Prosecution Insights
Last updated: October 01, 2026
Application No. 17/956,664

WATERMARK SERVER

Final Rejection §103
Filed
Sep 29, 2022
Examiner
EDWARDS, LINGLAN E
Art Unit
2408
Tech Center
2400 — Computer Networks
Assignee
Micro Focus LLC
OA Round
5 (Final)
70%
Grant Probability
Favorable
6-7
OA Rounds
0m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
348 granted / 498 resolved
+11.9% vs TC avg
Strong +24% interview lift
Without
With
+23.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
4 currently pending
Career history
504
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
53.9%
+13.9% vs TC avg
§102
7.2%
-32.8% vs TC avg
§112
19.3%
-20.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 498 resolved cases

Office Action

§103
DETAILED ACTION This communication is in respond to applicant’s response filed on June 26, 2026. Claims 1-8 and 10-21 are pending. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments with respect to amended claims have been fully considered but are moot in view of the new ground(s) of rejection. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 8, 12, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng et al. (US PG-PUB No. 2022/0345459 A1, hereinafter Tseng) in view of Stevens et al. (US PG-PUB No. 2015/0373032 A1, hereinafter Stevens). As per claim 1, Tseng disclosed a system comprising: a microprocessor; and a computer readable medium, coupled with the microprocessor and comprising microprocessor readable and executable instructions (Tseng, Abstract, Fig. 1, and claim 1, a system for mitigating a threat associated with network data packets) that, when executed by the microprocessor, cause the microprocessor to: receive an indication of a user being authenticated (Tseng, par 0036-0037, “The method 300 may commence with receiving from a client, by the authentication server, a request for access to the server at operation 305…. The method 300 may further include authenticating the client by the authentication server at operation 310. In an example embodiment, the authentication may include logging in by the client into the authentication server, i.e., authenticating the login request based on data provided in the login request.”); in response to receiving the indication of the user being authenticated, associating a first watermark with the user (Tseng, par 0037, “Upon the authentication, the authentication server may send an authentication token to the client.”); send the first watermark to a communication device of the user (Tseng, par 0037, “Upon the authentication, the authentication server may send an authentication token to the client.”), wherein the communication device of the user embeds the watermark into a communication; and send the first watermark to a first routing device on a network (Tseng, par 0038, “The method 300 may continue with receiving, by the mitigation device, from the client, at least one network packet directed to the server at operation 315. The at least one network packet may embed the authentication token.”), wherein the first routing device uses the first watermark embedded in the communication to determine how to route the communication on the network (Tseng, par 0040-0042, “The method 300 may continue at operation 325 with selectively forwarding, by the mitigation device, the at least one network packet to the server based on the validation of the authenticity of the authentication token….the mitigation device validates the authentication token existence on every network packet and forwards only network packets carrying valid authentication tokens (watermarks) to a server/servers (a backend server/servers), while any network packet not matching the compliance requirements is dropped by the mitigation device”, the mitigation device corresponds to the claimed routing device); Tseng does not explicitly disclose wherein the first watermark is at least one of: embedded in in an unused field in a header, embedded in an undefined field in a header, embedded in in a user defined field in a header and inserted into an extra field/header, however, in an analogous in securing network using watermarks, Stevens disclosed wherein the watermark is inserted into an extra field/header (Stevens, ¶0028, “The watermark can be inserted into a Session Initiation Protocol (SIP) header, an H.323 header, an H.264 header, an H.322 header, and/or the like. The watermark can be inserted into the header by adding an additional field(s) or replacing a field (or portion of a field).”); It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the system of Tseng to incorporate inserting the watermark into a protocol header by adding an additional field as disclosed by Stevens, in order to verify that the communication session is legitimate and does not pose a security breach (Stevens, ¶0004), thereby providing an additional layer of security for network communications. As per claim 8, Tseng-Stevens disclosed the system of claim 1, wherein the communication device of the user is a proxy server (Tseng, Fig. 1, Mitigation Device 220, and par 0028, mitigation device 220 selectively forwarding traffic on behalf of the server 115 based on authentication token, i.e., the mitigation device is the equivalent of a proxy server). Claim 12 recites substantially the same limitations as claim 1, in the form of a method implemented by the corresponding system, therefore, it is rejected under the same rationale. Claim 20 recites substantially the same limitations as claim 1, in the form of a computer readable medium with instructions for implementing functions of the corresponding system, therefore, it is rejected under the same rationale. Claim(s) 2 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng in view of Stevens as applied to claim 1 above, and further in view of Chitrapu et al. (US PG-PUB No. 2005/0154925 A1, hereinafter Chitrapu). As per claim 2, Tseng-Stevens disclosed the system of claim 1; Tseng does not explicitly disclose authenticating the user comprises authenticating the user at a first authentication level of a plurality of authentication levels associated with the user and wherein a second