Prosecution Insights
Last updated: October 01, 2026
Application No. 18/646,332

INDUSTRIAL PROCESS DEVICE FINGERPRINTING

Non-Final OA §102§103§112
Filed
Apr 25, 2024
Examiner
BINCZAK, BRANDON MICHAEL
Art Unit
2116
Tech Center
2100 — Computer Architecture & Software
Assignee
Schneider Electric SE
OA Round
1 (Non-Final)
39%
Grant Probability
At Risk
1-2
OA Rounds
8m
Est. Remaining
72%
With Interview

Examiner Intelligence

Grants only 39% of cases
39%
Career Allowance Rate
25 granted / 64 resolved
-15.9% vs TC avg
Strong +33% interview lift
Without
With
+33.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
29 currently pending
Career history
106
Total Applications
across all art units

Statute-Specific Performance

§101
8.2%
-31.8% vs TC avg
§103
55.8%
+15.8% vs TC avg
§102
9.7%
-30.3% vs TC avg
§112
26.2%
-13.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 64 resolved cases

Office Action

§102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-20 are pending, with independent claims 1 and 14. Information Disclosure Statement The information disclosure statement(s) (IDS) submitted on 10/29/2025 is/are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement(s) is/are being considered by the examiner. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION. — The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claim(s) 1-20 is/are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention. Regarding claim(s) 1 and 14: Where applicant acts as their lexicographer to specifically define a term of a claim contrary to its ordinary meaning, the written description must clearly redefine the claim term and set forth the uncommon definition so as to put one reasonably skilled in the art on notice that the applicant intended to so redefine that claim term. Process Control Corp. v. HydReclaim Corp., 190 F.3d 1350, 1357, 52 USPQ2d 1029, 1033 (Fed. Cir. 1999). The term “secure communication” in the claims is used to refer to communication with a device whose identity can be authenticated, while the accepted meaning refers to communication which is encrypted or otherwise protected against unauthorized access. The claims and specification describe no process of enabling communication which one of ordinary skill in the art would understand to be “secure” as the term is used in the art. “Authenticated” communication, on the other hand, refers to communication for which the identity of the sender and/or receiver is verified, as well as verifying that that the communication itself is valid/unmodified. The claim is indefinite because the specification does not clearly redefine the term. Regarding claim(s) 3: Claim 3 recites, “… a legacy communication protocol comprising minimum to no security.” “Minimum security” is a relative term which renders the claim indefinite. The term is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Regarding claims 2, 4-13, and 15-20: They are dependent on one or more rejected claims, and thus inherit those rejections. This rejection could be overcome by overcoming the rejection(s) to any claims upon which these claims depend, or by amending the claims such that they are no longer dependent on any rejected claim. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-4, 9, 14, 15, and 19 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by KOPROV et al, Systems and Methods for Authenticating Manufacturing Machines Through an Unobservable Fingerprinting System. Regarding claim 1: KOPROV teaches: A system for enabling secure communication among industrial process devices, the system comprising: an industrial peripheral device generating an output signal, the output signal having one or more recurring physical properties (Pg 2 "Physically unclonable functions (PUFs) utilize the natural variations within a hardware device to generate a distinct and unrepeatable response" and "... the vibration signal produced by the acceleration of these machines can be captured as a fingerprint, which can be used as an authentication token for accessing IT systems. This approach is insensitive to external noise and repeatable, making it suitable for generating consistent signatures over time."); and an industrial controller device configured to operate in at least one of a training mode and an operational mode (Pg 6 "Supervised ML may be applicable when someone wants to ... authenticate based on binary classification (target and non-target asset) in manufacturing facilities where several identical machine assets are presented."), Examiner notes that the paper describes a learning phase where a target machine's Physically Unclonable Functions (PUF) are learned, and then used in practice to identify/authenticate the machine. wherein in the training mode, the industrial controller device is configured to communicate with the industrial peripheral device via a communication network to obtain a unique fingerprint signal from the output signal (Pg 1 "… this paper proposes a method to extract a digital "fingerprint" of a manufacturing machine to uniquely identify itself on a connected network of machines." and pg 4 "To measure the motion of these assets, we used a nine Degrees of Freedom (DoF) internal measuring unit (IMU) MPU-9250. This IMU is equipped with a three-axis accelerometer, gyroscope, and magnetometer and is capable of transmitting data via I2C and SPI protocols, which are specifications for synchronous serial communication interfaces used for short-distance communication."), the unique fingerprint signal being indicative of the one or more recurring physical properties of the output signal and corresponding to an identity of the industrial peripheral device (Pg 2 "Physically unclonable functions (PUFs) utilize the natural variations within a hardware device to generate a distinct and unrepeatable response ..."), and wherein in the operational mode, the industrial controller device is configured to validate the identity of the industrial peripheral device based on the unique fingerprint signal (Pgs 8-10 "As a means of continuous authentication, some normal machine movement can be used as the password move for continuous authentication. 