Prosecution Insights
Last updated: October 04, 2026
Application No. 18/980,652

SYSTEMS AND METHODS FOR SAFETY-ENABLED CONTROL

Non-Final OA §102§103§112§DP
Filed
Dec 13, 2024
Priority
Jul 26, 2019 — provisional 62/879,102 +5 more
Examiner
SANDERS, JOSHUA T
Art Unit
Tech Center
Assignee
Fort Robotics Inc.
OA Round
1 (Non-Final)
74%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 74% — above average
74%
Career Allowance Rate
223 granted / 303 resolved
+13.6% vs TC avg
Strong +36% interview lift
Without
With
+36.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
30 currently pending
Career history
321
Total Applications
across all art units

Statute-Specific Performance

§101
12.1%
-27.9% vs TC avg
§103
46.5%
+6.5% vs TC avg
§102
17.4%
-22.6% vs TC avg
§112
19.5%
-20.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 303 resolved cases

Office Action

§102 §103 §112 §DP
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claims 1-20 are pending. Claims 1-20 are rejected, grounds follow. Priority Examiner acknowledges that instant application is a Continuation of Application 18/588,957 and has been accorded the benefit of the original priority date. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 12-18 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. The metes and bounds of the apparently novel lexical term “input validation window” (claims 12-18) and the apparently related “windowed input value” (claim 13, 16, 17) are not clear. The meaning of every term used in a claim should be apparent from the prior art or from the specification and drawings at the time the application is filed. Claim language may not be "ambiguous, vague, incoherent, opaque, or otherwise unclear in describing and defining the claimed invention." In re Packard, 751 F.3d 1307, 1311, 110 USPQ2d 1785, 1787 (Fed. Cir. 2014). Applicants need not confine themselves to the terminology used in the prior art, but are required to make clear and precise the terms that are used to define the invention whereby the metes and bounds of the claimed invention can be ascertained. (See MPEP 2173.05(a).I) Review of the specification suggests this is a limitation directed to the checking of whether a given input signal is correct (i.e. valid) or not, and for the purpose of applying art examiner has construed the limitation as reading upon prior art references which perform data accuracy checks on incoming signals, such as timeouts, hashing, or error-correction routines such as redundancy bits, etc. Should applicant intend a narrower interpretation; such as, e.g., that the input is evaluated for whether it is above or below a threshold, examiner suggests redrafting the claim to make the narrower interpretation more explicit, by setting forth limitations clarifying the scope of the “input validation window” expressly in the claim. Claims 19-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 19 recites the limitation "the input source" in Claim 19 line 1. There is insufficient antecedent basis for this limitation in the claim. Regarding Claim 20, dependent Claim(s) inherit the deficiencies of their respective parent claim(s). Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1, 3, 4, 6, and 8-10 and 12-14 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Dai et al., US Pg-Pub 2017/0329321. Regarding Claim 1, Dai discloses: A method comprising: generating a first safety condition (e.g. “critical safety zone” “hazard event”) for a first time period ([0087] “A typical hazard event is that a human enters a defined zone where an operating machine may harm the human seriously.” See [0071] “two safety zones… a critical one and a less critical one”) based on a first input value from an input source; ([0072] “ two subsystems surveying different safety zones each.” [0077] “Safety devices 6, 7 with hazard detecting means can be any kind of sensors known to be used for this purpose, for example proximity sensors, light barrier, laser scanner or the like.”) receiving a first unvalidated control value from a control system during the first time period; (e.g. F.Sub.N (Normal operation); see [0115] “In this case, the machine would run at 100%, if no safety zone violation is detected.”) transforming the first unvalidated control value (e.g. [0070] ‘F.sub.N is characterized by productivity P.sub.N…Productivity P.sub.N is the normal productivity.’) into a first safe control value based on the first safety condition; ([0088] “one can define a first critical safety zone Z.sub.1 around a machine 2 or a machine arrangement 5, an industrial robot for example, where the violation of this zone leads to stopping the robot immediately”) and outputting the first safe control value to a system under control. ([0135] “activates the machine arrangement 5, the respective actuator” [0078] “The machine 2 includes further a first actuator system having first safety function means configured to be triggered for executing a first safety function by the safety logic 3.”) Regarding Claim 3, Dai discloses all of the limitations of parent claim 1, Dai further discloses: generating a second safety condition (e.g. the less critical one) for a second time period ([0087] “A typical hazard event is that a human enters a defined zone where an operating machine may harm the human seriously.” See [0071] “two safety zones… a critical one and a less critical one”) based on a second input value from the input source; ([0072] “ two subsystems surveying different safety zones each.” [0077] “Safety devices 6, 7 with hazard detecting means can be any kind of sensors known to be used for this purpose, for example proximity sensors, light barrier, laser scanner or the like.”) receiving a second unvalidated control value from the control system during the second time period; ([0135] “second mode of operation F.sub.2 with less strongly reduced productivity P.sub.2, F.sub.2 and P2 as defined and explained above.”) validating the second unvalidated control value as a second safe control value based on the second safety condition; ([0088] “if the human is in the neighborhood outside this zone Z.sub.1, the robot can run at a reduced speed, so that the