Prosecution Insights
Last updated: October 02, 2026
Application No. 18/593,117

METHODS AND SYSTEMS FOR DETECTION OF CLOCK TAMPERING ON AN ELECTRONIC DEVICE

Final Rejection §103
Filed
Mar 01, 2024
Examiner
LANIER, BENJAMIN E
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Lexmark International Inc.
OA Round
2 (Final)
69%
Grant Probability
Favorable
3-4
OA Rounds
1y 0m
Est. Remaining
86%
With Interview

Examiner Intelligence

Grants 69% — above average
69%
Career Allowance Rate
650 granted / 937 resolved
+11.4% vs TC avg
Strong +17% interview lift
Without
With
+16.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
28 currently pending
Career history
964
Total Applications
across all art units

Statute-Specific Performance

§101
7.6%
-32.4% vs TC avg
§103
49.5%
+9.5% vs TC avg
§102
16.8%
-23.2% vs TC avg
§112
17.9%
-22.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 937 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment Applicant’s amendment filed on 13 July 2026 amends claims 1, 6, 7, 9, 12, and 13. Claim 5 has been cancelled. Applicant’s amendment has been fully considered and entered. Response to Arguments Applicant argues on page 6 of the response, “Claims 7, 9, and 13 have been amended to addresses [sic] the Examiner’s comments regarding antecedent basis in sections 7 to 12 of the Office Action. Applicants therefore respectfully consider that amended Claims 7, 9, and 13 are definite.” This argument has been fully considered and is persuasive. Therefore, the previous §112 rejections have been withdrawn. Applicant argues on page 6 of the response, “A Notice of Abandonment was issued on US Patent Application No. 18/593,101 on 25 March 2026. Applicants respectfully submit that the Double Patenting rejection is therefore rendered moot.” This argument has been fully considered and is persuasive. Therefore, the previous double patenting rejection has been withdrawn. Applicant argues on page 6 of the response, “Previous Claim 5 was not subject to the rejection under 35 U.S.C. 101. The rejection under 35 U.S.C. 101 therefore does not apply to amended Claim 1.” This argument has been fully considered and is persuasive. Therefore, the previous §101 rejections have been withdrawn. Applicant argues on page 7 of the response, “In addition, ‘019 also does not teach ‘when a difference between the host interval time and the component interval time is greater than a threshold, determining that the host firmware clock has been tampered with’ as required by Claim 1.” This argument is not persuasive because ‘019 discloses that the time between clock checks is compared to an expected time interval (Page 9, fourth paragraph) such that if the interval is large, a clock reset is performed (Page 9, fifth paragraph). Examiner notes that while ‘019 does not explicitly utilize the term “threshold”, the concept of performing a clock reset when a determined time interval is determined to be “large” shows that there is a specific value above which the ‘019 system defines as “large” and that specific value can be considered to be the claimed threshold. Applicant argues on pages 7-8 of the response, “So, ‘019 teach that many factors should be considered when determining clock tampering and that clock tampering should not be determined based on the difference in time alone. This teaches away from the feature of Claim 1 requiring that the clock tampering is determined directly…” This argument is not persuasive because the claims do not specify that the claimed threshold is the only mechanism allowed to be used to detect clock tampering. The claims simply specify that clock tampering is determined using the threshold and ‘019 does determine clock tampering using a threshold as discussed above. Whether or not ‘019 utilizes additional mechanisms to determine clock tampering is irrelevant since ‘019 can determine clock tampering at least in part utilizing a threshold as claimed. Additionally, teaching away from a reference pertains to proposed modifications to a primary reference in a 103 rejection, which was not the case for the rejections in question in the Non-Final dated 26 February 2026 (“Non-Final”). Applicant argues on page 9 of the response, “There is no discussion in Sasaki of the detection of tampering of the image forming apparatus itself or preventing operation of the image forming apparatus in response to detection of tampering of the image forming apparatus itself. Sasaki teaches that the cartridge may be incorrect/incompatible, so the skilled person is taught to trust the image forming device in determinations regarding the cartridge in Sasaki, rather than to base determinations regarding the image forming device on time measurements from the cartridge.” In response, Applicant has failed to fully considered the proposed modification of ‘019 in view of Sasaki presented in the Non-Final. Specifically, the Non-Final proposed (Page 25) modifying the ‘019 reference such that the clock tampering functionality is implemented within a printer