Prosecution Insights
Last updated: October 01, 2026
Application No. 18/879,319

METHOD AND SYSTEM FOR CONTROLLING ACCESS TO DATA IN AN INDUSTRIAL PLANT OR IN A DATABASE ASSOCIATED TO THE INDUSTRIAL PLANT

Non-Final OA §101§103§112
Filed
Dec 27, 2024
Priority
Jun 29, 2022 — EU 22181962.6 +4 more
Examiner
LEMMA, SAMSON B
Art Unit
2498
Tech Center
2400 — Computer Networks
Assignee
BASF SE
OA Round
1 (Non-Final)
88%
Grant Probability
Favorable
1-2
OA Rounds
12m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
809 granted / 917 resolved
+30.2% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
24 currently pending
Career history
936
Total Applications
across all art units

Statute-Specific Performance

§101
20.5%
-19.5% vs TC avg
§103
40.8%
+0.8% vs TC avg
§102
19.4%
-20.6% vs TC avg
§112
12.1%
-27.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 917 resolved cases

Office Action

§101 §103 §112
CTNF 18/879,319 CTNF 80349 DETAILED ACTION This is in response to the application No. 18/879,319 filed on December 27, 2024. The preliminary claim amendment filed on December 27, 2024 is acknowledged, accordingly the amended claims 1-8 which are submitted for examination are considered and claims 1 and 7 are independent. Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Preliminary claim amendment The preliminary claim amendment filed on December 27, 2024 is acknowledged, accordingly the amended claims 1-8 which are submitted for examination are considered and claims 1 and 7 are independent. Priority 4. This application filed on 12/27/2024 is a National Stage entry of PCT/EP2023/067642, International Filing Date: 06/28/2023, claims foreign priority to 22181962.6, filed on 06/29/2022. Information Disclosure Statement 5. The information disclosure statements (IDS) submitted on 12/27/2024 and 01/22/2025 have been considered. The submission is in-compliance with the provisions of 37 CFR 1.97. Form PTO-1449 is signed and attached hereto. Drawings 6. The drawings filed on December 27, 2024 are accepted. Specification 7. The specification filed on December 27, 2024 is objected to because of the following informalities: On Para. 0056, applicant’s submitted published specification, recites the following referring to figure 4: “FIG. 4 shows a further schematic representation of a graph structure of the plant of FIG. 3 . Here, a first scope 510 is associated to the plant 15”. “first scope 510” should be corrected as “first scope S10” so that it matches with what is designated on figure 4 or throughout the speciation. Appropriate correction is required. 07-30-03-h AIA Claim Interpretation 07-30-03 AIA 8. The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. 07-30-05 9. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. 07-30-06 10. This application includes one or more claim limitations that uses the word “means,” and are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are the following recited in claim 7: a. system for controlling access to data … b . at least one signal provider configured to provide a signal …and c. an authorization provider …being configured to provide authorization Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Examiner Note: After identifying a § 112(f) means-type claim limitation, the office examined the specification to determine what applicant has identified as the structure or material that performs the function recited in the § 112(f) claim limitation; Regarding the limitation a. system for controlling access to data , Applicant’s published specification para. 0078, identified sensors that performs the function of system for controlling access to data [Para. 0078, “A chemical plant may include more than 1.000 sensors producing measurement data points every couple of seconds. Such dimensions result in multiple terabytes of data to be handled in a system for controlling and/or monitoring chemical plants ”] However, the specification doesn’t explicitly identify as the structure or material that performs the function recited in the § 112(f) claim limitation such as b. at least one signal provider configured to provide a signal c. an authorization provider …being configured to provide authorization Claim Rejections - 35 USC § 112 07-30-02 AIA The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. 07-34-01 Claim 7 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. The following Claim limitations recited in claim 7 b. “ at least one signal provider configured to provide a signal” and c. “an authorization provider …being configured to provide authorization ” invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. Furthermore, the claim recitations are not supported in the specification by an algorithm for performing the claimed computer function. A. For claim limitation, “ at least one signal provider configured to provide a signal”, Para. 0020 of applicant’s submitted specification barely mention signal providers (e.g. sensor data, lab measurements) without linking the structure, material, or acts to the function. For claim limitation, “an authorization provider …being configured to provide authorization ” para. 0054 of applicant’s submitted specification barely mentions authorizing providers 31 - 33 as something which can be implemented or integrated into the graph structure or an authorization provider that can be associated to different graph elements within the graph structure without linking the structure, material, or acts to the function. Moreover, both of the above computer implemented 112(f) recitation are not supported in the specification by an algorithm for performing the claimed computer function Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. 