Prosecution Insights
Last updated: August 17, 2026
Application No. 18/929,959

DISTRIBUTED LEDGER TO ASSURE OWNERSHIP IN SECURELY ONBOARDED DEVICES

Non-Final OA §103§112
Filed
Oct 29, 2024
Priority
Dec 01, 2023 — provisional 63/605,376
Examiner
ANKRUM, ALEC CHRISTOPHER
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-58.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
12 currently pending
Career history
13
Total Applications
across all art units

Statute-Specific Performance

§101
9.4%
-30.6% vs TC avg
§103
59.4%
+19.4% vs TC avg
§112
28.1%
-11.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 0 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Status Claims 1-20 are under examination. Priority Applicant’s claim to priority to the following provisional application has been acknowledged by the examiner: 63/605,376 (12/01/2023) Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as failing to set forth the subject matter which the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the applicant regards as the invention. Regarding claims 1, 11, and 16, they recite the limitations “the alleged owners” twice. There is insufficient antecedent basis for this limitation as it is unclear whether it is referring to “an alleged owner” or different alleged owners. For examination purposes, “the alleged owners” is being interpreted as “the alleged owner”. Dependent claims 2-10, 12-15, and 17-20 are rejected based on their respective dependencies on the indefinite claims 1, 11, and 16. Regarding claim 8, the claim is incomplete for omitting essential elements, such omission amounting to gap between the elements. See MPEP § 2172.01. There are missing essential elements as it is not clear how the identity is verified from time ordered transfers. Regarding claims 5, 15, and 20, they recite the limitation “the distributed ledger is updated timely”. The term “timely” is a relative term which renders the claims indefinite. The term “timely” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. For examination purposes, the limitation “the distributed ledger is updated timely” is being interpreted as “the distributed ledger is updated”. Further regarding claim 5, it recites the limitation “the point in time”. There is insufficient antecedent basis for this limitation in the claim and it is unclear whether it is referring to “a past point in time” or another point in time. For examination purposes, “the point in time” is being interpreted as referring to the “past point in time” of claim 4. Further regarding claims 15 and 20, they recite the limitation “the point in time”. It is unclear whether this is the same point of time recited in the respective parent claims 14 and 19. For examination purposes, “the point in time” is being interpreted as referring to the “past point of time” of parent claims 14 and 19 respectively. Regarding claim 10, it recites the limitation “using the votes”. There is a lack of antecedent basis for this limitation in the claim. For examination purposes, “using the votes” is being interpreted as “using votes”. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-4, 11-14, and 16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Ma et al. (International Patent Publication No. WO 2024/170057), hereinafter Ma in view of Haddad et al. (United States Patent No. 2024/0086205), hereinafter Haddad. Regarding claim 1, Ma teaches a method for managing operation of an endpoint device, the method comprising (Ma Page 1 Lines 15-20: “The present disclosure relates to a method for securely authenticating an identity of an industrial device and a corresponding system as well as a method for onboarding an industrial device to a customer agent and a corresponding system.”): during an onboarding of the endpoint device to an orchestrator (Ma Page 8 Lines 28-30: “an onboarding system is configured to execute for onboarding an industrial device to a customer agent”): obtaining, by the endpoint device, an ownership voucher usable to, at least in part, ascertain an alleged owner of the endpoint device (Ma Page 4 Lines 32-34: “obtaining, by the industrial device, the DDID certificate comprises receiving, by the industrial device, the DDID certificate, the private key and the unique device identifier from the manufacturing agent.”); attempting, [by the endpoint device], to verify that the alleged owner is a current owner of the endpoint device using an immutable ledger (Ma Page 10 Lines 13-18: “The customer control system 30 comprises a customer agent 31 that is configured to access the industrial device 10 and the private blockchain, in particular the second blockchain node 32. The customer agent 31 connects to the industrial device 10 for the DDID certificate 12 and then to the second blockchain node 32 to look up the hash code of the DDID-certificate 12 with the unique identifier.”); in a first instance of the attempting where the alleged owners is verified as the current owner (Ma Page 10 Lines 13-18: “The customer control system 30 comprises a customer agent 31 that is configured to access the industrial device 10 and the private blockchain, in particular the second blockchain node 32. The customer agent 31 connects to the industrial device 10 for the DDID certificate 12 and then to the second blockchain node 32 to look up the hash code of the DDID-certificate 12 with the unique identifier.”): continuing, [by the endpoint device], performance of the onboarding to the orchestrator to join a deployment (Ma Page 10 Lines 18-20: “If the hash code is found and the value matches with the calculated hash code of the DDID-certificate 12 of the industrial device 10, the customer agent 31 will provision the industrial device 10 to a control system network.”), and providing, [by the endpoint device], computer implemented services as part of the deployment (Ma Page 10 Lines 20-24: “The customer agent 31 then use the DDID-certificate 