Prosecution Insights
Last updated: August 17, 2026
Application No. 18/425,303

MANAGING DATA PROCESSING SYSTEMS BASED ON MOTION DATA

Final Rejection §103
Filed
Jan 29, 2024
Examiner
CHANG, TOM Y
Art Unit
2455
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
2 (Final)
53%
Grant Probability
Moderate
3-4
OA Rounds
1y 7m
Est. Remaining
73%
With Interview

Examiner Intelligence

Grants 53% of resolved cases
53%
Career Allowance Rate
242 granted / 454 resolved
-4.7% vs TC avg
Strong +20% interview lift
Without
With
+20.0%
Interview Lift
resolved cases with interview
Typical timeline
4y 1m
Avg Prosecution
21 currently pending
Career history
479
Total Applications
across all art units

Statute-Specific Performance

§101
11.6%
-28.4% vs TC avg
§103
48.5%
+8.5% vs TC avg
§102
17.5%
-22.5% vs TC avg
§112
14.0%
-26.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 454 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is responsive to communication received on 06/12/2026. Claims 1-4, 8-14 and 16-24 are pending of which claims 1,14, 16 and 19 are amended, claims 21-24 new, the remainder of claims remain as originally presented. The Examiner recommends filing a written authorization for Internet communication in response to the present action. Doing so permits the USPTO to communicate with Applicant using Internet email to schedule interviews or discuss other aspects of the application. Without a written authorization in place, the USPTO cannot respond to Internet correspondence received from Applicant. The preferred method of providing authorization is by filing form PTO/SB/439, available at: https://www.uspto.gov/patent/forms/forms. See MPEP § 502.03 for other methods of providing written authorization. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claim 1-4, 8-14 and 16-24 rejected on the ground of nonstatutory double patenting as being unpatentable over claim 1-20 of U.S. Patent No. 12,598,213 in view of Sambamurthy US 2014/0282965. US 12,588,213 teaches all the limitation with action performed responsive to a policy in response to motion detection include sending of alerts and disable a trusted platform module as shown below. 12,598,213 claim1 does not aspect of the more specific determination of gait pattern. Sambamurthy in the same field of endeavor teach a system for security and access control of devices based upon biometrics include gait pattern. It would have been obvious to a person of ordinary skill in the art at the effective filing of the instant application to combine the location based behavior determination with the specific use of gait pattern to access user device access. The rationale for such a combination would be provide a additional method to identify thieves and theft of data/devices. 18/425,303 US 12,598,213 1. A method obtaining motion data for the data processing system, the motion data being usable to characterize a gait pattern for a person transporting the data processing system while the motion data is obtained; performing, at least in part, by a management controller of the data processing system, a motion analysis process using the motion data to determine whether the gait pattern of the motion data is expected for the data processing system; andin a first instance of the performing of the motion analysis process where it is determined that the gait pattern is not expected for the data processing system: identifying, by the management controller, a policy for the data processing system that, at least in part, governs operation of the data processing system, and initiating, by the management controller, performance of an action set based on the policy to update the operation of the data processing system to place the data processing system in an elevated security state wherein the action set comprises preventing, by the management controller, the data processing system from both decrypting and signing data structures by disabling a trusted platform module of the data processing system based on whether the gait pattern of the motion data is expected. 1. A method for managing a data processing system, the method comprising: obtaining, by a management controller of the data processing system and via an out-of-band communication channel, at least one policy from a provisioning server, Sambamurthy ¶65 Sambamurthy ¶92 Sambamurthy ¶92, 45 wherein the at least one policy is to be enforced while the data processing system is within a geographical region and indicates a desired manner of operation of the data processing system while the data processing system is within the geographical region; after obtaining the at least one policy, obtaining, by the management controller and via the out-of-band communication channel, location data for the data processing system, the data processing system comprises a single network module that is shared by both of the management controller and hardware resources of the data processing system, and the single network module being adapted to separately advertise network endpoints for the management controller and the hardware resources such that first communications meant for the hardware resources never flow through the management controller and second communications meant for the management controller never flow through the hardware resources; identifying, by the management controller, applicability of the at least one policy based on the location data; and in a first instance of the identifying where the at least one policy is applicable: making an identification regarding whether the data processing system is operating out of compliance with respect to the at least one policy, and in a first instance of the identification where the data processing system is operating out of compliance: performing, by the management controller, an action set based on the at least one policy to update operation of the data processing system to improve compliance of the data processing system with respect to the at least one policy; and providing, by the data processing system, a computer-implemented service based on the updated operation, wherein to enter the desired manner of operation, an action set is performed, the action set comprising disabling, by the management controller, a trusted platform module of the data processing system. