Prosecution Insights
Last updated: October 01, 2026
Application No. 18/918,507

SECURITY MODULE VALIDATION

Final Rejection §102
Filed
Oct 17, 2024
Priority
Aug 08, 2024 — IN 202411060007
Examiner
IDOWU, OLUGBENGA O
Art Unit
2494
Tech Center
2400 — Computer Networks
Assignee
Hewlett Packard Enterprise Development L.P.
OA Round
2 (Final)
72%
Grant Probability
Favorable
3-4
OA Rounds
1y 4m
Est. Remaining
91%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
469 granted / 655 resolved
+13.6% vs TC avg
Strong +19% interview lift
Without
With
+19.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
21 currently pending
Career history
686
Total Applications
across all art units

Statute-Specific Performance

§101
4.8%
-35.2% vs TC avg
§103
66.5%
+26.5% vs TC avg
§102
23.9%
-16.1% vs TC avg
§112
2.4%
-37.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 655 resolved cases

Office Action

§102
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot based on new grounds of rejection. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claim(s) 1 - 20 are rejected under 35 U.S.C. 102 (a)(1) as being anticipated by Fu, publication number: US 2018/0234255. As per claim 1, Fu teaches a non-transitory machine-readable storage medium comprising instructions that upon execution cause a system to: validate a security module connected to a processor module using a cryptographic device identity of the security module, the security module and the processor module being part of a computing system (authenticating a platform, central processing unit coupled to TPM, [0030]); perform a manifest certificate check based on a manifest certificate containing information representing a security processor in the security module, and identifiers of components in the processor module, the manifest certificate check to confirm that the manifest certificate refers to the security module (verifying TPM, [0045], comparing T sub ID to verify TPM, [0045]); based on determining that the manifest certificate check is successful, perform a manifest components check comprising comparing the identifiers of the components in the processor module obtained from the manifest certificate to stored component identifiers (verifying that the certificate was sent by an app on the trusted platform, [0048-0049]); and based on determining that the manifest components check is successful and the comparing producing a match, allow an operation of the computing system to continue (allowing secure communication, [0052]). As per claim 2, Fu teaches wherein the information representing the security processor in the security module comprises a reference to a security processor certificate that is bound to the security processor in the security module (TPM, [0053], EK certificate, [0037]). As per claim 3, Fu teaches wherein the security processor certificate comprises an endorsement key (EK) certificate, and the security processor comprises a trusted platform module (TPM) (TPM, [0053], EK certificate, [0037]). As per claim 4, Fu teaches wherein the manifest certificate check comprises obtaining an identifier of the security processor using the security processor certificate, and comparing the obtained identifier of the security processor to an identifier of the security processor in the manifest certificate, and wherein the instructions upon execution cause the system to: generate a failure indication in response to the obtained identifier of the security processor not matching the identifier of the security processor in the manifest certificate, the failure indication indicating that the security module is potentially not authorized for the processor module (Comparing, [0010][0045][0052]). As per claim 5, Fu teaches wherein the failure indication is to trigger a check of whether use of the security module with the processor module is part of an authorized action (prevent malicious processes, [0051]). As per claim 6, Fu teaches wherein the identifier of the security processor comprises an EK of the security processor (EK certificate, [0037]). As per claim 7, Fu teaches wherein the cryptographic device identity is stored in the security processor during a first stage of manufacture of the computing system, and the manifest certificate is provided after the first stage of manufacture of the computing system (authentication [0052][0044][0049]). As per claim 8, Fu teaches wherein the identifiers of the components in the processor module comprise identifiers of hardware components and identifiers of program components in the processor module (comparing T sub ID, [0045]) As per claim 9, Fu teaches wherein the manifest certificate comprises a platform certificate provided by a manufacturer of the computing system (issued by manufacturer, [0007][0044]) As per claim 10, Fu teaches wherein the stored component identifiers are included in a manifest repository (comparing T sub ID, [0045]) As per claim 11, Fu teaches wherein the instructions upon execution cause the system to: generate a failure indication in response to the identifiers of the components obtained from the manifest certificate not matching the stored component identifiers, the failure indication indicating that the security module is potentially not authorized for the processor module (preventing malicious processes, [0051]). As per claim 12, Fu teaches wherein the manifest certificate check further comprises deriving information based on a security processor certificate of the security processor, and determining based on the derived information whether the manifest certificate refers to the security processor to which the cryptographic device identity is bound (authenticating, [0049]) As per claim 13, Fu teaches wherein the security processor certificate comprises an endorsement key (EK) certificate, and the derived information comprises an EK or a digest based on the EK certificate (authenticating EK certificate, [0049]). As per claim 14, Fu teaches wherein the manifest certificate check comprises determining whether the manifest certificate is stored in the security module, wherein the manifest certificate check produces a failure indication if the manifest certificate is not stored in the security module, the failure indication indicating that the security module is potentially not authorized for the processor module (authenticating EK certificate, [0049]). As per claim 15, Fu teaches wherein the cryptographic device identity comprises a device identity (DevID) certificate (verifying and authenticating using T.sub ID, [0048]). As per claim 16, Fu teaches a method comprising: validating, by a management system comprising a hardware processor, a security module connected to a processor module using a cryptographic device identity of the security module, the security module and the processor module being part of a computing system (authenticating a platform, central processing unit coupled to TPM, [0030]); after the validating, performing, by the management system, a manifest certificate check based on a manifest certificate containing: information representing an identifier of a security processor in the security module (verifying TPM, [0045]), and manifest information comprising identifiers of components in the processor module, wherein the manifest certificate check comprises: accessing the identifier of the security processor usingg the manifest certificate, comparing the accessed identifier of the security processor to an identifier of the security processor in the manifest certificate (comparing T.sub. ID to verify TPM, [0045]), and based on the accessed identifier of the security processor matching the identifier of the security processor in the manifest certificate, comparing the identifiers of the components in the processor module obtained from the manifest certificate to stored component identifiers of components that are to be included in the device computing system (verifying application, [0048-0049]); and based on determining that the manifest certificate check is successful, allowing, by the management system, an operation of the computing system to continue (allowing application to prove trustworthiness, [0052]). As per claim 17, Fu teaches wherein the accessing of the identifier of the security processor using the manifest certificate comprises; using a reference in the manifest certificate to retrieve a security processor certificate, and obtaining the identifier of the security processor from the security processor certificate, and wherein the identifier of the security processor comprises an endorsement key (EK) of the security processor (EK certificate, [0037]). As per claim 18, Fu teaches comprising: generating, by the management system, a failure indication in response to: the accessed identifier of the security processor not matching the identifier of the security processor in the manifest certificate, or the identifiers of the components obtained from the manifest certificate not matching the stored component identifiers, wherein the failure indication indicates that the security module is potentially not authorized for the processor module (preventing malicious processes, [0051]). As per claim 19, Fu teaches a management system comprising: a processor; and a non-transitory storage medium comprising instructions executable on the processor to: validate a security module comprising a security processor and connected to a processor module using a cryptographic device identity of the security module, the security module and the processor module being part of a computing system (authenticating a platform, central processing unit coupled to TPM, [0030]); perform a manifest certificate check based on information in a manifest certificate, the manifest certificate containing information representing the security processor in the security module, and identifiers of components in the processor module, and the manifest certificate check comprising: obtaining a security processor certificate using a reference in the manifest certificate (Verifying TPM [0045]), determining based on information derived from the security processor certificate whether the manifest certificate refers to the security processor to which the cryptographic device identity is bound (Comparing T Sub ID [0045]), and based on determining that the manifest certificate refers to the security processor, comparing the identifiers of components in the processor module obtained from the manifest certificate to stored component identifiers (verifying applications, [0048-0049]); and based on determining that the manifest certificate check is successful, allow an operation of the computing system to continue (allowing applications to prove trustworthiness, [0052]). As per claim 20, Fu teaches wherein the cryptographic device identity comprises a Device Identity (Dev ID) certificate, the manifest certificate comprises a platform certificate, and the security processor certificate comprises an endorsement key (EK) certificate (T. sub ID, [0045], EK certificate, [0037], root and chain of trust [0030][00035]). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to OLUGBENGA O IDOWU whose telephone number is (571)270-1450. The examiner can normally be reached Monday-Friday 8am - 5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached at 5712723804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /OLUGBENGA O IDOWU/Primary Examiner, Art Unit 2494
Read full office action

