Prosecution Insights
Last updated: October 02, 2026
Application No. 18/292,484

UPDATE BACKUP AND FAILSAFE ROLLBACK IN SECURE ELEMENTS

Non-Final OA §103
Filed
Jan 26, 2024
Priority
Jul 28, 2021 — EU 21382708.2 +1 more
Examiner
NGUYEN, DUY KHUONG THANH
Art Unit
2199
Tech Center
2100 — Computer Architecture & Software
Assignee
Giesecke+Devrient Mobile Security Germany GmbH
OA Round
3 (Non-Final)
82%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
467 granted / 570 resolved
+26.9% vs TC avg
Strong +34% interview lift
Without
With
+34.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
17 currently pending
Career history
595
Total Applications
across all art units

Statute-Specific Performance

§101
12.7%
-27.3% vs TC avg
§103
66.1%
+26.1% vs TC avg
§102
7.0%
-33.0% vs TC avg
§112
6.1%
-33.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 570 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment 2. This office action has been issued in response to a reply filed on 07/07/2026. Claims 16-18, 20, 28-30 have been amended. Response to argument 3. Applicant's arguments with respect to claims 16-30 have been considered but are moot in view of the new ground(s) of rejection. Status of Claims 4. Claims 16-30 are pending, of which claims, of which claim 16, 29 and 30 are in independent form. The Office's Note: 5. The Office has cited particular paragraphs / columns and line numbers in the reference(s) applied to the claims above for the convenience of the Applicant. Although the specified citations are representative of the teachings of the art and are applied to specific limitations within the individual claim(s), other passages and figures may apply as well. It is respectfully requested from the Applicant in preparing responses, to fully consider the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the cited passages as taught by the prior art or relied upon by the Examiner. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. 6. Claim 29 invoked 112(f). This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: the update agent handler claim 29. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 7. Claim 16-30 rejected under 35 U.S.C. 103(a) as being unpatentable over Olinsky US 20180165157 (hereinafter Olinsky – IDS of records), in view Lee US 20230029025 (hereinafter Lee) and further in view Kim US 20140149789 (hereinafter Kim). Claim 16 rejected, Olinsky teaches a method for updating software loaded on a secure element (Olinsky, para [0004], second and third sentence), SE, wherein the SE comprises an update agent handler (Olinsky, para [0052]-[0053]: daemon) and an update agent (Olinsky, implicit: the code on the IoT device performing the update), the method comprising (Olinsky, abstract and summary): performing at the SE a secure backup of the current software version (Olinsky, para [ 0055] describes backing up the current version; [0056] discloses that these backups may be encrypted, thus making them a secure backup. Para [0069], the saved backup may also be encrypted.), to be stored thereon; performing at the SE an update process of the current software version, to obtain an updated software version(Olinsky, para [ 0057], the IoT device updates to the received release in a way that is self-managing and which is robust to failures in the IoT device update. Para [0059-0064], updated release and the updated release becomes the current release); and if the update process failed, performing a rollback to restore the software backup as a new current software version on the SE(Olinsky, para [0065-0066], buggy release or unstable release. Para [ 0067], use the previous release to rollback). Olinsky does not explicitly teach receiving at the SE from a device external to the SE a request to backup a current version of software loaded on the SE; (performing at the SE a secure backup of the current software version), the secure backup comprising the update agent handler instructing the update agent to create a restore image corresponding to the current software version loaded on the SE, wherein the update agent creates the restore image by encapsulating the current software version and securing the restore image with cryptographic keys, and returning the restore image as the software backup to the device external to the SE, to be stored thereon; if the update process failed, performing a rollback comprising receiving, at the SE from the device external to the SE, the restore image previously returned to the device and loading the restore image into the SE to restore the software backup as a new current software version on the SE. However, Lee teaches receiving at the SE from a device external to the SE a request to backup a current version of software loaded on the SE (Lee, US 20230029025, fig. 5 and para [0100], In operation 502, the external electronic device 300 can approve backup. The processor 120 of the external electronic device 300 may receive the message about the backup data 204, and based on the received message, determine whether the request application 205 requesting the backup operation is a reliable request application. The received message, for example, may include an ID of the electronic device 101, an ID of the request application 205, and the like.); (performing at the SE a secure backup of the current software version), the secure backup comprising the update agent handler instructing the update agent to create a restore image corresponding to the current software version loaded on the SE, wherein the update agent creates the restore image by encapsulating the current software version and securing the restore image with cryptographic keys (Lee, fig. 5 and para [0101], In operation 503, the electronic device 101 can load backup data. The processor 120 of the electronic device 101 may load the backup data 204 for content applications from the secure element 201 through the request application 205 and the backup application 203. Loading the backup data 204 