Prosecution Insights
Last updated: August 17, 2026
Application No. 17/104,311

INTEGRATED CIRCUIT FOR OBTAINING ENHANCED PRIVILEGES FOR A NETWORK-BASED RESOURCE AND PERFORMING ACTIONS IN ACCORDANCE THEREWITH

Non-Final OA §103
Filed
Nov 25, 2020
Examiner
WILCOX, JAMES J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
7 (Non-Final)
70%
Grant Probability
Favorable
7-8
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
435 granted / 620 resolved
+12.2% vs TC avg
Strong +61% interview lift
Without
With
+61.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
26 currently pending
Career history
657
Total Applications
across all art units

Statute-Specific Performance

§101
15.2%
-24.8% vs TC avg
§103
58.1%
+18.1% vs TC avg
§102
14.8%
-25.2% vs TC avg
§112
7.2%
-32.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 620 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This Office Action is in response to the amendment filed 02/10/2026. In the instant amendment, claims 1, 8, 15, 16, 19, 23 and 24 are amended, claims 6-7, 13-14, 18, 20 are cancelled; 1, 8, 15 are independent claims. Claims 1-5, 8-12, 15-17, 19 and 21-26 are pending in this application. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04/10/2026 has been entered. Information Disclosure Statement The information disclosure statement (IDS) submitted on 04/24/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Response to Arguments Applicant’s arguments with respect to claim(s) 1, 8 and 15 with regard to the limitations “maintaining, by the configuration register of the security coprocessor, a number of first requests received from the CPU, the number of first requests comprising the first request and a previously validated first request; determining whether the number of first requests is greater than a maximum number value,” have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-2, 8-9, 15 and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Kessler et al (“Kessler,” US 6,789,147), Hibbert et al (“Hibbert,” US 20170111368) in view of Thom et al (“Thom,” US 20140137178) and further in view of McCauley et al (“McCauley,” US 20210056545). Regarding claim 1, Kessler discloses a method implemented by a security coprocessor of a computing device, the security coprocessor comprising a configuration register, the method comprising: (Kessler, FIG. 2 and Col 4. Lines 42-49, describes a security coprocessor 212 integrated in the same system with the host processor 202, the coprocessor includes register files (Col. 9, Lines 23-29), execution units (Col. 9, Lines 45-51) and interfaces for receiving/processing requests from the CPU (Col. 4, Lines 41-58)) receiving by the security coprocessor, from a separate central processing unit (CPU) of the same computing device, a first request for elevated user privileges with respect to a network-based resource, (Kessler describes Col. 4, Lines 42-52, host processor 202 issues macro security operations Col. 4, Lines 20-40 to the security processor 212; Col. 10, Lines 55-67; Col. 11, Lines 1-10 continuous flow request mechanism describes CPU to coprocessor request transmission. Privileged cryptographic operations are used in network authentication Col. 8, Lines 42-48, SSL/TLS messaging (Col. 4, Lines 6-9) Kessler fails to explicitly disclose the first request initiated by a user interacting with a user interface executed by the CPU and having user privileges lower than the requested elevated user privileges. However, in an analogous art, Hibbert discloses the first request initiated by a user interacting with a user interface executed by the CPU and having user privileges lower than the requested elevated user privileges, (Hibbert, [0044] describes a request; [0077]-[0078] describes an administrator [user] interacting with a GUI [user interface] for defining certain privileges; [0093] for an elevated account such as administrative or super-user privilege status); [0043] describes a CPU; [0174], [0042]) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Hibbert with the system/method of Hibbert to include the first request initiated by a user interacting with a user interface executed by the CPU and having user privileges lower than the requested elevated user privileges. One would have been motivated to elevate privileges for application execution (Hibbert, [0002]). Kessler and Hibbert fail to explicitly disclose maintaining, by the configuration register of the security coprocessor, a number of first requests received from the CPU, the number of first requests comprising the first request and a previously valid first request; determining whether the number of first requests is greater than a maximum number value; in response to determining that the number of first requests is greater than the maximum number value, denying the request. However, in an analogous art, Thom discloses maintaining, by the configuration register of the security coprocessor, a number of first requests received from the CPU, (Thom, [0054] describes an attempt counter that is incremented each time the compare-and-increment function is invoked; and a successful-attempt counter incremented each time access is allowed; [0017], [0020]-[0022] describe that the TPM [security coprocessor] provides secure processing and storage, contains trusted functions and nonvolatile storage, maintains monotonic counters in that nonvolatile storage; and increments those counters through TPM functions; Also see FIG 1; [0018]-[0019] describe received from the CPU; [0020] describes a register used to store device settings or operating modes [configuration register]) the number of first requests comprising the first request and a previously valid first request; (Thom, [0046] the monotonic counter is