DETAILED ACTION
This action is responsive to communications filed on March 2, 2026. This action is made Non-Final.
Claims 1-20 are pending in the case.
Claims 1, 19, and 20 are independent claims.
Claims 1-20 are rejected.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea (mental process) without significantly more.
Regarding claim 1, in Step 1 of the 101-analysis set forth in MPEP 2106, the claim recites “A computer-implemented method”. A method is one of the four statutory categories of invention.
In Step 2a Prong 1 of the 101-analysis set forth in the MPEP 2106, the examiner has determined that the following limitations recite a process that, under the broadest reasonable interpretation, covers a mental process but for recitation of generic computer components:
“monitoring activity associated with a user” (A person can mentally evaluate a user and make a judgement to monitor their activity (MPEP 2106).)
“determining, using… the monitored activity of the user, that the user will need to access an asset that the user does not currently have access to” (A person can mentally evaluate the monitored activity of the user and make a judgement to determine they will need to access an asset they do not currently have access to (MPEP 2106).)
If claim limitations, under their broadest reasonable interpretation, covers performance of the limitations as a mental process but for the recitation of generic computer components, then it falls within the mental process grouping of abstract ideas. According, the claim “recites” an abstract idea.
In Step 2a Prong 2 of the 101-analysis set forth in MPEP 2106, the examiner has
determined that the following additional elements do not integrate this judicial exception into a
practical application:
“A computer-implemented method” (Uses a computer as a tool to perform an abstract idea (MPEP 2106.05(f)).)
“…using a trained machine learning model…” (Mere instructions to apply the judicial exception (MPEP 2106.05(f)).)
“the trained machine learning model trained with a plurality of previous workflows and associated access privileges required for the previous workflows” (Generally linking the use of the judicial exception to a particular technological environment or field of use (MPEP 2106.05(h)).)
“assigning an access privilege to the user, wherein the user is thereafter able to access to the asset” (Mere instructions to apply the judicial exception (MPEP 2106.05(f)).)
Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is “directed” to an abstract idea.
In Step 2b of the 101-analysis set forth in the 2019 PEG, the examiner has determined that the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
As discussed above, additional element (iii) recites use of a computer as a tool to perform the abstract idea, which is not indicative of significantly more. Additional elements (iv) & (vi) recite mere instructions to apply the judicial exception, which is not indicative of significantly more. Additional element (v) recites generally linking the use of a judicial exception to a particular technological environment or field of use, which is not indicative of significantly more. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 2, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 2 recites the following additional mental process:
“wherein determining… that the user will need access to the asset comprises learning a workflow of the user based on the monitored activity of the user” (A person can mentally evaluate the monitored activity of a user’s workflow and make a judgement to learn its patterns based on that (MPEP 2106).)
Further, claim 2 recites “…by the trained machine learning model…” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 3, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 3 recites the following additional mental process:
“wherein determining… that the user will need to access the asset comprises reviewing the history of the activity associated with the user” (A person can mentally evaluate the history of the activity associated with the user and make a judgement to determine that the user will need access to an asset they do not currently have access to (MPEP 2106).)
Further, claim 3 recites “wherein monitoring activity associated with the user comprises storing in a database a history of activity associated with the user” (In step 2A, prong 2, this recites insignificant extra-solution activity (mere data storage) to the judicial exception (MPEP 2106.05(g).) In step 2B, the courts have found steps that store and retrieve information in memory to be a well-understood, routine, and conventional activity, which is not indicative of significantly more (Storing and retrieving information in memory, Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015)).)
Further, claim 3 recites “…by the trained machine learning model…” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 4, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 4 recites the following additional mental process:
“wherein determining… that the user will need to access the asset is based on the user being denied access to the asset” (A person can mentally evaluate a user being denied access to an asset and make a judgement to determine the user needs access to that asset (MPEP 2106).)