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 4-11, 16 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Sambamurthy US 2014/0282965 and further in view of Mannan et al US 2017/0230179. Regarding claims 1, 16 and 19, Sambamurthy teaches a method, non-transitory CRM and system for managing a data processing system, comprising: obtaining motion data for the data processing system, the motion data being usable to characterize a gait pattern for a person transporting the data processing system while the motion data is obtained(SCED of device such as installed on a smart phone obtains motion data characterizing the activity of a user, the motion including gaIe data) [0065] Is also noted that the SCED may not only interface with the camera and the computer device, but also with any other type of biometric input device, such as skin recognition, iris recognition, galvanic resistant, heartbeat monitoring, gait monitoring, etc. [0069] In one embodiment, the SCED provides a side-band communications channel to the secure server. The SCED measures and tracks digital and physical activities (e.g., presence, motions, etc.) and establishes a link between the digital and physical activities of the user. In another embodiment, the SCED shares the same network communication path as the computer device. [0152] In one embodiment, the interaction data further includes one or more of a mouse input, an audio input, a biometric signal for the user, a geographic location of the user, a name of an active application interfaced by the user, an operation to save data to an external device, or an operation to print. In yet another embodiment, the screen captures are performed periodically with an interval between 1 and 10 seconds, although other intervals are also possible. performing, at least in part, by a management controller of the data processing system, a motion analysis process using the motion data to determine whether the gait pattern of the motion data is expected for the data processing system(determine the user patterns and behaviors fall outside of security model, patterns including gait, ¶s 65,92) [0065] Is also noted that the SCED may not only interface with the camera and the computer device, but also with any other type of biometric input device, such as skin recognition, iris recognition, galvanic resistant, heartbeat monitoring, gait monitoring, etc. [0092] In operation 708, the schema generation produces tags, identifies security-critical data, etc., as well as generating alerts based on the security model. A graph, search, analytics, and report generation engine produces security data for the administrator. For example, the security system may identify user patterns and behaviors as well as the times when the behaviors fall outside the security model. In this case, an alert is generated for the administrator identifying the unusual or unsafe behavior. and in a first instance of the performing of the motion analysis process where it is determined that the gait pattern is not expected for the data processing system(if behavior is outside the mode perform an action such as send and alert, ¶92): [0092] In operation 708, the schema generation produces tags, identifies security-critical data, etc., as well as generating alerts based on the security model. A graph, search, analytics, and report generation engine produces security data for the administrator. For example, the security system may identify user patterns and behaviors as well as the times when the behaviors fall outside the security model. In this case, an alert is generated for the administrator identifying the unusual or unsafe behavior. identifying, by the management controller, a policy for the data processing system that, at least in part, governs operation of the data processing system(security policy defines action responsive to detection such as generation of alerts, ¶84), [0084] The data store 632 includes several types of data, such as raw data related to computer use (e.g., images, inputs, screen captures, etc.), "cleansed" data (e.g., data that results from filtering the raw data according to some criteria), alert schema (e.g., events defined in the security policy that create alerts for administrator), and model results after applying the model to the data. The alert schema may identify potential security threats, such as a user accessing confidential documents that include words like "proprietary" or "confidential." and initiating, by the management controller, performance of an action set based on the policy to update the operation of the data processing system to place the data processing system in an elevated security state(action can be performed based on rules of a policy such as alerting a administrator, ¶84). [0084] The data store 632 includes several types of data, such as raw data related to computer use (e.g., images, inputs, screen captures, etc.), "cleansed" data (e.g., data that results from filtering the raw data according to some criteria), alert schema (e.g., events defined in the security policy that create alerts for administrator), and model results after applying the model to the data. The alert schema may identify potential security threats, such as a user accessing confidential documents that include words like "proprietary" or "confidential." Although Sambamurthy teaches a system including a TPM, Sambamurthy does not specifically teach disabling the TPM. Thus, Sambamurthy does not teach wherein the action set comprises preventing, by the management controller, the data processing system from both decrypting and signing data structures by disabling a trusted platform module of the data processing system based on whether the gait pattern of the motion data is expected. Mannan in the same field of endeavor as the invention teaches and method and system for protecting of computing devices from theft and intrusion. Mannan teaches wherein the action set comprises preventing, by the management controller, the data processing system from both decrypting and signing data structures by disabling a trusted platform module of the data processing system based on whether the gait pattern of the motion data is expected. [0080] “Biometric” information as used herein may refer to, but is not limited to, data relating to a user characterized by data relating to a subset of conditions including, but not limited to, their environment, medical condition, biological condition, physiological condition, chemical condition, ambient environment condition, position condition, neurological condition, drug condition, and one or more specific aspects of one or more of these said conditions. Accordingly, such biometric information may include, but not be limited, blood oxygenation, blood pressure, blood flow rate, heart rate, temperate, fluidic pH, viscosity, particulate content, solids content, altitude, vibration, motion, perspiration, EEG, ECG, energy level, etc. In addition, biometric information may include data relating to physiological characteristics related to the shape and/or condition of the body wherein examples may include, but are not limited to, fingerprint, facial geometry, baldness, DNA, hand geometry, odor, and scent. Biometric information may also include data relating to behavioral characteristics, including but not limited to, typing rhythm, gait, and voice. Regarding claim 4, Sambamurthy teaches wherein the motion data is obtained using at least one sensing component of the data processing system from a list of sensing components consisting of: an accelerometer; a gyroscope; a magnetometer; and a global positioning system sensor(authentication to gain access to device includes biometric authentication, ¶68,80, failure of authentication can trigger lockout of TPM until explicit reset, ¶250) [0068] “Secret” and “password” as used herein and throughout this disclosure, refer to secret information in textual, graphical, electronic, or in any other format upon providing of which access is given to a predefined and secured data, storage, or system. Secrets prove identity of accessor or accessing system to a computer system. The term “password” means the exact same thing as “secret” throughout this disclosure. Examples of secret or password include, but are not limited to, password, passphrase, graphical