incremented each time a request is made, regardless of whether access was allowed; [0043]-[0044] describe after a success access request, the TPM creates a new policy using the incremented monotonic-counter value. An initial failed request followed by a valid request advances the counter to nine and the new policy begins from that accumulated value. The counter therefore preserves the history of earlier requests, including the successful request) determining whether the number of first requests is greater than a maximum number value; (Thom, [0054]-[0055] describe determining whether the number of requests is greater than a maximum number threshold) in response to determining that the number of first requests is greater than the maximum number value, denying the request, (Thom, [0054]-[0055] describe determining whether the number of requests is greater than a maximum number threshold; [0039]-[0040], FIG 9 describe if no policy is satisfied, access is denied; once the request count exceeds the permitted number, subsequent access is locked or denied indefinitely) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Thom with the system/method of Kessler and Hibbert to include maintaining, by the configuration register of the security coprocessor, a number of first requests received from the CPU, the number of first requests comprising the first request and a previously valid first request; determining whether the number of first requests is greater than a maximum number value; in response to determining that the number of first requests is greater than the maximum number value, denying the request. One would have been motivated to provide attack prevention for trusted platform modules (Thom, [0012]). Kessler, Hibbert and Thom fail to explicitly disclose in response to determining that the number of first requests is less than or equal to the maximum number value; validating, by the security coprocessor, the first request, in response to validating the first request, providing, by the security coprocessor, a second request for the elevated user privileges to a network-based service, receiving, by the security coprocessor, a response from the network-based service, the response indicating that the second request for the elevated user privileges is granted, responsive to receiving the response, providing, by the security coprocessor, a third request to the network-based service to access the network-based resource in accordance with the elevated user privileges. However, in an analogous art, McCauley discloses in response to determining that the number of first requests is less than or equal to the maximum number value; validating, by the security coprocessor, the first request, in response to validating the first request, (McCauley discloses [0024], [0039], [0048]-[0049] Hardware Security Module 105 receives an operation request and performs policy validation, endorsement verification and authorization checks. It either approves or rejects based on validation) providing, by the security coprocessor, a second request for the elevated user privileges to a network-based service, (McCauley discloses [0053], [0047] the Hardware Security Module sends an operation description to the cryptoasset custodian service/relay server [0093]) receiving, by the security coprocessor, a response from the network-based service, the response indicating that the second request for the elevated user privileges is granted, (McCauley discloses [0025], [0048]-[0049] the network service or server returns approval or rejection and the Hardware Security Module receives the approval [0095]-[0097]) responsive to receiving the response, providing, by the security coprocessor, a third request to the network-based service to access the network-based resource in accordance with the elevated user privileges, (McCauley discloses [0098], [0026] after receiving the approval , Hardware Security Module 105 performs the cryptographic signing of a transaction, enabling the authorized network operation which is the cryptoasset transfer, [0005]-[0006]) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of McCauley with the system/method of Kessler, Hibbert and Thom to include in response to determining that the number of first requests is less than or equal to the maximum number value; validating, by the security coprocessor, the first request, in response to validating the first request, providing, by the security coprocessor, a second request for the elevated user privileges to a network-based service, receiving, by the security coprocessor, a response from the network-based service, the response indicating that the second request for the elevated user privileges is granted, responsive to receiving the response, providing, by the security coprocessor, a third request to the network-based service to access the network-based resource in accordance with the elevated user privileges. One would have been motivated to provide risk mitigation for a cryptoasset custodian system (McCauley, [0002]). Regarding claim 2, Kessler, Hibbert, Thom and McCauley disclose the method of claim 1. Hibbert further discloses wherein said validating comprises: (Hibbert, [0114]-[0115] describes the process of authenticating and verifying [validating] the privilege request(s), [0155], [0170] describes a co-processor, [0044] describes request(s)) requesting a user to provide credentials; (Hibbert, [0130] describes prompting the user for account credentials (e.g. username and password]) validating the provided credentials; (Hibbert, [0130] describes authenticating the user by his credentials which were entered into the prompt) and responsive to validating the provided credentials, (Hibbert, [0130] describes authenticating the user by