Prosecution Insights
Last updated: August 18, 2026
Application No. 18/057,442

SYSTEMS AND METHODS FOR COARSE WAVELENGTH DIVISION MULTIPLEXING SECURITY

Final Rejection §103
Filed
Nov 21, 2022
Priority
Dec 31, 2021 — provisional 63/266,304
Examiner
DILUZIO, NICHOLAS JOSEPH
Art Unit
2498
Tech Center
2400 — Computer Networks
Assignee
A-Plus Community Solutions Inc.
OA Round
4 (Final)
33%
Grant Probability
At Risk
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants only 33% of cases
33%
Career Allowance Rate
5 granted / 15 resolved
-24.7% vs TC avg
Strong +100% interview lift
Without
With
+100.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
23 currently pending
Career history
47
Total Applications
across all art units

Statute-Specific Performance

§101
9.0%
-31.0% vs TC avg
§103
65.8%
+25.8% vs TC avg
§102
7.7%
-32.3% vs TC avg
§112
17.6%
-22.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 15 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 07/16/2025 has been entered. Response to Amendment Examiner has fully considered Applicant’s amendments to the Claims in the arguments filed on 07/16/2025. Claims 2, 3, 8, 17, and 18 have been cancelled. Claim 22-25 are newly added. Claims 1, 4-7, 9-16, and 19-25 are pending. Response to Arguments Applicant’s arguments filed 07/16/2025, with respect to the rejections of independent claims 1, 16, and 20 and their corresponding dependent claims under 35 USC 103 have been fully considered and are persuasive. Therefore, the rejections have been withdrawn. However, upon further consideration, new grounds of rejection are made in view of previously applied references from Costa and Au, in addition to a newly applied reference from Muma et al. (US 20160301669 A1), hereinafter Muma. Specifically, Muma provides teachings regarding limitations previously rejected in view of Marquardt and Kim, in addition to the amended limitation “wherein the message received from the active device is encrypted; decrypting, by the control system, the message received from the active device, using an encryption key associated with the active device, to identify the … the candidate authentication key”. Muma combines with Costa to render obvious the identification of the candidate unique identifier and the candidate authentication key as a result of decrypting the message. Further, upon review, Examiner respectfully submits that Costa is sufficient to render obvious the full limitation “and in an instance in which the active device is authenticated, transmit a message to the active device authorizing the active device to communicate” based on teachings provided in at least paragraphs [0045], [0051], and [0212], exhibiting a capability by the control system to notify an active device of the result of an authentication procedure, wherein a successful authentication procedure results in permission for the active device to communicate. It is additionally submitted that the combination of Costa and Muma is sufficient to teach the combined limitation “decrypting … the message received from the active device, using an encryption key associated with the active device, to identify the candidate unique identifier and the candidate authentication key”. Specifically, Costa teaches the (authentication) message including the candidate unique identifier and candidate authentication key, and Muma teaches a capability to encrypt/decrypt authentication messages between devices in a PON. The encryption of an authentication message taught by Costa is, therefore, rendered obvious by the additional teaching provided by Muma. Muma’s particular means of encryption/decryption of an authentication message would provide enhanced security in the transmission of such a message, and thus, enhanced security in the authentication process overall. It is further understood that decryption of an encrypted payload including a candidate unique identifier and candidate authentication key would result in the identification of those contents. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 4, 9, 14, 16, 19, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Costa et al. (US 20110214160 A1), hereinafter Costa, in view of Muma et al. (US 20160301669 A1), hereinafter Muma, and Au et al. (US 20200319324 A1), hereinafter Au. Regarding Claim 1: Costa teaches A method … the method comprising: transmitting, by a control system, an authentication request to an active device (Costa – Paragraph [0175]: the OLT 100 transmits the first authentication message AM1 to the optical termination device OTD2 by means of the ODN 10) in a fiber optic network (Costa – Paragraph [0007]: A PON is a point-to-multipoint (P2MP) optical network with no active elements in the signals' path from source to destination. The only elements used in a PON are passive optical components, such as optical fiber, splices and splitters; and Paragraph [0008]: More particularly, a PON typically comprises an optical line termination (briefly termed OLT) and an optical distribution network (briefly termed ODN). The ODN comprises a plurality of optical links (typically comprising silica-based single-mode optical fibers) and optical splitters arranged so as to form a point-multipoint structure radiating from the OLT); receiving, by the control system, a message from the active device (Costa – Paragraph [0201]: the optical termination device OTD2 transmits the second authentication message AM2, possibly in the form of one or more Password messages, to the OLT 100), the message comprising a candidate unique identifier and a candidate authentication key (Costa – Paragraph [0196]: Besides, preferably, the remaining nine octets of the Password message are used for transporting the authentication code AC* calculated by the optical termination device OTD2 during step 210, the second number C2 generated during step 208 and the registration identifier Reg-ID2 retrieved by the optical termination device OTD2 at step 207; and Paragraph [0197]: the second authentication message AM2 corresponds to a sequence of Password messages, each containing a fragment of the authentication code AC* or of the second number C2, or of the registration identifier Reg-ID2; Examiner’s Comment: authentication code AC* is interpreted to represent a candidate authentication key and registration identifier Reg-ID2 is interpreted to represent a candidate unique identifier); and the candidate unique identifier and the candidate authentication key (Costa – Paragraph [0196]: Besides, preferably, the remaining nine octets of the Password message are used for transporting the authentication code AC* calculated by the optical termination device OTD2 during step 210, the second number C2 generated during step 208 and the registration identifier Reg-ID2 retrieved by the optical termination device OTD2 at step 207; and Paragraph [0197]: the second authentication message AM2 corresponds to a sequence of Password messages, each containing a fragment of the authentication code AC* or of the second number C2, or of the registration identifier Reg-ID2; Examiner’s Comment: authentication code AC* is interpreted to represent a candidate authentication key and registration identifier Reg-ID2 is interpreted to represent a candidate unique identifier); performing, by the control system, one or more authentication operations based on the candidate unique identifier and the candidate authentication key (Costa – Paragraph [0208]: the OLT 100 calculates the further authentication code AC by applying the authentication code generation algorithm AAi to the first number C1, the second number C2, the information OLT2_A_S, the further information ONT2_A_S, the identifier ONT-ID2 and the registration identifier Reg-ID2, by using the secret code SC2 as key for the authentication code generation algorithm AAi; and Paragraph [0209]: the OLT 100 compares the authentication code AC* received from the optical termination device OTD2 with the further authentication code AC calculated during step 214; and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2); in an instance in which the active device fails to be authenticated (Costa – Paragraph [0212]: Otherwise, if the authentication code AC* is not equal to the further authentication code AC, the OLT 100 preferably interrupts the authentication procedure), transmitting, by the control system, [an encryption key change] message to the active device (Costa – Paragraph [0212]: during step 217 the OLT 100 may send to the optical termination device OTD2 a notification informing the user of the optical termination device OTD2 that the authentication procedure has not been successfully completed); and in an instance in which the active device is authenticated, transmitting, by the control system, a message to the active device authorizing the device to communicate (Costa – Paragraph [0051]: permitting the transmission of the optical termination device only after the strong authentication procedure is successfully completed; and Paragraph [0045]: after the mutual authentication has been successfully completed, the OLT and the optical termination device preferably exchange data which, in combination with the secret code, allow both the OLT and the optical termination device to generate independently the encryption key; and Paragraph [0212]: during step 217 the OLT 100 may send to the optical termination device OTD2 a notification informing the user of the optical termination device OTD2 that the authentication procedure has not been successfully completed). Costa does not expressly teach a method for wavelength division multiplexing (WDM) security; and wherein the message received from the active device is encrypted; decrypting, by the control system, the message received from the active device, using an encryption key associated with the active device, to identify the candidate unique identifier and the candidate authentication key; and an encryption key change message to change the encryption key. However, Muma teaches a method for wavelength division multiplexing (WDM) security (Muma – Paragraph [0002]: The International Telecommunication Union Standardization Sector (ITU-T) defines an Optical Transport Network (OTN) as a set of Optical Network Elements (ONE) connected by fiber optic links, able to provide functionality of transport, multiplexing, routing, management, supervision and survivability of optical channels carrying client signals. The OTN was designed to provide support for optical networking using wavelength division multiplexing (WDM) … Paragraph [0050]: … Accordingly, embodiments of the present disclosure may improve the security of the encrypted messages.); and wherein the message received from the active device is encrypted (Muma – Paragraph [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification. Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic); decrypting, by the control system, the message received from the active device, using an encryption key associated with the active device (Muma – Paragraph [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification. Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic; and Paragraph [0099]: If the tags match, the system 100 can decrypt and accept the payload), to identify the candidate unique identifier and the candidate authentication key (Muma – [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic; and Paragraph [0099]: If the tags match, the system 100 can decrypt and accept the payload); and an encryption key change message to change the encryption key (Muma – Paragraph [0071]: As discussed above, a first technique for providing a more robust encryption includes periodically switching the encryption key. In operation of the system 100, the transmitter sends the two-bit KTI value 52 to the receiver once each multiframe. The transmitter uses the KTI value 52 to signal to the receiver that the transmitter will switch its encryption key and that the receiver should also switch its encryption key. If both the transmitter and the receiver synchronize each respective key switch, the receiver will be able to properly decrypt the encrypted OTN payload; and Paragraph [0079]: In this example, the system 100 is configured with a maximum key lifetime 202 of 14 multiframes. At period 204, the Rx decryption controller 112 determines that the maximum has been exceeded and that the receiver has not switched to the next key. This condition could be caused, for example, by a lack of the next key in the key table of the receiver. Therefore, at period 204, the Rx decryption controller inputs a failure pattern 206 into the payload of the decrypted OTN frame. The failure pattern will alert higher-layer applications of the key error. Consequently, higher-layer applications may load the appropriate next key into the key table of the receiver via the SPI 120. Once the Rx decryption controller 112 has the next key, it will reset the Rx multiframe counter 118 and decrypt the encrypted OTN payload; and Paragraph [0115]: In embodiments according to the present disclosure, system 100 may further comprise a performance monitor (PMON) for counting the number of frames that failed decryption. Such failures may be the result of authentication issues, key out-of-sync, frame slips or frame jumps).. It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, further incorporating Muma to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Muma’s teaching of a WDM security apparatus to encrypt communications between devices in a WDM optical network, and if the communications fail to be authenticated, to send an encryption key change message from the receiving device to the sending device into Costa’s method for authenticating devices using updatable keys. This additional functionality would enhance Costa’s method by providing additional security and means for device/communication verification, in addition to providing a secure corrective measure in response to any failure to authenticate. The combination of Costa and Muma does not expressly teach wherein the candidate unique identifier includes a combination of at least a portion of each of a media access control address of the active device, an active device serial number, a location identifier, and a configurable value. However, Au teaches wherein the candidate unique identifier includes a combination of at least a portion of each of a media access control address of the active device, an active device serial number, a location identifier, and a configurable value (Au – Paragraph [0109]: Each Type 1 device may be associated with a respective identifier (e.g. ID). Each Type 2 device may also be associated with a respective identify (ID) … The ID may be used for registration, initialization, communication, identification, verification, detection, recognition, authentication, access control, … , by the Type 1 device and/or the Type 2 device; and Paragraph [0210]: wherein the ID comprises at least one of: a name, a number, an alphanumeric ID, a string of text, numbers and symbols, …, a MAC address, …, a serial number, …, a physical address, a physical location, …, and another ID). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa and Muma, further incorporating Au to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Au’s teaching of a device identifier that includes at least a MAC address, serial number, location, and other configurable value into Costa and Muma’s combined method for authenticating devices in WDM fiber optic networks using updatable keys. This provides additional security by incorporating a highly specific and descriptive identifier for verifying devices in the network. Regarding Claim 4: Costa, Muma, and Au combine to teach the method of claim 1. Costa further teaches further comprising querying, by the control system, a stored set of unique keys for an authentication key corresponding to the candidate unique identifier associated with the active device (Costa – Paragraph [0153]: the registration identifier is transmitted from the optical termination device to the OLT 100 during the authentication procedure that will be described in detail hereinafter, and then is used by the OLT for recognizing the user (or the ONU), and retrieve the associated secret code; and Paragraph [0154]: in the association table AT of FIG. 1, only a registration identifier Reg-ID2 of the optical termination device OTD2 and its associated secret code SC2 are depicted; and Figure 1: illustration of a network including an OLT with an association table containing a unique identifier (Reg-ID2) corresponding to an authentication key (SC2 of AC*/AC)). The motivation to combine the arts is the same as that of Claim 1. Regarding Claim 9: Costa, Muma, and Au combine to teach the method of claim 1. Muma further teaches wherein the encryption key change message comprises instructions to cause the active device to terminate use of one or more of an existing encryption key or existing authentication key (Muma – Paragraph [0071]: As discussed above, a first technique for providing a more robust encryption includes periodically switching the encryption key. In operation of the system 100, the transmitter sends the two-bit KTI value 52 to the receiver once each multiframe. The transmitter uses the KTI value 52 to signal to the receiver that the transmitter will switch its encryption key and that the receiver should also switch its encryption key. If both the transmitter and the receiver synchronize each respective key switch, the receiver will be able to properly decrypt the encrypted OTN payload). The motivation to combine the arts is the same as that of Claim 1. Regarding Claim 14: Costa, Muma, and Au combine to teach the method of claim 1. Costa further teaches wherein the message is received via the fiber optic network (Costa – Paragraph [0001]: the present invention relates to a method for increasing security in a passive optical network; and Figure 1: illustration of the passive optical network through which the devices communicate messages). The motivation to combine the arts is the same as that of Claim 1. Regarding Claim 16: Costa teaches transmit an authentication request to an active device (Costa – Paragraph [0175]: the OLT 100 transmits the first authentication message AM1 to the optical termination device OTD2 by means of the ODN 10) in a fiber optic network (Costa – Paragraph [0007]: A PON is a point-to-multipoint (P2MP) optical network with no active elements in the signals' path from source to destination. The only elements used in a PON are passive optical components, such as optical fiber, splices and splitters; and Paragraph [0008]: More particularly, a PON typically comprises an optical line termination (briefly termed OLT) and an optical distribution network (briefly termed ODN). The ODN comprises a plurality of optical links (typically comprising silica-based single-mode optical fibers) and optical splitters arranged so as to form a point-multipoint structure radiating from the OLT); receive a message from the active device (Costa – Paragraph [0201]: the optical termination device OTD2 transmits the second authentication message AM2, possibly in the form of one or more Password messages, to the OLT 100), the message comprising a candidate unique identifier and a candidate authentication key (Costa – Paragraph [0196]: the message comprising a candidate unique identifier and a candidate authentication key; and Paragraph [0197]: the second authentication message AM2 corresponds to a sequence of Password messages, each containing a fragment of the authentication code AC* or of the second number C2, or of