Prosecution Insights
Last updated: August 17, 2026
Application No. 19/062,193

Method for Verifying a Correct Application of a Changeset

Non-Final OA §101§103
Filed
Feb 25, 2025
Priority
Feb 26, 2024 — EU 24159740.0
Examiner
HAILU, TESHOME
Art Unit
Tech Center
Assignee
ABB Schweiz AG
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
555 granted / 711 resolved
+18.1% vs TC avg
Strong +24% interview lift
Without
With
+23.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
14 currently pending
Career history
730
Total Applications
across all art units

Statute-Specific Performance

§101
14.5%
-25.5% vs TC avg
§103
56.3%
+16.3% vs TC avg
§102
15.1%
-24.9% vs TC avg
§112
7.7%
-32.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 711 resolved cases

Office Action

§101 §103
DETAILED ACTION This office action is in response to the original application filed on February 25, 2025. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-14 are pending. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 8-14 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claims 8-14 are directed to a tangible computer storage media having stored thereon computer executable instructions. Examiner respectfully asserts that the claimed subject matter does not fall with the statutory class listed in 35 U.S.C. 101. The specification fails to clearly define the tangible computer storage media, and therefore, it could be interpreted as a communication media which does not fall within one of the four statutory classes of 101. Appropriate correction is required. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-14 are rejected under 35 U.S.C. 103 as being unpatentable over Ziat (US Pub. No. 2015/0193224) in view of Zatko (US Pub. No. 2016/0191469). As per claim 1 Ziat discloses: A method for ensuring a correct application of a changeset that is configured for being applied to an industrial device, the method comprising: (abstract of Ziat, systems, methods, and computer-readable media for logging secure element updates of an electronic device are provided). Signing and encrypting, by a central server, the changeset; (paragraph 18 of Ziat, an electronic device (e.g., a cellular telephone) may automatically install and personalize updates to an applet and/or to an operating system on a secure element in the electronic device. In particular, when an update package (e.g., a digitally signed update package) containing such an update to a secure element applet and/or to a secure element operating system (e.g., as may be collectively referred to herein as a secure element asset) may be received from an updating device (e.g., a server), the secure element may identify any previous versions of the secure element asset installed on the secure element) and (paragraph 21 of Ziat, an update package may be signed using a private encryption key of the vendor, and the digital signature may be verified and/or the update package may be decrypted using the public encryption key of the vendor. However, in other embodiments, a symmetric encryption technique may be used. Thus, the same encryption key may be used to sign, encrypt, and/or decrypt an update package). Transmitting, by the central server, the encrypted changeset to the industrial device; (paragraph 55 of Ziat, the processor may execute a program module that may include instructions for operations in method 300. During operation, the processor may receive, from an updating device, an update package, which may have a digital signature (e.g., operation 310), where the update package may include an update to the asset installed on the secure element). Decrypting, by the industrial device, the encrypted changeset; (Paragraph 58 of Ziat, in some embodiments, the secure element may optionally decrypt the update package (e.g., operation 316) using a second encryption key, which may be associated with the vendor. This second encryption key may be the same as or different from the encryption key). Applying, by the industrial device, the changeset to the industrial device; (paragraph 60 of Ziat, the processor may install the update to the asset, and may personalize the asset using the user data (e.g., operation 320)). Logging, by the industrial device, the decrypting and the applying of the changeset as an event log; (paragraph 61 of Ziat, the processor may update one or both of counter 233 and/or log 235 based on the asset update (e.g., operation 322). In some embodiments, counter 233 may be incremented or otherwise updated when any secure element asset (e.g., applet or operating system) is updated and/or only when an applet secure element asset is updated and/or only when an operating system secure element asset is updated. If more than one asset is updated at a particular time, counter 233 may be incremented or otherwise updated once for each asset that is updated or once for all the simultaneously updated assets. Similarly, in some embodiments, a new entry may be added to log 235 and/or log 235 may be otherwise updated with any suitable information when any secure element asset (e.g., applet or operating system) is updated and/or only when an applet secure element asset is updated and/or only when an operating system secure element asset is updated). Ziat teaches the method of sending an update/change to the electronic device and logging the update to log 235 by electronic device (see paragraphs 55 and 61 of Ziat) but fails to clearly disclose: Querying, by the central server, the event log; retrieving and encrypting, by the industrial device, the event log; transmitting, by the industrial device, the encrypted event log to the central server; and