may be implemented as the request application 205 requests the backup data 204 via the backup application 203, and the backup application 203 verifies the received request and transmits the backup data 204 to the request application 205. Para [0102], The processor 120 of the electronic device 101 may generate the secure element 201 and a secure channel protocol by using a key stored in the secure element 201 and extract the backup data 204 from the secure element 201 by using the secure channel protocol. Fig. 2 and para [0049-0051], The backup data 204 may further include a package including an installation file and an execution file for each content application. The backup data 204 may further include a hash value for at least one of list information about the content application included in the secure element 201, information about the state of the content application, information about the state of the wireless communication of the content application, information about the authority of the content application, and access information of the content application. Para [0052-0053], The backup data 204 may be encrypted using either a key determined by a server for each content application or a key separately stored in the secure element 201. An initial installation process of the backup data 204 may be described below with reference to FIG. 4. Para [0054-0055], backup data. Fig. 3 and para [0065-0073], The backup data 204 may further include a package including an installation file and an execution file for each content application. Referring to FIG. 3, the backup data 204 may include an A content package 210, which is a package of the A content application 202-1, A content state data 211, a C content package 212, which is a package of the C content application 202-3, and C content state data 213.), and returning the restore image as the software backup to the device external to the SE, to be stored thereon(Lee, para [0065-0072] and para 0073-0074], The electronic device 101 may transmit the backup data 204 to the external electronic device 300. The transmitting of the backup data 204 from the electronic device 101 to the external electronic device 300 may be performed by transmitting the backup data 204 from the request application 205 of the electronic device 101 to the request application 305 of the external electronic device 300.); and if the update process failed, performing a rollback comprising receiving, at the SE from the device external to the SE, the restore image previously returned to the device and loading the restore image into the SE to restore the software backup as a new current software version on the SE (Lee, para [0112-00116], In operation 603, the secure element 201 may install and set the backup data 204. The processor 120 may set state information on a content application included in the backup data 204 to be the same as state information on the backup data 204 included in the electronic device 101. The processor 120 of the electronic device 101 may perform wireless activation of the content application, based on the set state information on the content application. Para [0121-0125], The backup data 204 transmitted to the external electronic device 300, on which integrity verification and decryption may be performed by the external electronic device 300, may be stored in a secure element in the external electronic device 300.). It would have obvious to one having ordinary skill in the art before the effecting filing date of the claimed invention to combine the teachings of cited references. Thus, one of ordinary skill in the art before the effecting filing date of the claimed invention would have been motivated to incorporate Lee into Olinsky to load encrypted backup data (load) from the secure element and transmits the backup data to the external electronic device when the processor receives a message requesting a backup operation from an external electronic device and when receiving a message about the backup completion from the external electronic device to set the backup data to an unusable state. The processor generates the secure element and a secure channel protocol using a key stored in the secure element, and extracts the backup data from the secure element using the secure channel protocol. The backup data is stored in a secure element of the external electronic device.as suggested by Lee (See abstract and summary). The Office would like to use prior art Kim to back up Olinsky and Lee to further teach limitation image (Kim, US 20140149789, para [0020], According to an aspect of another exemplary embodiment, there is provided a software recovery method of an image processing apparatus that is driven by software, the method including: storing reference software; receiving a predetermined command signal to recover current software; and recovering the current software with the stored reference software according to the received predetermined command signal. Fig. 1 and para [0039], he main software, which may be referred to as a main image, may include an application, middleware, drivers, and an operating system (OS), and the main software may be upgraded at a time through a booting process. The main software may be stored in a non-volatile memory such as read only memory (ROM), flash memory, hard disc drive, etc. In addition to the main software for driving, the display apparatus 1 may include various application programs relating to contents. Upgrading refers to replacing current software with a new version, e.g., higher version. Recovery used herein refers to new storage of current software for any reason, e.g., if the current software is not valid. The software used for recovery may be the same version as the current software or different therefrom. Hereinafter, main software will be an example for explaining software recovery and upgrade according to the present exemplary embodiment. Para [0057], This is to determine whether the reference