07-34-23 Applicant may: (a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. Claim Rejections - 35 USC § 101 07-04-01 AIA 07-04 13. 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. 14. Claim 8 is rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Regarding claim 8, the claim is directed to a computer program comprising code that is not stored in a non-transitory computer readable medium. In particular the claim recites “A computer program controlling access to data in an industrial plant or in a data base associated to the industrial plant, the program comprising code means for causing a system to execute a method according to claim 1, when the program is run on a computer controlling the system”. Examiner note that pending claims are interpreted as broadly as their terms reasonably allow. The broadest reasonable interpretation of this claim is, the claim is only directed to a computer program comprising a code”. The claim is directed to a program/software and is a program per se that is not within any of the four statutory categories of invention (process, machine, manufacture or composition of matter). Accordingly, the claim is directed to a non-statutory subject matter. Claim Rejections - 35 USC § 103 07-20-aia AIA 15. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-23-aia AIA The factual inquiries set forth in Graham v. John Deere Co. , 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or non-obviousness. 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-21-aia AIA Claim s 1-8 are rejected under 35 U.S.C. 103 as being unpatentable over European Patent Publication No EP3515035 B1, Dirk Schulz ( Schulz ) (Publication Date: 07/24/2019) in view of Heinz A. Preisig ( Presisig ) (NPL document titled, “A graph-theory-based approach to the analysis of large-scale plants”, 2009) (Both of these prior arts are provided with the IDS) [Both prior arts are provided with the IDS] The following is referring to independent claims 1 and 7 and dependent claim 8: As per independent claim 1 , Schulz discloses a method for controlling access to data in at least one an industrial plant or in a data base associated to the at least one industrial plant [Para 0001, “The present invention generally relates to digital access control, and in particular relates to methods, computer program products and systems for controlling access to data provided by devices of an automation system”; Para. 0006, “provide improved means for authorizing access to digital data of a device which forms part of an industrial automation system ” ] and , wherein elements of the industrial plant [Para. 0021, and figure 1, ref. 210, where elements of industrial plant is represented by digital data 210, “Figure 1, ref. 210, FIG. 1 illustrates a scenario with a requester 10, 20 requesting 1100 access to digital data 210 of a device 200 which forms part of an industrial automation system” and para. 0023, “devices forming part of an industrial information system are equipped with all kinds of sensors which provide digital data about the technical status of the respective devices … digital data 210 of a particular device 200. Such digital data may include all kinds of technical status data measured by respective sensors but also other technical information, such as for example, the device type, serial number, connection data, etc ] are mapped to graph elements of a graph structure [Para. 0027 and figure 1 and figure 3, elements of the industrial plant, digital data 210 is mapped to the annotation A1-An which is a graph elements of an access data structure/graph 300. “the digital data 210 has the annotations A1 to A5. The annotations may be directly stored on the device 200 together with the digital data 210 or they may be stored on a separate entity which maps the annotations to the device data 210 accordingly ” Figure 1, Para. 0026, “the digital data 210 is mapped or represented by the annotation A1 to An. Annotation A1 to An is a graph elements of a graph access data structure 300. Para. 0026, “The access data structure can be interpreted as a security policy which defines which data ( represented by the annotations A1 to An ) require which permissions (as defined in the requester properties RP1 to RP5) to be accessed by the requester 10, 20”. Furthermore, as shown on figure 3, digital data 210/elements of the industrial plant is also mapped to a1, a2 and a5. And a1-a5 are graph elements of the tree data structure graph shown on figure 3, “The digital data is pre-annotated with the semantic identifiers (annotations) a1, a2, a5 . The access data structure in this example defines the following associations: a1:ID1, a2:R1, a5:R2. That is, the authorization check component authorizes for the requester 11 access to the data objects mapped to a1 and a2 because the request is sent with the permissions defined for ID1 and R1 which are part of the respective associations ”] wherein the graph structure is based on a graph database plant model formed by a graph database comprising as graph elements nodes, edges and properties to represent and store data items associated with the elements of the industrial plant [See figure 3, para. 0010, “The access data structure may be stored as a data structure in a memory of the computer system . the access data structure stores associations between requester properties and the annotations of the digital data. In other words, the access data structure defines which of the requester properties