DETAILED ACTION
This Action is in consideration of the Applicant’s response on April 17, 2026. Claims 1, 24, 27, 36, and 42 are amended by the Applicant. Claims 3, 4, 7, 8, 12, 20 – 23, 25, 26, 29 – 33, 35, 37 – 41, and 43 – 47 are canceled. Claims 1, 2, 5, 6, 9 – 11, 13 – 19, 24, 27, 28, 34, 36, and 42, where Claims 1, 36, and 42 are in independent form, are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on May 18, 2026 has been entered.
Information Disclosure Statement
The information disclosure statements (IDSs) submitted on April 17, 2026 and April 17, 2026 were filed before the mailing date of the current action. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
Applicant's arguments filed April 17, 2026 have been fully considered but they are moot based on the new grounds of rejection necessitated by amendment.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 2, 5, 6, 9 – 11, 13 – 19, 24, 27, 28, 34, 36, and 42 are rejected under 35 U.S.C. 103 as being unpatentable over “Proof-of-PUF Enabled Blockchain: Concurrent Data and Device Security for Internet-of-Energy,” Asif, Rameez, et al. (hereinafter “Asif”), in view of PGPub. 2021/0234709 (hereinafter “Kim”).
1. Regarding Claim 1, Asif discloses of a device [Fig. 9] comprising:
a PUF module comprising a physically unclonable function, PUF, and internal PUF interface logic arranged to receive an input challenge and output an output response being a deterministic function of the input challenge, the deterministic function comprising the PUF [Figs. 9, 10a, 10b, 10c]; and
one or more outer layer components providing at least part of an unsecured channel for inputting the input challenge to the internal interface logic of the PUF module and receiving back the output response output by the internal interface logic [Fig. 10b; also Pg. 3, Table 1];
wherein at least one of the outer layer components is susceptible to manipulation of the input challenge and/or output response by a malicious process [Fig. 10b; also Pg. 3, Table 1], but the PUF module, including the internal PUF interface logic, is encapsulated within a housing of the device and separated from the one or more outer layer components, and is thus protected from manipulation by the malicious process [Figs. 9 and 10; PUF board encapsulated]; and
wherein the internal PUF interface logic comprises a logging mechanism arranged to automatically log a record of the input challenge and/or output response in a log medium [Fig. 10a-10c; Pg. 17-18; proof of PUF; records in secure database].
Asif, however, does not specifically disclose that the log medium is a local memory of the device embedded in the interface logic within the logging mechanism encapsulated within the housing of the device.
Kim discloses a system and method for using a PUF to generate secure information [Abstract]. Kim further discloses that the response from the PUF is stored locally in the device containing the PUF to perform calculations on it [Figs. 10 and 14; Para. 0134]. It would have been obvious to one skilled in the art before the effective date of the current invention to incorporate the teachings of Kim with Asif since both systems utilize a PUF to generate secret information. The combination stores the response to the challenge for further processing by the device. This would have been a obvious variation of a cryptographic device which further processes PUF outputs as the outputs must be stored to be further processed.
2. Regarding Claim 2, Asif, in view of Kim, discloses the limitations of Claim 1 above. Asif further discloses that the internal interface logic is implemented partially or wholly in firmware run on a processor of the device [Pg. 2], wherein the firmware is stored partially or wholly in read only memory, ROM, or a secure kernel [Pg. 16].
3. Regarding Claim 5, Asif, in view of Kim, discloses the limitations of Claim 1 above. Asif further discloses that the internal interface logic is implemented in fixed-function hardware circuitry [Fig. 9].
4. Regarding Claim 6, Asif, in view of Kim, discloses the limitations of Claim 1 above. Asif further discloses that the at least one outer layer component comprises an external interface for receiving the input challenge from a source external to the device and/or supplying the output response to a destination external to the device, the malicious process to which the at least one outer layer component is susceptible comprising interception and manipulation of the input challenge and/or output response between the source and the external interface [Fig. 10b].
5. Regarding Claim 9, Asif, in view of Kim, discloses the limitations of Claim 6 above. Asif further discloses that the device comprises a dedicated PUF device [Fig. 9].
6. Regarding Claim 10, Asif, in view of Kim, discloses the limitations of Claim 1 above. Asif further discloses that the at least one outer layer component comprises an application running on a processor within the housing of the device, wherein the application is configured to generate the input challenge, the malicious process to which the at least one outer layer component is susceptible comprising malware being run on the same processor as the application to manipulate the input challenge [Pg. 2].
7. Regarding Claim 11, Asif, in view of Kim, discloses the limitations of Claim 10 above. Asif further discloses that the internal interface logic is arranged to run on either:
a separate processor than the application [Pg. 2 and 16; Fig. 9]; or
the same processor as the application but in a privileged domain of a secure processor, whereas the application runs in an application domain.
8. Regarding Claim 13, Asif, in view of Kim, discloses the limitations of Claim 10 above. Asif further discloses that the device comprises an event data recorder, EDR, and the application comprises an EDR application [Fig. 10c].
9. Regarding Claim 14, Asif, in view of Kim, discloses the limitations of Claim 13 above. Asif further discloses that the application is configured to generate a result of a system which the EDR is configured to monitor, and the EDR is configured to record the result and a tag mapping the output response to the result [Pg. 16-17].