3D printers like Stratasys F123 perform nozzle cleaning between each layer. It can be used to authenticate the asset ..."). Regarding claim 2: KOPROV teaches: The system of claim 1, wherein the industrial peripheral device comprises a legacy device (Pg 2 "In addition, this approach can be easily integrated into existing or legacy machines without disrupting their operation and requires minimal human intervention and lightweight computation to perform registration, authentication, and certification."). Regarding claim 3: KOPROV teaches: The system of claim 1, wherein the industrial peripheral device comprises a legacy communication protocol comprising minimum to no security (Pg 4 "This IMU is equipped with a three-axis accelerometer, gyroscope, and magnetometer and is capable of transmitting data via I2C and SPI protocols …"). Examiner notes that both the I2C and SPI protocols are known in the art and do not incorporate security. See https://ez.analog.com/ez-blogs/b/engineering-mind/posts/securing-spi-and-why-it-matters, “SPI: This full-duplex protocol has no inherent mechanisms for authentication, encryption, or integrity verification.” and “I2C: Widely used for short-distance communication, I2C lacks encryption, authentication, and data integrity checks.” Regarding claim 4: KOPROV teaches: The system of claim 1, wherein the industrial peripheral device comprises at least one of an industrial sensor device and human machine interface (Pg 4 "This IMU is equipped with a three-axis accelerometer, gyroscope, and magnetometer …"). Regarding claim 9: KOPROV teaches: The system of claim 1, wherein in the operational mode, the industrial controller device is configured to continuously monitor the unique fingerprint signal to detect a change in the unique fingerprint signal during operation of the industrial peripheral device (Pgs 8-10 "As a means of continuous authentication, some normal machine movement can be used as the password move for continuous authentication. 3D printers like Stratasys F123 perform nozzle cleaning between each layer. It can be used to authenticate the asset ..."). Regarding claim(s) 14, 15, and 19: The listed claim(s) is/are rejected with the same justification, mutatis mutandis, as its/their counterpart claim(s) 1, 13, and 9, respectively. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 5 and 7 are rejected under 35 U.S.C. 103 as being unpatentable over KOPROV et al, Systems and Methods for Authenticating Manufacturing Machines Through an Unobservable Fingerprinting System as applied to claims 1 and 4 above, and further in view of RATTS et al (Doc ID US 20220330031 A1). Regarding claim 5: KOPROV teaches: The system of claim 4, RATTS teaches the following limitation(s) not taught by KOPROV: wherein the industrial sensor device comprises at least one of a flow meter, mass meter, gas chromatograph, pressure transmitter, Coriolis meter, multi-variable transmitter, and guided wave radar ([031] "… As one example, one environmental sensor 160 could be a temperature sensor, a pressure sensor or a flow meter, and another environmental sensor 160 could be an accelerometer."). Using pressure sensors and flow meters as sensors in industrial applications is/are known technique(s) in the art, as demonstrated by RATTS. It would have been obvious to a person having ordinary skill in the art (PHOSITA) before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the sensor types of RATTS with the motivation to incorporate well-known and tested types of sensors which would provide data in a predictable way. These types are among a limited number of predictable solutions and are obvious to try. Regarding claim 7: KOPROV teaches: The system of claim 1, RATTS teaches the following limitation(s) not taught by KOPROV: wherein the industrial controller device is configured to remotely communicate with the industrial peripheral device to obtain the unique fingerprint signal ([0032] "… the physical environment authenticator 124 can receive data (directly or indirectly) from the given environmental sensor 160 wirelessly …"). Communicating remotely in industrial applications is/are known technique(s) in the art, as demonstrated by RATTS. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the remote communication of RATTS with the motivation to not limit the system to wired applications where it may not be practical or feasible to locate the controller device in close proximity to the industrial device. This is a known technique which has long been used to improve similar devices. Claims 6, 8, and 11 are rejected under 35 U.S.C. 103 as being unpatentable over KOPROV et al, Systems and Methods for Authenticating Manufacturing Machines Through an Unobservable Fingerprinting System as applied to claim 1 above, and further in view of APELEWICZ et al (Doc ID US 20180309786 A1). Regarding claim 6: KOPROV teaches: The system of claim 1, APELEWICZ teaches the following limitation(s) not taught by KOPROV: wherein the industrial controller device comprises at least one of a remote terminal unit, programmable logic controller, and programmable automation controller ([0046] "SCADA systems can comprise at least one of: ... a Programmable Logic Controllers (PLCs) or other field programmable gate array (FGPA), ... Remote Terminal Units (RTUs) ... and a Human-Machine Interface (HMI) …"). Utilizing a programmable logic circuit (PLC) in industrial controller devices is/are known