robot is able to stop, when the human enters zone Z.sub.1.”) and outputting the second safe control value to the system under control. ([0135] “activates the machine arrangement 5, the respective actuator” [0078] “The machine 2 includes further a first actuator system having first safety function means configured to be triggered for executing a first safety function by the safety logic 3.”) Regarding Claim 4, Dai discloses all of the limitations of parent claim 1, Dai further discloses: wherein generating the first safety condition comprises generating the first safety condition based on the first input value and a signal from the control system. ([0118] “a sample scenario is described in which the failure situation is a CRC (cyclic redundancy check) error. In the sample scenario it is assumed that the safety device D.sub.1 is connected remotely via PROFINET (with PROFIsafe protocol), temporary communication errors like CRC or Watchdog errors can occur, which in the current practice lead to emergency stop of the system. In the following, it is described how the failover concept can be applied to such scenarios.” [0119] “Actually, failover is just a temporary solution to keep the machine running until the partial failure is recovered.”) Regarding Claim 6, Dai discloses all of the limitations of parent claim 1, Dai further discloses: detecting an operating mode of the system under control; and generating the first safety condition based on the operating mode. (“[0130] In this scenario, the local sensor is D.sub.1, equivalent to the first safety device 6, which detects presence of obstacles or humans in the immediate front of the vehicle, and triggers a controlled stop. Furthermore D.sub.2, equivalent to the second safety device 7, observes the larger area and is connected via wireless communication to the local AGV control. If D.sub.2 is temporarily unavailable, the local AGV can switch to reduced speed and rely on the local sensor for an acceptable time period.”) Regarding Claim 8, Dai discloses all of the limitations of parent claim 1, Dai further discloses: detecting a set of link metrics for a communication interface; ([0118] “temporary communication errors like CRC or Watchdog errors can occur,”) and generating the first safety condition based on the set of link metrics. (see [0121] and [0122] describing failover ([0121] “the system does not have to be stopped with a single CRC error, since there is a redundant safety device”) vs. serious failure warranting an e-stop ([0122] “Multiple CRC errors within a defined time interval are interpreted as a serious failure, in which case the machine must be stopped”) Regarding Claim 9, Dai discloses all of the limitations of parent claim 1, Dai further discloses: detecting an operating mode based on a set of link metrics for a communication interface; (e.g. local operation, [0129] “In case that the wireless connection is suddenly too slow, by a disturbance or a blocking wall impairing data transfer, etc., then the AGV control system loses communication to the central station and flags a Watchdog error because the communication via wireless connection is too slow.”) and generating the first safety condition based on the operating mode. ([0129] “One could start a timer instead of stopping the AGV in case of a Watchdog error. If within, e.g. 3 seconds the communication is not back and running, the AGV is stopped. Otherwise, it uses the local safety sensors, e.g. a laser scanner, as failover devices.” Including reduced speed, see [0130]). Regarding Claim 10, Dai discloses all of the limitations of parent claim 1, Dai further discloses: transforming the first unvalidated control value into the first safe control value based on the first safety condition and a set of unsafe command values comprising the first unvalidated control value. (operating at reduced speed, see e.g. [0041] “The concept of hierarchical safety control takes into account that the severity of such a hazard can be differently so that sometime the machine can run at a safely reduced speed instead of stopping, so that the overall productivity of the machine can be enhanced.”) Regarding Claim 12, Dai discloses all of the limitations of parent claim 1, Dai further discloses: accessing an input validation window for the input source; ([0123] “A CRC error can be detected by proofing the check-sum. Therefore, the safety controller registers the communication failure and interprets it as a malfunction of the corresponding safety device, if CRC errors appear repeatedly.”) validating the first input value as a validated input value based on the input validation window; and outputting the validated input value to the control system. (nb. i.e. normal operation where there is no CRC error; see [0121] “the system does not have to be stopped with a single CRC error, since there is a redundant safety device, and can recover itself automatically by switching back to the normal safety functions, when the next telegram becomes valid”) Regarding Claim 13, Dai discloses all of the limitations of parent claim 1, Dai further discloses: accessing an input validation window for the input source; ([0123] “A CRC error can be detected by proofing the check-sum. Therefore, the safety controller registers the communication failure and interprets it as a malfunction of the corresponding safety device, if CRC errors appear repeatedly.”) transforming the first input value into a windowed input value based on the input validation window; and outputting the windowed input value to the control system. ([0121] “But in most cases, CRC errors disappear after a short time period, and a stable communication with the device is established again. In such a situation, when above described failover concept is applied, the system does not have to be stopped with a single CRC error, since there is a redundant safety device”) Regarding Claim 14, Dai discloses all of the limitations of parent claim 1, Dai further discloses: accessing an input validation window for the input source; ([0123] “A CRC error can be detected by proofing the check-sum. Therefore, the safety controller registers the communication failure and interprets it as a malfunction of the corresponding safety device, if CRC errors appear repeatedly.”) and discarding the first input value based on the input validation window. ([0122] “Multiple CRC errors within a defined time interval are interpreted as a serious failure, in which case the machine must be stopped, see also FIG. 6. The commonly applied time interval for detection of CRC error accumulation is currently 100 hours.”) Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 2 and 15-18 is/are rejected under 35 U.S.C. 102(a)(1) as anticipated by Dai or, in the alternative, under 35 U.S.C. 103 as obvious over Dai in view of Koopman et al., US Pg-Pub 2019/0056735. Regarding Claim 2, Dai discloses, alternatively Dai teaches, all of the limitations of parent claim 1, Dai further discloses or alternatively teaches: at a safety subsystem, (e.g. devices 6, 7) generating the first safety condition based on the first input value; ([0077] “Safety devices 6, 7 with hazard detecting means can be any kind of sensors known to be used for this purpose, for example proximity sensors, light barrier, laser scanner or the like.”) and wherein transforming the first unvalidated control value comprises, at a command gate, transforming the first unvalidated control value into the first safe control value based on the first safety condition. ([0088] “one can define a first critical safety zone Z.sub.1 around a machine 2 or a machine arrangement 5, an industrial robot for example, where the violation of this zone leads to stopping the robot immediately”) In the interest of compact prosecution: should applicant feel that Dai fails to sufficiently disclose “a command gate”, Koopman et al., Teaches the use of Safety [Command] Gates for receipt, validation and output of command signals in a safety subsystem (see Koopman fig. 4) Koopman is analogous art because it is from the same field of endeavor as the claimed invention and other references of automated safety systems for operational plants. One of ordinary skill in the art before the effective filing date of the application could have modified the teachings of Banning to include validating and/or transforming control inputs at a command gate in a safety subsystem as suggested by Koopman. One of ordinary skill in the art before the effective filing date of the application could have been motivated to make this modification in order to permit integration of autonomous command components with arbitrarily bad failure modes into high dependability control systems, as suggested by Koopman. ([0022] “architecture that allows autonomy components with arbitrarily bad failure modes to be integrated into a high-dependability framework. In this architecture, autonomy components are allowed to fail while “safety gate” components uphold safety requirements. While this disclosure describes the architecture in the context of an autonomous ground vehicle (AGV), the architecture is general-purpose for application in any autonomous system including, without limitation, fully autonomous ground vehicles, semi-autonomous ground vehicles, air vehicles, and other robotic systems with complete or partial autonomy.”) Regarding Claim 15, Dai discloses or alternatively teaches: A method comprising: at a safety subsystem: generating a first safety condition (e.g. “critical safety zone” “hazard event”) based on a first input value from an input source; ([0072] “ two subsystems surveying different safety zones each.” [0077] “Safety devices 6, 7 with hazard detecting means can be any kind of sensors known to be used for this purpose, for example proximity sensors, light barrier, laser scanner or the like.”) validating the first input value as a first validated input value based on an input validation window for the input source; ([0123] “A CRC error can be detected by proofing the check-sum. Therefore, the safety controller registers the communication failure and interprets it as a malfunction of the corresponding safety device, if CRC errors appear repeatedly.”) and outputting the first validated input value to a control system; (nb. i.e. normal operation where there is no CRC error; see [0121] “the system does not have to be stopped with a single CRC error, since there is a redundant safety device, and can recover itself automatically by switching back to the normal safety functions, when the next telegram becomes valid”) and at a command gate: receiving a first unvalidated control value generated by a control system based on the first validated input value; (e.g. F.Sub.N (Normal operation); see [0115] “In this case, the machine would run at 100%, if no safety zone violation is detected.”) transforming the first unvalidated control value (e.g. [0070] ‘F.sub.N is characterized by productivity P.sub.N…Productivity P.sub.N is the normal productivity.’) into a first safe control value based on the first safety condition; ([0088] “one can define a first critical safety zone Z.sub.1 around a machine 2 or a machine arrangement 5, an industrial robot for example, where the violation of this zone leads to stopping the robot immediately”) and outputting the first safe control value to a system under control. ([0135] “activates the machine arrangement 5, the respective actuator” [0078] “The machine 2 includes further a first actuator system having first safety function means configured to be triggered for executing a first safety function by the safety logic 3.”) In the interest of compact prosecution: should applicant feel that Dai fails to sufficiently disclose “a command gate”, Koopman et al., Teaches the use of Safety [Command] Gates for receipt, validation and output of command signals in a safety subsystem (see Koopman fig. 4) Koopman is analogous art because it is from the same field of endeavor as the claimed invention and other references of automated safety systems for operational plants. One of ordinary skill in the art before the effective filing date of the application could have modified the teachings of Banning to include validating and/or transforming control inputs at a command gate in a safety subsystem as suggested by Koopman. One of ordinary skill