Prosecution Insights
Last updated: August 17, 2026
Application No. 18/150,268

CLOUD BASED APPLICATION ACCESS PRIVILEGE GOVERNANCE

Non-Final OA §101§103
Filed
Jan 05, 2023
Examiner
CELANI, NICHOLAS P
Art Unit
2449
Tech Center
2400 — Computer Networks
Assignee
ORACLE INTERNATIONAL Corporation
OA Round
5 (Non-Final)
46%
Grant Probability
Moderate
5-6
OA Rounds
0m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 46% of resolved cases
46%
Career Allowance Rate
213 granted / 463 resolved
-12.0% vs TC avg
Strong +42% interview lift
Without
With
+42.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
37 currently pending
Career history
501
Total Applications
across all art units

Statute-Specific Performance

§101
15.8%
-24.2% vs TC avg
§103
51.0%
+11.0% vs TC avg
§102
3.1%
-36.9% vs TC avg
§112
25.5%
-14.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 463 resolved cases

Office Action

§101 §103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims The following claim(s) is/are pending in this office action: 1, 5, 8-9, 13, 16-17, 21, 23-28 Claim(s) 1, 5, 8-9, 13, 16-17, 21, 23-28 is/are rejected. Applicant’s Invention as Claimed Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim(s) 1, 5, 8-9, 13, 16-17, 21, 23-28 is/are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claim(s) 1, 5, 8-9, 13, 16-17, 21, 23-28 is/are rejected under 35 U.S.C. 101 because the claimed invention is directed to math without significantly more. The claim(s) recite(s) “for the first identity access data, determining a first k value, comprising a first number of clusters value, for use in a k-means clustering algorithm, the determining the first k value comprising: encoding the first identity access data as a first plurality of binary vectors; using the first plurality of binary vectors, determining a first distinct identity access count using min-wise independent permutations locality sensitive hashing scheme and a locality-sensitive hashing; and normalizing the first distinct identity access count, wherein the normalized first distinct identity access count comprises the determined first k value; for the second identity access data, determining a second k value, comprising a second number of clusters value, for use in the k-means clustering algorithm, the determining the second k value comprising: encoding the second identity access data as a second plurality of binary vectors; using the second plurality of binary vectors, determining a second distinct identity access count using min-wise independent permutations locality sensitive hashing scheme and the locality-sensitive hashing; and normalizing the second distinct identity access count, wherein the normalized second distinct identity access count comprises the determined second k value; performing a first peer group analysis using the determined first k value with the k-means clustering algorithm, the first peer group analysis determining anomalies between the identities and corresponding access to the applications for the first identity access data; performing a second peer group analysis using the determined second k value with the k-means clustering algorithm, the second peer group analysis determining anomalies between the identities and corresponding access to the applications for the second identity access data; wherein the first k value comprises a different value than the second k value” which is the act of calculating a k-value for performing a k-means analysis and then performing the k-means analysis. This judicial exception is not integrated into a practical application because the claims merely claim a statistical analysis occurs. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional feature of “retrieving first identity access data and second identity access data, wherein each of the first and second identity access data comprise a plurality of identities, and for each of the identities, a listing of applications that the identity has access to and a corresponding permission level for that application” is insignificant pre-solution data gathering. To the extent that other claims include computer hardware the hardware is conventional. Claims not specifically mentioned are rejected by virtue of dependency and because they do not obviate the above-recited deficiencies. Claim Rejections - 35 USC § 103 A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 8-9, 16-17, and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Badawy (US Pub. 2020/0169603) in view of Shtar (US Pub. 2019/0158513) in view of Howard (US Pub. 2019/0199736) and further in view of Elsner (US Pub. 2019/0349391). With respect to Claim 1, Badawy teaches a method of access privilege governance comprising: (paras. 5, 44-47; identity access management system allows users of a system to have identities for accessing resources of a system.) Retrieving first identity access data and second identity access data, (Second data will be taught later. para. 54; harvester obtains identity management data such as identities.) wherein each of the first and second identity access data comprises a plurality of identities, and for each of the identities, a listing of applications that the identity has access to and a corresponding permission level for that application; (para. 29; users have identities. Identities have entitlements. Entitlements define access to, among other things, applications.) encoding the first identity access data as a first plurality of binary vectors; (para. 60, 63; system graphs identity data including weighing edges between identities as binary vectors.) using the first plurality of binary vectors, determining a first distinct identity access count (para. 67; identities are clustered into peer groups where identities are strongly connected. See also Shtar, para. 94; users are clustered based on access to resources.) and performing a first peer group analysis using the determined first k value with the k-means clustering algorithm, the first peer group analysis determining anomalies between the identities and corresponding access to the applications for the first identity access data. (A determined k value will be taught later. paras. 