12 to establish a secure connection with the industrial device 10 and issues an application instance certificate to the industrial device 10. The industrial device 10 can then use the application instance certificate to establish secure channel with other applications in a customer control system network of the end user.”); but Ma fails to explicitly teach attempting, by the endpoint device continuing, by the endpoint device and in a second instance of the attempting where the alleged owners is not verified as the current owner: discontinuing, by the endpoint device, the performance of the onboarding. However, Haddad teaches attempting, by the endpoint device (Haddad ¶40: “the retrieved owner certificate 110 may be validated by the network device 102 using the ownership voucher 108.”) continuing, by the endpoint device (Haddad ¶53: “If the iPXE scripts are validated, then at 230, the network device 208 may execute the iPXE scripts. For example, the iPXE scripts may cause the network device 208 to onboard with one of the servers 120.”) and in a second instance of the attempting where the alleged owners is not verified as the current owner (Haddad ¶35: “the techniques and architecture provide for verifying and verifying the iPXE scripts 106 prior to execution during a booting process, e.g., a boot up process, a bootstrap process, etc., of the network device 102. The techniques and architecture utilize the ownership voucher 108 and the owner certificate 110 to validate and verify the signed iPXE scripts 106.”): discontinuing, by the endpoint device, the performance of the onboarding (Haddad ¶43: “By validating and verifying the iPXE scripts 106 prior to execution of the iPXE scripts 106, the network device 102 may be prevented from onboarding with the wrong server 120.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Ma in view of Haddad for the endpoint device to perform these functions to help prevent the device from onboarding to incorrect or malicious deployments (Haddad ¶20: “the techniques may also help prevent the network device from running over different networks in a co-located network environment. In particular, the presence of a device specific certificate, i.e., the unique device identifier and trust anchor certificates, the ownership voucher, and the owner certificate, ensures that the network device boots only from its intended service providers and not from other network service providers, or even hacked bootstrap servers, when the network device is deployed in a network with multiple co-located bootstrap servers belonging to different network providers.”). Claims 11 and 16 are substantially similar to claim 1 and are rejected under the same rationale. In addition, Ma teaches claim 11’s a non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing an endpoint device, the operations comprising (Ma Page 9 Lines 15-20: “the functional modules and/or the configuration mechanisms are implemented as programmed software modules or procedures”) In addition, Ma teaches claim 16’s an endpoint device (Ma Page 1 Line 18: “an industrial device”), but fails to explicitly teach comprising: a processor; and a memory coupled to the processor to store instructions, which when executed by the processor, cause operations to be performed, the operations comprising However, Haddad teaches comprising: a processor; and a memory coupled to the processor to store instructions, which when executed by the processor, cause operations to be performed, the operations comprising (Haddad ¶58: “the method 300 may be performed by a system comprising one or more processors and one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform the method 300”). Regarding claim 2, the method of claim 1, wherein the ownership voucher comprises a certificate chain documenting changes in ownership over the endpoint device (Ma Page 8 Lines 7-9: “the private blockchain functions as a log of ownership. This log can also be extended by the current owner when reselling the industrial device to the next owner, this way achieving mutual authentication between industrial device and next owner.”). Claims 12 and 17 are substantially similar to claim 2 and are rejected under the same rationale. Regarding claim 3, the method of claim 2, wherein the immutable ledger is a distributed ledger that documents the changes in the ownership (Ma Page 8 Lines 7-9: “the private blockchain functions as a log of ownership. This log can also be extended by the current owner when reselling the industrial device to the next owner, this way achieving mutual authentication between industrial device and next owner.”). Claims 13 and 18 are substantially similar to claim 3 and are rejected under the same rationale. Regarding claim 4, the method of claim 3, wherein the ownership voucher is generated at a past point in time (Ma Page 4 Lines 12-13: “during manufacturing, the manufacture agent generates the DDID certificate for the industrial device.”). Claims 14 and 19 are substantially similar to claim 4 and are rejected under the same rationale. Claims 5, 15, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Ma in view of Haddad in view of Sarkar (United States Patent Publication No. 2023/0394152). Regarding claim 5, Ma and Haddad teach the method of claim 4, but fail to teach wherein the distributed ledger is updated timely, However, Sakar teaches wherein the distributed ledger is updated timely (Sakar ¶71: “For each owner, both the memory of the device and the blockchain ledger may be continuously updated with new ownership data.”), It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Ma and Haddad in view of Sakar to create an accurate chain of ownership of the device to increase security (Sakar ¶14: “One problem with the above is that a chain of ownership of the device may not be properly maintained during the lifespan of the device. The chain of ownership may function to indicate