Prosecution Insights
Last updated: October 02, 2026
Application No. 17/750,132

CONTINUOUS TRUSTED ACCESS OF ENDPOINTS

Final Rejection §103§112
Filed
May 20, 2022
Examiner
AYALA, KEVIN ALEXIS
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
6 (Final)
63%
Grant Probability
Moderate
7-8
OA Rounds
0m
Est. Remaining
92%
With Interview

Examiner Intelligence

Grants 63% of resolved cases
63%
Career Allowance Rate
115 granted / 182 resolved
+5.2% vs TC avg
Strong +28% interview lift
Without
With
+28.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
21 currently pending
Career history
211
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
56.2%
+16.2% vs TC avg
§102
6.5%
-33.5% vs TC avg
§112
23.9%
-16.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 182 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 02/20/2026 has been entered. Response to Arguments In response 35 USC 103 on page 9, filed 02/20/2026, for independent claims 1, 12 and 20 along with their respective dependent claims, applicant indicates that Cheng and shah fails to teach the independent claims. Applicant’s argument have been considered but are moot, because the newly recited amendment does not rely on the newly recited reference being applied to the prior rejection of record or any teaching or matter specifically challenged in the argument. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: sensing module in claim 1, 12 and 20. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-5, 7-16, 18-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim limitation “sensing module” invokes 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. The disclosure is devoid of any structure that performs the function in the claims such as “passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection”. Therefore, the claim is indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. Applicant may: (a) Amend the claim so that the claim limitation will no longer be interpreted as a limitation under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph; (b) Amend the written description of the specification such that it expressly recites what structure, material, or acts perform the entire claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (c) Amend the written description of the specification such that it clearly links the structure, material, or acts disclosed therein to the function recited in the claim, without introducing any new matter (35 U.S.C. 132(a)). If applicant is of the opinion that the written description of the specification already implicitly or inherently discloses the corresponding structure, material, or acts and clearly links them to the function so that one of ordinary skill in the art would recognize what structure, material, or acts perform the claimed function, applicant should clarify the record by either: (a) Amending the written description of the specification such that it expressly recites the corresponding structure, material, or acts for performing the claimed function and clearly links or associates the structure, material, or acts to the claimed function, without introducing any new matter (35 U.S.C. 132(a)); or (b) Stating on the record what the corresponding structure, material, or acts, which are implicitly or inherently set forth in the written description of the specification, perform the claimed function. For more information, see 37 CFR 1.75(d) and MPEP §§ 608.01(o) and 2181. Claims 2-5, 7-11, 13-16, and 18-19 falls together accordingly do not cure the deficiencies the independent claims. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-5, 7-16, and 18-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Re. claims 1, 12 and 20; the claims recite “the sensing module embedded in the asset being configured to passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection”. The specification does not support that the sensing module embedded in the asset is capable of “passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection”. The specification recites “In various embodiments, asset inventory service 320 may do so by embedding sensing 20 modules in networking equipment 308 which passively analyze communications between endpoints. The sensors may use deep packet inspection (DPI) to not only identify the protocols in use by a given packet (e.g., the automation protocol used between HMI 310, controller 306, and SCADA service 314), but also understand the action(s) that are being communicated and to classify both the type of device/component and its application 25 behavior [Page 14]”. The specification indicates the sensing modules embedding in networking equipment and not in the asset. Claims 2-5, 7-11, 13-16, and 18-19 falls together accordingly do not cure the deficiencies the independent claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-5, 7-16 and 18- 20 are rejected under 35 U.S.C. 103 as being unpatentable over Cheng et al. (US 11087005, hereinafter Cheng) in view of Shah et al. (US 20230105021, hereinafter Shah) in view of Jakobsson et al. (US 11757914, hereinafter Jakobsson) and in further view of Christian (US 20200204574). Re. claim 1, Cheng discloses a method, comprising: determining, by a device (Cheng discloses a device [Col 10 lines 1-16]), a profile of an asset in a computer network, the profile identifying a type of the asset and a particular activity of the asset (Cheng discloses a device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16]. The IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41], determines the profile that identifies the model and protocol or location); determining, by the device, a specific context of the