cartridge. Applicant has failed to address the combination of references as presented in the Non-Final. One cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Applicant argues on page 9 of the response, “There is no discussion in Sasaki of the detection of tampering of the image forming apparatus itself…” In response, the claims merely require the detection of tampering of the firmware clock, which was fully addressed in the Non-Final as being taught by the ‘019 reference (See Page 9, paragraphs 4-5). Applicant argues on page 9 of the response, “There is no discussion in Sasaki of preventing operation of the image forming apparatus in response to detection of tampering…” This argument is not persuasive because Sasaki discloses that failed authentication of the cartridge results in the stopping of image forming operations by the printer (Page 14, second to last paragraph). This would be considered to be preventing operation of the image forming apparatus as claimed. Applicant argues on page 10 of the response, “Further, even if features of ‘019 were implemented in an image forming device of Sasaki, it is not clear how the skilled person would implement ‘019 in Sasaki.” In response, the proposed modification is simply to implement the clock tampering functionality within a printer cartridge, which would be considered to be within the capabilities of those having ordinary skill in the art. Applicant argues on page 10 of the response, “Finally, there is no teaching or suggestion of preventing operation of the image forming device when tampering of an image device clock is detected.” This argument is not persuasive because Sasaki discloses that failed authentication of the cartridge results in the stopping of image forming operations by the printer (Page 14, second to last paragraph). This would be considered to be preventing operation of the image forming apparatus as claimed. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 2, 4, 6-19 are rejected under 35 U.S.C. 103 as being unpatentable over JP 2009512019 (“019”), in view of Sasaki, EP 3425546. Referring to claim 1, ‘019 discloses a clock tamper detection procedure wherein clock cycles are counted for a real-time clock until a desired count is reached such that the real-time clock is checked periodically (Page 9, first- fourth paragraphs: time between the clock checks reads on the claimed host time interval and the time of the previous check can read on the claimed host start time, while the time of the current check can read on the claimed host end time; client device reads on the imaging device; Examiner notes that the “imaging” name represents non-functional descriptive material since the “imaging” name does not define structure, nor does the name require functional steps to be performed in the claims. See MPEP 2111.04-2111.05) such that clock reading procedures can be implemented by firmware (Page 22, first full paragraph), which meets the limitation of reading a host start time from a host firmware clock of the imaging device, the host start time corresponding to a start of an action performed by a component of the imaging device, reading a host end time from the host end time from the host firmware clock, the host end time corresponding to an end of the action performed by the component of the imaging device. The time between clock checks is compared to an expected time interval (Page 9, fourth paragraph), which meets the limitation of comparing a host interval time between the host start time and the host end time with a component interval time, corresponding to the time taken to perform an action by the component. If the interval is large, a clock reset is performed (Page 9, fifth paragraph), which meets the limitation of when a different between the host interval time and the component interval time is greater than a threshold, determine that the host firmware clock has been tampered with. ‘019 does not specify that the clock tampering system is implemented in a supply item for use in an imaging system. Sasaki discloses tamper detection processing implemented (Page 10, first paragraph) within a printer cartridge (Page 8, third paragraph) such that a failed authentication of the cartridge results in the stopping of image forming operations by the printer (Page 14, second to last paragraph), which meets the limitation of when it is determined that the host firmware clock has been tampered with, preventing normal operation of the imaging device, wherein preventing normal operation of the imaging device comprises interrupting signals sent to a print component. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the clock tampering functionality of ‘019 to have been implemented within a printer cartridge in order to provide reliable cartridge verification as suggested by Sasaki (Page 3, second full paragraph). Referring to claim 2, 019 discloses that the client enters a sleep mode for the duration of the wait period such as 5 minutes (Page 8, last paragraph – Page 9, first paragraph), which meets the limitation of wherein the host start time is the time when a command is sent to the component of the imaging device, and the host end time is the time when a response to the command is received from the component. The time between clock checks is compared to an expected time interval (Page 9, fourth paragraph), which meets the limitation of and the component interval time is an expected response time for the command. Referring to claim 4, ‘019 discloses a clock tamper detection procedure wherein clock cycles are counted for a real-time clock until a desired count is reached such that the real-time clock is checked periodically (Page 9, first- fourth paragraphs: time between the clock checks reads on the claimed host time interval and the time of the previous check can read on the claimed host start time, while the time of the current check can read on the claimed host end time;) such that clock reading procedures can be implemented by firmware (Page 22, first full paragraph), which meets the limitation of wherein the host firmware of the imaging device sends the host start time and the host end time. The time between clock checks is compared to an expected time interval (Page 9, fourth paragraph), which meets the limitation of the component performs the steps of comparing a host interval time, with the component interval time. If the interval is large, a clock reset is performed (Page 9, fifth paragraph), which meets the limitation of when a different between the host interval time and the component interval time is greater than a threshold, determining that the host firmware clock has been tampered with. Referring to claim 6, ‘019 does not specify that the clock tampering system is implemented in a supply item for use in an imaging system. Sasaki discloses tamper detection processing implemented (Page 10, first paragraph) within a printer cartridge (Page 8, third paragraph) such that a failed authentication of the cartridge results in the stopping of image forming operations by the printer (Page 14, second to last paragraph), which meets the limitation of wherein preventing normal operation of the imaging device comprises interrupting signals sent to a print component. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the clock tampering functionality of ‘019 to have been implemented within a printer cartridge in order to provide reliable cartridge verification as suggested by Sasaki (Page 3, second full paragraph). Referring to claim 7, ‘019 discloses a clock tamper detection procedure wherein clock cycles are counted for a real-time clock until a desired count is reached such that the real-time clock is checked periodically (Page 9, first- fourth paragraphs: time between the clock checks reads on the claimed host time interval and the time of the previous check can read on the claimed host start time, while the time of the current check can read on the claimed host end time) and the time between clock checks is compared to an expected time interval (Page 9, fourth paragraph) such that clock reading procedures can be implemented by firmware (Page 22, first full paragraph), which meets the limitation of wherein the steps of comparing the host interval time with the component interval time and, when the different between the host interval time and the component interval time is greater than the threshold, determining that the host firmware clock has been tampered with, are performed by host firmware of the imaging device. Referring to claim 8, ‘019 discloses that the functionality is implemented in a client device (Page 9, first – fourth paragraph: the name of the device represents non-functional descriptive material since the name of the device does not define structure, nor does the name of the device require functional steps to be performed. See MPEP 2111.04-2111.05), which meets the limitation of wherein the component is a security device of the imaging device. Referring to claim 9, ‘019 discloses that the client enters a sleep mode for the duration of the wait period such as 5 minutes (Page 8, last paragraph – Page 9, first paragraph), which meets the limitation of wherein when the host firmware of the imaging device receives a response to the command, the host firmware sends the host end time to the component. Referring to claim 10, ‘019 discloses that the client enters a sleep mode for the duration of the wait period such as 5 minutes (Page 8, last paragraph – Page 9, first paragraph: start of the sleep mode would correspond with the claimed command; the beginning of the sleep mode corresponds with the claimed host start time), which meets the limitation of wherein the command comprises the host start time. Referring to claim 11, ‘019 discloses that the functionality is implemented in a client device (Page 9, first – fourth paragraph), which meets the limitation of wherein the steps of comparing the host interval time with the component interval time and, when the different between the host interval time and