in the art before the effective filing date of the application could have been motivated to make this modification in order to permit integration of autonomous command components with arbitrarily bad failure modes into high dependability control systems, as suggested by Koopman. ([0022] “architecture that allows autonomy components with arbitrarily bad failure modes to be integrated into a high-dependability framework. In this architecture, autonomy components are allowed to fail while “safety gate” components uphold safety requirements. While this disclosure describes the architecture in the context of an autonomous ground vehicle (AGV), the architecture is general-purpose for application in any autonomous system including, without limitation, fully autonomous ground vehicles, semi-autonomous ground vehicles, air vehicles, and other robotic systems with complete or partial autonomy.”) Regarding Claim 16, Dai discloses, alternatively Dai in view of Koopman teaches, all of the limitations of parent claim 15, Dai further discloses or alternatively teaches: at the safety subsystem: generating a second safety condition (e.g. the less critical one) based on a second input value from the input source; ([0087] “A typical hazard event is that a human enters a defined zone where an operating machine may harm the human seriously.” See [0071] “two safety zones… a critical one and a less critical one”) transforming the second input value into a second windowed input value based on the input validation window; and outputting the second windowed input value to the control system; ([0121] “But in most cases, CRC errors disappear after a short time period, and a stable communication with the device is established again. In such a situation, when above described failover concept is applied, the system does not have to be stopped with a single CRC error, since there is a redundant safety device”) and at a command gate: receiving a second unvalidated control value generated by the control system based on the second windowed input value; ([0135] “second mode of operation F.sub.2 with less strongly reduced productivity P.sub.2, F.sub.2 and P2 as defined and explained above.”) transforming the second unvalidated control value into a second safe control value based on the second safety condition; ([0088] “if the human is in the neighborhood outside this zone Z.sub.1, the robot can run at a reduced speed, so that the robot is able to stop, when the human enters zone Z.sub.1.”) and outputting the second safe control value to the system under control. ([0135] “activates the machine arrangement 5, the respective actuator” [0078] “The machine 2 includes further a first actuator system having first safety function means configured to be triggered for executing a first safety function by the safety logic 3.”) Regarding Claim 17, Dai discloses, alternatively Dai in view of Koopman teaches, all of the limitations of parent claim 15, Dai further discloses or alternative teaches: at the safety subsystem: generating a second safety condition (e.g. the less critical one) based on a second input value from the input source; ([0072] “ two subsystems surveying different safety zones each.” [0077] “Safety devices 6, 7 with hazard detecting means can be any kind of sensors known to be used for this purpose, for example proximity sensors, light barrier, laser scanner or the like.”) transforming the second input value into a second windowed input value based on the input validation window; and outputting the second windowed input value to the control system; ([0121] “But in most cases, CRC errors disappear after a short time period, and a stable communication with the device is established again. In such a situation, when above described failover concept is applied, the system does not have to be stopped with a single CRC error, since there is a redundant safety device”)and at a command gate: receiving a second unvalidated control value generated by the control system based on the second windowed input value; ([0135] “second mode of operation F.sub.2 with less strongly reduced productivity P.sub.2, F.sub.2 and P2 as defined and explained above.”) validating the second unvalidated control value as a second safe control value based on the second safety condition; ([0088] “if the human is in the neighborhood outside this zone Z.sub.1, the robot can run at a reduced speed, so that the robot is able to stop, when the human enters zone Z.sub.1.”) and outputting the second safe control value to the system under control. ([0135] “activates the machine arrangement 5, the respective actuator” [0078] “The machine 2 includes further a first actuator system having first safety function means configured to be triggered for executing a first safety function by the safety logic 3.”) Regarding Claim 18, Dai discloses, alternative Dai in view of Koopman teaches, all of the limitations of parent Claim 15, Dai further discloses and or teaches: at the safety subsystem: generating a second safety condition based on a second input value from the input source; (e.g. no human detected; see [0060] “ the control logic interacting with the machine in a way to operate in normal function mode in absence of a hazard situation”) validating the second input value as a second validated input value based on the input validation window; and outputting the second validated input value to the control system; (nb. i.e. normal operation where there is no CRC error; see [0121] “the system does not have to be stopped with a single CRC error, since there is a redundant safety device, and can recover itself automatically by switching back to the normal safety functions, when the next telegram becomes valid”) and at a command gate: receiving a second unvalidated control value generated by the control system based on the second validated input value; (e.g. F.Sub.N (Normal operation); see [0115] “In this case, the machine would run at 100%, if no safety zone violation is detected.”) validating the second unvalidated control value as a second safe control value based on the second safety condition; (ibid.) and outputting the second safe control value to