password, cognitive password, biometric information, data sequence, security token, time synchronized one-time password, etc., or a combination of secrets (e.g., as used in multi-factor authentication schemes). [0080] The data 610 may be captured for any digital or physical activity of the user, such as, mouse inputs, audio inputs, display updates, screen captures, external device being utilized (e.g., plugging in a thumb drive), biometric signals of the user (face, iris, fingerprints, heartbeat, temperature, weight, briefing patterns, etc.), location of the user (e.g., GPS data), timestamps, etc. [0250] As we attempt to consecutively access one to three NVRAM indices with the same user password, i.e., until we can unlock a key or fail at all three authdata-protected indices, we effectively treat NVRAM authdata protection as generic decryption. Therefore, TPM actually counts each failed attempt as a violation and may enter a lockout state where TPM will not respond to subsequent operations until an explicit reset or timeout occurs; for details, see under dictionary attack considerations in the TPM specification. TPM vendors are required to provide “some protection” against such attacks, and actual mechanisms are vendor specific whilst more robust counter measures have also been proposed within the prior art It would have been obvious to a person of ordinary skill in the art before the effective filing of the invention to modify Sambamurthy with ockout of the TPM as taught by Mannan. The reason for this modification would be to protect stealing of secrets and encryption keys stored in the TPM. Regarding claim 8, Sambamurthy teaches wherein the action set comprises providing, by the management controller and via an out-of-band communication channel and to a service system, a notification indicating that the gait pattern is unexpected(communicate alert to administrator upon determination of non-confirming gait pattern, communication via sidelink/out of band communication link). [0058] The security control integrated circuit 402 shares a link to the host computer with the display panel IC. This link provides the data to be displayed on the monitor and may utilize one or more different protocols such as HDMI, DVI, DP, etc. In addition, the security control IC 402 utilizes the side band network interface 408 to communicate with a remote security server without having to rely on networking resources from the host. The side band network interface 408 may utilize one or more communications protocols selected from a group consisting of USB, serial port, Ethernet, WiFi, Bluetooth, GPRS, any mobile communications protocol, etc. [0084] The data store 632 includes several types of data, such as raw data related to computer use (e.g., images, inputs, screen captures, etc.), "cleansed" data (e.g., data that results from filtering the raw data according to some criteria), alert schema (e.g., events defined in the security policy that create alerts for administrator), and model results after applying the model to the data. The alert schema may identify potential security threats, such as a user accessing confidential documents that include words like "proprietary" or "confidential." Regarding claim 9, Sambamurthy teaches wherein the notification is provided while a portion of hardware resources of the data processing system are inoperable(communication of a security alert to a administrator using sideband and not the regular network is implied since communication to a security server uses the sideband communication, ¶s58,95) [0058] The security control integrated circuit 402 shares a link to the host computer with the display panel IC. This link provides the data to be displayed on the monitor and may utilize one or more different protocols such as HDMI, DVI, DP, etc. In addition, the security control IC 402 utilizes the side band network interface 408 to communicate with a remote security server without having to rely on networking resources from the host. The side band network interface 408 may utilize one or more communications protocols selected from a group consisting of USB, serial port, Ethernet, WiFi, Bluetooth, GPRS, any mobile communications protocol, etc [0095] In one embodiment, the user may be also notified that the user has triggered a security alert, such as when the user is accessing a confidential file. Once the user is notified, the user may contact the administrator to explain the identified security alert. Regarding claim 10, Sambamurthy teaches wherein the policy is obtained by the management controller via an out-of-band communication channel and from a service system tasked with managing policies for the data processing system(security server transmits policies to the SCED via sideband link to enforce access control, ¶s 58,132). [0058] The security control integrated circuit 402 shares a link to the host computer with the display panel IC. This link provides the data to be displayed on the monitor and may utilize one or more different protocols such as HDMI, DVI, DP, etc. In addition, the security control IC 402 utilizes the side band network interface 408 to communicate with a remote security server without having to rely on networking resources from the host. The side band network interface 408 may utilize one or more communications protocols selected from a group consisting of USB, serial port, Ethernet, WiFi, Bluetooth, GPRS, any mobile communications protocol, etc [0132] In one embodiment, a security circuit is attached to the bus and controls the output to LCD, by interfacing with the circuitry that drives the LCD (e.g., processor and pixel memory). In addition, the SCED 1114 sends security data to the security server and receives security and configuration commands from the security server. In one embodiment, the security server sends authorized user information to the SCED regarding the users authorized to utilize the computing device, the policy rules for implementing security in the computing device, login parameters, authenticated devices that may be coupled to the computing device, etc. Regarding claim 11, Sambamurthy teaches wherein when the data processing system is in the elevated security state, data previously accessible via the data processing system is inaccessible via the data processing system(authentication is continuous meaning access can be granted to data but once authentication fails access is denied), ¶s111,112) [0111] In operation 860, access is granted to the user through the network access device. From operation 860, the method flows to operation 862 were continuous authentication and monitoring of user activities is performed. In operation 864, a check is made to determine if the authentication fails at any point in time. If the user continues being authenticated, the method flows back to operation 862, but if the authentication fails at any time, the method flows to operation 866. [0112] In operation 866, the access to the network access device is denied due to the failure of the authentication, and from operation 866 the method flows back to operation 852. In other embodiments (not shown), after the authentication fails, the method uses another loop to perform continuous authentication while access is disabled, and if the authentication is