the registration identifier Reg-ID2; Examiner’s Comment: authentication code AC* is interpreted to represent a candidate authentication key and registration identifier Reg-ID2 is interpreted to represent a candidate unique identifier); and the candidate unique identifier and the candidate authentication key (Costa – Paragraph [0196]: Besides, preferably, the remaining nine octets of the Password message are used for transporting the authentication code AC* calculated by the optical termination device OTD2 during step 210, the second number C2 generated during step 208 and the registration identifier Reg-ID2 retrieved by the optical termination device OTD2 at step 207; and Paragraph [0197]: the second authentication message AM2 corresponds to a sequence of Password messages, each containing a fragment of the authentication code AC* or of the second number C2, or of the registration identifier Reg-ID2; Examiner’s Comment: authentication code AC* is interpreted to represent a candidate authentication key and registration identifier Reg-ID2 is interpreted to represent a candidate unique identifier); perform one or more authentication operations based on the candidate unique identifier and the candidate authentication key (Costa – Paragraph [0208]: the OLT 100 calculates the further authentication code AC by applying the authentication code generation algorithm AAi to the first number C1, the second number C2, the information OLT2_A_S, the further information ONT2_A_S, the identifier ONT-ID2 and the registration identifier Reg-ID2, by using the secret code SC2 as key for the authentication code generation algorithm AAi; and Paragraph [0209]: the OLT 100 compares the authentication code AC* received from the optical termination device OTD2 with the further authentication code AC calculated during step 214; and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2); in an instance in which the active device fails to be authenticated (Costa – Paragraph [0212]: Otherwise, if the authentication code AC* is not equal to the further authentication code AC, the OLT 100 preferably interrupts the authentication procedure), transmit a[n encryption key change] message to the active device (Costa – Paragraph [0212]: during step 217 the OLT 100 may send to the optical termination device OTD2 a notification informing the user of the optical termination device OTD2 that the authentication procedure has not been successfully completed); and in an instance in which the active device is authenticated, transmit a message to the active device authorizing the device to communicate (Costa – Paragraph [0051]: permitting the transmission of the optical termination device only after the strong authentication procedure is successfully completed; and Paragraph [0045]: after the mutual authentication has been successfully completed, the OLT and the optical termination device preferably exchange data which, in combination with the secret code, allow both the OLT and the optical termination device to generate independently the encryption key; and Paragraph [0212]: during step 217 the OLT 100 may send to the optical termination device OTD2 a notification informing the user of the optical termination device OTD2 that the authentication procedure has not been successfully completed). Costa does not expressly teach an apparatus for wavelength division multiplexing (WDM) security, the apparatus comprising a processor and a memory storing software instructions that, when executed by the processor, cause the apparatus to; and wherein the message received from the active device is encrypted; decrypting, by the control system, the message received from the active device, using an encryption key associated with the active device, to identify the candidate unique identifier and the candidate authentication key; and an encryption key change message … to change the encryption key. However, Muma teaches an apparatus for wavelength division multiplexing (WDM) security (Muma – Paragraph [00 2]: The International Telecommunication Union Standardization Sector (ITU-T) defines an Optical Transport Network (OTN) as a set of Optical Network Elements (ONE) connected by fiber optic links, able to provide functionality of transport, multiplexing, routing, management, supervision and survivability of optical channels carrying client signals. The OTN was designed to provide support for optical networking using wavelength division multiplexing (WDM)… Paragraph [0050]: … Accordingly, embodiments of the present disclosure may improve the security of the encrypted messages.), the apparatus comprising a processor and a memory storing software instructions that, when executed by the processor, cause the apparatus to (Muma – Paragraph [0134]: Embodiments of the disclosure can be represented as a computer program product stored in a machine-readable medium (also referred to as a computer-readable medium, a processor-readable medium, or a computer usable medium having a computer-readable program code embodied therein). The machine-readable medium can be any suitable tangible, non-transitory medium, including magnetic, optical, or electrical storage medium including a diskette, compact disk read only memory (CD-ROM), memory device (volatile or non-volatile), or similar storage mechanism. The machine-readable medium can contain various sets of instructions, code sequences, configuration information, or other data, which, when executed, cause a processor to perform steps in a method according to an embodiment of the disclosure); wherein the message received from the active device is encrypted (Muma – Paragraph [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification. Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic); decrypting, by the control system, the message received from the active device, using an encryption key associated with the active device (Muma – Paragraph [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification. Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic; and Paragraph [0099]: If the tags match, the system 100 can decrypt and accept the payload), to identify the candidate unique identifier and the candidate authentication key (Muma – Paragraph [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification. Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic; and Paragraph [0099]: If the tags match, the system 100 can decrypt and accept the payload); and an encryption key change message … to change the encryption key (Muma – Paragraph [0071]: As discussed above, a first technique for providing a more robust encryption includes periodically switching the encryption key. In operation of the system 100, the transmitter sends the two-bit KTI value 52 to the receiver once each multiframe. The transmitter uses the KTI value 52 to signal to the receiver that the transmitter will switch its encryption key and that the receiver should also switch its encryption key. If both the transmitter and the receiver synchronize each respective key switch, the receiver will be able to properly decrypt the encrypted OTN payload; and Paragraph [0079]: In this example, the system 100 is configured with a maximum key lifetime 202 of 14 multiframes. At period 204, the Rx decryption controller 112 determines that the maximum has been exceeded and that the receiver has not switched to the next key. This condition could be caused, for example, by a lack of the next key in the key table of the receiver. Therefore, at period 204, the Rx decryption controller inputs a failure pattern 206 into the payload of the decrypted OTN frame. The failure pattern will alert higher-layer applications of the key error. Consequently, higher-layer applications may load the appropriate next key into the key table of the receiver via the SPI 120. Once the Rx decryption controller 112 has the next key, it will reset the Rx multiframe counter 118 and decrypt the encrypted OTN payload; and Paragraph [0115]: In embodiments according to the present disclosure, system 100 may further comprise a performance monitor (PMON) for counting the number of frames that failed decryption. Such failures may be the result of authentication issues, key out-of-sync, frame slips or frame jumps). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, further incorporating Muma to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Muma’s teaching of a WDM security apparatus to encrypt communications between devices in a WDM optical network, and if the communications fail to be authenticated, to send an encryption key change message from the receiving device to the sending device into Costa’s method for authenticating devices using updatable keys. This additional functionality would enhance Costa’s method by providing additional security and means for device/communication verification, in addition to providing a secure corrective measure in response to any failure to authenticate. However, Au teaches wherein the candidate unique identifier includes a combination of at least a portion of each of a media access control address of the active device, an active device serial number, a location identifier, and a configurable value (Au – Paragraph [0109]: Each Type 1 device may be associated with a respective identifier (e.g. ID). Each Type 2 device may also be associated with a respective identify (ID) … The ID may be used for registration, initialization, communication, identification, verification, detection, recognition, authentication, access control, … , by the Type 1 device and/or the Type 2 device; and Paragraph [0210]: wherein the ID comprises at least one of: a name, a number, an alphanumeric ID, a string of text, numbers and symbols, …, a MAC address, …, a serial number, …, a physical address, a physical location, …, and another ID). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa and Muma, further incorporating Au to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Au’s teaching of a device identifier that includes at least a MAC address, serial number, location, and other configurable value into Costa and Muma’s combined method for authenticating devices in WDM fiber optic networks using updatable keys. This addition would further enhance the security of a system by incorporating a highly specific and descriptive identifier for verifying devices in the network. Regarding Claim 19: Costa, Muma, and Au combine to teach the apparatus of Claim 16. Muma further teaches the processor and the memory storing software instructions that, when executed by the processor, further cause the apparatus to (Muma – Paragraph [0134]: Embodiments of the disclosure can be represented as a computer program product stored in a machine-readable medium (also referred to as a computer-readable medium, a processor-readable medium, or a computer usable medium having a computer-readable program code embodied therein). The machine-readable medium can be any suitable tangible, non-transitory medium, including magnetic, optical, or electrical storage medium including a diskette, compact disk read only memory (CD-ROM), memory device (volatile or non-volatile), or similar storage mechanism. The machine-readable medium can contain various sets of instructions, code sequences, configuration information, or other data, which, when executed, cause a processor to perform steps in a method according to an embodiment of the disclosure). Costa further teaches query a stored set of unique keys for an authentication key corresponding to a unique identifier associated with the active device (Costa – Paragraph [0153]: the registration identifier is transmitted from the optical termination device to the OLT 100 during the authentication procedure that will be described in detail hereinafter, and then is used by the OLT for recognizing the user (or the ONU), and retrieve the associated secret code; and Paragraph [0154]: in the association table AT of FIG. 1, only a registration identifier Reg-ID2 of the optical termination device OTD2 and its associated secret code SC2 are depicted; and Figure 1: illustration of a network including an OLT with an association table containing a unique identifier (Reg-ID2) corresponding to an authentication key (SC2 of AC*/AC)). The motivation to combine the arts is the same as that of Claim 16. Regarding Claim 20: Costa teaches transmit an authentication request to an active device (Costa – Paragraph [0175]: the OLT 100 transmits the first authentication message AM1 to the optical termination device OTD2 by means of the ODN 10) in a fiber optic network (Costa – Paragraph [0007]: A PON is a point-to-multipoint (P2MP) optical network with no active elements in the signals' path from source to destination. The only elements used in a PON are passive optical components, such as optical fiber, splices and splitters; and Paragraph [0008]: More particularly, a PON typically comprises an optical line termination (briefly termed OLT) and an optical distribution network (briefly termed ODN). The ODN comprises a plurality of optical links (typically comprising silica-based single-mode optical fibers) and optical splitters arranged so as to form a point-multipoint structure radiating from the OLT); receive a message from the active device (Costa – Paragraph [0201]: the optical termination device OTD2 transmits the second authentication message AM2, possibly in the form of one or more Password messages, to the OLT 100), the message comprising a candidate unique identifier and a candidate authentication key (Costa – Paragraph [0196]: the message comprising a candidate unique identifier and a candidate authentication key; and Paragraph [0197]: the second authentication message AM2 corresponds to a sequence of Password messages, each containing a fragment of the authentication code AC* or of the second number C2, or of the registration identifier Reg-ID2; Examiner’s Comment: authentication code AC* is interpreted to represent a candidate authentication key and registration identifier Reg-ID2 is interpreted to represent a candidate unique identifier); and the candidate unique identifier and the candidate authentication key (Costa – Paragraph [0196]: Besides, preferably, the remaining nine octets of the Password message are used for transporting the authentication code AC* calculated by the optical termination device OTD2 during step 210, the second number C2 generated during step 208 and the registration identifier Reg-ID2 retrieved by the optical termination device OTD2 at step 207; and Paragraph [0197]: the second authentication message AM2 corresponds to a sequence of Password messages, each containing a fragment of the authentication code AC* or of the second number C2, or of the registration identifier Reg-ID2; Examiner’s Comment: authentication code AC* is interpreted to represent a candidate authentication key and registration identifier Reg-ID2 is interpreted to represent a candidate unique identifier); perform one or more authentication operations based on the candidate unique identifier and the candidate authentication key (Costa – Paragraph [0208]: the OLT 100 calculates the further authentication code AC by applying the authentication code generation algorithm AAi to the first number C1, the second number C2, the information OLT2_A_S, the further information ONT2_A_S, the identifier ONT-ID2 and the registration identifier Reg-ID2, by using the secret code SC2 as key for the authentication code generation algorithm AAi; and Paragraph [0209]: the OLT 100 compares the authentication code AC* received from the optical termination device OTD2 with the further authentication code AC calculated during step 214; and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2); in an instance in which the active device fails to be authenticated (Costa – Paragraph [0212]: Otherwise, if the authentication code AC* is not equal to the further authentication code AC, the OLT 100 preferably interrupts the authentication procedure), transmit a[n encryption key change] message to the active device (Costa – Paragraph [0212]: during step 217 the OLT 100 may send to the optical termination device OTD2 a notification informing the user of the optical termination device OTD2 that the authentication procedure has not been successfully completed); and in an instance in which the active device is authenticated, transmit a message to the active device authorizing the device to communicate (Costa – Paragraph [0051]: permitting the transmission of the optical termination device only after the strong authentication procedure is successfully completed; and Paragraph [0045]: after the mutual authentication has been successfully completed, the OLT and the optical termination device preferably exchange data which, in combination with the secret code, allow both the OLT and the optical termination device to generate independently the encryption key; and Paragraph [0212]: during step 217 the OLT 100 may send to the optical termination device OTD2 a notification informing the user of the optical termination device OTD2 that the authentication procedure has not been successfully completed). Costa does not expressly teach A computer program product for wavelength division multiplexing (WDM) security, the computer program product comprising at least one non-transitory computer-readable storage medium storing software instructions that, when executed by an apparatus, cause the apparatus to; and wherein the message received from the active device is encrypted; decrypting, by the control system, the message received from the active device, using an encryption key associated with the active device, to identify the candidate unique identifier and the candidate authentication key; and an encryption key change message … to change the encryption key. However, Muma teaches A computer program product for wavelength division multiplexing (WDM) security (Muma – Paragraph [0002]: The International Telecommunication Union Standardization Sector (ITU-T) defines an Optical Transport Network (OTN) as a set of Optical Network Elements (ONE) connected by fiber optic links, able to provide functionality of transport, multiplexing, routing, management, supervision and survivability of optical channels carrying client signals. The OTN was designed to provide support for optical networking using wavelength division multiplexing (WDM)… Paragraph [0050]: … Accordingly, embodiments of the present disclosure may improve the security of the encrypted messages.), the computer program product comprising at least one non-transitory computer-readable storage medium storing software instructions that, when executed by an apparatus, cause the apparatus to (Muma – Paragraph [0134]: Embodiments of the disclosure can be represented as a computer program product stored in a machine-readable medium (also referred to as a computer-readable medium, a processor-readable medium, or a computer usable medium having a computer-readable program code embodied therein). The machine-readable medium can be any suitable tangible, non-transitory medium, including magnetic, optical, or electrical storage medium including a diskette, compact disk read only memory (CD-ROM), memory device (volatile or non-volatile), or similar storage mechanism. The machine-readable medium can contain various sets of instructions, code sequences, configuration information, or other data, which, when executed, cause a processor to perform steps in a method according to an embodiment of the disclosure); wherein the message received from the active device is encrypted (Muma – Paragraph [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification. Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic); decrypting, by the control system, the message received from the active device, using an encryption key associated with the active device (Muma – Paragraph [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification. Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic; and Paragraph [0099]: If the tags match, the system 100 can decrypt and accept the payload), to identify the candidate unique identifier and the candidate authentication key (Muma – Paragraph [0093]: In yet a further embodiment, the initialization vector additionally includes a unique transmitter identification. In order to correctly decrypt an OTN payload encrypted by a particular transmitter, the receiver must be configured to know the unique transmitter identification. Paragraph [0094]: In further embodiments of the present disclosure, the system 100 provides for authentication to ensure that received OTN frames can be authenticated to a sender. Specifically, the transmitter uses the unique initialization vector, the encryption key and the OTN payload to generate a 64-bit authentication tag (e.g., a message authentication code, or MAC), which is then transmitted in-band in reserved byte area fields 38 and 40 of the OTN header as shown in FIG. 1. The receiver uses the calculated initialization vector, the decryption key, the encrypted payload, and the authentication tag to determine whether the encrypted OTN payload is authentic; and Paragraph [0099]: If the tags match, the system 100 can decrypt and accept the payload); and an encryption key change message … to change the encryption key (Muma – Paragraph [0071]: As discussed above, a first technique for providing a more robust encryption includes periodically switching the encryption key. In operation of the system 100, the transmitter sends the two-bit KTI value 52 to the receiver once each multiframe. The transmitter uses the KTI value 52 to signal to the receiver that the transmitter will switch its encryption key and that the receiver should also switch its encryption key. If both the transmitter and the receiver synchronize each respective key switch, the receiver will be able to properly decrypt the encrypted OTN payload; and Paragraph [0079]: In this example, the system 100 is configured with a maximum key lifetime 202 of 14 multiframes. At period 204, the Rx decryption controller 112 determines that the maximum has been exceeded and that the receiver has not switched to the next key. This condition could be caused, for example, by a lack of the next key in the key table of the receiver. Therefore, at period 204, the Rx decryption controller inputs a failure pattern 206 into the payload of the decrypted OTN frame. The failure pattern will alert higher-layer applications of the key error. Consequently, higher-layer applications may load the appropriate next key into the key table of the receiver via the SPI 120. Once the Rx decryption controller 112 has the next key, it will reset the Rx multiframe counter 118 and decrypt the encrypted OTN payload; and Paragraph [0115]: In embodiments according to the present disclosure, system 100 may further comprise a performance monitor (PMON) for counting the number of frames that failed decryption. Such failures may be the result of authentication issues, key out-of-sync, frame slips or frame jumps). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, further incorporating Muma to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Muma’s teaching of a WDM security apparatus to encrypt communications between devices in a WDM optical network, and if the communications fail to be authenticated, to send an encryption key change message from the receiving device to the sending device into Costa’s method for authenticating devices using updatable keys. This additional functionality would enhance Costa’s method by providing additional security and means for device/communication verification, in addition to providing a secure corrective measure in response to any failure to authenticate. The combination of Costa and Muma does not expressly teach wherein the candidate unique identifier includes a combination of at least a portion of each of a media access control address of the active device, an active device serial number, a location identifier, and a configurable value. However, Au teaches wherein the candidate unique identifier includes a combination of at least a portion of each of a media access control address of the active device, an active device serial number, a location identifier, and a configurable value (Au – Paragraph [0109]: Each Type 1 device may be associated with a respective identifier (e.g. ID). Each Type 2 device may also be associated with a respective identify (ID) … The ID may be used for registration, initialization, communication, identification, verification, detection, recognition, authentication, access control, … , by the Type 1 device and/or the Type 2 device; and Paragraph [0210]: wherein the ID comprises at least one of: a name, a number, an alphanumeric ID, a string of text, numbers and symbols, …, a MAC address, …, a serial number, …, a physical address, a physical location, …, and another ID). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa and Muma, further incorporating Au to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Au’s teaching of a device identifier that includes at least a MAC address, serial number, location, and other configurable value into Costa and Muma’s combined method for authenticating devices in WDM fiber optic networks using updatable keys. This addition would further enhance the security of a system by incorporating a highly specific and descriptive identifier for verifying devices in the network. Claim(s) 5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Costa, in view of Muma, Au, and Mendonsa et al. (US 20210273786 A1), hereinafter Mendonsa. Regarding Claim 5: Costa, Muma, and Au combine to teach the method of claim 1. The combination of Costa, Muma, and Au does not expressly teach further comprising querying, by the control system, a stored set of unique keys for an encryption key corresponding to a unique identifier associated with the active device. However, Mendonsa teaches further comprising querying, by the control system, a stored set of unique keys for an encryption key corresponding to a unique identifier associated with the active device (Mendonsa – Paragraph [0032]: the data encryption controller accesses an encryption key table 328 to determine whether an encryption key has already been saved in association with the unique device identifier; and Paragraph [0033]: the encryption key table 328 stores a listing of unique device identifiers for different devices (e.g., device IDs, as shown in the encryption key table 328) such that each unique device identifier is associated with a corresponding public key and a private key). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Mendonsa to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Mendonsa’s teaching of a stored set of encryption keys corresponding to device identifiers into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This combination would provide a secure location from which to retrieve encryption keys associated with specific devices for authentication and/or communication purposes. Claim(s) 6 and 21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Costa, in view of Muma, Au, and Lebrun et al. (US 20200135321 A1), hereinafter Lebrun. Regarding Claim 6: Costa, Muma, and Au combine to teach the method of claim 1. Costa further teaches wherein performing the one or more authentication operations further comprises: comparing, by the control system, the candidate unique identifier to a stored unique identifier corresponding to the active device (Costa – Paragraph [0202]: When the OLT 100 receives the second authentication message AM2 from the optical termination device OTD2 … and Paragraph [0204]: it retrieves from the association table AT the secret code SC2 associated to the registration identifier Reg-ID2 of the optical termination device OTD2; and Paragraph [0207]: it calculates a further authentication code AC by applying the authentication code generation algorithm AAi to the first number C1 and at least one of: the second number C2, the information OLT2_A_S, the further information ONT2_A_S, the identifier ONT-ID2 and the registration identifier Reg-ID2, by using the secret code SC2 as key for the authentication code generation algorithm AAi; Examiner’s Comment: the retrieval and calculation steps of Costa’s method are performed as a part of a comparison of a received identifier to a stored identifier); determining, by the control system, whether the candidate unique identifier matches the stored unique identifier (Costa – Paragraph [0209]: Then, preferably, the OLT 100 compares the authentication code AC* received from the optical termination device OTD2 with the further authentication code AC calculated during step 214 (step 215); and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2; Examiner’s Comment: When AC* is found to be equal to AC, the authenticating device confirms that the unique identifier (Reg-ID2) from which AC was derived matched the received unique identifier) and in an instance the candidate unique identifier matches the stored unique identifier (Costa – Paragraph [0209]: Then, preferably, the OLT 100 compares the authentication code AC* received from the optical termination device OTD2 with the further authentication code AC calculated during step 214 (step 215); and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2; Examiner’s Comment: When AC* is found to be equal to AC, the authenticating device confirms that the unique identifier (Reg-ID2) from