75-77; cluster groups are analyzed. See also Shtar, para. 111; system determines whether an access to a resource group is suspicious.) But Badawy does not explicitly teach normalization. Shtar, however, does teach for the first identity access data, determining a first k value, comprising a number of clusters value, for use in a k-means clustering algorithm, the determining the first k value comprising: (paras. 96, 103-106; k-means clustering with a k value. See also Badawy, para. 87; k-means clustering.) normalizing the first distinct identity access count, wherein the normalized first distinct identity access count comprises the determined first k value; (para. 91-96; normalization of identity data for k-means clustering. Para. 96, 103; k value of 2.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of Badawy with the normalization to eliminate data noise and improve the model. (Shtar, para. 86) But modified Badawy does not explicitly teach locality sensitive hashing. Howard, however, does teach using min-wise independent permutations locality sensitive hashing scheme and a locality-sensitive hashing; (para. 78; MinHash locality-sensitive hashing to approximate Jaccard distance. See also Badawy, para. 63; similarity measuring using Jaccard similarity.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of modified Badawy with the MinHash LSH scheme to approximate the Jaccard distance for similarity determination. (Howard, para. 78) But modified Badawy does not explicitly teach wherein the first k value comprises a different value than the second k value. Elsner, however, does teach second identity access data; (paras. 46-47, 50; LDAP for an enterprise describing the access of the enterprise according to roles. Therefore, each enterprise has different identity access data. See also para. 63-64; analysis is rerun every 7 days using data from the last 30 days, so even within the same enterprise the system will use a second identity access data once time passes.) For the second identity access data, determining a second k value, comprising a second number of clusters value, for use in the k-means clustering algorithm, the determining the second k value comprising: encoding the second identity access data as a second plurality of binary vectors; using the second plurality of binary vectors, determining a second distinct identity count using min-wise independent permutations locality sensitive hashing scheme and the locality sensitive hashing; and normalizing the second distinct identity access count, wherein the normalized second distinct identity access count comprises the determined second k value; performing a second peer group analysis using the determined second k value with the k-means clustering algorithm, the second peer group analysis determining anomalies between the identities and corresponding access to the application for the second identity access data; wherein the first k value comprises a different value than the second k value. (These features are taught above with respect to first identity access data. paras. 46-47; LDAP for an enterprise describing the access of the enterprise according to roles. paras. 46-47, 50, 60-62; Clustering is based on LDAP. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to apply the same technique to the similar data of second identity access data to allow for analysis of another data set. para. 63-64; analysis is rerun every 7 days using data from the last 30 days. Duplication of parts is obvious, see MPEP 2144.04. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to apply the analysis to updated data in order to search for new anomalies.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of modified Badawy with the different k values in order to analyze different data with an accurate clustering fit. With respect to Claim 8, modified Badawy teaches the method of claim 1, and Badawy also teaches wherein the encoding the first identity access data as the first plurality of binary vectors comprises, for each identity, and for each possible combination of application/permission identity, a vector equals a 1 if the combination is present for that identity, and a 0 if the combination is not present for that identity. (para. 50, 54, 60; vector of entitlements for an entity. para. 29; users have identities. Identities have entitlements. Entitlements define access to, among other things, applications. para. 61; listing of identified entitlements for an identity. Examiner notes that a person of ordinary skill would conventionally assign 1 to a true and 0 to a false, but regardless the vector is binary (para. 63) and the assignment of either 1 or 0 to “present” is obvious to try.) With respect to Claim 9, it is substantially similar to Claim 1, and is rejected in the same manner, the same art and reasoning applying. Further, Badawy also teaches a non-transitory computer readable medium having instructions stored thereon that, when executed by one or more processors, cause the processors to provide cloud based access privilege governance, the governance comprising: (para. 105; processors. para. 113; computer readable medium such as a hard drive. Para. 47; cloud based applications or services.) With respect to Claim 16, it is substantially similar to Claim 8 and is rejected in the same manner, the same art and reasoning applying. With respect to Claim 17, Badawy teaches a cloud infrastructure comprising: (Para. 47; cloud based applications or services. paras. 