reestablished, the method goes back to operation 860 to obtain access to the network access device. Claims 2, 17 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Sambamurthy/Mannan as applied to claim 1 above, and further in view of Lee US 2017/0227995. Regarding claims 2, 17 and 20, Sambamurthy teaches a remote security server sending security policies to be enforced on the computing device using out of band communication(¶s 127,132) and teaches a machine learning(i.e.self-learning) algorithm to generate the model but is unclear as to which entity performs the self-learning model generation. Thus Sambamurthy does not teach prior to obtaining the motion data and during a provisioning process for the data processing system: obtaining, by the data processing system, initial motion data for the data processing system while a person authorized to transport the data processing system is transporting the data processing system, providing, by the management controller and via an out-of-band communication channel and to a service system, the initial motion data, and obtaining, by the management controller and via the out-of-band communication channel and from the service system, a gait signature, the gait signature being based on the initial motion data. Lee in the same field of endeavor as the invention teaches a system for biometric authentication including gait biometrics(walking behavioral model, ¶35). Lee teaches prior to obtaining the motion data and during a provisioning process for the data processing system: obtaining, by the data processing system, initial motion data for the data processing system while a person authorized to transport the data processing system is transporting the data processing system(during an enrollment phase the initial data from sensors is captured such data including walking behavior (i.e. gait),¶35) [0035] One embodiment of the enrollment phase is depicted in FIG. 2. At the simplest level, sensor data is first gathered (22). This data can be gathered in a variety of ways; for example, a sensor can be continuously sending data or the sensor can send data only in certain conditions. For example, a given sensor may only send data continuously when it detects motion, or a given sensor may be requested to send data gathered within a period of time before, during, and after when a legitimate user is using an explicit form of authentication (such as signing in with a password, pin, or using some biometric sensor). Once the data is sent, features of that sensor data are extracted (23), and an authentication model is trained (25) based on those extracted features. In some embodiments, a context model (21) is used to improve accuracy. The use of context models stems from the observation that users' behavioral patterns are often different from person to person, and vary under different usage contexts, when they use devices such as smartphones and wearables such as smartwatches or smartglasses. For embodiment, a person's behavior may be different when they are walking versus when they are riding a subway, versus when they are sitting in a chair at home. Instead of authenticating the user with one unified model, it may be better to utilize different finer-grained models to authenticate the user based on different usage contexts. For embodiment, using a user's walking behavioral model to authenticate the same user who is sitting while using the smartphone will likely be less accurate than having an authentication process that determines whether the user is walking or sitting, then using the appropriate authentication model. Thus, in FIG. 2, some or all of the extracted features (23), which may all be in the frequency domain, all in the time domain, or some combination of both, can be combined with the context model (21) to enable a system to detect context (24). That detected context (24) can be used with some or all of the extracted features (23) to train the authentication model (25) as well. providing, by the management controller and via the communication channel and to a service system, the initial motion data, and(initial enrollment phase included sending sensor data for training an authentication model where the training is performed on a remote server(i.e. security server), ¶9) [0009]…The method may also include an enrollment phase that includes receiving sensor data, sending the data for use in training an authentication model, and receiving the authentication model, whether the training is done by a remote server, or by the device itself such as a smartphone. In response to a failed authorization attempt, the method may also include blocking further access to a device or generating an alert. The sensor sampling rate may also be adjustable. This method may be conducted via a smartphone application. As such, it may also include utilizing sensors that do not generate data that is of concern for privacy, that would have required permission for those measurements to be used if they were used on the smartphone (such as GPS sensors, camera sensors, or microphones). The method may also include rapidly training an authentication model, such as when the training time is less than about 20 seconds. The method may also be utilized when the sensor is in one device, the authentication is accomplished in a second device, and a third device is optionally requesting the results of the authentication. obtaining, by the management controller and via the communication channel and from the service system, a gait signature, the gait signature being based on the initial motion data(the authentication model is returned to the device that performs the authentication .. from the remote device(i.e.security server) to the computing device(¶9), the authentication model based on user walking walking patterns(i.e. signature), ¶65) [0009]…The method may also include an enrollment phase that includes receiving sensor data, sending the data for use in training an authentication model, and receiving the authentication model, whether the training is done by a remote server, or by the device itself such as a smartphone. In response to a failed authorization attempt, the method may also include blocking further access to a device or generating an alert. The sensor sampling rate may also be adjustable. This method may be conducted via a smartphone application. As such, it may also include utilizing sensors that do not generate data that is of concern for privacy, that would have required permission for those measurements to be used if they were used on the smartphone (such as GPS sensors, camera sensors, or microphones). The method may also include rapidly training an authentication model, such as when the training time is less than about 20 seconds. The method may also be utilized when the sensor is in one device, the authentication is accomplished in a second device, and a third device is optionally requesting the results of the authentication. [0065] Therefore, in one embodiment, two sensors were selected, the accelerometer and gyroscope, because they have higher FS scores and furthermore, are the most common sensors built into current smartphones and smartwatches. These two sensors also represent different information about the user's behavior: 1) the accelerometer records coarse-grained motion