 8-25 “To obtain a seed 132 for the DEK 130, the database server 116 sends a request to the HSM 118 over a secured channel, such as the secure connection 150. At 918, the database server 116 retrieves the HMAC key cryptogram 126 from the local storage 142. At 920, the database server 116 retrieves the unique identifier 128 from the local storage 142. These retrieved values are sent to the HSM 118 through the secure connection 150…”). Regarding claim 12, Griffin in view of Thomas teaches the device of claim 11, wherein the at least one parameter received from the manufactured device comprises at least one of a customer identifier or a customer authentication key (Griffin Figure 9 Col. 17 line 15-27 “The HMAC key cryptogram 126 and the unique identifier 128 are cryptographically protected prior to being transmitted through the secure connection 150. To accomplish this, at 956, prior to transmitting the HMAC key cryptogram 126 and the unique identifier 128 from the database server 116 to the HSM 118, the key manager circuit 114 retrieves the RSA public key from the RSA key vault 970 and sends the RSA public key to the HSM 118 over the secure connection 150. The HMAC key cryptogram 126 and the unique identifier 128 are cryptographically protected using the RSA private key that resides (is written to) in the volatile memory of the database server 116 to generate the second item 962.”). Regarding claim 14, claim 14 recites similar limitation to claim 12, therefore rejected with the same rationale/motivation applied to claim 12. Regarding claim 13, Griffin teaches a non-transitory computer-readable storage medium having stored thereon computer program instructions, wherein the computer program instructions are configured to cause, upon execution by a computer processor (Abstract “Methods and systems are described for enhanced-security database encryption via cryptographic software”, Col. 1 line 40-41 “Various embodiments relate to a method performed by a processor”), the computer processor to: receive, from a manufactured device, at least one parameter associated with the manufactured device; send, to a key management system, a request for an activation code for the manufactured device, the request comprising the at least one parameter (Griffin Figure 9, Col. 17 line 8-25 “To obtain a seed 132 for the DEK 130, the database server 116 sends a request to the HSM 118 over a secured channel, such as the secure connection 150. At 918, the database server 116 retrieves the HMAC key cryptogram 126 from the local storage 142. At 920, the database server 116 retrieves the unique identifier 128 from the local storage 142. These retrieved values are sent to the HSM 118 through the secure connection 150. The HMAC key cryptogram 126 and the unique identifier 128 are cryptographically protected using the RSA private key that resides (is written to) in the volatile memory of the database server 116 to generate the second item 962. In an example embodiment, the second item 962 is a digital message transmitted from the database server 116 to the HSM 118 through the secure connection 150.”, where the seed 132 generated, based on HMAC in Figure 9 (924), corresponds to the activation code, consistent with the activation code generated based on HMAC in the instant application [0054]); and receive, from the key management system, the activation code in response to the request, wherein the key management system is configured to [[determine a unique identification of the manufactured device based on the at least one parameter]] (Griffin Figure 9 (924, 928, 958) Col. 17 line 38-40 and 48-59 “At 922, the HMAC key cryptogram 126 is decrypted by the key manager circuit 114 using the master key encryption key 122 to obtain the HMAC key 124…At 924, a seed 132 is generated by the key manager circuit 114 using the HMAC key 124 and the unique identifier 128. The seed 132 is generated by calling an HMAC function, the executable file for which may be, for example, installed on the HSM 118, and transmitted to the database server 116 through the secure connection 150. The purpose of the seed 132 is to securely generate a secret value that serves as an input to a key derivation function (KDF) executed on the database server 116 to generate the DEK 130. Advantageously, at 928 and 930, respectively, the HMAC key 124 and the unique identifier 128 are deleted from the HSM 118 to reduce security vulnerabilities.”, Figure 4, where a plurality of pairs, e.g. (412-414) and (426-428) are retrieved from server storage 142, where each pair is utilized to generate and return seed 1 (418) and seed 2 (432), corresponding to first and second activation codes, respectively, as disclosed in Col. 9 line 48-67 and Col. 10 line 1-36). Griffin discloses determining and retrieving the seed, i.e. activation code at 928, and further determining and