the system under control. (ibid.) Claim(s) 19-20 is/are rejected under 35 U.S.C. 102(a)(1) as anticipated by Banning et al., US 6,532,139 or, in the alternative, under 35 U.S.C. 103 as obvious over Banning in view of Koopman. Regarding Claim 19, Banning discloses: A method comprising: generating a safety condition based on an input value from the input source; (see fig. 3 and col. 4 line 57 “The state variables A, B, and C represent state variables such as pitch stick, signal selection and monitoring, pitch integral, etc. The SAFEBUS.RTM. architecture generally requires state variables A, B, and C to be placed into the IMM 14 for transmission to the other VMS channels via the SAFEBUS.RTM.. Because these variables are already placed on the SAFEBUS.RTM., the IOC 20 SAFEBUS.RTM. table memory is then designed to select key variables (e.g., pitch stick, signal selection and monitoring, pitch integral, etc.) for "freshness monitoring". Freshness monitoring refers to the condition wherein input data is stale (e.g., has not been updated as determined by time-tagged data).”) at a command gate, in response to receiving an unvalidated control value from a control system, validating the unvalidated control value as a safe control value based on the safety condition; (col. 5, line 1 “If the command or key variable is not updated, then the IOC 20 will disable the servo commands by issuing a discrete signal through a H-bridge cutoff 40. Conversely, if a failure occurs in the IOC 20, DSP 30, or servo loop closure, then the CPM 10 will detect either a command-position error or a lack of data freshness on the SVO position 15 feedback. In this case, the CPM 10 issues a direct discrete disable to the servo commands through the H-bridge cutoff 40.”) and outputting the safe control value to a system under control. (ibid. e.g. “issuing a discrete signal [to the servo]”) In the interest of compact prosecution: should applicant feel that Banning fails to sufficiently disclose “a command gate”, Koopman et al., Teaches the use of Safety [Command] Gates for receipt, validation and output of command signals in a safety subsystem (see Koopman fig. 4) Koopman is analogous art because it is from the same field of endeavor as the claimed invention and other references of automated safety systems for operational plants. One of ordinary skill in the art before the effective filing date of the application could have modified the teachings of Banning to include validating and/or transforming control inputs at a command gate in a safety subsystem as suggested by Koopman. One of ordinary skill in the art before the effective filing date of the application could have been motivated to make this modification in order to permit integration of autonomous command components with arbitrarily bad failure modes into high dependability control systems, as suggested by Koopman. ([0022] “architecture that allows autonomy components with arbitrarily bad failure modes to be integrated into a high-dependability framework. In this architecture, autonomy components are allowed to fail while “safety gate” components uphold safety requirements. While this disclosure describes the architecture in the context of an autonomous ground vehicle (AGV), the architecture is general-purpose for application in any autonomous system including, without limitation, fully autonomous ground vehicles, semi-autonomous ground vehicles, air vehicles, and other robotic systems with complete or partial autonomy.”) Regarding Claim 20, Banning discloses all of the limitations of parent claim 19, Banning further discloses: generating a second safety condition based on a second input value from the input source; (see fig. 3, Col. 5 line 44 “The IMM would continue to seek updates, and will determine if a cut-off was initiated 404. If the data received by the IMM is updated 402, then the variable reasonableness of the operating mechanism is determined 405.”) at the command gate, in response to receiving a second unvalidated control value from the control system, validating the second unvalidated control value as a second safe control value based on the second safety condition; (ibid. col. 5, line 47 “ If the IMM detects unreasonableness after checking the data through the control law, then an H-bridge cut-off 403 is initiated, and the IMM will again receive an update 401. Otherwise, if reasonableness is determined, a servo command is written 406 to the servo loop”) and outputting the second safe control value to the system under control. (ibid. e.g. “a servo command is written to the servo loop”). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 5, 7, and 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Dai in view of Banning. Regarding Claim 5, Dai teaches all of the limitations of parent Claim 1, Dai further teaches: generating a second safety condition for a second time period based on a second input value from the input source; receiving a second unvalidated control value from the control system during the second time period; Dai differs from the claimed invention in that: Dai does not appear to clearly articulate: discarding the second unvalidated control value based on the second safety condition; and outputting the first safe control value to a system under control. However, Banning teaches a safety system (see figs. 1-4) for servo-motors which includes discarding unvalidated commands (see fig.3 “is data updated 402”) and maintaining the last safe operating output (see col. 5 line 45 “ if the data is fresh. If the data is not fresh (updated), then a shut down would be activated through the h-bridge cutoff 403. The IMM would continue to seek updates, and will determine if a cut-off was initiated 404.”) Banning is analogous art because it is from the same field of endeavor as the claimed invention and other references of automated safety systems for operational plants. One of ordinary skill in the art before the effective filing date of the application could have modified the teachings of Dai to include discarding invalid commands and maintaining the last known safe output command, as suggested by Banning. One of ordinary skill in the