patterns of a user, such as how she walks; and 2) the gyroscope records fine-grained motions of a user such as how she holds a smartphone. Furthermore, these sensors do not need the user's permissions, making them useful for continuous background monitoring in implicit authentication scenarios, without requiring user interaction. In some embodiments, only a single sensor is used. In others, two or more are used. It would have been obvious to a person of ordinary skill in the art before the time of the effective filing of the instant application to modify Sambamurthy security server communicating security rules/polices using out of band communication with performing the machine learning training of an authentication model at a remote device such as the security server as taught by Lee. The reason for this modification would be to relieve the computing device of the burden to perform machine learning by offloading such task to the security server. Claims 3 and 18 is rejected under 35 U.S.C. 103 as being unpatentable over Sambamurthy/Mannan/Lee as applied to claim 2 and 17 above, and further in view of Phillips US 2019/0213597. Regarding claims 3 and 18, The combination of Sambamurthy/Mannan/Lee do not teach wherein performing the motion analysis process comprises: obtaining the gait pattern based on the motion data; comparing the gait pattern to the gait signature for the data processing system identify a level of similarity between the gait pattern and the gait signature; making a determination regarding whether the gait pattern is expected for the data processing system based on the level of similarity; and in a first instance where the level of similarity exceeds a similarity threshold: treating the gait pattern as unexpected. Phillips in the same field of endeavor as the invention teaches a system for transaction authentication using biometrics such as gait signatures. Phillips teaches wherein performing the motion analysis process comprises: obtaining the gait pattern based on the motion data(gait signature from sensors is obtained and compared to a gait authentication signature that is expected for a user, ¶23) comparing the gait pattern to the gait signature for the data processing system identify a level of similarity between the gait pattern and the gait signature(gait signature is compared to expected gait signature and if a match within a threshold similarity is judged as matching, ¶23) making a determination regarding whether the gait pattern is expected for the data processing system based on the level of similarity(gait signature is compared to expected gait signature and if a match withing a threshold similarity is judged as matching, ¶23) and in a first instance where the level of similarity exceeds a similarity threshold: treating the gait pattern as unexpected(if beyond threshold of similarity user in not authentic and transaction is denied or delayed, ¶23,72) [0023] Authentication device 230 includes one or more devices capable of receiving, generating, storing, processing, and/or providing information associated with authentication based on sensor data. For example, authentication device 230 may include a communication and/or computing device, such as a server computer, personal computer, mobile phone, laptop computer, tablet computer, or a similar type of device. Authentication device 230 may be capable of analyzing sensor data to produce sensor based signatures, produce sensor data that can be compared to the signatures, and/or determine whether sensor data matches a signature. Signatures may be based on a variety of authentication, such as object recognition methods (e.g., facial recognition, fingerprint recognition, retina recognition, voice recognition, and/or the like), gait recognition, ocular recognition, and/or the like. For example, authentication device 230 may include a gait authentication device that uses raw sensor data as input (e.g., gait sensor data, such as GPS, accelerometer, and/or gyroscope data) to produce a gait signature for a user. An example gait recognition device may also be capable of using raw sensor data to convert the sensor data into gait data that can be compared to a gait signature. Additionally, or alternatively, an example gait recognition device may perform authentication by comparing gait data to a gait signature to determine whether a match exists (e.g., an exact match or a match within a threshold degree of similarity). [0072] In some implementations, the action may include denying or holding the transaction, e.g., pending additional confirmation and/or authentication. For example, if transaction server 220 does not confirm and/or authenticate a transaction, transaction server 220 may cause the transaction to be denied or held (e.g., by holding or denying the transaction at the transaction server 220 and/or notifying a third party associated with the transaction—such as a bank associated with the user of the first user device 210 and/or second user device 210). Denying and/or holding the transaction may enable the user of the first user device 210 and/or the user of the second user device 210 to retry confirmation and/or authentication of the transaction in the same or a similar manner, or using a different form of confirmation and/or authentication. Holding and/or denying a transaction based on lack of confirmation and/or authentication may increase the security of transactions performed by user devices 210 that make use of transaction server 220 to confirm and/or authenticate transactions. It would have been obvious to a person of ordinary skill in the art before the time of the effective filing date of the instant application to modify Sambamurthy/Mannan/Lee’s gait based authentication with determining the a threshold level of similarity is determined. The reason for this modification would be to ensure that sufficient similarity to the gait signature for stronger authentication. Claims 12-13 are rejected under 35 U.S.C. 103 as being unpatentable over Sambanurthy/Mannan as applied to claim 1 above, and further in view of Shah US 2013/0326039. Regarding claim 12, Sambamurthy does not teach wherein the data processing system comprises a network module adapted to separately advertise network endpoints for the management controller and hardware resources of the data processing system, the network endpoints being usable by a service system to address communications to the hardware resources and the management controller. Shah in the same field of endeavor as the invention teaches a system for a network controller with integrated management controller. Shah teaches wherein the data processing system comprises a network module adapted to separately advertise network endpoints for the management controller and hardware resources of the data processing system, the network endpoints being usable by a service system to address communications to the hardware resources and the management controller(network control provide connection and routing of regular network traffic to host and management traffic to management controllers(ie. BMCs out-of band management), ¶s28, 51) [0028] The integration provides, in one NC 102, all of the network ports and interfaces for both network controller functions and management controller functions. As