his credentials which were entered into the prompt) validating the first request, (Hibbert, [0115] describes verifying the privilege request) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Hibbert with the system/method of Kessler to include wherein said validating comprises: requesting the user to provide credentials; validating the provided credentials; and responsive to validating the provided credentials, validating the first request.. One would have been motivated to elevate privileges for application execution (Hibbert, [0002]). Regarding claim 8, claim 8 is directed to a computing device.. Claim 8 is similar in scope to claim 1 and is therefore rejected under the same rationale. Regarding claim 9, claim 9 is directed to a computing device of claim 8. Claim 9 is similar in scope to claim 2 and is therefore rejected under the same rationale. Regarding claim 15, claim 15 is directed to a method. Claim 8 is similar in scope to claim 1 and is therefore rejected under the same rationale. Regarding claim 26, Kessler, Hibbert, Thom and McCauley discloses the method of claim 1. Hibbert further discloses wherein the number of first requests comprises an additional first request, the additional first request received by the security coprocessor and initiated by the user interacting with the user interface executed by the CPU and having user privileges lower than the requested elevated user privileges, (Hibbert, [0044] describes more than one request; [0077]-[0078] describes an administrator [user] interacting with a GUI [user interface] for defining certain privileges; [0093] for an elevated account such as administrative or super-user privilege status); [0043] describes a CPU; [0174], [0042]) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Hibbert with the system/method of Kessler to include wherein the number of first requests comprises an additional first request, the additional first request received by the security coprocessor and initiated by the user interacting with the user interface executed by the CPU and having user privileges lower than the requested elevated user privileges. One would have been motivated to elevate privileges for application execution (Hibbert, [0002]). Claims 3 and 10 are rejected under 35 U.S.C. 103 as being unpatentable Kessler et al (“Kessler,” US 6,789,147), Hibbert et al (“Hibbert,” US 20170111368) in view of Thom et al (“Thom,” US 20140137178) in view of McCauley et al (“McCauley,” US 20210056545) and further in view of Bowen et al (“Bowen,” US 20170366539). Regarding claim 3, Kessler, Hibbert, Thom and McCauley disclose the method of claim 2. Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein the credentials comprise at least one of: biometric information; environmental information; a passcode; a username; or a password. However, in an analogous art, Bowen discloses wherein the credentials comprise at least one of: biometric information; (Bowen, [0018], A user can provide any of various types of credentials in order to authenticate an identity of the user to the provider. These credentials can include, for example, a username and password pair, biometric data, a digital signature, or other such information) environmental information; a passcode; a username; (Bowen, [0018], A user can provide any of various types of credentials in order to authenticate an identity of the user to the provider. These credentials can include, for example, a username and password pair, biometric data, a digital signature, or other such information) or a password, (Bowen, [0018], A user can provide any of various types of credentials in order to authenticate an identity of the user to the provider. These credentials can include, for example, a username and password pair, biometric data, a digital signature, or other such information) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Bowen with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein the credentials comprise at least one of: biometric information; environmental information; a passcode; a username; or a password. One would have been motivated to verify that the user is associated with the corresponding domains or addresses, and authorized to have actions performed for them (Bowen, [0002]). Regarding claim 10, claim 10 is directed to the computing device of claim 9. Claim 10 is similar in scope to claim 3 and is therefore rejected under the same rationale. Claims 4 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Kessler et al (“Kessler,” US 6,789,147), Hibbert et al (“Hibbert,” US 20170111368), Thom et al (“Thom,” US 20140137178) in view of McCauley et al (“McCauley,” US 20210056545) and further in view of Skygebjerg et al (“Skygebjerg,” US 20150242602). Regarding claim 4, Kessler, Hibbert, Thom and McCauley disclose the method of claim 2. Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein the second request comprises at least one of: an identifier of the computing device; the provided credentials; an identifier of the network-based resource; voltage characteristics of the computing device; temperature characteristics of the computing device; or a location of the computing device. However, in an analogous art, Skygebjerg discloses wherein the second request comprises at least one of: (Skygebjerg, [0050] describes a second request) an identifier of the computing device; the provided credentials; an identifier of the network-based resource; voltage characteristics of the computing device; temperature characteristics of the computing device; or a location of the computing device (Skygebjerg, [0050] describe a second request for a location of the computing device) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Skygebjerg with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein the second request comprises at least one of: an identifier of the computing device; the provided credentials; an identifier of the network-based resource; voltage characteristics of the computing device; temperature characteristics of the computing device; or a location of the computing device. One would have been motivated to provide secure verification of the identity of a user (Skygebjerg, [0002]). Regarding claim 11, claim 11 is directed to the computing device of claim 9. Claim 11 is similar in scope to claim 4 and is therefore rejected under the same rationale. Claims 5 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Kessler et al (“Kessler,” US 6,789,147), Hibbert et al (“Hibbert,” US 20170111368), Thom et al (“Thom,” US 20140137178), McCauley et al (“McCauley,” US 20210056545) in view of Skygebjerg et al (“Skygebjerg,” US 20150242602) and further in view of Aal et al (“Aal,” EP3726394). Regarding claim 5, Kessler, Hibbert, Thom and McCauley disclose the method of claim 1. Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein said validating comprises: determining a location in which the computing device is located; determining at least one of voltage characteristics or temperature characteristics associated with the computing device; determining that the location is one from a plurality of predetermined locations. However, in an analogous art, Skygebjerg discloses wherein said validating comprises: determining a location in which the computing device is located; (Skygebjerg, [0050] describe a second request for a location of the computing device) determining that the location is one from a plurality of predetermined locations; (Skygebjerg, [0034] describes determining that the location is one from a plurality of predetermined locations which are ones taken previously by GPS and compared to a current location) and responsive to determining that the location is one from the plurality of predetermined locations (Skygebjerg, [0034] describes determining that the location is one from a plurality of predetermined locations which are ones taken previously by GPS and compared to a current location) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Skygebjerg with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein said validating comprises: determining a location in which the computing device is located; determining that the location is one from a plurality of predetermined locations; and responsive to determining that the location is one from the plurality of predetermined locations. One would have been motivated to provide secure verification of the identity of a user (Skygebjerg, [0002)). Kessler, Hibbert, Thom, McCauley and Skygebjerg fail to explicitly disclose determining that at least one of: the voltage characteristics are below a predetermined voltage threshold, or the temperature characteristics are below a predetermined temperature threshold; and responsive to determining that the location is one from the plurality of predetermined locations and determining that at least one of the voltage characteristics are below a predetermined threshold or the temperature characteristics are below a predetermined threshold, validating the first request. However, in an analogous art, Aal discloses determining at least one of voltage characteristics or temperature characteristics associated with the computing device; (Aal, [0055], [0021], [0044], [0040] describe determining voltage characteristics associated with the computer) determining that at least one of: the voltage characteristics are below a predetermined threshold, or the temperature characteristics are below a predetermined threshold; (Aal, [0055], [0021], [0044], [0040], describe determining that at least one of the voltage characteristics are below a threshold) and determining that at least one of the voltage characteristics are below a predetermined voltage threshold or the temperature characteristics are below a predetermined temperature threshold, (Aal, [0055], [0021], [0044], [0040] describe determining that at least one of the voltage characteristics are below a voltage threshold) validating the first request, (Aal, [0040], describes authenticating [validating] the first request). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Aal with the system/method of Kessler, Hibbert, Thom, McCauley and Skygebjerg to include determining that at least one of: the voltage characteristics are below a predetermined threshold, or the temperature characteristics are below a predetermined threshold; and responsive to determining that the location is one from the plurality of predetermined locations and determining that at least one of the voltage characteristics are below a predetermined voltage threshold or the temperature characteristics are below a predetermined temperature threshold, validating the first request. One would have been motivated to reconfigurable systems-on-a-chip (Aal, [0001]). Regarding claim 12, claim 12 is directed to the computing device of claim 8. Claim 12 is similar in scope to claim 5 and is therefore rejected under the same rationale. Claims 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over Kessler et al (“Kessler,” US 6,789,147), Hibbert et al (“Hibbert,” US 20170111368), Thom et al (“Thom,” US 20140137178) in view of McCauley et al (“McCauley,” US 20210056545) and further in view of Grigg et al (“Grigg,” US 20160173478). Regarding claim 16, Kessler, Hibbert, Thom and McCauley disclose the method of claim 15. Thom further discloses wherein said denying the request, (Thom, [0041] when more access requests are made than there are permitted policy entries, the monotonic counter advances beyond every permitted value so no policy entry can be satisfied; [0031], [0039], [0041] & [0047] supplies denial when the independent request-count condition has exceeded its permitted limit) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Thom with the system/method of Kessler and Hibbert to wherein said denying the request. One would have been motivated to provide attack prevention for trusted platform modules (Thom, [0012]). Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein said denying the request comprises: requesting the user to provide credentials; validating the provided credentials; and responsive to validating the provided credentials and determining that the number of first requests is greater than the predetermined threshold, denying the first request. However, in an analogous art, Grigg discloses wherein said denying the request comprises: requesting the user to provide credentials; (Grigg, [0054] describes after receiving he user’s access request, the system sends the user a request to provide one or more authentication credentials corresponding to the required level of authentication) validating the provided credentials; (Grigg, [0062] describes the system validates the received credentials by comparing them with stored information and validates the user-authentication level when the credentials are accurate) and responsive to validating the provided credentials (Grigg, [0062] describes and responsive to validating the provided credentials) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Grigg with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein said denying the request comprises: requesting the user to provide credentials; validating the provided credentials; and responsive to validating the provided credentials and determining that the number of first requests is greater than the predetermined threshold, denying the first request. One would have been motivated to provide authentication using previously-validated authentication credentials, (Grigg, [0005]). Regarding claim 17, Kessler, Hibbert, Thom, McCauley and Grigg disclose the method of claim 16. Grigg further discloses wherein the credentials comprise at least one of: biometric information; (Grigg, [0033] biometrics; [0013] biometric screening parameter) environmental information; a passcode; (Grigg, [0013] personal identification number (PIN)) a username; or (Grigg, [0033]-[0034] username) a password, (Grigg, [0033]-[0034] password) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Grigg with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein the credentials comprise at least one of: biometric information; environmental information; a passcode; a username; or a password. One would have been motivated to provide authentication using previously-validated authentication credentials, (Grigg, [0005]). Claims 19 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Kessler et al (“Kessler,” US 6,789,147), Hibbert et al (“Hibbert,” US 20170111368), Thom et al (“Thom,” US 20140137178), McCauley et al (“McCauley,” US 20210056545) in view of Skygebjerg et al (“Skygebjerg,” US 20150242602) and further in view of Priel et al (“Priel,” US 20100332851). Regarding claim 19, Kessler, Hibbert, Thom and McCauley disclose the method of claim 15. Thom further discloses wherein said denying the request, (Thom, [0041] when more access requests are made than there are permitted policy entries, the monotonic counter advances beyond every permitted value so no policy entry can be satisfied; [0031], [0039], [0041] & [0047] supplies denial when the independent request-count condition has exceeded its permitted limit) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Thom with the system/method of Kessler and Hibbert to wherein said denying the request. One would have been motivated to provide attack prevention for trusted platform modules (Thom, [0012]). Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein said denying the request comprises: determining a location in which the computing device is located; determining at least one of voltage characteristics or temperature characteristics associated with the computing device; determining that the location is one from a plurality of predetermined locations. However, in an analogous art, Skygeberg discloses wherein said denying the request comprises: (Skygeberg, [0044] describes wherein said denying the request) determining a location in which the computing device is located; (Skygebjerg, [0050] describe a second request for a location of the computing device) determining that the location is one from a plurality of predetermined locations; (Skygebjerg, [0034] describes determining that the location is one from a plurality of predetermined locations which are ones taken previously by GPS and compared to a current location) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Skygebjerg with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein said denying the request comprises: determining a location in which the computing device is located; determining at least one of voltage characteristics or temperature characteristics associated with the computing device; determining that the location is one from a plurality of predetermined locations. One would have been motivated to provide secure verification of the identity of a user (Skygebjerg, [0002)). Kessler, Hibbert, Thom and Skygebjerg fail to explicitly disclose determining at least one of voltage characteristics or temperature characteristics associated with the computing device; determining that at least one of the voltage characteristics are below a predetermined voltage threshold or temperature characteristics are below a predetermined temperature threshold; and responsive to determining that the number of first requests is