art before the effective filing date of the application could have been motivated to make this modification in order to extend fault detection capability beyond monitoring execution completion or output validity, as suggested by Banning (see Col. 4 line 10 “extends the fault detection capability beyond simply monitoring the execution of a singular process execution completion or output validity.”) Regarding Claim 7, Dai teaches all of the limitations of parent claim 1, Dai differs from the claimed invention in that: Dai does not appear to clearly articulate generating a control validation window based on the first input value and an operating mode of the system under control; Nor transforming the first unvalidated control value into the first safe control value based on the first safety condition and the control validation window. However, Banning teaches a safety system (see figs. 1-4) for servo-motors which includes verifying the unvalidated control value is safe for execution (see col. 5 line 51 “if reasonableness is determined, a servo command is written 406 to the servo loop”) based on the operational mode (e.g. if the servo is operational, see col. 6 line 1) and a control law “reasonableness check” (analogous to a ‘validation window’ see col 5. Line 47 “If the data received by the IMM is updated 402, then the variable reasonableness of the operating mechanism is determined 405. If the IMM detects unreasonableness after checking the data through the control law, then an H-bridge cut-off 403 is initiated”) Banning is analogous art because it is from the same field of endeavor as the claimed invention and other references of automated safety systems for operational plants. One of ordinary skill in the art before the effective filing date of the application could have modified the teachings of Dai to include discarding invalid commands and maintaining the last known safe output command, as suggested by Banning. One of ordinary skill in the art before the effective filing date of the application could have been motivated to make this modification in order to extend fault detection capability beyond monitoring execution completion or output validity, as suggested by Banning (see Col. 4 line 10 “extends the fault detection capability beyond simply monitoring the execution of a singular process execution completion or output validity.”) Regarding Claim 11, Dai teaches all of the limitations of parent claim 1, Dai differs from the claimed invention in that: Dai does not appear to clearly articulate: further comprising generating a control validation window based on the first input value; Nor transforming the first unvalidated control value into a first safe control value based on the control validation window. However, Banning teaches a safety system (see figs. 1-4) for servo-motors which includes verifying the unvalidated control value is safe for execution (see col. 5 line 51 “if reasonableness is determined, a servo command is written 406 to the servo loop”) based on the input value (e.g. if the data is fresh or stale, see col. 5 line 42) and a control law “reasonableness check” (analogous to a ‘validation window’ see col 5. Line 47 “If the data received by the IMM is updated 402, then the variable reasonableness of the operating mechanism is determined 405. If the IMM detects unreasonableness after checking the data through the control law, then an H-bridge cut-off 403 is initiated”) Banning is analogous art because it is from the same field of endeavor as the claimed invention and other references of automated safety systems for operational plants. One of ordinary skill in the art before the effective filing date of the application could have modified the teachings of Dai to include discarding invalid commands and maintaining the last known safe output command, as suggested by Banning. One of ordinary skill in the art before the effective filing date of the application could have been motivated to make this modification in order to extend fault detection capability beyond monitoring execution completion or output validity, as suggested by Banning (see Col. 4 line 10 “extends the fault detection capability beyond simply monitoring the execution of a singular process execution completion or output validity.”) Double Patenting For Clarity of the Record, Examiner notes that the application is separately rejected under nonstatutory double patenting over each of US 12,204,309 and US 11,947,331. i.e. two independent rejections. The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1 and 3 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 of U.S. Patent No. 12,204,309. Although the claims at issue are not identical, they are not patentably distinct from each other because as illustrated in the table below, the reference patent teaches or fairly suggests the claims at issue in the present application: Instant Application 12,204,309 1. a method comprising: 1. A method comprising: generating a first safety condition for a first time period based on a first input value from an input source generating a second safety condition during a second time period based on a second input value from the input source; receiving a first unvalidated control value from the control system during the first time period; receiving a second unvalidated control value from the control system during the second time period; transforming the first unvalidated control value into a first safe control value based on the first safety condition; transforming the second unvalidated control value into a second safe control value based on the second safety condition; and outputting the first safe control value to a system under control. outputting the second safe control value to the system under control. 