Prosecution Insights
Last updated: October 02, 2026
Application No. 18/539,536

METHOD FOR PROVIDING INFORMATION ABOUT A SECURITY-CRITICAL SOFTWARE STATE OF AN EMBEDDED DEVICE

Non-Final OA §101§103
Filed
Dec 14, 2023
Priority
Feb 09, 2023 — DE 10 2023 201 038.0
Examiner
PAN, HANG
Art Unit
2193
Tech Center
2100 — Computer Architecture & Software
Assignee
Robert Bosch GmbH
OA Round
3 (Non-Final)
75%
Grant Probability
Favorable
3-4
OA Rounds
6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
481 granted / 644 resolved
+19.7% vs TC avg
Strong +26% interview lift
Without
With
+25.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
23 currently pending
Career history
679
Total Applications
across all art units

Statute-Specific Performance

§101
16.8%
-23.2% vs TC avg
§103
62.9%
+22.9% vs TC avg
§102
7.6%
-32.4% vs TC avg
§112
9.0%
-31.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 644 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to applicant’s RCE filed on 04/29/2026. Claims 1-15 are pending and examined in this office action. Claims 12-15 are new claims. Per claim 11, an “embedded device” is interpreted as a physical device with a processor and memory. Response to Arguments Applicant’s arguments filed on 04/29/2026 have been fully considered. However, they are not persuasive. Per 103 rejection, applicant argued The cited portions of Gottschlich, Galula, and Singh, individually or in combination, do not teach, suggest, or disclose "updating, by the central monitoring unit, the digital twin of the embedded device based on the transmitted information," where the transmitted information is determined about a security-critical software state based on an identifier ascertained from execution traces and includes "at least one of the identifier, information about the identity, the enabled functions of the executed software, and information about distorted fingerprints," as recited in amended claim 1. Neither Gottschlich's alert notifications nor Singh's pre-deployment patch testing constitutes updating a digital twin based on transmitted software-state information in the manner claimed. Accordingly, the Gottschlich-Galula-Singh combination does not teach, suggest, or disclose the digital-twin updating step recited in amended claim 1. The examiner respectfully disagrees. First, Gottschlich discloses sending the information (security-critical software state) to a central monitor unit for a remedial action (paragraphs [0080][0049]-[0052]; application associated with the fingerprint can be marked as blacklisted when the fingerprint classifier determines that the fingerprint is indicative (the security-critical software state) of a malicious, fraudulent, or harmful application; the fingerprint classifier can initiate an alert to notify an external system regarding the application for a remedial action). Then, Singh discloses applying security patch (a remedial action) to a digital twin device and an actual device (Fig. 5; paragraph [0085][0087]; a system level controller at a server; a digital twin is selected and assigned as a backup BBMD for a local BBMD device that is connected to a local subnet, the digital twin is a replica of a local BBMD device, so that upgrades and patches (e.g., operating system updates, security patches) can first be applied and tested on the digital twin before being applied to the actual local BBMD device). Therefore, the combination of Gottschlich and Singh would teach the claim limitation of “updating, by the central monitoring unit, the digital twin of the embedded device based on the provided information”, because after a malicious software is detected in the embedded device, an alert (security-critical software state) is sent to a central monitor unit for a remedial action. Based on the alert, the central monitor unit provides a remedial action (applying a security patch) to protect the embedded device (which includes applying the security patch to the digital twin first). The rationale for above combination is evidenced in Martini (US PGPUB 2018/0069878; paragraphs [0045][0046]; after detecting a client device is exhibiting anomalous behavior commonly associated with a malware; based on this information, the anti-malware system applies a corrective action (remedial action), which includes installing a security patch). Therefore, the examiner believes the combination of Gottschlich and Singh would teach the above claim limitation, see the updated 103 rejection below. Claims 12-15 are rejected under new grounds of rejection. The examiner is available for a phone interview with applicant. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-15 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, mathematical relationship or an abstract idea) without significantly more. Statutory Category: Claim 1 recites a method for providing information about a security-critical software state of an embedded device, wherein, the embedded device has a network connection to a central monitoring unit for central monitoring of the embedded device and of further embedded devices, the method comprising the following steps: ascertaining execution traces of at least one software executed on the embedded device; determining an identifier for the executed software on based on the ascertained execution traces, wherein the identifier is specific to an identity and/or to enabled functions of the executed software; determining the information about the security-critical software state based the identifier; transmitting the information about the security-critical software state for the central monitoring unit via the network connection, wherein the information about the security-critical software state includes at least one of the identifier, information about the identity, the enabled functions of the executed software, and information about distorted fingerprints; and updating, by the central monitoring unit, the digital twin of the embedded device based on the transmitted information. Step 2A – Prong 1: Claim 1 recites: ascertaining execution traces of at least one software executed on the embedded device (a mental step of verification); determining an identifier for the executed software on based on the ascertained execution traces, wherein the identifier is specific to an identity and/or to enabled functions of the executed software (a mental step of determination); determining the information about the security-critical software state based on the identifier (a mental step of determination). These limitations as drafted, is a process that, under their broadest reasonable interpretation, covers an abstract idea of performance of the limitation in the mind or manually. That is, nothing in the claim elements precludes the steps from practically being performed mentally or using pen and paper. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the mental process grouping of abstract idea. Accordingly, the claim recites an abstract idea under step 2A prong 1. This judicial exception is not integrated into a practical application. In particular, the claim 1 recites additional elements such as “transmitting the information about the security-critical software state for the central monitoring unit via the network connection, wherein the information about the security- critical software state includes at least one of the identifier, information about the identity, the enabled functions of the executed software, and information about distorted fingerprints”. Examiner would like to point out that with the broad reasonable interpretation, these elements amount to mere transmitting the result of a mental process, which do not impose any meaningful limits on practicing the mental process (insignificant additional element and a post solution activity). Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to insignificant additional elements under Step 2B. This judicial exception is not integrated into a practical application. In particular, the claim 1 recites additional elements such as updating, by the central monitoring unit, the digital twin of the embedded device based on the transmitted information, which is an extra solution activity of updating a device, that is a Well-Understood, Routine, Conventional (WURC) Activity, as evidenced in Martini (US PGPUB 2018/0069878; paragraphs [0045][0046]; after detecting a client device is exhibiting anomalous behavior commonly associated with a malware; based on this information, the anti-malware system applies a corrective action (remedial action), which includes installing a security patch). Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea under Prong II step 2B. This judicial exception is not integrated into a practical application. In particular, the claim 1 recites additional elements such as “the embedded device has a network connection to a central monitoring unit”. The additional elements in the claim amount to no more than generic hardware component with instructions to apply the exception, which cannot integrate a judicial exception into a practical application or provide an inventive concept. Accordingly, these additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to insignificant additional elements under Step 2B. Dependent claims 2-8, 12-15 do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of dependent claims 2-8 recite more steps of a mental process (comparing, detecting, defining, determining, ascertaining) which can be performed mentally or using pen and paper or recite insignificant additional element and a post solution activity (alerting, transmitting). Therefore, these claims are not patent eligible. Independent claim 9 (a storage medium storing instructions to perform the method of claim 1) is rejected under the similar rational as claim 1. The additional elements in the claim amounts to no more than generic hardware component with instructions to apply the exception, which cannot integrate a judicial exception into a practical application or provide an inventive concept. Independent claim 10 (an apparatus to perform the method of claim 1) is rejected under the similar rational as claim 1. The additional elements in the claim amounts to no more than generic hardware component with instructions to apply the exception, which cannot integrate a judicial exception into a practical application or provide an inventive concept. Independent claim 11 (a system with a processor and memory to perform the method of claim 1) is rejected under the similar rational as claim 1. The additional elements in the claim amounts to no more than generic hardware component with instructions to apply the exception, which cannot integrate a judicial exception into a practical application or provide an inventive concept. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-13 are rejected under 35 U.S.C. 103 as being unpatentable over Gottschlich et al. (US PGPUB 2019/0319977) hereinafter Gottschlich, in view of GALULA et al. (US PGPUB 2020/0216097) hereinafter GALULA, in view of Singh et al. (US PGPUB 2020/0313925) hereinafter Singh. Per claim 1, Gottschlich discloses a method for updating a device, comprising the following steps: ascertaining execution traces of at least one software executed on the device, determining an identifier for the executed software based on the ascertained execution traces, wherein the identifier is specific to an identity and/or to enabled functions of the executed software (paragraphs [0080][0049]-[0051]; a fingerprint for the application is extracted by the fingerprint extractor using the processed telemetry event data and performance monitor unit counter information, processed trace data from the trace processor are combined to form into an application fingerprint (the application fingerprint is an identifier that is specific to an identity of the executed application); determining the information about the security-critical software state based on the identifier; transmitting the information about the security-critical software state for the central monitoring unit via the network connection, wherein the information about the security-critical software state includes at least one of the identifier, information about the identity, the enabled functions of the executed software, and information about distorted fingerprints (paragraphs [0080][0049]-[0052]; application (the identifier) associated with the fingerprint can be marked as blacklisted when the fingerprint classifier determines that the fingerprint is indicative (the security-critical software state) of a malicious, fraudulent, or harmful application; the fingerprint classifier can initiate an alert to notify an external system regarding the application (the identifier) for a remedial action). Gottschlich does not explicitly teach the device is an embedded device and the embedded device has a network connection to a central monitoring unit for central monitoring of the embedded device. However, GALULA suggests the above (paragraphs [0027]-[0028]; a network of embedded devices, and a security layer that can communicate to a server for detecting cyber threats). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Gottschlich and GALULA to apply Gottschlich’s method of detecting malicious application execution to networked embedded devices, this would increase the usage and versatility of Gottschlich’s invention. Gottschlich also does not explicitly teach updating, by the central monitoring unit, the digital twin of the embedded device based on the transmitted information. However, Gottschlich discloses transmitting the information (security-critical software state) to a central monitor unit for a remedial action (paragraphs [0080][0049]-[0052]). Furthermore, Singh discloses applying a remedial action (security patch) to a digital twin device and an actual device (Fig. 5; paragraph [0085][0087]; a system level controller at a server; a digital twin is selected and assigned as a backup BBMD for a local BBMD device that is connected to a local subnet, the digital twin is a replica of a local BBMD device, so that upgrades and patches (e.g., operating system updates, security patches) can first be applied and tested on the digital twin before being applied to the actual local BBMD device). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Gottschlich, GALULA and Singh that an external server (central monitoring unit) provides a digital twins for each embedded device on a network and updating the digital twins with a security update (remedial action) based on provided security information, as this is a common practice in the field of the art to improve the security of a device (see, Martini, US PGPUB 2018/0069878; paragraphs [0045][0046]; after detecting a client device is exhibiting anomalous behavior commonly associated with a malware; based on this information, the anti-malware system applies a corrective action (remedial action), which includes installing a security patch). Per claim 2, Gottschlich further suggests comparing the identifier with at least one specification for determining the identity and/or the enabled functions of the executed software, wherein a match of the identifier with at least one of several entries in a database is ascertained (paragraphs [0050][0051][0060]; the fingerprint classifier compares the fingerprint to one or more cluster prototypes stored in the fingerprint database, distances between