which AC was derived matched the received unique identifier) authenticating, by the control system, the active device (Costa – Paragraph [0027]: The OLT, which stores an association between the serial number (provided during the Serial Number Acquisition phase) and the expected password, then checks whether the password received from the optical termination device matches with the expected password. In the affirmative, the OLT allows the optical termination device to access the PON; and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2). The combination of Costa, Muma, and Au does not expressly teach comparing, by the control system, the candidate authentication key to a stored authentication key corresponding to the active device; and the candidate authentication key matches the stored authentication key; and the candidate authentication key matches the stored authentication key. However, Lebrun teaches comparing, by the control system, the candidate authentication key to a stored authentication key corresponding to the active device (Lebrun – Paragraph [0129]: the user device 110 can communicate the authentication key to the dose management system 130 via the network 105. When the dose management system 130 receives the key, the data processing module 131 can then compare the received authentication key to any stored authentication keys, such as by reading the received authentication key and any stored authentication keys); and the candidate authentication key matches the stored authentication key (Lebrun – Paragraph [0129]: If a match is determined between the received authentication key and a stored authentication key, then that user device 110 can be re-authenticated, such as without the user 101 having to take any additional steps); and the candidate authentication key matches the stored authentication key (Lebrun – Paragraph [0129]: If a match is determined between the received authentication key and a stored authentication key, then that user device 110 can be re-authenticated, such as without the user 101 having to take any additional steps). Lebrun further teaches authenticate the active device (Lebrun – Paragraph [0129]: If a match is determined between the received authentication key and a stored authentication key, then that user device 110 can be re-authenticated, such as without the user 101 having to take any additional steps). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Lebrun to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Lebrun’s teaching to compare a received device authentication key to a stored device authentication key into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This combined functionality enhances the method by establishing a process for maintaining and implementing values for authenticating users/devices in a system. Regarding Claim 21: Costa, Muma, and Au combine to teach the computer program product of claim 20. Costa further teaches compare the candidate unique identifier to a stored unique identifier corresponding to the active device (Costa – Paragraph [0202]: When the OLT 100 receives the second authentication message AM2 from the optical termination device OTD2 … and Paragraph [0204]: it retrieves from the association table AT the secret code SC2 associated to the registration identifier Reg-ID2 of the optical termination device OTD2; and Paragraph [0207]: it calculates a further authentication code AC by applying the authentication code generation algorithm AAi to the first number C1 and at least one of: the second number C2, the information OLT2_A_S, the further information ONT2_A_S, the identifier ONT-ID2 and the registration identifier Reg-ID2, by using the secret code SC2 as key for the authentication code generation algorithm AAi; Examiner’s Comment: the retrieval and calculation steps of Costa’s method are performed as a part of a comparison of a received identifier to a stored identifier); determine whether the candidate unique identifier matches the stored unique identifier (Costa – Paragraph [0209]: Then, preferably, the OLT 100 compares the authentication code AC* received from the optical termination device OTD2 with the further authentication code AC calculated during step 214 (step 215); and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2; Examiner’s Comment: When AC* is found to be equal to AC, the authenticating device confirms that the unique identifier (Reg-ID2) from which AC was derived matched the received unique identifier) and in an instance the candidate unique identifier matches the stored unique identifier (Costa – Paragraph [0209]: Then, preferably, the OLT 100 compares the authentication code AC* received from the optical termination device OTD2 with the further authentication code AC calculated during step 214 (step 215); and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2; Examiner’s Comment: When AC* is found to be equal to AC, the authenticating device confirms that the unique identifier (Reg-ID2) from which AC was derived matched the received unique identifier) authenticate the active device (Costa – Paragraph [0027]: The OLT, which stores an association between the serial number (provided during the Serial Number Acquisition phase) and the expected password, then checks whether the password received from the optical termination device matches with the expected password. In the affirmative, the OLT allows the optical termination device to access the PON; and Paragraph [0210]: If the authentication code AC* is equal to the further authentication code AC, then the OLT 100 authenticates the optical termination device OTD2). Muma further teaches the at least one non-transitory computer-readable storage medium storing further software instructions that, when executed by the apparatus, cause the apparatus to (Muma – Paragraph [0134]: Embodiments of the disclosure can be represented as a computer program product stored in a machine-readable medium (also referred to as a computer-readable medium, a processor-readable medium, or a computer usable medium having a computer-readable program code embodied therein). The machine-readable medium can be any suitable tangible, non-transitory medium, including magnetic, optical, or electrical storage medium including a diskette, compact disk read only memory (CD-ROM), memory device (volatile or non-volatile), or similar storage mechanism. The machine-readable medium can contain various sets of instructions, code sequences, configuration information, or other data, which, when executed, cause a processor to perform steps in a method according to an embodiment of the disclosure). The combination of Costa, Muma, and Au does not expressly teach compare the candidate authentication key to a stored authentication key corresponding to the active device; and the candidate authentication key matches the stored authentication key; and the candidate authentication key matches the stored authentication key. However, Lebrun teaches compare the candidate authentication key to a stored authentication key corresponding to the active device (Lebrun – Paragraph [0129]: the user device 110 can communicate the authentication key to the dose management system 130 via the network 105. When the dose management system 130 receives the key, the data processing module 131 can then compare the received authentication key to any stored authentication keys, such as by reading the received authentication key and any stored authentication keys); and the candidate authentication key matches the stored authentication key (Lebrun – Paragraph [0129]: If a match is determined between the received authentication key and a stored authentication key, then that user device 110 can be re-authenticated, such as without the user 101 having to take any additional steps); and the candidate authentication key matches the stored authentication key (Lebrun – Paragraph [0129]: If a match is determined between the received authentication key and a stored authentication key, then that user device 110 can be re-authenticated, such as without the user 101 having to take any additional steps). Lebrun further teaches authenticate the active device (Lebrun – Paragraph [0129]: If a match is determined between the received authentication key and a stored authentication key, then that user device 110 can be re-authenticated, such as without the user 101 having to take any additional steps). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Lebrun to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Lebrun’s teaching to compare a received device authentication key to a stored device authentication key into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This combined functionality enhances the method by establishing a process for maintaining and implementing values for authenticating users/devices in a system. Claim(s) 7 is/are rejected under 35 U.S.C. 103 as being unpatentable over Costa, in view of Muma, Au, and Choi (US 20170163009 A1), hereinafter Choi. Regarding Claim 7: Costa, Muma, and Au combine to teach the method of claim 1. The combination of Costa, Muma, and Au does not expressly teach wherein the active device is an optical terminal located at a central office, head end, or customer premise. However, Choi teaches wherein the active device is an optical terminal located at a central office, head end, or customer premise (Choi – Paragraph [0044]: The WDM-PON 100 may include a base station transceiver (OLT: optical line terminal) 110 which is disposed in the center office (CO), a subscriber terminal (ONU: optical network unit or ONT: optical network terminal) 130 which is provided at a subscriber side, and a remote node (RN) 120). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Choi to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Choi’s teaching to authenticate a device including a terminal of a central office, head end, or customer premise into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This combination enhances the method by defining specific devices for applying the method. Claim(s) 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Costa, in view of Muma, Au, and Kim et al. (US 20190173862 A1), hereinafter Kim. Regarding Claim 10: Costa, Muma, and Au combine to teach the method of claim 9. The combination of Costa, Muma, and Au does not expressly teach wherein the encryption key change message further comprises one or more of a new encryption key or new authentication key for the active device. However, Kim teaches wherein the encryption key change message further comprises one or more of a new encryption key or new authentication key for the active device (Kim – Paragraph [0094]: Continuing with this example, in transmitting an encryption key change message, the MGM 202 may also transmit a set of encryption keys (e.g., an encryption key set) that the master ECU 206 can use to generate encryption keys. The master ECU 206 may generate encryption keys using the transmitted encryption key set or selectively assign at least one of encryption keys included in the encryption key set). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Kim to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Kim’s teaching to include a new encryption key within a message to change an encryption key into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This addition would help facilitate the encryption key change in response to the message. In addition, incorporating an encryption key of Kim with the message described by the combination of Costa, Muma, and Au is nothing but applying a known technique to a known device/method ready for improvement to yield predictable results, as per KSR vs Teleflex rationale. Claim(s) 11, 12, and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Costa, in view of Muma, Au, and McClintock et al. (US 10007779 B1), hereinafter McClintock. Regarding Claim 11: Costa, Muma, and Au combine to teach the method of claim 1. Costa further teaches unique key set as associated with a stored unique identifier corresponding to the active device (Costa – Paragraph [0153]: the registration identifier is transmitted from the optical termination device to the OLT 100 during the authentication procedure that will be described in detail hereinafter, and then is used by the OLT for recognizing the user (or the ONU), and retrieve the associated secret code; and Paragraph [0154]: in the association table AT of FIG. 1, only a registration identifier Reg-ID2 of the optical termination device OTD2 and its associated secret code SC2 are depicted; and Figure 1: illustration of a network including an OLT with an association table containing a unique identifier (Reg-ID2) corresponding to an authentication key (SC2 of AC*/AC); and Paragraph [0282]: Then, preferably, at a step 501, the OLT 100 retrieves from one of its registers, in particular the active_key_register, the encryption key EK it is using with the optical termination device OTD2, identified by the identifier OTD2_ID; Examiner’s Comment: the teachings from Costa combine to demonstrate storing sets of authentication and encryption keys as being associated with stored device identifiers). The combination of Costa, Muma, and Au does not expressly teach further comprising: generating, by the control system, a new unique key set for the active device, wherein the new unique key set comprises a new encryption key and new authentication key; and storing, by the control system, the new unique key set. However, McClintock teaches further comprising: generating, by the control system, a new unique key set for the active device (McClintock – Col. 4, Lines 28-40: A source of a credential may include an entity (e.g., user, account, device, system) with which the credential is associated with. Credentials can include passwords, personal identification number (PIN), username, cryptographic credentials, payment credentials, biometric credentials, multifactor authentication or authorization code or token, and the like. Cryptographic credentials can include cryptographic keys such as encryption keys, public keys, private keys, and the like. In some cases, a cryptographic key may include a master key that is used to retrieve, encrypt, decrypt, or derive other keys. Cryptographic credentials can also include digital certificates and digital signatures; and Col. 9, Lines 18-19: The credential management module 219 may also be configured to update the stored credential data; and Col. 9, Lines 6-8: the credential management module 219 may be configured to encrypt, decrypt, or otherwise transform the credential data; and Col. 8, Lines 59-61: the functionalities of the access control module 218 and/or the credential management module 219 may instead be provided by the service provider 206), wherein the new unique key set comprises a new encryption key and new authentication key (McClintock – Col. 4, Lines 28-40: Credentials can include passwords, personal identification number (PIN), username, cryptographic credentials, payment credentials, biometric credentials, multifactor authentication or authorization code or token, and the like. Cryptographic credentials can include cryptographic keys such as encryption keys, public keys, private keys, and the like. In some cases, a cryptographic key may include a master key that is used to retrieve, encrypt, decrypt, or derive other keys. Cryptographic credentials can also include digital certificates and digital signatures); and storing, by the control system, the new unique key set (McClintock – Col. 8, Lines 63-67: the credential management module 218 may be configured to provide storage, retrieval, and/or update of credentials associated with the user 202 and/or user device 204 in conjunction with a credential data store 217A). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating McClintock to arrive at the conclusion of the claimed invention. One would be motivated to incorporate McClintock’s teaching of a capability to update device credentials including encryption and authentication keys into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This combination improves the method by enabling the authentication system to update outdated or compromised credentials. Regarding Claim 12: Costa, Muma, Au, and McClintock combine to teach the method of claim 11. McClintock further teaches wherein the new unique key set is generated (McClintock – Col. 9, Lines 18-19: The credential management module 219 may also be configured to update the stored credential data; and Col. 9, Lines 6-8: the credential management module 219 may be configured to encrypt, decrypt, or otherwise transform the credential data). Muma further teaches in response to determining the active device fails to be authenticated or in response to a configuration parameter (Muma – Paragraph [0071]: As discussed above, a first technique for providing a more robust encryption includes periodically switching the encryption key. In operation of the system 100, the transmitter sends the two-bit KTI value 52 to the receiver once each multiframe. The transmitter uses the KTI value 52 to signal to the receiver that the transmitter will switch its encryption key and that the receiver should also switch its encryption key. If both the transmitter and the receiver synchronize each respective key switch, the receiver will be able to properly decrypt the encrypted OTN payload; and Paragraph [0079]: In this example, the system 100 is configured with a maximum key lifetime 202 of 14 multiframes. At period 204, the Rx decryption controller 112 determines that the maximum has been exceeded and that the receiver has not switched to the next key. This condition could be caused, for example, by a lack of the next key in the key table of the receiver. Therefore, at period 204, the Rx decryption controller inputs a failure pattern 206 into the payload of the decrypted OTN frame. The failure pattern will alert higher-layer applications of the key error. Consequently, higher-layer applications may load the appropriate next key into the key table of the receiver via the SPI 120. Once the Rx decryption controller 112 has the next key, it will reset the Rx multiframe counter 118 and decrypt the encrypted OTN payload; and Paragraph [0115]: In embodiments according to the present disclosure, system 100 may further comprise a performance monitor (PMON) for counting the number of frames that failed decryption. Such failures may be the result of authentication issues, key out-of-sync, frame slips or frame jumps). The motivation to combine the arts is the same as that of Claim 11. Regarding Claim 13: Costa, Muma, and McClintock combine to teach the method of claim 12. McClintock further teaches wherein the configuration parameter defines a periodic time value configured to describe a time within which one or more keys of a unique key set for the active device must be changed (McClintock – Col. 2, Lines 8-16: A credential (e.g., password, cryptographic key, digital certificate) may be expected to be changed periodically or at a certain frequency. The time interval between such expected credential changes may be referred to as the credential's maximum age. The maximum age may be fixed (e.g., 90 days) or varied, predefined or dynamically generated based on various factors, and/or associated with one or more credentials or credential sources). The motivation to combine the arts is the same as that of Claim 11. Claim(s) 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Costa, in view of Muma, Au, and Ovadia (US 20220291728 A1), hereinafter Ovadia. Regarding Claim 15: Costa, Muma, and Au combine to teach the