5, 44-47; identity access management system allows users of a system to have identities for accessing resources of a system.) a database storing first identity access data and second identity access data for a plurality of identities and a plurality of applications, (Second data will be taught later. para. 51; database querying. para. 54; harvester obtains identity management data such as identities.) wherein each of the first and second identity access data comprises a plurality of identities, and for each of the identities, a listing of applications that the identity has access to and a corresponding permission level for that application; (para. 29; users have identities. Identities have entitlements. Entitlements define access to, among other things, applications.) an access privilege governance server coupled to the database, (para. 51; servers) encoding the first identity access data as a first plurality of binary vectors; (para. 63; system graphs identity data including weighing edges between identities as binary vectors.) using the first plurality of binary vectors, determining a first distinct identity access (para. 67; identities are clustered into peer groups where identities are strongly connected. See also Shtar, para. 94; users are clustered based on access to resources.) and a first performing peer group analysis using the determined first k value with the k-means clustering algorithm, the first peer group analysis determining anomalies between the identities and corresponding access to the applications for the first identity access data; (A determined k value will be taught later. paras. 75-77; cluster groups are analyzed. See also Shtar, para. 111; system determines whether an access to a resource group is suspicious.) But Badawy does not explicitly teach normalization. Shtar, however, does teach the access privilege governance server determining access profile anomalies comprising: (para. 111; system determines whether access to a resource is suspicious) For the first identity access data, determining a first k value, comprising a first number of clusters value, for use in a k-means clustering algorithm, the determining the first k value comprising: (paras. 96, 103-106; k-means clustering with a k value. See also Badawy, para. 87; k-means clustering.) normalizing the first distinct identity access count, wherein the normalized first distinct identity access count comprises the determined first k value; (para. 91-96; normalization of identity data for k-means clustering. Para. 96, 103; k value of 2.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the infrastructure of Badawy with the normalization to eliminate data noise and improve the model. (Shtar, para. 86) But modified Badawy does not explicitly teach locality sensitive hashing. Howard, however, does teach using min-wise independent permutations locality sensitive hashing scheme and a locality-sensitive hashing; (para. 78; MinHash locality-sensitive hashing to approximate Jaccard distance. See also Badawy, para. 63; similarity measuring using Jaccard similarity.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the infrastructure of modified Badawy with the MinHash LSH scheme to approximate the Jaccard distance for similarity determination. (Howard, para. 78) But modified Badawy does not explicitly teach wherein the first k value comprises a different value than the second k value. Elsner, however, does teach second identity access data; (paras. 46-47, 50; LDAP for an enterprise describing the access of the enterprise according to roles. Therefore, each enterprise has different identity access data. See also para. 63-64; analysis is rerun every 7 days using data from the last 30 days, so even within the same enterprise the system will use a second identity access data once time passes.) For the second identity access data, determining a second k value, comprising a second number of clusters value, for use in the k-means clustering algorithm, the determining the second k value comprising: encoding the second identity access data as a second plurality of binary vectors; using the second plurality of binary vectors, determining a second distinct identity count using min-wise independent permutations locality sensitive hashing scheme and the locality sensitive hashing; and normalizing the second distinct identity access count, wherein the normalized second distinct identity access count comprises the determined second k value; performing a second peer group analysis using the determined second k value with the k-means clustering algorithm, the second peer group analysis determining anomalies between the identities and corresponding access to the application for the second identity access data; wherein the first k value comprises a different value than the second k value. (These features are taught above with respect to first identity access data. paras. 46-47; LDAP for an enterprise describing the access of the enterprise according to roles. paras. 46-47, 50, 60-62; Clustering is based on LDAP. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to apply the same technique to the similar data of second identity access data to allow for analysis of another data set. para. 63-64; analysis is rerun every 7 days using data from the last 30 days. Duplication of parts is obvious, see MPEP 2144.04. Therefore, it would have been obvious to one of ordinary skill prior to the effective filing date to apply the analysis to updated data in order to search for new anomalies.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the infrastructure of modified Badawy with the different k values in order to analyze different data with an accurate clustering fit. With respect to Claim 23, it is substantially similar to Claim 8 and is rejected in the same manner, the same art and reasoning applying. Claims 5, 13, and 21 are rejected under 35 U.S.C. 103 as being unpatentable over Badawy (US Pub. 2020/0169603) in view of Shtar (US Pub. 2019/0158513), in view of Howard (US Pub. 2019/0199736), in view of Elsner (US Pub. 2019/0349391) and further in view of Wikipedia (“Determining the number of clusters in a data set”, Wikipedia, December, 2022). With respect to Claim 5, modified Badawy teaches the method of claim 1, but does not explicitly teach particular identity access counts. Wikipedia, however, does teach wherein the normalizing the first distinct identity access count comprises: when the first distinct identity access count is greater than or equal to 100, the determined k value is 50, and when the first distinct identity access count is between 50 and 99, the determined first k value is 45% - 50% of