Prosecution Insights
Last updated: October 02, 2026
Application No. 19/075,851

INTRUSION DETECTION IN COMPUTING DEVICES ONBOARD AN AIRCRAFT

Non-Final OA §101§103§112
Filed
Mar 11, 2025
Priority
Dec 04, 2024 — IN 202411095758
Examiner
WYSZYNSKI, AUBREY H
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Honeywell International Inc.
OA Round
1 (Non-Final)
90%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
649 granted / 725 resolved
+31.5% vs TC avg
Moderate +12% lift
Without
With
+12.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
14 currently pending
Career history
747
Total Applications
across all art units

Statute-Specific Performance

§101
13.8%
-26.2% vs TC avg
§103
37.3%
-2.7% vs TC avg
§102
22.9%
-17.1% vs TC avg
§112
8.4%
-31.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 725 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-20 are presented for examination. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-5, 8-13, 16-18 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Overview of 101 Framework: Step 1: Is the claim directed to a statutory category (process, machine, manufacture, or composition of matter)? Step 2A, Prong 1: Is the claim directed to a judicial exception (e.g., an abstract idea, law of nature, or natural phenomenon)? Step 2A, Prong 2: If the claim is directed to a judicial exception, does the claim recite additional elements that integrate the exception into a practical application? Step 2B: If the claim does not integrate the exception into a practical application, does it add "significantly more" (an inventive concept) to the judicial exception? Claims 1, 8, 16: Claim 1 is a method, Claim 8 is an Intruder Detection System (machine), and Claim 16 is a non-transitory computer-readable medium (manufacture). Because they share the same fundamental limitations, they are evaluated together. Step 1: Statutory Categories Yes. Claim 1 is a process. Claim 8 is a machine/system. Claim 16 is an article of manufacture. All independent claims satisfy Step 1. Step 2A, Prong 1: Directed to a Judicial Exception Yes. The independent claims are directed to the abstract idea of collecting data, analyzing that data using an algorithm (an "intruder detection machine learning model"), recognizing a pattern (identifying an "anomalous data pattern"), and outputting a result ("generating a notification"). Under USPTO guidance, machine learning models and pattern recognition inherently rely on mathematical concepts and mental processes. Therefore, the claims recite a judicial exception. Step 2A, Prong 2: Integrated into a Practical Application No. In order to pass Prong 2, the claims must recite elements that apply the abstract idea to a specific technological improvement or otherwise integrate it into a practical application. The claims limit the operating environment to "onboard an aircraft," but applying an abstract idea to a specific technological environment does not integrate it into a practical application. Furthermore, the claims simply end with "generating a notification indicative of a potential security breach." Generating notifications or outputting data as mere insignificant extra-solution activity. The independent claims do not recite an active mitigation step or a specific improvement to how the computer or aircraft functions; they merely use generic computing components to execute the abstract idea. Step 2B: Significantly More No. The additional elements recited (e.g., "computing device," "source device," "training engine") are invoked at a high level of generality and represent well-understood, routine, and conventional computer hardware and data gathering techniques. There is no inventive concept provided beyond the abstract idea itself. Conclusion: Claims 1, 8, and 16 are unpatentable under § 101, as currently drafted. Claims 2-5, 7, 9-13, 15, 17-18, 20 These dependent claims add specific details to the data gathering steps, the computing environment, or the mathematical model used. They do not overcome the § 101 deficiencies of their parent independent claims. Claims 2, 9, 10, 11, 17: These claims add details regarding the training dataset (using "synthetic data," "probable anomalous data patterns," and specific ML models like VAE or GAN). Adding more specific mathematical algorithms or data gathering parameters to an abstract idea does not integrate it into a practical application or provide significantly more. They remain directed to mathematical concepts/mental processes. Claims 3, 4, 12, 13, 18: These claims narrow the generic "computing device" to an Electronic Flight Bag (EFB), Flight Management System (FMS), or Access Point (AP). Restricting the abstract idea to a specific conventional piece of aviation hardware is merely limiting the use of the abstract idea to a particular technological environment. Claim 5: Adds details about the specific historical data traffic metrics evaluated (volume, type, destination, etc.). This is pure data gathering. Claims 6, 14, 19 These dependent claims introduce physical, active steps that alter the operation of the aircraft's computer systems, distinguishing them from the mere data analysis and notification steps of the independent claims. Claim 6 (Method), Claim 14 (System), Claim 19 (CRM): These claims add the steps of obtaining flight operation data, comparing it to previous data to determine tampering, and replacing the previous flight operation data with the flight operation data. Step 2A, Prong 2: Integrated into a Practical Application Yes. Unlike the