asset within the computer network (Cheng discloses the IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41]. A device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16], determine what kind of protocol the device is using in the network). Although Cheng discloses assessing risk score and matching profiles, Cheng does not explicitly teach but Shah teaches determining, by the device, an expected behavior for assets associated with the type and the particular activity of the asset, and within the specific context (Shah teaches ANSS 100 may use one or more AI/ML techniques to identify patterns, sequencing, rates, trends, signatures, values, attributes, and/or other indicia of regular or expected behavior from the network data groups. UEs 103 for different content at different times to detect commonality for an expected behavior [0034][0057][0014][0016]); assigning, by the device, a risk score for the asset based on one or more risk factors associated with the expected for assets associated with the type and the particular activity, and within specific context (Shah teaches analysis may include comparing the actual behavior exhibited by the new requests or network data against the expected behavior of the one or more models [0027]. The regression analysis that compares parameters, values, timing, and/or other attributes of new network data 303 and 305 against the modeled expected behavior 301. The comparison may be used to determine whether new network data 303 and 305 exhibit anomalous behavior that deviates from the modeled expected behavior 301, and/or to quantify the threat risk posed by any detected anomalous behavior to the devices and/or systems protected by ANSS 100 [0040][0041-0042][0057][0069]); performing, by the device, one or more mitigation actions on the asset based on the risk score and a policy associated with the asset (Shah teaches ANSS 100 may implement (at 110) different protections in response to detecting anomalous behavior via the regression analysis and/or the computed threat risk associated with that anomalous behavior. For instance, ANSS 100 may generate an alert that notifies a system administrator of first anomalous behavior by a first UE when the first anomalous behavior is classified to be of a low threat (e.g., a threat score of 1), and ANSS 100 may block network data being issued by a second UE when the anomalous behavior of the second UE is classified to be a significant threat (e.g., a threat score of 9) [0029][0028][0041-42][0057]. Generating and adapting network security rules and/or policies based on the expected behaviors that are modeled, and/or performing different actions in response to anomalous behavior that deviates from the expected behaviors used to define the rules and/or policies [0014-0015]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng to include determining, by the device, an expected behavior for assets associated with the type and the particular activity of the asset, and within the specific context; assigning, by the device, a risk score for the asset based on one or more risk factors associated with the expected for assets associated with the type and the particular activity, and within specific context; performing, by the device, one or more mitigation actions on the asset based on the risk score and a policy associated with the asset as disclosed by Shah. One of ordinary skill in the art would have been motivated for the purpose of performing different actions in response to anomalous behavior that deviates from the expected behaviors (Shah [0014]). Although Cheng discloses risk score, the combination of Cheng-Shah do not explicitly teach but Jakobsson teaches wherein the one or more mitigation actions comprise blocking, remediating or continuing the particular activity of the asset based at least in part on whether the risk score belongs to a high risk index rand, a medium risk index range or a low risk index range (Jakobsson discloses a security action is performed based on the determined security risk, if applicable. In some embodiments, in 204 and/or 210, one or more security risk scores are determined and based on these score(s), a security action is selected among different security action options. For example, the security action to be performed is selected based on the security risk associated with the sender of the initially received message. The selected security action is performed. For example, a security risk score may indicate that the message is of very low risk (e.g., risk score is below a first threshold) and the message is fully allowed to be accessed by the intended recipient (e.g., allow the message to a message inbox of the intended recipient). If not, the security risk score may indicate that the message is of medium risk (e.g., risk score is above the first threshold but below a second threshold) and the message is modified to include a warning prior to being allowed to be accessed by the intended recipient (e.g., allow the modified message to a message inbox of the intended recipient). Otherwise, the security risk score may indicate that the message is of high risk (e.g., risk score is above the second threshold) and the message is not allowed to be accessed by the intended recipient (e.g., send the message to an administrator for further analysis) [Col 41 line 43- Col 42 line 3]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng-Shah to include wherein the one or more mitigation actions comprise blocking, remediating or continuing the particular activity of the asset based at least in part on whether the risk score belongs to a high risk index rand, a medium risk index range or a low