Prosecution Timeline

Show 2 earlier events
May 05, 2026
Interview Requested
May 12, 2026
Applicant Interview (Telephonic)
May 12, 2026
Examiner Interview Summary
May 15, 2026
Response Filed
Jul 15, 2026
Final Rejection mailed — §102
Sep 03, 2026
Interview Requested
Sep 10, 2026
Applicant Interview (Telephonic)
Sep 21, 2026
Examiner Interview Summary

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730938
METHOD AND SYSTEM FOR DETECTION OF TAMPERING IN EXECUTABLE CODE
1y 11m to grant Granted Sep 08, 2026
Patent 12724881
ANOMALY DETECTION
2y 0m to grant Granted Sep 01, 2026
Patent 12719761
SYSTEMS AND METHODS FOR COMMUNICATION MODIFICATION TO REDUCE INACCURATE MACHINE-LEARNING-BASED COMMUNICATION SUPPRESSIONS
4y 0m to grant Granted Aug 25, 2026
Patent 12712742
METHOD AND SYSTEM FOR SECURITY IN A VIRTUAL ENVIRONMENT
2y 6m to grant Granted Aug 18, 2026
Patent 12670410
PRIVACY ENHANCED FEDERATED TRAINING AND INFERENCE OVER VERTICALLY AND HORIZONTALLY PARTITIONED DATA
3y 4m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
72%
Grant Probability
91%
With Interview (+19.0%)
3y 3m (~1y 4m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 655 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month