10. Regarding Claim 15, Asif, in view of Kim, discloses the limitations of Claim 14 above. Asif further discloses that the tag comprises: a cryptographic signature generated by signing the result with the output response; or a hash-based message authentication code, HMAC, generated as a function of the result and the output response [Fig. 10c; SHA 256].
11. Regarding Claim 16, Asif, in view of Kim, discloses the limitations of Claim 14 above. Asif further discloses that the input challenge comprises meaningful data used by the application, representing a state of the system being monitored [Section 5.2; Fig. 10c].
12. Regarding Claim 17, Asif, in view of Kim, discloses the limitations of Claim 16 above. Asif further discloses that the result is dependent on said data [Section 5.2; Fig. 10c].
13. Regarding Claim 18, Asif, in view of Kim, discloses the limitations of Claim 13 above. Asif further discloses that the EDR is an EDR for a vehicle, a system which the EDR is configured to monitor comprising a system of the vehicle [Figs. 10c and 11; Pg. 13].
14. Regarding Claim 19, Asif, in view of Kim, discloses the limitations of Claim 1 above. Asif further discloses that the one or more outer layer components are implemented in the same housing as the PUF module [Fig. 9].
15. Regarding Claim 24, Asif, in view of Kim, discloses the limitations of Claim 23 above. Asif further discloses that said local memory is a tamperproof memory and/or write-once memory [Pg. 16, section 5].
16. Regarding Claim 27, Asif, in view of Kim, discloses the limitations of Claim 1 above. Asif further discloses that the internal PUF interface logic is configured to perform the logging of the record in real-time in response the inputting of the input challenge [Figs. 10a-10c; Pgs. 16-19; PUF implementation].
17. Regarding Claim 28, Asif, in view of Kim, discloses the limitations of Claim 1 above. Asif further discloses that the internal PUF interface logic is configured to periodically log any input challenges received and/or output responses generated during each instance of a periodic window of time [Figs. 10a-10c; Pgs. 16-19; PUF implementation with blockchain].
18. Regarding Claim 34, Asif discloses the limitations of Claim 1 above. Asif further discloses that the logging mechanism is configured to output the record, for the logging thereof, in a packet that further comprises a signature generated based on a cryptographic key of the logging mechanism applied to at least part of the packet comprising the record [Figs. 7 and 8].
19. Regarding Claims 36 and 42, Asif discloses of a computer program embodied on a non-transitory computer-readable medium and configured so as, when run on one or more processors, the one or more processors perform [Section 5.3, Pg. 20] a method of using a device [Figs. 10a-10c], the device including:
a PUF module comprising a physically unclonable function, PUF, and internal PUF interface logic arranged to receive an input challenge and output an output response being a deterministic function of the input challenge, the deterministic function comprising the PUF [Figs. 9, 10a, 10b, 10c]; and
one or more outer layer components providing at least part of an unsecured channel for inputting the input challenge to the internal interface logic of the PUF module and receiving back the output response output by the internal interface logic [Fig. 10b; also Pg. 3, Table 1];
wherein at least one of the outer layer components is susceptible to manipulation of the input challenge and/or output response by a malicious process [Fig. 10b; also Pg. 3, Table 1], but the PUF module, including the internal PUF interface logic, is encapsulated within a housing of the device and separated from the one or more outer layer components, and is thus protected from manipulation by the malicious process [Figs. 9 and 10; PUF board encapsulated]; and
wherein the internal PUF interface logic comprises a logging mechanism arranged to automatically log a record of the input challenge and/or output response in a log medium [Fig. 10c; proof of PUF], the method comprising:
after the record of the input challenge and/or output response has been logged in said log medium, inputting a candidate challenge to the device via the unsecured channel of the outer layer in order to cause the PUF module to generate a candidate response and return the candidate response to via the unsecured channel [Pgs. 16-19; Sections 5.1, 5.2, and 5.3; Figs. 10a-10c; PUF implementation with blockchain];
checking for evidence of manipulation by checking the candidate challenge against record of the original input challenge logged in the log medium, and/or by checking the candidate response against the record of the original output response logged in the log medium [Pgs. 16-19; Sections 5.1, 5.2, and 5.3; Figs. 10a-10c; PUF implementation with blockchain].
Asif, however, does not specifically disclose that the log medium is a local memory of the device embedded in the interface logic within the logging mechanism encapsulated within the housing of the device.
Kim discloses a system and method for using a PUF to generate secure information [Abstract]. Kim further discloses that the response from the PUF is stored locally in the device containing the PUF to perform calculations on it [Figs. 10 and 14; Para. 0134]. It would have been obvious to one skilled in the art before the effective date of the current invention to incorporate the teachings of Kim with Asif since both systems utilize a PUF to generate secret information. The combination stores the response to the challenge for further processing by the device. This would have been a obvious variation of a cryptographic device which further processes PUF outputs as the outputs must be stored to be further processed.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. PGPub. 2018/0351754; PGPub. 2018/0183589.
Contacts
Any inquiry concerning this communication or earlier communications from the examiner should be directed to TAE K KIM whose telephone number is (571)270-1979. The examiner can normally be reached M-F 9:30-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached at 5712727642. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/TAE K KIM/Primary Examiner, Art Unit 2496