risk index range as disclosed by Jakobsson. One of ordinary skill in the art would have been motivated for the purpose of minimize a security risk (Jakobsson Col 61 lines 34-41]). Cheng-Shah-Jackobsson do not explicitly teach but Christian teaches wherein determining the profile of the asset comprises: receiving, from a sensing module embedded in the asset, information including the type of the asset and the particular activity of the asset, the sensing module embedded in the asset being configured to passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection (Christian teaches protocol analysis and packet analysis (as explained below), are combined with the historical and current activities/behavior of the user and other “like” or similar users. This combination allows data analysis module 112 to establish baseline 120 for data 130 as will be explained further below. The historical and present activities/behavior of the user that may be combined with the results of protocol and packet analyses, include but are not limited to, the types of applications used by the user and other like users, user's role/permission level and that of other like users, typical session length, typical data traffic patterns/data-types, past security or performance issues, etc. Packet/payload analysis, encompassed by packet analysis module 116 in the embodiment of FIG. 1, is concerned with performing a deep inspection and analysis of the payload of every packet of data 130 transmitted/received by network 108. As explained above, the results of this analysis are used in defining baseline 120 of data 130 by data analysis module 112. The present technology utilizes techniques oftentimes called Deep Packet Inspection (DPI), also referred to as complete packet inspection and Information eXtraction (IX), for examining the header as well as the data part of each packet as it passes in and out of network 108 [0100][0122][0201] Fig. 1). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng-Shah-Jakobsson to include wherein determining the profile of the asset comprises: receiving, from a sensing module embedded in the asset, information including the type of the asset and the particular activity of the asset, the sensing module embedded in the asset being configured to passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection as disclosed by Chistian. One of ordinary skill in the art would have been motivated for the purpose of minimize a security risk (Jakobsson Col 61 lines 34-41]). Re. claim 2, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, wherein the asset performs a plurality of activities, and wherein the asset has a corresponding plurality of profiles (Cheng discloses a device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16]. The IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41]). Although Cheng discloses risk score, the combination of Cheng-Shah do not explicitly teach but Jakobsson teaches aggregating a plurality of risk scores associated with the corresponding plurality of profiles to determine an overall risk assessment of the asset (Jakobsson teaches These component scores are then combined (e.g., added, weighted then added, averaged, etc.) to determine an overall risk score [Col 55 lines 15-37]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng-Shah to include mitigation action based on the risk score as disclosed by Jakobsson. One of ordinary skill in the art would have been motivated for the purpose of one or more specific types of risk and a separate total score is calculated for each of the different types of risk based on its associated component scores (Jakobsson [Col 58 lines 9-29]). Re. claim 3, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, wherein determining the profile of the asset further comprises: receiving the profile from a behavioral analytics engine (Cheng discloses the IoT device behavior deviation determination engine 710 can determine an IoT device is actually deviating from regular IoT device behaviors if it begins communicating with a new external host [Col 33 lines 50-67]. In determining operational performance deviations of an IoT device using device profiles, the IoT device behavior deviation determination engine 710 can determine the operational performance deviations of the IoT device by comparing or tracking instances of an IoT device, included as part of a device profile of the IoT device [Col 34 lines 1-27]). Re. claim 4, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, wherein the profile is based on component tags and activity tags associated with the asset (Cheng discloses the IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services. Protocols can include applicable protocols used in providing IoT devices access to network services. For example, protocols can include infrastructure protocols, identification protocols, transport protocols, discovery protocols, data protocols, device management protocols, semantic protocols, and multi-layer framework protocols. IoT device risk factors related to protocols used by IoT devices in accessing network services can include a number of differed protocols used by an IoT device in accessing network services and characteristics of protocols used by an IoT device in accessing network services. For example, IoT device risk factors related to protocols used by an IoT device in accessing network services can include a number of protocols used by an IoT device in accessing network services at a specific time or during a specific time duration [Col 7 line 53-Col 8 line 4], shows protocol at a specific time (which could be the activity tag)). Re. claim 5, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, Shah further teaches wherein the one or more mitigation actions are selected from a group consisting of: blocking the particular activity of the asset; blocking all activities of the asset; remediating the particular activity of the asset; continuing the particular activity of the asset; and flagging the particular activity of the asset (Shah teaches ANSS 100 may dynamically select an action to perform based on the risk classification (e.g., the score for the threat risk) and the one or more parameters from the new request that contributed to the risk classification. ANSS 100 may select a first action to perform in response to classifying an anomalous value of a first parameter as a threat risk of 10, and may select a second action to perform in response to classifying an anomalous value of a second parameter as a threat risk of 10, wherein the first action may protect against a first type of attack associated with the first parameter having an anomalous value, and the second action may protect against a second type of attack associated with the second parameter. In this case, the first action may include a rate limiting rule that limits the number of requests a UE may issue in a given interval, and the second action may include a blocking rule that prevents requests with a certain anomalous parameter from reaching its intended destination. [0042] [0079]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng to include wherein the one or more mitigation actions are selected from a group consisting of: blocking the particular activity of the asset; blocking all activities of the asset; remediating the particular activity of the asset; continuing the particular activity of the asset; and flagging the particular activity of the asset as disclosed by Shah. One of ordinary skill in the art would have been motivated for the purpose of performing different actions in response to anomalous behavior that deviates from the expected behaviors (Shah [0014]). Re. claim 7, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, wherein determining the specific context of the asset within the computer network is based on one or more factors selected from a group consisting of: a location of the asset within the computer network; a type of the computer network; a known configuration of the asset; communication paths used by the particular activity; destinations of traffic sent by the asset; one or more protocols in use by the asset; a level within a logical network model; a particular cell in which the asset operates; a particular area in which the asset operates; a particular zone in which the asset operates; a particular security level of the asset; and a time at which the particular activity operates (Cheng discloses the IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41]. A device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16], determine what kind of protocol the device is using in the network). Re. claim 8, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, wherein the expected behavior is based on one or more of a learned behavior, a researched behavior, and a configured behavior (Cheng discloses regular IoT device behavior includes typical behavior exhibited by IoT devices in operation. Regular IoT device behavior can include typical IoT device behavior of a specific IoT device, typical IoT device behavior of IoT devices of a specific type, and typical IoT device behavior of a group of IoT devices. For example, regular IoT device behavior can include typical IoT device behavior of a group of IoT devices within an enterprise network. In another example, regular IoT device behavior can include typical IoT device behavior of a group of IoT devices at a physical location [Col 9 lines 36-58], acting as learned behavior). Re. claim 9, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, Although Cheng discloses risk score, the combination of Cheng-Shah do not explicitly teach but Jakobsson teaches wherein the one or more mitigation actions are based on one or more configurable thresholds (Jakobsson teaches the risk score now is −10−5+10+65=60, which is compared to a threshold T1=50. As a result of the score R exceeding T1, the already-modified message is sent to a unit that “scrubs” it. If the score R had exceeded a second threshold T2=72, then the email would not have been delivered, and if the score were below T3=−15, then the email would be delivered verbatim but with a smiley emoji added to the subject line, whereas if the score was greater than or equal to T3, any emoji in the subject line is removed before the message is delivered [Col 22 lines 1-44]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng-Shah to include wherein the one or more mitigation actions are based on one or more configurable thresholds as disclosed by Jakobsson. One of ordinary skill in the art would have been motivated for the purpose of one or more specific types of risk and a separate total score is calculated for each of the different types of risk based on its associated component scores (Jakobsson [Col 58 lines 9-29]). Re. claim 10, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, wherein the one or more risk factors are selected from a group consisting of: riskiness of activity regardless of context; riskiness of the type of device regardless of context; riskiness of a communication reach to a destination outside of the computer network regardless of context; riskiness of a communication reach from a source outside of the computer network regardless of context; and riskiness of a protocol in use by the particular activity regardless of context (Cheng discloses