Prosecution Insights
Last updated: October 01, 2026
Application No. 18/732,332

SYSTEM AND METHOD FOR ANOMALY BEHAVIOR ANALYSIS AND DETECTION IN INDUSTRIAL CONTROL SYSTEMS

Non-Final OA §103§112
Filed
Jun 03, 2024
Priority
Feb 21, 2024 — TW 113106226
Examiner
WALIULLAH, MOHAMMED
Art Unit
Tech Center
Assignee
National Cheng Kung University
OA Round
1 (Non-Final)
87%
Grant Probability
Favorable
1-2
OA Rounds
0m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
641 granted / 739 resolved
+26.7% vs TC avg
Moderate +11% lift
Without
With
+11.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
24 currently pending
Career history
756
Total Applications
across all art units

Statute-Specific Performance

§101
7.7%
-32.3% vs TC avg
§103
62.6%
+22.6% vs TC avg
§102
4.8%
-35.2% vs TC avg
§112
11.7%
-28.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 739 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim limitation of 1 “a data collection module…”, “a data processing module… ” , “ a response execution module…”, “an anomaly detection module… ‘’invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure(hardware), material, or acts to the function. Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. Applicant may: (a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. Dependent claims 2-7 do not cure the deficiencies, also rejected accordingly. The term “a high-frequency and high-accuracy” in claim 1 is a relative term which renders the claim indefinite. The term “high-frequency and high-accuracy” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. Appropriate correction required. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-10 are rejected under 35 U.S.C. 103 as being unpatentable over KROYZER et al(WO 2015104691 A2) in view of ZHANG(CN 201811404708 A). With regards to claim 1, KROYZER discloses, An anomaly behavior analysis and detection system in an industrial control system (FIG. 2 shows a simplified schematic diagram of a system for detection of anomalies in an industrial control system, according to one or more embodiments of the disclosed subject matter.), comprising: a data collection module configured for collecting operation data from the industrial control system (FIG 1 step 2 and associated text; page 8 line 27- 35; In the first step 2 shown in FIG. 1, data of correct operational parameters is collected from at least one input device. For example, data may be provided from industrial control system 104 to the anomaly detection system 100 via an input/output (I/O) interface 112. The input device may include at least one of, for example, a sensor 108, from the SCADA 106 directly, from a distributed control system (DCS) 110, from remote FO, a network, a virtual network, data logs and known libraries from databases. In some embodiments, the data collected may include for example at least one of: data from sensors operating within the control system 104, tags (i.e., from SCADA 106, PLC 136, or DCS 1 10), SCADA processing data, IT data, operator data, log files (i.e., from operating systems, IT, and/or SCADA 106), network data or communication data.); a data processing module configured for preliminarily processing the collected operation data (FIG 1 step 4, 6 and associated text;); an anomaly detection module, including one or more detection units [[based on a finite state machine (FSM) configured for]] actively querying and analyzing the processed data according to a predefined [[state machine]] model to identify potential anomaly behaviors (FIG 1 step 10 and associated text; page 6 line 5-11; In one or more embodiments, a method of detecting an anomaly in an industrial process plant can include predicting a value of an operational parameter of the industrial process plant after a control device therein has been subject to a known operating state modification. The method can further include instructing the control device to have the known operating state modification and comparing a value of the operational parameter resulting from the instructing with the predicted value. The method also includes controlling the industrial control system responsively to a result of the comparing.); and a response execution module configured for executing predefined response measures after the anomaly behaviors are identified by the detection unit (FIG 1 step 12 and associated text; page 6 line 12-20; In one or more embodiments, a method of detecting an anomaly in an industrial process plant can include predicting a response of the industrial process plant to a perturbation produced by a control device therein. The response can be indicated by a change in an operational parameter of the industrial process plant. The method can further include comparing an actual response of the industrial process plant to the perturbation with the predicted result, and determining existence of an anomaly responsively to the comparing. Page 14 line 0-9; In the responding step 260, the industrial control system 410 takes action in response to the result of the determining step 250. If the result indicates that an anomaly has occurred, the industrial control