Prosecution Insights
Last updated: August 15, 2026
Application No. 18/915,605

VALIDATION OF SOFTWARE RESIDING ON REMOTE COMPUTING DEVICES

Final Rejection §103
Filed
Oct 15, 2024
Priority
Mar 16, 2020 — divisional of 11/080,387 +3 more
Examiner
ULLAH, SHARIF E
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Integrity Security Services LLC
OA Round
2 (Final)
85%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
389 granted / 460 resolved
+26.6% vs TC avg
Strong +22% interview lift
Without
With
+21.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
18 currently pending
Career history
481
Total Applications
across all art units

Statute-Specific Performance

§101
13.4%
-26.6% vs TC avg
§103
60.5%
+20.5% vs TC avg
§102
6.8%
-33.2% vs TC avg
§112
11.9%
-28.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 460 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/08/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Response to Arguments Applicant’s arguments have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-7, 9-17, 19-20 are rejected under 35 U.S.C 103 as being unpatentable over Van Someren (US 2004/0268339), hereon referred to as Van, in view of Tayler (US 2018/0114000), and hereon referred to as Taylor, in view of Scherer, III et al. (US 2018/0121656), hereon referred to as Scherer. In regards to claims 1, 10 & 20, Van discloses obtaining an authentic copy of the software, wherein the authentic copy is a last known authorized software provided to the device (In order to verify the calculations carried out by the system, the user will refer to a trusted third party or agent who is assumed to have definitive knowledge of the firmware that should be contained within the ROM the agent provides a validation routine for the user to run himself whenever he wishes to validate the firmware. A validation routine along with a firmware file containing a copy of the "correct" firmware (i.e. the expected contents of the ROM) is supplied on a CD ROM or other physical media; Paragraphs 0066-0079); sending a software validation request comprising a first value to the device (the validation routine issues a random challenge from a pseudo-random generator; This acts as one input to the MAC or other software authentication function within the module; wishing to check the validity of the firmware 18, first picks a random challenge number in some large, predefined range and passes that challenge on to the system via some channel; Paragraphs 0065-0070; 0075-0080); receiving a first check value generated based on the first value and the software installed on the device (Computes the Message Authentication Code using both the challenge value and the full contents of the firmware within the system, and sends back an authentication code to the user; The output from the software authentication function 20 is returned as a response to the validation routine; Paragraphs 0065-0070; 0075-0080); computing a second check value based on the authentic copy and the first value (As part of the validation routine there is a further MAC or authentication routine corresponding to the routine within the module. This takes as one of its inputs the random challenge from the random number generator, and as its other input the expected contents of the ROM; The user then presents the same (or an equivalent) challenge to the trusted third party or agent, via some other channel. The agent then computes the same message authentication code using the same challenge, and returns the correct response; Paragraphs 0065-0070; 0075-0081). However, Van does not disclose modifying operation of the device when a comparison of the first check value and the second check value indicates that the software installed on the device is not valid. In an analogous art Taylor discloses modifying operation of the device when a comparison of the first check value and the second check value indicates that the software installed on the device is not valid (If access is denied then the connection between the server device and the client device will likely be severed before ending the process; If the fingerprint is not matched in the database then the attestation will fail and the application server code may choose not to grant access to the sensitive service or data, or might perhaps request additional levels of attestation from the user of the remote client device in order to neutralize any malicious actions being performed by modified client software; Paragraphs 0045-055). At the time before the effective filing date of the invention, it would have been obvious to the one with ordinary skill in the art to combine the teachings disclosed by Van, with the teachings disclosed by Taylor regarding modifying operation of the device when a comparison of the first check value and the second check value indicates that the software installed on the device is not valid. The suggestion/motivation of the combination would have been to provide additional security in authenticity checking of software code (Taylor; Paragraph 0001). However, the combination of Van and Taylor does not disclose the device is not valid, the modifying operation of the device including correcting or recovering the software in the device. In an analogous art Scherer discloses the device is not valid, the modifying operation of the device including correcting or recovering the software in the device ( the peripheral device replacing the operating firmware with the replacement firmware retrieved by the peripheral device at block 608. Replacing the operating firmware with the replacement firmware may comprise the replacement firmware being installed over an existing installation of the operating firmware on memory of the peripheral device. In comparison to operating firmware determined to be untrustworthy by the validator, replacement firmware retrieved from a data source may be considered trusted firmware. Additionally, the replacement firmware may be an older or newer version of firmware in comparison to the operating firmware installed on memory of the peripheral device; Paragraphs 0040-0050). At the time before the effective filing date of the invention, it would have been obvious to the one with ordinary skill in the art to combine the teachings disclosed by the combination of Van and Taylor, with the teachings disclosed by Scherer regarding the device is not valid, the modifying operation of the device including correcting or recovering the software in the device. The suggestion/motivation of the combination would have been to provide for firmware verification on a peripheral device that can couple to a computing device (Scherer; Abs.). In regards to claims 2 & 13, Van discloses wherein sending the software validation request comprises communicating with the device through an electronic communications channel ( The communication channels 26,30 may include any convenient communication channels such as a wired or wireless network, the Internet, or point to point connections; Paragraphs 0070-0075). In regards to claims 3 & 11, Taylor discloses wherein the first check value is stored in a secure data repository (The response validation module receives the response from the attestation response handling module and information from a database of known good fingerprints; Paragraphs 0050-0055). In regards to claims 4 & 14, Taylor