a device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16]. The IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41]). Re. claim 11, the combination of Cheng-Shah-Jakobsson-Christian teach the method as in claim 1, wherein the type of the asset is one or more features selected from a group consisting of: a make of the asset; a model of the asset; a hardware version of the asset; a firmware version of the asset; a software version of the asset; a manufacturer of the asset; a country of origin of the asset; a date of manufacture of the asset; and an operating system of the asset (Cheng discloses a device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16]). Re. claim 12, Cheng discloses a non-transitory, computer-readable medium having computer-executable instructions stored thereon that, when executed by a processor on a computer, cause the computer to perform a method comprising (Cheng discloses An engine can include hardware, firmware, or software embodied in a computer-readable medium for execution by the processor [Col 4 lines 4-24]): determining a profile of an asset in a computer network, the profile identifying a type of the asset and a particular activity of the asset (Cheng discloses a device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16]. The IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41], determines the profile that identifies the model and protocol or location); determining a specific context of the asset within the computer network (Cheng discloses the IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41]. A device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16], determine what kind of protocol the device is using in the network). Although Cheng discloses assessing risk score and matching profiles, Cheng does not explicitly teach but Shah teaches determining, by the device, an expected behavior for assets associated with the type and the particular activity of the asset, and within the specific context (Shah teaches ANSS 100 may use one or more AI/ML techniques to identify patterns, sequencing, rates, trends, signatures, values, attributes, and/or other indicia of regular or expected behavior from the network data groups. UEs 103 for different content at different times to detect commonality for an expected behavior [0034][0057][0014][0016]); assigning, by the device, a risk score for the asset based on one or more risk factors associated with the expected for the assets associated with the type and the particular activity, and within specific context (Shah teaches analysis may include comparing the actual behavior exhibited by the new requests or network data against the expected behavior of the one or more models [0027]. The regression analysis that compares parameters, values, timing, and/or other attributes of new network data 303 and 305 against the modeled expected behavior 301. The comparison may be used to determine whether new network data 303 and 305 exhibit anomalous behavior that deviates from the modeled expected behavior 301, and/or to quantify the threat risk posed by any detected anomalous behavior to the devices and/or systems protected by ANSS 100 [0040][0041-0042][0057][0069]); performing, by the device, one or more mitigation actions on the asset based on the risk score and a policy associated with the asset (Shah teaches ANSS 100 may implement (at 110) different protections in response to detecting anomalous behavior via the regression analysis and/or the computed threat risk associated with that anomalous behavior. For instance, ANSS 100 may generate an alert that notifies a system administrator of first anomalous behavior by a first UE when the first anomalous behavior is classified to be of a low threat (e.g., a threat score of 1), and ANSS 100 may block network data being issued by a second UE when the anomalous behavior of the second UE is classified to be a significant threat (e.g., a threat score of 9) [0029][0028][0041-42][0057]. Generating and adapting network security rules and/or policies based on the expected behaviors that are modeled, and/or performing different actions in response to anomalous behavior that deviates from the expected behaviors used to define the rules and/or policies [0014-0015]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng to include determining, by the device, an expected behavior for assets associated with the type and the particular activity of the asset, and within the specific context; assigning, by the device, a risk score for the asset based on one or more risk factors associated with the expected for assets associated with the type and the particular activity, and within specific context; performing, by the device, one or more mitigation actions on the asset based on the risk score, wherein the one or more mitigation actions comprises enforcement of one or more network policies on the asset, the one or more network policies configured based on the risk score as disclosed by Shah. One of ordinary skill in the art would have been motivated for the purpose of performing different actions in response to anomalous behavior that deviates from the expected behaviors (Shah [0014]). Although Cheng discloses risk score, the combination of Cheng-Shah do not explicitly teach but Jakobsson teaches wherein the one or more mitigation actions comprise blocking, remediating or continuing the particular activity of the asset based at least in part on whether the risk score belongs to a high risk index rand, a medium risk index range or a low risk index range (Jakobsson discloses a security action is performed based on the determined security risk, if applicable. In some