should have permissions to access respective data objects of the device by storing associations between the requester properties (e.g., ID, roles) and the annotations of the respective data objects. Para. 9, “Each annotation is an identifier for meta-data of the digital data characterizing the semantic meaning of the digital data in accordance with a semantic technical dictionary” and para. 12, “a predefined annotation relationship data structure defines relationships between annotations. A particular requester property is associated with a particular annotation by an assignment of the particular requester property to an annotation node of the annotation hierarchy which is a supra-node of the particular annotation . The annotation relationship data structure may define a hierarchy between annotations in that a first annotation can be a supra-node of a second annotation which is a subordinate node of the supra-node… Other hierarchical structures (e.g., tree structures) may also be used to implement the annotation relationship data structure. See also figure 3, i.e hierarchical access data structure that comprises supra-nodes and subordinate nodes and that is a tree graph structure ] , the method comprising: defining scopes associated to graph elements of the graph structure, [Para. 0010-0011., “the access data structure stores associations between requester properties /scopes and the annotations of the digital data. In other words, the access data structure defines which of the requester properties/scopes should have permissions to access respective data objects of the device by storing associations between the requester properties (e.g., ID, roles) and the annotations of the respective data objects” and para. 0012, “A particular requester property is associated with a particular annotation by an assignment of the particular requester property to an annotation node of the annotation hierarchy which is a supra-node of the particular annotation” and para. 0039, “ ARDS 320 is a simple hierarchical tree structure with a0 being the root node of the hierarchy. In the example, the root node a0 has an association with the requestor property R6 which is the third requestor property of the requestor 11.” The requester properties correspond to the claim limitation “Scopes” The data structure or hierarchical tree structure corresponds to the limitation “graph structure”] wherein at least one authorization provider is associated to one of the scopes [para. 0021, “the access request is processed by an authorization check component 400 by using a particular access data structure 300” and para. 0025, “ The authorization check component 400 is part of the authorization system 100 ” and para. 0029, “ the authorization check component checks all of the requester properties of the requester 10, 20” The authorization check component 400 meets the limitation of “authorization provider which is associated with the requester properties that corresponds to the limitation scope ”]], receiving a request for data from a requesting entity for data from at least one a target entity via an application programming interface (API) [Para, 0007, “To get access to the digital data of the device, initially a corresponding access request is generated by a requester ” Para, 0008, “The request of the requester having one or more requester properties is then received via an appropriate interface by a computer system which handles the access control to the digital data.” Para. 0025, “The request 30 is then received 1100 by the authorization check component 400 via interface 110.” And see figure 1A, ref. 110, the interface is the respective API for Receiving request to access data and the interface corresponds to the claim limitation API ], determining to which scope the requested data is related to [ Para. 0010, “The authorization check component accesses an access data structure in response to the request.” Para, 0029, “The authorization check component 400 then compares 1300 at least one requester property of the requester with the requester properties associated with the annotations of the digital data 210 for which access is requested ”], providing authorization to the request from the requesting entity for the data from the target entity by the at least one authorization provider associated to the scope to which the request is related to [Para. 0037, “ the security policy as defined by ADS 300 provides access authorizations to the respective data objects mapped to the annotations A1 to An in each case where at least one of the requester properties RP1 to RP5 is matches with a requester property of the received data access request” and para. 0039, “the authorization check component would authorize the requester to access a data object mapped to a0 ”] , and granting the requesting entity access to the requested data based on the authorized request [Para. 0008, “ authorization check component which checks whether the received requester properties entitle the requester to get access to the requested digital data or whether the request is to be rejected because the received requester properties do not include all required permissions for the requested data ” and para. 0029, “the authorization check component 300 authorizes 1400 the requester 10, 20 to access the digital data represented by the at least one respective annotation A1 which is associated with the at least one requester property RP1 in accordance with the permissions as defined by the at least one requester property RP1” That is, the access to digital data is granted if all the