noted above, the network ports can be individually configured to allow any combination of management and network communication traffic. Packet filtering and merging logic facilitates delivering traffic to the appropriate controller or host and sending and receiving both network and management communications over the same port. [0051] Additionally, one or more network interfaces may be provided in the NC 102 for network traffic (e.g., LAN traffic). The network interfaces may include one or more ports, for example, each of which may support a certain traffic rate (e.g., 100 Mbps or 1 Gbps). The network interfaces may include port configuration logic that is operable to specify, on a global or individual basis whether any particular port or group of ports is permitted to carry or support: 1) network communication traffic for the network controller but no management communication traffic for the management controller; 2) management communication traffic but no network communication traffic; 3) both network communication traffic and management communication traffic; and 4) neither network communication traffic nor management communication traffic. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the instant application to modify Sambamurthy/Mannan with network controller that handles both network and management traffic as taught by Shah. The reason for this modification would be to provide more efficient connection that processes both normal host traffic and management traffic relieving the need for a dedicated management port on a device. Regarding claim 13, Shah teaches wherein an out-of-band communication channel that services the management controller runs through the network module, and an in-band communication channel that services the hardware resources also runs through the network module(management and regular network traffic through same network interface, ¶51) [0051] Additionally, one or more network interfaces may be provided in the NC 102 for network traffic (e.g., LAN traffic). The network interfaces may include one or more ports, for example, each of which may support a certain traffic rate (e.g., 100 Mbps or 1 Gbps). The network interfaces may include port configuration logic that is operable to specify, on a global or individual basis whether any particular port or group of ports is permitted to carry or support: 1) network communication traffic for the network controller but no management communication traffic for the management controller; 2) management communication traffic but no network communication traffic; 3) both network communication traffic and management communication traffic; and 4) neither network communication traffic nor management communication traffic. Claims 14 and 21 are rejected under 35 U.S.C. 103 as being unpatentable over Sambamurthy/Mannan as applied to claim 1 above, and further in view of Kariman US 2015/0208195. Regarding 14, Sambamurthy/Mannan does not teach wherein the management controller and a network module of the data processing system are on separate power domains from hardware resources of the data processing system so that the management controller and the network module are operable while the hardware resources are unpowered, wherein the motion analysis process is performed while the hardware resources are unpowered, and wherein the action set comprises providing, by the management controller and the network module, a notification to a service system via an out-of-band communication channel. Kariman in the same field of endeavor as the invention teaches a system for remote management and monitoring of computing devices. Kariman teaches wherein the management controller and a network module of the data processing system are on separate power domains from hardware resources of the data processing system so that the management controller and the network module are operable while the hardware resources are unpowered(system includes in-band hardware and out-of-band hardware with different power sources(i.e. domains), separate power supplies allow location/motion reporting to occur in case of theft ¶s 17,23) [0017] FIG. 4 illustrates an exemplary embodiment of the disclosed invention, where the circuitry that operates the network access software 3 and/or the out-of-band operating system 2 is powered from a separate power source 8 than the electronic device 7. In another exemplary embodiment, the location detection system 4 may be communicatively coupled with the electronic device 7 in a way that allows the in-band operating system 1 and the out-of-band operating system 2 to exchange data with the location detection system 4 while it is communicatively coupled with the electronic device. Therefor the location detection system 4 can be detached and uncoupled with the electronic device 7. [0023] One exemplary embodiment includes a method and apparatus of providing persistent out-of-band geographic location information of an electronic device. An electronic device is equipped with a GPS receiver embedded into the device circuitry and an out-of-band stack that is independent from the in-band stack, as exemplified in this disclosure. Upon a certain command received from a server, for example in an event of device loss or theft, and/or in the event if the device geographic location information was not received within a set timeframe, and/or in the event of an alert received from the device in-band stack, and/or upon any other condition or the lack thereof, the out of band stack on the device activates a GPS receiver and transmits the geographical location information to the server. The server then stores this information in a database and visualizes this information, for example, on an electronic map upon a request of the operating personnel. In another exemplary embodiment, the out-of-band stack may initialize GPS upon a certain trigger, such as a signal from an accelerometer sensor indicative of the device movement or an impact. In another exemplary embodiment, the out-of-band stack may initialize GPS periodically, on schedule, to send geographical location updates to a remote server. In another exemplary embodiment, the out-of-band stack may initialize GPS upon a certain unique set of conditions, such as receiving a triggering data form the in-band operating system and upon receiving a certain combination of parameters from plurality of sensors coupled with the electronic device. In another exemplary embodiment, the out-of-band stack may transmit to a remote server identifying indicia of the electronic device at the time of transmission of geographical location information or at any other time. In another exemplary embodiment, the out-of-band stack may transmit to a remote server identifying indicia of the electronic device and transmit geographic location information, in one exemplary embodiment, after receiving a request from the remote server or not receiving a request, or upon some other condition. wherein the motion analysis process is performed while the hardware resources are unpowered(when in-band circuitry is obstructed or turned off such as in the case of theft, location reporting and other theft mitigation action can still be performed, ¶s4,6,23) [0004] On the other end of the spectrum are consumers and businesses that also need