embodiments, in 204 and/or 210, one or more security risk scores are determined and based on these score(s), a security action is selected among different security action options. For example, the security action to be performed is selected based on the security risk associated with the sender of the initially received message. The selected security action is performed. For example, a security risk score may indicate that the message is of very low risk (e.g., risk score is below a first threshold) and the message is fully allowed to be accessed by the intended recipient (e.g., allow the message to a message inbox of the intended recipient). If not, the security risk score may indicate that the message is of medium risk (e.g., risk score is above the first threshold but below a second threshold) and the message is modified to include a warning prior to being allowed to be accessed by the intended recipient (e.g., allow the modified message to a message inbox of the intended recipient). Otherwise, the security risk score may indicate that the message is of high risk (e.g., risk score is above the second threshold) and the message is not allowed to be accessed by the intended recipient (e.g., send the message to an administrator for further analysis) [Col 41 line 43- Col 42 line 3]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng-Shah to include wherein the one or more mitigation actions comprise blocking, remediating or continuing the particular activity of the asset based at least in part on whether the risk score belongs to a high risk index rand, a medium risk index range or a low risk index range as disclosed by Jakobsson. One of ordinary skill in the art would have been motivated for the purpose of minimize a security risk (Jakobsson Col 61 lines 34-41]). Cheng-Shah-Jackobsson do not explicitly teach but Christian teaches wherein determining the profile of the asset comprises: receiving, from a sensing module embedded in the asset, information including the type of the asset and the particular activity of the asset, the sensing module embedded in the asset being configured to passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection (Christian teaches protocol analysis and packet analysis (as explained below), are combined with the historical and current activities/behavior of the user and other “like” or similar users. This combination allows data analysis module 112 to establish baseline 120 for data 130 as will be explained further below. The historical and present activities/behavior of the user that may be combined with the results of protocol and packet analyses, include but are not limited to, the types of applications used by the user and other like users, user's role/permission level and that of other like users, typical session length, typical data traffic patterns/data-types, past security or performance issues, etc. Packet/payload analysis, encompassed by packet analysis module 116 in the embodiment of FIG. 1, is concerned with performing a deep inspection and analysis of the payload of every packet of data 130 transmitted/received by network 108. As explained above, the results of this analysis are used in defining baseline 120 of data 130 by data analysis module 112. The present technology utilizes techniques oftentimes called Deep Packet Inspection (DPI), also referred to as complete packet inspection and Information eXtraction (IX), for examining the header as well as the data part of each packet as it passes in and out of network 108 [0100][0122][0201] Fig. 1). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng-Shah-Jakobsson to include wherein determining the profile of the asset comprises: receiving, from a sensing module embedded in the asset, information including the type of the asset and the particular activity of the asset, the sensing module embedded in the asset being configured to passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection as disclosed by Chistian. One of ordinary skill in the art would have been motivated for the purpose of minimize a security risk (Jakobsson Col 61 lines 34-41]). Re. claim 13, rejection of claim 12 is included and claim 13 is rejected with the same rationale as applied in claim 2 above. Re. claim 14, rejection of claim 12 is included and claim 14 is rejected with the same rationale as applied in claim 3 above. Re. claim 15, rejection of claim 12 is included and claim 15 is rejected with the same rationale as applied in claim 4 above. Re. claim 16, rejection of claim 12 is included and claim 16 is rejected with the same rationale as applied in claim 5 above. Re. claim 17, rejection of claim 12 is included and claim 17 is rejected with the same rationale as applied in claim 6 above. Re. claim 18, rejection of claim 12 is included and claim 18 is rejected with the same rationale as applied in claim 7 above. Re. claim 19, rejection of claim 12 is included and claim 19 is rejected with the same rationale as applied in claim 8 above. Re. claim 20, Cheng discloses an apparatus, comprising: a processor configured to execute one or more processes (Cheng discloses processor [Col 2 lines 42-52]); and a memory configured to store a process that is executable by the processor (Cheng discloses processor coupled to the memory [Col 2 lines 42-52]), the process, when executed, configured to: determine a profile of an asset in a computer network, the profile identifying a type of the asset and a particular activity of the asset (Cheng discloses a device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16]. The IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41], determines the profile that identifies the