greater than the predetermined threshold, and determining that at least one of the voltage characteristics are below a predetermined voltage threshold or the temperature characteristics are below a predetermined temperature threshold, denying the first request. However, in an analogous art, Priel discloses determining at least one of voltage characteristics or temperature characteristics associated with the computing device; (Priel, [0047] describes It is noted that method 100 can also include one or more of the following optional stages: (i) stage 140 of determining whether a level of a supply voltage is outside an allowed supply voltage level range; and (ii) stage 142 of determining if a monitored temperature is outside an allowed temperature range. If one (or both) of the answers to these questions is positive then method 100 can jump to stage 130 (if either one of these changes mandates an appliance of a cryptographic module protective measure) or to stage 120 (if either one of these changes is only a factor in the determination of whether to apply a cryptographic module protective measure). determining that at least one of the voltage characteristics are below a predetermined voltage threshold or temperature characteristics are below a predetermined temperature threshold; (Priel, [0047] describes It is noted that method 100 can also include one or more of the following optional stages: (i) stage 140 of determining whether a level of a supply voltage is outside an allowed supply voltage level range; and (ii) stage 142 of determining if a monitored temperature is outside an allowed temperature range. If one (or both) of the answers to these questions is positive then method 100 can jump to stage 130 (if either one of these changes mandates an appliance of a cryptographic module protective measure) or to stage 120 (if either one of these changes is only a factor in the determination of whether to apply a cryptographic module protective measure). and determining that at least one of the voltage characteristics are below a predetermined voltage threshold or the temperature characteristics are below a predetermined temperature threshold, (Priel, [0047] describes It is noted that method 100 can also include one or more of the following optional stages: (i) stage 140 of determining whether a level of a supply voltage is outside an allowed supply voltage level range; and (ii) stage 142 of determining if a monitored temperature is outside an allowed temperature range. If one (or both) of the answers to these questions is positive then method 100 can jump to stage 130 (if either one of these changes mandates an appliance of a cryptographic module protective measure) or to stage 120 (if either one of these changes is only a factor in the determination of whether to apply a cryptographic module protective measure; [0047] supplies protective action based on an abnormal supply voltage determination). Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Priel with the system/method of Kessler, Hibbert, Thom, McCauley and Skygebjerg to include determining at least one of voltage characteristics or temperature characteristics associated with the computing device; determining that at least one of the voltage characteristics are below a predetermined voltage threshold or temperature characteristics are below a predetermined temperature threshold; and responsive to determining that the number of first requests is greater than the predetermined threshold, and determining that at least one of the voltage characteristics are below a predetermined voltage threshold or the temperature characteristics are below a predetermined temperature threshold, denying the first request.. One would have been motivated to provide a method for protecting a cryptographic module and a device having cryptographic module protection capabilities (Priel, [0001]). Regarding claim 24, Kessler, Hibbert, Thom and McCauley disclose the method of claim 15. Thom further discloses wherein said denying the first request, (Thom, [0041] when more access requests are made than there are permitted policy entries, the monotonic counter advances beyond every permitted value so no policy entry can be satisfied; [0031], [0039], [0041] & [0047] supplies denial when the independent request-count condition has exceeded its permitted limit) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Thom with the system/method of Kessler and Hibbert to wherein said denying the first request. One would have been motivated to provide attack prevention for trusted platform modules (Thom, [0012]). Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein said denying the first request comprises: determining a voltage characteristic of the computing device is below a predetermined voltage threshold; and responsive to determining the voltage characteristic of the computing device is below the predetermined voltage threshold, denying the first request. However, in an analogous art, Priel discloses wherein said denying the first request comprises: determining a voltage characteristic of the computing device is below a predetermined voltage threshold; (Priel, [0039] discloses an absolute power supply-voltage monitor that determines the level of a supply voltage provided within the device; [0039] & [0047] describes determining whether the supply voltage is outside an allowed supply voltage range. The lower boundary of that predetermined range supplies a low-voltage threshold) and responsive to determining the voltage characteristic of the computing device is below the predetermined voltage threshold, denying the first request (Priel, [0039] describes an absolute supply-voltage monitor that determines the level of a supply voltage provided