a fingerprint and one or more fingerprint clusters can be formed into a classification vector used to classify the fingerprint as malicious or benign based on the classification of the closest clusters); detecting, in an event of a deviation of the identifier from each of the entries of the at least one specification, the security-critical software state based on the comparison; defining the information about the security-critical software state based on the comparison and/or the detection, wherein, in an event that the security-critical software state is detected, a security measure is initiated by a response module of the embedded device, wherein the security measure includes at least one of the following actions: restarting the embedded device, updating the executed software, degrading the embedded device, alerting the central monitoring unit (paragraphs [0080][0049]-[0052][0054]; a deviation in a fingerprint being classified triggers the telemetry analyzer to confirm that the fingerprint has deviated from a fingerprint or cluster of fingerprints stored in the fingerprint database should be classified accordingly as benign or malicious; application associated with the fingerprint can be marked as blacklisted (defining the information), when the fingerprint classifier determines that the fingerprint is indicative (the security-critical software state) of a malicious, fraudulent, or harmful application; the fingerprint classifier can initiate an alert to notify an external system regarding the application and its classification). Per claim 3, Gottschlich further suggests wherein the determining of the information about the security-critical software state is performed by the embedded device by an agent component (paragraphs [0050][0051]; application associated with the fingerprint can be marked as blacklisted when the fingerprint classifier determines that the fingerprint is indicative (the security-critical software state) of a malicious, fraudulent, or harmful application). Per claim 4, Gottschlich in views of GALULA further suggests wherein the central monitoring unit is configured as a backend that is connected to several further embedded devices (Gottschlich, paragraphs [0080][0049]-[0052]; application associated with the fingerprint can be marked as blacklisted when the fingerprint classifier determines that the fingerprint is indicative of a malicious, fraudulent, or harmful application; the fingerprint classifier can initiate an alert to notify an external system (central monitor) regarding the application and its classification; GALULA, paragraphs [0027][0028]; embedded devices in a network); Singh further discloses wherein the central monitoring unit provides additional digital twins of several further embedded devices (Fig. 5; paragraph [0085][0087]; a system level controller at a server; a digital twin is selected and assigned as a backup BBMD for a local BBMD device that is connected to a local subnet, the digital twin is a replica of a local BBMD device, so that upgrades and patches (e.g., operating system updates, security patches) can first be applied and tested on the digital twin before being applied to the actual local BBMD device). Per claim 5, Gottschlich further suggests wherein the information about the security-critical software state provided for the central monitoring unit includes at least one of the following items of information: the identifier, information about the identity and/or the enabled functions of the executed software, a result of comparing the identifier with at least one specification, a result of detecting the security-critical software state based on the comparison (paragraphs [0050]-[0052][0060]; application associated with the fingerprint can be marked as blacklisted when the fingerprint classifier determines that the fingerprint (identifier) is indicative of a malicious, fraudulent, or harmful application; the fingerprint classifier can initiate an alert to notify an external system regarding the application (information about an identity) and its classification (a result of detecting the security-critical software state); The fingerprint classifier compares the fingerprint to one or more cluster prototypes stored in the fingerprint database, distance(s) between a fingerprint and one or more fingerprint clusters can be formed into a classification vector (a result of comparing the identifier with at least one specification) used to classify the fingerprint as malicious or benign based on the classification of the closest cluster). Per claim 6, Gottschlich further suggests wherein the ascertaining of the execution traces includes at least one of the following steps: ascertaining an access of the executed software to memory addresses of the embedded device, ascertaining a file access of the executed software on the embedded device, ascertaining an access to operating system resources of the executed software on the embedded device (paragraphs [0018][0049]; extract application behavioral fingerprints from hardware telemetry, such as central processing unit (CPU) telemetry or from operating system (OS) telemetry; the