requester properties entitle the requester to access the data ] Schulz doesn’t explicitly disclose the following underlined claim limitation : “ wherein the graph structure is based on a graph database plant model formed by a graph database comprising as graph elements nodes, edges …and store data items associated with the elements of the industrial plant ” However, Presisig discloses the above underlined claim limitation: “ wherein the graph structure is based on a graph database plant model formed by a graph database comprising as graph elements nodes, edges …and store data items associated with the elements of the industrial plant ” [ Note: This prior art also is also recited in the applicant’s own submitted published specification, Para. 0037-0038, “the application of the graph structures based on graph databases on the analysis of large-scale plants is described. The industrial plant is analyzed and mapped to a graph structure. A graph relates to a graph database comprising a set of vertices (nodes) and edges (links, lines), in which an edge connects two or more nodes. Thus, a graph structure is used to map or represent a system architecture for example of an industrial plant like a chemical plant” See page 598, Right column 1.2, “Network modelling basics”] Schulz and Presisig are analogous arts and are in the same field of endeavor as they both pertain and directed to an industrial plant or in a data base associated to the at least one industrial plant It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the system and a graphical data structure of Schulz by adding a mechanism such as “wherein the graph structure is based on a graph database plant model formed by a graph database comprising as graph elements nodes, edges …and store data items associated with the elements of the industrial plant ” as taught by Presisig because this would enhance and simplify the security and access control of data in an industrial plant by using a graph structure and a graph-theory based approach to analyze large scale plants. [ See Preisig, 1.2, “Network Modelling basics” and figure 1, 2] As per independent claim 7 , Schulz discloses a system for controlling access to data in at least one industrial plant or in a database associated to the at least one industrial plant, [Para 0001, “The present invention generally relates to digital access control, and in particular relates to methods, computer program products and systems for controlling access to data provided by devices of an automation system”; Para. 0006, “provide improved means for authorizing access to digital data of a device which forms part of an industrial automation system ” ] wherein elements of the industrial plant Para. 0021, and figure 1, ref. 210, where elements of industrial plant is represented by digital data 210, “Figure 1, ref. 210, FIG. 1 illustrates a scenario with a requester 10, 20 requesting 1100 access to digital data 210 of a device 200 which forms part of an industrial automation system” and para. 0023, “devices forming part of an industrial information system are equipped with all kinds of sensors which provide digital data about the technical status of the respective devices … digital data 210 of a particular device 200. Such digital data may include all kinds of technical status data measured by respective sensors but also other technical information, such as for example, the device type, serial number, connection data, etc ] are mapped to graph elements of a graph structure Para. 0027 and figure 1 and figure 3, elements of the industrial plant, digital data 210 is mapped to the annotation A1-An which is a graph elements of an access data structure/graph 300. “the digital data 210 has the annotations A1 to A5. The annotations may be directly stored on the device 200 together with the digital data 210 or they may be stored on a separate entity which maps the annotations to the device data 210 accordingly ” Figure 1, Para. 0026, “the digital data 210 is mapped or represented by the annotation A1 to An. Annotation A1 to An is a graph elements of a graph access data structure 300. Para. 0026, “The access data structure can be interpreted as a security policy which defines which data ( represented by the annotations A1 to An ) require which permissions (as defined in the requester properties RP1 to RP5) to be accessed by the requester 10, 20”. Furthermore, as shown on figure 3, digital data 210/elements of the industrial plant is also mapped to a1, a2 and a5. And a1-a5 are graph elements of the tree data structure graph shown on figure 3, “The digital data is pre-annotated with the semantic identifiers (annotations) a1, a2, a5 . The access data structure in this example defines the following associations: a1:ID1, a2:R1, a5:R2. That is, the authorization check component authorizes for the requester 11 access to the data objects mapped to a1 and a2 because the request is sent with the permissions defined for ID1 and R1 which are part of the respective associations ”] representing the industrial plant, wherein the graph structure is based on a graph database plant model formed by a graph database comprising as graph elements nodes , edges and properties to represent and store data items associated with the elements of the industrial plant [See figure 3, para. 0010, “The access data structure may be stored as a data structure in a memory of the computer system. the access data structure stores associations between requester properties and the annotations of the digital data. In other words, the access data structure defines which