system 410 takes appropriate corrective action. Such an action may include alerting an operator, for example by displaying an alert and/or producing an audible alert, directing one or more of the control elements 14 to operate in such a way so as to mitigate the effects of the anomaly, or shutting down part or all of the industrial process plant); KROYZER does not exclusively but ZHANG teaches, an anomaly detection module, including one or more detection units based on a finite state machine (FSM) configured for analyzing data according to a predefined state machine model to identify potential anomaly behaviors (page 4 para 10; It can be understood that the expression mode of the embodiment sequence model can be used but not limited to finite state machine (FSM), method for detecting the abnormal sequence can be used but not limited to probability analysis, model detection technology (ModelChecker) and so on. In the field of industrial control abnormality detection, the expression mode of any sequence mode and the method based on sequence abnormality detection are in the protection range of the device of the present embodiment.) wherein, the anomaly detection module is enabled, through an actively-querying finite state machine (FSM) mechanism, to identify non-standard operation behaviors more effectively (page 8 para 9;It can be understood that the expression mode of the sequence model can be used but not limited to finite state machine (FSM), method for detecting the abnormal sequence can be used but not limited to probability analysis, model detection technology (Model Checker) and so on. In the field of industrial control abnormality detection, the expression mode of any sequence mode and the method based on sequence abnormality detection are in the protection range of the method of the embodiment.), and perform a high-frequency and high-accuracy anomaly behavior detection function in the industrial control system (Abstract: according to the continuously obtained network flow, automatically generating network safety baseline, by analyzing history baseline sequence trend; it can find the potential threat of baseline sequence gradually deviates from normal value; the method of the embodiment reduces the operation complexity of generating industrial control safety baseline, improves the stability of the baseline safety). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention accur was made to modify KROYZER’s system with teaching of ZHANG in order to provides an industrial control network anomaly detection(ZHANG Abstract) With regards to claim 2, KROYZER in view of ZHANG discloses, wherein the anomaly behavior analysis and detection system in the industrial control system enhances information exchange and security between devices through a Modbus/TCP communication protocol (ZHANG The Schneider upper computer communicates with the PLC based on the Modbus protocol without authentication. Generally, the upper computer sends a request based on a certain function code, the PLC responds to the corresponding function code. The request function code is usually: reading the coil, reading the register, reading the discrete input and so on. PLC for the request of the upper computer, giving the response of the corresponding point value. The method of the present embodiment can give an alarm of the following abnormal situations:)and constructs a Programmable Logic Controller (PLC) state set through continuous discovery and monitoring on PLC states ( page 8 line 33-35; In some embodiments, the data collected may include for example at least one of: data from sensors operating within the control system 104, tags (i.e., from SCADA 106, PLC 136, or DCS 1 10), SCADA processing data, IT data, operator data, log files (i.e., from operating systems, IT, and/or SCADA 106), network data or communication data.). With regards to claim 3, KROYZER further discloses, wherein the data collection module further comprises a sensor data interface unit for directly collecting operation data from the sensors in the industrial control system, so as to improve the real-time and accuracy of data collection (Page 8 line 27-35; In the first step 2 shown in FIG. 1, data of correct operational parameters is collected from at least one input device. For example, data may be provided from industrial control system 104 to the anomaly detection system 100 via an input/output (I/O) interface 112. The input device may include at least one of, for example, a sensor 108, from the SCADA 106 directly, from a distributed control system (DCS) 110, from remote FO, a network, a virtual network, data logs and known libraries from databases. In some embodiments, the data collected may include for example at least one of: data from sensors operating within the control system 104, tags (i.e., from SCADA 106, PLC 136, or DCS 1 10), SCADA processing data, IT data, operator data, log files (i.e., from operating systems, IT, and/or SCADA 106), network data or communication data.). With regards to claim 4, KROYZER further discloses, wherein the data processing module comprises a data standardization unit for