the distinct identity access count; and when the first distinct identity access count is between 1 and 9, the determined first k value is the distinct identity access count, and when the first distinct identity access count is between 10 and 49, the determined first k value is 85% - 90% of the first distinct identity access count. (pg. 1; choice of k is [1, n], and k can equal n to zero out error. pgs. 1-2; marginal error rate decreases as k increases, which suggests marginal increase in k has falling value. This is anticipatory of the distinct access count equaling the k-value when distinct access count is 1-9. Further, the disclosure that one can choose any value 1-n renders obvious all of these claimed k-values because these particular points are not evidenced as critical by the specification and lie within the prior art teaching of 1-n. Consequently, the limitation is obvious as a routine optimization over the prior art teaching that 1-n can be selected for k and that increasing k has diminishing returns.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of modified Badawy with the k-value routine optimization in order to strike a balance between maximum compression of data and maximum accuracy. (Wikipedia, pg. 1) With respect to Claims 13 and 21, they are substantially similar to Claim 5 and are rejected in the same manner, the same art and reasoning applying. Claims 24-25 are rejected under 35 U.S.C. 103 as being unpatentable over Badawy (US Pub. 2020/0169603) in view of Shtar (US Pub. 2019/0158513), in view of Howard (US Pub. 2019/0199736), in view of Elsner (US Pub. 2019/0349391) and further in view of Brar (US Pub. 2021/0377166). With respect to Claim 24, modified Badawy teaches the method of Claim 1, but does not explicitly teach a LPG in a VCN. Brar, however, does teach further comprising using a cloud infrastructure for access privilege governance, the cloud infrastructure comprising a first virtual cloud network (VCN) comprising a local peering gateway (LPG) communicatively coupled to a secure shell (SSH) VCN via the LPG; wherein the LPG is contained in a control plane VCN and the SSH VCN is communicatively coupled to a data plane VCN. (Access privilege governance was taught above. Fig. 16, Paras. 192-193; VCN includes a LPG coupled to a SSH VCN. The LPG is in the control plane and the SSH VCN is coupled to a data plane VCN.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of modified Badawy with the LPG in a VCN in order to provide infrastructure as a service. (Brar, para. 38-40, 192) With respect to Claim 25, it is substantially similar to Claim 24 and is rejected in the same manner, the same art and reasoning applying. Claims 26-28 are rejected under 35 U.S.C. 103 as being unpatentable over Badawy (US Pub. 2020/0169603) in view of Shtar (US Pub. 2019/0158513), in view of Howard (US Pub. 2019/0199736), in view of Elsner (US Pub. 2019/0349391) and further in view of Al-Serw (Al-Serw, Nour, “K-Means: The maths behind it, how it works and an example” available at https://nouralserw.medium.com/k-means-the-maths-behind-it-how-it-works-and-an-example-67fdcfcb80f0, 4/11/2022). With respect to Claim 26, modified Badawy teaches the method of Claim 1, and Shtar also teaches k-means clustering (paras. 96, 103-106; k-means clustering with a k value. See also Badawy, para. 87; k-means clustering.) The same motivation to combine as the independent claim applies here. However, modified Badawy does not explicitly teach recalculating a mean. Al-Serw, however, does teach wherein the k-means clustering algorithm comprises: assigning each observation to a cluster with a nearest mean; and recalculating a means for observations assigned to each cluster. (Examiner notes that Shtar and Badawy previously taught k-means clustering, and therefore they teach this limitation through inherency. Regardless, Examiner cites Al-Serw, pgs. 3-4, Steps 3-4; In k-means clustering each data point is assigned to the cluster with the closest centroid, and then the centroids are re-averaged.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of modified Badawy with the recalculating a mean in order to perform k-means clustering. With respect to Claims 27-28, they are substantially similar to Claim 26 and are rejected in the same manner, the same art and reasoning applying. Alternate Grounds Claims 1, 8-9, 16-17, and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Badawy (US Pub. 2020/0169603) in view of Shtar (US Pub. 2019/0158513) in view of Howard (US Pub. 2019/0199736) in view of Elsner (US Pub. 2019/0349391) and further in view of Wikipedia (“Determining the number of clusters in a data set”, Wikipedia, December, 2022). With respect to Claim 1, Badawy, Shtar, Howard, and Elsner teach as above, but under this ground of rejection do not teach normalizing the distinct identity access count, a determined first k-value or k-means clustering. Wikipedia, however, does teach normalizing the first distinct identity access count, wherein the normalized first distinct identity access count comprises the determined first k value; (pg. 1; selection of k to strike a balance between maximum compression of data and maximum accuracy. See also pgs. 1-2; elbow method.) for the first identity access data, determining a first k value, comprising a number of clusters value, for use in a k-means clustering algorithm, the determining the first k value comprising: (pg. 1; determining a k for a data set.) and performing a first peer group analysis using the determined first k value with the k-means clustering algorithm, the first peer group analysis determining anomalies between the identities and corresponding access to the applications for the first identity access data. (pg. 1; solving the clustering problem.) It would have been obvious to one of ordinary skill prior to the effective filing date to combine the method of modified Badawy with the determining a k-value in order to select acceptable error for the calculation while compressing the data. (Wikipedia, pg. 1) The same citation would apply, mutatis mutandis, to all other claims. Remarks