the component interval time is greater than the threshold, determining that the host firmware clock has been tampered with, are performed by the component. Referring to claim 12, ‘019 discloses a clock tamper detection procedure wherein clock cycles are counted for a real-time clock until a desired count is reached such that the real-time clock is checked periodically (Page 9, first- fourth paragraphs: time between the clock checks reads on the claimed host time interval and the time of the previous check can read on the claimed host start time, while the time of the current check can read on the claimed host end time; client device reads on the imaging device; Examiner notes that the “imaging” name represents non-functional descriptive material since the “imaging” name does not define structure, nor does the name require functional steps to be performed in the claims. See MPEP 2111.04-2111.05) such that clock reading procedures can be implemented by firmware (Page 22, first full paragraph), which meets the limitation of read a host start time from a host firmware clock of the imaging device, the host start time corresponding to a start of an action performed by a component of the imaging device, read a host end time from the host end time from the host firmware clock, the host end time corresponding to an end of the action performed by the component of the imaging device. The time between clock checks is compared to an expected time interval (Page 9, fourth paragraph), which meets the limitation of compare a host interval time between the host start time and the host end time with a component interval time, corresponding to the time taken to perform an action by the component. If the interval is large, a clock reset is performed (Page 9, fifth paragraph), which meets the limitation of when a different between the host interval time and the component interval time is greater than a threshold, determine that the host firmware clock has been tampered with. ‘019 does not specify that the clock tampering system is implemented in a supply item for use in an imaging system. Sasaki discloses tamper detection processing implemented (Page 10, first paragraph) within a printer cartridge (Page 8, third paragraph) such that a failed authentication of the cartridge results in the stopping of image forming operations by the printer (Page 14, second to last paragraph), which meets the limitation of when it is determined that the host firmware clock has been tampered with, preventing normal operation of the imaging device, wherein preventing normal operation of the imaging device comprises interrupting signals sent to a print component. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the clock tampering functionality of ‘019 to have been implemented within a printer cartridge in order to provide reliable cartridge verification as suggested by Sasaki (Page 3, second full paragraph). Referring to claim 13, ‘019 discloses a clock tamper detection procedure wherein clock cycles are counted for a real-time clock until a desired count is reached such that the real-time clock is checked periodically (Page 9, first- fourth paragraphs: time between the clock checks reads on the claimed host time interval and the time of the previous check can read on the claimed host start time, while the time of the current check can read on the claimed host end time; client device reads on the imaging device; Examiner notes that the “imaging” name represents non-functional descriptive material since the “imaging” name does not define structure, nor does the name require functional steps to be performed in the claims. See MPEP 2111.04-2111.05), which meets the limitation of receiving a host start time and a host end time and calculate a host interval time between the host start time and the host end time, or receive the host interval time. The time between clock checks is compared to an expected time interval (Page 9, fourth paragraph), which meets the limitation of compare the host interval time, with a component interval time corresponding to the time taken to perform an action by the component. If the interval is large, a clock reset is performed (Page 9, fifth paragraph), which meets the limitation of when a different between the host interval time and the component interval time is greater than a threshold determine that a host firmware clock of the imaging device has been tampered with. ‘019 does not specify that the clock tampering system is implemented in a supply item for use in an imaging system. Sasaki discloses tamper detection processing implemented (Page 10, first paragraph) within a printer cartridge (Page 8, third paragraph) such that a failed authentication of the cartridge results in the stopping of image forming operations by the printer (Page 14, second to last paragraph), which meets the limitation of when it is determined that the host firmware clock has been tampered with, preventing normal operation of the imaging device, wherein preventing normal operation of the imaging device comprises interrupting signals sent to a print component. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the clock tampering functionality of ‘019 to have been implemented within a printer cartridge in order to provide reliable cartridge verification as suggested by Sasaki (Page 3, second full paragraph). Referring to claim 14, ‘019 discloses that the real-time clock is checked every 5 minutes (Page 9, paragraph 1: 5-minute wait period reads on the claimed action), which meets the limitation of perform the action for the component interval time. After the predetermined wait time, the client device reads the current value of the real-time clock (Page 9, paragraph 2) such that the clock reading procedures can be implemented by firmware (Page 22, first full paragraph), which meets the limitation of communicate the end of the action to host firmware of the imaging device. Referring to claim 15, ‘019 discloses that the client enters a sleep mode for the duration of the wait period (Page 8, last paragraph), which meets the limitation of wherein the component suspends communication with the host firmware for the component interval time. Referring to claim 16, ‘019 discloses that the wait time is predetermined such as 5 minutes (Page 8, last paragraph – Page 9, first paragraph), which meets the limitation of wherein the action is an operation with a consistent execution time. Referring to claim 17, ‘019 discloses that the functionality is implemented in a client device (Page 9, first – fourth paragraph: the name of the device represents non-functional descriptive material since the name of the device does not define structure, nor does the name of the device require functional steps to be performed. See MPEP 2111.04-2111.05), which meets the limitation of wherein the component is a security device. Referring to claims 18, 19, ‘019 does not specify that the clock tampering system is implemented in a supply item for use in an imaging system. Sasaki discloses tamper detection processing implemented (Page 10, first paragraph: calculation unit 107 within the IC tag 101 of cartridge) within a printer cartridge (Page 8, third paragraph: IC tag 101 added to process cartridge 210; cartridge 210 reads on the claimed supply item), which meets the limitation of a supply item for use with an imaging device in an imaging system, an imaging system comprising the supply item of claim 19 installed in the imaging device. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the clock tampering functionality of ‘019 to have been implemented within a printer cartridge in order to provide reliable cartridge verification as suggested by Sasaki (Page 3, second full paragraph). Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over JP 2009512019 (“019”), in view of Sasaki, EP 3425546, and further in view of Wang, CN 116547612. Referring to claim 3, ‘019 discloses that the interval between clock checks is based on the use of a counter (Page 9, first paragraph). ‘019 does not specify subtraction of a start time from an end time. Wang discloses time interval determination using counters (Page 10, fifth paragraph) and time interval determination by subtracting a start time from an ending time (Page 10, fourth paragraph), which meets the limitation of determining the host interval time by subtracting the host start time from the host end time. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention for the interval of ‘019 to have been determined by subtracting a start time from and end time, instead of using counters, since Wang discloses that such an interval determine represents one of a finite number of possible embodiments that could be utilized by one of ordinary skill in the art with a reasonable expectation of success. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BENJAMIN E LANIER whose telephone number is (571)272-3805. The examiner can normally be reached M-Th: 5:30-4:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at 5712705143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BENJAMIN E LANIER/Primary Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Mar 01, 2024
Application Filed
Feb 26, 2026
Non-Final Rejection mailed — §103
Jul 13, 2026
Response Filed
Aug 17, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726336
SECURE KEY EXCHANGE USING KEY-ASSOCIATED ATTRIBUTES
3y 6m to grant Granted Sep 01, 2026
Patent 12711231
PREVENTING PROFILED SIDE CHANNEL ATTACKS
2y 9m to grant Granted Aug 18, 2026
Patent 12705334
ZERO TRUST AUTHENTICATION OF SECURE SYSTEMS WITH TRUSTED PLATFORM MODULES
2y 1m to grant Granted Aug 11, 2026
Patent 12699777
OWNER REVOCATION EMULATION CONTAINER
2y 9m to grant Granted Aug 04, 2026
Patent 12694078
ENTERPRISE APPLICATION MANAGEMENT WITH ENROLLMENT TOKENS
2y 3m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
69%
Grant Probability
86%
With Interview (+16.9%)
3y 7m (~1y 0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 937 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month