Prosecution Insights
Last updated: October 02, 2026
Application No. 18/392,805

SYSTEMS AND METHODS FOR PERFORMING REMOTE ATTESTATION ON LEGACY TECHNOLOGY

Non-Final OA §103
Filed
Dec 21, 2023
Examiner
MAHMOUDI, RODMAN ALEXANDER
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
Denso Corporation
OA Round
3 (Non-Final)
80%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
204 granted / 254 resolved
+22.3% vs TC avg
Strong +16% interview lift
Without
With
+16.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
18 currently pending
Career history
279
Total Applications
across all art units

Statute-Specific Performance

§101
8.2%
-31.8% vs TC avg
§103
57.7%
+17.7% vs TC avg
§102
15.4%
-24.6% vs TC avg
§112
12.8%
-27.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 254 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Examiner’s Remarks In view of the appeal brief filed on 03/25/2026, PROSECUTION IS HEREBY REOPENED. A new ground of rejection is set forth below. To avoid abandonment of the application, appellant must exercise one of the following two options: (1) file a reply under 37 CFR 1.111 (if this Office Action is non-final) or a reply under 37 CFR 1.113 (if this Office Action is final); or, (2) initiate a new appeal by filing a notice of appeal under 37 CFR 41.31 followed by an appeal brief under 37 CFR 41.37. The previously paid notice of appeal fee and appeal brief fee can be applied to the new appeal. If, however, the appeal fees set forth in 37 CFR 41.20 have been increased since they were previously paid, then appellant must pay the difference between the increased fees and the amount previously paid. A Supervisory Patent Examiner (SPE) has approved of reopening prosecution by signing below: Response to Amendments This communication is in response to the amendments filed on 3 September 2025: Claims 1, 4, 8, 11, 15 and 18 are amended. Claims 1-20 are pending. Response to Arguments In response to Applicant’s remarks filed in the Notice of Appeal on 20 March 2026: a. Applicant’s arguments on Page 4 that the claim requires the steps of “initiating a secure boot with the device in response to the predetermined condition not being present…” has been fully considered and is deemed fully persuasive. Applicant’s attention is directed to the new grounds of rejection presented in this Office Action. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-2, 4, 8, 11 and 15-16 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Kornegay et al. (U.S. PGPub. 2018/0196945), hereinafter Kornegay, in view of GORU et al. (U.S. PGPub. 2020/0017066), hereinafter Goru, in further view of Huang (U.S. PGPub. 2024/0070285). Regarding claim 1, Kornegay teaches A method for performing remote attestation on legacy technology input (Kornegay, Paragraph [0010], see “…the data traffic module having computer executable code stored thereon configured to provide remote attestation of the one or more legacy components to a trusted remote host computer outside of the system”), the method comprising: sending an integrity request to a Root of Trust (ROT) (Kornegay, Paragraph [0026], see “…integrity measuring by computing hashes of executable code, configuration data, and other system state information…thus establishing a root-of-trust within such heterogeneous network environment”) (Kornegay, Paragraph [0027], see “Data traffic module 100 is thus configured to provide integrity measurement to the various legacy components in the non-TPM enabled network 10…”, where “Data traffic module 10” is being read as being comprised in the system that acts as a root-of-trust in heterogeneous computer networks and provides one or more of remote attestation, integrity measuring, secure boot operations, remote authentications, etc., therefore, an integrity request/attestation request/secure boot request is received by the system to provide the different features); sending an attestation request from the ROT to a device, the attestation request comprising an encrypted secret (Kornegay, Paragraph [0010], see “…the data traffic module having computer executable code stored thereon configured to provide remote attestation of the one or more legacy components to a trusted remote host computer outside of the system”) (Kornegay, Paragraph [0027], see “Data traffic module 100 is thus configured to provide integrity measurement to the various legacy components…The hashtags are used in remote attestation to reliably establish code identity to remote or local verifiers…A secret can be sealed along with a list of hashtags of programs…”); verifying at least one of authenticity, integrity, and freshness of the attestation request with the device (Kornegay, Paragraph [0009], see “…remote attestation, which allows a trusted device to present reliable evidence to remote parties about the software it is running”) (Kornegay, Paragraph [0025], see “…the data traffic module 100 to perform remote attestation and authentication on each respective legacy computing device 208 in order to prevent firmware downgrade/rollback attacks”, which is verifying authenticity and integrity of the attestation request with the device); Kornegay does not teach the following limitation(s) as taught by Goru: performing a safety test configured to determine whether a predetermined condition is present (Goru, Paragraph [0035], see “…when where the vehicle 1 is not parked, meaning that the vehicle 1 is moving, a test is made in order to determine whether a child is present in the child seat…”, which is analogous to performing a safety test configured to determine whether a predetermined condition is present (a vehicle is moving)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, by implementing techniques of performing a safety test configured to determine whether a vehicle is moving, disclosed of Goru. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of performing a safety test configured to determine whether a vehicle is moving. This allows for better security management and safety to determine whether a vehicle is in a predetermined condition during the safety test. Goru is deemed as analogous art due to the art disclosing techniques of performing a safety test configured to determine whether a vehicle is moving (Goru, Paragraph [0035]). Kornegay as modified by Goru do not teach the following limitation(s) as taught by Huang: initiating a secure boot with the device in response to the predetermined condition not being present (Huang, Paragraph [0008], see “…the bootloader is further configured to: determine whether the secure boot process is initiated based on a cold reset command or a warm reset command in response to the hash value not matching the pre-stored hash value…”, which is analogous to initiating a secure boot with the device in response to the predetermined condition not being presented (i.e., the hash values not matching)); in response to the secure boot being successful, the device creates a primary message comprising the encrypted secret, and sends the message to the ROT; in response to the secure boot failing, the device creates a secondary message indicating that the secure boot has failed, and sends the message to the ROT (Huang, Paragraph [0028], see “…the bootloader 121 may determine that the secure boot process fails, and the bootloader 121 may cease the secure boot process. In an embodiment, the bootloader 121 may output an alert indicating failure of the secure boot process through transceiver 130…the bootloader 121 may output an alert through the transceiver 130 to an output device such as a display or a buzzer to alert a user that the secure boot process has failed through the output device”, which is analogous to in response to the secure boot failing, creating a message indicating that the secure boot has failed and sending the message to the ROT. Applicant’s attention is directed to the fact that only one of the two limitations consisting of the boot being successful or failing needs to be addressed, due to the fact that only one of them will be initiated). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, and techniques disclosed of Goru, by implementing techniques of initiating a secure boot with the device in response to a predetermined condition not being present and in response to the secure boot failing, sending a message indicating that the secure boot has failed, disclosed of Huang. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of initiating a secure boot with the device in response to a predetermined condition not being present and in response to the secure boot failing, sending a message indicating that the secure boot has failed. This allows for better security management through ensuring continuous system availability, preventing unauthorized operation and limiting security risks in the environment. Huang is deemed as analogous art due to the art disclosing techniques of initiating a secure boot with the device in response to a predetermined condition not being present and in response to the secure boot failing, sending a message indicating that the secure boot has failed (Huang, Paragraph [0028]). Regarding claim 2, Kornegay as further modified by Huang do not teach the following limitation(s) as taught by Goru: The method of claim 1, wherein the legacy technology is related to a vehicle, and the predetermined conditions is at least one of: a vehicle is in drive, the vehicle is not in park, or the vehicle is moving (Goru, Paragraph [0035], see “…when where the vehicle 1 is not parked, meaning that the vehicle 1 is moving, a test is made in order to determine whether a child is present in the child seat…”, which is analogous to performing a safety test configured to determine whether a predetermined condition is present (a vehicle is moving)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, and techniques disclosed of Huang, by implementing techniques of the predetermined condition being when the vehicle is moving, disclosed of Goru. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of the predetermined condition being when the vehicle is moving. This allows for better security management and effectiveness for performing the safety test when the predetermined condition is met. Goru is deemed as analogous art due to the art disclosing techniques of the predetermined condition being when the vehicle is moving (Goru, Paragraph [0035]). Regarding claim 4, Kornegay as modified by Goru do not teach the following limitation(s) as taught by Huang: The method of claim 1, wherein, in response to the secure boot failing, the device creates a message indicating that the secure boot has failed, and sends the message to the ROT (Huang, Paragraph [0028], see “…the bootloader 121 may determine that the secure boot process fails, and the bootloader 121 may cease the secure boot process. In an embodiment, the bootloader 121 may output an alert indicating failure of the secure boot process through transceiver 130…the bootloader 121 may output an alert through the transceiver 130 to an output device such as a display or a buzzer to alert a user that the secure boot process has failed through the output device”, which is analogous to in response to the secure boot failing, creating a message indicating that the secure boot has failed and sending the message to the ROT (i.e., user)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, and techniques disclosed of Goru, by implementing techniques of in response to the secure boot failing, sending a message indicating that the secure boot has failed, disclosed of Huang. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of in response to the secure boot failing, sending a message indicating that the secure boot has failed. This allows for better security management by sending a message that acts as an immediate safety trigger by halting loading unauthorized, corrupted, or malicious code before the system boots. Huang is deemed as analogous art due to the art disclosing techniques of in response to the secure boot failing, sending a message indicating that the secure boot has failed (Huang, Paragraph [0028]). Regarding claims 8 and 15, the claims are rejected under the same reasoning as claim 1. Regarding claims 11 and 18, the claims are rejected under the same reasoning as claim 4. Regarding claim 16, the claim is rejected under the same reasoning as claim 2. Claims 3, 10 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Kornegay, in view of Goru, in further view of Huang, in further view of LIM et al. (U.S. PGPub. 2024/0126887), hereinafter Lim. Regarding claim 3, Kornegay as modified by Goru and further modified by Huang do not teach the following limitation(s) as taught by Lim: The method of claim 1, wherein the primary message further comprises an indication that the secure boot was successful (Lim, Paragraph [0051], see “…the second vehicle controller 20 that is successful in the secure boot may notify another vehicle controller of that the second vehicle controller 20 is successful in the secure boot”, which is analogous to indicating that the secure boot was successful in a message). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, techniques disclosed of Goru, and techniques disclosed of Huang, by implementing techniques of indicating that a secure boot was successful after it has been completed, disclosed of Lim. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of indicating that a secure boot was successful after it has been completed. This allows for better security management and critical assurance that a device’s integrity remains intact, whilst instantly validating system integrity to both users and networks. Lim is deemed as analogous art due to the art disclosing techniques of indicating that a secure boot was successful after it has been completed (Lim, Paragraph [0051]). Regarding claims 10 and 17, the claims are rejected under the same reasoning as claim 3. Claims 5 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Kornegay, in view of Goru, in further view of Huang, in further view of POCHEUV et al. (U.S. PGPub. 2020/0145409), hereinafter Pocheuv. Regarding claim 5, Kornegay as modified by Goru and further modified by Huang do not teach the following limitation(s) as taught by Pocheuv: The method of claim 1, wherein the integrity request is sent from a remote server to the ROT or based on a scheduled task stored by the ROT (Pocheuv, Paragraph [0064], see “…The authentication policy server 112 sends the authentication request 903 to the RoT identity server 114…”, which is analogous to the integrity request being sent from a remote server (authentication policy server) to the ROT (RoT identity server)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, techniques disclosed of Goru, and techniques disclosed of Huang, by implementing techniques of the integrity request being sent from a remote server to the ROT, disclosed of Pocheuv. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of the integrity request being sent from a remote server to the ROT. This allows for better security management and allows for the ROT to access data and resources from anywhere remotely with an internet connection. Pocheuv is deemed as analogous art due to the art disclosing techniques of the integrity request being sent from a remote server to the ROT (Pocheuv, Paragraph [0064]). Regarding claim 12, the claim is rejected under the same reasoning as claim 5. Claims 6, 13 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Kornegay, in view of Goru, in further view of Huang, in further view of Pocheuv, in further view of Xia et al. (U.S. PGPub. 2022/0052919), hereinafter Xia. Regarding claim 6, Kornegay as modified by Goru and further modified by Huang and Pocheuv do not teach the following limitation(s) as taught by Xia: The method of claim 5, further comprising sending a message, with the ROT, to the remote server indicating whether the secure boot was successful or failed (Xia, Paragraph [0077], see “…During a device system boot process, a TPM of a device records a key system status of the device. After a device system is booted up, the device sends a report to a remote server for remote attestation and authentication…”, which is analogous to sending a message with the ROT (e.g., TPM of a device) to a remote server indicating whether the secure boot was successful or failed (i.e., report)). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, techniques disclosed of Goru, techniques disclosed of Huang, and techniques disclosed of Pocheuv, by implementing techniques of sending a message with an ROT to a remote server indicating whether the secure boot was successful or failed, disclosed of Xia. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of sending a message with an ROT to a remote server indicating whether the secure boot was successful or failed. This allows for better security management through guaranteeing device trustworthiness, preventing spoofing and allowing for generating incident responses based on the failed boot. Xia is deemed as analogous art due to the art disclosing techniques of sending a message with an ROT to a remote server indicating whether the secure boot was successful or failed (Xia, Paragraph [0077]). Regarding claims 13 and 19, the claims are rejected under the same reasoning as claim 6. Claims 7, 14 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Kornegay, in view of Goru, in further view of Huang, in further view of Sheth et al. (U.S. PGPub. 