authentication level of the plurality of authentication levels has a second watermark associated with the user; however, in an analogous in secure network communication using watermarks, Chitrapu disclosed the concept of associating different watermarks with different security levels (Chitrapu, par 0069, “In an embodiment, different watermarks/signatures/encryption codes are used at various security levels. At low security levels, simple watermarks/signatures/encryption codes may be used, such as only WEP or GSM based. At higher levels of security, more complex watermarks/signatures/encryption codes may be used, such as using TRU specific tokens/keys to produce them. At the highest levels of security, complex watermarks/signatures/encryption codes may be used, such as using multiple TRU specific tokens/keys on multiple abstraction layers and other information. Additionally, wireless users at the highest security levels may be asked frequently to re-authenticate themselves.”); it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the system of Tseng to incorporate the using different watermarks for different security levels as disclosed by Chitrapu, in order to efficiently manage resource based on desired security level (Chitrapu, par 0067). Claim 13 recites substantially the same limitations as claim 2, in the form of a method implemented by the corresponding system, therefore, it is rejected under the same rationale. Claim(s) 3, 14 and 21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng in view of Stevens as applied to claim 1 above, and further in view of Chaubey et al. (US PG-PUB No. 2021/0306276 A1, hereinafter Chaubey). As per claim 3, Tseng-Stevens disclosed the system of claim 1, wherein the first watermark has at least one associated routing factor (Tseng, par 0039, “…the shared token generation algorithm stipulates using “token-authentication-formula md5_Salt-SrcIp-SrcPort-DstIp-DstPort,” there is a client at 1.1.1.1:1111 address that wants to talk to the server at 192.168.1.1.1:53 address, and a current hash salt value is 123456. When the authentication server receives a login request from the client, the authentication server computes an authentication token as md5(123456-1.1.1.1-1111-192.168.1.11-53) and truncates the authentication token to 32 bits.”, i.e., the token is generated based on source and destination IP address and port which are routing factors); Tseng does not explicitly disclose wherein the at least one associated routing factor comprises at least one of: an internal routing, and an external routing; however, in an analogous art in network communication control, Chaubey disclosed implementing network policies using routing factor, where the routing factor comprises at least one of: an internal routing, and an external routing (Chaubey, par 0083, “…The one or more policy rule configurations may include one or more policy fields. A policy field may be associated with one or more aspects used to define policy information (e.g., information that can be used to define the network traffic that the policy rule applies to and define how a firewall is to handle the network traffic that the policy rule applies to). Examples of policy fields may include a field relating to a source zone of the network traffic (e.g., internal to the network, external to the network, and/or the like), a field relating to a destination zone of the network traffic (e.g., internal to the network, external to the network, and/or the like), a field relating to a source address associated with the network traffic (such as an IP address), a field relating to a destination address associated with the network traffic (such as an IP address), a field related to a user associated with the network a field relating to a port associated with the network traffic, a field relating to an application associated with the network traffic (e.g., which application(s) the policy information applies to), a field relating to an application feature associated with the network traffic (e.g., which application feature(s) the policy information applies to)…”); therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the system of Tseng that generates watermark using information include routing factors, to further incorporate routing factors such as network traffic zones such as internal or external traffic of network as disclosed by Chaubey, in order to allow additional ways for implementing network policies based on the routing factors (Chaubey, par 0083). Claim 14 recites substantially the same limitations as claim 3, in the form of a method implemented by the corresponding system, therefore, it is rejected under the same rationale. Claim 21 recites substantially the same limitations as claim 3, in the form of a computer readable medium with instructions for implementing functions of the corresponding system, therefore, it is rejected under the same rationale. Claim(s) 4 and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng in view of Stevens as applied to claim 1 above, and further in view of Lee (US PG-PUB No. 2020/0358744 A1, hereinafter Lee). As per claim 4, Tseng-Stevens disclosed the system of claim 1, wherein the communication is a communication session (Tseng, par 0041, “In an example embodiment, the authentication token may be valid for a single session associated with the client, for example, for a current login of the user into the authentication server. In further example embodiments, the authentication token may be valid for a plurality of sessions associated with the client (i.e., for the current session and further sessions (e.g., further logins of the client into the authentication server) within predetermined period of time)”), wherein the first watermark has a routing factor associated the communication session (Tseng, par 0039, “…the shared token generation algorithm stipulates using “token-authentication-formula md5_Salt-SrcIp-SrcPort-DstIp-DstPort,” there is a client at 1.1.1.1:1111 address that wants to talk to the server at 192.168.1.1.1:53 address, and a current hash salt value is 123456. When the authentication server receives a login request from