software I is normal, i.e., whether the software image is not broken, and includes, e.g., determination on check-sum or program length. If it is determined that the reference software I is valid, the software recovery unit 15 decodes the reference software I (operation S63), and recovers the software (operation S65).) It would have obvious to one having ordinary skill in the art before the effecting filing date of the claimed invention to combine the teachings of cited references. Thus, one of ordinary skill in the art before the effecting filing date of the claimed invention would have been motivated to incorporate Kim into Olinsky and Lee to recover current software with the stored reference software according to a predetermined command signal. The predetermined command signal is received from a content provider that transmits a broadcasting signal. A user interface generator generates a graphic user interface through which the predetermined command signal is input. as suggested by Kim (See abstract and summary). Claim 17 is rejected for the reasons set forth hereinabove for claim 16, Olinsky, Lee and Kim teach the method according to claim 16, wherein the current software version comprises an operating system of the SE, and wherein the restore image is identified using a flag as being a restore image (Kim, Fig. 1 and para [0039], he main software, which may be referred to as a main image, may include an application, middleware, drivers, and an operating system (OS), and the main software may be upgraded at a time through a booting process. The main software may be stored in a non-volatile memory such as read only memory (ROM), flash memory, hard disc drive, etc. In addition to the main software for driving, the display apparatus 1 may include various application programs relating to contents. Upgrading refers to replacing current software with a new version, e.g., higher version. Recovery used herein refers to new storage of current software for any reason, e.g., if the current software is not valid. The software used for recovery may be the same version as the current software or different therefrom. Hereinafter, main software will be an example for explaining software recovery and upgrade according to the present exemplary embodiment. Para [0057], This is to determine whether the reference software I is normal, i.e., whether the software image is not broken, and includes, e.g., determination on check-sum or program length. If it is determined that the reference software I is valid, the software recovery unit 15 decodes the reference software I (operation S63), and recovers the software (operation S65). Para [0024-0025], The recovering may include: setting a recovery flag corresponding to the predetermined command signal; determining whether the recovery flag is set; and recovering the current software with the reference software if it is determined that the recovery flag is set. Para [0044], As shown in FIG. 1, the software recovery module 10 includes a flag setting unit 11 (e.g., flag setter) which sets a recovery flag corresponding to the command signal, a flag checker 13 which checks whether the recovery flag is set, and a software recovery unit 15 (e.g., current software recoverer) which recovers the current software with the reference software I if it is determined that the recovery flag exists. The flag setting unit 11 which sets the recovery flag may include middleware or an application, and determines whether the recovery flag is set. If the recovery flag exists, a bootstrap loader which controls a booting process loads the reference software I. That is, the flag checker 13 and the software recovery unit 15 are provided by functionally distinguishing the operation of the bootstrap loader. As described above, if the recovery flag is set by the application, the display apparatus 1 enters the rebooting operation, and if the recovery flag is confirmed to exist, the bootstrap loader releases the recovery flag and recovers the software. After recovering the software is executed by using the reference software I, the display apparatus 1 is rebooted again. Para [0056-0057], recover software. Olinsky, para [ 0055] describes backing up the current version; [0056] discloses that these backups may be encrypted, thus making them a secure backup. Para [0069], the saved backup may also be encrypted.). Claim 18 is rejected for the reasons set forth hereinabove for claim 17, Olinsky, Lee and Kim teach the method according to claim 17, wherein the update agent is personalized with data including the cryptographic keys before the restore image is created (Lee, page [0072], The processor 120 of the electronic device 101 may generate the secure element 201 and a secure channel protocol by using a key stored in the secure element 201 and extract the backup data 204 from the secure element 201 by using the secure channel protocol. The key stored in advance in the secure element 201 may be generated in advance for backup authentication. Para [0078, 0093 and 0095], key. Olinsky, para [ 0055] describes backing up the current version; [0056] discloses that these backups may be encrypted, thus making them a secure backup. Para [0069], the saved backup may also be encrypted.); and wherein the update agent handler is configured to return the restore image as the backup software to the device external to the SE(Lee, para [0103], operation 504, the electronic device 101 can transmit backup data. The processor 120 of the electronic device 101 may transmit the backup data 204 to the external electronic device 300. The transmitting of the backup data 204 from the electronic device 101 to the external electronic device 300 may be performed by transmitting the backup data 204 from the request application 205 of the electronic device to the request application 305 of the external electronic device 300. The processor 320 of the external electronic device 300, through the backup application 303, may determine