reliable and persistent LBS. For example, they need to track and prevent theft of electronic equipment, such as laptops and phones; provide services, such as automotive fleet tracking, cargo tracking, and help controlling access to assets based on their location, etc. Another important area of LBS application is tracking and securing network-enabled embedded devices. One of the limiting factors of proliferation of the Internet-enabled embedded devices is the lack of cost-efficient, robust security controls to provide sufficient security in the context of the emerging use-models--persistent LBS plays here an important role. [0006] One consequence of this inscrutability is that providing persistent LBS oftentimes requires installing additional controls that are bulky, expensive, and often resource consuming. Conventional LBS-enabled systems have a major drawback that if the system's main electronics are powered off or the operating system (or LBS related executable code) hung or crashed, or obstructed, LBS services would be no longer available. While some LBS-enabled systems provide additional controls enhancing the reliability and persistence, they still depend on the same set of electronics and software used to operate the system. An example could be a personal computer equipped with GPS receiver, and network software stack executed in the OS that facilitates the geo-location data acquisition and transmission from the GPS receiver to a remote website. If the Operating System (OS) crashes, the location-data will no longer be available. Therefore, additional integrated out-of-band controls are required to provide secure and persistent LBS, both for local use and use by a remote system. [0023] One exemplary embodiment includes a method and apparatus of providing persistent out-of-band geographic location information of an electronic device. An electronic device is equipped with a GPS receiver embedded into the device circuitry and an out-of-band stack that is independent from the in-band stack, as exemplified in this disclosure. Upon a certain command received from a server, for example in an event of device loss or theft, and/or in the event if the device geographic location information was not received within a set timeframe, and/or in the event of an alert received from the device in-band stack, and/or upon any other condition or the lack thereof, the out of band stack on the device activates a GPS receiver and transmits the geographical location information to the server. The server then stores this information in a database and visualizes this information, for example, on an electronic map upon a request of the operating personnel. In another exemplary embodiment, the out-of-band stack may initialize GPS upon a certain trigger, such as a signal from an accelerometer sensor indicative of the device movement or an impact. In another exemplary embodiment, the out-of-band stack may initialize GPS periodically, on schedule, to send geographical location updates to a remote server. In another exemplary embodiment, the out-of-band stack may initialize GPS upon a certain unique set of conditions, such as receiving a triggering data form the in-band operating system and upon receiving a certain combination of parameters from plurality of sensors coupled with the electronic device. In another exemplary embodiment, the out-of-band stack may transmit to a remote server identifying indicia of the electronic device at the time of transmission of geographical location information or at any other time. In another exemplary embodiment, the out-of-band stack may transmit to a remote server identifying indicia of the electronic device and transmit geographic location information, in one exemplary embodiment, after receiving a request from the remote server or not receiving a request, or upon some other condition. and wherein the action set comprises providing, by the management controller and the network module, a notification to a service system via an out-of-band communication channel(a notification to include location information of the devices is sent to a monitoring server/manager using out of band power/hardware, ¶23) [0023] One exemplary embodiment includes a method and apparatus of providing persistent out-of-band geographic location information of an electronic device. An electronic device is equipped with a GPS receiver embedded into the device circuitry and an out-of-band stack that is independent from the in-band stack, as exemplified in this disclosure. Upon a certain command received from a server, for example in an event of device loss or theft, and/or in the event if the device geographic location information was not received within a set timeframe, and/or in the event of an alert received from the device in-band stack, and/or upon any other condition or the lack thereof, the out of band stack on the device activates a GPS receiver and transmits the geographical location information to the server. The server then stores this information in a database and visualizes this information, for example, on an electronic map upon a request of the operating personnel. In another exemplary embodiment, the out-of-band stack may initialize GPS upon a certain trigger, such as a signal from an accelerometer sensor indicative of the device movement or an impact. In another exemplary embodiment, the out-of-band stack may initialize GPS periodically, on schedule, to send geographical location updates to a remote server. In another exemplary embodiment, the out-of-band stack may initialize GPS upon a certain unique set of conditions, such as receiving a triggering data form the in-band operating system and upon receiving a certain combination of parameters from plurality of sensors coupled with the electronic device. In another exemplary embodiment, the out-of-band stack may transmit to a remote server identifying indicia of the electronic device at the time of transmission of geographical location information or at any other time. In another exemplary embodiment, the out-of-band stack may transmit to a remote server identifying indicia of the electronic device and transmit geographic location information, in one exemplary embodiment, after receiving a request from the remote server or not receiving a request, or upon some other condition. It would have been obvious to a person of ordinary skill in the art before the effective filing of the invention to implement apply the concept of a separate power supply to the management controller as taught by Kariman to provide a separate power to the security device of Sambamurthy/Mannan. The reason for this modification would be to allow management function such as monitoring of the device even if the device is obstructed or turned off due to theft. Regarding claim 21. Kariman teaches wherein the hardware resources comprise at least one sensing component of the data processing system(out of band power source allow location tracking even when in-band hardware are obstructed/turned off, ¶17) and wherein, while the hardware resources are unpowered, the management controller manages power to the at least one sensing component of the hardware resources in order to obtain the motion data(out of band power source allow location tracking using GPS sensing hardware even