Further, claim 3 recites “…by the trained machine learning model…” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 5, it is dependent upon claim 4, and thereby incorporates the limitations of, and corresponding analysis applied to claim 4. Further, claim 5 recites the following additional mental process:
“wherein determining… that the user will need to access the asset comprises tracing back through a history of activity associated with the user to determine one or more operations the user performed prior to being denied access to the asset” (A person can mentally evaluate the history of activity associated with a user, particularly the operations prior to being denied access to an asset, and make a judgement to determine that the user will need access to the asset based on that (MPEP 2106).)
Further, claim 5 recites “…by the trained machine learning model…” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 6, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 6 recites the following additional mental process:
“wherein determining… that the user will need to access the asset comprises identifying a previous workflow from the plurality of previous workflows based on the monitored activity of the user, wherein the identified previous workflow has an access privilege to the asset” (A person can mentally evaluate the monitored activity of a user and make a judgement to identify a previous workflow from the plurality of previous workflows, wherein the that workflow has an access privilege to the asset (MPEP 2106).)
Further, claim 6 recites “…by the trained machine learning model…” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Further claim 6 recites “wherein assigning the access privilege to the user comprises assigning the access privilege of the identified previous workflow to the user” (In step 2a, prong 2, this recites generally linking the use of the judicial exception to a particular technological environment or field of use (MPEP 2106.05(h).) In step 2B, generally linking the use of the judicial exception to a particular technological environment or field of use is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 7, it is dependent upon claim 6, and thereby incorporates the limitations of, and corresponding analysis applied to claim 6. Further, claim 7 recites the following additional mental process:
“wherein identifying the previous workflow from the plurality of previous workflows comprises at least one of: correlating the plurality of the previous workflows and the monitored activity associated with the user; or correlating attributes of the plurality of the previous workflows and attributes of the user.” (A person can mentally evaluate the plurality of previous workflows and make a judgement to identify a previous workflow based on a correlation with the monitored activity of the user and the attributes of each (MPEP 2106).)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 8, it is dependent upon claim 6, and thereby incorporates the limitations of, and corresponding analysis applied to claim 6. Further, claim 8 recites the following additional mental process:
“wherein the identified previous workflow has at least one trigger that matches at least one trigger identified from the monitored activity of the user” (A person can mentally evaluate a workflow and make a judgement to determine that it has at least one trigger matching at least one trigger in the monitored activity (MPEP 2106).)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 9, it is dependent upon claim 6, and thereby incorporates the limitations of, and corresponding analysis applied to claim 6. Further, claim 9 recites the following additional mental process:
“wherein the identified previous workflow has at least one attribute that matches at least one attribute associated with the user” (A person can mentally evaluate a workflow and make a judgement to determine that it has at least one attribute matching at least one attribute of the user (MPEP 2106).)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 10, it is dependent upon claim 6, and thereby incorporates the limitations of, and corresponding analysis applied to claim 6. Further, claim 10 recites “wherein assigning the access privilege of the identified previous workflow to the user comprises assigning the identified previous workflow to the user” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 11, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 11 recites the following additional mental processes:
“monitoring activity associated with a plurality of other users” (A person can mentally evaluate a plurality of users and make a judgement to monitor their activity (MPEP 2106).)
“learning… using the monitored activity of the plurality of other users, a workflow of one or more of the plurality of other users based on the monitored activity of the plurality of other users, the learned workflow of the other users having an access privilege to the asset” (A person can mentally evaluate the monitored activity of a plurality of users and make a judgement to learn a workflow associated with one or more of them that has access to a particular asset (MPEP 2106).)
“wherein determining… that the user will need access to the asset comprises identifying the learned workflow of the other users” (A person can mentally evaluate the learned workflow of other users who have access to a particular asset in comparison to another user without that access and make a judgement to determine that user will need access to that asset (MPEP 2106).)