whether the request application 305 of the external electronic device 300 is an approved application, and when the request application 305 is determined to be an approved application, receive the backup data 204.). Claim 19 is rejected for the reasons set forth hereinabove for claim 16, Olinsky, Lee and Kim teach the method according to claim 16, further comprising receiving at the SE a request to update the current software version, the update request comprising a software update, wherein the update process is performed using the software update(Olinsky, para [ 0057], the IoT device updates to the received release in a way that is self-managing and which is robust to failures in the IoT device update. Para [0059-0064], updated release and the updated release becomes the current release). Claim 20 is rejected for the reasons set forth hereinabove for claim 19, Olinsky, Lee and Kim teach the method according to claim 19, wherein upon receiving at the SE the update request, the method comprises further verifying the update request, and if the request is allowed, performing the update process(Olinksky, para [0004], if the updated release is determined to be valid, the updated release is made the current release. Para [0053], upon receiving the indication related to the update for the IoT device, the IoT device validates the update. In some examples, the IoT device validates the update by validating that the update is properly signed.). Claim 21 is rejected for the reasons set forth hereinabove for claim 20, Olinsky, Lee and Kim teach the method according to claim 20, wherein verifying the update request comprises instructing the update agent handler to verify integrity and confidentiality of the update request and of the software update contained therein(Olinksky, para [0004], if the updated release is determined to be valid, the updated release is made the current release. Para [0053], upon receiving the indication related to the update for the IoT device, the IoT device validates the update. In some examples, the IoT device validates the update by validating that the update is properly signed. Para [0061-0062], the determination is a signature check that includes comparing, for each image binary in the updated release, the signature on the image binary with the corresponding signature indicated in the metadata for the image binary… a determination is made as to whether or not the updated release is a forgery. In some examples, the determination at decision block 453 includes a checksum verification.). Claim 22 is rejected for the reasons set forth hereinabove for claim 16, Olinsky, Lee and Kim teach the method according to claim 16, wherein performing at the SE an update process of the current software version comprises updating the current software version based on the software update, deleting the current software version and loading the updated software version into the SE as the new current software version(Olinksy, para [0060-0064], Returning to decision block 452, if it was determined at decision block 452 that the updated release is valid, the process moves to block 458. At block 458, in some examples, the updated release is made the current release. In some examples, this is accomplished by moving the primary pointer to the updated release, so that the updated release becomes the current release. The process then advances to block 459. At block 459, in some examples, the IoT device begins execution of the current release.). Claim 23 is rejected for the reasons set forth hereinabove for claim 22, Olinsky, Lee and Kim teach the method according to claim 22, wherein the update process is determined to have failed if during the performing of the software update process, the software update process is aborted before being completed(Olinksy, para [0062], At block 455, in some examples, the update is rejected and the current release is maintained. In some examples, the IoT device notifies the cloud service that the update is rejected. The process then proceeds to block 459.). Claim 24 is rejected for the reasons set forth hereinabove for claim 22, Olinsky, Lee and Kim teach the method according to claim 22, wherein the update process is determined to have failed if after completing the software update process, the update agent handler reboots the new current software version and during the rebooting process a boot failure occurs(Olinsky, para [0064-00665], a release may have been determined to be valid prior to moving the pointer, but upon execution of the release, the release starts to crash. ). Claim 25 is rejected for the reasons set forth hereinabove for claim 24, Olinsky, Lee and Kim teach the method of claim 24, further comprising the update agent handler instructing the update agent to perform the rollback(Olinsky, para [0065-0066], buggy release or unstable release. Para [ 0067], use the previous release to rollback). Claim 26 is rejected for the reasons set forth hereinabove for claim 22, Olinsky, Lee and Kim teach the method according to claim 22, wherein the update process is determined to have failed if after completing the software update process, the new current software version is successfully booted, and the SE determines that there is a data inconsistency between data and applets stored in the SE and the new current software version(Olinsky, para [0065-0066], buggy release or unstable release. Para [0071], erratic behavior. Para [0075], an operator of the cloud service may identify a severe bug or problem with the current release and force a rollback to a prior release to prevent the current release from causing damage or being exploited.). Claim 27 is rejected for the reasons set forth hereinabove for claim 26, Olinsky, Lee and Kim teach the method of claim 26, further comprising the update agent handler determining whether other updates in the SE are operational, and if other updates are not operational, instructing the update agent to perform the