3. The method of claim 1 1. A method comprising: by a safety subsystem: generating a second safety condition for a second time period based on a second input value from the input source generating a first safety condition during a first time period based on a first input value from an input source; generating a second safety condition during a second time period based on a second input value from the input source; by a command gate: receiving a second unvalidated control value from the control system during the second time period; receiving a first unvalidated control value from a control system during the first time period; validating the second unvalidated control value as a second safe control value based on the second safety condition validating the first unvalidated control value as a first safe control value based on the first safety condition; and outputting the second safe control value to the system under control. outputting the first safe control value to a system under control; receiving a second unvalidated control value from the control system during the second time period; transforming the second unvalidated control value into a second safe control value based on the second safety condition; and outputting the second safe control value to the system under control. Claims 1-11 and 19-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-7 and 10 of U.S. Patent No. 11,947,331. Although the claims at issue are not identical, they are not patentably distinct from each other because as illustrated in the table below, the reference patent teaches or fairly suggests the claims at issue in the present application: Instant Application 11,947,331 1. a method comprising 1. A system comprising: generating a first safety condition for a first time period based on a first input value from an input source receive a second input value from the input source; generate a second safety condition based on the second input value; and receive a second unvalidated control value from a control system during the first time period receive a second unvalidated control value from the control system; transforming the first unvalidated control value into a first safe control value based on the first safety condition transform the second unvalidated control value into a second safe control value based on the second safety condition; and outputting the first safe control value to a system under control. output the second safe control value to the system under control. 2. The method of claim 1 1. a system comprising: wherein generating the first safety condition comprising, at a safety subsystem generating the first safety condition based on the first input value ... a safety subsystem configured to… generate a second safety condition based on the second input value. wherein transforming the first unvalidated control signal comprises, at a command gate, transforming the first unvalidated control value into the first safe control value based on the first safety condition. …a command gate configured to… transform the second unvalidated control value into a second safe control value based on the second safety condition 3. The method of claim 1, further comprising 1. A system comprising: a safety subsystem configured to: generating a second safety condition for a second time period based on a second input value from the input source during a first time period: receive a first input value from an input source; generate a first safety condition based on the first input value and output the first safety condition; and during a second time period succeeding the first time period: receive a second input value from the input source; generate a second safety condition based on the second input value; and output the second safety condition; and a command gate configured to: receiving a second unvalidated control value from the control system during the second time period; during the first time period: receive a first unvalidated control value from a control system distinct from the input source; receive the first safety condition from the safety subsystem; validating the second unvalidated control value as a second safe control value based on the second safety condition validate the first unvalidated control value as a first safe control value based on the first safety condition; and outputting the second safe control value to the system under control. output the first safe control value to a system under control; and during the second time period: receive a second unvalidated control value from the control system; receive the second safety condition from the safety subsystem; transform the second unvalidated control value into a second safe control value based on the second safety condition; and output the second safe control value to the system under control. 4. The method of claim 1, wherein the first safety condition comprises generating the first safety condition based on the first input value and a signal from the control system 2. The system of claim 1, wherein the safety subsystem is further configured to:during the first time period:receive a first watchdog signal from the control system; andgenerate the first safety condition based on the first input value and the first watchdog signal; 5. The method of claim 1, further comprising: 3. The system of claim 1: wherein the safety subsystem is further configured to, generating a second safety condition for a second time period based on a second input value from the input source during a third time period succeeding the second time period: receive a third input value from the input source; generate a third safety condition based on the third input value; receiving a second unvalidated control value from the control system during the second time period wherein the command gate is further configured to, during the third time period: receiving a third unvalidated control value from the control system discarding the second unvalidated control value based on the second safety condition discard the third unvalidated control value based on the third safety condition. outputting the first safe control value to a system under control (nb. See claim 1 final line) 6. The method of claim 1, wherein generating the first safety condition comprises 4. The system of claim 1, wherein the safety subsystem is further configured to detected an operating mode of the system under control detect a first operating mode of the system under control and generating the first safety condition based on the operating mode and generate the first safety condition based on