of the requester properties should have permissions to access respective data objects of the device by storing associations between the requester properties (e.g., ID, roles) and the annotations of the respective data objects. Para. 9, “Each annotation is an identifier for meta-data of the digital data characterizing the semantic meaning of the digital data in accordance with a semantic technical dictionary” and para. 12, “a predefined annotation relationship data structure defines relationships between annotations. A particular requester property is associated with a particular annotation by an assignment of the particular requester property to an annotation node of the annotation hierarchy which is a supra-node of the particular annotation. The annotation relationship data structure may define a hierarchy between annotations in that a first annotation can be a supra-node of a second annotation which is a subordinate node of the supra-node… Other hierarchical structures (e.g., tree structures) may also be used to implement the annotation relationship data structure. See also figure 3, i.e hierarchical access data structure that comprises supra-nodes and subordinate nodews and that is a tree graph structure] , wherein each scope being associated to one of the graph elements in the graph structure [Para. 0010-0011., “the access data structure stores associations between requester properties/scope and the annotations of the digital data. In other words, the access data structure defines which of the requester properties should have permissions to access respective data objects of the device by storing associations between the requester properties (e.g., ID, roles) and the annotations of the respective data objects” and para. 0012, “A particular requester property is associated with a particular annotation by an assignment of the particular requester propert/scope to an annotation node of the annotation hierarchy which is a supra-node of the particular annotation” and para. 0039, “ ARDS 320 is a simple hierarchical tree structure with a0 being the root node of the hierarchy. In the example, the root node a0 has an association with the requestor property R6 which is the third requestor property of the requestor 11.” The requester properties correspond to the claim limitation “Scopes” The data structure or hierarchical tree structure corresponds to the limitation graph structure] , wherein each scope comprises at least one signal provider configured to provide a signal [ Para. 0026. “ the digital d ata represented by the annotation A1 can be accessed if the requester has at least one of the requester properties RP1 or RP3 (both are associated with annotation A1 through direct assignments represented by the dashed arrows between the annotation A1 and the respective requester properties/each scope)], the system comprising: an application programming interface (API) configured to receive a request from a requesting entity for data from at least one target entity in the at least one industrial plant, [Para, 0007, “To get access to the digital data of the device, initially a corresponding access request is generated by a requester ” Para, 0008, “The request of the requester having one or more requester properties is then received via an appropriate interface by a computer system which handles the access control to the digital data.” Para. 0025, “The request 30 is then received 1100 by the authorization check component 400 via interface 110.” And see figure 1A, ref. 110, the interface is the respective API for Receiving request to access data and the interface corresponds to the claim limitation API ], and at least one authorization provider associated to one of the scopes [para. 0021, “the access request is processed by an authorization check component 400 by using a particular access data structure 300” and para. 0025, “The authorization check component 400 is part of the authorization system 100” and para. 0029, “the authorization check component checks all of the requester properties of the requester 10, 20” The authorization check component 400 meets the limitation of “authorization provider which is associated with the requester properties that corresponds to the limitation scope”] and being configured to provide an authorization of data from the scope to which the target entity is associated to [Para. 0037, “ the security policy as defined by ADS 300 provides access authorizations to the respective data objects mapped to the annotations A1 to An in each case where at least one of the requester properties RP1 to RP5 is matches with a requester property of the received data access request” and para. 0039, “the authorization check component would authorize the requester to access a data object mapped to a0 ”] Schulz doesn’t explicitly disclose the following underlined claim limitation : “ wherein the graph structure is based on a graph database plant model formed by a graph database comprising as graph elements nodes, edges …and store data items associated with the elements of the industrial plant ” However, Presisig discloses the above underlined claim limitation: “ wherein the graph structure is based on a graph database plant model formed by a graph database comprising as graph elements nodes, edges …and store data items associated with the elements of the industrial plant ” [ Note: This prior art also is also recited in the applicant’s own submitted published specification, Para. 0037-0038, “the application of the graph structures based on graph databases on the analysis of large-scale plants is