Applicant appeals and files a Brief 7/17/2026. An appeal conference was held and the Conference finds the arguments unpersuasive, but reopens to add a 101 rejection and to reject Claim 5 and similar claims under 103. The instant claims are directed to solving a known mathematical problem. Examiner cites Wikipedia to show that the art understood that finding the appropriate k-value for a k-means analysis is a distinct problem from performing the k-means algorithm. The art recognized the same issue presenting in the specification, namely that utilizing a maximum k value will increase accuracy but require additional computation. Compare Wikipedia, pg. 1 (“[T]he optimal choice of k will strike a balance between maximum compression of the data using a single cluster and maximum accuracy by assigning each data point to its own cluster.”) with Spec, para. 45 (“The normalization in accordance to embodiments provides unexpected results as performance improves while the accuracy remains the same or nearly the same as using non-normalized, much higher cluster counts.”). The claims are directed to a mathematical answer to a mathematical problem. The specification purports to present an algorithm for identifying an optimal k-value, much like the disclosed elbow method or other approaches detailed in Wikipedia. Consequently, the claims are directed to a judicial exception and are rejected. The Conference also decides to reject Claim 5 and similar claims. As an initial point, in the method set (Claim 5 itself) the method is obvious whenever any conditional branch is obvious. Examiner cites Wikipedia to anticipate the k=n branch (“the extreme case of zero error if each data point is considered its own cluster (i.e., when k equals the number of data points n).”). Applicant admits that in some embodiments the distinct identity access count will be n (“Depending on the size of the selected identity access data and its access profile similarity, the distinct identity access data count can vary from 1 to N.” Spec, para. 44). Consequently, Wikipedia renders obvious because “[i]n the case where the claimed ranges ‘overlap or lie inside ranges disclosed by the prior art’ a prima facie case of obviousness exists.” (MPEP 2144.05) k=distinct access count when distinct access count can equal n for values of n=1-9 is obvious over the teaching that one can always set k=n to zero out the error. For the similar claims in the other statutory categories (Claims 13 and 21) Examiner is required to teach all four branches. Those branches are obvious as routine optimizations. The art already knew that one had to strike a balance between increasing k to reduce error but minimizing k for calculation efficiency. Applicant identifies four break points – At 10 distinct values the k calculation shifts from 1distinctN to .9distinctN. At 50 it shifts to .5distinctN and at 100 it caps at k=50. But it is clear from Wikipedia and from Applicant’s own specification statements that those values have no criticality to their meaning without knowing the distribution of the underlying data. In other words, one cannot measure how much error is removed, and therefore the marginal accuracy, in the abstract. One would have to know the distribution of the data points. Consequently, the specification statement that “The normalization, which generally reduces the original determined access count, is done to the keep the cluster count manageable to avoid performance issues. The normalization in accordance to embodiments provides unexpected results as performance improves while the accuracy remains the same or nearly the same as using non-normalized, much higher, cluster counts” is simply not true in the abstract. It is true that reducing k will simplify calculation, but it is not true that normalization would keep the accuracy the same or nearly the same. Therefore the claimed k-values are non-critical values lying within a previously-disclosed broader scope and are obvious. See MPEP 2144.05(II)(A). If the above break points were unexpectedly accurate it would be inappropriate to use a routine optimization rationale. However, Applicant provides no evidentiary support for the contention. Further, the contention would necessarily be a moving target based upon the processing power of the machine performing the k-means clustering. A high performance processor can tolerate more calculation before performance is impacted, which would necessarily shift the optimal k-value for calculation. In other words, the “performance improves” part of the “performance improves while the accuracy remains the same” statement is processor-dependent and the claims on their face are processor-agnostic (see, e.g., Claim 9, “when executed by one or more processors”). The Conference finds the statement to be a mere allegation of patentability that is unpersuasive to defeat obviousness due to routine optimization. Turning to the complaints in the Brief, Badawy and Shtar, like the instant claims, engage in peer group analysis. See Badawy, para. 53; “Specifically, It is desirable to group or cluster the identities of an enterprise 100 into peer groups such that the identities in a peer group are similar with respect to the set of entitlements assigned to the identities of that group (e.g., relative to other identities or other groups). Peer grouping of the identities within an enterprise (or viewing the peer groups of identities) may allow, for example, an auditor other person performing a compliance analysis or evaluation to quantitatively and qualitatively assess the effectiveness of any applicable pre-existing polices, or lack thereof, and how strictly they are enforced.” Badawy begins by gathering entitlement data. Specifically, Badawy discloses “The identity management data stored may thus include a set entries, each entry corresponding to and including an identity (e.g., alphanumerical identifiers for identities) as defined and managed by the identity management system, a list or vector of entitlements assigned to that identity by the identity management system, and a time stamp at which the