DETAILED ACTION
This action is responsive to RCE filed on April 21st, 2026.
Claims 1~18 and 20 are examined.
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Prosecution Application
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04/21/26 has been entered.
Response to Arguments
Applicant’s arguments with respect to claims 1~18 and 20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
In response to Applicant’s argument regarding that Siddesh does not specifically teach the authentication processor being integrated on at least one of a separate device on a central server of the industrial plant or a SCADA system of the industrial plant. Examiner respectfully disagrees. Just because Siddesh pointed out in the state of the art that CAPTCHA servers require, however, more resources in terms of memory capacity and energy consumption, for example, extensive databases, than are available, for example, in an industrial plant at the fieldbus level or in a field device, is not an explicit discouragement for using separate CAPTCHA servers. The motivation for placing the CAPTCHA inside the field device is to secure against cyber-attacks, especially DDos attacks. Applicant’s claimed invention is explicitly making the CAPTCHA functionality separate from the edge device, a predictable variation of prior art elements according to their established functions. It is a design choice that when implemented in Siddesh, would have allowed one of ordinary skill in the art to reasonably conclude the field device would continue operating without the CAPTCHA functionalities. Hence when combining with the newly cited reference by Meriac, the combination teaches the claimed invention as currently amended.
Claim Rejections - 35 USC § 102
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claim 12 is rejected under 35 U.S.C. 102(a)(1) as being anticipated by Siddesh et al. hereinafter Siddesh (U.S 2015/0244697).
Regarding Claim 12,
Siddesh taught a method for enabling secure access to an industrial edge device of an industrial plant, the method comprising:
establishing communication between the industrial edge device and a user device [¶40, field device FD connected with a servicing device CU2];
transmitting, by the user device, a request to the industrial edge device, to access the industrial edge device [¶41, the servicing device CU2 requests interaction with the web server WS2 (FD)];
receiving, at the industrial edge device, the request [¶42, following receipt of the request by the web server WS (FD)];
in response to the request, generating by an authentication processor associated with the industrial device, a graphical authentication task [¶11, the field device has a function for distinguishing computers from humans; ¶38];
transmitting, by the authentication processor, the graphical authentication task to the user device for the user device to execute to provide as a response thereto [¶11, the field device has a function for distinguishing computers from humans; ¶38]; and
verifying, by the authentication processor, the response provided by the user device to determine whether to grant the user device access to the industrial edge device, wherein verifying the response comprises comparing the response to a predetermined range of predetermined model responses to detect if the response falls within the predetermined range of predetermined model responses such that the authentication processor grants the user access to the industrial edge device in response to the response falling within the range of predetermined model responses [¶11, upon an accessing of the field device via the web server, the function for distinguishing computers from humans is executed, in order to assure that the accessing of the field device is being done by a human user]. Note: utilizing CAPTCHAs imply that responses are compared to prior responses that are converted into a score that comprises a range or threshold. A lower score would be more indicative of a user (and thus, granted access) while a higher score would indicate a machine (access denied).
Regarding Claims 13~17 and 20, the claims are similar in scope to claims 6~10 below and therefore, rejected under the same rationale.
Claim Rejections - 35 USC § 103
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claims 1~3 and 6~10 are rejected under 35 U.S.C. 103 as being unpatentable over Siddesh et al. hereinafter Siddesh (U.S 2015/0244697) in view of Meriac (U.S 2017/0237770).
Regarding Claim 1,
Siddesh taught an authentication system for an industrial plant, the authentication system comprising:
an industrial edge device configured for at least one of monitoring and controlling an operation within the industrial plant [¶2, industrial plants are field devices, which serve for determining and/or monitoring process variables];
a user device configured to communicate with the industrial edge device to request access to the industrial edge device [¶40, servicing device CU2]; and
an authentication processor associated with the industrial edge device, the authentication processor configured to communicate a graphical authentication task to the user device in response to the request for access [¶11, the field device has a function for distinguishing computers from humans; ¶38],
the authentication processor further configured to verify a response to the graphical authentication task from the user device for determining whether to grant the user device access to the industrial edge device [¶11, upon an accessing of the field device via the web server, the function for distinguishing computers from humans is executed, in order to assure that the accessing of the field device is being done by a human user].
While Siddesh taught in order to verify that the request is from a human and not a computer, before accessing the web server WS by the computing unit CU1 is permitted, a CAPTCHA query is performed. To this end, the web server WS sends, likewise via the Internet I1, a request 2 to a CAPTCHA server CS, the CAPTCHA server creates a CAPTCHA or retrieves a CAPTCHA from a database DB1 and sends the CAPTCHA as response 3 to the request 2 to the web server WS1 [¶35] however, did not specifically teach the authentication processor being integrated on at least one of a separate device on a central server of the industrial plant or a Supervisory Control and Data Acquisition (SCADA) system of the industrial plant.