described. The industrial plant is analyzed and mapped to a graph structure. A graph relates to a graph database comprising a set of vertices (nodes) and edges (links, lines), in which an edge connects two or more nodes. Thus, a graph structure is used to map or represent a system architecture for example of an industrial plant like a chemical plant” See page 598, Right column 1.2, “Network modelling basics” Schulz and Presisig are analogous arts and are in the same field of endeavor as they both pertain and directed to an industrial plant or in a data base associated to the at least one industrial plant It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the system and a graphical data structure of Schulz by adding a mechanism such as “wherein the graph structure is based on a graph database plant model formed by a graph database comprising as graph elements nodes, edges …and store data items associated with the elements of the industrial plant ” as taught by Presisig because this would enhance and simplify the security and access control of data in an industrial plant by using a graph structure and a graph-theory based approach to analyze large scale plants. [ See Preisig, 1.2, “Network Modelling basics” and figure 1, 2] As per dependent claim 8 dependent claim 8 is rejected for the same reason/rationale as that of the above independent claim 1. The following is referring to dependent claims 2-6: As per dependent claim 2 the combination of Schulz and Presisig discloses a method as applied to claim 1 above. Furthermore, Schulz discloses the method, wherein at least one role defining access rights to the data in the industrial plant or the data base is associated to the entity [Para. 0007, “requester properties which can be relevant in the context of authorizing access are so-called roles of the requester. Role Based Access Control (RBAC) concepts are well known in the field of access control. RBAC is a policy neutral access control mechanism defined around roles and privileges. Thereby, one or more roles are assigned to the requester. The assignment of roles occurs during the design phase of the security policy. Each role defines permissions to perform certain operations. It is to be noted that permissions can also be defined directly at the level of the identifier of the requester. Roles are commonly used to facilitate the administration of access rights but they are not necessarily to be used” para. 0010, “he access data structure defines which of the requester properties should have permissions to access respective data objects of the device by storing associations between the requester properties (e.g., ID, roles) and the annotations of the respective data objects.” Para. 0011, “a particular role (e.g., energy monitoring) is directly assigned to an annotation (identifier) of particular device data (e.g., an input current of a speed drive). The direct assignment indicates that the permissions of the particular role allow access to the digital data whose annotation is assigned to the particular role” and para. 0024.” I n RBAC systems, permissions are bundled in so-called roles RP1 to RPn. Such roles include predefined sets of permissions which are appropriate for certain activities. For example, a role "energy monitoring" can bundle all access permissions needed to perform the activities which are needed for monitoring the energy behavior (energy consumption) in the industrial automation system. By using roles, only one respective role profile needs to be defined which can then be assigned to all users or system applications performing energy monitoring activities. In the example of FIG. 1, the role RP1 is assigned 51 to the requestor 10, 20. That is, the request 30 is made with the permissions bundled in the requestor property RP1.]], wherein the authorization for the requested data is performed based on the role associated to the entity [ Para. 0031, “rsequester properties with permissions (e.g., user roles), data models, and access rights in a flexible and secure manner by design. When being presented with an access request, the authorization check component checks the semantics of the data object(s) in question and only needs to confirm authorization of the requester (role) against this semantics. and para. 0032, “ access is granted based on roles/group membership, users have one or more roles/group memberships ”] As per dependent claim 3 the combination of Schulz and Presisig discloses a method as applied to claim 1 above. Furthermore, Schulz discloses the method,, wherein the requesting entity is a user ,[Figure 1, ref. 10, “user” ] a service, a micro-service and/or a data processing pipeline [ Figure 1, ref. system 20”] [see also para. 0023, human users 10 (e.g., operators, service engineers, etc.) or other systems 20 may request access to the digital data 210 of a particular device 200”]. As per dependent claim 4 the combination of Schulz and Presisig discloses a method as applied to claim 1 above. Furthermore, Schulz discloses the method wherein the target entity is a user, an internal or external service, an internal or external micro-service and/or a data processing pipeline [See figure 3, ref. 210 and paragraph 0023, “users 10 (e.g., operators, service engineers, etc.) or other systems 20 may request access to the digital data 210 of a particular device 200. Such digital data may include all kinds of technical status data measured by respective sensors but also other technical information, such as for example, the device type, serial number, connection data, etc. A human user 