the client, the authentication server computes an authentication token as md5(123456-1.1.1.1-1111-192.168.1.11-53) and truncates the authentication token to 32 bits.”, i.e., the token is generated based on source and destination IP address and port); Tseng does not explicitly disclose a setup message, ….and wherein the first routing device allows the communication session if the setup message contains the first watermark; however, in an analogous art in secure communication using embedded watermark/token, Lee disclosed the concept of embedding token in setup message of communication and a routing device allows the communication session if the setup message contains the token (Lee, par 0055, “Firewall A 312 may verify the token of a received packet for initial requests for a communication session or flow (such as the packets used to establish a TCP connection) or for all received packets for transmission through the firewall. Firewall B 318 may similarly verify tokens of received packets or may ignore tokens once a communication session is established between two applications.”); it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the system of Tseng to incorporate the setup message and traffic verification as disclosed by Lee, in order to ensure only authorized communication can be established (Lee, par 0055). Claim 15 recites substantially the same limitations as claim 4, in the form of a method implemented by the corresponding system, therefore, it is rejected under the same rationale. Claim(s) 5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng in view of Stevens as applied to claim 1 above, and further in view of Akhter et al. (US Pat. No. 8,730,983 B1, hereinafter Akhter). As per claim 5, Tseng-Stevens disclosed the system of claim 1, Tseng does not explicitly disclose the first watermark applies to a first type of communication and wherein the first routing device restricts specific communications associated with the first type of communication and routes all other types of communications; however, in an analogous art in traffic management using packet watermarking, Akhter disclosed the first watermark applies to a first type of communication and wherein the first routing device restricts specific communications associated with the first type of communication and routes all other types of communications (Akhter, Abstract, “Backpressure based on ingress watermarks for different packet types is disclosed. Use of a circular-reorder queue (CRQ) for both ingress and egress allows packet reordering and packet passing”, col. 3, lines 42-52, link-partner backpressure generation based on configurable watermarks); it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the system of Tseng to incorporate the configurable watermarks based on packet types as disclosed by Akhter, in order to optimize throughput as suggested by Akhter (Akhter, col. 1, lines 26-31). Claim(s) 6 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng in view of Stevens as applied to claim 1 above, and further in view of Watson et al. (US Pat. No. 6,775,704 B1 hereinafter Watson) and Akhter et al. (US Pat. No. 8,730,983 B1, hereinafter Akhter). As per claim 6, Tseng-Stevens disclosed the system of claim 1, Tseng does not explicitly disclose the network comprises a private network and an external network, wherein the first watermark comprises a plurality of watermarks, and wherein the plurality of watermarks comprises an internal watermark for the private network and an external watermark for the external network; however, in an analogous art in secure network communication, Watson disclosed separating internal network and external network, and use token for identifying authenticated traffic (Watson, col. 6, lines 11-27, “….the system 60 is placed at or in front of a boundary separating an internal network from an external network so all service-related traffic can be checked by the authentication application 63. Internal packets 65 and external packets 64 efficiently pass through the system 60. No internal state is maintained by the system 60. Internal packets 65 containing recognized service requests are intercepted and a token is generated based on data contained within the request packet. The token is included with the request packet and forwarded as an external packet 64”); Further, Akhter disclosed the concept of using different watermarks for different packet types (Akhter, Abstract, “Backpressure based on ingress watermarks for different packet types is disclosed. Use of a circular-reorder queue (CRQ) for both ingress and egress allows packet reordering and packet passing”, col. 3, lines 42-52, link-partner backpressure generation based on configurable watermarks); it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the system of Tseng to incorporate the separation of internal network and external network as disclosed by Watson, and the configurable watermarks based on packet types as disclosed by Akhter, in order to prevent unauthorized traffic as suggested by Watson (Watson, col. 6, lines 11-27) and optimize throughput as suggested by Akhter (Akhter, col. 1, lines 26-31). Claim 16 recites substantially the same limitations as claim 6, in the form of a method implemented by the corresponding system, therefore, it is rejected under the same rationale. Claim(s) 7 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng in view of Stevens, Watson and Akhter as applied to claim 6 above, and further in view of Gluck (US PG-PUB No. 2016/0269360 A1, hereinafter Gluck). As per claim 7, Tseng-Stevens-Watson-Akhter disclosed the system of claim 6, Tseng does not explicitly disclose the first watermark is removed by a firewall when the communication is sent to the external network and wherein a second routing device on the external network uses the second watermark for routing the communication on the external network; however, in an analogous art in secure network communication, Gluck disclosed the first watermark is removed by a firewall when the communication is sent to the external network (Gluck, par 0029, “…the firewall agent (i.e., the agent in the component sensing the