verifying, by the central server, the encrypted event log. However, in the same field of endeavor, Zatko teaches this limitation as, (paragraph 182 of Zatko, the trusted computing device 130 processes the received write-file entry. That is, the trusted device 130 responds to the request for the one or event log entries received from the write file 133, such as described in blocks 505 to 515 of FIG. 5. For example, based on the received write-file entry request, the trusted computing device 130 determines from the write-file entry that the write-file entry relates to the stored event log entries. The trusted computing device 130 also identifies the one or more event log entries that are responsive to the determined write-file entry. The trusted device 130 then generates an output based on the identified event log entries that is responsive to the write-file entry. For example, the isolated environment processor 135 may generate a copy of append-only event log entries stored in the secure storage 136 as the output. And, in certain example embodiments, the trusted computing device 130 secures the output, such as by encrypting the output for the requested event-log entries, such as described in block 520 of FIG. 5. For example, the isolated environment processor 135 may encrypt the responsive event log entries to generate a secure output that can be communicated via the network 105 to a second host device 110 that can decrypt the encrypted event log entries). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Ziat and include the above limitation using the teaching of Zatko in order to create a log file and encrypt the event log entries to generate a secure output that can be communicated via the network 105 to a second host device 110 that can decrypt the encrypted event log entries (see paragraph 182 of Zatko). Claim 8 is rejected under the same reason set forth in rejection of claim 1. As per claim 2 Ziat in view of Zatko discloses: The method of claim 1, wherein the encrypted event log is stored in a Trusted Execution Environment (TEE) of the industrial device so that the encrypted event log is protected by secure hardware. (paragraph 44 of Ziat, secure subsystem 218 may also include a log 235 that may be configured to track some, any, or all updates made to secure element assets of secure element 230. Log 235 may be any suitable data structure or memory location on secure element 230 that may be updated or otherwise edited by main SE operating system 232 and/or updating SE operating system 234 during or after such a process of updating a secure element asset (e.g., an applet or main SE operating system) on secure element 230). Claim 9 is rejected under the same reason set forth in rejection of claim 2. As per claim 3 Ziat in view of Zatko discloses: The method of claim 1, wherein the changeset comprises data and/or instructions for modifying a behavior and/or a performance of an industrial device. (Paragraph 18 of Ziat, an electronic device (e.g., a cellular telephone) may automatically install and personalize updates to an applet and/or to an operating system on a secure element in the electronic device. In particular, when an update package (e.g., a digitally signed update package) containing such an update to a secure element applet and/or to a secure element operating system (e.g., as may be collectively referred to herein as a secure element asset) may be received from an updating device (e.g., a server), the secure element may identify any previous versions of the secure element asset installed on the secure element). Claim 10 is rejected under the same reason set forth in rejection of claim 3. As per claim 4 Ziat in view of Zatko discloses: The method of claim 1, wherein applying the changeset and/or the logging as the event log is verifiable by a remote attestation method. (Paragraph 42 of Ziat, continuing at least with the example of an update package for updating an applet type secure element asset, main SE operating system 232 may verify a digital signature of such an update package using an encryption key that may be associated with a vendor of secure element 230 or a vendor of the applet (e.g., a key associated with ISD 237 and/or SSD 238)). Claim 11 is rejected under the same reason set forth in rejection of claim 4. As per claim 5 Ziat in view of Zatko discloses: The method of claim 1, further comprising verifying an authenticity and/or an integrity of the industrial device. (Paragraph 103 of Ziat, an SMP broker component of device 112 may be configured to manage secure communication authentication with device 110 (e.g., secure element 230 of device 100)). Claim 12 is rejected under the same reason set forth in rejection of claim 5. As per claim 6 Ziat in view of Zatko discloses: The method of claim 1, wherein the event log comprises at least one of: a timestamp, a sequence number, a type of the industrial device, a version of the industrial device, a source of the changeset, a destination of the changeset, an action. (Paragraph 44 of Ziat, Log 235 may be any suitable data structure or memory location on secure element 230 that may be updated or otherwise edited by main SE operating system 232 and/or updating SE operating system 234 during or after such a process of updating a secure element asset (e.g., an applet or main SE operating system) on secure element 230. Such an update may include the addition of a new entry in the log 235 that may be indicative of any suitable information descriptive of a newly added applet or main SE operating system (e.g., version name, date of generation (e.g., globally or for device 110), or any other suitable information). Such