rollback(Olinsky, para [0050], the cloud services are capable of initiating both upgrades and downgrades in the release. In some examples, the cloud can force IoT devices to rollback to an old release. ). Claim 28 is rejected for the reasons set forth hereinabove for claim 16, Olinsky, Lee and Kim d teach the method according to claim 16, wherein performing a roll-back to restore the software backup as the current software version on the SE comprises ( Olinsky, para [0065-0066], buggy release or unstable release. Para [ 0067], use the previous release to rollback.): receiving at the SE from the device the software backup , wherein the software backup comprises the restore image (Lee, para [0112-00116], In operation 603, the secure element 201 may install and set the backup data 204. The processor 120 may set state information on a content application included in the backup data 204 to be the same as state information on the backup data 204 included in the electronic device 101. The processor 120 of the electronic device 101 may perform wireless activation of the content application, based on the set state information on the content application. Para [0121-0125], The backup data 204 transmitted to the external electronic device 300, on which integrity verification and decryption may be performed by the external electronic device 300, may be stored in a secure element in the external electronic device 300. ); and checking, by the update agent using the cryptographic keys, integrity and confidentiality of the software backup(Lee, para [0114-0115], In operation 602, the secure element 201 decrypts and verifies the backup data 204. The processor 120 may verify integrity of the backup data 204 stored in the secure element 201 in the electronic device 101 and perform decryption on the backup data 204. An ECDSA may be used to verify the integrity of the backup data 204. The processor 120 of the electronic device 101 may verify the integrity of the backup data 204 by verifying an elliptic curve digital signature of the backup data 204.); instructing by the update agent handler the update agent to perform loading of the software backup into the SE( Olinsky, para [0065-0066], buggy release or unstable release. Para [ 0067], use the previous release to rollback.). Claim 29 rejected, Olinsky teaches a secure element(Olinsky, para [0004], IoT device), SE, comprising an update agent handler (Olinsky, para [0052]-[0053]: daemon) and an update agent(Olinsky, implicit: the code on the IoT device performing the update), wherein the update agent handler is configured to(Olinsky, abstract and summary): receive from the device a request to update the current software version, the update request comprising a software update, and to instruct the update agent to perform an update process of the current software version by using the software update(Olinsky, para [ 0057], the IoT device updates to the received release in a way that is self-managing and which is robust to failures in the IoT device update. Para [0059-0064], updated release and the updated release becomes the current release); and if the update process failed, instruct the update agent to perform a rollback to restore the software backup as a new current software version on the SE(Olinsky, para [0065-0066], buggy release or unstable release. Para [ 0067], use the previous release to rollback). Olinsky does not explicitly teach receive from a device external to the SE a request to backup a current version of software loaded on the SE, instruct the update agent to generate a restore image corresponding to the current software version loaded on the SE by encapsulating the current software version and securing the restore image with cryptographic keys, and return the restore image as the software backup to the device external to the SE, to be stored thereon; if the update process failed, receive from the device external to the SE the restore image and instruct the update agent to perform a rollback by loading the restore image into the SE to restore the software backup as a new current software version on the SE. However, Lee teaches receive from a device external to the SE a request to backup a current version of software loaded on the SE (Lee, US 20230029025, fig. 5 and para [0100], In operation 502, the external electronic device 300 can approve backup. The processor 120 of the external electronic device 300 may receive the message about the backup data 204, and based on the received message, determine whether the request application 205 requesting the backup operation is a reliable request application. The received message, for example, may include an ID of the electronic device 101, an ID of the request application 205, and the like.), instruct the update agent to generate a restore image corresponding to the current software version loaded on the SE by encapsulating the current software version and securing the restore image with cryptographic keys (Lee, fig. 5 and para [0101], In operation 503, the electronic device 101 can load backup data. The processor 120 of the electronic device 101 may load the backup data 204 for content applications from the secure element 201 through the request application 205 and the backup application 203. Loading the backup data 204 may be implemented as the request application 205 requests the backup data 204 via the backup application 203, and the backup application 203 verifies the received request and transmits the backup data 204 to the request application 205. Para [0102], The processor 120 of the electronic device 101 may generate the secure element 201 and a secure channel protocol by using a key stored in the secure element 201 and extract the backup data 204 from the secure element 201 by using the secure channel protocol. Fig. 2 and para [0049-0051], The backup data 204 may further include a package including an installation file and an execution file for each content application. The backup data 204 may