Prosecution Insights
Last updated: October 01, 2026
Application No. 18/702,144

IT Security of an Automation System

Non-Final OA §103
Filed
Apr 18, 2024
Priority
Oct 18, 2021 — DE 10 2021 211 755.4 +2 more
Examiner
WILLIAMS, JEFFERY L
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Siemens Aktiengesellschaft
OA Round
5 (Non-Final)
69%
Grant Probability
Favorable
5-6
OA Rounds
1y 3m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 69% — above average
69%
Career Allowance Rate
349 granted / 507 resolved
+10.8% vs TC avg
Strong +19% interview lift
Without
With
+19.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
23 currently pending
Career history
534
Total Applications
across all art units

Statute-Specific Performance

§101
9.1%
-30.9% vs TC avg
§103
35.8%
-4.2% vs TC avg
§102
22.4%
-17.6% vs TC avg
§112
30.3%
-9.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 507 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This action is in response to the communication filed on 8/18/26. Claims 1 – 4, 6 – 12 are pending. All objections and rejections not set forth below have been withdrawn. Any references to applicant’s disclosure are made by way of applicant’s pre-grant printed patent publication, US 2025/0013732 A1. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 8/18/26 has been entered. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “a check module to”, “a generation module to”, and “an authentication module to” in claim 12. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1 – 4, 6 – 9, and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Venkataramani, US 2018/0004934 A1, in view of Mautone et al. (Mautone), US 2023/0224325 A1, in view of Hulshof, US 2022/0045848 A1. Regarding claim 1, Venkataramani discloses: A method for ensuring security of an automation system (e.g. Venkataramani, Abstract), the method comprising: checking a piece of authentication information previously provided for authentication at an end point of the automation system for a minimum security requirement including assessing meta-information (e.g. Venkataramani, fig. 1:114, 131, 133) which includes …and a generation time of a generation of the password (e.g. Venkataramani, par. 37 – password “meta-information” comprises a history of password change times informing when a password was last changed), related to the piece of authentication information stored at the end point (e.g. Venkataramani, fig. 1:132; fig. 2:203; par. 20, 23, 27, 30, 38, 39). Herein the system compares previously used passwords (i.e. authentication [information] stored at an endpoint – e.g. fig. 1:113) for accessing profiles, accounts, computers and/or services (i.e. end points) against metadata describing password characteristics and usage (e.g. fig. 1:114, 131, 133) so as to determine, at least, a compliance with the requirements of a password policy, and if they do not meet compliance, then the passwords are marked to be changed during authentication. Venkataramani does not appear to explicitly teach that the “…access[ed] meta-information …includes a hash value of a password…”. However, like Venkataramani, Mautone teaches a system for the automated management of passwords (e.g. Mautone, Abstract; par. 3-7) and for accessing meta-information related to stored passwords so as to aid in the management of the passwords (e.g. Mautone, par. 12, 40, 115, 117). Furthermore, Mautone teaches that the “…access[ed] meta-information …includes a hash value of a password…” (e.g. Mautone, par. 138 – 142). It would have been obvious to one of ordinary skill in the art to recognize the teachings of Mautone for accessing meta-information including a hash of the password within the system of Venkataramani. This would have been obvious because one of ordinary skill in the art would have been motivated by the teaching that accessing the hash of the password and performing comparisons of hashes instead of the password helps to further provide security against breaches of the password (e.g. Mautone, par. 138). Thus, the combination enables: subjecting the piece of authentication information and/or meta-information previously provided to a comparison with authentication information and/or meta-information from preceding or revealed security incidents and, depending on the comparison assessing whether the minimum requirement is met (e.g. Venkataramani, par. 23, 27, 36, 37, claim 4 – herein the passwords and/or indicators are checked against policies and/or rules and/or historical information based upon security breaches – i.e. “information and/or metainformation from …security incidents”, and depending upon the check passwords may be indicated as insecure – i.e. requiring change). if the piece of authentication information does meet the minimum security requirement, using an authentication module to authenticate at the end point (e.g.. Venkataramani, fig. 1:111; par. 33 – compliant passwords are used by the client for authentication to the