Further, claim 11 recites “…by the trained machine learning model…” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Further, claim 11 recites “wherein assigning the access privilege to the user comprises assigning the learned workflow of the other users to the user” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 12, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 12 recites “wherein assigning the access privilege to the user comprises updating a workflow associated with the user with the access privilege” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 13, it is dependent upon claim 12, and thereby incorporates the limitations of, and corresponding analysis applied to claim 12. Further, claim 13 recites “wherein the workflow is updated to include the access privilege as an action associated with a trigger in the workflow” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 14, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 14 recites “wherein the access privilege is assigned to the user prior to the user needing access to the asset” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 15, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 15 recites “wherein the access privilege is assigned to the user for a limited time” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 16, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 16 recites “wherein monitoring activity associated with the user comprises detecting a trigger initiated by at least one of a device associated with the user or an action of the user” (In step 2a, prong 2, this recites generally linking the use of the judicial exception to a particular technological environment or field of use (MPEP 2106.05(h).) In step 2B, generally linking the use of the judicial exception to a particular technological environment or field of use is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 17, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 17 recites “wherein the asset is at least one of a physical asset or a logical asset” (In step 2a, prong 2, this recites generally linking the use of the judicial exception to a particular technological environment or field of use (MPEP 2106.05(h).) In step 2B, generally linking the use of the judicial exception to a particular technological environment or field of use is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 18, it is dependent upon claim 1, and thereby incorporates the limitations of, and corresponding analysis applied to claim 1. Further, claim 18 recites “training a machine learning model to obtain the trained machine learning model, wherein the machine learning model is trained with the plurality of previous workflows and associated access privileges required for the previous workflows, and wherein at least one of the previous workflows was completed by a previous user” (In step2A, prong 2, this recites mere instructions to apply the judicial exception (MPEP 2106.05(f).) In step 2B, mere instructions to apply the judicial exception is not indicative of significantly more.)
Since the claim does not recite additional elements that either integrate the judicial exception into a practical application, nor provide significantly more than the judicial exception, the claim is not patent eligible.
Regarding claim 19, in Step 1 of the 101-analysis set forth in MPEP 2106, the claim recites “A system comprising: a processor; and non-transitory memory”. A system of the described configuration is within one of the four statutory categories of invention.
In Step 2a Prong 1 of the 101-analysis set forth in the MPEP 2106, the examiner has determined that the following limitations recite a process that, under the broadest reasonable interpretation, covers a mental process but for recitation of generic computer components:
“monitor activity associated with a user” (A person can mentally evaluate a user and make a judgement to monitor their activity (MPEP 2106).)
“determine, using… the monitored activity of the user, that the user will need to access an asset that the user does not currently have access to” (A person can mentally evaluate the monitored activity of the user and make a judgement to determine they will need to access an asset they do not currently have access to (MPEP 2106).)
If claim limitations, under their broadest reasonable interpretation, covers performance of the limitations as a mental process but for the recitation of generic computer components, then it falls within the mental process grouping of abstract ideas. According, the claim “recites” an abstract idea.
In Step 2a Prong 2 of the 101-analysis set forth in MPEP 2106, the examiner has
determined that the following additional elements do not integrate this judicial exception into a
practical application:
“A system comprising: a processor; and non-transitory memory coupled to the processor, the memory containing a set of instructions thereon that when executed by the processor cause the processor to…” (Uses a computer as a tool to perform an abstract idea (MPEP 2106.05(f)).)
“…using a trained machine learning model…” (Mere instructions to apply the judicial exception (MPEP 2106.05(f)).)
“the trained machine learning model trained with a plurality of previous workflows and associated access privileges required for the previous workflows” (Generally linking the use of the judicial exception to a particular technological environment or field of use (MPEP 2106.05(h)).)
“assign an access privilege to the user, wherein the user is thereafter able to access to the asset” (Mere instructions to apply the judicial exception (MPEP 2106.05(f)).)
Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is “directed” to an abstract idea.
