Prosecution Insights
Last updated: August 17, 2026
Application No. 19/017,820

SECURE KEY REPLACEMENT SYSTEM, SECURE KEY REPLACEMENT DEVICE AND SECURE KEY REPLACEMENT METHOD

Non-Final OA §103
Filed
Jan 13, 2025
Priority
Jan 23, 2024 — IL 310499
Examiner
ZHU, ZHIMEI
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Winbond Electronics Corp.
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
228 granted / 294 resolved
+19.6% vs TC avg
Strong +37% interview lift
Without
With
+37.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
8 currently pending
Career history
304
Total Applications
across all art units

Statute-Specific Performance

§101
10.4%
-29.6% vs TC avg
§103
49.6%
+9.6% vs TC avg
§102
10.1%
-29.9% vs TC avg
§112
19.0%
-21.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 294 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 9, 10, 19 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Chen (CN 110995427 A) above, and further in view of Shigeeda (US 2005/0055552). Regarding claims 9 and 19, Chen teaches A secure key replacement device (Machine Translation, page 40, [0062] and Fig. 1: “The execution station device 104 receives the public key update message sent by the master station device 102, uses the public key before the update to sign and verify the public key update message, and when the signature verification is successful, replaces the public key before the update with the updated public key”. The Examiner interprets the execution station device 104 as A secure key replacement device.), comprising: a secure storage configured to securely store (Machine Translation, pages 87-89, [0 127] and Fig. 8: “The computer device includes a processor, memory, network interface, and database connected via a system bus…. The database of this computer device is used to store control system key data.”) a first public key forming a key pair with a first private key stored by an active signing server (Machine Translation, page 42, [0064] and Fig. 1: “when the master station device 102 and the execution station device 104 establish a communication connection for the first time, the master station device 102 performs key initialization, generates an initialized private key and a corresponding public key based on an asymmetric encryption algorithm, stores the initialized private key, and sends the corresponding public key to the execution station device 104.” And see Machine Translation, page 68, [0099] and Fig. 5: “In step S506, the master station device uses the private key before the update to sign the updated public key and generates a public key update message.” And see Machine Translation, page 69, [0101] and Fig. 5: In step S510, the execution station device receives the public key update message sent by the master station device.” And see Machine Translation, page 70, [0102] and Fig. 5: “In step S512, the execution station device uses the public key before the update to … verify the public key update message.” The Examiner interprets the master station device 102 as an active signing server. The Examiner further interprets “the corresponding public key” in [0064] as a first public key forming a key pair with a first private key stored by an active signing server.); and a secure processor configured to (Machine Translation, pages 87-89, [0127] and Fig. 8: “The computer device includes a processor, memory, network interface, and database connected via a system bus…. The processor in this computer device provides computing and control capabilities.”): reject an instruction to replace the first public key, the instruction not being authorized by a signature formed by the active signing server using the first private key (Machine Translation, page 52, [0077] and Fig. 3: “Step S208: Send the public key update message to the execution station device; the execution station device uses the public key before the update to sign and verify the public key update message”. And see Machine Translation, page 55, [0080] and Fig. 3: “Step S210: Receive the public key request message sent by the execution station device when the signature verification fails.” And see Machine Translation, pages 55-56, [0081] and Fig. 3: “Among them, the public key request message is used to obtain the updated public key from the master station device. Specifically, when the signature verification of the public key update message by the execution station device fails, the master station device receives the public key request message sent by the execution station device.” And see Machine Translation, page 56, [0082] and Fig. 3: “Step S212: Regenerate the public key update message and send it to the execution station device.” Also see Machine Translation, pages 62-63, [0091]: “Specifically, when the signature verification fails, the execution station device resends the public key request message to the master station device. After receiving the public key request message, the master station device resends the public key update message to the execution station device.” Because the execution station device resends the public key request message to the master station device when the signature verification fails (the instruction not being authorized by a signature formed by the active signing server using the first private key), Chen discloses reject an instruction to replace the first public key, the instruction not being authorized by a signature formed by the active signing server using the first private key); receive a replacement command signed by the first private key, the replacement command being configured to be used to instruct the device to replace the first public key with a second public key forming a key pair with a second private key (Machine Translation, page 51, [0075] and Fig. 3: “Step S206: Sign the updated public key using the private key before the update to generate a public key update message.” And see Machine Translation, page 51, [0076]: “The public key update message is used to notify the execution station device that the public key has been updated and to send the updated public key to the execution station device, including the updated public key and the private key signature of the master station device.” And see Machine Translation, page 52, [0077] and Fig. 3: “Step S208: Send the public key update message to the execution station device”.); authenticate the replacement command using the first public key; and replace the first public key with the second public key responsibly to authenticating the replacement command using the first public key (Machine Translation, pages 52-53, [0077] and Fig. 3: “Step S208: Send the public key update message to the execution station device; the execution station device uses the public key before the update to … verify the public key update message, and when the signature verification is successful, replace