model and protocol or location); determine a specific context of the asset within the computer network (Cheng discloses the IoT device risk assessment system 106 functions to determine risk levels of IoT devices according to IoT device risk factors related to protocols used by IoT devices in accessing network services [Col 7 lines 53-67] [Col 8 lines 18-41]. A device profile for an IoT device includes either or both characteristics of the IoT device and characteristics of how the IoT device functions in operation. For example a device profile can include a type of device of an IoT device, a maker of an IoT device, a module of an IoT device, firmware on an IoT device, an operating system of an IoT device, applications executing at or capable of being executed at an IoT device, an entity or an organization associated with an IoT device, a physical location of an IoT device, a network location of an IoT device, uses of an IoT device, characteristics of an IoT device actually operating, patterns of an IoT device in operating [Col 10 lines 1-16], determine what kind of protocol the device is using in the network). Although Cheng discloses assessing risk score and matching profiles, Cheng does not explicitly teach but Shah teaches determine an expected behavior for assets associated with the type and the particular activity of the asset, and within the specific context (Shah teaches ANSS 100 may use one or more AI/ML techniques to identify patterns, sequencing, rates, trends, signatures, values, attributes, and/or other indicia of regular or expected behavior from the network data groups. UEs 103 for different content at different times to detect commonality for an expected behavior [0034][0057][0014][0016]); assign a risk score for the asset based on one or more risk factors associated with the expected for assets associated with the type and the particular activity, and within specific context (Shah teaches analysis may include comparing the actual behavior exhibited by the new requests or network data against the expected behavior of the one or more models [0027]. The regression analysis that compares parameters, values, timing, and/or other attributes of new network data 303 and 305 against the modeled expected behavior 301. The comparison may be used to determine whether new network data 303 and 305 exhibit anomalous behavior that deviates from the modeled expected behavior 301, and/or to quantify the threat risk posed by any detected anomalous behavior to the devices and/or systems protected by ANSS 100 [0040][0041-0042][0057][0069]); perform one or more mitigation actions on the asset based on the risk score and a policy associated with the asset (Shah teaches ANSS 100 may implement (at 110) different protections in response to detecting anomalous behavior via the regression analysis and/or the computed threat risk associated with that anomalous behavior. For instance, ANSS 100 may generate an alert that notifies a system administrator of first anomalous behavior by a first UE when the first anomalous behavior is classified to be of a low threat (e.g., a threat score of 1), and ANSS 100 may block network data being issued by a second UE when the anomalous behavior of the second UE is classified to be a significant threat (e.g., a threat score of 9) [0029][0028][0041-42][0057]. Generating and adapting network security rules and/or policies based on the expected behaviors that are modeled, and/or performing different actions in response to anomalous behavior that deviates from the expected behaviors used to define the rules and/or policies [0014-0015]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng to include determining, by the device, an expected behavior for assets associated with the type and the particular activity of the asset, and within the specific context; assigning, by the device, a risk score for the asset based on one or more risk factors associated with the expected for assets associated with the type and the particular activity, and within specific context; performing, by the device, one or more mitigation actions on the asset based on the risk score, wherein the one or more mitigation actions comprises enforcement of one or more network policies on the asset, the one or more network policies configured based on the risk score as disclosed by Shah. One of ordinary skill in the art would have been motivated for the purpose of performing different actions in response to anomalous behavior that deviates from the expected behaviors (Shah [0014]). Although Cheng discloses risk score, the combination of Cheng-Shah do not explicitly teach but Jakobsson teaches wherein the one or more mitigation actions comprise blocking, remediating or continuing the particular activity of the asset based at least in part on whether the risk score belongs to a high risk index rand, a medium risk index range or a low risk index range (Jakobsson discloses a security action is performed based on the determined security risk, if applicable. In some embodiments, in 204 and/or 210, one or more security risk scores are determined and based on these score(s), a security action is selected among different security action options. For example, the security action to be performed is selected based on the security risk associated with the sender of the initially received message. The selected security action is performed. For example, a security risk score may indicate that the message is of very low risk (e.g., risk score is below a first threshold) and the message is fully allowed to be accessed by the intended recipient (e.g., allow the message to a message inbox of the intended recipient). If not, the security risk score may indicate that the message is of medium risk (e.g., risk score is above the first threshold but below a second threshold) and the message is modified to include a warning prior to being allowed to be accessed by the intended recipient (e.g., allow the modified message to a message inbox of the intended recipient). Otherwise, the security risk score may indicate that the message is of high risk (e.g., risk score is above the second threshold) and the message is not allowed to be accessed by the intended recipient (e.g., send the message to an administrator for further analysis) [Col 41 line 43- Col 42 line 3]). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng-Shah to include wherein the one or more mitigation actions comprise blocking, remediating or continuing the particular activity of the asset based at least in part on whether the risk score belongs to a high risk index rand, a medium risk index range or a low risk index range as disclosed by Jakobsson. One of ordinary skill in the art would have been motivated for the purpose of minimize a security risk (Jakobsson Col 61 lines 34-41]). Cheng-Shah-Jackobsson do not explicitly teach but Christian teaches wherein determining the profile of the asset comprises: receiving, from a sensing module embedded in the asset, information including the type of the asset and the particular activity of the asset, the sensing module embedded in the asset being configured to passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection (Christian teaches protocol analysis and packet analysis (as explained below), are combined with the historical and current activities/behavior of the user and other “like” or similar users. This combination allows data analysis module 112 to establish baseline 120 for data 130 as will be explained further below. The historical and present activities/behavior of the user that may be combined with the results of protocol and packet analyses, include but are not limited to, the types of applications used by the user and other like users, user's role/permission level and that of other like users, typical session length, typical data traffic patterns/data-types, past security or performance issues, etc. Packet/payload analysis, encompassed by packet analysis module 116 in the embodiment of FIG. 1, is concerned with performing a deep inspection and analysis of the payload of every packet of data 130 transmitted/received by network 108. As explained above, the results of this analysis are used in defining baseline 120 of data 130 by data analysis module 112. The present technology utilizes techniques oftentimes called Deep Packet Inspection (DPI), also referred to as complete packet inspection and Information eXtraction (IX), for examining the header as well as the data part of each packet as it passes in and out of network 108 [0100][0122][0201] Fig. 1). Therefore, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to modify the method and system disclosed by Cheng-Shah-Jakobsson to include wherein determining the profile of the asset comprises: receiving, from a sensing module embedded in the asset, information including the type of the asset and the particular activity of the asset, the sensing module embedded in the asset being configured to passively analyze communications between the asset and other devices in the computer network to identify protocols in use by a given packet and one or more actions that are being communicated using deep packet inspection as disclosed by Chistian. One of ordinary skill in the art would have been motivated for the purpose of minimize a security risk (Jakobsson Col 61 lines 34-41]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Covell (US 11985128) discloses analyzing metadata associated with the interaction, (e.g., employee profile, applications typically used by the user, location, time of day) comparing the metadata against the user's profile, and classifying the interaction as either suspicious or not suspicious (i.e., normal). Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KEVIN A AYALA whose telephone number is (571)270-3912. The examiner can normally be reached Monday-Thursday 8AM-5PM; Friday: Variable EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached on 571-272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /KEVIN AYALA/Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Show 17 earlier events
Mar 07, 2026
Response after Non-Final Action
Mar 23, 2026
Non-Final Rejection mailed — §103, §112
Jun 08, 2026
Interview Requested
Jul 03, 2026
Interview Requested
Jul 14, 2026
Applicant Interview (Telephonic)
Jul 14, 2026
Response Filed
Jul 14, 2026
Examiner Interview Summary
Sep 18, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750232
IMMUTABLE DOCUMENT SEALING AND AUTHENTICATION
2y 5m to grant Granted Sep 29, 2026
Patent 12737467
METHOD AND SYSTEM FOR DYNAMIC APPLICATION OF STORAGE ENCRYPTION
5y 7m to grant Granted Sep 15, 2026
Patent 12706757
USER DEVICE FOR ACQUIRING VERIFIABLE CLAIMS, SYSTEM INCLUDING SAID USER DEVICE, AND METHOD FOR ACQUIRING VERIFIABLE CLAIMS
2y 7m to grant Granted Aug 11, 2026
Patent 12683757
ADAPTIVE COUNTERMEASURE FOR BIT LEAKAGE IN LATTICE-BASED CRYPTOGRAPHY
3y 6m to grant Granted Jul 14, 2026
Patent 12659143
METHOD AND DEVICE FOR CORRECTING POLARIZATION DISTORTION OF FARADAY ROTATOR MIRROR FOR QUANTUM KEY DISTRIBUTION IN COMMUNICATION SYSTEM
3y 3m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

7-8
Expected OA Rounds
63%
Grant Probability
92%
With Interview (+28.4%)
3y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 182 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month