Prosecution Insights
Last updated: October 02, 2026
Application No. 19/096,903

SECURE ELEMENT AND OPERATING METHOD

Non-Final OA §102§103§112
Filed
Apr 01, 2025
Priority
Apr 19, 2024 — EU 24171382.5
Examiner
LEWIS, LISA C
Art Unit
Tech Center
Assignee
NXP Semiconductors N.V.
OA Round
1 (Non-Final)
81%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
551 granted / 682 resolved
+20.8% vs TC avg
Strong +16% interview lift
Without
With
+15.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
9 currently pending
Career history
694
Total Applications
across all art units

Statute-Specific Performance

§101
13.1%
-26.9% vs TC avg
§103
42.5%
+2.5% vs TC avg
§102
8.4%
-31.6% vs TC avg
§112
23.8%
-16.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 682 resolved cases

Office Action

§102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitations use a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are: sensing unit, processing unit, power management unit, radio frequency communication unit, storage unit in claims 15-32. Because these claim limitations are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, they are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. The limitation “processing unit” is described in [0045] as “a data processing circuit that may be a microprocessor, a co-processor, a microcontroller, a microcomputer, a central processing unit, a field programmable gate array (FPGA), a programmable logic circuit, and/or any circuit that manipulates signals (analog or digital) based on operational instructions that are stored in a memory”. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim limitations “sensing unit”, “power management unit”, “radio frequency communication unit”, and “storage unit” invoke 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. The specification does not provide any structure for these units. Therefore, the claims are indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. Applicant may: (a) Amend the claims so that the claim limitations will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. If applicant does not intend to have these limitations interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitations to avoid them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitations recite sufficient structure to perform the claimed function so as to avoid them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 15, 17, 19-25, 27, 29, and 31 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Guilley et al. (US 2021/0004461). Regarding claims 15, 27, and 29, Guilley teaches a secure element (a device (i.e., a secure element) for protecting an integrated circuit from perturbation attacks, the device comprising a sensing unit configured to detect a perturbation attack – see [0018]) (and corresponding method and vehicle access system) comprising: A sensing unit configured to sense one or more signal characteristics (the sensing unit may comprise additional heterogeneous sensors configured to generate data by monitoring different physical parameters and/or different software activities performed by the integrated circuit - see [0040] – [0041] wherein the signal characteristics comprise characteristics of signals transmitted to and from components of a vehicle access system (the sensing unit may comprise additional heterogeneous sensors configured to generate data by monitoring different physical parameters and/or different software activities performed by the integrated circuit…comprising…physical sensors configured to measure temperature or pressure or voltage or frequency or light or current in substrate or movement – see [0040] – [0041]. The protection method and device according to the embodiments of the invention may be used in a wide range of communication and data processing applications such as in the car industry application to ensure anti-theft protection, in…electronic keys – see [0026]. The physical parameters monitored on the system bus comprising the device and the integrated circuit correspond to “signals transmitted to and from components of a vehicle access system”. The integrated circuit of the system bus of an application in the car industry corresponds to the “components of a vehicle access system”). A processing unit configured to conclude, in dependence on an output of the sensing unit, that one or more attacks are carried out on the vehicle access system (device may further comprise an analysis unit, the analysis unit being configured to receive at least one binary vector provided by the sensing unit, the analysis unit being configured to detect a perturbation attack from the at least one binary vector – see [0018]). Regarding claims 17 and 31, Guilley teaches that the signal characteristics comprise characteristics of supply signals transmitted to the components and/or characteristics of data signals transmitted to and from the components (see [0041], [0137], and [0140] (measured voltage = supply signals, and data signals = measurement data). Regarding claim 19, Guilley teaches that the attacks include fault injection attacks (see [0144] and [0227]). Regarding claim 20, Guilley teaches that the processing unit is configured to conclude that attacks are carried out based on a machine learning model (see [0038] – [0039]). Regarding claim 21, Guilley teaches that the sensing unit is configured to be coupled to the components through a dedicated signal sensing network or through a communication network between the secure elements and the components (In some embodiments, the sensing unit may comprise at least one pair of sensors – see [0030]. The pair of sensors = dedicated signal sensing network. Also, the sensors are implicitly “configured to be coupled” to the respective monitored components in order to sense something). Regarding claim 22, Guilley teaches that the processing unit is further configured to perform one or more preventive actions if the processing unit concludes that at least one of the attacks is carried out (see [0203]). Regarding claim 23, Guilley teaches that the preventive actions include deactivating a host microcontroller included in the vehicle access system and/or warning a main microcontroller included in the vehicle access system (see [0203]). Regarding claim 24, Guilley teaches that the processing unit is configured to perform the preventive actions during an authentication process which is carried out between the secure element and the host microcontroller (see [0069] and [0203]). Regarding claim 25, Guilley teaches further comprising a storage unit configured to store attack-monitoring data, wherein the processing unit is configured to update the attack-monitoring data if the processing unit concludes that at least one of the attacks is carried out (see [0120] – [0125]). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim 26 is rejected under 35 U.S.C. 103 as being unpatentable over Guilley et al. (US 2021/0004461) in view of Yorke et al. (US 2018/0015905). The teachings of Guilley are relied upon for the reasons set forth above. Regarding claim 26, Guilley does not teach that the attack monitoring data includes an attack counter. Yorke teaches In this embodiment, the vehicle security device 31 additionally monitors RF communication for attempts to compromise existing OEM vehicle security systems. The vehicle security device 31 monitors RF communication to determine if a brute force method is being used in an attempt to access the vehicle. If the vehicle security device 31 monitors a predetermined number of access requests followed by incorrect responses to the challenge seed that the vehicle ECU sent, the vehicle security device 31 determines that a brute force method is being used in an attempt to compromise the existing OEM vehicle security systems – see [0078] It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guilley by including an attack counter in order to train the ML algorithm, based upon the beneficial teachings provided by Yorkey. These modifications would result in better accuracy to the ML system. Claims 16, 28, and 30 is rejected under 35 U.S.C. 103 as being unpatentable over Guilley et al. (US 2021/0004461) in view of Kondeva (“Target Applications for Secure Elements in Future Cars”) and Kneib et al. (US 2018/0337938). The teachings of Guilley are relied upon for the reasons set forth above. Regarding claims 16, 28, and 30, Guilley does not explicitly teach a tamper resistant IC, although tamper resistant security modules/HSMs in vehicles was well known. Further, Kondeva teaches using tamper resistant IC’s – see slide 5. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guilley by using a tamper resistant IC in order to improve the robustness of security relevant circuitry against physical attacks based upon the beneficial teachings provided by Kondeva. These modifications would result in increased security to the system. Further, regarding claims 16, 28, and 30, Guilley teaches monitoring different physical parameters and software activities (see [0040] and [0041]. Guilley also teaches monitoring activities of a processor, peripheral, congestion on a system bus, hardware performance counters, watchdogs, timers, and a software stack - see [0114] – [0117]. Therefore, Guilley already suggests an interaction with, or at least moniotoring of further parts of the protected system. In the car industry/electronic key context mentioned in Guilley, the selection of the concrete modules with which the device interacts, or whose signals are monitored is an implementation of this. In addition, for further evidence, Kneib teaches: FIG. 5 shows as network subscriber in part a control unit 5 comprising a microcontroller 510 as well as a CAN transceiver 520. Microcontroller 510 comprises a CPU 511, a memory 512, a CAN controller 513 as well as a security module 514 (e.g. a hardware security module, i.e., a module having a secured memory and a separate secured processing unit), which are respectively connected to an internal communication line 51 (host interface). Security module 514 is additionally connected to an additional secure communication connection 52 (secure interface). In this development, microcontroller 510 comprises as a hardware component for implementing or supporting the provided methods a monitoring unit 515, which is likewise connected to secure communication connection 52. A receiving line (CAN Rx) from the side of CAN receiver 520 leads from the latter respectively to CAN controller 513 and monitoring unit 515. A transmission line (CAN Tx) in the direction of CAN transceiver 520 leads respectively from CAN controller 513 and monitoring unit 515 via a common AND block (&) to CAN transceiver 520. CAN transceiver 520 is connected to a CAN bus (CAN H, CAN L). In an alternative development, FIG. 6 shows as a network subscriber, likewise in excerpted form, a control unit 6 comprising a microcontroller 610 and a CAN transceiver 620. Microcontroller 610 comprises a CPU 611, a memory 612, a CAN controller 613 and a security module 614 (e.g., a hardware security module, i.e. a module having a secured memory and separate secured processing unit), which are respectively connected to an internal communication line 61 (host interface). Security module 614 is additionally connected to an additional secure communication connection 62 (secure interface). An SPI interface module 615 is likewise connected to the secure communication connection 62. In this development, CAN transceiver 620 comprises as hardware component for implementing or supporting the provided methods a monitoring unit 621, which is connected via the SPI interface unit 615 of the microcontroller to secure communication connection 62 of the microcontroller. A receiving line (CAN Rx) from the side of the receiving and transmitting means 622 of CAN transceiver 620 leads from the latter respectively to CAN controller 613 and to monitoring module 621. A transmitting line (CAN Tx) in the direction of receiving and transmitting means 622 of CAN transceiver 620 leads respectively from CAN controller 613 and monitoring module 621 via a common AND block (&) to receiving and transmitting means 622, which are connected to a CAN bus (CAN H, CAN L). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guilley and Kondeva (if not explicitly taught) to include at least one of a power management unit, a controller area network transceiver, a host microcontroller, and a radio frequency communication unit, based upon the beneficial teachings provided by Kneib. These modifications would result in better communication. Claims 18 and 32 is rejected under 35 U.S.C. 103 as being unpatentable over Guilley et al. (US 2021/0004461) in view of and Kneib et al. (US 2018/0337938). Further, regarding claims 18 and 32, Guilley teaches monitoring different physical parameters and software activities (see [0040] and [0041]. Guilley also teaches monitoring activities of a processor, peripheral, congestion on a system bus, hardware performance counters, watchdogs, timers, and a software stack - see [0114] – [0117]. Therefore, Guilley already suggests an interaction with, or at least moniotoring of further parts of the protected system. In the car industry/electronic key context mentioned in Guilley, the selection of the concrete modules with which the device interacts, or whose signals are monitored is an implementation of this. In addition, for further evidence, Kneib teaches: FIG. 5 shows as network subscriber in part a control unit 5 comprising a microcontroller 510 as well as a CAN transceiver 520. Microcontroller 510 comprises a CPU 511, a memory 512, a CAN controller 513 as well as a security module 514 (e.g. a hardware security module, i.e., a module having a secured memory and a separate secured processing unit), which are respectively connected to an internal communication line 51 (host interface). Security module 514 is additionally connected to an additional secure communication connection 52 (secure interface). In this development, microcontroller 510 comprises as a hardware component for implementing or supporting the provided methods a monitoring unit 515, which is likewise connected to secure communication connection 52. A receiving line (CAN Rx) from the side of CAN receiver 520 leads from the latter respectively to CAN controller 513 and monitoring unit 515. A transmission line (CAN Tx) in the direction of CAN transceiver 520 leads respectively from CAN controller 513 and monitoring unit 515 via a common AND block (&) to CAN transceiver 520. CAN transceiver 520 is connected to a CAN bus (CAN H, CAN L). In an alternative development, FIG. 6 shows as a network subscriber, likewise in excerpted form, a control unit 6 comprising a microcontroller 610 and a CAN transceiver 620. Microcontroller 610 comprises a CPU 611, a memory 612, a CAN controller 613 and a security module 614 (e.g., a hardware security module, i.e. a module having a secured memory and separate secured processing unit), which are respectively connected to an internal communication line 61 (host interface). Security module 614 is additionally connected to an additional secure communication connection 62 (secure interface). An SPI interface module 615 is likewise connected to the secure communication connection 62. In this development, CAN transceiver 620 comprises as hardware component for implementing or supporting the provided methods a monitoring unit 621, which is connected via the SPI interface unit 615 of the microcontroller to secure communication connection 62 of the microcontroller. A receiving line (CAN Rx) from the side of the receiving and transmitting means 622 of CAN transceiver 620 leads from the latter respectively to CAN controller 613 and to monitoring module 621. A transmitting line (CAN Tx) in the direction of receiving and transmitting means 622 of CAN transceiver 620 leads respectively from CAN controller 613 and monitoring module 621 via a common AND block (&) to receiving and transmitting means 622, which are connected to a CAN bus (CAN H, CAN L). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guilley (if not explicitly taught) to include at least one of a power management unit, a controller area network transceiver, a host microcontroller, and a radio frequency communication unit, based upon the beneficial teachings provided by Kneib. These modifications would result in better communication. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to LISA C LEWIS whose telephone number is (571)270-7724. The examiner can normally be reached Monday - Thursday 7am-2pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /LISA C LEWIS/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Apr 01, 2025
Application Filed
Sep 15, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743525
MODEL-BASED CONFIDENCE RANKING OF WEB APPLICATION VULNERABILITIES
2y 0m to grant Granted Sep 22, 2026
Patent 12739098
METHOD AND APPARATUS FOR PROVIDING CREDENTIAL SERVICE RELATED TO CLOUD SERVICE
2y 3m to grant Granted Sep 15, 2026
Patent 12739099
Verifiable Key Exchange for Cryptography
2y 1m to grant Granted Sep 15, 2026
Patent 12712729
METHODS AND SYSTEMS IMPLEMENTED IN A NETWORK ARCHITECTURE WITH NODES CAPABLE OF PERFORMING MESSAGE-BASED TRANSACTIONS
2y 11m to grant Granted Aug 18, 2026
Patent 12706744
COMPUTER-IMPLEMENTED SYSTEM AND METHOD FOR MANAGING AUTHENTICATION BETWEEN USER DEVICE AND AUTHENTICATION SERVER USING PRIVATE-PUBLIC KEY CRYPTOGRAPHY
2y 3m to grant Granted Aug 11, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
81%
Grant Probability
96%
With Interview (+15.6%)
2y 10m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 682 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month