retrieving a signature, however, Griffin does not explicitly disclose determining a unique value associated with the device based on the received parameter. Thomas discloses determine a unique identification of the manufactured device based on the at least one parameter (Thomas [0013] “The processing circuit may send a pairing request message including an identification of a device type of the host device to an accessory device, and may receive an encrypted key generator and a random number from the accessory device in response.”, where the key generator and the random number are subsequently used for deriving a unique device key used only for the device as disclosed in [0014]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin to incorporate the teaching of Thomas to utilize the above feature, with the motivation of establishing trust and secure delivery of content between the communicating devices, as recognized by (Thomas [0013]). Regarding claim 16, Griffin teaches a device comprising: a processor; and a storage medium having stored thereon program logic, wherein the processor is configured to, upon execution of the stored program logic (Abstract “Methods and systems are described for enhanced-security database encryption via cryptographic software”, Col. 1 line 40-41 “Various embodiments relate to a method performed by a processor”): receive a request for an activation code database from a remote computing device, the request comprising at least one parameter (Griffin Figure 9, Col. 17 line 8-25 “To obtain a seed 132 for the DEK 130, the database server 116 sends a request to the HSM 118 over a secured channel, such as the secure connection 150. At 918, the database server 116 retrieves the HMAC key cryptogram 126 from the local storage 142. At 920, the database server 116 retrieves the unique identifier 128 from the local storage 142. These retrieved values are sent to the HSM 118 through the secure connection 150. The HMAC key cryptogram 126 and the unique identifier 128 are cryptographically protected using the RSA private key that resides (is written to) in the volatile memory of the database server 116 to generate the second item 962. In an example embodiment, the second item 962 is a digital message transmitted from the database server 116 to the HSM 118 through the secure connection 150.”, where the seed 132 generated, based on HMAC in Figure 9 (924), corresponds to the activation code, consistent with the activation code generated based on HMAC in the instant application [0054], where the request includes parameters, e.g. timestamp and signature as illustrated in Figure 9); retrieve at least one pair [based on the at least one parameter], the pair comprising a unique identifier and secret key (Griffin Figure 9 (918,920, 956) Col. 17 line 8-15 “To obtain a seed 132 for the DEK 130, the database server 116 sends a request to the HSM 118 over a secured channel, such as the secure connection 150. At 918, the database server 116 retrieves the HMAC key cryptogram 126 from the local storage 142. At 920, the database server 116 retrieves the unique identifier 128 from the local storage 142. These retrieved values are sent to the HSM 118 through the secure connection 150.”, where the HMAC key cryptogram 126 and the unique identifier 128 correspond to the secret key and unique ID (UID), respectively, Griffin further discloses the above described concept for a plurality of pairs retrieved, as described in e.g. Figure 4, where a plurality of pairs, e.g. (412-414) and (426-428) are retrieved from server storage 142, where each pair is utilized to generate seed 1 (418) and seed 2 (432), corresponding to first and second activation codes, respectively, as disclosed in Col. 9 line 48-67 and Col. 10 line 1-36, with the motivation of encrypting different information with different keys, similarly see Figure 7 for the plurality of pairs retrieval (714-716) and (734-736)); generate an activation code for the unique identifier; and return the activation code to the remote computing device (Griffin Figure 9 (924, 928, 958) Col. 17 line 38-40 and 48-59 “At 922, the HMAC key cryptogram 126 is decrypted by the key manager circuit 114 using the master key encryption key 122 to obtain the HMAC key 124…At 924, a seed 132 is generated by the key manager circuit 114 using the HMAC key 124 and the unique identifier 128. The seed 132 is generated by calling an HMAC function, the executable file for which may be, for example, installed on the HSM 118, and transmitted to the database server 116 through the secure connection 150. The purpose of the seed 132 is to securely generate a secret value that serves as an input to a key derivation function (KDF) executed on the database server 116 to generate the DEK 130. Advantageously, at 928 and 930, respectively, the HMAC key 124 and the unique identifier 128 