further include a hash value for at least one of list information about the content application included in the secure element 201, information about the state of the content application, information about the state of the wireless communication of the content application, information about the authority of the content application, and access information of the content application. Para [0052-0053], The backup data 204 may be encrypted using either a key determined by a server for each content application or a key separately stored in the secure element 201. An initial installation process of the backup data 204 may be described below with reference to FIG. 4. Para [0054-0055], backup data. Fig. 3 and para [0065-0073], The backup data 204 may further include a package including an installation file and an execution file for each content application. Referring to FIG. 3, the backup data 204 may include an A content package 210, which is a package of the A content application 202-1, A content state data 211, a C content package 212, which is a package of the C content application 202-3, and C content state data 213.), and return the restore image as the software backup to the device external to the SE, to be stored thereon (Lee, para [0065-0072] and para 0073-0074], The electronic device 101 may transmit the backup data 204 to the external electronic device 300. The transmitting of the backup data 204 from the electronic device 101 to the external electronic device 300 may be performed by transmitting the backup data 204 from the request application 205 of the electronic device 101 to the request application 305 of the external electronic device 300.); and if the update process failed, receive from the device external to the SE the restore image and instruct the update agent to perform a rollback by loading the restore image into the SE to restore the software backup as a new current software version on the SE (Lee, para [0112-00116], In operation 603, the secure element 201 may install and set the backup data 204. The processor 120 may set state information on a content application included in the backup data 204 to be the same as state information on the backup data 204 included in the electronic device 101. The processor 120 of the electronic device 101 may perform wireless activation of the content application, based on the set state information on the content application. Para [0121-0125], The backup data 204 transmitted to the external electronic device 300, on which integrity verification and decryption may be performed by the external electronic device 300, may be stored in a secure element in the external electronic device 300.). It would have obvious to one having ordinary skill in the art before the effecting filing date of the claimed invention to combine the teachings of cited references. Thus, one of ordinary skill in the art before the effecting filing date of the claimed invention would have been motivated to incorporate Lee into Olinsky to load encrypted backup data (load) from the secure element and transmits the backup data to the external electronic device when the processor receives a message requesting a backup operation from an external electronic device and when receiving a message about the backup completion from the external electronic device to set the backup data to an unusable state. The processor generates the secure element and a secure channel protocol using a key stored in the secure element, and extracts the backup data from the secure element using the secure channel protocol. The backup data is stored in a secure element of the external electronic device.as suggested by Lee (See abstract and summary). The Office would like to use prior art Kim to back up Olinsky and Lee to further teach limitation image (Kim, US 20140149789, para [0020], According to an aspect of another exemplary embodiment, there is provided a software recovery method of an image processing apparatus that is driven by software, the method including: storing reference software; receiving a predetermined command signal to recover current software; and recovering the current software with the stored reference software according to the received predetermined command signal. Fig. 1 and para [0039], he main software, which may be referred to as a main image, may include an application, middleware, drivers, and an operating system (OS), and the main software may be upgraded at a time through a booting process. The main software may be stored in a non-volatile memory such as read only memory (ROM), flash memory, hard disc drive, etc. In addition to the main software for driving, the display apparatus 1 may include various application programs relating to contents. Upgrading refers to replacing current software with a new version, e.g., higher version. Recovery used herein refers to new storage of current software for any reason, e.g., if the current software is not valid. The software used for recovery may be the same version as the current software or different therefrom. Hereinafter, main software will be an example for explaining software recovery and upgrade according to the present exemplary embodiment. Para [0057], This is to determine whether the reference software I is normal, i.e., whether the software image is not broken, and includes, e.g., determination on check-sum or program length. If it is determined that the reference software I is valid, the software recovery unit 15 decodes the reference software I (operation S63), and recovers the software (operation S65).) It would have obvious to one having ordinary skill in the art before the effecting filing date of the claimed invention to combine the teachings of cited references. Thus, one of ordinary skill in the art before the effecting filing date of the claimed invention would have been motivated to incorporate Kim into Olinsky and Lee to recover current software with the stored reference software according to a