converting the collected operation data into a unified format for subsequent anomaly detection and analysis (Page 9 line 27-35; In the fifth step 10, current operational parameters may be detected in the industrial control system. For example, the analysis module 116 can receive data from the industrial control system 104 via I/O 1 12 and analyze the data as it is received in order to determine if an anomaly is present in the system. In particular, the anomaly detection system 100 may check the current operational parameter(s) (which may be the same parameters used to form the training data or different from the training data parameters but related in some way to the training data parameters), or the correlation of at least two current operational parameters, for any potential deviation from the training data that would indicate an abnormal or incorrect operation of the industrial control system 104. Such a deviation may be detected, if a portion of the industrial control system has been taken over by an attacker or otherwise manipulated. ). With regards to claim 5, KROYZER further discloses, wherein the detection unit of the anomaly detection module is further provided with an adaptive learning unit so as to automatically adjust detection parameters based on historical data to improve the accuracy of identification of anomaly behaviors (Page 9 line 8-15; In the third step 6, the data of the correct operational parameters may be analyzed and stored as training data. The step of analyzing may be broken down into two discreet steps. The data may first be processed and then analyzed. The step of processing may include: data correlation (e.g., correlating at least two operational parameters), rate of change differences, creating histograms, spectral analysis, recording delay patterns and interpreting the smoothness of the data. The analysis of the data include: developing a learning algorithm, developing temporal causalities, model analysis, Markovian connectivity analysis, Markov random field analysis and differential Markov random field analysis.; FIG 4-6 and associated text;). With regards to claim 6, KROYZER further discloses, wherein the response execution module further comprises a security incident log recording unit for recording all the identified anomaly behaviors and the response measures of the system, so as to facilitate post-incident analysis and audit (page 10 line 13-19; In the sixth step 12, a communication function may be performed when the detected deviation is above or below a predefined threshold. For example, the communication function may include at least one of: creating an alarm (e.g., a visual or auditory alarm via alarm module 122), communicating data to at least one of a control system (e.g., to the SCADA 106 or the DCS 110) and an operator (e.g., to a system user via user interface 120 or to a user of the industrial control system via UMI 132), and recording the data (e.g., in data storage module 124) or the alarm.). With regards to claim 7, KROYZER further discloses, wherein by setting different monitoring frequencies in the anomaly detection module, a frequency of the active query is allowed to be dynamically adjusted according to an actual operation of the industrial control system, thereby effectively improving the detection sensitivity of the anomaly behaviors without adding additional system burden (page 15, line 8-30; The monitoring may occur or begin before, during, and/or after the modification. The method may further comprise performing the steps at regular or random intervals. The predicting may be performed based on calculation of the effect the modification will have on the industrial process plant. The predicting may be performed based on data collected during a learning procedure. The learning procedure may comprise the steps of: modifying, in a predetermined way, an operational state of at least one of the control devices at a time when the anomaly is assumed not to be occurring; • monitoring one or more operational parameters for changes during and/or after the modifying; and recording the modification and information regarding the corresponding change in the one or more operational parameters. The learning procedure may comprise carrying out the steps more than once, e.g., a plurality of times. The predetermined anomaly may be unauthorized access of the industrial control system by a third party. The third party may operate control devices of the industrial process plant under abnormal conditions, and send information to the industrial control system simulating measurements of operational parameters operating under normal condition. The system may be a physical system. For example, it may be a power plant, such as a solar thermal power plant. The control devices may be configured to regulate at least one or more conditions selected from the group including temperature of a thermal fluid of the plant, pressure of the thermal fluid, angle of reflectors of the plant, temperature of working fluid of a turbine of the plant, and pressure of working fluid of a turbine of the plant.). With regards to claim 