profiles, accounts, computers and/or services) and storing updated meta-information related to the piece of authentication information at the end point (e.g. Venkataramani, par. 27, 28, 35, 37, claim 4). Herein, encrypted passwords at the end point are further associated with stored rules, that are downloaded and updated from a manager, i.e. “updated meta-information” (e.g. fig. 1:114; par. 27). Furthermore, additionally stored in association with the encrypted passwords are indicators characterizing the time the password was changed and how many times the password was used for authentication, i.e. “updated meta-information” (e.g. par. 27). else, if the piece of authentication information does not meet the minimum security requirement, generating a new piece of authentication information, and providing the authentication module with the new piece of authentication information to authenticate at the end point (e.g. Venkataramani, fig. 1:111; par. 28, 35 – new passwords are generated to replace the non-compliant passwords, wherein the new password is stored and ready to be used for authentication to a profile, account, computer and/or service) and storing meta-information related to the new piece of authentication information (e.g. Venkataramani, par. 28). Herein, the password agent generates a new password, which is encrypted and stored at the endpoint, and furthermore stores updated password rules, i.e. “meta-information related to the new piece of authentication information at the endpoint”. While the combination teaches the use of password hashes by a password manager, the combination does not appear to explicitly teach that the password hash, i.e. “meta-information related to the new piece of authentication information”, is stored along with the password at the end-point. However, Hulshof, like Venkataramani and Mautone, also discloses a password manager for updating and storing user passwords (e.g. Hulshof, par. 5, 49), and further teaches that the password manager should store the hash value of the password along with the password (e.g. Hulshof, par. 49). It would have been obvious to one of ordinary skill in the art to apply the password hash storage teachings of Hulshof within the combination of Veknatramani and Mautone for a password manager that updates and protects the security of passwords using hash values of the passwords. This would have been obvious because one of ordinary skill in the art would have been motivated by the teachings that using stored hash values of passwords for authentication decreases the security risk to a password during authentication (e.g. Hulshof, par. 12, 49; see also Mautone, par. 138). Thus, the combination enables: the stored meta-information related to the new piece of authentication information including a hash value of the new piece of authentication information (e.g. Hulshof, par. 49). Regarding claim 2, the combination enables: wherein the piece of authentication information comprises the password (e.g. Venkataramani, Abstract). Regarding claim 3, the combination enables: wherein the minimum requirement comprises a minimum length or a minimum complexity of the authentication information (e.g. Venkataramani, par. 3, 36). Regarding claim 4, Venkataramani discloses an authentication module for providing a password to be used for authentication. However, Venkataramani fails to disclose that the authentication module provides the password by emulating an entry. However, Mautone also discloses means for providing a password for authentication (e.g. Mautone, Abstract), and furthermore teaches that the provision is by means of injecting the password, or emulating keystroke entry of the password (e.g. Mautone, par. 58, 59). It would have been obvious to one of ordinary skill in the art to employ the emulation teachings of Mautone within the system of Venkataramani. This would have been obvious because one of ordinary skill in the art would have been motivated by the teaching that the emulation of password entry provides convenience to the user (e.g. Mautone, par. 58, 59). Thus, the combination enables: wherein the authentication module emulates an entry of the authentication information (e.g. Venkataramani, par. 33; Abstract; Mautone, par. 58, 59). Regarding claim 6, the combination enables: further comprising repeating the method and checking the piece of meta-information to determine whether the minimum requirement is met (e.g. Venkataramani, par. 27). Regarding claim 7, the combination enables: wherein the comparison comprises comparing a hash value of the piece of authentication information and/or meta-information previously provided with a hash value of the authentication information and/or meta-information from preceding or revealed security incidents, such that the comparison does not require comparing plaintext of the authentication information and/or meta-information (e.g. Venkataramani, par. 27, 37, 36, 37, claim 4; Mautone, par. 138 – 142 – herein encrypted