predetermined command signal. The predetermined command signal is received from a content provider that transmits a broadcasting signal. A user interface generator generates a graphic user interface through which the predetermined command signal is input. as suggested by Kim (See abstract and summary). Claim 30 rejected, Olinsky teaches an apparatus external to a secure element, SE,the apparatus, comprising at least one processor, at least one memory including computer program code, and the at least one processor with the at least one memory and the computer program code, being arranged to cause the apparatus to at least perform(Olinsky, abstract and summary): requesting the SE to update the current software version, and receiving from the SE an update result(Olinsky, para [ 0057], the IoT device updates to the received release in a way that is self-managing and which is robust to failures in the IoT device update. Para [0059-0064], updated release and the updated release becomes the current release); and if the update result indicates an update process failure, instructing the SE to perform a rollback to restore the software backup stored in the memory as a new current software version on the SE(Olinsky, para [0065-0066], buggy release or unstable release. Para [ 0067], use the previous release to rollback). Olinsky does not explicitly teach requesting [[a]]the secure element, SE, to perform a secure backup of a current version of software loaded on the SE, including creation at the SE of a restore image corresponding to the current software version loaded on the SE by encapsulating the current software version and securing the restore image with cryptographic keys; receiving from the SE the restore image as a software backup of the current software version loaded on the SE, and storing the software backup in the memory; if the update result indicates an update process failure, sending the restore image stored in the memory to the SE and instructing the SE to perform a rollback by loading the restore image into the SE to restore the software backup stored in the memory as a new current software version on the SE. However, Lee teaches requesting the secure element, SE, to perform a secure backup of a current version of software loaded on the SE, including creation at the SE of a restore image corresponding to the current software version loaded on the SE by encapsulating the current software version and securing the restore image with cryptographic keys (Lee, fig. 5 and para [0101], In operation 503, the electronic device 101 can load backup data. The processor 120 of the electronic device 101 may load the backup data 204 for content applications from the secure element 201 through the request application 205 and the backup application 203. Loading the backup data 204 may be implemented as the request application 205 requests the backup data 204 via the backup application 203, and the backup application 203 verifies the received request and transmits the backup data 204 to the request application 205. Para [0102], The processor 120 of the electronic device 101 may generate the secure element 201 and a secure channel protocol by using a key stored in the secure element 201 and extract the backup data 204 from the secure element 201 by using the secure channel protocol. Fig. 2 and para [0049-0051], The backup data 204 may further include a package including an installation file and an execution file for each content application. The backup data 204 may further include a hash value for at least one of list information about the content application included in the secure element 201, information about the state of the content application, information about the state of the wireless communication of the content application, information about the authority of the content application, and access information of the content application. Para [0052-0053], The backup data 204 may be encrypted using either a key determined by a server for each content application or a key separately stored in the secure element 201. An initial installation process of the backup data 204 may be described below with reference to FIG. 4. Para [0054-0055], backup data. Fig. 3 and para [0065-0073], The backup data 204 may further include a package including an installation file and an execution file for each content application. Referring to FIG. 3, the backup data 204 may include an A content package 210, which is a package of the A content application 202-1, A content state data 211, a C content package 212, which is a package of the C content application 202-3, and C content state data 213. Lee, para [0065-0072] and para 0073-0074], The electronic device 101 may transmit the backup data 204 to the external electronic device 300. The transmitting of the backup data 204 from the electronic device 101 to the external electronic device 300 may be performed by transmitting the backup data 204 from the request application 205 of the electronic device 101 to the request application 305 of the external electronic device 300.); receiving from the SE the restore image as a software backup of the current software version loaded on the SE, and storing the software backup in the memory (Lee, US 20230029025, fig. 5 and para [0100], In operation 502, the external electronic device 300 can approve backup. The processor 120 of the external electronic device 300 may receive the message about the backup data 204, and based on the received message, determine whether the request application 205 requesting the backup operation is a reliable request application. The received message, for example, may include an ID of the electronic device 101, an ID of the request application 205, and the like.); if the update result indicates an update process failure, sending the restore image stored in the memory to the SE and instructing the SE to perform a rollback by loading the restore image into the SE to restore the software backup stored in