technique(s) in the art, as demonstrated by APELEWICZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the PLC industrial controller of APELEWICZ with the motivation to use a well-known and low profile computing solution such as a PLC as a controller for an industrial application. This is a known technique which has long been used to improve similar devices. Regarding claim 8: KOPROV teaches: The system of claim 1, APELEWICZ teaches the following limitation(s) not taught by KOPROV: wherein the industrial controller device comprises a field programmable gate array programmed to extract the one or more physical properties of the output signal ([0046] "SCADA systems can comprise at least one of: ... a Programmable Logic Controllers (PLCs) or other field programmable gate array (FGPA), ... Remote Terminal Units (RTUs) ... and a Human-Machine Interface (HMI) …"). Utilizing a field programmable gate array (FPGA) in industrial controller devices is/are known technique(s) in the art, as demonstrated by APELEWICZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the FPGA industrial controller of APELEWICZ with the motivation to use a well-known and low profile computing solution such as a FPGA as a controller for an industrial application. This is a known technique which has long been used to improve similar devices. Regarding claim 11: KOPROV teaches: The system of claim 1, APELEWICZ teaches the following limitation(s) not taught by KOPROV: further comprising a supervisory control and data acquisition system configured to monitor at least one of the industrial controller device and the industrial peripheral device and to provide control thereof via the communication network ([0046] "SCADA systems can comprise at least one of: ... a Programmable Logic Controllers (PLCs) or other field programmable gate array (FGPA), ... Remote Terminal Units (RTUs) ... and a Human-Machine Interface (HMI) …"). Utilizing a supervisory control and data acquisition (SCADA) system in industrial controller devices is/are known technique(s) in the art, as demonstrated by APELEWICZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the SCADA monitoring of APELEWICZ with the motivation to use a well-known computing solution such as a SCADA to monitor an industrial application. This is a known technique which has long been used to improve similar devices. Claims 10, 16-18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over KOPROV et al, Systems and Methods for Authenticating Manufacturing Machines Through an Unobservable Fingerprinting System as applied to claims 9, 14, and 19 above, and further in view of KOSTADINOV (Doc ID US 9843449 B2). Regarding claim 10: KOPROV teaches: The system of claim 1, KOSTADINOV teaches the following limitation(s) not taught by KOPROV: wherein the industrial controller device is configured to at least one of report the detected change in the unique fingerprint signal, disengage communications with the industrial peripheral device, and stop a process of the industrial peripheral device ((44) Col 11 lines 9-22 "... the second security transformation device 314 may detect ... a change in power consumption to the non-secure device 304, a difference in an actual and expected control signal, ..., etc. Accordingly, the second security transformation device 314 may take various actions such as disabling the non-secure device 304, sending a notification to the first device 302 (e.g., a control system), remove power to the non-secure device 304 ..."). Taking remedial actions after a failed authentication attempt by a device is/are known technique(s) in the art, as demonstrated by KOSTADINOV. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the remedial actions of KOSTADINOV with the motivation to provide the functionality to respond to events such as the device not matching the expected fingerprint and being suspected of being an imposter. This is a known technique which has long been used to improve similar devices. Regarding claim 16: KOPROV teaches: The system of claim 14, KOSTADINOV teaches the following limitation(s) not taught by KOPROV: wherein processing the unique fingerprint signal comprises comparing the unique fingerprint signal with one or more known fingerprint signals to recognize a match of the unique fingerprint signal to one of the known fingerprint signals ((44) Col 11 lines 9-17 "... the second security transformation device 314 may detect ... a change in power consumption to the non-secure device 304, a difference in an actual and expected control signal, ..., etc."). Comparing a captured or received device fingerprint to a known version is/are known technique(s) in the art, as demonstrated by KOSTADINOV. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the fingerprint comparison of KOSTADINOV with the motivation to ensure that received fingerprints match an expected template closely enough to determine that it was produced by the same machine that produced the known sample. Comparing received data to known data is known work in similar fields of endeavor and variations such as this are predictable to one of ordinary skill in the art. Regarding claim 17: The combination of KOPROV and KOSTADINOV teaches: The method of claim 16, further comprising preventing communication with the industrial peripheral device if no match is recognized (KOSTADINOV (44) Col 11 lines 18-23 "... the second security transformation device 314 may take various actions such as disabling the non-secure device 304, sending a notification to the first device 302 (e.g., a control system), remove power to the non-secure device 304 ..."). Taking remedial actions after a failed authentication attempt by a device, such as preventing communication with the device, is/are known technique(s) in the art, as demonstrated by KOSTADINOV. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV and KOSTADINOV with the remedial actions of KOSTADINOV with the motivation to provide the functionality to respond to events such as the device not matching the expected fingerprint and being suspected of being an imposter. This is a known technique which has long been used to improve similar devices. Regarding claim 18: The combination of KOPROV and KOSTADINOV teaches: The method of claim 17, further comprising reporting suspicious activity if no match is recognized (KOSTADINOV (44) Col 11 lines 18-23 "... the second security transformation device 314 may take various actions such as ... sending a notification to the first device 302 (e.g., a control system), ... log a record of the suspicious behavior/condition …".). Taking remedial actions after a failed authentication attempt by a device, such as reporting the event, is/are known technique(s) in the art, as demonstrated by KOSTADINOV. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV and KOSTADINOV with the remedial actions of KOSTADINOV with the motivation to provide the functionality to respond to events such as the device not matching the expected fingerprint and being suspected of being an imposter. This is a known technique which has long been used to improve similar devices. Regarding claim 20: KOPROV teaches: The method of claim 19, KOSTADINOV teaches the following limitation(s) not taught by KOPROV: further comprising at least one of reporting the detected change in the unique fingerprint signal, disengaging communications with the industrial peripheral device, and stopping a process of the industrial peripheral device, if a change in the unique fingerprint signal is detected (KOSTADINOV (44) Col 11 lines 18-23 "... the second security transformation device 314 may take various actions such as disabling the non-secure device 304, sending a notification to the first device 302 (e.g., a control system), remove power to the non-secure device 304 ..."). Taking remedial actions after a failed authentication attempt by a device, such as stopping the device, is/are known technique(s) in the art, as demonstrated by KOSTADINOV. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the remedial actions of KOSTADINOV with the motivation to provide the functionality to respond to events such as the device not matching the expected fingerprint and being suspected of being an imposter. This is a known technique which has long been used to improve similar devices. Claims 12 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over KOPROV et al, Systems and Methods for Authenticating Manufacturing Machines Through an Unobservable Fingerprinting System as applied to claim 1 above, and further in view of WANG et al (Doc ID US 20260222998 A1). Regarding claim 12: KOPROV teaches: The method of claim 19, WANG teaches the following limitation(s) not taught by KOPROV: further comprising at least one of reporting the detected change in the unique fingerprint signal, disengaging communications with the industrial peripheral device, and stopping a process of the industrial peripheral device, if a change in the unique fingerprint signal is detected (KOSTADINOV (44) Col 11 lines 18-23 "... the second security transformation device 314 may take various actions such as disabling the non-secure device 304, sending a notification to the first device 302 (e.g., a control system), remove power to the non-secure device 304 ..."). Measuring a device’s signal characteristics, such as jitter, data rate (baud rate), and delay, is/are known technique(s) in the art, as demonstrated by WANG. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the device fingerprinting and authentication of KOPROV with the signal metrics of WANG with the motivation to utilize known types of signal metrics from which to extract the device fingerprint. This method has been used to improve similar devices in the same field of endeavor. Regarding claim 13: The combination of KOPROV and WANG teaches: The system of claim 12, wherein the one or more physical properties of the output signal are altered to define the unique fingerprinted signal (KOPROV Pg 4 "We tested two control methods for password movement: simultaneous XYZ movement and change in spindle RPM versus one at a-time axis movement and spindle rotation."). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The website https://ez.analog.com/ez-blogs/b/engineering-mind/posts/securing-spi-and-why-it-matters provides general information about the SPI and I2C communication protocols relevant to claim 3. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON BINCZAK whose telephone number is (703) 756-4528. The examiner can normally be reached M-F 0800-1600 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRANDON BINCZAK/Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Apr 25, 2024
Application Filed
Aug 13, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730897
Automation Platform for Pentest Collaboration
3y 8m to grant Granted Sep 08, 2026
Patent 12695767
PREDICTIVE BAD EVENT ALERT GENERATION
4y 2m to grant Granted Jul 28, 2026
Patent 12694091
SYSTEMS AND METHODS FOR COLLECTIVE ATTESTATION OF SPDM-ENABLED DEVICES IN AN INFORMATION HANDLING SYSTEM (IHS)
3y 4m to grant Granted Jul 28, 2026
Patent 12634133
COMPUTING SYSTEMS AND METHODS FOR PROTECTING APPLICATION PROGRAMMING INTERFACES WITH TWO-FACTOR AUTHENTICATION
3y 4m to grant Granted May 19, 2026
Patent 12470534
PARTIAL POOL CREDENTIALLING AUTHENTICATION SYSTEM
2y 6m to grant Granted Nov 11, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
39%
Grant Probability
72%
With Interview (+33.4%)
3y 1m (~8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 64 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month