and/or hashed information associated with the passwords is compared - such that plaintext is not exposed). Regarding claim 8, it is rejected for the same reasons as claim 4, wherein the combination enables: wherein the authentication module is designed for authentication using an emulation of an entry of the new piece of authentication information (e.g. Venkataramani, par. 33; Abstract; Mautone, par. 59). Regarding claim 9, the combination enables: wherein the authentication module is set up and designed for cryptographically protected storage of the new piece of authentication information (e.g. Venkataramani, par. 20, 35; fig. 8:113). Regarding claim 12, it is a system claim comprising the means for implementing the method of the above claims, and it is rejected, at least, for the same reasons. Furthermore, because the combination enables: A security system for an automation system (e.g. Venkataramani, fig. 1), the security system comprising: an authentication module (e.g. Venkataramani, fig. 1:111, 110); a check module … (e.g. Venkataramani, fig. 1:132; fig. 2:203) … a generation module … (e.g. Venkataramani, fig. 8:111) … PLEASE NOTE, the applicant’s claim 12 does not explicitly limit the scope of the claim to “…comprising: … an authentication module…”. Rather, the applicant has amended the claim to recite a characterization describing the function of an authentication module (i.e. “the authentication module to receive …”). However, this functional description of an authentication module does not include a statement that the authentication module itself is actually included as a structure of the claimed security system. Thus, the examiner does not interpret claim 12 as being structurally limited by an authentication module. However, for the sake of compact prosecution, and in anticipation of appropriate amendment by the applicant, the examiner notes that the prior art also teaches “… an authentication module … (e.g. Venkataramani, fig. 1:111, 110). Claims 10 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Venkataramani, US 2018/0004934 A1, in view of Mautone et al. (Mautone), US 2023/0224325 A1, in view of Hulshof, US 2022/0045848 A1, in view of Braun, US 2006/0026672 A1. Regarding claim 10, Venkataramani discloses a system for authentication and updating passwords. However, Venkataramani does not disclose that the authentication and password updates could be used within industrial automation, production, and processing systems. However, Braun teaches that industrial automation, production, and processing systems also require the use of password authentication and password updates. It would have been obvious to one of ordinary skill in the art to apply the system teachings of Braun within the context of Venkataramani. This would have been obvious because one of ordinary skill in the art would have been motivated by the teaching that industrial automation, production, and processing systems require security achieved via the use of passwords (e.g. Braun, par. 2 – 6). Thus, the combination enables: wherein the automation system comprises a production system and/or a process technology system (e.g. Braun, par. 2). Regarding claim 11, it is rejected for the same reasons as claim 10, and furthermore because the combination enables: wherein the endpoint comprises at least one production tool and/or an industrial control device and/or a process technology device (e.g. Venkataramani, par. 2-8; fig. 1:12). Response to Arguments Applicant's arguments filed 8/18/26 have been fully considered but they are not persuasive. Applicant argues or alleges essentially that: … … It does not compare the authentication information or its meta-information with authentication information or meta-information from preceding or revealed security incidents. Nor does it assess the minimum security requirement depending on such a comparison. At most, Venkataramani uses a security breach as a reason to update password- expiration settings globally; it does not use incident-derived authentication information or incident-derived meta-information as comparison data for determining whether the particular authentication information meets the minimum security requirement. … (Remarks, pg. 7, 8) Examiner respectfully responds: The examiner respectfully disagrees. Specifically, the prior art explicitly discloses the comparison of a password with that of information associated with breached passwords and rules based upon password breach events (i.e. “authentication information and/or meta-information from …security incidents”). Furthermore, upon such comparison, the password is accessed to be insecure, i.e. not meeting a minimum security requirement, and flagged to be changed. Furthermore, also disclosed is determining minimum security requirements necessary for changing the password (e.g. Venkataramani, par. 23, 27, 36, 37, claim 4). Applicant argues or alleges essentially that: … Applicants further respectfully submit that even