information may be stored as any suitable data type in log 235, such as one or more data strings, vector matrices of octet strings, hex number(s), and the like). Claim 13 is rejected under the same reason set forth in rejection of claim 6. As per claim 7 Ziat in view of Zatko discloses: The method of claim 1, further comprising a changeset audit file, wherein the changeset audit file comprises at least one of: an event log sequence number begin, an event log sequence number end, a cryptographic algorithm, and a cryptographic value. (Paragraph 44 of Ziat, Log 235 may be any suitable data structure or memory location on secure element 230 that may be updated or otherwise edited by main SE operating system 232 and/or updating SE operating system 234 during or after such a process of updating a secure element asset (e.g., an applet or main SE operating system) on secure element 230. Such an update may include the addition of a new entry in the log 235 that may be indicative of any suitable information descriptive of a newly added applet or main SE operating system (e.g., version name, date of generation (e.g., globally or for device 110), or any other suitable information). Such information may be stored as any suitable data type in log 235, such as one or more data strings, vector matrices of octet strings, hex number(s), and the like). Claim 14 is rejected under the same reason set forth in rejection of claim 7. Conclusion The prior art made or record and not relied upon is considered pertinent to applicant’s disclosure are: Consalus’s reference (US Pub. No. 2015/0172259) discloses: A portable computing device with methodologies for client-side analytic data collection are described. In one embodiment, for example, a method performed by a portable computing device having non-volatile memory includes the steps of obtaining event information reflecting runtime behavior of an application executing on the portable computing device; cryptographically encrypting the event information; storing the encrypted event information in the non-volatile memory; decrypting the encrypted event information; and sending the decrypted event information to a server over a data network, the decrypted event information encapsulated in a cryptographically secured network data stream when sent over the data network to the server. Badam’s reference (US 9,596,235) discloses: One or more systems and/or techniques are provided for managing a partially encrypted file system, for storage hardware virtualization, and/or for storage management. In example, data may be stored in a partially encrypted file system, where sensitive data is encrypted for security and non-sensitive data is unencrypted, which may mitigate energy usage otherwise used for encrypting non-sensitive data, thus improving battery life. In an example, a storage device may be exposed to applications as a plurality of isolated storage structures where an application is provided data access to an isolated storage structure assigned to the application but not to isolated storage structures assigned to other applications, which may provide hardware level isolation with improved energy efficiency. In an example, a storage management component, configured to provide isolation and encryption, may be integrated into a computing device as an application specific integrated circuit (ASIC) or a system on a chip (SoC). Thadishetty’s reference (US 9,893,882) discloses: The disclosed apparatus may include a storage device that stores an asymmetric key pair including a public encryption key and a private encryption key assigned to a computing device. This apparatus may also include at least one processing unit communicatively coupled to the storage device. The processing unit may encrypt, via one key within the asymmetric key pair, a copy of identification information that identifies the computing device. The processing unit may then maintain the encrypted copy of the identification information and an unencrypted copy of the identification information in connection with the computing device. Next, the processing unit may detect evidence of device tampering in connection with the computing device by (1) decrypting, via another key within the asymmetric key pair, the encrypted copy of the identification information and (2) determining that the decrypted copy of the identification information differs from the unencrypted copy of the identification information. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TESHOME HAILU whose telephone number is (571)270-3159. The examiner can normally be reached M-F 8 a.m. - 5 p.m.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TESHOME HAILU/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Feb 25, 2025
Application Filed
Jul 27, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705496
METHOD AND APPARATUS FOR AUTOMATICALLY GENERATING WELDING PROCEDURE SPECIFICATION USING MACHINE LEARNING ALGORITHMS
2y 10m to grant Granted Aug 11, 2026
Patent 12705609
System, Method, and Computer Program Product for Secure Data Distribution
1y 12m to grant Granted Aug 11, 2026
Patent 12695636
PROOF OF DATA RETENTION WITH BLOCKCHAIN
1y 11m to grant Granted Jul 28, 2026
Patent 12694044
DATA PROCESSING SYSTEMS AND METHODS FOR AUTOMATICALLY DETECTING AND DOCUMENTING PRIVACY-RELATED ASPECTS OF COMPUTER SOFTWARE
1y 7m to grant Granted Jul 28, 2026
Patent 12688294
VIRTUAL TRUSTED PLATFORM MODULE IMPLEMENTATION METHOD AND RELATED APPARATUS
3y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+23.5%)
3y 3m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 711 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month