are deleted from the HSM 118 to reduce security vulnerabilities.”, Figure 4, where a plurality of pairs, e.g. (412-414) and (426-428) are retrieved from server storage 142, where each pair is utilized to generate and return seed 1 (418) and seed 2 (432), corresponding to first and second activation codes, respectively, as disclosed in Col. 9 line 48-67 and Col. 10 line 1-36). While Griffin discloses the aforementioned limitations, however, Griffin does not explicitly disclose that the request includes a parameter, and retrieving/determining the above mentioned pair based on the parameter. Thomas discloses retrieving…based on the at least one parameter, each of the plurality of pairs the pair including a unique ID (UID) and secret key (Thomas [0013] “The processing circuit may send a pairing request message including an identification of a device type of the host device to an accessory device, and may receive an encrypted key generator and a random number from the accessory device in response. The key generator may be encrypted using an encryption key derived from the random number and a global key, which global key is known to the host device and is the same value for all devices of a same device type. The processing circuit may use the global key and the received random number to derive the encryption key used for decrypting the key generator. Using the key generator and the random number, the processing circuit may derive a device key for use establishing secure delivery of content from the accessory device.”, where the retrieved pair based on the request is 1) an encrypted key generator, corresponding to a secret key generator, and 2) a random number, which is a unique number to be used in conjunction with a global key to derive and identify a unique decryption key for decryption the encrypted key generator where the random number corresponds to a unique ID, , where there are plurality of device types as disclosed in [0045, 0077], and accordingly have their corresponding pair disclosed above in [0013]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin to incorporate the teaching of Thomas to utilize the above feature, with the motivation of establishing trust and secure delivery of content between the communicating devices, as recognized by (Thomas [0013]). Regarding claim 19, Griffin in view of Thomas teaches the device of claim 17, wherein generation of the activation code comprises generation of a message authentication code for the secret key (Griffin Figure 9 (924) Col. 17 line 38-40 and 48-59 “At 922, the HMAC key cryptogram 126 is decrypted by the key manager circuit 114 using the master key encryption key 122 to obtain the HMAC key 124…At 924, a seed 132 is generated by the key manager circuit 114 using the HMAC key 124 and the unique identifier 128. The seed 132 is generated by calling an HMAC function…”). Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas, Libonate (US 20150312255 A1), hereinafter Libonate ,Sidle (US 20110246773 A1), hereinafter Sidle and John et. al. (US 20190149527 A1), hereinafter John. Regarding claim 2, Griffin in view of Thomas teaches the device of claim 1. wherein the at least one parameter comprises at least.. Griffin does not teach the below limitation. Thomas discloses wherein the at least one parameter comprises the device type (Thomas [0013] “The processing circuit may send a pairing request message including an identification of a device type of the host device to an accessory device, and may receive an encrypted key generator and a random number from the accessory device in response.”, where the key generator and the random number are subsequently used for deriving a unique device key used only for the device as disclosed in [0014], further in [0047] Figure 3A 318). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin to incorporate the teaching of Thomas to utilize the above feature, with the motivation of establishing trust and secure delivery of content between the communicating devices, as recognized by (Thomas [0013]). Griffin in view of Thomas do not disclose the limitations below. Libonate discloses wherein the at least one parameter comprises a customer identifier (CID) (Libonate illustrates in Figure 1 a user device sending a request which includes a subscriber identifier, i.e. a customer identifier (CID)), It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin to incorporate the teaching of Libonate to utilize the above feature, with the motivation of associating the request with subscriber identifier and then a unique identifier instead of the device/customer identifier, which prevent tracking device/customer requests and activities, as recognized by (Libonate [0014]). Griffin in view of Thomas and Libonate do not disclose the limitations below. Sidle discloses wherein the at least one parameter comprises a first