the public key before the update with the updated public key”). Chen differs from claim 9 in that it fails to teach that the second private key is stored by a new active signing server. However, Shigeeda teaches the following: The authentication server 1 1-7 serves as the primary authentication server. When a failure occurs, the authentication server 1 1-7 is automatically switched to the authentication server 2 1-8 serving as a backup authentication server so that it can continue processing such as authentication. ([0047] and Fig. 1). Shigeeda further discloses a second private key stored by a new active signing server (see [0051] and Fig. 2: “In step S2-2, a key pair of the primary authentication server itself is generated. In the assurance system according to the present invention, the authentication server 1 1-7 needs to generate a set (pair) of a public key and a private key based on public key cryptography. These encryption keys are used to prevent imposing or protect the security of communication between the authentication server 1 1-7 and the client PC 1-1 or 1-3 or the network device 1-5.” And see [0062] and Fig. 3: “In step S3-2, a key pair of the secondary authentication server 2 1-8 is generated. Details of key pair generation are the same as in those described in step S2-2 for key pair generation of the authentication server 1 1-7. These encryption keys are used to prevent imposing or protect the security of communication between the authentication server 2 1-8 and the client PC 1-1 or 1-3 or the network device 1-5. Of the key pair of the secondary authentication server 2 1-8, the public key is made open to the client PCs 1-1 and 1-3 and the network device 1-5.” The Examiner interprets the secondary authentication server 2 1-8 as a new active signing server. The Examiner further interprets the private key stored by the secondary authentication server 2 1-8 as a second private key stored by a new active signing server). Both Chen and Shigeeda teach a second private key used to prevent imposing or protect the security of communications. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to substitute the active signing server of Chen with the new active signing server of Shigeeda as the server storing the second private key. It would have been obvious because doing so achieves the predictably result of securing and authenticating communications using digital signatures created by the second private key. Regarding claims 10 and 20, Chen further teaches wherein the secure processor is configured to: authenticate using the first public key signatures signed by the active signing server (Machine Translation, pages 52-53, [0077] and Fig. 3: “Step S208: Send the public key update message to the execution station device; the execution station device uses the public key before the update to … verify the public key update message, and when the signature verification is successful, replace the public key before the update with the updated public key”); and after the first public key is replaced with the second public key (Machine Translation, pages 52-53, [0077] and Fig. 3: “Step S208: Send the public key update message to the execution station device; the execution station device uses the public key before the update to … verify the public key update message, and when the signature verification is successful, replace the public key before the update with the updated public key”), authenticate using the second public key signatures signed by the (Machine Translation, page 3, [0004]: “With the development of key security technology, in control systems, when the master station device sends command information to the execution station device, it uses a private key generated based on an asymmetric encryption algorithm to encrypt and sign the sent command information. After receiving the command information, the execution station device uses the public key sent by the master station device to decrypt the command information”). Chen differs from claim 10 in that it teaches the active signing server instead of the new active signing server signing the second public key signatures. However, Shigeeda discloses authenticat[ing] using the second public key signatures signed by the new active signing server (see [0047] and Fig. 1: “The authentication server 1 1-7 serves as the primary authentication server. When a failure occurs, the authentication server 1 1-7 is automatically switched to the authentication server 2 1-8 serving as a backup authentication server so that it can continue processing such as authentication.” And see [0051] and Fig. 2: “In step S2-2, a key pair of the primary authentication server itself is generated. In the assurance system according to the present invention, the authentication server 1 1-7 needs to generate a set (pair) of a public key and a private key based on public key cryptography. These encryption keys are used to prevent imposing or protect the security of communication between the authentication server 1 1-7 and the client PC 1-1 or 1-3 or the network device 1-5.” And see [0062] and Fig. 3: “In step S3-2, a key pair of the secondary authentication server 2 1-8 is generated. Details of key pair generation are the same as in those described in step S2-2 for key pair generation of the authentication server 1 1-7. These encryption keys are used to prevent imposing or protect the security of communication between the authentication server 2 1-8 and the client PC 1-1 or 1-3 or the network device 1-5. Of the key pair of the secondary authentication server 2 1-8, the public key is made open to the client PCs 1-1 and 1-3 and the network device 1-5.” The Examiner interprets the secondary authentication server 2 1-8 as the new active signing server). Both Chen and Shigeeda teach a second private key used to prevent imposing or protect the security of communications. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to substitute the active signing server of Chen with the new active signing server of Shigeeda as the server signing the second public key signatures. It would have been obvious because doing so achieves the predictably result of securing and authenticating communications using digital signatures created by the second private key. Allowable Subject Matter Claims 1-8 and 11-18 are allowed. The following is an Examiner’s Statement of Reasons for Allowance: Regarding independent claims 1 and 11, although the prior art of record (such as Chen (CN 110995427 A)) teaches A secure key replacement system, comprising an active signing server including: a secure storage and processing unit configured to: store a first private key [Machine Translation, [0062] and Fig. 1: “the master station device 102 is the master station device of the control system, which holds the private key and is responsible for key management, such as …key update”]; generate signatures using the first private key for authentication by devices storing a first public key forming a key pair with the first private key [Machine Translation, [0064]: “when the master station device 102 and the execution station device 104 establish a communication connection for the first time, the master station device 102 performs key initialization, generates an initialized private key and a corresponding public key based on an asymmetric encryption algorithm, stores the initialized private key, and sends the corresponding public key to the execution station device 104.” And see Machine Translation, page 52, [0076] and Fig. 2: “based on an asymmetric encryption algorithm, the master station device uses the private key that was valid before the update to sign the public key to be released, i.e., the updated public key, and generates a public key update message.” And see Machine Translation, page 52, [0077] and Fig. 3: “Step S208: Send the public key update message to the execution station device; the execution station device uses the public key before the update to … verify the public key update message”]; and sign a replacement command using the first private key, the replacement command being configured to be used to instruct the devices to replace the first public key with a second public key forming a key pair with a second private key [Machine Translation, page 44, [0067] and Fig. 2: “Step S202: After the key update condition is met, an updated key is generated according to the asymmetric encryption algorithm; the updated key includes a private key and a public key.” And see Machine Translation, page 51, [0075] and Fig. 3: “Step S206: Sign the updated public key using the private key before the update to generate a public key update message.” And see Machine Translation, page 51, [0076]: “The public key update message is used to notify the execution station device that the public key has been updated and to send the updated public key to the execution station device, including the updated public key and the private key signature of the master station device.”]; and an interface configured to provide the signatures to the devices [Machine Translation, page 79, [0114] and Fig. 6: “The message sending module 606 is used to send the public key update message to the execution station device; the execution station device uses the public key before the update to … verify the public key update message”. And see Machine Translation, page 52, [0076] and Fig. 2: “based on an asymmetric encryption algorithm, the master station device uses the private key that was valid before the update to sign the public key to be released, i.e., the updated public key, and generates a public key update message.”]; none of the prior art of record alone or in combination teaches an interface configured to provide … the replacement command to at least one entity, which is remote to the active signing server and the devices to store the replacement command, the at least one entity including an orchestration server and/or at least one other signing server, a recited limitation of claims 1 and 11. The closest prior art made of record are: • Chen (CN 110995427 A) teaches a method comprising the following steps: after a key updating condition is met, generating an updated key according to an asymmetric encryption algorithm; wherein the updated secret key comprises a private key and a public key; storing the updated private key; signing the updated public key by using the private key before updating to generate a public key updating message; sending the public key update message to an execution station device; and the execution station device performs signature verification on the public key update message by using the public key before update, replaces the public key before update with the public key after update when the signature verification is passed, and sends a confirmation message to the master station device (Abstract). • Shigeeda (US 2005/0055552) discloses the following: In a client PC or device, the reliability of multiplexed authentication servers is assured. In an assurance system including a client PC (1-1, 1-3), an authentication server 1 (1-7), and a device (1-5) connected to a network, a multiplexed system is built by arranging an authentication server 2 (1-8) in order to back up the authentication server 1 (1-7), public key cryptography is used for encrypted communication between the client PC, the authentication servers 1 and 2, and the device, and the public keys of the authentication servers 1 and 2 are electronically signed by using the private key of one system administrator (1-10) by public key cryptography (Abstract). • Yasaki (US 2020/0178080) teaches the following: A key generation apparatus includes a memory, a communication interface, and a processor. The memory stores a first private key corresponding to a first public key. The communication interface communicates with a peer apparatus that stores the first public key. The processor generates a second public key and a second private key in response to a key update request from the peer apparatus, generates a digital signature by encrypting data including the second public key with the first private key, and sends a message including the data and the digital signature to the peer apparatus. In addition, the processor switches the first private key to the second private key (Abstract). Any comments considered necessary by applicant must be submitted no later than the payment of the issue fee and, to avoid processing delays, should preferably accompany the issue fee. Such submissions should be clearly labeled “Comments on Statement of Reasons for Allowance.” Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZHIMEI ZHU whose telephone number is (571)270-7990. The examiner can normally be reached 10am-6pm Monday-Friday. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ZHIMEI ZHU/Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Jan 13, 2025
Application Filed
Jul 15, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12693994
METHOD FOR REDUCING FALSE-POSITIVES FOR IDENTIFICATION OF DIGITAL CONTENT
2y 10m to grant Granted Jul 28, 2026
Patent 12677150
STATEFUL MULTI-PRIVILEGED SD-WAN CONTROL CONNECTIONS
2y 8m to grant Granted Jul 07, 2026
Patent 12671674
DYNAMIC BYPASS
1y 10m to grant Granted Jun 30, 2026
Patent 12657330
ACCESS CONTROL OF MANAGED CLUSTERS PERFORMING DATA PROCESSING ON CLOUD PLATFORMS
2y 3m to grant Granted Jun 16, 2026
Patent 12647783
METHOD AND SYSTEM FOR AUTOMATED SECURE DEVICE REGISTRATION AND PROVISIONING OVER CELLULAR OR WIRELESS NETWORK
3y 8m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+37.2%)
2y 8m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 294 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month