within the device; [0039], [0047] describes determining whether the supply voltage is outside an allowed supply-voltage range. The outer boundary of that predetermined range supplies a low-voltage threshold; [0047] supplies protective action based on an abnormal supply voltage determination) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Priel with the system/method of Kessler, Hibbert, Thom, Skygebjerg and McCauley to include determining at least one of voltage characteristics or temperature characteristics associated with the computing device; determining that at least one of the voltage characteristics are below a predetermined voltage threshold or temperature characteristics are below a predetermined temperature threshold; and responsive to determining that the number of first requests is greater than the predetermined threshold, and determining that at least one of the voltage characteristics are below a predetermined voltage threshold or the temperature characteristics are below a predetermined temperature threshold, denying the first request.. One would have been motivated to provide a method for protecting a cryptographic module and a device having cryptographic module protection capabilities (Priel, [0001]). Claims 21-23 are rejected under 35 U.S.C. 103 as being unpatentable over Kessler et al (“Kessler,” US 6,789,147), Hibbert et al (“Hibbert,” US 20170111368), Thom et al (“Thom,” US 20140137178) in view of McCauley et al (“McCauley,” US 20210056545) and further in view of Aal et al (“Aal,” EP3726394). Regarding claim 21, Kessler, Hibbert, Thom and McCauley disclose the method of claim 1. Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein said validating the first request comprises: determining a voltage characteristic of the computing device is below a predetermined voltage threshold; and responsive to determining the voltage characteristic of the computing device is below the predetermined voltage threshold, validating the first request. However, in an analogous art, Aal discloses wherein said validating the first request comprises: determining a voltage characteristic of the computing device is below a predetermined voltage threshold; (Aal, [0055], [0021], [0044], [0040] describes determining a voltage characteristic of the computer is below a voltage threshold) and responsive to determining the voltage characteristic of the computing device is below the predetermined voltage threshold, validating the first request, (Aal, [0055], [0021], [0044] describes determining a voltage characteristic of the computer is below a voltage threshold and [0040] authenticating [validating] the first request) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Aal with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein said validating the first request comprises: determining a voltage characteristic of the computing device is below a predetermined voltage threshold; and responsive to determining the voltage characteristic of the computing device is below the predetermined voltage threshold, validating the first request. One would have been motivated to reconfigurable systems-on-a-chip (Aal, [0001]). Regarding claim 22, Kessler, Hibbert, Thom and McCauley disclose the method of claim 1. Thom further discloses wherein said denying the first request, (Thom, [0041] when more access requests are made than there are permitted policy entries, the monotonic counter advances beyond every permitted value so no policy entry can be satisfied; [0031], [0039], [0041] & [0047] supplies denial when the independent request-count condition has exceeded its permitted limit) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Thom with the system/method of Kessler and Hibbert to wherein said denying the first request. One would have been motivated to provide attack prevention for trusted platform modules (Thom, [0012]). Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein said denying the first request comprises: determining a voltage characteristic of the computing device is above a predetermined voltage threshold; and responsive to determining the voltage characteristic of the computing device is above the predetermined voltage threshold, denying the first request. However, in an analogous art, Aal discloses wherein said denying the first request comprises: determining a voltage characteristic of the computing device is above a predetermined voltage threshold; (Aal, [0055], [0021], [0044], [0040] describes dismissing [denying] the first request comprises: determining a voltage characteristic of the computer is above the voltage threshold) and responsive to determining the voltage characteristic of the computing device is above the predetermined voltage threshold, denying the first request, (Aal, [0055], [0021], [0044], [0040] describes and responsive to determining the voltage characteristic of the computer is above the voltage threshold, dismissing [denying] the first request) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Aal with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein said denying the first request comprises: determining a voltage characteristic of the computing device is above a predetermined voltage threshold; and responsive to determining the voltage characteristic of the computing device is above the predetermined voltage threshold, denying the first request. One would have been motivated to reconfigurable systems-on-a-chip (Aal, [0001]). Regarding claim 23, Kessler, Hibbert, Thom and McCauley disclose the computing device of claim 8. Kessler, Hibbert, Thom and McCauley fail to explicitly disclose determines a voltage characteristic of the computing device is below a predetermined voltage threshold; and responsive to a determination