nonce value (Sidle [0035-0040] “a request message 10a is generated by the client module 40 which includes the following data:… Nonce (used to detect replays)”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Libonate to incorporate the teaching of Sidle to utilize the above feature, with the motivation detecting replay attack (Sidle [0040]). Griffin in view of Thomas, Libonate and Sidle do not disclose the limitations below. John discloses wherein the at least one parameter comprises the date range (John [0066] “At step 402, the access device 102 may reside on the airplane and may transmit a key request message to the key management server 114, requesting a first key identifier and a first public key corresponding to a first private key. The access device 102 may include data that indicates the request time and the requested time by which to receive the first ephemeral public key and the key identifier. The request message may also include the number of requested public keys, the requested time to live on each of the requested public keys, and any other relevant request information.”, where the request includes a time to live duration, corresponding to date/time range/duration). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Thomas, Libonate and Sidle to incorporate the teaching of John to utilize the above feature, with the motivation of ability to establish a successful connection between the access device and a remote computer during an connection intermittent environment., as recognized by (John Abstract [0064] and throughout). Claims 4-5 are rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas, Libonate (US 20150312255 A1), hereinafter Libonate. Regarding claim 4, Griffin in view of Thomas teaches the device of claim 3. Griffin in view of Thomas teaches the plurality of pairs. However, Griffin in view of Thomas do not explicitly disclose the limitation below. Emphasis in italic. Libonate discloses wherein the plurality of pairs corresponds to manufactured devices associated with a customer identifier (Libonate [0023] CDS 230 may include one or more computation and communication devices that gather, process, search, store, and/or provide information in a manner described herein. For example, in some implementations, CDS 230 may encrypt a UIDH based on randomized information (e.g., a random number) and a shared key to create a transactional identifier, and may modify the request by inserting the transactional identifier and/or the randomized information into a packet associated with the request (e.g., into a packet header, trailer, payload, etc.). CDS 230 may transmit the modified request to content provider 250 which may enable targeted content to be provided to user device 210 being used by the subscriber with which the UIDH is associated. Additional details regarding CDS 230 are described in below with respect to FIG. 3.”, [0025] “…Content provider 250 may receive, from ad provider 255, targeted content, such as advertising content, etc., that corresponds to a transactional identifier and may provide, via the particular user device 210, the targeted content and/or other content to the subscriber with which the transactional identifier is associated.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin to incorporate the teaching of Libonate to utilize the above feature, with the motivation of associating the request with subscriber identifier and then a unique identifier instead of the device/customer identifier, which prevent tracking device/customer requests and activities, as recognized by (Libonate [0014]). Regarding claim 5, Griffin in view of Thomas and Libonate teaches the device of claim 4. Griffin does not explicitly disclose the limitation below. Thomas discloses wherein the manufactured devices are of a device type indicated in the request (Thomas [0013] “The processing circuit may send a pairing request message including an identification of a device type of the host device to an accessory device, and may receive an encrypted key generator and a random number from the accessory device in response.”, where the key generator and the random number are subsequently used for deriving a unique device key used only for the device as disclosed in [0014]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin to incorporate the teaching of Thomas to utilize the above feature, with the motivation of establishing trust and secure delivery of content between the communicating devices, as recognized by (Thomas [0013]). Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas, Libonate (US 20150312255 A1), hereinafter Libonate and Maurice (US 20130198720 A1). Regarding claim 6, Griffin in view of Thomas and Libonate teaches the device of claim 4. Griffin in view of Thomas and Libonate do not disclose the limitation below. Maurice discloses wherein the manufactured devices are manufactured within a date range indicated in the request (Maurice [0057] “A request may include information about the requesting device 120-140, the location of the requesting device 120-140, the type of network or networks the requesting device 120-140 is in communication with, or other information. For example, in one embodiment the request may include a request for a specific version of an application. In another embodiment, the request may include a request for an application and the device receiving the request determines which version of the application to send to the requesting device. A request may include the manufacturer, model number, year manufactured, or additional information regarding hardware specifications of the requesting device, one or more internal components in the requesting device, or one or more devices in communication with the requesting device.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Thomas and Libonate to incorporate the teaching of Maurice to utilize the above feature, with the motivation of determining resource that best suited based on features in the request, as recognized by (Maurice [0025]). Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas and Niset (US 20150089230 A1). Regarding claim 7, Griffin in view of Thomas teaches the device of claim 3. Griffin in view of Thomas does not disclose the limitation below. Niset discloses wherein the key management system is configured to generate the activation code for a a first unique identifier of the plurality of pairs using, at least in part, a nonce value of the request and a customer identifier of the request (Niset illustrates in Figure 3 concatenating random numbers sequence r with a unique Identifier t included in the request, where the random numbers sequence r corresponds to the first nonce and the unique Identifier t corresponds to identifying the machine 30 corresponds to CID, and the result of the concatenation corresponds to the second nonce, then generating an HMAC result using the result of the concatenation, i.e. second nonce, and a secret key KHMAC, [0075] “The request 13 contains the number of random numbers that are requested (s in the figure) and a unique identifier tag number (t in the figure) that will be used to detect possible replay attacks and thus guarantee uniqueness. [0077] b. Upon receipt of the request 13, the HRNG 8 in device 10 will produce the random numbers sequence (r in the figure). Note that the random numbers can be generated at the time of the request, or be generated at an earlier time and stored in a buffer. [0078] c. The device 10 subsequently concatenates the random numbers sequence r with the unique tag t and calculates in block 50 its authentication code HMAC (r,t,K.sub.HMAC) using the machines secret key K.sub.HMAC 21. The HRNG device 10 then sends back to the agent 30 the random numbers sequence r in plaintext along with the resulting HMAC(r, t, K.sub.HMAC). [0079] d. Upon receipt of the random numbers sequence r and the HMAC (r,t,K.sub.HMAC), the agent 30 calculates the HMAC in block 51 of the random numbers sequence r with the unique identifier t using its secret key K.sub.HMAC 20. The results are compared in block 61. If the result corresponds to what was received, the machine can confirm authentication of the HRNG device 10, as well as integrity and uniqueness of the received public random numbers sequence...”, Consistent with the nonce being a random number described in the instant application in [0028-0029]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Thomas to incorporate the teaching of Niset to utilize the above feature, with the motivation of confirming authentication, integrity and uniqueness of the received public random numbers sequence, as recognized by (Niset [0075]). Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas and Cignetti (US 20190074960 A1). Regarding claim 15, Griffin in view of Thomas teaches the non-transitory computer-readable storage medium of claim 14. Griffin in view of Thomas does not disclose the limitation below. Cignetti discloses wherein the customer identifier or the customer authentication key is stored onto a memory of the manufactured device by a manufacturer of the device (Cignetti Col. 5 line 62-65 “ the HSM key may be a cryptographic key stored on the HSM 206 during the manufacturing process by the manufacturer of the HSM.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Thomas to incorporate the teaching of Cignetti to utilize the above feature, with the motivation of protecting cryptographic keys, as recognized by (Cignetti Col. 5 line 55-67 and Col. 6 line 1-35). Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas and Niset (US 20150089230 A1). Regarding claim 17, Griffin in view of Thomas teaches the device of claim 16. Griffin in view of Thomas does not disclose the limitation below. Niset discloses wherein the at least one parameter comprises a customer identifier, first nonce value, device type, and date range, and wherein generation of the activation code comprises: generate a second nonce value using the first nonce value and the customer identifier; generate the activation code using the second nonce value and the secret key (Niset illustrates in Figure 3 concatenating random numbers sequence r with a unique Identifier t included in the request, where the random numbers sequence r corresponds to the first nonce and the unique Identifier t corresponds to identifying the machine 30 corresponds to CID, and the result of the concatenation corresponds to the second nonce, then generating an HMAC result using the result of the concatenation, i.e. second nonce, and a secret key KHMAC, [0075] “The request 13 contains the number of random numbers that are requested (s in the figure) and a unique identifier tag number (t in the figure) that will be used to detect possible replay attacks and thus guarantee uniqueness. [0077] b. Upon receipt of the request 13, the HRNG 8 in device 10 will produce the random numbers sequence (r in the figure). Note that the random numbers can be generated at the time of the request, or be generated at an earlier time and stored in a buffer. [0078] c. The device 10 subsequently concatenates the random numbers sequence r with the unique tag t and calculates in block 50 its authentication code HMAC (r,t,K.sub.HMAC) using the machines secret key K.sub.HMAC 21. The HRNG device 10 then sends back to the agent 30 the random numbers sequence r in plaintext along with the resulting HMAC(r, t, K.sub.HMAC). [0079] d. Upon receipt of the random numbers sequence r and the HMAC (r,t,K.sub.HMAC), the agent 30 calculates the HMAC in block 51 of the random numbers sequence r with the unique identifier t using its secret key K.sub.HMAC 20. The results are compared in block 61. If the result corresponds to what was received, the machine can confirm authentication of the HRNG device 10, as well as integrity and uniqueness of the received public random numbers sequence...”, Consistent with the nonce being a random number described in the instant application in [0028-0029]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Thomas to incorporate the teaching of Niset to utilize the above feature, with the motivation of confirming authentication, integrity and uniqueness of the received public random numbers sequence, as recognized by (Niset [0075]). Claim 18 are rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas and Niset (US 20150089230 A1) and Yavuz (US 20130326224 A1), hereinafter Yavuz. Regarding claim 18, Griffin in view of Thomas and Niset teaches the device of claim 17. Griffin in view of Thomas does not disclose the below limitation below. Niset discloses wherein generation of the second nonce value comprises computation of [[a hash of] the results of concatenating the first nonce value and the customer identifier (Niset illustrates in Figure 3 concatenating random numbers sequence r with a unique Identifier t included in the request, where the random numbers sequence r corresponds to the first nonce and the unique Identifier t corresponds to identifying the machine 30 corresponds to CID, and the result of the concatenation corresponds so the second nonce, then generating an HMAC result using the result of the concatenation, i.e. second nonce, and a secret key KHMAC, [0075] “The request 13 contains the number of random numbers that are requested (s in the figure) and a unique identifier tag number (t in the figure) that will be used to detect possible replay attacks and thus guarantee uniqueness. [0077] b. Upon receipt of the request 13, the HRNG 8 in device 10 will produce the random numbers sequence (r in the figure). Note that the random numbers can be generated at the time of the request, or be generated at an earlier time and stored in a buffer. [0078] c. The device 10 subsequently concatenates the random numbers sequence r with the unique tag t and calculates in block 50 its authentication code HMAC (r,t,K.sub.HMAC) using the machines secret key K.sub.HMAC 21. The HRNG device 10 then sends back to the agent 30 the random numbers sequence r in plaintext along with the resulting HMAC(r, t, K.sub.HMAC). [0079] d. Upon receipt of the random numbers sequence r and the HMAC (r,t,K.sub.HMAC), the agent 30 calculates the HMAC in block 51 of the random numbers sequence r with the unique identifier t using its secret key K.sub.HMAC 20. The results are compared in block 61. If the result corresponds to what was received, the machine can confirm authentication of the HRNG device 10, as well as integrity and uniqueness of the received public random numbers sequence...”, Consistent with the nonce being a random number described in the instant