owners of the device during the lifespan of the device, where the chain of ownership may begin from a manufacturing of the device. The chain of ownership may include ownership information that is falsified or incomplete. The ownership information may be compromised, tampered, hacked, and/or replaced with malicious information. The ownership information may indicate owners with no physical existence, or owner identities may be falsified. As a result, the risk that the security of the device has been compromised (e.g., due to a previous owner installing a backdoor to secretly access the device) may be increased”). Ma further teaches and the ownership voucher does not reflect any changes in the ownership over the endpoint device past the point in time (Ma Page 4 Lines 12-13: “during manufacturing, the manufacture agent generates the DDID certificate for the industrial device.”). Examiner note: not reflecting any changes in ownership over the endpoint device past the past point in time is inherent as certificate transfers for the industrial device cannot be reflected before it was generated. Claims 15 and 20 are substantially similar to claim 5 and are rejected under the same rationale. Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Ma et al. in view of Haddad in view of Goodman et al. (United States Patent No. 2024/0333531), hereinafter Goodman. Regarding claim 6, Ma and Haddad teach the method of claim 1, but fail to teach further comprising: during the onboarding of the endpoint device to the orchestrator: ascertaining, by the endpoint device and using the ownership voucher, whether the alleged owner of the endpoint device has delegated authority over the endpoint device to the orchestrator; and in an instance of the ascertaining where the alleged owner of the endpoint device has not delegated authority over the endpoint device: discontinuing, by the endpoint device, the performance of the onboarding. However, Goodman teaches further comprising: during the onboarding of the endpoint device to the orchestrator (Goodman ¶130: “the components of FIG. 1A may perform various methods to onboard endpoint devices. FIG. 3 illustrates a method that may be performed by the components of the system of FIGS. 1A-1K.”): ascertaining, by the endpoint device and using the ownership voucher, whether the alleged owner of the endpoint device has delegated authority over the endpoint device to the orchestrator (Goodman ¶110: “To onboard endpoint device 136, orchestrator 132 may, at interaction 240, send a voucher request to voucher management system 110. The voucher request may be a request for an ownership voucher for an endpoint device (e.g., 136).”); and in an instance of the ascertaining where the alleged owner of the endpoint device has not delegated authority over the endpoint device: discontinuing, by the endpoint device, the performance of the onboarding (Goodman ¶142-143: “At operation 310, the endpoint device may conclude that the orchestrator does not have authority over it. At operation 31, the endpoint may terminate the onboarding. The onboarding may be terminated by the endpoint device refusing to participate in the onboarding process.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Ma and Haddad in view of Goodman to increase security of the endpoint device while still allowing for authority over them to be granted (Goodman ¶18: “embodiments disclosed herein may facilitate establishment of authority while limiting key proliferation. Accordingly, a system in accordance with embodiments disclosed herein may be less like to suffer and suffer at reduced levels from compromises of devices that may expose keys used to establish authority for onboarding and/or other purposes. For example, keys to which authority is delegated in ownership vouchers may be generally restricted from distribution while still allowing authority over those devices to be established.”). Claims 7 and 9 are rejected under 35 U.S.C. 103 as being unpatentable over Ma et al. in view of Haddad in view of Smith et al. (United States Patent No. 11,683,685), hereinafter Smith. Regarding claim 7, Ma and Haddad teach the method of claim 1, but fail to teach wherein the immutable ledger and the ownership voucher are maintained, in part, by a voucher management system. However, Smith teaches wherein the immutable ledger and the ownership voucher are maintained, in part, by a voucher management system. (Smith Col. 8 Line 60 - Col. 9 Line 2: “the certificate may be saved as an entry in a CPL data store (e.g., database, listing, repository, ledger, data set, or other collection or organization of information). The CPL data store may be accessed to produce a machine-readable or OCF-signed document for use during onboarding, provisioning, auditing, or other uses. In various examples, the CPL data store and other data stores or sources discussed herein) may be distributed or coordinated among multiple entities, or operated in aspects of blockchain and distributed ledger configurations.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Ma and Haddad in view of Smith to increase the availability of the immutable ledger and ownership voucher (Smith Col. 9 Lines 2-4: “such data stores may include aspects of caching, remote/local data management, including to provide redundant or offline availability of data.”). Regarding claim 9, Ma and Haddad teach the method of claim 1, wherein attempting, by the endpoint device, to verify that the alleged owner is the current owner of the endpoint device using the immutable ledger comprises (Ma Page 10 Lines 13-20: “The customer control system 30 comprises a customer agent 31 that is configured to access the industrial device 10 and the private blockchain, in particular the second blockchain node 32. The customer agent 31 connects to the industrial device 10 for the DDID certificate 12 and then to the second blockchain node 32 to look