10 may request data access, for example, for updating configuration data, system engineering purposes, technical status monitoring, etc. Such purposes illustrate various potential uses of the digital data for different purposes and reflect different semantic contexts for such data . A system 20 may request data access, for example, to send control instructions to be received by the device, to retrieve technical status data for status prediction, etc. A person skilled in the field of industrial automation is able to transfer the herein disclosed approach of semantics-based information security to any device data use scenario known in the field of industrial automation and figure 4 and para. 0040, “In the example of FIG. 4A, the device 200a is a variable speed drive with two digital data objects 210a, 210b. The first data object 210a (L1) provides the value of the electric current L1 on the device input side, as measured. The second data object 210b provides the value of the voltage UL1 from L1 to Neutral, as measured The current L1 is annotated with two annotation tags A1, A2.] As per dependent claim 5 the combination of Schulz and Presisig discloses a method as applied to claim 1 above. Furthermore, Schulz discloses the method, wherein the data comprises data relating to a production asset in the industrial plant, processing data, telemetry data, meta data, laboratory data, production data [ Para,.0006, “authorizing access to digital data of a device which forms part of an industrial automation system . As used herein, a device forms part of an industrial automation system if the device is configurable and/or controllable by the automation system, and/or can be integrated for respective analytics applications .. Note: Devices of industrial systems includes production plants as defined at para. 0002, “Devices of industrial systems (e.g., production plants, smart buildings, ventilation systems, etc.) are typically monitored and process controlled by automation systems. For example, process plant devices typically provide tens of thousands of signals which are relevant for monitoring the technical state and/or process control of the plant. Some devices provide data in a digital format which are of interest to operators (users) of the automation system or they may be relevant to particular computer system functions for further processing. The devices are typically connected via appropriate network technology (e.g., the Internet of Things (loT))” para. 0016-0017, “a computer program product is provided for authorizing access to digital data of a device which forms part of an industrial automation system” See also para. 0032-0033] . As per dependent claim 6 Schulz discloses a method as applied to claim 1 above. Furthermore, Schulz discloses industrial automation system [ Para. 0032-0033 wherein industrial systems includes (e.g., production plants) as defined in para. 0002] Schulz doesn’t explicitly disclose: the limitation “wherein the industrial plant is a chemical plant”. However, Presisig discloses “ wherein industrial plant is a chemical plant” [ Conclusion, “graph theoretical approaches in the context of representing and solving models describing the operation of chemical plants”] Schulz and Presisig are analogous arts and are in the same field of endeavor as they both pertain and directed to an industrial plant or in a data base associated to the at least one industrial plant It would have been obvious to one having ordinary skill in the art, before the effective filing of the claimed invention, to modify the access control method of data in an industrial plant structure of Schulz by adding a mechanism such as “wherein industrial plant is a chemical plant ” as taught by Presisig because this would enhance the application of the security and access control of data particularly in a chemical plant by using a graph structure and a graph-theory based approach to analyze large scale chemical plants. [ See Preisig, 1.2, “Network Modelling basics” and figure 1, 2] Conclusion 07-96 AIA 17. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. A. US Publication No. 2023/0208840 A1 Venable discloses methods for an authorization and access control system for access rights using relationship graphs. A service provider may provide an authorization and access control system that allows users within the service provider and/or customer entities to assign and change access rights or permissions to computing resources. When providing control of these access rights, the service provider may utilize relationship graphs, queried and generated using a graph database, to visualize and determine access rights that are inherited through different relationships and policies defining these access rights. The relationship graph may show edges for nodes that correspond to related objects, such as actors, groups, and resources. Paths over the relationship graph may be used to determine access rights that may be inherited by users. Once determined, these access rights may be established and/or updated with computing systems . B. US Publication No. 20190297085 A1 De Wijs discloses a computer system for authorizing a user to process data received from one or more devices includes: an interface component for receiving the data; an application component for receiving requests from the user, the requests including one or more requests to perform data processing operations on at least a subset of the data; a data storage and data access component for storing and access the data; one or more evaluation components for processing