2022/0070251), hereinafter Sheth. Regarding claim 7, Kornegay as modified by Goru and further modified by Huang do not teach the following limitation(s) as taught by Sheth: The method of claim 1, further comprising: verifying the integrity of the received integrity request with the ROT (Sheth, Paragraph [0058], see “…the kernel metrics storage service may require that the application provide a nonce in order to prevent MitM and replay attacks. If the kernel metrics storage service successfully validates the connection details provided…”, which is analogous to verifying the integrity of the received integrity request); and verifying the test is safe to proceed based on the verified integrity request (Sheth, Paragraph [0058], see “…If the kernel metrics storage service successfully validates the connection details provided by the application, the kernel metrics storage service may generate a response comprising the requested kernel secure boot metrics for the kernel, the nonce provided by the application, and the description of the connection validated by the kernel metrics storage service,” where “response” is analogous to verifying that the test is safe to proceed based on the verified integrity request). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, techniques disclosed of Goru, and techniques disclosed of Huang, by implementing techniques of verifying the integrity of the integrity request and verifying that the test is safe to proceed based on the verified integrity request, disclosed of Sheth. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of verifying the integrity of the integrity request and verifying that the test is safe to proceed based on the verified integrity request. This allows for better security management by validating the request before providing the details needed to fulfil the request (perform the test)). Sheth is deemed as analogous art due to the art disclosing techniques of verifying the integrity of the integrity request and verifying that the test is safe to proceed based on the verified integrity request (Sheth, Paragraph [0058]). Regarding claims 14 and 20, the claims are rejected under the same reasoning as claim 7. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Kornegay, in view of Goru, in further view of Huang, in further view of SCHMIDT et al. (U.S. PGPub. 2018/0270230), hereinafter Schmidt. Regarding claim 9, Kornegay as modified by Goru and further modified by Huang do not teach the following limitation(s) as taught by Schmidt: The computer program product of claim 8, wherein the computer readable code when executed using one or more computing device processors, cause the one or more computing processors to: perform a safety test and a reboot with the device (Schmidt, Paragraph [0024], see “…the authenticity test is performed when starting up or booting the motor vehicle, when the device and/or the switch device are switched on or taken into operation after a parked phase”). Therefore, it would have been obvious for one of ordinary skill in the art before the effective filing date of the claimed invention to have modified the techniques disclosed of Kornegay, techniques disclosed of Goru, and techniques disclosed of Huang, by implementing techniques of performing a safety test and a reboot with the device, disclosed of Schmidt. One of ordinary skill in the art would have been motivated to make this modification in order to implement techniques for performing remote attestation on legacy technology, comprising of performing a safety test and a reboot with the device. This allows for better security management by performing a safety test alongside a reboot with the device to ensure the device is at its peak performance and capabilities. Schmidt is deemed as analogous art due to the art disclosing techniques of performing a safety test and a reboot with the device (Schmidt, Paragraph [0024]). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to RODMAN ALEXANDER MAHMOUDI whose telephone number is (571)272-8747. The examiner can normally be reached on M-F 11:00am – 7:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached on (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /RODMAN ALEXANDER MAHMOUDI/Examiner, Art Unit 2499 /PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Dec 21, 2023
Application Filed
Jun 11, 2025
Non-Final Rejection mailed — §103
Sep 03, 2025
Response Filed
Dec 23, 2025
Final Rejection mailed — §103
Mar 20, 2026
Notice of Allowance
Mar 25, 2026
Response after Non-Final Action
Apr 12, 2026
Response after Non-Final Action
Jul 13, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730900
SYSTEM DESIGN DEVICE, SYSTEM DESIGN METHOD, AND STORAGE MEDIUM
1y 8m to grant Granted Sep 08, 2026
Patent 12726361
METHOD, APPARATUS, AND COMPUTER-READABLE RECORDING MEDIUM FOR CONTROLLING ACCESS OF USER AND USER TERMINAL THAT ACCESS SERVER SYSTEM USING DIGITAL SIGNATURE
1y 11m to grant Granted Sep 01, 2026
Patent 12711228
Breach Response Data Management System and Method
1y 12m to grant Granted Aug 18, 2026
Patent 12705332
METHOD FOR VERIFYING THE AUTHENTICITY OF AN ACTUATOR COMMAND
3y 0m to grant Granted Aug 11, 2026
Patent 12694092
PRE-REGISTRATION OF AUTHENTICATION DEVICES
2y 0m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
80%
Grant Probability
97%
With Interview (+16.5%)
2y 9m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 254 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month