In Step 2b of the 101-analysis set forth in the 2019 PEG, the examiner has determined that the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
As discussed above, additional element (iii) recites use of a computer as a tool to perform the abstract idea, which is not indicative of significantly more. Additional elements (iv) & (vi) recite mere instructions to apply the judicial exception, which is not indicative of significantly more. Additional element (v) recites generally linking the use of a judicial exception to a particular technological environment or field of use, which is not indicative of significantly more. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Regarding claim 20, in Step 1 of the 101-analysis set forth in MPEP 2106, the claim recites “A non-transitory processor readable medium”. A non-transitory medium is within one of the four statutory categories of invention.
In Step 2a Prong 1 of the 101-analysis set forth in the MPEP 2106, the examiner has determined that the following limitations recite a process that, under the broadest reasonable interpretation, covers a mental process but for recitation of generic computer components:
“monitor activity associated with a user” (A person can mentally evaluate a user and make a judgement to monitor their activity (MPEP 2106).)
“determine, using… the monitored activity of the user, that the user will need to access an asset that the user does not currently have access to” (A person can mentally evaluate the monitored activity of the user and make a judgement to determine they will need to access an asset they do not currently have access to (MPEP 2106).)
If claim limitations, under their broadest reasonable interpretation, covers performance of the limitations as a mental process but for the recitation of generic computer components, then it falls within the mental process grouping of abstract ideas. According, the claim “recites” an abstract idea.
In Step 2a Prong 2 of the 101-analysis set forth in MPEP 2106, the examiner has
determined that the following additional elements do not integrate this judicial exception into a
practical application:
“A non-transitory processor readable medium containing a set of instructions thereon that when executed by a processor cause the processor to…” (Uses a computer as a tool to perform an abstract idea (MPEP 2106.05(f)).)
“…using a trained machine learning model…” (Mere instructions to apply the judicial exception (MPEP 2106.05(f)).)
“the trained machine learning model trained with a plurality of previous workflows and associated access privileges required for the previous workflows” (Generally linking the use of the judicial exception to a particular technological environment or field of use (MPEP 2106.05(h)).)
“assign an access privilege to the user, wherein the user is thereafter able to access to the asset” (Mere instructions to apply the judicial exception (MPEP 2106.05(f)).)
Since the claim as a whole, looking at the additional elements individually and in combination, does not contain any other additional elements that are indicative of integration into a practical application, the claim is “directed” to an abstract idea.
In Step 2b of the 101-analysis set forth in the 2019 PEG, the examiner has determined that the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
As discussed above, additional element (iii) recites use of a computer as a tool to perform the abstract idea, which is not indicative of significantly more. Additional elements (iv) & (vi) recite mere instructions to apply the judicial exception, which is not indicative of significantly more. Additional element (v) recites generally linking the use of a judicial exception to a particular technological environment or field of use, which is not indicative of significantly more. Considering the additional elements individually and in combination, and the claim as a whole, the additional elements do not provide significantly more than the abstract idea. Therefore, the claim is not patent eligible.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-10 and 12-20 is/are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Geusz et al., US Patent 11,159,511 (“Geusz”).
Claim 1:
Geusz discloses a computer-implemented method comprising:
monitoring activity associated with a user (see Fig. 1, 2; col. 3, lines 35-40 - receiving, by the one or more computers, data indicating a current context of a client device associated with a particular user; accessing, by the one or more computers, first authentication data that demonstrates that the particular user has been authenticated using a first authentication protocol; col. 6, lines 55-63 - perform an analysis on previous and current context data corresponding to the user. In particular, the management server 108 can retrieve previous and current context data stored in the historical data database 112. The management server 108 can analyze the previous and current context data to determine trends, frequency patterns, and other statistical measures that provide an indication as to what service the user is likely to pick; col. 8, lines 25-30 - data 5 indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis; col. 8, lines can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection.);
determining, using a trained machine learning model and the monitored activity of the user, that the user will need access to an asset that the user does not currently have access to, the trained machine learning model trained with a plurality of previous workflows and associated access privileges required for the previous workflows (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 45-49 - previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance.); and
assigning an access privilege to the user, wherein the user is thereafter able to access the asset (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 41-65 - a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. anagement server 108 can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-12 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request; col. 15, lines 35-53 - before the management server 108 receives requests, e.g., negotiating authenticated sessions with the KOC 110 and storing tokens/tickets for the authenticated sessions even before the user requests access to a service, the delay is reduced once the user does request access to the service. Previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance. Predictively initiate or maintain authentication for a user.).