application in [0028-0029]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Libonate, Sidle and John to incorporate the teaching of Niset to utilize the above feature, with the motivation of confirming authentication, integrity and uniqueness of the received public random numbers sequence, as recognized by (Niset [0075]). Griffin in view of Thomas, Libonate, Sidle, John and Niset do not disclose the limitations below. Yavuz discloses generating the second nonce value comprises computing a hash of the results of concatenating the first nonce value and the CID (Yavuz illustrates in Figure 5 (568) generation of the hash of a concatenation of a nonce and a device identifier, [0061] “generates a hash value for the concatenated random nonce and the device identifier of the sender, H(nonce.parallel.device ID) (block 568). ”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Libonate, Sidle, John and Niset to incorporate the teaching of Yavuz to utilize the above feature, with the motivation of taking advantage of hashing messages and inputs, e.g. security where an attacker cannot generate forged input data that produces the same hash, as recognized by (Yavuz [0015]). Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Griffin (US 10615969 B1), hereinafter Griffin in view of Thomas et. al. (US 20100306538 A1), hereinafter Thomas and Combs (US 10061932 B1), hereinafter Combs. Regarding claim 20, Griffin in view of Thomas teaches the device of claim 16. Griffin in view of Thomas does not disclose the limitation below. Combs discloses wherein the return of the activation code to the remote computing device further comprises a return of a customer identifier value and at least one customer authentication key with the activation code (Combs discloses receiving a ciphertext object, which includes HMAC, i.e. activation code, and unique identifier, and cryptographic key, corresponding to authentication key, Col. 5 line 41-52 “FIG. 2 illustrates an example XML encapsulation used to describe a ciphertext object in a file. The ciphertext object encoded in XML can include one or more pre-determined fields. As non-limiting examples, the XML schema can include fields for name, unique identifier, location, and ciphertext. Numerous other fields could be used as appropriate, in addition to or instead of those described above. As non-limiting examples, the ciphertext object can include other or additional parameters, such as packet version, role key unique identifier, role key version unique identifier, salt, initialization vector, and hash-based message authentication code (HMAC).”, Col. 16 line 21-33 “The decryption processor can receive the ciphertext object from the encryption processor or from any suitable permanent or temporary data store. In some embodiments, such as that depicted in FIG. 1, the decryption processor can be configured to request a corresponding decryption key from the key server. Alternatively, the recipient may receive the key from the key server, bypassing the decryption processor. In that architecture, the recipient could provide both the ciphertext object and the key to the decryption processor. In that embodiment, the key may be stored on a persistent secure storage device accessible to the recipient, such as a smart card. The key can then be used to decrypt the ciphertext object provided to the recipient.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have modified Griffin in view of Thomas to incorporate the teaching of Combs to utilize the above feature, with the motivation of protecting sensitive data and securely copying data between application, as recognized by (Combs Abstract). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Smith (US 20160314486 A1) discloses manufacturer can use the Customer ID to verify that the storage device. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BASSAM A NOAMAN whose telephone number is (571)272-2705. The examiner can normally be reached Monday-Friday 8:30 AM-5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BASSAM A NOAMAN/Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Aug 01, 2025
Application Filed
Sep 16, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739270
INTELLIGENT WORKFLOW FOR PROTECTING SERVERS FROM OUTSIDE THREATS
4y 7m to grant Granted Sep 15, 2026
Patent 12739115
PROTOCOLS WITH NOISY RESPONSE-BASED CRYPTOGRAPHIC SUBKEYS
2y 0m to grant Granted Sep 15, 2026
Patent 12730867
METHOD AND SYSTEM FOR AUTHENTICATION
3y 11m to grant Granted Sep 08, 2026
Patent 12732343
ACCOUNT OPENING METHODS, SYSTEMS, AND APPARATUSES
2y 9m to grant Granted Sep 08, 2026
Patent 12732344
AUTHORITY MANAGEMENT METHOD
2y 9m to grant Granted Sep 08, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+46.2%)
2y 9m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 282 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month