the memory as a new current software version on the SE (Lee, para [0112-00116], In operation 603, the secure element 201 may install and set the backup data 204. The processor 120 may set state information on a content application included in the backup data 204 to be the same as state information on the backup data 204 included in the electronic device 101. The processor 120 of the electronic device 101 may perform wireless activation of the content application, based on the set state information on the content application. Para [0121-0125], The backup data 204 transmitted to the external electronic device 300, on which integrity verification and decryption may be performed by the external electronic device 300, may be stored in a secure element in the external electronic device 300.). It would have obvious to one having ordinary skill in the art before the effecting filing date of the claimed invention to combine the teachings of cited references. Thus, one of ordinary skill in the art before the effecting filing date of the claimed invention would have been motivated to incorporate Lee into Olinsky to load encrypted backup data (load) from the secure element and transmits the backup data to the external electronic device when the processor receives a message requesting a backup operation from an external electronic device and when receiving a message about the backup completion from the external electronic device to set the backup data to an unusable state. The processor generates the secure element and a secure channel protocol using a key stored in the secure element, and extracts the backup data from the secure element using the secure channel protocol. The backup data is stored in a secure element of the external electronic device.as suggested by Lee (See abstract and summary). The Office notes that Lee also teaches an apparatus external to a secure element, SE(Lee, fig. 3, secure element 201 and external electronic device 300) The Office would like to use prior art Kim to back up Olinsky and Lee to further teach limitation image (Kim, US 20140149789, para [0020], According to an aspect of another exemplary embodiment, there is provided a software recovery method of an image processing apparatus that is driven by software, the method including: storing reference software; receiving a predetermined command signal to recover current software; and recovering the current software with the stored reference software according to the received predetermined command signal. Fig. 1 and para [0039], he main software, which may be referred to as a main image, may include an application, middleware, drivers, and an operating system (OS), and the main software may be upgraded at a time through a booting process. The main software may be stored in a non-volatile memory such as read only memory (ROM), flash memory, hard disc drive, etc. In addition to the main software for driving, the display apparatus 1 may include various application programs relating to contents. Upgrading refers to replacing current software with a new version, e.g., higher version. Recovery used herein refers to new storage of current software for any reason, e.g., if the current software is not valid. The software used for recovery may be the same version as the current software or different therefrom. Hereinafter, main software will be an example for explaining software recovery and upgrade according to the present exemplary embodiment. Para [0057], This is to determine whether the reference software I is normal, i.e., whether the software image is not broken, and includes, e.g., determination on check-sum or program length. If it is determined that the reference software I is valid, the software recovery unit 15 decodes the reference software I (operation S63), and recovers the software (operation S65).) It would have obvious to one having ordinary skill in the art before the effecting filing date of the claimed invention to combine the teachings of cited references. Thus, one of ordinary skill in the art before the effecting filing date of the claimed invention would have been motivated to incorporate Kim into Olinsky and Lee to recover current software with the stored reference software according to a predetermined command signal. The predetermined command signal is received from a content provider that transmits a broadcasting signal. A user interface generator generates a graphic user interface through which the predetermined command signal is input. as suggested by Kim (See abstract and summary). Inquiry 8. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DUY KHUONG THANH NGUYEN whose telephone number is (571)270-7139. The examiner can normally be reached Monday - Friday 0800-1630. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lewis Bullock can be reached on 5712723759. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DUY KHUONG T NGUYEN/ Primary Examiner, Art Unit 2199
Read full office action

Prosecution Timeline

Jan 26, 2024
Application Filed
Sep 26, 2025
Non-Final Rejection mailed — §103
Dec 29, 2025
Response Filed
Apr 07, 2026
Final Rejection mailed — §103
Jul 07, 2026
Request for Continued Examination
Jul 09, 2026
Response after Non-Final Action
Sep 15, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748583
AUTOMOTIVE SECURITY CONFIGURATION MANAGEMENT
2y 9m to grant Granted Sep 29, 2026
Patent 12730622
RELAY DEVICE AND NON-TRANSITORY COMPUTER-READABLE STORAGE MEDIUM
2y 10m to grant Granted Sep 08, 2026
Patent 12730611
POLICY CONTROLLED FUNCTION GENERATORS
2y 5m to grant Granted Sep 08, 2026
Patent 12717566
RECOMMENDING VERSION UPDATES FOR SOFTWARE PACKAGES
3y 11m to grant Granted Aug 25, 2026
Patent 12717558
Spreadsheet-Based Software Application Development
2y 8m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
82%
Grant Probability
99%
With Interview (+34.0%)
2y 8m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 570 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month