identity management data was collected from the identity management system.” (para. 60) A list of entitlements for an identity is anticipatory of Spec, para. 38 and Table 1. A vector of entitlements for an identity is anticipatory of Spec, para. 39 and Table 2. Badawy then generates a graph with similarity weights and prunes the graph. The graph is constructed using a jaccard similarity (para. 63) and “the pruning of the graph is associated with locality aspect of identity governance, where an identity’s access entitlements should not be directed impacted, if at all, by another identity with strong dissimilar entitlement pattern (e.g., a weak connecting edge)… The pruned identity graph can then be used to cluster the identities into peer groups of identities at step 240. Within this graph approach, a representation of a peer group could be represented by a maximal clique, where every identity is strongly connected (e.g., similar) to every other identity within the peer group, and consequently, members of the clique all share a relatively large, and hence dominant, common core of entitlements.” (paras. 66-67) In other words, the jaccard similarity is used to identify similar data points. This is directly analogous to the specification’s use of Minhash to identify “distinct” identity access counts, which Spec, paras. 40-41 describe as “a technique for quickly estimating how similar two sets are and is an instance of locality sensitive hashing (LSH)…LSH allows a hash code to be precomputed that is then quickly and easily compared to another precomputed LSH hash code to determine if two objects should be compared in more detail or quickly discarded.” Examiner cites the Howard reference, which suggests using Minhash as a substitute for Jaccard distance because “Jaccard distance [] can be expensive to compute.” (Howard, para. 78). Therefore, the art already knew that Minhash could be applied to determine similarity when one prunes for locality in access governance. Consequently, when Applicant argues at Brief, pgs. 4-5 that “a data-derived k-value” is a novelty, that is incorrect because Badawy’s number of peer groups is not pre-defined values. Rather the peer groups naturally arise out of the characteristics of the underlying data, and they are calculated in Badawy using a function that performs the same purpose as Applicant’s Minhash, and the Howard reference evidences the art knew one could substitute a Minhash for the Jaccard calculation to lower processing requirements. Next we turn to the normalization step. Applicant is correct to argue over this step, because it largely destroys whatever value the claim has had up to this point. Examiner asserts that Badawy/Howard renders obvious the calculations up to this point, but even if they did not the calculations are made irrelevant by the normalization step. Whether we are talking about Jaccard similarity or Minhash similarity, whether two data points are similar or not is a function of a threshold of similarity. Consequently, the result of the encoding/locality-sensitive-hashing steps is that the claimed distinct access count could be anything from 1 (where the similarity threshold is set very low such that all points are similar and should be analyzed together) to N (where the similarity threshold is set very high such that data points are dissimilar). Applicant’s Specification admits as much (“Depending on the size of the selected identity access data and its access profile similarity, the distinct identity access data count can vary from 1 to N”). But even if the steps up to this point result in N one needn’t worry, as the normalization step will allow one to reduce N to whatever value one wants. Table 3 identifies that sometimes N stays as N (see “Between 1 and 9” row) and sometimes N is modified in a relative fashion (see “Between 10 and 49” and “Between 50 and 99”) and sometimes N is modified to (or, more accurately, replaced with) an absolute value (see “100 and above”). The particular values in Table 3 are not claimed in the independent claims. The broadest reasonable interpretation of the normalization step encompasses no modification of the prior value at all or complete replacement of the prior value with any other arbitrary value. Consequently, when Applicant states “The claims do not recite an unconstrained choice of k” that is almost entirely false. A person of ordinary skill prior to the instant disclosure knew that one could select k to be anything 1-N, since one cannot cluster N datapoints into more than N clusters. The result of performing the encoding/hashing/normalization steps would result in 1-N choices for k, with the sole exclusion of situations where some accesses are exactly the same. i.e. if Accesser A and Accesser B had exactly the same accesses, even the most stringent similarity threshold could not find dissimilarity between them. However, that situation is covered by the prior art, which specifically prunes based on similarity and therefore would be forced to place two identical data points into a shared peer group. But even that teaching misses the point – in the vast majority of datasets one would expect at least some dissimilarity in the accesses (especially because the granularity of the description of the accesses is not a claimed limitation) so in the vast majority of the situations different Minhash uses would result in different distinct access counts and different normalizations would result in different modifications of those access counts to every reasonably conceivable value of k. With due respect to Applicant’s argument on Brief, pg. 5, there is no way to read the claims in light of Spec, paras. 44-45 as anything other than a statement that the claim intends to embrace virtually any value of k that one might use. Applicant does not explain how the claim as a whole is nonobvious when the calculations Applicant argues are limiting on the result are claimed in such a broad manner that they do not, in fact, limit the result. Spec, paras. 