up the hash code of the DDID-certificate 12 with the unique identifier. If the hash code is found and the value matches with the calculated hash code of the DDID-certificate 12 of the industrial device 10, the customer agent 31 will provision the industrial device 10 to a control system network.”): but Ma and Haddad fail to teach obtaining, from voting nodes that participate in management of the immutable ledger, votes regarding the current owner of the endpoint device; and identifying the current owner using the votes. However, Smith teaches obtaining, from voting nodes that participate in management of the immutable ledger (Smith Col. 16 Lines 21-26: “Blockchain transactions may be integrity protected using a distributed hashing algorithm that requires each transaction processor (e.g., ‘miner’) to agree to the next block in the blockchain. Integrity is achieved through a consensus of multiple miners (e.g., via a vote), each miner having access to its own copy of the ledger.”), votes regarding the current owner of the endpoint device (Smith Col. 13 Lines 18-28: “A self-sovereign identity blockchain is a mechanism for individual assertion of identity (identifiers) that may be published through the blockchain such that blockchain members agree (or vote) regarding which asymmetric key possesses which identifier.”); and identifying the current owner using the votes (Smith Col. 13 Lines 18-28: “A self-sovereign identity blockchain is a mechanism for individual assertion of identity (identifiers) that may be published through the blockchain such that blockchain members agree (or vote) regarding which asymmetric key possesses which identifier.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Ma and Haddad in view of Smith to utilize voting nodes within the immutable ledger to identify the current user in order to increase the integrity of the ledger (Smith Col. 16 Lines 26-31: “If a majority of the miners agree on the contents of the ledger, then those agreed upon contents become the ‘truth’ for the ledger; the miners that disagree will accept the truth of the majority. Integrity is provable because an attacker would have to compromise a majority of miners and modify their copies of the ledger; this is extremely difficult (if not impossible).”). Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Ma in view of Haddad in view of McFarlane (United States Patent Publication No. 2021/0005293) in view of Smith. Regarding claim 10, Ma and Haddad teach the method of claim 1, wherein attempting, by the endpoint device, to verify that the alleged owner is the current owner of the endpoint device using the immutable ledger comprises (Ma Page 10 Lines 13-20: “The customer control system 30 comprises a customer agent 31 that is configured to access the industrial device 10 and the private blockchain, in particular the second blockchain node 32. The customer agent 31 connects to the industrial device 10 for the DDID certificate 12 and then to the second blockchain node 32 to look up the hash code of the DDID-certificate 12 with the unique identifier. If the hash code is found and the value matches with the calculated hash code of the DDID-certificate 12 of the industrial device 10, the customer agent 31 will provision the industrial device 10 to a control system network.”): but fail to teach obtaining, from a trusted quorum, an attestation regarding the current owner of the endpoint device; However, McFarlane teaches obtaining, from a trusted quorum, an attestation regarding the current owner of the endpoint device (McFarlane ¶61: “The quorum blockchain node component 406 may confirm ownership of the signed transaction and may execute the smart contract for the hospital representative to view the user's data.”); It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Ma and Haddad in view of McFarlane to utilize a quorum’s attestation to increase security due to its increased nodes (McFarlane ¶43: “each block may be inherently resistant to modification of the data due to, for example, management by a peer-to-peer network adhering to a protocol for internode communication and validating new blocks.”). Ma, Haddad, and McFarlane fail to teach and identifying the current owner using the votes. However, Smith teaches and identifying the current owner using the votes (Smith Col. 13 Lines 18-28: “A self-sovereign identity blockchain is a mechanism for individual assertion of identity (identifiers) that may be published through the blockchain such that blockchain members agree (or vote) regarding which asymmetric key possesses which identifier.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Ma, Haddad, and McFarlane in view of Smith to utilize voting nodes within the immutable ledger to identify the current user in order to increase the integrity of the ledger (Smith Col. 16 Lines 26-31: “If a majority of the miners agree on the contents of the ledger, then those agreed upon contents become the ‘truth’ for the ledger; the miners that disagree will accept the truth of the majority. Integrity is provable because an attacker would have to compromise a majority of miners and modify their copies of the ledger; this is extremely difficult (if not impossible).”). Allowable Subject Matter Claims 8 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims as well as rewritten to overcome the 112(b) rejection. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Won et al. (United States Patent Publication No. 2018/0183587). Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALEC ANKRUM whose telephone number is (571)272-9209. The examiner can normally be reached M-F 7:15am-3:15pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.C.A./Examiner, Art Unit 2434 /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Oct 29, 2024
Application Filed
Jul 23, 2026
Non-Final Rejection mailed — §103, §112 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month