Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This office action is responsive to Request for Continued Examination filed on 5/14/2026. Claims 1, 9, and 17 are amended. Claims 2, 10 are previously cancelled. Consequently, claim 1, 3-9, and 11-20 are pending examination.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 3-9, and 11-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
Claim1 is drawn to a system, claim 9 is drawn to a method, claim 17 is drawn to computer program product. As such, claims 1,13, and 17 are drawn to one of the statutory categories of invention.
Step 2A, prong One. The claims recite the abstract idea of managing authorization and approval workflows for requested operations using credential verification and rule-based access control. Specifically, the claims recite, accessing an electronic request and electronic approval, identifying a multi admin verification rule, comparing credentials, determining whether an approval is valid, maintaining and updating an approval state, determining whether a threshold condition is satisfied, and controlling whether a requested operation is permitted t execute. These limitations describe certain methods of organizing human activity, including, commercial or legal interactions (including agreements in the form of contracts; legal obligations; advertising, marketing or sales activities or behaviors; business relations) managing personal behavior or relationships or interactions between people (including social activities, teaching, and following rules or instructions) , supervisory approval process, access authorization and enforcement of approval policies.
Step 2A, Prong two. The claims do not integrate the abstract idea into a practical application. Although the claims recite a ‘multi-admin verification rule”, “approval state”, “data store”, and various software components, these elements merely apply the abstract approval policy using generic computer technology. The claims “verification component” only stores and updates approval status information. The claims “execution components” conditionally permits or prevents execution of an operation based on approval state. These are conventional computer functions involving receiving, storing, updating and processing data. The claims do not recite a specific improvement to computer functionality, a new authentication protocol, an improved cryptographic technique, a specific improvement to database architecture or a technological improvement in how data store operate. Instead, the claims use generic computer components as tools to implement approval and authorization policies.
Step 2B. The claims fail to recite an inventive concept sufficient to transform the abstract idea into patent eligible subject matter. The additional limitations, individually and as an ordered combination, amount to no more than generic computer implementation of approval management logic. Although the specification describes improving security relative to RBAC and MFA systems, the claims themselves only recite the use of authorization rules requiring multiple approvals and prohibiting self-approval before execution of an operation. Such security policies represent abstract decision-making rules rather than a technological improvement to computer system themselves. Accordingly, the claims are directed to an abstract implemented on generic computer technology and therefore are not patent eligible under 35 U.S.C. 101.
Response to Arguments
Applicant's arguments filed have been fully considered but they are not persuasive.
Applicant argues that the amended claims are directed to a specific technological implementation involving maintenance of approval states associated with electronic requests and control of application of data operations to data objects stored in a data store. However, the claims, when considered as a while, remain directed to the abstract idea using generic computer components.
Under Step 2a, Prong one., the claims continue to recite the abstract idea of: receiving requests and approvals, evaluating authorization rules, comparing credentials, tracking approval status, determining whether threshold approval conditions are satisfied and allowing or preventing execution of operations based on those determinations. These limitations describe certain methos of organizing human activity including supervisory authorization and approval workflows.
Applicant argues that the claims are directed to “operation level control” of modifications to stored data. However, adding conditional logic approval steps does not make it patent eligible. The claimed “approval state”, simply represents stored status information reflecting whether approval conditions have been met.
The claims do not recite any specific technological mechanism for improving how computers store data, authenticate credentials, secure communications, or execute operations. Instead, the claims recite generic functional results implemented using generic computer components including processors, memory, computing devices, credentials, and data stores.
Applicant further argues that the claims address technical problem s relating to spoofing, credential misuse, and insider threats. While improving security may account for a technical objective, the claims themselves recite policy-based restriction requiring multiple approvals and prohibiting self-approval before execution of an operation. The claims do not recite a specific improvement to authentication technology, cryptographic validation, network security protocols or a data storage architecture.
Under step 2A, prong two, the claims do not integrate the abstract idea into a practical application. The recited “verification component, “state management component”, and “execution components” perform conventional computer functions such as: receiving electronic information, comparing stored value, updating status information and conditionally permitting execution. These are routine data processing operations performed by generic computer technology.
Applicant reliance on BASCOM is not persuasive. Unlike BOSCAM, the present claims do not recite a specific unconventional technical arrangement that improves computer functionality or network architecture. Instead, the claims merely apply approval and authorization rules within a conventional computing environment.
Applicant also argues that the clams cannot practically be performed mentally or with pen and paper. However, the mere recitation of generic computer implementation does not ender the abstract idea patent eligible. The Courts held that implementing authorization or organizational practices using generic computer technology remains abstract even where the claimed operations are performed electronically.
Under Step 2B, the claims do not recite significantly more than the abstract idea itself. The additional limitations, individually and as an ordered combination, amount to no more than conventional computer implementation of approval management logic. Maintaining an approval state, updating the approval state and controlling execution based on approval status represent routine computer functions associated with access control system. Although applicant characterizes the claims as improving computer security functionality, the claims merely recite the use of the administrative approval rules to decide whether a requested operation is permitted. The claims therefore improve the abstract decision-making policy rather than the function of the computer itself. Accordingly, the claims remain directed to an abstract idea implemented using generic computer components and therefore remain ineligible under 35 U.S.C. 101.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SARGON N NANO whose telephone number is (571)272-4007. The examiner can normally be reached 7:30 AM-3:30 PM. M.S.T..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas Taylor can be reached on 571 272 3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SARGON N NANO/Primary Examiner, Art Unit 2443