events on a sub-systems)….can remove the token before forwarding the request….”); Watson further disclose a second routing device on the external network uses the second watermark for routing the communication on the external network (Watson, col. 6, lines 11-27, separating internal network and external network, and use token for identifying authenticated traffic); it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the system of Tseng to further incorporate the removal of token before forwarding request as disclosed by Gluck, and the separation of internal network and external network as disclosed by Watson, in order to prevent unauthorized traffic as suggested by Watson (Watson, col. 6, lines 11-27). Claim 17 recites substantially the same limitations as claim 7, in the form of a method implemented by the corresponding system, therefore, it is rejected under the same rationale. Claim(s) 10 and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng in view of Stevens as applied to claim 1 above, and further in view of Bartsch (US PG-PUB No. 2008/0133932 A1, hereinafter Bartsch). As per claim 10, Tseng-Stevens disclosed the system of claim 1; Tseng does not explicitly disclose the first watermark comprises a plurality of watermarks and wherein the plurality of watermarks are generated by a plurality of watermark servers that each require a separate authentication by the user or a separate authentication by a plurality of users; in an analogous art in secure network communication, Bartsch disclosed the first watermark comprises a plurality of watermarks and wherein the plurality of watermarks are generated by a plurality of watermark servers that each require a separate authentication by the user or a separate authentication by a plurality of users (Bartsch, par 0036, “….a watermark application 131 according to the invention can use a plurality of watermarks for checking 152 and marking 151, the choice of a certain watermark being made dependent on certain properties of the data, e.g. on the data type (e.g. document type, audio or video data, picture data, executable program data, etc), or for different types of access, accessing persons, or terminals different watermarks can be used”, i.e., watermark differs based on properties include different accessing persons (read: a separate authentication by a plurality of users)); it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the system of Tseng to incorporate the choice of watermark based on data properties such as different types of access and accessing persons as disclosed by Bartsch, in order to reduce risk of data misuse (Bartsch, par 0020). Claim 18 recites substantially the same limitations as claim 10, in the form of a method implemented by the corresponding system, therefore, it is rejected under the same rationale. Claim(s) 11 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tseng in view of Stevens as applied to claim 1 above, and further in view of Bellipady et al. (Us PG-PUB No. 2005/0138365 A1, hereinafter Bellipady). As per claim 11, Tseng-Stevens disclosed the system of claim 1; Tseng does not explicitly receive an indication that the user is no longer authenticated; and in response to receiving the indication that the user is no longer authenticated, send a message to the first routing device that the first watermark is no longer valid; however, in an analogous art in secure network communications, Bellipady disclosed receive an indication that the user is no longer authenticated; and in response to receiving the indication that the user is no longer authenticated, send a message to the first routing device that the first watermark is no longer valid (Bellipady, par 0010, “The OCSP server transmits an OCSP request that includes a service request and the certificate to be validated, to a corresponding CRL. Based on the CRL, the OCSP server receives a response that the certificate is current, expired or unknown. The OCSP server then transmits this response…”); it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the system of Tseng to incorporate the concept of access revocation as disclosed by Bellipady, in order to ensure traffic can only be forwarded while access rights are still valid. Claim 19 recites substantially the same limitations as claim 11, in the form of a method implemented by the corresponding system, therefore, it is rejected under the same rationale. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Moskowitz (US PG-PUB No. 2003/0200439 A1) disclosed a method and system for packet watermarking and efficient provisioning of bandwidth. Evans et al. (US Pat. No. 12,249,344 B1) disclosed a method and system for encoding audio watermarks with frequency extensions to enable enhanced watermark detection. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Linglan Edwards whose telephone number is (571)270-5440. The examiner can normally be reached 8:30am - 5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

Show 8 earlier events
Nov 10, 2025
Response Filed
Dec 17, 2025
Final Rejection mailed — §103
Feb 11, 2026
Response after Non-Final Action
Feb 19, 2026
Request for Continued Examination
Mar 06, 2026
Response after Non-Final Action
Apr 28, 2026
Non-Final Rejection mailed — §103
Jul 24, 2026
Response Filed
Sep 10, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12432179
VIRTUAL FIREWALL CONSTRUCTION METHOD BASED ON OPENSTACK FRAMEWORK
2y 6m to grant Granted Sep 30, 2025
Patent 12235960
BEHAVIORAL THREAT DETECTION DEFINITION AND COMPILATION
2y 11m to grant Granted Feb 25, 2025
Patent 12224983
Detecting and Preventing Transmission of Spam Messages Using Modified Source Numbers
3y 8m to grant Granted Feb 11, 2025
Patent 12223023
AUTHENTICATION SYSTEM, AUTHENTICATION APPARATUS, AUTHENTICATION METHOD AND COMPUTER PROGRAM
2y 11m to grant Granted Feb 11, 2025
Patent 12219060
ACCESS POLICY TOKEN
2y 9m to grant Granted Feb 04, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

6-7
Expected OA Rounds
70%
Grant Probability
94%
With Interview (+23.9%)
3y 4m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 498 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month