Claim(s) 19 and 20:
Claim(s) 19 and 20 correspond to Claim 1, and thus, Geusz discloses the limitations of claim(s) 19 and 20 as well.
Claim 2:
Geusz further discloses wherein determining by the trained machine learning model that the user will need access to the asset comprises learning a workflow of the user based on the monitored activity of the user (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 45-49 - previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance.).
Claim 3:
Geusz further discloses wherein monitoring activity associated with the user comprises storing in a database a history of activity associated with the user, and wherein determining by the trained machine learning model that the user will need to access the asset comprises reviewing the history of the activity associated with the user (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 45-49 - previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance.).
Claim 4:
Geusz further discloses wherein determining by the trained machine learning model that the user will need access to the asset is based on the user being denied access to the asset (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service; col. 15, lines 45-48 - previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance; col. 21, lines 33-42 - data corresponding to the previous requests made by the user can include whether the request resulted in a successful or unsuccessful connection to the requested service, a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device, private and public keys corresponding to the requested service, the physical characteristics of the client device at the time the user requested and the physical characteristics of the client device at the time the user was granted access to the service or not granted access to the service.).
Claim 5:
Geusz further discloses wherein determining by the trained machine learning model that the user will need to access the asset comprises tracing back through a history of activity associated with the user to determine one or more operations the user performed prior to being denied access to the asset (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service … and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service; col. 21, lines 33-42 - data corresponding to the previous requests made by the user can include whether the request resulted in a successful or unsuccessful connection to the requested service … and the physical characteristics of the client device at the time the user was granted access to the service or not granted access to the service.).
Claim 6:
Geusz further discloses wherein determining by the trained machine learning model that the user will need access to the asset comprises identifying a previous workflow from the plurality of previous workflows based on the monitored activity of the user, wherein the identified previous workflow has an access privilege to the asset, and wherein assigning the access privilege to the user comprises assigning the access privilege of the identified previous workflow to the user (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 35-53 - before the management server 108 receives requests, e.g., negotiating authenticated sessions with the KOC 110 and storing tokens/tickets for the authenticated sessions even before the user requests access to a service, the delay is reduced once the user does request access to the service. Previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance. Predictively initiate or maintain authentication for a user.).
Claim 7:
Geusz further discloses wherein identifying the precious workflow from the plurality of previous workflows comprises at least one of: correlating the plurality of previous workflows and the monitored activity associated with the user; or correlating attributes of the plurality of previous workflows and attributes of the user (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 35-53 - before the management server 108 receives requests, e.g., negotiating authenticated sessions with the KOC 110 and storing tokens/tickets for the authenticated sessions even before the user requests access to a service, the delay is reduced once the user does request access to the service. Previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance. Predictively initiate or maintain authentication for a user.).
Claim 8:
Guesz further discloses wherein the identified previous workflow has at least one trigger that matches at least one trigger identified from the monitored activity of the user (see Fig. 1, 2; col. 7, lines 3-14 - When the context is detected again, the management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity). Based on the location context and history of accesses, when the management server 108 detects that the client device 104 returns to that context (e.g., the 20 particular location), the management server 108 can automatically authenticate the user and create an authenticated session for the authentication protocol(s) that are needed to access the particular secured network resource; col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 35-53 - before the management server 108 receives requests, e.g., negotiating authenticated sessions with the KOC 110 and storing tokens/tickets for the authenticated sessions even before the user requests access to a service, the delay is reduced once the user does request access to the service. Previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance. Predictively initiate or maintain authentication for a user.).