under the Examiner's characterization of the rejection set forth in the Advisory Action mailed July 16, 2026, the proposed modification is still improper because it is contrary to Hulshofs own express teaching and would frustrate the very security rationale Hulshof describes. … … … A proposed modification that would render the reference relied upon unsatisfactory for its intended purpose, or that would change its principle of operation, does not support a conclusion of obviousness. … … …Modifying Venkataramani so that the hash is stored at Venkataramani endpoint-the very "computer" Hulshof treats as untrusted-is squarely contrary to that principle of operation and defeats Hulshof's intended purpose. A skilled artisan, starting from Hulshof's own teaching, would not have been motivated to relocate the hash to the one place Hulshof says it must not be stored. … (Remarks, pg. 8 – 10) Examiner respectfully responds: The examiner respectfully disagrees, at least for the reason that, contrary to the allegations of the applicant, Hulshof does not teach that the specific security architecture of Venkataramani, comprising a password manager, having an encrypted storage of credential information on a client computer, is insecure. Additionally, those having ordinary skill in the art (as further evidenced by Mautone, e.g. fig. 1:144) do not consider the storage of encrypted credential information on a client computer to be insecure. Furthermore, there is no evidence of record that the storage of a password hash, along with the password, within the encrypted storage of Venkataramani would render the reference of Venkataramani unsatisfactory for its intended purpose nor would it change the principle of operation of the combination of Venkataramani and Mautone which makes use of password hashes to further protect against the disclosure of the password. Applicant argues or alleges essentially that: … … Nor is the required motivation supplied by the Examiner's characterization of the modification as a mere application of a "known" technique. Advisory Action at 2. Under KSR and In re Kahn, an obviousness rejection must still articulate a reason, with rational underpinning, for the specific modification proposed-not merely assert that a technique was known in the abstract. … … (Remarks, pg. 10) Examiner respectfully responds: The examiner respectfully notes that the office actions of record clearly and explicitly articulated a motivation for why one of ordinary skill in the art would also store the password hash along with the stored password. The applicant’s remarks are unpersuasive, at least, for the reason that they fail to ever address the specific motivation stated on record. Applicant argues or alleges essentially that: … … Because Venkataramani system does not present the keyboard-entry exposure problem that motivates Hulshof's hash-storage arrangement, a skilled artisan would have had no apparent reason-and the Office has identified none to import that arrangement into Venkataramani. … (Remarks, pg. 10, 11) Examiner respectfully responds: The examiner respectfully notes that the applicant’s remarks are unpersuasive, at least, for the reason that the office action does not rely upon an importation of the entire architecture of Hulshof into that of Venkataramani. Rather, the rejection clearly relies only upon a teaching that a password hash can be stored along with the password. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JEFFERY L WILLIAMS whose telephone number is (571)272-7965. The examiner can normally be reached on 7:30 am - 4:00 pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JEFFERY L WILLIAMS/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Show 6 earlier events
Feb 05, 2026
Response after Non-Final Action
Feb 11, 2026
Non-Final Rejection mailed — §103
Apr 20, 2026
Response Filed
May 19, 2026
Final Rejection mailed — §103
Jul 08, 2026
Response after Non-Final Action
Aug 18, 2026
Request for Continued Examination
Aug 19, 2026
Response after Non-Final Action
Aug 25, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732481
SUPPORTING ZONE-BASED POLICY ENFORCEMENT FOR A FIREWALL CONNECTED TO A ONE-ARM LOAD BALANCER
1y 9m to grant Granted Sep 08, 2026
Patent 12712748
PHYSICALLY UNCLONABLE FUNCTION (PUF) AUTHORITY FOR IDENTIFICATION TRUST IN COMMUNICATIONS WITH INTERNET OF THINGS (IOT) DEVICES
1y 8m to grant Granted Aug 18, 2026
Patent 12688293
PROACTIVE BROWSER CONTENT ANALYSIS
1y 6m to grant Granted Jul 21, 2026
Patent 12683810
RADIO AUTHENTICATION AS ROOT OF TRUST FOR TRANSPORT LAYER SECURITY
2y 1m to grant Granted Jul 14, 2026
Patent 12639417
AUTOMATED MONITORING AND UPDATING OF PASSCODES FOR APPLICATIONS AND WEB SITES/SERVICES
2y 4m to grant Granted May 26, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
69%
Grant Probability
88%
With Interview (+19.0%)
3y 9m (~1y 3m remaining)
Median Time to Grant
High
PTA Risk
Based on 507 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month