Prosecution Insights
Last updated: October 01, 2026
Application No. 18/592,314

ENHANCED SUBSTATION GATEWAY-BASED OPERATIONAL TECHNOLOGY SECURITY MONITORING AND AUTOMATED RESPONSE

Final Rejection §103§112
Filed
Feb 29, 2024
Examiner
MACILWINEN, JOHN MOORE JAIN
Art Unit
2454
Tech Center
2400 — Computer Networks
Assignee
GE Infrastructure Technology LLC
OA Round
4 (Final)
68%
Grant Probability
Favorable
5-6
OA Rounds
1y 4m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 68% — above average
68%
Career Allowance Rate
465 granted / 689 resolved
+9.5% vs TC avg
Strong +28% interview lift
Without
With
+27.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
18 currently pending
Career history
718
Total Applications
across all art units

Statute-Specific Performance

§101
9.5%
-30.5% vs TC avg
§103
55.6%
+15.6% vs TC avg
§102
10.8%
-29.2% vs TC avg
§112
19.5%
-20.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 689 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed 7/21/2026 have been fully considered and are persuasive. On pages 8 - 10, Applicant argues that the amended claim language has claimed beyond the previous rejections made under 35 USC 102 and 35 USC 103. Applicant’s arguments are persuasive. However, after further search and consideration, a new grounds of rejection has been made further in view of Ke (Ke, Xiaodi. "Interprocess communication mechanisms with Inter-Virtual machine shared memory." (Year: 2011)) and Cardenas (US-20210185081-A1) - with Borges (US-20250062612-A1) additionally being relied upon for the rejection of claim 8. Specification The specification is objected to as failing to provide proper antecedent basis for the claimed subject matter for the reasons given below in the 35 USC 112 written description rejection. See 37 CFR 1.75(d)(1) and MPEP § 608.01(o). Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), first paragraph: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1 – 2, 6 – 16, and 20 are rejected under 35 U.S.C. 112, first paragraph, as failing to comply with the written description requirement. The claims contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventors, at the time the application was filed, had possession of the claimed invention. Regarding claim 1, said claim has been amended to recite “identifying by a digital ghost based at least in part on one or more digital twins . . . an alert”. Applicant has pointed to paragraphs [20-24] and [27] as providing support for this language. The specification as a whole has additionally been reviewed. While both digital twins and digital ghosts are discussed, a digital ghost performing the “identifying [of] an alert” is wholly absent from the originally filed specification. Claim 1 has further been amended to recite “retrieving, by the digital ghost using a virtual system based on Inter-Process Communication (IPC) . . . IT analytics data and OT analytics data. While digital ghosts are referenced in the specification (as noted above), as are IT and OT data, a digital ghost performing the claimed “retrieving” of the noted analytics data absent from the originally filed specification. Regarding claim 2, said claim has been amended to recite “wherein the digital ghost resides in an upper OSI layer beyond IT firewalls and OT firewalls of a power substation that houses the power substation physical components.” Applicant’s specification as a whole has been reviewed for support for the above language, including [20-27] (referenced in the remarks filed by Applicant along with the present claim amendments). While digital ghosts, power substations, and power substation physical components are all discussed, along with where: “The digital ghost may resides beyond IT/OT firewalls, inside the industrial control system itself” (see the originally filed specification, [24]) and “The digital ghost as an upper OSI layer may represent a system that emulates the actual or main system. . .” (see the originally filed specification, [25]), the written description in the specification fails to support the above noted claim language. The digital ghost “as an upper OSI layer” is not the same thing as “resides in an upper OSI layer beyond . . . firewalls”. Similarly “resides beyond IT/OT firewalls” is not the same thing as “resides in an upper OSI layer beyond . . . firewalls”. The issues with the clarity and definiteness of this amended claim language (discussed below in the rejection made under 35 USC 112, 2nd paragraph) are likely related to this lack of written description support. Regarding claims 6 and 7, said claims depend on claim 1 and inherit the issues noted above. Regarding claim 8, said claim recites limitations analogous to those addressed above when discussing claim 1. Claim 8 thus suffers from the same issues noted above which appear claim 1. Regarding claims 9 - 14, said claims depend on claim 8 and inherit the issues noted above. Regarding claim 15, said claim recites limitations analogous to those addressed above when discussing claim 1. Claim 15 thus suffers from the same issues noted above which appear claim 1. Regarding claims 16 and 20, said claims depend on claim 15 and inherit the issues noted above. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 2 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Regarding claim 2, said claim has been amended to recite “wherein the digital ghost resides in an upper OSI layer beyond IT firewalls and OT firewalls of a power substation that houses the power substation physical components.” It is unclear what the intended scope is for recitation that the digital ghost “resides” in an “upper OSI layer”. As discussed in Cloudflare (Cloudfare. "What is the OSI Model?". https://web.archive.org/web/20220514164445/https://www.cloudflare.com/learning/ddos/glossary/open-systems-interconnection-model-osi/. (Year: 2022)), the OSI model is purely conceptual in nature, and not an actual representation of anything where something can “reside” (or otherwise said to be located, stationed, or dwell permanently or continuously – as www.merriam-webster.com defines reside). Claim 2 also recites that the above noted residing is in an “upper” layer. “Upper” is a relative term which renders the claim indefinite. The term “upper” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. That the “upper” residing is “beyond IT firewalls and OT firewalls” exacerbates rather the issues with indefinites, as the scope of what can be considered “beyond” is generally unclear and indefinite itself. Where “IT firewalls and OT firewalls” “reside” is unclear and indefinite given the issues with how an item (such as a firewall) can “reside” in an OSI layer (which is merely a concept and not a location, as noted above) is unclear. It is additionally unclear how the term “beyond” is meant to further limit this recitation – how a software construct such as the claimed “digital ghost” can reside/be located/dwell continuously “beyond” a location (conceptual or otherwise) is unclear and indefinite. The combination of these issues thus renders claim 2 as a whole unclear and indefinite. In order to perform a complete examination, the language has been interpreted broadly (e.g., that there is a digital ghost in use in combination with the claimed firewalls in the power substation environment). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Storms (US-20190104138-A1) in view of Ke (Ke, Xiaodi. "Interprocess communication mechanisms with Inter-Virtual machine shared memory." (Year: 2011)) and Cardenas (US-20210185081-A1). Regarding claim 1, Storms shows a method for preventing security attacks ([24,29]) with a virtualization of power substation physical components into an information technology-operational technology architecture ([15-18]), the method comprising: identifying, by a virtual ([60] discussing a VM-based implantation) system connected to a power substation physical components (Fig. 1 illustrating the network topology and [17-19] discussing a (virtualized; see [60]) threat monitoring edge devices communicating with both OT and IT systems) an alert ([15] discussing to “detect threats”); retrieving, by the virtual system based on communication between a first virtual machine of the virtual system ([32,35,41]) connected to an information technology (IT) environment of the power substation network and a connection to an operational technology (OT) environment of the power substation network ([15-19, 50,66], discussing where a virtualized edge device is connected to both IT and OT monitoring sensors which can report to “various individuals and/or entities”), IT and OT analytics data associated with a device indicated in the alert ([32,35,41]); performing a cyber-physical ([31] discussing use of IT and OT analytic information) analysis ([29] discussing responsiveness to analyzed data from monitored components) of power substation physical components (Fig. 1 showing components 104 which, as [25] notes, “include subsystems for generating and/or distributing the power”) based on the IT analytics data and the OT analytics data ([31-32] discussing monitoring and correlation steps performed using gathered IT and OT data, including application of machine learning algorithms on collected data); and preventing, by the virtual system, communication with the device based on the cyber-physical analysis (Fig. 2, [16,31-33, 42]). Storms does not show where the virtualized communication is inter-process communication (IPC) between a first virtual machine and a second virtual machine. Ke shows where the virtualized communication is inter-process communication (IPC) between a first virtual machine and a second virtual machine (Abstract, pgs. 2, 10-11, and 14). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of Storms, including the VM use and VM communication, with the VM-to-VM communication techniques disclosed by Ke in order to ensure fast and reliable communication between the cooperating processes (Ke, pg. 14). Storms in view of Ke does not show all of: identifying by a digital ghost based at least in part on one or more digital twins of the power substation physical components and associated with the power substation network, an alert indictive of a potential security attack; and retrieving by the digital ghost using a virtual system, analytics data. Cardenas shows: identifying by a digital ghost based at least in part on one or more digital twins ([39] discussing a “ghost system” that “may include a copy of the components of the installation in a ‘digital twin’”) of the power substation ([35] discussing an “electrical installation”, see also Fig. 3) physical components and associated with the power substation network, an alert indictive of a potential security attack (Abstract, [35,38-39,44]; and retrieving by the digital ghost using a virtual system, analytics data ([44]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the security monitoring and response techniques of the above combination with the digital ghost of Cardenas in order to provide more effective mitigation of cybersecurity incidents impacting critical infrastructure (i.e., the power grid; see Cardenas ([3-6]). Regarding claim 15, Storms shows a system for preventing security attacks on power substation physical components of a power substation network ([15] discussing an “electric grid”, see also the visualization of Fig. 1 and continued discussion in [17-19]), the system comprising: a virtual system ([60] discussing a VM-based implantation) comprising a first virtual machine connected to an information technology (IT) environment of the power substation network and further comprising a second virtual machine connected to an operational technology (OT) environment of the power substation network ([17-19] discussing a (virtualized; see [60]) threat monitoring edge devices communicating with both OT and IT systems); and memory coupled to processing circuitry (Fig. 5), wherein the processing circuitry is configured to: identify, an alert indicative of a potential security attack ([17-19]); retrieve, by the virtual system, IT analytics data and OP analytics data associated with a device indicated in the alert ([32,35,41]); perform a cyber-physical ([31] discussing use of IT and OT analytic information) analysis ([29] discussing responsiveness to analyzed data from monitored components) based on the IT analytics data and the OT analytics data ([31-32] discussing monitoring and correlation steps performed using gathered IT and OT data, including application of machine learning algorithms on collected data); and prevent, by the virtual system, communication with the device based on the cyber-physical analysis (Fig. 2, [16,31-33, 42]). Storms does not show where the VM communication is inter-process communication (IPC). Ke discloses mechanism for VM to VM communication performed via IPC (Abstract, pgs. 2, 10-11, and 14). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of Storms, including the VM use and VM communication, with the VM-to-VM communication techniques disclosed by Ke in order to ensure fast and reliable communication between the cooperating processes (Ke, pg. 14). Storms in view of Ke do not show use of a digital ghost based at least in part on one or more digital twins of the power substation physical components, and identifying and retrieval steps by the digital ghost. Cardens shows use of a digital ghost based at least in part on one or more digital twins of the power substation physical components (Abstract, [35,38-39,44]), and identifying and retrieval steps by the digital ghost ([35,38-39,44]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the security monitoring and response techniques of the above combination with the digital ghost of Cardenas in order to provide more effective mitigation of cybersecurity incidents impacting critical infrastructure (i.e., the power grid; see Cardenas ([3-6]). Claims 2 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Storms in view of Ke and Cardenas as applied to claims 1 and 15 above, further in view of Kudo (US-20030126243-A1). Regarding claim 2, Storms in view of Ke and Cardenas shows the power substation network (Storms, Fig. 1, [15]), and wherein the digital ghost resides in an upper OSI layer beyond IT firewalls and OT firewalls (Storms, [17-19]) of a power substation that houses the power substation physical components (Cardenas, [35,38-39] discussing a digital ghost system residing in conjunction with a power substation and a components such as firewalls). The above combination does not show: wherein the alert is a new node alert indicating that the device is new to the network or was previously unidentified in the network. Kudo shows wherein the alert is a new node alert indicating that the device is new to the network or was previously unidentified in the network ([31,38]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of the above combination with the new device alerts of Kudo in order to prevent unintended changes to the network topology (Kudo, [38]). Regarding claim 16, Storms in view of Ke and Cardenas shows the power substation network (Storms, Fig. 1, [15]). The above combination does not show: wherein the alert is a new node alert indicating that the device is new to the network or was previously unidentified in the network. Kudo shows wherein the alert is a new node alert indicating that the device is new to the network or was previously unidentified in the network ([31,38]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of