method of claim 14. Costa further teaches wherein [telemetry] data is received via passive-optical networking (Costa – Paragraph [0007]: A PON is a point-to-multipoint (P2MP) optical network with no active elements in the signals' path from source to destination. The only elements used in a PON are passive optical components, such as optical fiber, splices and splitters; and Paragraph [0148]: FIG. 1 schematically shows a PON 1 that, in the exemplary embodiment herein after described, is suitable for FTTH applications; and Figure 1: illustration of the passive optical network through which the devices communicate messages). The combination of Costa, Muma, and Au does not expressly teach telemetry data. However, Ovadia teaches wherein telemetry data is received via passive-optical networking (Ovadia – Paragraph [0028]: The environment 10 includes a customer premises 24 that houses, in this example, three computing devices, referred to herein as customer-premises devices 26-1-1, 26-1-2 and 26-1-3 (generally CPDs 26). The three CPDs 26 may be located in the same environment, or in different environments. For example, the CPD 26-1-1 may be a cable modem or a passive-optical network (PON) optical network unit (ONU) that is located in a room with little ventilation, and has other electronic devices stacked on top of the CPD 26-1-1; and Paragraph [0031]: The CPD 26-1-1 includes a telemetry agent 34-1-1 that is configured to provide telemetry data to the controller device 12 intermittently, periodically, upon the occurrence of an event, such as, by way of non-limiting example, a change in operational metrics, or in response to a request from the controller device 12). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Ovadia to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Ovadia’s teaching to transmit telemetry data between devices in a passive optical network into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This combination improves the method by specifically incorporating telemetry data useful in device/user authentication. Claim(s) 22-25 is/are rejected under 35 U.S.C. 103 as being unpatentable over Costa, in view of Muma, Au, and Bartsch (Bartsch, Witali. FIDO Device Onboard Specification - Proposed Standard, March 23, 2021. FIDO Alliance, 23 Mar. 2021.), hereinafter Bartsch. Regarding Claim 22: Costa, Muma, and Au combine to teach the method of claim 1. Costa, Muma, and Au do not expressly teach wherein the encryption key is assigned to the active device during manufacture of the active device. However, Bartsch teaches wherein the encryption key is assigned to the active device during manufacture of the active device (Bartsch – Section 3.4.2, P. 35: The Ownership Voucher is created during Device manufacture, but is not stored in the device. Instead, the Ownership Voucher is transmitted along the supply chain to mirror the device’s progress. The Ownership Voucher is extended to contain a list or ledger of subsequent "owners" of the device, identified only by public keys in a signature chain; and P. 36: High level representation of an Ownership Voucher established during device manufacture; and P. 37: “OVPubKey” is the public key of the device’ initial owner (e.g., the manufacturer)). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Bartsch to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Bartsch’s teaching to establish an encryption key for a device during the manufacture of the device into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This addition provides additional security by ensuring that a device’s identity is securely rooted. Regarding Claim 23: Costa, Muma, and Au combine to teach the method of claim 1. Costa, Muma, and Au do not expressly teach wherein the authentication key and the configurable value are generated for the active device during manufacture of the active device. However, Bartsch teaches wherein the authentication key (Bartsch – Section 3.4.1, P. 35: The GUID parameter “DCGuid” is the current device’s GUID, to be used for the next ownership transfer) and the configurable value (Bartsch – Section 3.4.1, P. 35: The “DCHmacSecret” parameter contains a secret, initialized with a random value by the Device during the DI protocol or equivalent Device initialization) are generated for the active device during manufacture of the active device (Bartsch – Section 1, P. 6: During manufacturing, a FIDO Device Onboard equipped device is ideally configured with: … Other credentials, please see § 3.4.1 Device Credential Persisted Type (non-normative) for more information). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Bartsch to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Bartsch’s teaching to additionally establish other device-specific verifying credentials during manufacture into Costa, Muma, and Au’s system for authenticating devices in WDM fiber optic networks using updatable keys. This combined functionality would help fortify device attestation processes. Regarding Claim 24: Costa, Muma, and Au combine to teach the apparatus of claim 16. Costa, Muma, and Au do not expressly teach wherein the encryption key is assigned to the active device during manufacture of the active device. However, Bartsch teaches wherein the encryption key is assigned to the active device during manufacture of the active device (Bartsch – Section 3.4.2, P. 35: The Ownership Voucher is created during Device manufacture, but is not stored in the device. Instead, the Ownership Voucher is transmitted along the supply chain to mirror the device’s progress. The Ownership Voucher is extended to contain a list or ledger of subsequent "owners" of the device, identified only by public keys in a signature chain; and P. 36: High level representation of an Ownership Voucher established during device manufacture; and P. 37: “OVPubKey” is the public key of the device’ initial owner (e.g., the manufacturer)). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Bartsch to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Bartsch’s teaching to establish an encryption key for a device during the manufacture of the device into Costa, Muma, and Au’s method for authenticating devices in WDM fiber optic networks using updatable keys. This addition provides additional security by ensuring that a device’s identity is securely rooted. Regarding Claim 25: Costa, Muma, and Au combine to teach the apparatus of claim 16. Costa, Muma, and Au do not expressly teach wherein the authentication key and the configurable value are generated for the active device during manufacture of the active device. However, Bartsch teaches wherein the authentication key (Bartsch – Section 3.4.1, P. 35: The GUID parameter “DCGuid” is the current device’s GUID, to be used for the next ownership transfer) and the configurable value (Bartsch – Section 3.4.1, P. 35: The “DCHmacSecret” parameter contains a secret, initialized with a random value by the Device during the DI protocol or equivalent Device initialization) are generated for the active device during manufacture of the active device (Bartsch – Section 1, P. 6: During manufacturing, a FIDO Device Onboard equipped device is ideally configured with: … Other credentials, please see § 3.4.1 Device Credential Persisted Type (non-normative) for more information). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Costa, Muma, and Au, further incorporating Bartsch to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Bartsch’s teaching to additionally establish other device-specific verifying credentials during manufacture into Costa, Muma, and Au’s system for authenticating devices in WDM fiber optic networks using updatable keys. This combined functionality would help fortify device attestation processes. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Kozaki et al. (US 20080247550 A1) teaches a PON system that periodically changes encryption keys used in secure inter-device communication Hu et al. (US 20230231728 A1) teaches methods for secure PON communication including device authentication process similar to those of the claimed invention Lohr (US 20160149867 A1) teaches a system for encrypting/decrypting authentication communications between devices in PONs Any inquiry concerning this communication or earlier communications from the examiner should be directed to NICHOLAS JOSEPH DILUZIO whose telephone number is (703)756-1229. The examiner can normally be reached Mon - Fri -- 7:30 AM - 5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NICHOLAS JOSEPH DILUZIO/Examiner, Art Unit 2498 /YIN CHEN SHAW/Supervisory Patent Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Show 4 earlier events
Jul 16, 2025
Request for Continued Examination
Jul 22, 2025
Response after Non-Final Action
Oct 01, 2025
Non-Final Rejection mailed — §103
Dec 09, 2025
Interview Requested
Dec 18, 2025
Applicant Interview (Telephonic)
Dec 30, 2025
Examiner Interview Summary
Jan 02, 2026
Response Filed
Aug 17, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12596792
DATA ENCRYPTION DETECTION
4y 0m to grant Granted Apr 07, 2026
Patent 12490087
AUTHENTICATION SERVER FUNCTION SELECTION IN AN AUTHENTICATION AND KEY AGREEMENT
3y 6m to grant Granted Dec 02, 2025
Patent 12475218
METHOD AND SYSTEM FOR IDENTIFYING A COMPROMISED POINT-OF-SALE TERMINAL NETWORK
3y 0m to grant Granted Nov 18, 2025
Patent 12367440
ARTIFICIAL INTELLIGENCE-BASED SYSTEM AND METHOD FOR FACILITATING MANAGEMENT OF THREATS FOR AN ORGANIZATON
2y 11m to grant Granted Jul 22, 2025
Patent 11966466
UNIFIED WORKLOAD RUNTIME PROTECTION
2y 3m to grant Granted Apr 23, 2024
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
33%
Grant Probability
99%
With Interview (+100.0%)
3y 1m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 15 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month