44-45 are clear that one embodiment embraced by the claim scope is that the encoding/hashing steps result in a distinct identity access count that can be N, and that normalizations embraced by the claim scope performed on that value would result in k-value range that is bounded by N not being modified or being absolutely modified to any lesser value including a value of 1. Therefore, the result of Applicant’s allegedly novel algorithm in at least some embodiments is the same thing the art had before – “just pick a value of [1, N] for k that you think will be effective in balancing accuracy versus calculation difficulty.” Applicant’s argument inverts the proper analysis. The fact that in other embodiments (for particular data sets, or for using particular Minhash similarity parameters, or for using particular normalization parameters) the k-value choice may be constrained is not relevant, because Examiner is not required to show that there are no non-obvious points within the claim scope, Examiner is only required to show that at least one point within the scope is obvious. Applicant’s argument must be effective over the entire claim scope before it can even possibly be persuasive. Examiner agrees, for example, that if one considered the particular data in Table 1 and one performed locality hashing using the particular Minhash function in para. 41, and then one performed the particular normalization in Table 3, the k-value would be constrained – even dictated to be a particular value. For that hypothetical claim (one which has a host of currently-unclaimed features) Examiner agrees that a “constraint” argument would be applicable over the entire breadth of the claim scope. Examiner assumes there are other claim scopes in which the k-value would be constrained over the entire breadth of the scope. But those claims are not these claims, Applicant does not include the features, the breadth of the claim embraces the scope Examiner details above, and Applicant’s argument directed to unclaimed features is unpersuasive. Regardless, the argument is secondary because Examiner’s rejection endeavors to show the obviousness of the constraining math. Examiner does not rely solely upon the argument that Applicant does not truly limit the k-value. As stated above, Examiner agrees that one can hypothesize at least some data sets in which the encoding/hashing/normalizing would be effective in limiting the k-value selection. So Examiner teaches the limitations for what they are. Applicant argues at Brief, pg. 6 that “A count of communities that happens to result after graph clustering is not a count of distinct identity access.” Applicant does not dispute the encoding step, which as Examiner states above is anticipated by Badawy. That leaves “using the first plurality of binary vectors, determining a first distinct identity access count using min-wise independent permutations locality sensitive hashing scheme and a locality-sensitive hashing.” Applicant does not appear to dispute that Badawy performs a Jaccard similarity on the encodings. Applicant does not appear to dispute that the Jaccard similarities compared to a threshold has the effect of determining similarities. Applicant does not explain how determining grouped similar accesses fails to render obvious identifying a distinct access count. Therefore Badawy departs from the Specification and claim language only in two aspects: 1) it does not call the result of its action a distinct identity access count and 2) it uses Jaccard similarity rather than Minhash. Howard supplies the latter, and the former is merely a distinction in what Applicant terms the output of the step. The prior art is not required to call a method step or a structure by the same name as Applicant, it is only required to render the step or structure obvious. In other words, “A count of communities that happens to result” from Badawy when it is modified by Howard’s Minhash is a count of distinct identity access profiles, because the mechanism by which the Specification determines the encoding are distinct is by the output of a Minhash similarity hashing application and Badawy in view of Howard counts communities formed by Minhash. Applicant next argues at Brief, pg. 7 that Shtar does not teach normalization and a k value. Applicant argues that Shtar performs a different normalization and that it’s k value “occurs only after use groups have already been discovered.” Shtar discloses a normalization technique, and the independent claims do not particularly limit how normalization is performed. Shtar teaches that normalization eliminates noise and improves the model, and therefore one of skill was motivated to apply it to the outcome of Badawys pruning to additionally eliminate noise and improve the model. Obviousness is not limited to the exact prior art usage of the technique, but instead it is generally obvious to apply known techniques to similar things for the same benefit, see MPEP 2143. Further, Examiner will also cite Wikipedia in an alternate ground, which explicitly teaches some multiple normalizations. With respect to the k-value, the citation is for a k-value for k-means clustering. Examiner is not sure what the argument that k values “occurs only after the groups have been discovered” has to do with anything, that is how the instant claims function as well. The claims determine a distinct access count, which is a number of peer groups. The claims then normalize that number, which is also a number of peer groups. The specification calls the result of the normalization a “normalized cluster count” which “is then used in the peer group analysis using k-means clustering in order to derive insights” (Spec, para. 46) so Examiner fails to see how this argument distinguishes Applicant’s characterization of Shtar from the claims. Shtar finds a value in performing a near/far analysis with k=2. Applicant does not explain how that is any different from Table 3 finding value in k=50 or from k=DAC when DAC=2. Regardless, the citation for Shtar is only that Applicant did not invent k-means clustering and that k-means clustering requires the selection of a k-value. Supplying a value for the k-value was taught through the actions of the previous steps where Badawy modified by Howard generated groupings of similar data points together with the teaching from Shtar that one could normalize to remove noise and improve the model. Since Wikipedia explicitly teaches the issue of finding a k-value for a k-means analysis, Examiner will also cite Wikipedia in the alternate grounds for this feature. At Brief, pgs. 8-9, Applicant advances the interesting notion that Howard’s use of Minhash somehow results in different calculation than Applicant’s use of Minhash. The argument is unpersuasive because it lacks any reasonable basis. When Applicant uses the term “distinct identity access count” that includes detecting if two things are not-same but similar and grouping them because that is what Minhash does, see Spec, paras. 