Claim 9:
Geusz further discloses wherein the identified previous workflow has at least one attribute that matches at least one attribute associated with the user (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 35-53 - before the management server 108 receives requests, e.g., negotiating authenticated sessions with the KOC 110 and storing tokens/tickets for the authenticated sessions even before the user requests access to a service, the delay is reduced once the user does request access to the service. Previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance. Predictively initiate or maintain authentication for a user.).
Claim 10:
Geusz discloses wherein assigning the access privilege of the identified previous workflow the user comprises assigning the identified previous workflow to the user (see Fig. 1, 2; col. 7, lines 3-24 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similar ity). Based on the location context and history of accesses, when the management server 108 detects that the client device 104 returns to that context (e.g., the 20 particular location), the management server 108 can automatically authenticate the user and create an authenticated session for the authentication protocol(s) that are needed to access the particular secured network resource; col. 8, lines 46-65 – retrieves the necessary information from the management database 114 for accessing the predicted service before the user transmits a request for the predicted service. The necessary information can include a user's username, password, key value, any previous tickets, currently pending tickets, and various protocol types corresponding to the user. management server
108 can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device.).
Claim 12:
Geusz discloses wherein assigning the access privilege to the user comprises updating a workflow associated with the user with the access privilege (see col. 7, lines 3-24 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similar ity). Based on the location context and history of accesses, when the management server 108 detects that the client device 104 returns to that context (e.g., the 20 particular location), the management server 108 can automatically authenticate the user and create an authenticated session for the authentication protocol(s) that are needed to access the particular secured network resource; col. 8, lines 46-65 – retrieves the necessary information from the management database 114 for accessing the predicted service before the user transmits a request for the predicted service. The necessary information can include a user's username, password, key value, any previous tickets, currently pending tickets, and various protocol types corresponding to the user. management server 108 can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 12, lines 39-44 - receive an update from the client device 104 corresponding to the user ')ohn," that indicates a change to the data of the user profile 122. Additionally, the management server 108 may receive an update from the key distribution center 110 that indicates a change to the data of the user profile 122; col. 13, lines 15-17 - management server 108 can determine if the stored key in each of the device profiles 120 needs to be updated to the new received key for each respective user.).
Claim 13:
Geusz further discloses wherein the workflow is updated to include the access privilege as an action associated with a trigger in the workflow (see Fig. 1, 2; col. 7, lines 3-14 - When the context is detected again, the management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity). Based on the location context and history of accesses, when the management server 108 detects that the client device 104 returns to that context (e.g., the 20 particular location), the management server 108 can automatically authenticate the user and create an authenticated session for the authentication protocol(s) that are needed to access the particular secured network resource; col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 12, lines 39-44 - receive an update from the client device 104 corresponding to the user ')ohn," that indicates a change to the data of the user profile 122. Additionally, the management server 108 may receive an update from the key distribution center 110 that indicates a change to the data of the user profile 122; col. 13, lines 15-17 - management server 108 can determine if the stored key in each of the device profiles 120 needs to be updated to the new received key for each respective user; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 35-53 - before the management server 108 receives requests, e.g., negotiating authenticated sessions with the KOC 110 and storing tokens/tickets for the authenticated sessions even before the user requests access to a service, the delay is reduced once the user does request access to the service. Previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance. Predictively initiate or maintain authentication for a user.).
Claim 14:
Geusz further discloses wherein the access privilege is assigned to the user prior to the user needing access to the asset (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 41-65 - a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. anagement server 108 can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-12 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request; col. 15, lines 35-53 - before the management server 108 receives requests, e.g., negotiating authenticated sessions with the KOC 110 and storing tokens/tickets for the authenticated sessions even before the user requests access to a service, the delay is reduced once the user does request access to the service. Previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance. Predictively initiate or maintain authentication for a user.).