the above combination with the new device alerts of Kudo in order to prevent unintended changes to the network topology (Kudo, [38]). Claims 6, 7, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Storms in view of Ke and Cardenas, further in view of Vasseur (US-20210297442-A1). Regarding claim 6, Storms in view of Ke and Cardenas shows wherein performing the cyber-physical analysis of the power substation physical components comprises: generating the baseline IT-OT model (Storms, [18] discussing recording “configuration information” over “certain time based intervals” which [20] notes includes a “normal or typical range of values”) using IT area network interfaces (Storms, [28,58]) and information shared between the first virtual machine and the second virtual machine (Storms, [15-19,31, 60] discussing a virtualized implementation of the networking architecture, including data shared via the shared data storage) based on the IPC (Ke, Abstract, pgs. 2, 10-11, and 14); generating an IT-OT operational analytics model based on the IT analytics data and the OT analytics data (Storms, [20] discussing “OTE operational characteristics” including as noted in [22] the “current status (e.g., posture) of the OTE being monitored” with further discussion in [35,47]), comparing the IT-OT operational analytics model to the baseline IT-OT model (Storms, [20,35,47,49] discussing comparing real time operational data to typical data). Storms in view of Ke and Cardenas does not show consideration of communication protocols, accessed ports, network traffic flows, device functionality, and device profiles. Vasseur shows consideration of communication protocols ([41-42]), accessed ports ([42]), network traffic flows ([41-43]), device functionality ([47]), and device profiles ([49-59]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of Storms in view of Ke with the additional data collected and tracked, as suggested by Vasseur, in order to utilize a more complete understanding of the monitored network and thus better detect deviations from normal/expected values. Regarding claim 7, the above combination further shows detecting a deviation of the IT-OT operational analytics model from the baseline IT-OT model (Storms, [35,47]). Regarding claim 20, Storms in view of Ke and Cardenas shows wherein the processing circuitry is further configured to: generate a baseline IT-OT model (Storms, [18] discussing recording “configuration information” over “certain time based intervals” which [20] notes includes a “normal or typical range of values”) using IT area network interfaces (Storms, [28,58]) and information shared between the first virtual machine and the second virtual machine (Storms, [15-19,31, 60] discussing a virtualized implementation of the networking architecture, including data shared via the shared data storage) based on the IPC (Ke, Abstract, pgs. 2, 10-11, and 14); generating an IT-OT operational analytics model based on the IT analytics data and the OT analytics data (Storms, [20] discussing “OTE operational characteristics” including as noted in [22] the “current status (e.g., posture) of the OTE being monitored” with further discussion in [35,47]), perform the cyber-physical analysis based on comparing the IT-OT operational analytics model to the baseline IT-OT model (Storms, [20,35,47,49] discussing comparing real time operational data to typical data). Storms in view of Ke and Cardenas does not show consideration of communication protocols, accessed ports, network traffic flows, device functionality, and device profiles. Vasseur shows consideration of communication protocols ([41-42]), accessed ports ([42]), network traffic flows ([41-43]), device functionality ([47]), and device profiles ([49-59]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of Storms in view of Ke with the additional data collected and tracked, as suggested by Vasseur, in order to utilize a more complete understanding of the monitored network and thus better detect deviations from normal/expected values. Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Storms in view of Ke, Cardenas, and Borges (US-20250062612-A1). Regarding claim 8, Storms shows a non-transitory computer-readable storage medium comprising instructions to cause processing circuitry to prevent security attacks of a power substation network, upon execution of the instructions by the processing circuitry, to: identify, by a virtual ([60] discussing a VM-based implantation) system connected to a power substation physical components (Fig. 1 illustrating the network topology and [17-19] discussing a (virtualized; see [60]) threat monitoring edge devices communicating with both OT and IT systems) an alert ([15] discussing to “detect threats”); retrieving, by the virtual system based on communication between a first virtual machine of the virtual system ([32,35,41]) connected to an information technology (IT) environment of the power substation network and a connection to an operational technology (OT) environment of the power substation network ([15-19, 50,66], discussing where a virtualized edge device is connected to both IT and OT monitoring sensors