discloses a first instruction for disabling or partially disabling the device, a second instruction for correcting or recovering the software in the device, a third instruction for preventing data transfer from the device, or a fourth instruction for sending an alert from the device (. If the fingerprint is not matched in the database then the attestation will fail and the application server code 302 may choose not to grant access to the sensitive service or data, or might perhaps request additional levels of attestation from the user of the remote client device in order to neutralize any malicious actions being performed by modified client software; Paragraphs 0047-0055). In regards to claims 5 & 15, Taylor discloses wherein the modifying comprises at least one of: disabling or partially disabling the device, or correcting or recovering the software in the device (the application server code may choose not to grant access to the sensitive service or data, or might perhaps request additional levels of attestation from the user of the remote client device in order to neutralize any malicious actions being performed by modified client software; Paragraphs 0047-0055). In regards to claims 6 & 16, Van discloses wherein receiving the first check value further comprises: receiving, from the device, the first check value, which was generated based on the first value, the software, and static data stored in a memory of the device, wherein the static data comprises at least one of: one or more binary executable files, one or more data files, or one or more directories (When a challenge is presented, the Message Authentication Code is computed not on the basis of the firmware alone, but on the entirety of the data (including the random data) contained within the ROM 14. The agent 28 of course computes its code using the correct, known, entirety of the contents of the ROM; Paragraphs 0075-0080). In regards to claim 7, Taylor discloses wherein the software validation request indicates a time limit for generation of the first check value by the device (A non-response from the client device or failure to respond within a timeout period will be considered an attestation failure. The exact form of the attestation response 308 will depend on the characteristics of the software attestation scheme employed; Paragraphs 0050-0055). In regards to claims 9 & 19, Taylor discloses a detection that the device has transitioned from a lower powered state to a higher powered state, a first expiration of a randomly determined time period, or a second expiration of a non-random predetermined interval since the sending of a previous software validation request (another viable strategy might be to request attestation at regular time intervals during the duration of the connectivity period between the server and client. It will be appreciated that various other strategies might be employed in selecting the best intervals to attest the client software; Paragraphs 0050-0055). In regards to claim 12, the combination of Van, Taylor and Scherer discloses a trusted software repository configured to store the authentic copy of the software (The elements presented in the claim(s) do not contain any additional features, do not present any inventive step or novelty not addressed/presented in the combination of Van, Taylor and Scherer. Examiner takes official notice, that these elements are commonly known, minor design details that are derivable from the prior art and are well known, and obvious to an ordinary skill in the art. The additional features of these claims represent normal design options, which the skilled person would implement the combination of Van, Taylor and Scherer, depending on the circumstances, without exercising any inventive activity). Claims 8 & 18 are rejected under 35 U.S.C 103 as being unpatentable over the combination of Van, Taylor and Scherer in view of in view of Gligor et al. (US 2022/0108006), and hereon referred to as Gligor. In regards to claims 8 & 18, the combination of Van, Taylor and Scherer does not disclose storing information related to an estimated time for generating of the first check value by the device, and wherein, if an actual time for generation of the first check value deviates by greater than a predetermined threshold from the estimated time, the software installed on the device is determined as not valid regardless of the comparison of the first check value and the second check value. However, in an analogous art Gligor discloses storing information related to an estimated time for generating of the first check value by the device, and wherein, if an actual time for generation of the first check value deviates by greater than a predetermined threshold from the estimated time, the software installed on the device is determined as not valid regardless of the comparison of the first check value and the second check value (Then the verifier records this conclusion in its memory and, in one embodiment, displays it in human-perceptible form on its display. If the response or the system is incorrect or untimely, the verifier concludes that a RoT is not established, records this conclusion in its memory and, in one embodiment, displays it in human-perceptible form; Paragraphs 0055-0060). At the time before the effective filing date of the invention, it would have been obvious to the one with ordinary skill in the art to combine the teachings disclosed by the combination of Van, Taylor and Scherer, with the teachings disclosed by Gligor regarding storing information related to an estimated time for generating of the first check value by the device, and wherein, if an actual time for generation of the first check value deviates by greater than a predetermined threshold from the estimated time, the software installed on the device is determined as not valid regardless of the comparison of the first check value and the second check value. The suggestion/motivation of the combination would have been to provide additional security in authenticity checking of software code (Gligor; Paragraph 0001). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHARIF E ULLAH whose telephone number is (571)272-5453. The examiner can normally be reached Mon-Fri 7:00-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHARIF E ULLAH/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Oct 15, 2024
Application Filed
Mar 25, 2026
Non-Final Rejection mailed — §103
Jun 25, 2026
Response Filed
Jul 15, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12695928
VIDEO TRANSMISSION METHOD, VIDEO TRANSMISSION APPARATUS, ELECTRONIC DEVICE AND READABLE MEDIUM
3y 3m to grant Granted Jul 28, 2026
Patent 12695605
METHOD AND APPARATUS FOR A SOFTWARE DEFINED NETWORK
2y 11m to grant Granted Jul 28, 2026
Patent 12689500
CRYPTOGRAPHIC COMMUNICATION SYSTEM, CRYPTOGRAPHIC COMMUNICATION DEVICE, CRYPTOGRAPHIC COMMUNICATION METHOD, AND CRYPTOGRAPHIC COMMUNICATION PROGRAM
2y 9m to grant Granted Jul 21, 2026
Patent 12689504
SYSTEMS AND METHOD FOR ADAPTIVE RECURSIVE DESCENT DATA REDUNDANCY
1y 10m to grant Granted Jul 21, 2026
Patent 12684016
TRANSPORT LAYER SECURITY STACK FOR RESOURCE CONSTRAINED DEVICES
2y 9m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+21.7%)
2y 6m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 460 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month