8, KROYZER discloses, An anomaly behavior analysis and detection method in an industrial control system, comprising the following steps: (S01) collecting, by a data collection module, operation data from sensors and programmable logic controllers (PLCs) of the industrial control system (FIG 1 step 2 and associated text; page 8 line 27- 35; In the first step 2 shown in FIG. 1, data of correct operational parameters is collected from at least one input device. For example, data may be provided from industrial control system 104 to the anomaly detection system 100 via an input/output (I/O) interface 112. The input device may include at least one of, for example, a sensor 108, from the SCADA 106 directly, from a distributed control system (DCS) 110, from remote FO, a network, a virtual network, data logs and known libraries from databases. In some embodiments, the data collected may include for example at least one of: data from sensors operating within the control system 104, tags (i.e., from SCADA 106, PLC 136, or DCS 1 10), SCADA processing data, IT data, operator data, log files (i.e., from operating systems, IT, and/or SCADA 106), network data or communication data.); (S02) preliminarily processing, by a data processing module, the collected operation data, including data standardization and format conversion (FIG 1 step 4, 6 and associated text; page 9 line 4-15; As the amount of data that may collected may be enormous, e.g., at least terabytes in size, some embodiments may include a second step 4 which may include big data collecting and/or big data handling. The big data handling may be done online, offline or via sub-sampling, for example, by transmitting the data to a remote data processing system 1 18. In the third step 6, the data of the correct operational parameters may be analyzed and stored as training data. The step of analyzing may be broken down into two discreet steps. The data may first be processed and then analyzed. The step of processing may include: data correlation (e.g., correlating at least two operational parameters), rate of change differences, creating histograms, spectral analysis, recording delay patterns and interpreting the smoothness of the data. The analysis of the data include: developing a learning algorithm, developing temporal causalities, model analysis, Markovian connectivity analysis, Markov random field analysis and differential Markov random field analysis; Page 9 line 27-35; In the fifth step 10, current operational parameters may be detected in the industrial control system. For example, the analysis module 116 can receive data from the industrial control system 104 via I/O 1 12 and analyze the data as it is received in order to determine if an anomaly is present in the system. In particular, the anomaly detection system 100 may check the current operational parameter(s) (which may be the same parameters used to form the training data or different from the training data parameters but related in some way to the training data parameters), or the correlation of at least two current operational parameters, for any potential deviation from the training data that would indicate an abnormal or incorrect operation of the industrial control system 104. Such a deviation may be detected, if a portion of the industrial control system has been taken over by an attacker or otherwise manipulated. Note: data collected from sensors/PLC suggest that data are collected from specific fields and format ); (S05) actively querying and analyzing, [[according to a predefined state machine model,]] the processed data through a detection unit in an anomaly detection module (FIG 1 step 10 and associated text; page 6 line 5-11; In one or more embodiments, a method of detecting an anomaly in an industrial process plant can include predicting a value of an operational parameter of the industrial process plant after a control device therein has been subject to a known operating state modification. The method can further include instructing the control device to have the known operating state modification and comparing a value of the operational parameter resulting from the instructing with the predicted value. The method also includes controlling the industrial control system responsively to a result of the comparing.); (S06) the detection unit automatically adjusting detection parameters according to historical data by using an adaptive learning unit to improve the identification accuracy of anomaly behaviors (FIG 5 steps 160-180 and associated text; In the monitoring step 170, the prediction engine monitors one or more operational parameters, as returned by the sensors 16, which are affected by the modification performed in step 160. This monitoring 170 can take place during and/or after the modifying 160. In the recording step 180, the prediction engine records both the modification and information regarding the corresponding change in the operational parameters. The information includes the measured change in the operational parameter, and may also include information relating to the timing and duration of the change. The recorded