the data; and an authorization component for granting or denying to the user access to process at least a subset of the data, a grant or denial being based on user specific data . C. US Publication No. 20220300502 A1 to Enver et al discloses system for securely and efficiently obtaining data from a process plant and processing that data for consumption by one or more external applications or systems includes receiving event data from various data sources in or associated with a plant via various different data formats and data communication structures at a centralized server or gateway , wherein each microservice stores the new higher level data in the time series database as a timed event and/or in a distributed graph database as a node in one or more process graphs and/or creates new events and places those new events in the event stream at a particular time ordered place in the event stream . D. US Patent No. 7676281 A1 to Hood discloses system related to industrial control systems and, more particularly, to data storage and retrieval in an industrial automation environment. Turning now to FIG. 4, a distributed database system 400 that can be employed within an industrial automation environment is illustrated. The database system 400 includes a security component 402 that receives a data request from a requesting entity 404 . The security component 402 is employed to ensure the requesting entity 404 is authorized to access data associated requesting entity 404 is authorized to access data associated with the distributed database system 400 . For example, it may not be desirable to grant access to accounting data within the distributed database system 400 to a line worker. The security component 402 can then analyze the provided data and determine whether the requesting entity 404 is authorized to access data within the distributed database system 400 . For instance, the security component 402 can review a table that includes identities of entities and authorization levels associated therewith . E. US Patent No. 8176320 B1 Belanger et al discloses techniques for granting access to secured data. An access candidate may access some or all of the secured data by gaining access to two sequential levels of security. The first security level secures access to the resources used to manipulate the secured data and the second security level secures access to the secured data by the resources. Attributes associated with the access candidate are considered in deciding whether to grant or deny access to the resources . Based on a comparison of access requirements of the secured data with the applicable attributes of the access candidate, a decision on whether to grant access to the requested portions of the secured data . F. See the other cited prior arts. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMSON B LEMMA whose telephone number is 571-272-3806. The examiner can normally be reached on M-F 8am-10pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor Yin-Chen Shaw can be reached on 571-272-8593. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). /SAMSON B LEMMA/Primary Examiner, Art Unit 2498 Application/Control Number: 18/879,319 Page 2 Art Unit: 2498 Application/Control Number: 18/879,319 Page 3 Art Unit: 2498 Application/Control Number: 18/879,319 Page 4 Art Unit: 2498 Application/Control Number: 18/879,319 Page 5 Art Unit: 2498 Application/Control Number: 18/879,319 Page 6 Art Unit: 2498 Application/Control Number: 18/879,319 Page 8 Art Unit: 2498 Application/Control Number: 18/879,319 Page 9 Art Unit: 2498 Application/Control Number: 18/879,319 Page 10 Art Unit: 2498 Application/Control Number: 18/879,319 Page 11 Art Unit: 2498 Application/Control Number: 18/879,319 Page 12 Art Unit: 2498 Application/Control Number: 18/879,319 Page 13 Art Unit: 2498 Application/Control Number: 18/879,319 Page 14 Art Unit: 2498 Application/Control Number: 18/879,319 Page 15 Art Unit: 2498 Application/Control Number: 18/879,319 Page 16 Art Unit: 2498 Application/Control Number: 18/879,319 Page 17 Art Unit: 2498 Application/Control Number: 18/879,319 Page 18 Art Unit: 2498 Application/Control Number: 18/879,319 Page 19 Art Unit: 2498 Application/Control Number: 18/879,319 Page 20 Art Unit: 2498 Application/Control Number: 18/879,319 Page 21 Art Unit: 2498 Application/Control Number: 18/879,319 Page 22 Art Unit: 2498 Application/Control Number: 18/879,319 Page 23 Art Unit: 2498 Application/Control Number: 18/879,319 Page 24 Art Unit: 2498 Application/Control Number: 18/879,319 Page 25 Art Unit: 2498 Application/Control Number: 18/879,319 Page 26 Art Unit: 2498 Application/Control Number: 18/879,319 Page 27 Art Unit: 2498
Read full office action

Prosecution Timeline

Dec 27, 2024
Application Filed
Apr 03, 2026
Non-Final Rejection (signed) — §101, §103, §112
May 13, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732520
GENERATION DEVICE, GENERATION METHOD, AND GENERATION PROGRAM
2y 0m to grant Granted Sep 08, 2026
Patent 12719874
SECURITY MANAGEMENT OF TRUSTED NETWORK FUNCTIONS
1y 8m to grant Granted Aug 25, 2026
Patent 12712643
SYSTEM AND METHOD FOR NETWORK DISTRIBUTION OF QUANTUM ENTANGLEMENT
1y 11m to grant Granted Aug 18, 2026
Patent 12694098
SYSTEMS AND METHODS FOR MANAGING STATE
1y 8m to grant Granted Jul 28, 2026
Patent 12689615
DATA PROCESSING METHOD AND APPARATUS, COMPUTER DEVICE, AND STORAGE MEDIUM
2y 0m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+11.2%)
2y 9m (~12m remaining)
Median Time to Grant
Low
PTA Risk
Based on 917 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month