40-41. Therefore, when Howard Minhashes the code blocks that make up the procedure it is determining whether the two processes comprise things that are so similar as to make the processes the same thing, i.e. indistinct (“The Jaccard distance can be approximated by the fraction of [Minhash] hashes in which the blocks selected for two procedures are equal”). It is the same thing as comparing the Smith and Alice rows (1, 3, 6, 0 to 1, 3, 6, 0) to recognize they are so similar as to be the same thing, see Spec, para. 42. In other words, both Howard and Applicant employ Minhash as a means of detecting fuzzy similarity because Minhash is a means of detecting fuzzy similarity, just as a threshold Jaccard distance is a means of detecting fuzzy similarity. Applicant next argues that Elsner does not teach different k values. Applicant states that “The number n is therefore ordinarily supplied by pre-existing organizational group definitions, not derived from application/permission vectors.” Examiner disputes this, because Elsner states LDAP attributes is not a limitation, rather “any grouping mechanism that identifies groupings based on expected user contributions to log activity may be used.” (Elsner para. 51) But even if it were true, that would only be distinguishing Elsner from limitations that Examiner had already cited Badawy/Howard/Shtar for. The Elsner citation is largely because Examiner expected Applicant to dispute duplication of parts for what is clearly a duplication of parts scenario (repeating all the calculation steps a second time on second access data, and then claiming “wherein the first k value comprises a different value than the second k value”). Assuming the teachings with respect to the first calculations were sufficiently taught, one has just as much motivation to apply them to a second group of data as the first. That is because applying a known technique to similar things in the same way is generally obvious, see MPEP 2143(I)(C). An otherwise obvious technique, here the first k-value derivation for a first dataset, does not become nonobvious just because one duplicatively applies it to a second dataset for the same type of outcome. However, to ensure that “different value” was more explicitly taught, Examiner cited Elsner to teach different enterprises with different access data. Examiner also cited rerunning of the analysis, which anticipates a second analysis and suggests different data from the first analysis. Applicant argues that theoretically two enterprises could have the same data and theoretically the data could remain the same. Examiner agrees, that is a theoretical possibility. But that does not defeat obviousness, because obviousness is not limited to what “necessarily” must happen but rather what is suggested from the disclosure. Rerunning the analysis is done because the reference suggests that the data would change. If the data did not change, the suggestion to continually rerun the same analysis would lack utility. A person of ordinary skill would expect different enterprises to have different data sets. Therefore the Elsner teaching suggests a second analysis resulting in a different outcome. Finally, Applicant argues at Brief, pg. 10, that obvious to try is not applicable to assigning a 0 or 1 for binary vectorization because Examiner does not identify a design need. The design need is inherent in the name. Binary requires a 0,1 assignment. There are two possible ways to assign permitted/not-permitted, either permitted is 1 and non-permitted is 0, or vice-versa. Therefore the claimed assignment is one of two possible outcomes, and is obvious to try. The 103 rejections are maintained as above. All claims are rejected under 101. Claim 5 and similar claims are rejected under 103. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to NICHOLAS P CELANI whose telephone number is (571)272-1205. The examiner can normally be reached on M-F 9-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Vivek Srivastava can be reached on 571-272-7304. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NICHOLAS P CELANI/Examiner, Art Unit 2449
Read full office action

Prosecution Timeline

Show 17 earlier events
Feb 04, 2026
Examiner Interview Summary
Feb 09, 2026
Response Filed
Mar 13, 2026
Final Rejection mailed — §101, §103
Apr 23, 2026
Interview Requested
May 08, 2026
Response after Non-Final Action
May 21, 2026
Notice of Allowance
Jul 24, 2026
Response after Non-Final Action
Jul 30, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706878
ZERO-TRUST ARCHITECTURE FOR SECURE AGGREGATION IN FEDERATED LEARNING
3y 9m to grant Granted Aug 11, 2026
Patent 12695797
MEDIA COMMUNICATIONS FOR WEARABLE DEVICES
3y 1m to grant Granted Jul 28, 2026
Patent 12682092
SYSTEMS AND METHODS FOR USER DATA COLLECTION
3y 8m to grant Granted Jul 14, 2026
Patent 12647250
CIPHERTEXT CONVERSION SYSTEM, CIPHERTEXT CONVERSION METHOD, AND NON-TRANSITORY COMPUTER READABLE MEDIUM
1y 9m to grant Granted Jun 02, 2026
Patent 12634201
Detecting site locations of unknown network devices
4y 10m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
46%
Grant Probability
88%
With Interview (+42.3%)
3y 2m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 463 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month