Claim 15:
Geusz further discloses wherein the access privilege is assigned to the user for a limited time (see col. 4, lines 59-63 - expires within the threshold amount of time, automatically renewing the authentication of the particular user; col. 13, lines 5-8 - the management server 108 may determine that the particular user profile is in need of a new key because its current key has expired; col. 16, lines 14-16 - TGT includes a session key indicated by the KOC 110, an expiration date; col. 19, line 67 - loses authentication, through expiration; col. 21, lines 10-11 - TGT includes a session key indicated by the KDC, an expiration date; Claim 10 - based on determining that authentication of the particular user for the first authentication protocol or the second authentication protocol expires within the threshold amount of time, automatically renewing.).
Claim 16:
Geusz further discloses wherein monitoring activity associated with the user comprises detecting a trigger initiated by at least one of a device associated with the user or an action of the user (see Fig. 1, 2; col. 7, lines 3-14 - When the context is detected again, the management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity). Based on the location context and history of accesses, when the management server 108 detects that the client device 104 returns to that context (e.g., the 20 particular location), the management server 108 can automatically authenticate the user and create an authenticated session for the authentication protocol(s) that are needed to access the particular secured network resource; col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 12, lines 39-44 - receive an update from the client device 104 corresponding to the user ')ohn," that indicates a change to the data of the user profile 122. Additionally, the management server 108 may receive an update from the key distribution center 110 that indicates a change to the data of the user profile 122; col. 13, lines 15-17 - management server 108 can determine if the stored key in each of the device profiles 120 needs to be updated to the new received key for each respective user; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 35-53 - before the management server 108 receives requests, e.g., negotiating authenticated sessions with the KOC 110 and storing tokens/tickets for the authenticated sessions even before the user requests access to a service, the delay is reduced once the user does request access to the service. Previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance. Predictively initiate or maintain authentication for a user.).
Claim 17:
Geusz further discloses wherein the asset is at least one of a physical asset or a logical asset (see col. 5, lines 65-67 - resources may be files, data sources, data bases, applications, web pages, etc., and may be provided within the local network or outside the local network.).
Claim 18:
Geusz further discloses further comprising training a machine learning module to obtain the trained machine learning module, wherein the machine learning model is trained with the plurality of previous workflows and associated access privileges required for the previous workflows, and wherein the at least one of the previous workflows was completed by a previous user (see Fig. 1, 2; col. 7, lines 3-14 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. In other words, after a user has made use of certain authentication protocols in a context, the management server 108 can automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similarity); col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 45-49 - previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance.).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Geusz, and further in view of Toth et al., US Publication 2020/0184049 (“Toth”).