the first input value and the first operating mode 7. The method of claim 1: Further comprising generating a control validation window based on the first input value and an operating mode of the system under control 5. the system of claim 4, … generate a first control validation window based on the first input value and the first operating mode;… wherein transforming the first unvalidated control value comprises transforming the first unvalidated control value into the first safe control value based on the first safety condition and the control validation window … validate the first unvalidated control value as the first safe control value based on the first control validation window 8. The method of claim 1, wherein generating the first safety condition comprises: 6. The system of claim 1, wherein the safety subsystem is further configured to: detecting a set of link metrics for a communication interface; …detecting a first set of link metrics for a first communication interface and generating the first safety condition based on the set of link metrics and generate the first safety condition based on the first input value and the first set of link metrics 9. The method of claim 1, wherein generating the first safety condition comprises: 7. The system of claim 6, wherein the safety subsystem is further configured to: detecting an operating mode based on a set of link metrics for a communication interface; detect a first operating mode based on the first set of link metrics and generating the first safety condition based on the operating mode. and generate the first safety condition based on the first input value and the first operating mode. 10. Wherein transforming the first unvalidated control value comprises 10. The system of claim 1, wherein transforming the first unvalidated control value into the first safe control value based on the first safety condition … the command gate is configured to transform the second unvalidated command value into the second safe control value based on the second safety condition and a set of unsafe command values comprising the first unvalidated control value (in view of Claim 9: the command gate configured to validate [a control value] as [safe] based on "a set of unsafe command values") 11. The method of claim 1, further comprising 5. the system of claim 4, wherein the safety subsystem is further configured to generating a control validation window based on the first input value …generate a second control validation window based on the second input value… wherein transforming the first unvalidated control value comprises transforming the first unvalidated control value into a first safe control value based on the control validation window …transform the second unvalidated control value into the second safe control value based on the second control validation window. 19. A method comprising: 1. a system comprising generating a safety condition based on an input value from the input source; …receive a first input value from an input source; generate a first safety condition based on the first input source; at a command gate, in response to receiving an unvalidated control value from a control system, validating the unvalidated control value as a safe control value based on the safety condition; and a command gate configured to: … receive a first unvalidated control value from a control system… validate the first unvalidated control value as a first safe control value based on the first safety condition outputting the safe control value to a system under control and output the first safe control value to a system under control; 20. The method of claim 19, further comprising generating a second safety condition based on a second input value from the input source; (obvious in view of claim 1, because this claim is merely restating a repetition of the actions taken with respect to the first input value and first unvalidated command; except as directed to a second [nominal] command) at the command gate, in response to receiving a second unvalidated control value from the control system, validating the second unvalidated control value as a second safe control value based on the second safety condition (this appears to be a mere duplication of parts, and mere duplications are not patentably distinct absent a showing of new and unexpected results; see MPEP 2144.04) and outputting the safe control value to the system under control Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Iida et al., US Pg-Pub 2009/0072631 – which teaches a robot work cell which monitors a safety signal (RFID proximity sensors) which determine the presence and identity of workers, and modifies the operational state of the machinery in the work-cell according to worker “danger avoiding capability”. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOSHUA T SANDERS whose telephone number is (571)272-5591. The examiner can normally be reached Generally Monday through Friday. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Mohammad Ali can be reached at 571-272-4105. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /J.T.S./Examiner, Art Unit 2119 /MOHAMMAD ALI/Supervisory Patent Examiner, Art Unit 2119
Read full office action

Prosecution Timeline

Dec 13, 2024
Application Filed
Sep 18, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743066
METHOD FOR CONTROLLING A BUILDING AUTOMATION SYSTEM
3y 1m to grant Granted Sep 22, 2026
Patent 12732018
IMPROVED SIGNALLING SOLUTIONS FOR ELECTRICAL INSTALLATIONS
2y 10m to grant Granted Sep 08, 2026
Patent 12700732
Direct-Drive Wind Farm Parameter Tuning Method and System Considering the Interaction between Generators
3y 4m to grant Granted Aug 04, 2026
Patent 12693643
INFORMATION PROCESSING DEVICE AND COMPUTER-READABLE STORAGE MEDIUM
3y 0m to grant Granted Jul 28, 2026
Patent 12695307
MODEL PREDICTION-BASED CONTROL METHOD FOR GRID FORMING OF MULTI-PORT AUTONOMOUS RECONFIGURABLE SOLAR PLANTS
2y 8m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
74%
Grant Probability
99%
With Interview (+36.2%)
2y 9m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 303 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month