information may be stored in a database, which is accessed by the prediction engine when compiling its prediction. The prediction engine may carry out the learning procedure 150 for different control elements 14. In addition, it may carry out the learning procedure multiple times, thereby arriving at a range of predicted values.; Page 9 line 8-15; In the third step 6, the data of the correct operational parameters may be analyzed and stored as training data. The step of analyzing may be broken down into two discreet steps. The data may first be processed and then analyzed. The step of processing may include: data correlation (e.g., correlating at least two operational parameters), rate of change differences, creating histograms, spectral analysis, recording delay patterns and interpreting the smoothness of the data. The analysis of the data include: developing a learning algorithm, developing temporal causalities, model analysis, Markovian connectivity analysis, Markov random field analysis and differential Markov random field analysis.; FIG 4-6 and associated text;); (S07) executing predefined response measures by a response execution module when anomaly behaviors are recognized by the detection unit, including giving an alarm and automatically adjusting the operation parameters of the system (FIG 6 260 and associated text; page 14 line 0-7; In the responding step 260, the industrial control system 410 takes action in response to the result of the determining step 250. If the result indicates that an anomaly has occurred, the industrial control system 410 takes appropriate corrective action. Such an action may include alerting an operator, for example by displaying an alert and/or producing an audible alert, directing one or more of the control elements 14 to operate in such a way so as to mitigate the effects of the anomaly, or shutting down part or all of the industrial process plant ); and (S08) recording all identified anomaly behaviors and system response measures in a security incident log for post-incident analysis and audit (page 10 line 13-19; In the sixth step 12, a communication function may be performed when the detected deviation is above or below a predefined threshold. For example, the communication function may include at least one of: creating an alarm (e.g., a visual or auditory alarm via alarm module 122), communicating data to at least one of a control system (e.g., to the SCADA 106 or the DCS 110) and an operator (e.g., to a system user via user interface 120 or to a user of the industrial control system via UMI 132), and recording the data (e.g., in data storage module 124) or the alarm.) Note: data/incident recorded but claim does not perform post-incident analysis and audit, its an intended use). KROYZER does not exclusively but ZHANG teaches, (S03) carrying out information exchange between devices by a Modbus/TCP communication protocol to enhance the safety and accuracy of data collection (ZHANG The Schneider upper computer communicates with the PLC based on the Modbus protocol without authentication. Generally, the upper computer sends a request based on a certain function code, the PLC responds to the corresponding function code. The request function code is usually: reading the coil, reading the register, reading the discrete input and so on. PLC for the request of the upper computer, giving the response of the corresponding point value. The method of the present embodiment can give an alarm of the following abnormal situations:); (S04) constructing a programmable logic controller (PLC) state set for continuously monitoring the operation state of the PLC (ZHANG page 6 para 1; FIG. 4 is a schematic diagram of a typical application scenario of the method according to the embodiment of the present embodiment. The method of the present embodiment is realized on the monitoring device; the continuous communication traffic of the upper computer and the lower computer in the industrial control network is introduced to the monitoring device through the mirror image port. when there is a malicious attacker or point is abnormal caused by other reasons, the embodiment method will perform abnormal alarm in time. respectively the protection of the Schneider series PLC (programmable logic controller) and Siemens S7-300 PLC as an example, respectively indicates how the method of the embodiment has an abnormal detection effect); (S05) actively querying and analyzing, according to a predefined state machine model, the processed data through a detection unit in an anomaly detection module (page 8 para 9;It can be understood that the expression mode of the sequence model can be used but not limited to finite state machine (FSM), method for detecting the abnormal sequence can be used but not limited to probability analysis, model detection technology (Model Checker) and so on. In the field of industrial control abnormality detection, the expression mode of any sequence mode and the method based on sequence abnormality detection are in the protection range of the method of the embodiment.