Claim 11:
Guesz further teaches or suggests monitoring activity associated with a plurality of other users; and learning, by the trained machine learning model using the monitored activity of the plurality of other users, a workflow of one or more of the plurality other users based on the monitored activity of the plurality of other users, the learned workflow of the other users having an access privilege to the asset, wherein determining by the trained machine learning model that the user will need access to the asset comprises identifying the learned workflow of the other users, and wherein assigning the access privilege to the user comprises assigning (see Fig. 1, 2; col. 7, lines 3-24 - management server 108 can predictively authenticate the user for the authentication protocol(s) that have been used in that context previously, without the user specifically directing the system to do so. automatically obtain authentication for those authentication protocols when the user is in the same or similar context (e.g., in a context determined to match the previously observed context within a threshold level of similar ity). Based on the location context and history of accesses, when the management server 108 detects that the client device 104 returns to that context (e.g., the 20 particular location), the management server 108 can automatically authenticate the user and create an authenticated session for the authentication protocol(s) that are needed to access the particular secured network resource; col. 8, lines 25-65 - data indicating usage of the client device 104 corresponding with a particular user in the management database 114 for future analysis. can analyze data indicating connections to services that the client device 104 and user 102 previously requested in the past, and the contexts in which those connections were made. The management server 108 can determine whether the request resulted in a successful or unsuccessful connection to the requested service, the type of requested service, the authentication protocol used to connect to the requested service, private and public keys of the client device 104, private and public keys corresponding to the requested service, the physical characteristics of the client device 104 at the time the user 102 requested the service, and the state of the client device 104 at the time the user was granted access to the service or not granted access to the service. provide the context data and the historical data of the client device 104 to a neural network or other machine-learning model to predict which service(s) the user 102 may request access to, or what authentication protocols may be needed. management server can retrieve and store the data for accessing the predicted service. At a later point in time, when the user does in fact transmit the request to the management server 108 for the predicted service, the management server 108 can automatically provide the user with an authenticated session for the service to his/her client device; col. 14. Lines 10-51 - management server 108 can include a neural network to predict a service that a user will request for before receiving the request. train the neural network model using data for each particular user from the management database 114. data can include the context data for each user and corresponding client device 104. The management server 108 can apply this data to train the neural network model each time a new request is received from a client device. In addition, the management server 108 can apply this data to train the neural network model during an offline mode. management server 108 applies the trained neural network model, the management server 108 can apply data from the management database 114 for a particular user to determine one or more services that a user may request; col. 15, lines 45-49 - previous patterns of user requests can be used to selectively determine which authentication protocols and/or resources should have authentication performed predictively in advance.).
Guesz does not explicitly disclose the learned workflow of the other users to the user.
Toth teaches or suggests the learned workflow of the other users to the user (see para. 0021 - enable the machine-learning algorithm to identify potentially malicious authentication requests based on the order, timing, method, and/or other parameters of such requests. machine-learning system may continuously train and/or otherwise update models to account for changes in user behavior over time at both a user-specific level and at a population level (e.g., as new authentication capabilities, such as facial recognition are more widely adopted, and/or the like); para. 0049 - predetermined valid event pattern may be generated by the computing platform based on at least one previous successful login occurrence associated with the first user account; para. 0050 - the predetermined valid event pattern may include valid order data, valid timing data, and valid device data associated with the at least one previous successful login occurrence associated with the first user account; para. 0051 - client authentication computing platform 110 may generate the predetermined valid event pattern based on valid population-level authentication data that may include and/or be determined based on authentication event information associated with a plurality of other users linked to other user accounts (e.g., different from the first user account) maintained by client authentication computing platform 110 and/or account portal computing platform 120; para. 0053 - client authentication computing platform 110 may generate one or more authentication commands (e.g., based on determining that the event pattern more closely matches the valid pattern than the malicious pattern). client authentication computing platform 110 may generate one or more authentication commands directing the account portal computing platform (e.g., account portal computing platform 120) to allow access to the one or more secured information resources associated with the first user account in the first client portal session.).
Accordingly, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Toth with those of Geusz. One would have been motivated to do so for the purpose of efficiently enabling a user to be granted access to secured resources based on other users valid authentication patterns, while monitoring and protecting against malicious patterns, improving authentication processes, as taught by Toth (0021, 0051, 0053).
Response to Arguments
Rejections under 35 USC 101:
Applicant argues the OA is indicating implementing “using a trained machine learning model” in the human mind.
The Examiner respectfully disagrees and notes that the “using a trained machine learning model” is indicated above as an additional element and not part of the indicated abstract idea.
Rejections under 35 USC 102:
Applicant’s further arguments have been considered but are not persuasive because the arguments do not correspond to the rationales as used in the current rejection.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Andrew T McIntosh whose telephone number is (571)270-7790. The examiner can normally be reached M-Th 8:00am-5:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Tamara Kyle can be reached at 571-272-4241. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ANDREW T MCINTOSH/Primary Examiner, Art Unit 2144