that the voltage characteristic of the computing device is below the predetermined voltage threshold and the determination that the number of first requests is less than or equal to the predetermined threshold, validates the request. However, in an analogous art, Aal discloses determines a voltage characteristic of the computing device is below a predetermined voltage threshold; (Aal, [0011], [0055], [0021], [0044] describes wherein the coprocessor determines whether the voltage characteristic of the computer is below a voltage threshold) and responsive to a determination that the voltage characteristic of the computing device is below the predetermined voltage threshold and the determination that the number of first requests is less than or equal to the predetermined threshold (Aal, [0055], [0021], [0044], [0040] and the determination that the number of first requests is less than or equal to the predetermined threshold) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Aal with the system/method of Kessler, Hibbert, Thom and McCauley to include determines a voltage characteristic of the computing device is below a predetermined voltage threshold; and responsive to a determination that the voltage characteristic of the computing device is below the predetermined voltage threshold and the determination that the number of first requests has the predetermined relationship with the predetermined threshold, validates the request. One would have been motivated to reconfigurable systems-on-a-chip (Aal, [0001]). Claim 25 is rejected under 35 U.S.C. 103 as being unpatentable over Kessler et al (“Kessler,” US 6,789,147), Hibbert et al (“Hibbert,” US 20170111368), Thom et al (“Thom,” US 20140137178), McCauley et al (“McCauley,” US 20210056545) in view of Skygebjerg et al (“Skygebjerg,” US 20150242602) and further in view of Aal et al (“Aal,” EP3726394). Regarding claim 25, Kessler, Hibbert, Thom and McCauley disclose the method of claim 15. Thom further discloses wherein said denying the first request, (Thom, [0041] when more access requests are made than there are permitted policy entries, the monotonic counter advances beyond every permitted value so no policy entry can be satisfied; [0031], [0039], [0041] & [0047] supplies denial when the independent request-count condition has exceeded its permitted limit) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Thom with the system/method of Kessler and Hibbert to wherein said denying the first request. One would have been motivated to provide attack prevention for trusted platform modules (Thom, [0012]). Kessler, Hibbert, Thom and McCauley fail to explicitly disclose wherein said denying the first request comprises: determining a voltage characteristic of the computing device is above a predetermined voltage threshold; and responsive to determining the voltage characteristic of the computing device is above the predetermined voltage threshold, denying the first request. However, in an analogous art, Aal discloses wherein said denying the first request comprises: determining a voltage characteristic of the computing device is above a predetermined voltage threshold; (Aal, [0055], [0021], [0044], [0040] describes wherein said dismissing [denying] the first request comprises determining the voltage characteristic of the computer is above a voltage threshold) and responsive to determining the voltage characteristic of the computing device is above the predetermined voltage threshold, denying the first request, (Aal, [0055], [0021], [0044], and [0040] describes and responsive to determining the voltage characteristic of the computer is above the voltage threshold, dismissing [denying] the first request) Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Aal with the system/method of Kessler, Hibbert, Thom and McCauley to include wherein said denying the first request comprises: determining a voltage characteristic of the computing device is above a predetermined voltage threshold; and responsive to determining the voltage characteristic of the computing device is above the predetermined voltage threshold, denying the first request. One would have been motivated to reconfigurable systems-on-a-chip (Aal, [0001]). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES J WILCOX whose telephone number is (571)270-3774. The examiner can normally be reached M-F: 8 A.M. to 5 P.M.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu T. Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JAMES J WILCOX/Examiner, Art Unit 2439 /LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Show 28 earlier events
Jul 30, 2025
Applicant Interview (Telephonic)
Jul 31, 2025
Examiner Interview Summary
Aug 15, 2025
Response Filed
Dec 10, 2025
Final Rejection mailed — §103
Feb 10, 2026
Response after Non-Final Action
Apr 10, 2026
Request for Continued Examination
Apr 12, 2026
Response after Non-Final Action
Jul 29, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706953
EMBEDDED AND DISTRIBUTABLE POLICY ENFORCEMENT
4y 3m to grant Granted Aug 11, 2026
Patent 12688305
RISK ANALYSIS OF A DISTRIBUTED TEST OBJECT
1y 10m to grant Granted Jul 21, 2026
Patent 12634284
Systems and methods for pause and resume functionality for shared Privileged Remote Access (PRA) sessions
2y 7m to grant Granted May 19, 2026
Patent 12621331
DETECTION OF SECURITY RISKS BASED ON SECRETLESS CONNECTION DATA
4y 10m to grant Granted May 05, 2026
Patent 12609934
Service Mesh-Based Control of Access to a Storage Application
2y 11m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

7-8
Expected OA Rounds
70%
Grant Probability
99%
With Interview (+61.3%)
3y 2m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 620 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month