Meriac taught the authentication processor being integrated on at least one of a separate device on a central server of the industrial plant or a Supervisory Control and Data Acquisition (SCADA) system of the industrial plant [¶73~¶75, the IoT device 1 generates a communication 115 which includes a task. On receiving the communication 115, the genuine devices 10a-n may present details of the communication 115 to a user of the genuine device 10 a-10 n to request user authorisation to solve 105 the task and/or to connect to the IoT device 1; ¶71, such tasks may be generated by a trusted resource (e.g. a server) and provisioned on the IoT device whereby the solution may also be generated by the trusted device and transmitted to the IoT device, such that the IoT device is used as a proxy device for the server; ¶164, the IoT device 1 may transmit a ‘CAPTCHA’ (task) to the connecting device as a task to be solved, whereby the solution to the CAPTCHA may be sent back to the IoT device 1 for verification].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention was made, to combine, Meriac’s teaching of limitations with the teachings of Siddesh, because the combination reduce the number of unwanted communications being sent thereto from rogue devices [¶7].
Regarding Claim 2,
Siddesh taught wherein the industrial edge device comprises one of a remote terminal unit (RTU), programmable logic controller (PLC), programmable automation controller (PAC), sensor, instrument, data radio, and modem [¶2, field devices include all equipment used in a plant].
Regarding Claim 3,
Siddeshn taught wherein the user device comprises a personal device or a shared device [¶40, the servicing device CU2 can also be a PC, or a mobile device, i.e., a smart phone or a tablet].
Regarding Claim 6,
Siddesh taught wherein the graphical authentication task comprises at least one of a graphical puzzle task, a Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) task, and a drawing task [Fig. 4, CAPTCHA].
Regarding Claim 7,
Siddesh taught wherein the graphical authentication task comprises at least one of a static image and video image [¶45, CAPTCHA in the form of distorted pictures].
Regarding Claim 8,
Siddesh taught wherein the authentication processor is further configured to communicate one or more additional authentication tasks to the user device in response to the request for access and to verify an additional response to the one or more additional authentication tasks for determining whether to grant the user device access to the industrial edge device [¶46, login page to input username/password followed by CAPTCHA].
Regarding Claim 9,
Siddesh taught wherein at least one of the one or more additional authentication tasks comprises a credentials-based authentication task [¶46, login page to input username/password].
Regarding Claim 10,
Siddesh taught wherein the authentication processor is configured to execute processor-executable instructions to generate the graphical authentication task [¶54, low power microprocessor used in field devices].
Claims 4 and 5 are rejected under 35 U.S.C. 103 as being unpatentable over Siddesh and Meriac in view of Nixon et al. hereinafter Nixon (U.S 2022/0078267).
Regarding Claim 4,
Siddesh-Meriac-Nixon taught wherein the user device communicates with the industrial edge device using a Transmission Control Protocol/Internet (TCP/IP) protocol [¶50, different external devices, hosts or servers connected to the field device 10 via the communication interface 20 that conform to any desired standard communication protocol, such as an IP or packet-based protocol such as TCP, UDP].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention was made, to combine, Nixon’s teaching of limitations with the teachings of Siddesh and Meriac, because the combination enables communication connections between the field device 10 and external client devices to be established independently of one another [¶52].
Regarding Claim 5,
Siddesh-Meriac-Nixon taught wherein the user device communicates with the industrial edge device using a User Datagram Protocol (UDP) [¶50, different external devices, hosts or servers connected to the field device 10 via the communication interface 20 that conform to any desired standard communication protocol, such as an IP or packet-based protocol such as TCP, UDP]. The rationale to combine as discussed in claim 4, applies here as well.
Claims 11 and 18 is rejected under 35 U.S.C. 103 as being unpatentable over Siddesh and Meriac in view of Shimizu et al. hereinafter Shimizu (U.S 2023/0280724).
Regarding Claims 11 and 18,
Siddesh-Meriac-Shimizu taught wherein the authentication processor comprises the Supervisory Control and Data Acquisition (SCADA) system of the industrial plant, and wherein the SCADA system is configured to generate the graphical authentication task [¶53, SCADA Web HMI System includes HMI server device 2 and HMI client device 3. Note: since Siddesh’s field devices has a web server that allows access by servicing devices, the combination with Shimizu’s SCADA system reads on the claim].
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention was made, to combine, Shimizu’s teaching of limitations with the teachings of Siddesh and Meriac, because the combination enables real-time system monitoring, process control, and data collection [¶3].
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HEE SOO KIM whose telephone number is (571)270-3229. The examiner can normally be reached M-F 9AM-5PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas Taylor can be reached on (571) 272-3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HEE SOO KIM/Primary Examiner, Art Unit 2443