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention was made to modify KROYZER’s system with teaching of ZHANG in order to provides an industrial control network anomaly detection(ZHANG Abstract) With regards to claim 9, KROYZER in view of ZHANG discloses, wherein the steps (S04) and (S07) respectively comprise the following detailed steps: (S041) further continuously monitors output values of various sensors in the industrial control system by a sensor data interface unit, so as to update the programmable logic controller (PLC) state set in real time and ensure the real-time identification of the abnormal state of the system (ZHANG page 4 para 2; he industrial control network abnormality detection method and device provided by the embodiment of the invention, based on the unsupervisors type baseline learning method, automatically generating safety time period of the base line, and the abnormal data frame or data frame sequence to alarm, generating the baseline safety the new time period; analyzing the change trend of history safety line sequence in the preset time period, predicting and alarming the potential safety threat according to the trend analysis result, so as to realize the abnormal detection of the industrial control network; it does not need to perform manual adjustment confirmation after generating network safety monitoring-type learning in advance; and according to the continuously obtained network flow, automatically generating network safety line, by analyzing the historical baseline sequence trend, it can find the baseline sequence gradually deviates from the potential threat of the normal value, the method of the embodiment reduces the operation complexity of generating industrial control safety line, improves the stability of the safety line. ); and (S071) implementing differentiated response strategies according to the types of anomalies, such as immediately disconnecting the power supply of related devices for high-security anomalies, and adjusting operation parameters for performance-affecting anomalies to optimize the performance of the system (KROYZER FIG 6 260 and associated text; page 14 line 0-7; In the responding step 260, the industrial control system 410 takes action in response to the result of the determining step 250. If the result indicates that an anomaly has occurred, the industrial control system 410 takes appropriate corrective action. Such an action may include alerting an operator, for example by displaying an alert and/or producing an audible alert, directing one or more of the control elements 14 to operate in such a way so as to mitigate the effects of the anomaly, or shutting down part or all of the industrial process plant). With regards to claim 10, KROYZER further discloses, wherein the step (S05) comprises the following detailed steps: (S051) further analyzing the processed data by an anomaly detection module using enhanced data analysis techniques, including machine learning algorithm and pattern recognition, thus improving the recognition ability and accuracy of detection for complex anomaly behaviors (Page 9 line 8-15; In the third step 6, the data of the correct operational parameters may be analyzed and stored as training data. The step of analyzing may be broken down into two discreet steps. The data may first be processed and then analyzed. The step of processing may include: data correlation (e.g., correlating at least two operational parameters), rate of change differences, creating histograms, spectral analysis, recording delay patterns and interpreting the smoothness of the data. The analysis of the data include: developing a learning algorithm, developing temporal causalities, model analysis, Markovian connectivity analysis, Markov random field analysis and differential Markov random field analysis.; FIG 4-6 and associated text;) Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US10607006 b2, US20250094670 Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOHAMMED WALIULLAH whose telephone number is (571)270-7987. The examiner can normally be reached 8.30 to 430 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 1-571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MOHAMMED WALIULLAH/Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Jun 03, 2024
Application Filed
Aug 10, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750377
DEPLOYING HANDWRITING RECOGNITION SERVERS FOR DIFFERENT SECURITY LEVELS
3y 10m to grant Granted Sep 29, 2026
Patent 12737495
Machine Learning Training with Enforced Differential Privacy Using Secure Multi-Party Computation
2y 2m to grant Granted Sep 15, 2026
Patent 12732374
HARDWARE VIRTUALIZED TPM INTO VIRTUAL MACHINES
2y 0m to grant Granted Sep 08, 2026
Patent 12722600
TERMINAL DEVICE AND METHOD PROCESSING OF DATA FOR TERMINAL DEVICE
3y 2m to grant Granted Sep 01, 2026
Patent 12726370
PSEUDO-HOMOMORPHIC AUTHENTICATION OF USERS WITH BIOMETRY
2y 8m to grant Granted Sep 01, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
87%
Grant Probability
98%
With Interview (+11.0%)
2y 4m (~0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 739 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month