which can report to “various individuals and/or entities”), IT and OT analytics data associated with a device indicated in the alert ([32,35,41]); perform a cyber-physical ([31] discussing use of IT and OT analytic information) analysis ([29] discussing responsiveness to analyzed data from monitored components) of power substation physical components (Fig. 1 showing components 104 which, as [25] notes, “include subsystems for generating and/or distributing the power”) based on the IT analytics data and the OT analytics data ([31-32] discussing monitoring and correlation steps performed using gathered IT and OT data, including application of machine learning algorithms on collected data); and prevent, by the virtual system, communication with the device based on the cyber-physical analysis (Fig. 2, [16,31-33, 42]). Storms does not show where the virtualized communication is inter-process communication (IPC) between a first virtual machine and a second virtual machine. Ke shows where the virtualized communication is inter-process communication (IPC) between a first virtual machine and a second virtual machine (Abstract, pgs. 2, 10-11, and 14). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of Storms, including the VM use and VM communication, with the VM-to-VM communication techniques disclosed by Ke in order to ensure fast and reliable communication between the cooperating processes (Ke, pg. 14). Storms in view of Ke does not show all of: identifying by a digital ghost based at least in part on one or more digital twins of the power substation physical components and associated with the power substation network, an alert indictive of a potential security attack; and retrieving by the digital ghost using a virtual system, analytics data, and block communication, wherein the digital ghost uses anomaly-based context to predict and block unexpected actions. Cardenas shows: identifying by a digital ghost based at least in part on one or more digital twins ([39] discussing a “ghost system” that “may include a copy of the components of the installation in a ‘digital twin’”) of the power substation ([35] discussing an “electrical installation”, see also Fig. 3) physical components and associated with the power substation network, an alert indictive of a potential security attack (Abstract, [35,38-39,44]; and retrieving by the digital ghost using a virtual system, analytics data ([44]), and block communication ([61-62]), wherein the digital ghost uses anomaly-based context to predict and block unexpected actions ([35,38-39,44] discussing distinguishing “normal operating conditions . . . from abnormal conditions”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the security monitoring and response techniques of the above combination with the digital ghost of Cardenas in order to provide more effective mitigation of cybersecurity incidents impacting critical infrastructure (i.e., the power grid; see Cardenas ([3-6]). The above combination does not show consideration of configuration changes of the power substation network. Borges shows consideration of configuration changes of the power substation network ([115]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the security monitoring and response techniques of the above combination with the configuration awareness of Borges in order to ensure additional aspects of the monitored network are fully considered (including the configuration of monitored devices) and thus more completely monitor and protect the network status and health. Claims 9 and 10 are rejected under 35 U.S.C. 103 as being unpatentable over Storms in view of Ke, Cardenias, and Borges, as applied to claim 8 above, further in view of Kudo. Regarding claim 9, the above combination shows the power substation network (Fig. 1, [15]). The above combination does not show: wherein the alert is a new node alert indicating that the device is new to the network or was previously unidentified in the network. Kudo shows wherein the alert is a new node alert indicating that the device is new to the network or was previously unidentified in the network ([31,38]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of the above combination with the new device alerts of Kudo in order to prevent unintended changes to the network topology (Kudo, [38]). Regarding claim 10, the above combination shows claim 1. The above combination does not show wherein the alert is a new communication link alert indicating that the device has requested a new communication link. Kudo shows wherein the alert is a new communication link alert indicating that the device has requested a new communication link ([18,26]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of the above combination with the new device alerts of Kudo in order to prevent unintended changes to the network topology (Kudo, [38]). Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Storms in view of Ke, Cardenias, and Borges, as applied to claim 8 above, further in view of Abraham (US-5983270-A). Regarding claim 11, the above combination shows device monitoring on the power substation network (Storms, [15-18,32,35]). The above combination does not show an alert that is a new protocol alert indicating use of a protocol that has not been approved for the network. Abraham shows an alert that is a new protocol alert indicating use of a protocol that has not been approved for the network (col. 35 line 55 – col. 36 line 11, col. 36 line 64 – col. 37 line 4). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of the above combination with the protocol monitoring of Abraham in order to maintain the desired operational state of the monitored network. Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Storms in view of Ke, Cardenias, and Borges, further in view of Ingram (Ingram, David, and Brian Smellie. "Solving Electrical Substation Timing Problems." Tekron Whitepaper, October. (Year: 2014)). Regarding claim 12, the above combination shows claim 8. The above combination does not show: wherein the alert is a wrong time alert indicating that the device has reported an incorrect time. Ingram shows wherein the alert is a wrong time alert indicating that the device has reported an incorrect time (pgs. 6 – 7 and pg. 10 lines 52-59). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of the above combination with the time monitoring and alerting mechanisms of Ingram in order to better ensure system reliability and consistency via ensuring consistent time is maintained across the network. Claims 13 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Storms in view of Ke, Cardenias, and Borges, further in view of Vasseur (US-20210297442-A1). Regarding claim 13, the above combination shows wherein execution of the instructions further causes the processing circuitry to: generate the baseline IT-OT model (Storms, [18] discussing recording “configuration information” over “certain time based intervals” which [20] notes includes a “normal or typical range of values”) using IT area network interfaces (Storms, [28,58]) and information shared between the first virtual machine and the second virtual machine (Storms, [15-19,31, 60] discussing a virtualized implementation of the networking architecture, including data shared via the shared data storage) based on the IPC (Ke, Abstract, pgs. 2, 10-11, and 14); generate an IT-OT operational analytics model based on the IT analytics data and the OT analytics data (Storms, [20] discussing “OTE operational characteristics” including as noted in [22] the “current status (e.g., posture) of the OTE being monitored” with further discussion in [35,47]), compare the IT-OT operational analytics model to the baseline IT-OT model (Storms, [20,35,47,49] discussing comparing real time operational data to typical data). The above combination does not show consideration of communication protocols, accessed ports, network traffic flows, device functionality, and device profiles. Vasseur shows consideration of communication protocols ([41-42]), accessed ports ([42]), network traffic flows ([41-43]), device functionality ([47]), and device profiles ([49-59]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the networking and monitoring techniques of Storms with the additional data collected and tracked, as suggested by Vasseur, in order to utilize a more complete understanding of the monitored network and thus better detect deviations from normal/expected values. Regarding claim 14, the above combination further shows to: detect a deviation of the IT-OT operational analytics model from the baseline IT-OT model (Storms, [35,47]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. This includes: Bonomi (US-20180115519-A1). THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOHN M MACILWINEN whose telephone number is (571)272-9686. The examiner can normally be reached Monday - Friday, 9:00 - 5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Glenton B Burgess can be reached at (571) 272 - 3949. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. JOHN MACILWINEN Primary Examiner Art Unit 2442 /JOHN M MACILWINEN/Primary Examiner, Art Unit 2454
Read full office action

Prosecution Timeline

Show 2 earlier events
Dec 30, 2025
Response Filed
Jan 27, 2026
Final Rejection mailed — §103, §112
Mar 23, 2026
Response after Non-Final Action
Apr 22, 2026
Request for Continued Examination
May 03, 2026
Response after Non-Final Action
May 28, 2026
Non-Final Rejection mailed — §103, §112
Jul 21, 2026
Response Filed
Sep 09, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744816
CENTRALIZED COMPLIANCE MANAGEMENT PLATFORM FOR SECURITY OBJECTS
2y 8m to grant Granted Sep 22, 2026
Patent 12712804
PACKET TRANSMISSION METHOD, APPARATUS, AND SYSTEM, NETWORK DEVICE, AND STORAGE MEDIUM
2y 7m to grant Granted Aug 18, 2026
Patent 12706934
Systems and methods for active directory protection in zero trust networks
2y 4m to grant Granted Aug 11, 2026
Patent 12689559
AUTOMATED PREVENTATIVE CONTROLS IN DIGITAL WORKFLOW
2y 4m to grant Granted Jul 21, 2026
Patent 12676892
Security policy framework for cloud environments
2y 8m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
68%
Grant Probability
95%
With Interview (+27.9%)
3y 11m (~1y 4m remaining)
Median Time to Grant
High
PTA Risk
Based on 689 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month