independent claims that stop at merely notifying the user of an anomaly, Claims 6, 14, and 19 require taking a specific, active corrective action: replacing tampered flight optimization data. A claim that effects a specific technological improvement to the functioning of a computer or network is deemed integrated into a practical application. By actively replacing corrupted flight data within the aircraft's critical computing systems, these claims improve the security and operational functioning of the aircraft's systems, moving the claim out of the realm of pure abstract data analysis. Claims 7, 15, 20: These limit the calculation of a "predetermined time period" based on communication session duration. This is an algorithmic calculation that does not provide an inventive concept. However, based on their dependency to claims 6, 15 and 20, which are deemed eligible, these claims are inherently eligible. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 6, 8 and 16 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 6 recites the limitation "comparing the flight operation data with pervious flight operation optimization data…to determine that the previous flight operation data is tampered.” The word “optimization” appears abruptly. It is unclear if “previous flight operation optimization data” is a separate dataset from “previous flight operation data.” This renders the claim indefinite. Claim 8: The claim recites monitoring data traffic originating from "at least one source device." However, the subsequent identification step refers to identifying an anomalous source device from "the at least one source." Dropping the word "device" creates an ambiguity regarding whether the claim is referring back to the original hardware device. Claim 16: The preamble and initial steps refer repeatedly to "anomalous data patterns." However, the model training and analysis steps suddenly shift to identifying an "anomalous data usage pattern." The addition of the word "usage" obscures the scope of the claim and breaks the consistency of the terminology. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-2, 8-11 and 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over US 2017/0094527 to Shatti et al., and further in view of US 2020/0285997 to Bhattacharyya et al. Regarding claims 1, 8 and 16: Shatti teaches a method (Paragraph 0008 and abstract: threat detection, intrusion detection and mitigation associated with aerial vehicles) comprising: monitoring data traffic associated with a computing device onboard an aircraft, wherein the data traffic originates from at least one source device coupled to the computing device (0027, 0029 and 0042: monitoring wireless network data traffic and radio protocols associated with an aircraft, where the data originates from a source device). Shatti teaches extracting features from signals to detect anomalous instructions but lacks or does not expressly disclose machine learning anomaly detection. However, Bhattacharyya teaches analyzing the data traffic using an intruder detection machine learning model to identify an anomalous data pattern (analyzing captured data streams using machine learning anomaly detection model to identify anomalous data patterns and distinguish abnormal states, 0003 and 0085). the intruder detection machine learning model being trained using a training dataset comprising historical data traffic metrics and anomalous data patterns associated with the historical data traffic metrics (training the machine learning classification/anomaly detection model using historical training data representing normal metrics and previously identified anomalous data patterns, 0086). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Shatti with Bhattacharyya to include machine learning anomaly detection in order to improve the accuracy of the intrusion detection and automate the recognition of complex, evolving cyber threats. Shatti, as modified above further discloses identifying an anomalous source device from the at least one source device corresponding to the anomalous data pattern (identifying the specific source device/transmitter originating the rogue or anomalous signals based on identifying features, 0012 and 0088); and generating a notification indicative of a potential security breach associated with the anomalous source device (generating threat detection alerts and initiating countermeasures upon detecting an intrusion, 0102 and Fig. 5). Regarding claims 2 and 9, Shatti lacks or does not expressly disclose synthetic training dataset. However, Bhattacharyya teaches the training dataset further comprises synthetic data traffic metrics and probable anomalous data patterns associated with the synthetic data traffic metrics, the synthetic data traffic metrics and the probable anomalous data patterns being generated using the historical data traffic metrics and the anomalous data patterns (utilizing mathematical models to establish bounds of normal operations and simulating abnormal conditions). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Shatti with Bhattacharyya to synthetic training data in order to improve the accuracy of the intrusion detection and automate the recognition of complex, evolving cyber threats. Regarding claims 10 , 11 and 17, Shatti lacks or does not expressly disclose synthetic training dataset. However, Bhattacharyya teaches wherein to generate the synthetic data traffic metrics and probable anomalous data patterns, the instructions cause the processing resource to process the historical data traffic metrics and anomalous data patterns using a generative machine learning model, and the generative machine learning model being one of Variational Autoencoder (VAE) and Generative Adversarial Network (GAN) (machine learning, reciting specific generative models line GANs or VAEs to create synthetic training data represents the application of off the self algorithmic tools. The USPTO routinely holds that substituting one known ML algorithm (e.g. standard classification) for another known algorithm (e.g. GANs) to achieve a predictable result (generic training data) is obvious) . Claims 3, 4-7, 12-15, 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over US 2017/0094527 to Shatti et al., and further in view of US 2020/0285997 to Bhattacharyya et al and further in view of US 10,502,572 to Surmi. Regarding claims 3, 4, 12, 13, 18, Shatti, as modified above, lacks or does not expressly disclose EFB or FMS, or an access point. However, Surmi teaches further teaches wherein the computing device is one of an Electronic Flight Bag (EFB) and Flight Management System (FMS) (cybersecurity architectures specifically designed to protect embedded aircraft mission computers (equivalent to FMS) and “cyber kneeboards” (the military equivalent of a tablet EFB) from network intrusions, abstract and Fig 11. ); wherein the computing device is an Access Point (AP), and the at least one source device is at least one user device connected to the AP (Multilayered obstructed brokered MOB hub that acts as a secure wireless routing AP interfacing with mobile tables (user devices), 0035 and Fig. 14). It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Shatti, as modified above, to apply the intrusion detection of Shatti with the specific aviation hardware nodes taught by Surmi. Regarding claim 5, Shatti, as modified above, further teaches the method of claim 4, wherein the historical data traffic metrics comprises information associated with volume of data, type of data, an intended destination of data, frequency of transmissions of data, port access requests, login attempts to different communication channels of the computing device, or a combination thereof (0106: The IP header can be used, such as via fingerprinting, which exploits peculiarities of IP, TCP, UDP, and ICMP to determine the operating system. Regarding claim 6, 14 and 19, Shatti, as modified above, further teaches the method of claim 5, wherein the method further comprises: obtaining flight operation data for a predetermined time period prior to identification of the anomalous data pattern, the flight operation data is usable for managing flight operations of the aircraft; comparing the flight operation data with previous flight operation optimization data obtained during the predetermined time period to determine that the previous flight operation data is tampered; and replacing the previous flight operation data with the flight operation data (0012: protocol manipulation countermeasures, including intercepting signals and modifying or correcting system states to maintain appropriate operational conditions. Furthermore, maintaining a last known good configuration and rolling back corrupted database entries is ubiquitous, conventional data-integrity practice in computer science).. Regarding claim 7, 15 and 20, Shatti, as modified above, further teaches the method of claim 6, wherein the predetermined time period is determined based on a duration of communication session between the anomalous source device and the AP (0123: One application-layer vulnerability exploit manipulates a feature of the session control protocol to deny service to non-malicious users. A protocol manipulation attack can comprise an attacker sending a legitimate request that deviates from the intended purpose of the protocol in a way to overburden the device. These types of attacks include registration hijacking, call hijacking, and media modification. Message flooding attacks send a large number of packets to the targeted device in order to overwhelm the processing capacity of that device. In this case, the device is too busy to process legitimate packets. 0095: A host checks to see if the medium is being used and waits for a period of time to re-check. Often, this period is increased each successive time the medium is busy, so this feature can be exploited by an attacker to impede communications. If a collision is detected, it notifies all hosts on the shared medium that a collision has occurred.). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to AUBREY H WYSZYNSKI whose telephone number is (571)272-8155. The examiner can normally be reached M-F 9-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AUBREY H WYSZYNSKI/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Mar 11, 2025
Application Filed
Jul 01, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750406
REVERSE PATH FEEDBACK PROTOCOL FOR UNIDIRECTIONAL NETWORKS
3y 6m to grant Granted Sep 29, 2026
Patent 12744686
NETWORK RESOURCES LOG VALIDATION METHODS AND PRUNING MECHANISMS USING BLOCKCHAIN
2y 2m to grant Granted Sep 22, 2026
Patent 12712883
Managing Edge Application Permissions
3y 0m to grant Granted Aug 18, 2026
Patent 12705352
SCANNING FOR MALWARE BASED ON PROCESS IDENTIFICATION
3y 9m to grant Granted Aug 11, 2026
Patent 12705336
VALIDATING A USER SESSION
1y 8m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+12.5%)
2y 7m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 725 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month