dynamic similarity vectors measure how similar a sample behaves to known applications, such as using process genealogy, file and registry accesses (ascertaining file access), network activities). Per claim 7, Gottschlich further suggests ascertaining an imprint at hardware or operating system level of the embedded device, the imprint resulting from a software package (paragraph [0018]; extract application behavioral fingerprints from hardware telemetry, such as central processing unit (CPU) telemetry or from operating system (OS) telemetry; Gottschlich does not explicitly the software package is an instrumented software package. However, (official notice), using an instrumented software package to generate application trace is a common practice in the field of the art, as evidenced in Harsha et al. (US PGPUB 2008/0301502, abstract)). Per claim 8, GALULA further suggests wherein the identifier is specific to imprints from a predefined number of sequential execution steps of the software in order to determine the identifier as a stateful fingerprint (paragraph [0073]; a heuristic engine may detect anomalies based on at least one of the following models: detection of anomalous execution patterns (an execution of a specific sequence of programs (a predefined number of sequential execution steps))). Claim 9 is rejected under similar rationales as claim 1. Claim 10 is rejected under similar rationales as claim 1. Claim 11 is rejected under similar rationales as claim 1. Per claim 12, Gottschlich further suggests wherein the information about the security-critical software state includes the identifier (paragraph [0051]; the fingerprint classifier marks a fingerprint and application (identifier) associated with the fingerprint as blacklisted, which indicates the application as a malicious, fraudulent, or harmful application). Per claim 13, Gottschlich further suggests wherein the information about the security-critical software state includes the information about the identity (paragraph [0051]; the fingerprint classifier marks a fingerprint and application (identity) associated with the fingerprint as blacklisted, which indicates the application as a malicious, fraudulent, or harmful application). Claim 14 is rejected under 35 U.S.C. 103 as being unpatentable over Gottschlich, in view of GALULA, in view of Singh, and in view of Das et al. (US PGPUB 2013/0097659) hereinafter Das. Per claim 14, Gottschlich does not explicitly teach wherein the information about the security-critical software state includes the enabled functions of the executed software. However, Das suggests the above (paragraphs [0021][0031]; analyzing an application's fingerprint to determine enabled functions of the application). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Gottschlich, GALULA, Singh and Das to include the enabled functions of the executed software in the information about the security-critical software state, as this information is useful in security analysis of an executed application. Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Gottschlich, in view of GALULA, in view of Singh, and in view of Petry et al. (US PGPUB 2019/0075130) hereinafter Petry. Per claim 15, Gottschlich does not explicitly teach wherein the information about the security-critical software state includes the information about the distorted fingerprints. However, Petry suggests (paragraphs [0058][0059]; an application's fingerprint may be altered/distorted during security analysis). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Gottschlich, GALULA, Singh and Das to include altered/distorted fingerprints of the executed software in the information about the security-critical software state, as this information is useful in security analysis of an executed application. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to HANG PAN whose telephone number is (571)270-7667. The examiner can normally be reached 9 AM to 5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Chat Do can be reached at 571-272-3721. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HANG PAN/Primary Examiner, Art Unit 2193
Read full office action

Prosecution Timeline

Dec 14, 2023
Application Filed
Oct 07, 2025
Non-Final Rejection mailed — §101, §103
Dec 05, 2025
Response Filed
Dec 29, 2025
Final Rejection mailed — §101, §103
Apr 29, 2026
Request for Continued Examination
May 02, 2026
Response after Non-Final Action
Sep 14, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743364
WORKFLOW IMPACT ANALYSIS
2y 7m to grant Granted Sep 22, 2026
Patent 12730741
SERVICE CONFIGURATION METHOD AND APPARATUS
3y 5m to grant Granted Sep 08, 2026
Patent 12730629
LIVE FIRMWARE UPDATE SWITCHOVER
3y 0m to grant Granted Sep 08, 2026
Patent 12718106
SOFTWARE TEST CASE MAINTENANCE
2y 9m to grant Granted Aug 25, 2026
Patent 12711044
System and method to dynamically configure cloud resources
2y 6m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
75%
Grant Probability
99%
With Interview (+25.6%)
3y 3m (~6m remaining)
Median Time to Grant
High
PTA Risk
Based on 644 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month