when in-band hardware are obstructed/turned off, ¶17) [0017] FIG. 4 illustrates an exemplary embodiment of the disclosed invention, where the circuitry that operates the network access software 3 and/or the out-of-band operating system 2 is powered from a separate power source 8 than the electronic device 7. In another exemplary embodiment, the location detection system 4 may be communicatively coupled with the electronic device 7 in a way that allows the in-band operating system 1 and the out-of-band operating system 2 to exchange data with the location detection system 4 while it is communicatively coupled with the electronic device. Therefor the location detection system 4 can be detached and uncoupled with the electronic device 7. Claims 22-24 are rejected under 35 U.S.C. 103 as being unpatentable over Sambamurthy/Mannan/Shah/Kariman as applied to claim 14 above, and further in view of Berger US 2014/0020123. Regarding claim 22, Sambamurthy/Mannan/Shah/Kariman do not teach wherein the notification to the service system comprises instructions for a security measure in addition to the elevated security state of the data processing system. Berger in the same field of endeavor teaches an embedded theft deterrence system. Berger teaches wherein the notification to the service system comprises instructions for a security measure in addition to the elevated security state of the data processing system(based on motion detection/gps sensing a platformi(.e. computing device/laptop with embedded theft response) will determine platform has been stolen and place platform in suspecting status (i.e. state) , ¶s61, 213) [0061] In one embodiment, the platform 210 sends movement information, from motion sensor 226 and/or BSSID and RSSI sensor 228, or GPS receiver 227, to the security server 280. The movement information is evaluated by movement evaluator 284, to determine whether the platform is being stolen. If so, security server 280 may send an alert, via alerting logic 290. In one embodiment, security server 280 also has messaging for exit control system 288. Exit control system 288 sends messages to a controlled exit point upon suspicion of theft of the platform. A controlled exit point may be an exit point with a guard who can be alerted, a gate or door that can be locked, or an exit point with a different type of exit control mechanism. When the message from the security server 280 is received, the exit is locked and/or the guard is alerted, to enable them to search. [0213] If a "suspecting" status update is received from the platform, at block 2820, the process continues to block 2825. At block 2825, the process determines whether the suspecting mode was entered because of an attempt to override the disarming in the armed or suspecting modes. If so, at block 2830 the system alerts the controlled exit point. This may include alerting a guard, locking a gate, sounding an audio alarm at the exit point or throughout the building, or other actions. In one embodiment, some of these actions may take place with a time delay. For example, before alerting guards, the system may provide sufficient time for a user to disarm his platform, in case this was a false positive. In one embodiment, in order to further reduce false positives, the platform may locally provide an indicator to the user, so that he is aware that the platform is in suspecting mode and that further significant movement with it will cause the guards to be alerted. This indicator may be a visual indicator, an audio indicator, or another type of indicator. It would have been obvious to a person of ordinary skill in the art before the effective filing of the invention to modify Sambamurthy/Mannan/Shah/Kariman with tracking location of the platform to report theft and perform other antitheft actions. The reason for this modification would be to protect assets from theft and effective recovery of assets. Regarding claim 23, Berger teaches comprising, based on the instructions for the security measure, elevating a security state of a building associated with the data processing system( theft status is reported to security guards of a building, ¶213). [0213] If a "suspecting" status update is received from the platform, at block 2820, the process continues to block 2825. At block 2825, the process determines whether the suspecting mode was entered because of an attempt to override the disarming in the armed or suspecting modes. If so, at block 2830 the system alerts the controlled exit point. This may include alerting a guard, locking a gate, sounding an audio alarm at the exit point or throughout the building, or other actions. In one embodiment, some of these actions may take place with a time delay. For example, before alerting guards, the system may provide sufficient time for a user to disarm his platform, in case this was a false positive. In one embodiment, in order to further reduce false positives, the platform may locally provide an indicator to the user, so that he is aware that the platform is in suspecting mode and that further significant movement with it will cause the guards to be alerted. This indicator may be a visual indicator, an audio indicator, or another type of indicator. Regarding claim 24, Berger teaches comprising locking an exit point of the building in response to elevating the security state of the building(locking the gate of the building upon suspecting status determination, ¶213). Applicant Remarks Applicant’s arguments with respect to claims 1-4, 8-14 and 16-24 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Tom Y. Chang whose telephone number is 571-270-5938. The examiner can normally be reached on Monday-Friday from 9am to 5pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Emmanuel Moise, can be reached on (571)272-3865. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center. Status information for published applications may be obtained from Patent Center. Status information for unpublished applications is available through Patent Center for authorized users only. Should you have questions about access to Patent Center, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated- interview-request-air-form. /TOM Y CHANG/ Primary Examiner, Art Unit 2455
Read full office action

Prosecution Timeline

Jan 29, 2024
Application Filed
Mar 17, 2026
Non-Final Rejection mailed — §103
Jun 12, 2026
Response Filed
Jul 28, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699597
SYSTEMS AND METHODS FOR IMPLEMENTING TRANS-CLOUD APPLICATION TEMPLATES
4y 10m to grant Granted Aug 04, 2026
Patent 12627665
ADMITTING AN ENTITY COMPUTING DEVICE TO A NETWORK BASED ON A SIGNAL STRENGTH AND NETWORK CONDITIONS
2y 9m to grant Granted May 12, 2026
Patent 12547828
TRAFFIC-BASED GPU LOAD ROUTING WITHIN LLM CLUSTERS
2y 0m to grant Granted Feb 10, 2026
Patent 12542838
METHODS, DEVICES, AND SYSTEMS FOR DETERMINING A SUBSET FOR AUTONOMOUS SHARING OF DIGITAL MEDIA
1y 11m to grant Granted Feb 03, 2026
Patent 12536243
SYSTEM AND METHOD FOR URL FETCHING RETRY MECHANISM
2y 9m to grant Granted Jan 27, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
53%
Grant Probability
73%
With Interview (+20.0%)
4y 1m (~1y 7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 454 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month